This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows 7 occasionally fails to start.

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey guys, it's me, ClementZ again.

My problem now relates to startup.
It began today.

Yesterday, before going to bed, I turned off my computer.
There was that customary shield next to the "Shut Down" button, indicating that updates needed to be installed.
Nothing unusual about that, I proceeded to shut Down, and the updates installed, as per usual.
Only unusual thing was the amount of updates - 19.
Shut Down completes, without any problems.
I then go to bed.

Today, wake up, go to school, the usual.
Come back, turn on the computer, but it doesn't turn on.
I turn it off, turn in back on, and get the BSOD.
Computer restarts, and prompts me to Startup Repair
I decide against System Restore this time, and do other things.

The computer restarts,
And begins configuring 14693 updates. Once those have been configured, it starts as normal (albeit with abnormal "Preparing Desktop" and other messages), with one problem.
I get a "Solve PC Issues" message regarding my backup.
I click on it, and I get an error message saying that Windows cannot locate the location of the backup.
I then plugged in my harddrive, and click the error message again.
Backup attempts to run, but after about 45 seconds, I get a message saying, "A shadow copy could not be created. Please check "VSS" and "SPP" application event logs for more information. Details: Insufficient storage available to create either the shadow copy storage file or other shadow copy data."
What the hell? My 465GB external HDD has 334 GB of free space (this is with a previous backup) and my 920 GB internal HDD has 836 GB of free space. Where is there not enough space?

Furthermore, it seems that my computer is unable to read the backups that I had previously done two weeks ago on this computer.

Anywho, I decide to restart, where my original problem happens, except without the BSOD. I just get a black, unresponsive screen fro 20 minutes.
I manually turn off the computer (because nothing worked), and turned it back on again.
I get prompted to Startup Repair once again, and this time, decide to do a System Restore.
It runs for 15 or so minutes, before saying that failed due to a system error (8x0000fff or something, I can't remember as I was mad and panicking),
The computer restarts, and the black screen returns for 5 minutes, then to the logon screen.

MSE doesn't read anything, and I have not yet ran MalwareBytes, and I am still unable to access my HOSTS file.

I am here now, typing, unwilling to turn off my computer again, because I don't want to have to do that again, if it isn't necessary.

My system:
Hewlett-Packard

Windows 7 Home Premium 64-Bit

Intel Core i3 530 @2.93 GHz
8192 MB RAM
NVIDIA GeFore GT 220 GPU
1TB HDD
model is p6334f

Harddrive is an HP Portable SimpleSave Harddrive.

Help?

HijackThisLog

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:25:14 PM, on 16/12/2011
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\WhatPulse\WhatPulse.exe
C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe
C:\Windows\V0650Mon.exe
C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\HPSSBackupMonitor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files (x86)\Windows Media Player\wmplayer.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
C:\Users\Owner\Downloads\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Norton Safe Web Lite BHO - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll
O3 - Toolbar: Norton Safe Web Lite - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\coIEPlg.dll
O4 - HKLM\..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [RogersServicepointAgent.exe] "C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe" /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe
O4 - HKCU\..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Owner\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - Startup: HP SimpleSave Monitor.lnk = Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: BackupService - ArcSoft, Inc. - C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Norton Safe Web Lite (NSL) - Symantec Corporation - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Rogers SHS Service (RogersSelfHelpService) - Rogers Cable Communications - C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
O23 - Service: Rogers Update Manager (RogersUpdateManager) - Rogers Cable Communications - C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ServicepointService - Radialpoint Inc. - C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 13773 bytes
Hello ClementZ,

No malware showing here, however:

C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe

For a while, many ISP's were providing their customers with RadialPoint antivirus software. Most have since switched to anything else, after all the problems RadialPoint caused. I cannot express how many systems I have run into where this pretty awful "security" software has caused problems. As a rule of thumb, for future reference, ISP's tend to provide security softwares that costs them less, not because they are the best, so truly better to decline any ISP offered security programs. Plenty of good, free versions to choose from, if you wish to save money.

I can't say RadialPoint is the problem there, but it usually is. Let's get a detailed look at things and see.


The system is Windows 7, so when running any of the scan files we use, be sure to right click the file, then select "Run as administrator" to start the scan/tool.

And To make sure you have an accurate view of files there, make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"



To keep them from interfering with the repairs, be sure to temporarily disable all antivirus/anti-spyware softwares while these steps are being completed. This can usually be done through right clicking the software's Taskbar icons, or accessing each software through Start - Programs. Here are some antivirus disable tips if needed.

——-

Click here and download OldTimer's OTL to your desktop, then click that to open the scan display. At the top click "Scan All Users", then click "Run Scan". Make no other changes at this time.

When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are also saved in the same location as OTL.exe. Post the contents of those back here please.

———–

Click here and download the installer for Gmer to your desktop, then click that file to run Gmer.


Once the opening scan finishes, click on Scan (again, before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan).

When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.

Note - If Gmer shows it has located infection once it's opening scan completes, do not click the Scan button. We don't want hidden malware settings to cause any problems. Instead, just click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Copy the information and post it here please.

———–

Download aswMBR ( 511KB ) to your desktop.
  • Double click the aswMBR.exe icon to run it
  • Decline a download of avast itself if offered
  • If avast! antivirus is already installed, go to the dropdown next to AV engine: and select (none)
  • Click the Scan button to start the scan
  • On completion of the scan, click the save log button, save it to your desktop and post it in your next reply.

A lot, but comprehensive, and will make sure we get a good view of everything.
1. Should I remove the ServicePointAgent thing then? And 2. The computer stopped having these problems a while ago, Should I run the two scans, just in case anyway?
OTL.txt

