OTL.txt
OTL logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/11/05 02:10:39 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
PRC - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
PRC - [2011/01/04 15:51:14 | 004,318,520 | —- | M] (Rogers) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
PRC - [2011/01/04 15:51:14 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
PRC - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010/10/27 21:21:54 | 001,155,072 | —- | M] (Last.fm) – C:\Program Files (x86)\Last.fm\LastFM.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
PRC - [2010/02/23 12:00:00 | 000,028,672 | —- | M] (Creative Technology Ltd.) – C:\Windows\V0650Mon.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/04/08 15:51:34 | 002,814,976 | —- | M] (WhatPulse.org) – C:\Program Files (x86)\WhatPulse\WhatPulse.exe
PRC - [2008/06/01 17:05:02 | 001,529,856 | —- | M] (Rokario Software) – C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/07 18:53:16 | 000,265,536 | —- | M] () – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/11/05 02:10:39 | 001,989,592 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
MOD - [2011/01/04 15:42:24 | 000,158,208 | —- | M] () – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\Windows7Features.dll
MOD - [2010/10/27 21:23:04 | 000,106,496 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll
MOD - [2010/10/27 21:22:52 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_messengernotify.dll
MOD - [2010/10/27 21:22:42 | 000,058,880 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_skypenotify.dll
MOD - [2010/10/27 21:22:08 | 000,147,456 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_madtranscode.dll
MOD - [2010/10/27 21:22:00 | 000,028,160 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_httpinput.dll
MOD - [2010/10/27 21:19:28 | 000,372,736 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll
MOD - [2010/10/27 21:19:06 | 000,025,088 | —- | M] () – C:\Program Files (x86)\Last.fm\breakpad.dll
MOD - [2010/10/27 21:18:50 | 000,180,224 | —- | M] () – C:\Program Files (x86)\Last.fm\Moose1.dll
MOD - [2010/10/27 21:18:34 | 000,540,672 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmTools1.dll
MOD - [2010/10/27 21:13:52 | 001,382,507 | —- | M] () – C:\Program Files (x86)\Last.fm\libfftw3f-3.dll
MOD - [2010/10/27 21:13:52 | 000,074,240 | —- | M] () – C:\Program Files (x86)\Last.fm\zlibwapi.dll
MOD - [2009/12/01 19:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2008/04/16 17:42:30 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtNetwork4.dll
MOD - [2008/04/16 17:42:16 | 000,524,288 | —- | M] () – C:\Program Files (x86)\Last.fm\QtSql4.dll
MOD - [2008/04/16 17:42:02 | 006,701,056 | —- | M] () – C:\Program Files (x86)\Last.fm\QtGui4.dll
MOD - [2008/04/16 17:36:38 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtXml4.dll
MOD - [2008/04/16 17:36:34 | 001,654,784 | —- | M] () – C:\Program Files (x86)\Last.fm\QtCore4.dll
MOD - [2008/04/02 14:26:50 | 000,233,472 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll
MOD - [2008/04/02 14:26:34 | 000,021,504 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll
MOD - [2008/04/02 14:26:28 | 000,135,168 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:
64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:
64bit: - [2011/04/08 16:09:28 | 000,290,816 | —- | M] (Puran Software) [Disabled | Stopped] – C:\Windows\SysNative\PuranDefragS.exe – (PuranDefrag)
SRV:
64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe – (ServicepointService)
SRV - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe – (NSL)
SRV - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe – (BackupService)
SRV - [2010/06/03 14:46:36 | 000,163,840 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe – (RogersUpdateManager)
SRV - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe – (RogersSelfHelpService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/12/16 22:00:00 | 000,163,840 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE – (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,126,464 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE – (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/07/07 18:21:28 | 000,174,184 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:
64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:
64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:
64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:
64bit: - [2010/03/31 12:00:00 | 000,393,536 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0650Vid.sys – (V0650Vid)
DRV:
64bit: - [2010/03/26 13:37:36 | 000,173,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:
64bit: - [2009/10/02 07:58:58 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:
64bit: - [2009/09/17 07:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:
64bit: - [2009/09/17 00:57:46 | 000,023,536 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms – (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
DRV:
64bit: - [2009/08/20 19:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:
64bit: - [2008/05/06 15:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:
64bit: - [2007/05/14 16:06:18 | 000,027,520 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://hp.ca.msn.com/default.aspx
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 12 6E 58 55 1C CB 01 [binary data]
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/07/05 21:32:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\FinalVideoDownloader\Firefox [2011/09/26 14:47:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/15 16:26:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/19 18:16:00 | 000,000,000 | —D | M]
[2011/11/15 16:27:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2011/12/02 19:36:52 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/17 20:37:14 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\[removed]
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 20:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/26 14:47:44 | 000,000,000 | —D | M] (FinalVideoDownloader plugin for Mozilla Firefox) – C:\PROGRAM FILES (X86)\FINALVIDEODOWNLOADER\FIREFOX
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W30WC1OY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 02:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:44:20 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/04 22:32:18 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:44:20 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/04 22:44:20 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/04 22:44:20 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Rogers Servicepoint Agent (Enabled) = C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.9_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe (Rokario Software)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:
64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:
64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF5ABC5E-3819-46FA-B907-6644B8D77739}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F14C9C70-7912-4006-82E7-648CDC421877}: DhcpNameServer = [removed]
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell - "" = AutoRun
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/22 16:04:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{91C8AE5A-BB9F-419A-B807-90D90A51D55D}
[2011/12/22 15:50:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E4B636FE-0D14-4091-BD72-BF178781D1F8}
[2011/12/21 17:00:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B0D7CAB2-283A-46FC-B63D-3CF4549811B5}
[2011/12/21 17:00:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{596D9425-13D5-4B80-BC07-478FA159BB03}
[2011/12/20 16:50:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{20C67B7F-D5C3-4EA0-B5D6-56D29ADA0C1E}
[2011/12/20 16:50:17 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DFA22BDD-7835-4B93-AAE2-78CA8DE57ACE}
[2011/12/19 15:37:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6B2D2CFB-E218-4509-8DBC-1C3F5E23DBBF}
[2011/12/19 15:37:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C0514324-FD0C-40D9-98C9-9F26F79F97C9}
[2011/12/19 01:16:31 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\testdisk-6.13
[2011/12/18 14:19:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{44BB564C-9A5D-4ECA-A491-598725543B8F}
[2011/12/18 14:19:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{787CE0ED-7694-486F-8B12-F6E856BE90BD}
[2011/12/17 23:59:01 | 000,847,872 | —- | C] (Western Digital) – C:\Users\Owner\Desktop\WinDlg.exe
[2011/12/17 18:10:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{90A5972C-7BB8-4434-BCF7-4992703AB95A}
[2011/12/17 18:10:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{11942ED9-762F-4B29-AA48-1E73D9174F6B}
[2011/12/16 23:55:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/16 23:55:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 23:55:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/16 23:55:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/16 23:55:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/16 23:55:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/16 23:55:56 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/16 23:55:56 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/16 23:55:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/16 23:55:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/16 23:55:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2011/12/16 19:55:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{89AD739B-048A-483E-B5A4-90EFDFEC221D}
[2011/12/16 19:55:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9F35A44D-7831-4E38-8B81-A379E2E589A7}
[2011/12/16 19:44:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/16 19:44:29 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/16 19:44:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/16 16:12:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{08E737A6-FF5D-4392-BC54-54B89DADB99B}
[2011/12/16 16:12:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{193BCD13-B7E1-417C-9436-9E9839830F18}
[2011/12/15 15:46:42 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{64FB69B7-74CC-47C3-BB08-4A4D1B53B257}
[2011/12/15 15:46:20 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{AD888F84-5AC8-4DAE-AE88-76DFAB16EDE3}
[2011/12/14 15:34:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{CE849C1F-5527-4043-994E-66FCC5453AF0}
[2011/12/14 15:33:48 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{51218CFE-F55F-4AF7-8A29-B66D2ECF2431}
[2011/12/13 13:12:44 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{10D6B9BA-5ABD-4595-ACF1-2BC1A952B2A7}
[2011/12/13 13:12:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{D4719874-5EF8-4ADA-BDE1-9DF14592C529}
[2011/12/12 16:42:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{78C8EADE-1861-4A4F-82FC-0D8EBE41CD10}
[2011/12/12 16:42:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1F5940F6-4833-47C0-A8D6-6F3710C13DA3}
[2011/12/11 15:22:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F17D7D39-E8EE-49AE-B1FB-CD16F135987E}
[2011/12/11 15:22:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{43592173-D04B-45A6-B9BA-F2940021C273}
[2011/12/10 13:17:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6139CE19-6638-48EC-82A4-DD09E4B9FDDE}
[2011/12/10 13:17:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{3DDFEF60-49CB-4902-82EA-851F00BCBB83}
[2011/12/09 15:46:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D11940F-25C7-4195-878D-C6D97EA34FAB}
[2011/12/09 15:46:09 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9212E1E8-EBE4-4CE6-9986-B98FC234CF22}
[2011/12/09 15:40:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 15:39:31 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 15:39:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/09 15:27:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/08 16:03:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DDAB35AE-CDDB-4EE2-9D37-01E8677CEAFC}
[2011/12/08 16:03:23 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E99F74B6-9F3D-4CD1-8691-8109D3FE1AB8}
[2011/12/07 17:06:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{14A84DDE-F7AE-418A-87DA-0A2F66E4C349}
[2011/12/07 17:05:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F4B6C955-2EC9-42DD-BFE7-F3E5C6919AFD}
[2011/12/06 15:41:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B95D42A0-65A3-4A1B-A3E1-8B9C28E3E627}
[2011/12/06 15:40:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B52DFCA2-286F-471E-9504-E75B5C7AFE7D}
[2011/12/05 15:18:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C7A225BB-8584-4747-AD7D-D57565502B8E}
[2011/12/05 15:17:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F0335E61-8562-4472-ACD3-0939C2E3147F}
[2011/12/04 11:09:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{2B18B578-FB1B-4873-9E52-F22E0EA27329}
[2011/12/04 11:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9FF0B248-7DB8-4BB0-9FD7-822D83D789F0}
[2011/12/03 22:21:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8AE60C4C-DE4D-4002-8B38-E6E858EE7699}
[2011/12/03 22:20:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8B161D07-75C5-4A71-AA10-8A9B8AD2359D}
[2011/12/03 10:20:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1FB7C86A-8AB1-46A8-A7CF-78B7058A8D94}
[2011/12/03 10:20:13 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1B136402-BF9E-44A0-ABE9-2B784578CAD6}
[2011/12/02 16:04:07 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/02 15:42:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D1A43B8-8A4E-4E52-9976-7FE2AC6425A2}
[2011/12/02 15:42:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{5A72F670-75B5-4A8C-A932-EA1DEB4CAB95}
[2011/12/01 16:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puran Defrag
[2011/12/01 16:25:40 | 001,417,216 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranFD.exe
[2011/12/01 16:25:40 | 000,290,816 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragS.exe