OTL logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/11/05 02:10:39 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
PRC - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
PRC - [2011/01/04 15:51:14 | 004,318,520 | —- | M] (Rogers) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
PRC - [2011/01/04 15:51:14 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
PRC - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010/10/27 21:21:54 | 001,155,072 | —- | M] (Last.fm) – C:\Program Files (x86)\Last.fm\LastFM.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
PRC - [2010/02/23 12:00:00 | 000,028,672 | —- | M] (Creative Technology Ltd.) – C:\Windows\V0650Mon.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/04/08 15:51:34 | 002,814,976 | —- | M] (WhatPulse.org) – C:\Program Files (x86)\WhatPulse\WhatPulse.exe
PRC - [2008/06/01 17:05:02 | 001,529,856 | —- | M] (Rokario Software) – C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/07 18:53:16 | 000,265,536 | —- | M] () – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/11/05 02:10:39 | 001,989,592 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
MOD - [2011/01/04 15:42:24 | 000,158,208 | —- | M] () – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\Windows7Features.dll
MOD - [2010/10/27 21:23:04 | 000,106,496 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll
MOD - [2010/10/27 21:22:52 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_messengernotify.dll
MOD - [2010/10/27 21:22:42 | 000,058,880 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_skypenotify.dll
MOD - [2010/10/27 21:22:08 | 000,147,456 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_madtranscode.dll
MOD - [2010/10/27 21:22:00 | 000,028,160 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_httpinput.dll
MOD - [2010/10/27 21:19:28 | 000,372,736 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll
MOD - [2010/10/27 21:19:06 | 000,025,088 | —- | M] () – C:\Program Files (x86)\Last.fm\breakpad.dll
MOD - [2010/10/27 21:18:50 | 000,180,224 | —- | M] () – C:\Program Files (x86)\Last.fm\Moose1.dll
MOD - [2010/10/27 21:18:34 | 000,540,672 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmTools1.dll
MOD - [2010/10/27 21:13:52 | 001,382,507 | —- | M] () – C:\Program Files (x86)\Last.fm\libfftw3f-3.dll
MOD - [2010/10/27 21:13:52 | 000,074,240 | —- | M] () – C:\Program Files (x86)\Last.fm\zlibwapi.dll
MOD - [2009/12/01 19:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2008/04/16 17:42:30 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtNetwork4.dll
MOD - [2008/04/16 17:42:16 | 000,524,288 | —- | M] () – C:\Program Files (x86)\Last.fm\QtSql4.dll
MOD - [2008/04/16 17:42:02 | 006,701,056 | —- | M] () – C:\Program Files (x86)\Last.fm\QtGui4.dll
MOD - [2008/04/16 17:36:38 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtXml4.dll
MOD - [2008/04/16 17:36:34 | 001,654,784 | —- | M] () – C:\Program Files (x86)\Last.fm\QtCore4.dll
MOD - [2008/04/02 14:26:50 | 000,233,472 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll
MOD - [2008/04/02 14:26:34 | 000,021,504 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll
MOD - [2008/04/02 14:26:28 | 000,135,168 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/04/08 16:09:28 | 000,290,816 | —- | M] (Puran Software) [Disabled | Stopped] – C:\Windows\SysNative\PuranDefragS.exe – (PuranDefrag)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe – (ServicepointService)
SRV - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe – (NSL)
SRV - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe – (BackupService)
SRV - [2010/06/03 14:46:36 | 000,163,840 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe – (RogersUpdateManager)
SRV - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe – (RogersSelfHelpService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/12/16 22:00:00 | 000,163,840 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE – (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,126,464 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE – (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/07/07 18:21:28 | 000,174,184 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/03/31 12:00:00 | 000,393,536 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0650Vid.sys – (V0650Vid)
DRV:64bit: - [2010/03/26 13:37:36 | 000,173,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/10/02 07:58:58 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 07:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/17 00:57:46 | 000,023,536 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms – (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
DRV:64bit: - [2009/08/20 19:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/05/06 15:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://hp.ca.msn.com/default.aspx
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 12 6E 58 55 1C CB 01 [binary data]
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4

========== FireFox ==========


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/07/05 21:32:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\FinalVideoDownloader\Firefox [2011/09/26 14:47:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/15 16:26:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/19 18:16:00 | 000,000,000 | —D | M]

[2011/11/15 16:27:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2011/12/02 19:36:52 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/17 20:37:14 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\[removed]
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 20:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/26 14:47:44 | 000,000,000 | —D | M] (FinalVideoDownloader plugin for Mozilla Firefox) – C:\PROGRAM FILES (X86)\FINALVIDEODOWNLOADER\FIREFOX
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W30WC1OY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 02:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:44:20 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/04 22:32:18 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:44:20 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/04 22:44:20 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/04 22:44:20 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Rogers Servicepoint Agent (Enabled) = C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.9_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe (Rokario Software)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF5ABC5E-3819-46FA-B907-6644B8D77739}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F14C9C70-7912-4006-82E7-648CDC421877}: DhcpNameServer = [removed]
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell - "" = AutoRun
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 16:04:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{91C8AE5A-BB9F-419A-B807-90D90A51D55D}
[2011/12/22 15:50:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E4B636FE-0D14-4091-BD72-BF178781D1F8}
[2011/12/21 17:00:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B0D7CAB2-283A-46FC-B63D-3CF4549811B5}
[2011/12/21 17:00:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{596D9425-13D5-4B80-BC07-478FA159BB03}
[2011/12/20 16:50:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{20C67B7F-D5C3-4EA0-B5D6-56D29ADA0C1E}
[2011/12/20 16:50:17 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DFA22BDD-7835-4B93-AAE2-78CA8DE57ACE}
[2011/12/19 15:37:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6B2D2CFB-E218-4509-8DBC-1C3F5E23DBBF}
[2011/12/19 15:37:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C0514324-FD0C-40D9-98C9-9F26F79F97C9}
[2011/12/19 01:16:31 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\testdisk-6.13
[2011/12/18 14:19:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{44BB564C-9A5D-4ECA-A491-598725543B8F}
[2011/12/18 14:19:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{787CE0ED-7694-486F-8B12-F6E856BE90BD}
[2011/12/17 23:59:01 | 000,847,872 | —- | C] (Western Digital) – C:\Users\Owner\Desktop\WinDlg.exe
[2011/12/17 18:10:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{90A5972C-7BB8-4434-BCF7-4992703AB95A}
[2011/12/17 18:10:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{11942ED9-762F-4B29-AA48-1E73D9174F6B}
[2011/12/16 23:55:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/16 23:55:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 23:55:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/16 23:55:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/16 23:55:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/16 23:55:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/16 23:55:56 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/16 23:55:56 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/16 23:55:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/16 23:55:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/16 23:55:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2011/12/16 19:55:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{89AD739B-048A-483E-B5A4-90EFDFEC221D}
[2011/12/16 19:55:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9F35A44D-7831-4E38-8B81-A379E2E589A7}
[2011/12/16 19:44:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/16 19:44:29 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/16 19:44:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/16 16:12:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{08E737A6-FF5D-4392-BC54-54B89DADB99B}
[2011/12/16 16:12:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{193BCD13-B7E1-417C-9436-9E9839830F18}
[2011/12/15 15:46:42 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{64FB69B7-74CC-47C3-BB08-4A4D1B53B257}
[2011/12/15 15:46:20 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{AD888F84-5AC8-4DAE-AE88-76DFAB16EDE3}
[2011/12/14 15:34:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{CE849C1F-5527-4043-994E-66FCC5453AF0}
[2011/12/14 15:33:48 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{51218CFE-F55F-4AF7-8A29-B66D2ECF2431}
[2011/12/13 13:12:44 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{10D6B9BA-5ABD-4595-ACF1-2BC1A952B2A7}
[2011/12/13 13:12:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{D4719874-5EF8-4ADA-BDE1-9DF14592C529}
[2011/12/12 16:42:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{78C8EADE-1861-4A4F-82FC-0D8EBE41CD10}
[2011/12/12 16:42:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1F5940F6-4833-47C0-A8D6-6F3710C13DA3}
[2011/12/11 15:22:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F17D7D39-E8EE-49AE-B1FB-CD16F135987E}
[2011/12/11 15:22:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{43592173-D04B-45A6-B9BA-F2940021C273}
[2011/12/10 13:17:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6139CE19-6638-48EC-82A4-DD09E4B9FDDE}
[2011/12/10 13:17:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{3DDFEF60-49CB-4902-82EA-851F00BCBB83}
[2011/12/09 15:46:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D11940F-25C7-4195-878D-C6D97EA34FAB}
[2011/12/09 15:46:09 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9212E1E8-EBE4-4CE6-9986-B98FC234CF22}
[2011/12/09 15:40:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 15:39:31 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 15:39:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/09 15:27:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/08 16:03:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DDAB35AE-CDDB-4EE2-9D37-01E8677CEAFC}
[2011/12/08 16:03:23 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E99F74B6-9F3D-4CD1-8691-8109D3FE1AB8}
[2011/12/07 17:06:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{14A84DDE-F7AE-418A-87DA-0A2F66E4C349}
[2011/12/07 17:05:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F4B6C955-2EC9-42DD-BFE7-F3E5C6919AFD}
[2011/12/06 15:41:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B95D42A0-65A3-4A1B-A3E1-8B9C28E3E627}
[2011/12/06 15:40:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B52DFCA2-286F-471E-9504-E75B5C7AFE7D}
[2011/12/05 15:18:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C7A225BB-8584-4747-AD7D-D57565502B8E}
[2011/12/05 15:17:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F0335E61-8562-4472-ACD3-0939C2E3147F}
[2011/12/04 11:09:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{2B18B578-FB1B-4873-9E52-F22E0EA27329}
[2011/12/04 11:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9FF0B248-7DB8-4BB0-9FD7-822D83D789F0}
[2011/12/03 22:21:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8AE60C4C-DE4D-4002-8B38-E6E858EE7699}
[2011/12/03 22:20:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8B161D07-75C5-4A71-AA10-8A9B8AD2359D}
[2011/12/03 10:20:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1FB7C86A-8AB1-46A8-A7CF-78B7058A8D94}
[2011/12/03 10:20:13 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1B136402-BF9E-44A0-ABE9-2B784578CAD6}
[2011/12/02 16:04:07 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/02 15:42:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D1A43B8-8A4E-4E52-9976-7FE2AC6425A2}
[2011/12/02 15:42:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{5A72F670-75B5-4A8C-A932-EA1DEB4CAB95}
[2011/12/01 16:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puran Defrag
[2011/12/01 16:25:40 | 001,417,216 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranFD.exe
[2011/12/01 16:25:40 | 000,290,816 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragS.exe
[2011/12/01 16:25:40 | 000,275,968 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDC.exe
[2011/12/01 16:25:40 | 000,270,336 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefrag.dll
[2011/12/01 16:25:40 | 000,130,048 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragBT.exe
[2011/12/01 16:25:40 | 000,000,000 | —D | C] – C:\Program Files\Puran Defrag
[2011/12/01 16:13:19 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B6323AF0-6488-4B51-9343-41EC1DF20D1A}
[2011/12/01 16:12:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7940265E-F90B-4E8B-B1A2-3EB5664144C1}
[2011/11/30 17:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/30 15:25:29 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{19C62BA7-FD7A-4102-9E86-50ECD7714AFD}
[2011/11/30 15:25:07 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B962C5FB-79F8-4B7D-B6C6-5EB38FC1495A}
[2011/11/29 13:11:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DB245045-2B52-4213-8524-A5092754DCDC}
[2011/11/29 13:10:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1E0B4E88-6799-4C13-B421-F31168D619DB}
[2011/11/28 19:08:41 | 000,000,000 | -HSD | C] – C:\Boot
[2011/11/24 21:16:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/23 20:50:02 | 000,000,000 | —D | C] – C:\ProgramData\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application
[2011/11/23 20:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/23 20:34:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/11/23 20:33:46 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:33:46 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/11/23 20:33:45 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:33:45 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:33:45 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/23 20:33:45 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:24:34 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 20:24:34 | 008,792,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 20:24:34 | 007,042,880 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 20:24:34 | 001,452,648 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/23 20:24:34 | 000,174,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/23 20:24:34 | 000,029,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/11/23 20:24:33 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 20:24:33 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 20:24:33 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 20:24:33 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 20:24:33 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 20:24:33 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 20:24:33 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 20:24:33 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 20:24:33 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 20:24:33 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 20:24:33 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 20:24:33 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 20:24:33 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 20:24:33 | 001,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 20:24:33 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 20:24:33 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 20:24:33 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 20:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/11/23 20:23:27 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/11/23 20:23:08 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/23 15:59:51 | 000,000,000 | —D | C] – C:\Windows\ERDNT