[2011/12/01 16:25:40 | 000,275,968 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDC.exe
[2011/12/01 16:25:40 | 000,270,336 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefrag.dll
[2011/12/01 16:25:40 | 000,130,048 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragBT.exe
[2011/12/01 16:25:40 | 000,000,000 | —D | C] – C:\Program Files\Puran Defrag
[2011/12/01 16:13:19 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B6323AF0-6488-4B51-9343-41EC1DF20D1A}
[2011/12/01 16:12:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7940265E-F90B-4E8B-B1A2-3EB5664144C1}
[2011/11/30 17:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/30 15:25:29 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{19C62BA7-FD7A-4102-9E86-50ECD7714AFD}
[2011/11/30 15:25:07 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B962C5FB-79F8-4B7D-B6C6-5EB38FC1495A}
[2011/11/29 13:11:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DB245045-2B52-4213-8524-A5092754DCDC}
[2011/11/29 13:10:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1E0B4E88-6799-4C13-B421-F31168D619DB}
[2011/11/28 19:08:41 | 000,000,000 | -HSD | C] – C:\Boot
[2011/11/24 21:16:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/23 20:50:02 | 000,000,000 | —D | C] – C:\ProgramData\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application
[2011/11/23 20:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/23 20:34:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/11/23 20:33:46 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:33:46 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/11/23 20:33:45 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:33:45 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:33:45 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/23 20:33:45 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:24:34 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 20:24:34 | 008,792,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 20:24:34 | 007,042,880 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 20:24:34 | 001,452,648 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/23 20:24:34 | 000,174,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/23 20:24:34 | 000,029,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/11/23 20:24:33 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 20:24:33 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 20:24:33 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 20:24:33 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 20:24:33 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 20:24:33 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 20:24:33 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 20:24:33 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 20:24:33 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 20:24:33 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 20:24:33 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 20:24:33 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 20:24:33 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 20:24:33 | 001,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 20:24:33 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 20:24:33 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 20:24:33 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 20:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/11/23 20:23:27 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/11/23 20:23:08 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/23 15:59:51 | 000,000,000 | —D | C] – C:\Windows\ERDNT
========== Files - Modified Within 30 Days ==========
[2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000UA.job
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:42:11 | 000,729,756 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/22 15:42:11 | 000,630,488 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/22 15:42:11 | 000,111,572 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/22 15:38:17 | 000,000,653 | —- | M] () – C:\ProgramData\SHSupdates.xml
[2011/12/22 15:37:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/22 15:36:33 | 2090,135,551 | -HS- | M] () – C:\hiberfil.sys
[2011/12/20 16:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000Core.job
[2011/12/18 14:49:17 | 000,018,188 | —- | M] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | M] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | M] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/17 06:16:58 | 000,441,224 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 22:37:16 | 000,000,950 | —- | M] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/12/11 15:18:28 | 000,000,448 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Owner.job
[2011/12/10 13:12:26 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/09 15:27:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/03 16:12:07 | 000,001,945 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
========== Files Created - No Company Name ==========
[2011/12/18 14:49:17 | 000,018,188 | —- | C] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | C] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | C] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/16 22:37:16 | 000,000,950 | —- | C] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/11/28 19:11:51 | 000,383,786 | RHS- | C] () – C:\bootmgr
[2011/11/23 22:09:25 | 000,001,945 | —- | C] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
[2011/11/20 18:56:02 | 000,822,916 | —- | C] () – C:\Users\Owner\AppData\Local\census.cache
[2011/11/20 18:55:53 | 000,112,588 | —- | C] () – C:\Users\Owner\AppData\Local\ars.cache
[2011/11/20 18:49:32 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/11/10 16:36:00 | 000,735,006 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/07 18:53:44 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 13:12:25 | 002,205,064 | —- | C] () – C:\ProgramData\shs_setup_4059-354328.exe
[2011/07/30 13:12:23 | 000,000,653 | —- | C] () – C:\ProgramData\SHSupdates.xml
[2011/07/29 19:38:38 | 001,896,720 | —- | C] () – C:\Users\Owner\AppData\Local\tmpIMG023.JPG
[2011/01/22 13:39:45 | 000,001,940 | —- | C] () – C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/12 03:58:23 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/07/15 17:45:05 | 000,007,597 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2010/07/05 11:57:43 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/07/05 11:57:42 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/07/05 11:57:42 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/07/05 11:57:42 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/07/05 11:57:42 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/07/05 11:57:42 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/07/05 11:57:42 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/07/05 11:57:42 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/07/05 11:57:42 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/07/05 11:57:42 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/07/05 11:57:42 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/07/05 11:57:42 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/07/05 11:53:19 | 000,000,079 | —- | C] () – C:\Windows\EPNX510.ini