========== Files - Modified Within 30 Days ==========

[2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000UA.job
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:42:11 | 000,729,756 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/22 15:42:11 | 000,630,488 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/22 15:42:11 | 000,111,572 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/22 15:38:17 | 000,000,653 | —- | M] () – C:\ProgramData\SHSupdates.xml
[2011/12/22 15:37:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/22 15:36:33 | 2090,135,551 | -HS- | M] () – C:\hiberfil.sys
[2011/12/20 16:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000Core.job
[2011/12/18 14:49:17 | 000,018,188 | —- | M] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | M] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | M] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/17 06:16:58 | 000,441,224 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 22:37:16 | 000,000,950 | —- | M] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/12/11 15:18:28 | 000,000,448 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Owner.job
[2011/12/10 13:12:26 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/09 15:27:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/03 16:12:07 | 000,001,945 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk

========== Files Created - No Company Name ==========

[2011/12/18 14:49:17 | 000,018,188 | —- | C] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | C] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | C] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/16 22:37:16 | 000,000,950 | —- | C] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/11/28 19:11:51 | 000,383,786 | RHS- | C] () – C:\bootmgr
[2011/11/23 22:09:25 | 000,001,945 | —- | C] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
[2011/11/20 18:56:02 | 000,822,916 | —- | C] () – C:\Users\Owner\AppData\Local\census.cache
[2011/11/20 18:55:53 | 000,112,588 | —- | C] () – C:\Users\Owner\AppData\Local\ars.cache
[2011/11/20 18:49:32 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/11/10 16:36:00 | 000,735,006 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/07 18:53:44 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 13:12:25 | 002,205,064 | —- | C] () – C:\ProgramData\shs_setup_4059-354328.exe
[2011/07/30 13:12:23 | 000,000,653 | —- | C] () – C:\ProgramData\SHSupdates.xml
[2011/07/29 19:38:38 | 001,896,720 | —- | C] () – C:\Users\Owner\AppData\Local\tmpIMG023.JPG
[2011/01/22 13:39:45 | 000,001,940 | —- | C] () – C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/12 03:58:23 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/07/15 17:45:05 | 000,007,597 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2010/07/05 11:57:43 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/07/05 11:57:42 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/07/05 11:57:42 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/07/05 11:57:42 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/07/05 11:57:42 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/07/05 11:57:42 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/07/05 11:57:42 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/07/05 11:57:42 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/07/05 11:57:42 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/07/05 11:57:42 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/07/05 11:57:42 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/07/05 11:57:42 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/07/05 11:53:19 | 000,000,079 | —- | C] () – C:\Windows\EPNX510.ini
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >

Extras.txt

OTL Extras logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – "%1" %*
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – "%1" %*
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – "%1" %*
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – "%1" %*
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – "%1" %*
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – "%1" %*
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{3C5E60F1-0821-4B07-97EA-84EB5A927CF6}" = MobileMe Control Panel
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"EPSON NX510 Series" = EPSON NX510 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3
"Rocketfish VF0650" = Rocketfish HD Webcam (1.00.06.00)
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33A783E8-DC11-427F-A56C-8ED43EEC0695}" = RPS CRT
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A1F0A1A-474C-4151-8534-5F61832D88CD}" = Comic Life
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{7FC8C210-A319-4835-A87D-B935EFB4C148}" = Microsoft Live Search Toolbar
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PUBLISHERR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PUBLISHERR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PUBLISHERR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PUBLISHERR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PUBLISHERR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0019-0000-0000-0000000FF1CE}" = Microsoft Office Publisher 2010
"{91140000-0019-0000-0000-0000000FF1CE}_Office14.PUBLISHERR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Bandwidth Monitor_is1" = Bandwidth Monitor
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"FinalVideoDownloader_is1" = Final Video Downloader 2011
"Free 3D Photo Maker_is1" = Free 3D Photo Maker version 2.0.6
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Video to JPG Converter_is1" = Free Video to JPG Converter version 1.8.7
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"LastFM_is1" = Last.fm 1.5.4.27091
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 8.0 (x86 en-GB)" = Mozilla Firefox 8.0 (x86 en-GB)
"NSS" = Norton Security Scan
"NST" = Norton Safe Web Lite
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PUBLISHERR" = Microsoft Publisher 2010
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"RadialpointClientGateway_is1" = Rogers Servicepoint Agent 3.7.44
"Rocketfish Live! Central" = Rocketfish Live! Central
"Rogers Self Help Software" = Rogers Self Help Software
"Rogers Update Manager" = Rogers Update Manager
"RSH Home Networking Wizard" = RSH Home Networking Wizard
"Trusted Software Assistant_is1" = File Type Assistant
"Uninstall_is1" = Uninstall 1.0.0.1
"WhatPulse" = WhatPulse [removed]
"WinLiveSuite" = Windows Live Essentials