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
Extras.txt
OTL Extras logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_USERS\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – "%1" %*
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – "%1" %*
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – "%1" %*
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – "%1" %*
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – "%1" %*
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – "%1" %*
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – "%1" %*
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC2
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1FB31F44-D4D0-4D76-944A-A1A5D79FD321}" = Windows Live Family Safety
"{3C5E60F1-0821-4B07-97EA-84EB5A927CF6}" = MobileMe Control Panel
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6CFB1B20-ECAE-488F-9FFB-6AD420882E71}" = iTunes
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.79
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{CEA21F20-DBF4-464C-8B81-28B8508AFDDD}" = Windows Live Family Safety
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"EPSON NX510 Series" = EPSON NX510 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"PC-Doctor for Windows" = Hardware Diagnostic Tools
"Puran Defrag Free Edition_is1" = Puran Defrag Free Edition 7.3
"Rocketfish VF0650" = Rocketfish HD Webcam (1.00.06.00)
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 29
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33A783E8-DC11-427F-A56C-8ED43EEC0695}" = RPS CRT
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = Epson Event Manager
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A1F0A1A-474C-4151-8534-5F61832D88CD}" = Comic Life
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7C5B4583-7CBF-4289-B195-03B553959DEA}" = VoiceOver Kit
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{7FC8C210-A319-4835-A87D-B935EFB4C148}" = Microsoft Live Search Toolbar
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PUBLISHERR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PUBLISHERR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.SingleImage_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PUBLISHERR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PUBLISHERR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.SingleImage_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010
"{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PUBLISHERR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.SingleImage_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PUBLISHERR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.SingleImage_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.SingleImage_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{91140000-0019-0000-0000-0000000FF1CE}" = Microsoft Office Publisher 2010
"{91140000-0019-0000-0000-0000000FF1CE}_Office14.PUBLISHERR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}" = Microsoft Search Enhancement Pack
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B60DCA15-56A3-4D2D-8747-22CF7D7B588B}" = HP Support Assistant
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B9A03B7B-E0FF-4FB3-BA83-762E58A1B0AA}" = HP Support Information
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C611CF88-969D-43E6-A877-D6D6439DD081}" = HP Remote Solution
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Bandwidth Monitor_is1" = Bandwidth Monitor
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"FinalVideoDownloader_is1" = Final Video Downloader 2011
"Free 3D Photo Maker_is1" = Free 3D Photo Maker version 2.0.6
"Free Audio CD Burner_is1" = Free Audio CD Burner version 1.4.7
"Free Video to JPG Converter_is1" = Free Video to JPG Converter version 1.8.7
"HP Remote Solution" = HP Remote Solution
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"LastFM_is1" = Last.fm 1.5.4.27091
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 8.0 (x86 en-GB)" = Mozilla Firefox 8.0 (x86 en-GB)
"NSS" = Norton Security Scan
"NST" = Norton Safe Web Lite
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PUBLISHERR" = Microsoft Publisher 2010
"Office14.SingleImage" = Microsoft Office Home and Student 2010
"RadialpointClientGateway_is1" = Rogers Servicepoint Agent 3.7.44
"Rocketfish Live! Central" = Rocketfish Live! Central
"Rogers Self Help Software" = Rogers Self Help Software
"Rogers Update Manager" = Rogers Update Manager
"RSH Home Networking Wizard" = RSH Home Networking Wizard
"Trusted Software Assistant_is1" = File Type Assistant
"Uninstall_is1" = Uninstall 1.0.0.1
"WhatPulse" = WhatPulse [removed]
"WinLiveSuite" = Windows Live Essentials
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 22/12/2011 12:24:39 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4009
Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 5007
Error - 22/12/2011 12:24:40 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5007
Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6006
Error - 22/12/2011 12:24:41 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6006
Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 7004
Error - 22/12/2011 12:24:42 AM | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 7004
[ Hewlett-Packard Events ]
Error - 07/10/2011 5:38:12 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 07/10/2011 5:38:12 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 24/10/2011 3:55:40 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 18/11/2011 10:33:59 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description = en-CA Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)
at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)
at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()
Error - 03/12/2011 11:14:02 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 03/12/2011 11:14:05 AM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 09/12/2011 4:49:39 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 09/12/2011 4:49:40 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 09/12/2011 4:49:41 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
Error - 09/12/2011 4:49:41 PM | Computer Name = Owner-PC | Source = Hewlett-Packard | ID = 0
Description =
[ System Events ]
Error - 17/12/2011 7:17:30 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 17/12/2011 6:28:25 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 18/12/2011 3:13:04 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 18/12/2011 7:50:12 PM | Computer Name = Owner-PC | Source = volsnap | ID = 393232
Description = The shadow copies of volume G: were aborted because volume G:, which
contains shadow copy storage for this shadow copy, was force dismounted.