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 22/12/2011 12:24:39 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4009

Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5007

Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5007

Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6006

Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6006

Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7004

Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7004

[ Hewlett-Packard Events ]
Error - 07/10/2011 5:38:12 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 07/10/2011 5:38:12 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 24/10/2011 3:55:40 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 18/11/2011 10:33:59 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 03/12/2011 11:14:02 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 03/12/2011 11:14:05 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 09/12/2011 4:49:39 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 09/12/2011 4:49:40 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 09/12/2011 4:49:41 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 09/12/2011 4:49:41 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =

[ System Events ]
Error - 17/12/2011 7:17:30 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 17/12/2011 6:28:25 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 18/12/2011 3:13:04 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 18/12/2011 7:50:12 PM | Computer Name = Owner-PC | Source = volsnap | ID = 393232
Description = The shadow copies of volume G: were aborted because volume G:, which
contains shadow copy storage for this shadow copy, was force dismounted.

Error - 18/12/2011 8:21:48 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 19/12/2011 2:00:55 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 19/12/2011 4:30:11 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 20/12/2011 4:12:16 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 21/12/2011 5:57:27 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2

Error - 22/12/2011 4:38:36 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2


< End of report >

Gmer

OTL logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/11/05 02:10:39 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
PRC - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
PRC - [2011/01/04 15:51:14 | 004,318,520 | —- | M] (Rogers) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
PRC - [2011/01/04 15:51:14 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
PRC - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010/10/27 21:21:54 | 001,155,072 | —- | M] (Last.fm) – C:\Program Files (x86)\Last.fm\LastFM.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
PRC - [2010/02/23 12:00:00 | 000,028,672 | —- | M] (Creative Technology Ltd.) – C:\Windows\V0650Mon.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/04/08 15:51:34 | 002,814,976 | —- | M] (WhatPulse.org) – C:\Program Files (x86)\WhatPulse\WhatPulse.exe
PRC - [2008/06/01 17:05:02 | 001,529,856 | —- | M] (Rokario Software) – C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/07 18:53:16 | 000,265,536 | —- | M] () – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/11/05 02:10:39 | 001,989,592 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
MOD - [2011/01/04 15:42:24 | 000,158,208 | —- | M] () – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\Windows7Features.dll
MOD - [2010/10/27 21:23:04 | 000,106,496 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll
MOD - [2010/10/27 21:22:52 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_messengernotify.dll
MOD - [2010/10/27 21:22:42 | 000,058,880 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_skypenotify.dll
MOD - [2010/10/27 21:22:08 | 000,147,456 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_madtranscode.dll
MOD - [2010/10/27 21:22:00 | 000,028,160 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_httpinput.dll
MOD - [2010/10/27 21:19:28 | 000,372,736 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll
MOD - [2010/10/27 21:19:06 | 000,025,088 | —- | M] () – C:\Program Files (x86)\Last.fm\breakpad.dll
MOD - [2010/10/27 21:18:50 | 000,180,224 | —- | M] () – C:\Program Files (x86)\Last.fm\Moose1.dll
MOD - [2010/10/27 21:18:34 | 000,540,672 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmTools1.dll
MOD - [2010/10/27 21:13:52 | 001,382,507 | —- | M] () – C:\Program Files (x86)\Last.fm\libfftw3f-3.dll
MOD - [2010/10/27 21:13:52 | 000,074,240 | —- | M] () – C:\Program Files (x86)\Last.fm\zlibwapi.dll
MOD - [2009/12/01 19:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2008/04/16 17:42:30 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtNetwork4.dll
MOD - [2008/04/16 17:42:16 | 000,524,288 | —- | M] () – C:\Program Files (x86)\Last.fm\QtSql4.dll
MOD - [2008/04/16 17:42:02 | 006,701,056 | —- | M] () – C:\Program Files (x86)\Last.fm\QtGui4.dll
MOD - [2008/04/16 17:36:38 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtXml4.dll
MOD - [2008/04/16 17:36:34 | 001,654,784 | —- | M] () – C:\Program Files (x86)\Last.fm\QtCore4.dll
MOD - [2008/04/02 14:26:50 | 000,233,472 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll
MOD - [2008/04/02 14:26:34 | 000,021,504 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll
MOD - [2008/04/02 14:26:28 | 000,135,168 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2011/04/08 16:09:28 | 000,290,816 | —- | M] (Puran Software) [Disabled | Stopped] – C:\Windows\SysNative\PuranDefragS.exe – (PuranDefrag)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe – (ServicepointService)
SRV - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe – (NSL)
SRV - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe – (BackupService)
SRV - [2010/06/03 14:46:36 | 000,163,840 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe – (RogersUpdateManager)
SRV - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe – (RogersSelfHelpService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/12/16 22:00:00 | 000,163,840 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE – (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,126,464 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE – (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/07/07 18:21:28 | 000,174,184 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/03/31 12:00:00 | 000,393,536 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0650Vid.sys – (V0650Vid)
DRV:64bit: - [2010/03/26 13:37:36 | 000,173,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/10/02 07:58:58 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 07:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/17 00:57:46 | 000,023,536 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms – (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
DRV:64bit: - [2009/08/20 19:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/05/06 15:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://hp.ca.msn.com/default.aspx
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 12 6E 58 55 1C CB 01 [binary data]
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4

========== FireFox ==========


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/07/05 21:32:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\FinalVideoDownloader\Firefox [2011/09/26 14:47:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/15 16:26:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/19 18:16:00 | 000,000,000 | —D | M]

[2011/11/15 16:27:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2011/12/02 19:36:52 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/17 20:37:14 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\[removed]
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 20:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/26 14:47:44 | 000,000,000 | —D | M] (FinalVideoDownloader plugin for Mozilla Firefox) – C:\PROGRAM FILES (X86)\FINALVIDEODOWNLOADER\FIREFOX
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W30WC1OY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 02:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:44:20 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/04 22:32:18 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:44:20 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/04 22:44:20 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/04 22:44:20 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Rogers Servicepoint Agent (Enabled) = C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.9_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe (Rokario Software)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF5ABC5E-3819-46FA-B907-6644B8D77739}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F14C9C70-7912-4006-82E7-648CDC421877}: DhcpNameServer = [removed]
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell - "" = AutoRun
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 16:04:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{91C8AE5A-BB9F-419A-B807-90D90A51D55D}
[2011/12/22 15:50:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E4B636FE-0D14-4091-BD72-BF178781D1F8}
[2011/12/21 17:00:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B0D7CAB2-283A-46FC-B63D-3CF4549811B5}
[2011/12/21 17:00:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{596D9425-13D5-4B80-BC07-478FA159BB03}
[2011/12/20 16:50:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{20C67B7F-D5C3-4EA0-B5D6-56D29ADA0C1E}
[2011/12/20 16:50:17 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DFA22BDD-7835-4B93-AAE2-78CA8DE57ACE}
[2011/12/19 15:37:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6B2D2CFB-E218-4509-8DBC-1C3F5E23DBBF}
[2011/12/19 15:37:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C0514324-FD0C-40D9-98C9-9F26F79F97C9}
[2011/12/19 01:16:31 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\testdisk-6.13
[2011/12/18 14:19:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{44BB564C-9A5D-4ECA-A491-598725543B8F}
[2011/12/18 14:19:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{787CE0ED-7694-486F-8B12-F6E856BE90BD}
[2011/12/17 23:59:01 | 000,847,872 | —- | C] (Western Digital) – C:\Users\Owner\Desktop\WinDlg.exe
[2011/12/17 18:10:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{90A5972C-7BB8-4434-BCF7-4992703AB95A}
[2011/12/17 18:10:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{11942ED9-762F-4B29-AA48-1E73D9174F6B}
[2011/12/16 23:55:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/16 23:55:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 23:55:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/16 23:55:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/16 23:55:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/16 23:55:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/16 23:55:56 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/16 23:55:56 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/16 23:55:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/16 23:55:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/16 23:55:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2011/12/16 19:55:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{89AD739B-048A-483E-B5A4-90EFDFEC221D}
[2011/12/16 19:55:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9F35A44D-7831-4E38-8B81-A379E2E589A7}
[2011/12/16 19:44:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/16 19:44:29 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/16 19:44:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/16 16:12:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{08E737A6-FF5D-4392-BC54-54B89DADB99B}
[2011/12/16 16:12:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{193BCD13-B7E1-417C-9436-9E9839830F18}
[2011/12/15 15:46:42 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{64FB69B7-74CC-47C3-BB08-4A4D1B53B257}
[2011/12/15 15:46:20 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{AD888F84-5AC8-4DAE-AE88-76DFAB16EDE3}
[2011/12/14 15:34:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{CE849C1F-5527-4043-994E-66FCC5453AF0}
[2011/12/14 15:33:48 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{51218CFE-F55F-4AF7-8A29-B66D2ECF2431}
[2011/12/13 13:12:44 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{10D6B9BA-5ABD-4595-ACF1-2BC1A952B2A7}
[2011/12/13 13:12:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{D4719874-5EF8-4ADA-BDE1-9DF14592C529}
[2011/12/12 16:42:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{78C8EADE-1861-4A4F-82FC-0D8EBE41CD10}
[2011/12/12 16:42:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1F5940F6-4833-47C0-A8D6-6F3710C13DA3}
[2011/12/11 15:22:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F17D7D39-E8EE-49AE-B1FB-CD16F135987E}
[2011/12/11 15:22:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{43592173-D04B-45A6-B9BA-F2940021C273}
[2011/12/10 13:17:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6139CE19-6638-48EC-82A4-DD09E4B9FDDE}
[2011/12/10 13:17:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{3DDFEF60-49CB-4902-82EA-851F00BCBB83}
[2011/12/09 15:46:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D11940F-25C7-4195-878D-C6D97EA34FAB}
[2011/12/09 15:46:09 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9212E1E8-EBE4-4CE6-9986-B98FC234CF22}
[2011/12/09 15:40:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 15:39:31 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 15:39:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/09 15:27:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/08 16:03:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DDAB35AE-CDDB-4EE2-9D37-01E8677CEAFC}
[2011/12/08 16:03:23 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E99F74B6-9F3D-4CD1-8691-8109D3FE1AB8}
[2011/12/07 17:06:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{14A84DDE-F7AE-418A-87DA-0A2F66E4C349}
[2011/12/07 17:05:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F4B6C955-2EC9-42DD-BFE7-F3E5C6919AFD}
[2011/12/06 15:41:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B95D42A0-65A3-4A1B-A3E1-8B9C28E3E627}
[2011/12/06 15:40:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B52DFCA2-286F-471E-9504-E75B5C7AFE7D}
[2011/12/05 15:18:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C7A225BB-8584-4747-AD7D-D57565502B8E}
[2011/12/05 15:17:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F0335E61-8562-4472-ACD3-0939C2E3147F}
[2011/12/04 11:09:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{2B18B578-FB1B-4873-9E52-F22E0EA27329}
[2011/12/04 11:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9FF0B248-7DB8-4BB0-9FD7-822D83D789F0}
[2011/12/03 22:21:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8AE60C4C-DE4D-4002-8B38-E6E858EE7699}
[2011/12/03 22:20:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8B161D07-75C5-4A71-AA10-8A9B8AD2359D}
[2011/12/03 10:20:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1FB7C86A-8AB1-46A8-A7CF-78B7058A8D94}
[2011/12/03 10:20:13 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1B136402-BF9E-44A0-ABE9-2B784578CAD6}
[2011/12/02 16:04:07 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/02 15:42:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D1A43B8-8A4E-4E52-9976-7FE2AC6425A2}
[2011/12/02 15:42:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{5A72F670-75B5-4A8C-A932-EA1DEB4CAB95}
[2011/12/01 16:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puran Defrag
[2011/12/01 16:25:40 | 001,417,216 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranFD.exe
[2011/12/01 16:25:40 | 000,290,816 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragS.exe
[2011/12/01 16:25:40 | 000,275,968 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDC.exe
[2011/12/01 16:25:40 | 000,270,336 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefrag.dll
[2011/12/01 16:25:40 | 000,130,048 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragBT.exe
[2011/12/01 16:25:40 | 000,000,000 | —D | C] – C:\Program Files\Puran Defrag
[2011/12/01 16:13:19 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B6323AF0-6488-4B51-9343-41EC1DF20D1A}
[2011/12/01 16:12:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7940265E-F90B-4E8B-B1A2-3EB5664144C1}
[2011/11/30 17:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/30 15:25:29 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{19C62BA7-FD7A-4102-9E86-50ECD7714AFD}
[2011/11/30 15:25:07 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B962C5FB-79F8-4B7D-B6C6-5EB38FC1495A}
[2011/11/29 13:11:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DB245045-2B52-4213-8524-A5092754DCDC}
[2011/11/29 13:10:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1E0B4E88-6799-4C13-B421-F31168D619DB}
[2011/11/28 19:08:41 | 000,000,000 | -HSD | C] – C:\Boot
[2011/11/24 21:16:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/23 20:50:02 | 000,000,000 | —D | C] – C:\ProgramData\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application
[2011/11/23 20:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/23 20:34:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/11/23 20:33:46 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:33:46 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/11/23 20:33:45 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:33:45 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:33:45 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/23 20:33:45 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:24:34 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 20:24:34 | 008,792,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 20:24:34 | 007,042,880 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 20:24:34 | 001,452,648 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/23 20:24:34 | 000,174,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/23 20:24:34 | 000,029,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/11/23 20:24:33 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 20:24:33 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 20:24:33 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 20:24:33 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 20:24:33 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 20:24:33 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 20:24:33 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 20:24:33 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 20:24:33 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 20:24:33 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 20:24:33 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 20:24:33 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 20:24:33 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 20:24:33 | 001,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 20:24:33 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 20:24:33 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 20:24:33 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 20:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/11/23 20:23:27 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/11/23 20:23:08 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/23 15:59:51 | 000,000,000 | —D | C] – C:\Windows\ERDNT