Error - 18/12/2011 8:21:48 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 19/12/2011 2:00:55 AM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 19/12/2011 4:30:11 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 20/12/2011 4:12:16 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 21/12/2011 5:57:27 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
Error - 22/12/2011 4:38:36 PM | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7023
Description = The Superfetch service terminated with the following error: %%2
< End of report >
Gmer
OTL logfile created on: 22/12/2011 4:06:06 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 6.35 Gb Available Physical Memory | 80.12% Memory free
15.86 Gb Paging File | 14.14 Gb Available in Paging File | 89.20% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 920.04 Gb Total Space | 835.90 Gb Free Space | 90.86% Space Free | Partition Type: NTFS
Drive D: | 11.38 Gb Total Space | 1.69 Gb Free Space | 14.84% Space Free | Partition Type: NTFS
Drive F: | 100.00 Mb Total Space | 37.72 Mb Free Space | 37.72% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
PRC - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/11/05 02:10:39 | 000,924,632 | —- | M] (Mozilla Corporation) – C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
PRC - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe
PRC - [2011/01/04 15:51:14 | 004,318,520 | —- | M] (Rogers) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe
PRC - [2011/01/04 15:51:14 | 000,488,760 | —- | M] (Radialpoint Inc.) – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgentComHandler.exe
PRC - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
PRC - [2010/10/27 21:21:54 | 001,155,072 | —- | M] (Last.fm) – C:\Program Files (x86)\Last.fm\LastFM.exe
PRC - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe
PRC - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe
PRC - [2010/02/23 12:00:00 | 000,028,672 | —- | M] (Creative Technology Ltd.) – C:\Windows\V0650Mon.exe
PRC - [2009/12/01 19:49:52 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/04/08 15:51:34 | 002,814,976 | —- | M] (WhatPulse.org) – C:\Program Files (x86)\WhatPulse\WhatPulse.exe
PRC - [2008/06/01 17:05:02 | 001,529,856 | —- | M] (Rokario Software) – C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe
========== Modules (No Company Name) ==========
MOD - [2011/11/07 18:53:16 | 000,265,536 | —- | M] () – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
MOD - [2011/11/05 02:10:39 | 001,989,592 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/05/26 14:14:52 | 000,477,080 | —- | M] () – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe
MOD - [2011/01/04 15:42:24 | 000,158,208 | —- | M] () – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\Windows7Features.dll
MOD - [2010/10/27 21:23:04 | 000,106,496 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll
MOD - [2010/10/27 21:22:52 | 000,057,344 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_messengernotify.dll
MOD - [2010/10/27 21:22:42 | 000,058,880 | —- | M] () – C:\Program Files (x86)\Last.fm\ext_skypenotify.dll
MOD - [2010/10/27 21:22:08 | 000,147,456 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_madtranscode.dll
MOD - [2010/10/27 21:22:00 | 000,028,160 | —- | M] () – C:\Program Files (x86)\Last.fm\srv_httpinput.dll
MOD - [2010/10/27 21:19:28 | 000,372,736 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll
MOD - [2010/10/27 21:19:06 | 000,025,088 | —- | M] () – C:\Program Files (x86)\Last.fm\breakpad.dll
MOD - [2010/10/27 21:18:50 | 000,180,224 | —- | M] () – C:\Program Files (x86)\Last.fm\Moose1.dll
MOD - [2010/10/27 21:18:34 | 000,540,672 | —- | M] () – C:\Program Files (x86)\Last.fm\LastFmTools1.dll
MOD - [2010/10/27 21:13:52 | 001,382,507 | —- | M] () – C:\Program Files (x86)\Last.fm\libfftw3f-3.dll
MOD - [2010/10/27 21:13:52 | 000,074,240 | —- | M] () – C:\Program Files (x86)\Last.fm\zlibwapi.dll
MOD - [2009/12/01 19:49:50 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2008/04/16 17:42:30 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtNetwork4.dll
MOD - [2008/04/16 17:42:16 | 000,524,288 | —- | M] () – C:\Program Files (x86)\Last.fm\QtSql4.dll
MOD - [2008/04/16 17:42:02 | 006,701,056 | —- | M] () – C:\Program Files (x86)\Last.fm\QtGui4.dll
MOD - [2008/04/16 17:36:38 | 000,376,832 | —- | M] () – C:\Program Files (x86)\Last.fm\QtXml4.dll
MOD - [2008/04/16 17:36:34 | 001,654,784 | —- | M] () – C:\Program Files (x86)\Last.fm\QtCore4.dll
MOD - [2008/04/02 14:26:50 | 000,233,472 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll
MOD - [2008/04/02 14:26:34 | 000,021,504 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll
MOD - [2008/04/02 14:26:28 | 000,135,168 | —- | M] () – C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/04/27 17:21:18 | 000,288,272 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe – (NisSrv)
SRV:
64bit: - [2011/04/27 17:21:18 | 000,012,784 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe – (MsMpSvc)
SRV:
64bit: - [2011/04/08 16:09:28 | 000,290,816 | —- | M] (Puran Software) [Disabled | Stopped] – C:\Windows\SysNative\PuranDefragS.exe – (PuranDefrag)
SRV:
64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2011/11/07 22:51:00 | 002,253,120 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe – (nvUpdatusService)
SRV - [2011/11/07 18:53:32 | 000,381,248 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2011/06/06 11:55:28 | 000,064,952 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/01/04 15:51:20 | 000,689,464 | —- | M] (Radialpoint Inc.) [Auto | Running] – C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\ServicepointService.exe – (ServicepointService)
SRV - [2010/11/23 21:21:18 | 000,130,000 | R— | M] (Symantec Corporation) [Unknown | Running] – C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\ccSvcHst.exe – (NSL)
SRV - [2010/07/01 10:38:26 | 000,083,512 | —- | M] (ArcSoft, Inc.) [Auto | Running] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\uUACTokenSvc.exe – (BackupService)
SRV - [2010/06/03 14:46:36 | 000,163,840 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\Update Manager\RogersUpdateManager.exe – (RogersUpdateManager)
SRV - [2010/06/03 14:46:32 | 000,139,264 | —- | M] (Rogers Cable Communications) [Auto | Running] – C:\Program Files (x86)\Rogers\SelfHealing\RogersSelfHelpService.exe – (RogersSelfHelpService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/10/02 16:26:12 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2007/12/16 22:00:00 | 000,163,840 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE – (EPSON_EB_RPCV4_01) EPSON V5 Service4(01)
SRV - [2007/01/10 22:02:00 | 000,126,464 | —- | M] (SEIKO EPSON CORPORATION) [Auto | Running] – C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE – (EPSON_PM_RPCV4_01) EPSON V3 Service4(01)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/07/07 18:21:28 | 000,174,184 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:
64bit: - [2011/05/10 07:06:08 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:
64bit: - [2011/04/27 15:25:24 | 000,084,864 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NisDrvWFP.sys – (NisDrv)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:
64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:
64bit: - [2010/03/31 12:00:00 | 000,393,536 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\V0650Vid.sys – (V0650Vid)
DRV:
64bit: - [2010/03/26 13:37:36 | 000,173,056 | —- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\CtClsFlt.sys – (CtClsFlt)
DRV:
64bit: - [2009/10/02 07:58:58 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:
64bit: - [2009/09/17 07:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:
64bit: - [2009/09/17 00:57:46 | 000,023,536 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] – c:\Program Files\PC-Doctor for Windows\pcdsrvc_x64.pkms – (PCDSRVC{F36B3A4C-F95654BD-06000000}_0)
DRV:
64bit: - [2009/08/20 19:05:06 | 000,239,616 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:
64bit: - [2008/05/06 15:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV:
64bit: - [2007/05/14 16:06:18 | 000,027,520 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://hp.ca.msn.com/default.aspx
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E1 12 6E 58 55 1C CB 01 [binary data]
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page =
http://g.msn.com/HPCON/4
IE - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPCON/4
========== FireFox ==========
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll (Rogers)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_1.2.0.6\coFFNST\ [2011/07/05 21:32:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\FinalVideoDownloader\Firefox [2011/09/26 14:47:44 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/15 16:26:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/19 18:16:00 | 000,000,000 | —D | M]
[2011/11/15 16:27:09 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (No name found) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions
[2011/12/22 15:44:03 | 000,000,000 | —D | M] (FT DeepDark) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2011/12/02 19:36:52 | 000,000,000 | —D | M] (WOT) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/17 20:37:14 | 000,000,000 | —D | M] (British English Dictionary) – C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\w30wc1oy.default\extensions\[removed]
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/24 21:16:43 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 20:23:29 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/26 14:47:44 | 000,000,000 | —D | M] (FinalVideoDownloader plugin for Mozilla Firefox) – C:\PROGRAM FILES (X86)\FINALVIDEODOWNLOADER\FIREFOX
() (No name found) – C:\USERS\OWNER\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\W30WC1OY.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2011/11/05 02:10:40 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/04 22:44:20 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/11/04 22:32:18 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/04 22:44:20 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/11/04 22:44:20 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/11/04 22:44:20 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Rogers Servicepoint Agent (Enabled) = C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\nprpspa.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Owner\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Activation Technologies (Enabled) = C:\Windows\system32\Wat\npWatWeb.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: WOT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.2.9_0\
CHR - Extension: YouTube = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.2_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: Skype Click to Call = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.4_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\1.2.0.6\CoIEPlg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [RogersServicepointAgent.exe] C:\Program Files (x86)\Rogers Online Protection\Rogers Servicepoint Agent\RogersServicepointAgent.exe (Rogers)
O4 - HKLM..\Run: [V0650Mon.exe] C:\Windows\V0650Mon.exe (Creative Technology Ltd.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [bandmon] C:\Program Files (x86)\Rokario\Bandwidth Monitor\bandmon.exe (Rokario Software)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [EPSON NX510 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIFIA.EXE /FU "C:\Users\Owner\AppData\Local\Temp\E_SB6F1.tmp" /EF "HKCU" File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000..\Run: [WhatPulse] C:\Program Files (x86)\WhatPulse\WhatPulse.exe (WhatPulse.org)
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk = C:\Users\Owner\AppData\Roaming\HP SimpleSave Application\StartHelper.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRemoteRecursiveEvents = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: VerboseStatus = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoInternetOpenWith = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousMachineGroupPolicy = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SynchronousUserGroupPolicy = 0
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKU\S-1-5-21-1331670900-2246307111-1120618914-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O8:
64bit: - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8:
64bit: - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Free YouTube to iPod Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoipodconverter.htm ()
O8 - Extra context menu item: Free YouTube to Mp3 Converter - C:\Users\Owner\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9 - Extra Button: Download Video - {3B54DEAB-C6D4-48a8-8C32-A70558643400} - C:\Program Files (x86)\FinalVideoDownloader\fvdRunner.html ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zone.msn.com/binary/Solit…wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/MessengerGam…1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EF5ABC5E-3819-46FA-B907-6644B8D77739}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F14C9C70-7912-4006-82E7-648CDC421877}: DhcpNameServer = [removed]