========== Files - Modified Within 30 Days ==========

[2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000UA.job
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:42:11 | 000,729,756 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/22 15:42:11 | 000,630,488 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/22 15:42:11 | 000,111,572 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/22 15:38:17 | 000,000,653 | —- | M] () – C:\ProgramData\SHSupdates.xml
[2011/12/22 15:37:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/22 15:36:33 | 2090,135,551 | -HS- | M] () – C:\hiberfil.sys
[2011/12/20 16:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000Core.job
[2011/12/18 14:49:17 | 000,018,188 | —- | M] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | M] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | M] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/17 06:16:58 | 000,441,224 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 22:37:16 | 000,000,950 | —- | M] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/12/11 15:18:28 | 000,000,448 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Owner.job
[2011/12/10 13:12:26 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/09 15:27:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/03 16:12:07 | 000,001,945 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk

========== Files Created - No Company Name ==========

[2011/12/18 14:49:17 | 000,018,188 | —- | C] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | C] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | C] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/16 22:37:16 | 000,000,950 | —- | C] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/11/28 19:11:51 | 000,383,786 | RHS- | C] () – C:\bootmgr
[2011/11/23 22:09:25 | 000,001,945 | —- | C] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
[2011/11/20 18:56:02 | 000,822,916 | —- | C] () – C:\Users\Owner\AppData\Local\census.cache
[2011/11/20 18:55:53 | 000,112,588 | —- | C] () – C:\Users\Owner\AppData\Local\ars.cache
[2011/11/20 18:49:32 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/11/10 16:36:00 | 000,735,006 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/07 18:53:44 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 13:12:25 | 002,205,064 | —- | C] () – C:\ProgramData\shs_setup_4059-354328.exe
[2011/07/30 13:12:23 | 000,000,653 | —- | C] () – C:\ProgramData\SHSupdates.xml
[2011/07/29 19:38:38 | 001,896,720 | —- | C] () – C:\Users\Owner\AppData\Local\tmpIMG023.JPG
[2011/01/22 13:39:45 | 000,001,940 | —- | C] () – C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/12 03:58:23 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/07/15 17:45:05 | 000,007,597 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2010/07/05 11:57:43 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/07/05 11:57:42 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/07/05 11:57:42 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/07/05 11:57:42 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/07/05 11:57:42 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/07/05 11:57:42 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/07/05 11:57:42 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/07/05 11:57:42 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/07/05 11:57:42 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/07/05 11:57:42 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/07/05 11:57:42 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/07/05 11:57:42 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/07/05 11:53:19 | 000,000,079 | —- | C] () – C:\Windows\EPNX510.ini
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >

aswMBR

aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-22 16:28:51
—————————–
16:28:51.643 OS Version: Windows x64 6.1.7601 Service Pack 1
16:28:51.643 Number of processors: 4 586 0x2502
16:28:51.643 ComputerName: OWNER-PC UserName: Owner
16:28:52.798 Initialize success
16:29:03.974 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:29:03.989 Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 8
16:29:04.005 Disk 0 MBR read successfully
16:29:04.005 Disk 0 MBR scan
16:29:04.005 Disk 0 Windows 7 default MBR code
16:29:04.005 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:29:04.020 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 942118 MB offset 206848
16:29:04.052 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 11649 MB offset 1929664512
16:29:04.052 Service scanning
16:29:04.473 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
16:29:05.066 Modules scanning
16:29:05.066 Disk 0 trace - called modules:
16:29:05.066 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
16:29:05.081 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007b63060]
16:29:05.081 3 CLASSPNP.SYS[fffff88001b6143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800789d050]
16:29:05.097 Scan finished successfully
16:29:29.417 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
16:29:29.417 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"
Some things to consider removing in addition to Radial Point.

Go to Start - Control Panel - Programs - Programs and Features, then click on each of the following programs, if they show there, and click "Uninstall/Change".

Rogers Servicepoint Agent 3.7.44
Pando Media Booster - Pando uses P2P (Peer-to-Peer) file swapping technology. Although they do say user's files and systems are not automatically included in the file swapping network, any file download using their services is. So uses your bandwidth to share, and so speed up, their file transfers. Which can benefit their paying customers at free customer's expense.
Puran Defrag Free Edition 7.3 - Defragging was helpful on older systems, like Windows 98, but since then a myth exists (and these vendors promote it) that defragging still "speeds" systems up. You have a 64 bit Windows 7 install, so uses a much more vibrant file system, and less need for things like defragging. And what looks like a terrabyte hard drive, so boocoo space available. Defrag maybe once every 6 months, perhaps, but no real benefit from anything more frequent, and may in fact cause file system corruption.
Norton Security Scan - Only scans, so no real benefit. I see you have used Eset Online Scan, which does remove the malware it finds.
Norton Safe Web Lite - Free software from Norton. Includes it's own Search bar, which it suggests aids in providing "safe searches". Pretty sure it also aids in Norton receiving compensation for some of the links it directs users to.

Of course in all of that, ServicePoint (RadialPoint) is the one you need to uninstall. Hopefully it hasn't corrupted your existing antivirus program, Security Essentials.

Make the necessary changes, reboot, then run and post another OTL OTL.Txt log please.
OTL.txt

OTL logfile created on: 22/12/2011 6:55:04 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 6.78 Gb Available Physical Memory | 85.49% Memory free
15.86 Gb Paging File | 14.62 Gb Available in Paging File | 92.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 836.01 Gb Free Space | 90.87% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS

Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/09/05 12:04:58 | 000,035,736 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\reader_sl.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
PRC - [2010/02/23 12:00:00 | 000,028,672 | —- | M] (Creative Technology Ltd.) – C:\Windows\V0650Mon.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/04/08 15:51:34 | 002,814,976 | —- | M] (WhatPulse.org) – C:\Program Files (x86)\WhatPulse\WhatPulse.exe
PRC - [2008/06/01 17:05:02 | 001,529,856 | —- | M] (Rokario Software) – C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe


========== Modules (No Company Name) ==========

MOD - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
MOD - [2009/12/01 19:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Running] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Stopped] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe – (BackupService)
SRV - [2010/06/03 14:46:36 | 000,163,840 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe – (RogersUpdateManager)
SRV - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe – (RogersSelfHelpService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/12/16 22:00:00 | 000,163,840 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE – (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,126,464 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE – (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/07/07 18:21:28 | 000,174,184 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/03/31 12:00:00 | 000,393,536 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0650Vid.sys – (V0650Vid)
DRV:64bit: - [2010/03/26 13:37:36 | 000,173,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:64bit: - [2009/10/02 07:58:58 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/09/17 07:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:64bit: - [2009/09/17 00:57:46 | 000,023,536 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms – (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
DRV:64bit: - [2009/08/20 19:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2008/05/06 15:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCON/4


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://hp.ca.msn.com/default.aspx
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 12 6E 58 55 1C CB 01 [binary data]
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\FinalVideoDownloader\Firefox [2011/09/26 14:47:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/15 16:26:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/19 18:16:00 | 000,000,000 | —D | M]