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (systempropertiesperformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell - "" = AutoRun
O33 - MountPoints2\{c70b017d-9783-11e0-a847-406186961016}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/12/22 16:04:10 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{91C8AE5A-BB9F-419A-B807-90D90A51D55D}
[2011/12/22 15:50:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E4B636FE-0D14-4091-BD72-BF178781D1F8}
[2011/12/21 17:00:47 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B0D7CAB2-283A-46FC-B63D-3CF4549811B5}
[2011/12/21 17:00:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{596D9425-13D5-4B80-BC07-478FA159BB03}
[2011/12/20 16:50:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{20C67B7F-D5C3-4EA0-B5D6-56D29ADA0C1E}
[2011/12/20 16:50:17 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DFA22BDD-7835-4B93-AAE2-78CA8DE57ACE}
[2011/12/19 15:37:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6B2D2CFB-E218-4509-8DBC-1C3F5E23DBBF}
[2011/12/19 15:37:00 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C0514324-FD0C-40D9-98C9-9F26F79F97C9}
[2011/12/19 01:16:31 | 000,000,000 | —D | C] – C:\Users\Owner\Desktop\testdisk-6.13
[2011/12/18 14:19:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{44BB564C-9A5D-4ECA-A491-598725543B8F}
[2011/12/18 14:19:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{787CE0ED-7694-486F-8B12-F6E856BE90BD}
[2011/12/17 23:59:01 | 000,847,872 | —- | C] (Western Digital) – C:\Users\Owner\Desktop\WinDlg.exe
[2011/12/17 18:10:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{90A5972C-7BB8-4434-BCF7-4992703AB95A}
[2011/12/17 18:10:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{11942ED9-762F-4B29-AA48-1E73D9174F6B}
[2011/12/16 23:55:59 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/16 23:55:58 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/16 23:55:57 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/16 23:55:57 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/16 23:55:57 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/16 23:55:57 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/16 23:55:56 | 002,309,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/12/16 23:55:56 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/16 23:55:56 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/16 23:55:56 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/12/16 23:55:55 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
[2011/12/16 22:37:15 | 000,000,000 | —D | C] – C:\Program Files\Core Temp
[2011/12/16 19:55:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{89AD739B-048A-483E-B5A4-90EFDFEC221D}
[2011/12/16 19:55:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9F35A44D-7831-4E38-8B81-A379E2E589A7}
[2011/12/16 19:44:32 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/16 19:44:29 | 000,723,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/16 19:44:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/16 16:12:37 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{08E737A6-FF5D-4392-BC54-54B89DADB99B}
[2011/12/16 16:12:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{193BCD13-B7E1-417C-9436-9E9839830F18}
[2011/12/15 15:46:42 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{64FB69B7-74CC-47C3-BB08-4A4D1B53B257}
[2011/12/15 15:46:20 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{AD888F84-5AC8-4DAE-AE88-76DFAB16EDE3}
[2011/12/14 15:34:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{CE849C1F-5527-4043-994E-66FCC5453AF0}
[2011/12/14 15:33:48 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{51218CFE-F55F-4AF7-8A29-B66D2ECF2431}
[2011/12/13 13:12:44 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{10D6B9BA-5ABD-4595-ACF1-2BC1A952B2A7}
[2011/12/13 13:12:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{D4719874-5EF8-4ADA-BDE1-9DF14592C529}
[2011/12/12 16:42:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{78C8EADE-1861-4A4F-82FC-0D8EBE41CD10}
[2011/12/12 16:42:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1F5940F6-4833-47C0-A8D6-6F3710C13DA3}
[2011/12/11 15:22:52 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F17D7D39-E8EE-49AE-B1FB-CD16F135987E}
[2011/12/11 15:22:30 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{43592173-D04B-45A6-B9BA-F2940021C273}
[2011/12/10 13:17:50 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{6139CE19-6638-48EC-82A4-DD09E4B9FDDE}
[2011/12/10 13:17:27 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{3DDFEF60-49CB-4902-82EA-851F00BCBB83}
[2011/12/09 15:46:31 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D11940F-25C7-4195-878D-C6D97EA34FAB}
[2011/12/09 15:46:09 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9212E1E8-EBE4-4CE6-9986-B98FC234CF22}
[2011/12/09 15:40:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/09 15:39:31 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/12/09 15:39:30 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/12/09 15:27:11 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2011/12/08 16:03:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DDAB35AE-CDDB-4EE2-9D37-01E8677CEAFC}
[2011/12/08 16:03:23 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{E99F74B6-9F3D-4CD1-8691-8109D3FE1AB8}
[2011/12/07 17:06:15 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{14A84DDE-F7AE-418A-87DA-0A2F66E4C349}
[2011/12/07 17:05:53 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F4B6C955-2EC9-42DD-BFE7-F3E5C6919AFD}
[2011/12/06 15:41:05 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B95D42A0-65A3-4A1B-A3E1-8B9C28E3E627}
[2011/12/06 15:40:43 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B52DFCA2-286F-471E-9504-E75B5C7AFE7D}
[2011/12/05 15:18:01 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{C7A225BB-8584-4747-AD7D-D57565502B8E}
[2011/12/05 15:17:45 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{F0335E61-8562-4472-ACD3-0939C2E3147F}
[2011/12/04 11:09:21 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{2B18B578-FB1B-4873-9E52-F22E0EA27329}
[2011/12/04 11:09:08 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{9FF0B248-7DB8-4BB0-9FD7-822D83D789F0}
[2011/12/03 22:21:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8AE60C4C-DE4D-4002-8B38-E6E858EE7699}
[2011/12/03 22:20:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{8B161D07-75C5-4A71-AA10-8A9B8AD2359D}
[2011/12/03 10:20:32 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1FB7C86A-8AB1-46A8-A7CF-78B7058A8D94}
[2011/12/03 10:20:13 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1B136402-BF9E-44A0-ABE9-2B784578CAD6}
[2011/12/02 16:04:07 | 000,000,000 | –SD | C] – C:\32788R22FWJFW
[2011/12/02 15:42:36 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7D1A43B8-8A4E-4E52-9976-7FE2AC6425A2}
[2011/12/02 15:42:14 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{5A72F670-75B5-4A8C-A932-EA1DEB4CAB95}
[2011/12/01 16:25:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Puran Defrag
[2011/12/01 16:25:40 | 001,417,216 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranFD.exe
[2011/12/01 16:25:40 | 000,290,816 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragS.exe
[2011/12/01 16:25:40 | 000,275,968 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDC.exe
[2011/12/01 16:25:40 | 000,270,336 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefrag.dll
[2011/12/01 16:25:40 | 000,130,048 | —- | C] (Puran Software) – C:\Windows\SysNative\PuranDefragBT.exe
[2011/12/01 16:25:40 | 000,000,000 | —D | C] – C:\Program Files\Puran Defrag
[2011/12/01 16:13:19 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B6323AF0-6488-4B51-9343-41EC1DF20D1A}
[2011/12/01 16:12:56 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{7940265E-F90B-4E8B-B1A2-3EB5664144C1}
[2011/11/30 17:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/30 15:25:29 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{19C62BA7-FD7A-4102-9E86-50ECD7714AFD}
[2011/11/30 15:25:07 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{B962C5FB-79F8-4B7D-B6C6-5EB38FC1495A}
[2011/11/29 13:11:11 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{DB245045-2B52-4213-8524-A5092754DCDC}
[2011/11/29 13:10:49 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Local\{1E0B4E88-6799-4C13-B421-F31168D619DB}
[2011/11/28 19:08:41 | 000,000,000 | -HSD | C] – C:\Boot
[2011/11/24 21:16:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/11/23 20:50:02 | 000,000,000 | —D | C] – C:\ProgramData\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HPSS
[2011/11/23 20:47:40 | 000,000,000 | —D | C] – C:\Users\Owner\AppData\Roaming\HP SimpleSave Application
[2011/11/23 20:41:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/11/23 20:34:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2011/11/23 20:33:46 | 005,067,584 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2011/11/23 20:33:46 | 000,137,536 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2011/11/23 20:33:45 | 010,406,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2011/11/23 20:33:45 | 003,074,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2011/11/23 20:33:45 | 000,837,952 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/11/23 20:33:45 | 000,222,528 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2011/11/23 20:24:34 | 024,742,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/11/23 20:24:34 | 008,792,384 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2011/11/23 20:24:34 | 007,042,880 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/11/23 20:24:34 | 001,452,648 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/11/23 20:24:34 | 000,174,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/11/23 20:24:34 | 000,029,288 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvhdap64.dll
[2011/11/23 20:24:33 | 024,796,992 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/11/23 20:24:33 | 018,871,616 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/11/23 20:24:33 | 017,248,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/11/23 20:24:33 | 015,693,120 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/11/23 20:24:33 | 013,205,312 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2011/11/23 20:24:33 | 007,581,504 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/11/23 20:24:33 | 005,578,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/11/23 20:24:33 | 002,808,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2011/11/23 20:24:33 | 002,542,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/11/23 20:24:33 | 002,458,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2011/11/23 20:24:33 | 002,401,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/11/23 20:24:33 | 002,232,128 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/11/23 20:24:33 | 002,099,520 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/11/23 20:24:33 | 001,543,488 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/11/23 20:24:33 | 001,454,400 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/11/23 20:24:33 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/11/23 20:24:33 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/11/23 20:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2011/11/23 20:23:27 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2011/11/23 20:23:27 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2011/11/23 20:23:08 | 000,000,000 | —D | C] – C:\NVIDIA
[2011/11/23 15:59:51 | 000,000,000 | —D | C] – C:\Windows\ERDNT
========== Files - Modified Within 30 Days ==========
[2011/12/22 16:03:59 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Owner\Desktop\OTL.exe
[2011/12/22 15:51:04 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000UA.job
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:45:28 | 000,020,432 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/22 15:42:11 | 000,729,756 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/22 15:42:11 | 000,630,488 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/22 15:42:11 | 000,111,572 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/22 15:38:17 | 000,000,653 | —- | M] () – C:\ProgramData\SHSupdates.xml
[2011/12/22 15:37:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/22 15:36:33 | 2090,135,551 | -HS- | M] () – C:\hiberfil.sys
[2011/12/20 16:51:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1331670900-2246307111-1120618914-1000Core.job
[2011/12/18 14:49:17 | 000,018,188 | —- | M] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | M] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | M] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/17 06:16:58 | 000,441,224 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/16 22:37:16 | 000,000,950 | —- | M] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/12/11 15:18:28 | 000,000,448 | -H– | M] () – C:\Windows\tasks\Norton Security Scan for Owner.job
[2011/12/10 13:12:26 | 000,000,332 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForOwner.job
[2011/12/09 15:27:20 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/03 16:12:07 | 000,001,945 | —- | M] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
========== Files Created - No Company Name ==========
[2011/12/18 14:49:17 | 000,018,188 | —- | C] () – C:\Users\Owner\Desktop\smart.htm
[2011/12/18 14:49:17 | 000,015,704 | —- | C] () – C:\Users\Owner\Desktop\help