[2011/11/15 16:27:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2011/12/02 19:36:52 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/17 20:37:14 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\[removed]
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 20:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/26 14:47:44 | 000,000,000 | —D | M] (FinalVideoDownloader plugin for Mozilla Firefox) – C:\PROGRAM FILES (X86)\FINALVIDEODOWNLOADER\FIREFOX
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W30WC1OY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 02:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:44:20 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/04 22:32:18 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:44:20 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/04 22:44:20 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/04 22:44:20 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Rogers Servicepoint Agent (Enabled) = C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.9_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe (Rokario Software)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O8:64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF5ABC5E-3819-46FA-B907-6644B8D77739}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F14C9C70-7912-4006-82E7-648CDC421877}: DhcpNameServer = [removed]
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell - "" = AutoRun
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/22 16:28:41 | 001,917,952 | —- | C] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2011/12/22 16:04:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{91C8AE5A-BB9F-419A-B807-90D90A51D55D}
[2011/12/22 15:50:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E4B636FE-0D14-4091-BD72-BF178781D1F8}
[2011/12/21 17:00:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B0D7CAB2-283A-46FC-B63D-3CF4549811B5}
[2011/12/21 17:00:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{596D9425-13D5-4B80-BC07-478FA159BB03}
[2011/12/20 16:50:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{20C67B7F-D5C3-4EA0-B5D6-56D29ADA0C1E}
[2011/12/20 16:50:17 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DFA22BDD-7835-4B93-AAE2-78CA8DE57ACE}
[2011/12/19 15:37:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6B2D2CFB-E218-4509-8DBC-1C3F5E23DBBF}
[2011/12/19 15:37:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C0514324-FD0C-40D9-98C9-9F26F79F97C9}
[2011/12/19 01:16:31 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\testdisk-6.13
[2011/12/18 14:19:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{44BB564C-9A5D-4ECA-A491-598725543B8F}
[2011/12/18 14:19:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{787CE0ED-7694-486F-8B12-F6E856BE90BD}
[2011/12/17 23:59:01 | 000,847,872 | —- | C] (Western Digital) – C:\Users\Owner\Desktop\WinDlg.exe
[2011/12/17 18:10:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{90A5972C-7BB8-4434-BCF7-4992703AB95A}
[2011/12/17 18:10:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{11942ED9-762F-4B29-AA48-1E73D9174F6B}
[2011/12/16 23:55:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/16 23:55:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 23:55:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/16 23:55:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/16 23:55:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/16 23:55:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/16 23:55:56 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/16 23:55:56 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/16 23:55:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/16 23:55:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/16 23:55:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2011/12/16 19:55:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{89AD739B-048A-483E-B5A4-90EFDFEC221D}
[2011/12/16 19:55:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9F35A44D-7831-4E38-8B81-A379E2E589A7}
[2011/12/16 19:44:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/16 19:44:29 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/16 19:44:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/16 16:12:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{08E737A6-FF5D-4392-BC54-54B89DADB99B}
[2011/12/16 16:12:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{193BCD13-B7E1-417C-9436-9E9839830F18}
[2011/12/15 15:46:42 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{64FB69B7-74CC-47C3-BB08-4A4D1B53B257}
[2011/12/15 15:46:20 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{AD888F84-5AC8-4DAE-AE88-76DFAB16EDE3}
[2011/12/14 15:34:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{CE849C1F-5527-4043-994E-66FCC5453AF0}
[2011/12/14 15:33:48 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{51218CFE-F55F-4AF7-8A29-B66D2ECF2431}
[2011/12/13 13:12:44 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{10D6B9BA-5ABD-4595-ACF1-2BC1A952B2A7}
[2011/12/13 13:12:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{D4719874-5EF8-4ADA-BDE1-9DF14592C529}
[2011/12/12 16:42:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{78C8EADE-1861-4A4F-82FC-0D8EBE41CD10}
[2011/12/12 16:42:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1F5940F6-4833-47C0-A8D6-6F3710C13DA3}
[2011/12/11 15:22:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F17D7D39-E8EE-49AE-B1FB-CD16F135987E}
[2011/12/11 15:22:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{43592173-D04B-45A6-B9BA-F2940021C273}
[2011/12/10 13:17:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6139CE19-6638-48EC-82A4-DD09E4B9FDDE}
[2011/12/10 13:17:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{3DDFEF60-49CB-4902-82EA-851F00BCBB83}
[2011/12/09 15:46:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D11940F-25C7-4195-878D-C6D97EA34FAB}
[2011/12/09 15:46:09 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9212E1E8-EBE4-4CE6-9986-B98FC234CF22}
[2011/12/09 15:40:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 15:39:31 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 15:39:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/09 15:27:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/08 16:03:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DDAB35AE-CDDB-4EE2-9D37-01E8677CEAFC}
[2011/12/08 16:03:23 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E99F74B6-9F3D-4CD1-8691-8109D3FE1AB8}
[2011/12/07 17:06:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{14A84DDE-F7AE-418A-87DA-0A2F66E4C349}
[2011/12/07 17:05:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F4B6C955-2EC9-42DD-BFE7-F3E5C6919AFD}
[2011/12/06 15:41:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B95D42A0-65A3-4A1B-A3E1-8B9C28E3E627}
[2011/12/06 15:40:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B52DFCA2-286F-471E-9504-E75B5C7AFE7D}
[2011/12/05 15:18:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C7A225BB-8584-4747-AD7D-D57565502B8E}
[2011/12/05 15:17:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F0335E61-8562-4472-ACD3-0939C2E3147F}
[2011/12/04 11:09:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{2B18B578-FB1B-4873-9E52-F22E0EA27329}
[2011/12/04 11:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9FF0B248-7DB8-4BB0-9FD7-822D83D789F0}
[2011/12/03 22:21:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8AE60C4C-DE4D-4002-8B38-E6E858EE7699}
[2011/12/03 22:20:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8B161D07-75C5-4A71-AA10-8A9B8AD2359D}
[2011/12/03 10:20:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1FB7C86A-8AB1-46A8-A7CF-78B7058A8D94}
[2011/12/03 10:20:13 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1B136402-BF9E-44A0-ABE9-2B784578CAD6}
[2011/12/02 16:04:07 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/02 15:42:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D1A43B8-8A4E-4E52-9976-7FE2AC6425A2}
[2011/12/02 15:42:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{5A72F670-75B5-4A8C-A932-EA1DEB4CAB95}
[2011/12/01 16:13:19 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B6323AF0-6488-4B51-9343-41EC1DF20D1A}
[2011/12/01 16:12:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7940265E-F90B-4E8B-B1A2-3EB5664144C1}
[2011/11/30 17:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/30 15:25:29 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{19C62BA7-FD7A-4102-9E86-50ECD7714AFD}
[2011/11/30 15:25:07 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B962C5FB-79F8-4B7D-B6C6-5EB38FC1495A}
[2011/11/29 13:11:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DB245045-2B52-4213-8524-A5092754DCDC}
[2011/11/29 13:10:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1E0B4E88-6799-4C13-B421-F31168D619DB}
[2011/11/28 19:08:41 | 000,000,000 | -HSD | C] – C:\Boot
[2011/11/24 21:16:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/23 20:50:02 | 000,000,000 | —D | C] – C:\ProgramData\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application
[2011/11/23 20:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/23 20:34:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/11/23 20:33:46 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:33:46 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/11/23 20:33:45 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:33:45 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:33:45 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/23 20:33:45 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:24:34 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 20:24:34 | 008,792,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 20:24:34 | 007,042,880 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 20:24:34 | 001,452,648 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/23 20:24:34 | 000,174,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/23 20:24:34 | 000,029,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/11/23 20:24:33 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 20:24:33 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 20:24:33 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 20:24:33 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 20:24:33 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 20:24:33 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 20:24:33 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 20:24:33 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 20:24:33 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 20:24:33 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 20:24:33 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 20:24:33 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 20:24:33 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 20:24:33 | 001,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 20:24:33 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 20:24:33 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 20:24:33 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 20:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/11/23 20:23:27 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/11/23 20:23:08 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/23 15:59:51 | 000,000,000 | —D | C] – C:\Windows\ERDNT

========== Files - Modified Within 30 Days ==========

[2011/12/22 18:53:37 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/22 18:51:59 | 2090,135,551 | -HS- | M] () – C:\hiberfil.sys
[2011/12/22 17:51:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000UA.job
[2011/12/22 16:57:41 | 000,729,756 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/22 16:57:41 | 000,630,488 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/22 16:57:41 | 000,111,572 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/22 16:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000Core.job
[2011/12/22 16:29:29 | 000,000,512 | —- | M] () – C:\Users\Owner\Desktop\MBR.dat
[2011/12/22 16:28:43 | 001,917,952 | —- | M] (AVAST Software) – C:\Users\Owner\Desktop\aswMBR.exe
[2011/12/22 16:10:51 | 000,302,592 | —- | M] () – C:\Users\Owner\Desktop\Gmer.exe
[2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:38:17 | 000,000,653 | —- | M] () – C:\ProgramData\SHSupdates.xml
[2011/12/18 14:49:17 | 000,018,188 | —- | M] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | M] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | M] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/17 06:16:58 | 000,441,224 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 22:37:16 | 000,000,950 | —- | M] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/12/10 13:12:26 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/09 15:27:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/03 16:12:07 | 000,001,945 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk

========== Files Created - No Company Name ==========

[2011/12/22 16:29:29 | 000,000,512 | —- | C] () – C:\Users\Owner\Desktop\MBR.dat
[2011/12/22 16:10:59 | 000,302,592 | —- | C] () – C:\Users\Owner\Desktop\Gmer.exe
[2011/12/18 14:49:17 | 000,018,188 | —- | C] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | C] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | C] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/16 22:37:16 | 000,000,950 | —- | C] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/11/28 19:11:51 | 000,383,786 | RHS- | C] () – C:\bootmgr
[2011/11/23 22:09:25 | 000,001,945 | —- | C] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
[2011/11/20 18:56:02 | 000,822,916 | —- | C] () – C:\Users\Owner\AppData\Local\census.cache
[2011/11/20 18:55:53 | 000,112,588 | —- | C] () – C:\Users\Owner\AppData\Local\ars.cache
[2011/11/20 18:49:32 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/11/10 16:36:00 | 000,735,006 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/07 18:53:44 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 13:12:25 | 002,205,064 | —- | C] () – C:\ProgramData\shs_setup_4059-354328.exe
[2011/07/30 13:12:23 | 000,000,653 | —- | C] () – C:\ProgramData\SHSupdates.xml
[2011/07/29 19:38:38 | 001,896,720 | —- | C] () – C:\Users\Owner\AppData\Local\tmpIMG023.JPG
[2011/01/22 13:39:45 | 000,001,940 | —- | C] () – C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/12 03:58:23 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/07/15 17:45:05 | 000,007,597 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2010/07/05 11:57:43 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/07/05 11:57:42 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/07/05 11:57:42 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/07/05 11:57:42 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/07/05 11:57:42 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/07/05 11:57:42 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/07/05 11:57:42 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/07/05 11:57:42 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/07/05 11:57:42 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/07/05 11:57:42 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/07/05 11:57:42 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/07/05 11:57:42 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/07/05 11:53:19 | 000,000,079 | —- | C] () – C:\Windows\EPNX510.ini
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat

< End of report >


I'm very rarely getting the "computer failing to start." message now
However, my computer often spends 5+ minutes in a black screen before even sending me to the logon screen.
Looks okay so far. RadialPoint seems to still show In Google chrome there. I am not very familiar with this browser - it doesn't use standard methods like most others, so is a bit tougher to get a handle on. For now, I am pasting what I found on the web:

1) Type chrome://extensions/ in the omnibar
2) locate the extension you want to remove (in this case, Servicepoint)
3) click the (uninstall) buttton

From what I understand, the "omnibar" is just the address bar at the top.

———–

Let's do some standard scans now. They may shed some light on other issues, as well as pick up any malware that is lingering. Then re-assess your startup lag. You may have to uninstall and reinstall Security essentials - RadialPoint may have damaged it. But first do these scans.


Be sure to continue to temporarily disable any protective software when running the scan tools we use here.


Open and update Malwarebytes.

* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform quick scan", then click Scan.
* The scan may take some time to finish,so please be patient.
* When the scan is complete, click OK, then Show Results to view the results.
* Make sure that everything is checked, and click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
* The log is automatically saved by Malwarebytes and can be viewed by clicking the Logs tab in Malwarebytes.
* Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.

—————

Disable your antivirus program and click here and download the esetsmartinstaller_enu.exe Eset installer. Then click that file to run the scanner (right click/Run as administrator).

If you accept the Terms of Use, check the box and click Start. It will take a couple minutes for the scanner to get ready. When the Computer scan settings display shows, check the following boxes:

Remove found threats
Scan unwanted applications


Next to "Current scan targets: Operating memory, Local drives", click the "Change" word. Make sure you place a check next to all disk drives, including any external drives that are attached (no need to check off the floppy or DVD/CD-Rom drives).

Then click the Advanced option, the place a check next to the following (if it is not already checked):

Enable Anti-Stealth technology

Click Start. This scan may take a while, so please be patient.

If infection is found, at the end of the scan click "List of found threats".

In that display, at the bottom, select the option to save the results as a text file, and save that to your desktop. Post that back here please.

Post that log and the Malwarebytes log please.
MalwareBytes
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 8391

Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421

22/12/2011 7:31:29 PM
mbam-log-2011-12-22 (19-31-29).txt

Scan type: Quick scan
Objects scanned: 202111
Time elapsed: 1 minute(s), 39 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

The ESET Scanner found nothing.

Oh, and when I went to Google Chrome, ServicePoint wasn't there as an extension.
I don't mean to keep harping on Rogers software, but would like to check one file. In addition, please go to Programs and Features, and uninstall Microsoft Security Essentials, under the assumption RadialPoint did corrupt it. Reboot, reinstall (download here), reboot, and check for any change in startup time please.


Please locate the following hilighted file(s), zip a copy of it, and send it to jintan AT malwarecrypt.com as an attachment. Please place "Submitted Files - ClementZ/wtt/rogers" as the email Subject.

C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
K, I reinstalled MSE, and computer is starting up slightly more quickly. Now, how do I create .zip files? I can turn it into a .rar file, would that do ? Or must it be a .zip file?
I received the file, thanks. Looks like it does things like home page and Hosts file checks, and some network checking functions. No security parts in it, so unrelated to RadialPoint. Not much else I can see to suggest here, but before we do some final cleaning up on your system, anything else I might help with?
So, aside from maybe reinstalling the OS, there's nothing anyone can do to speed up start-up times? Oh And, another problem. HP Startup assistant tries to update/install a new version whenever I startup the computer. It always fails. I'm wondering if there's anyway to fix this, or if the program is even all that important.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI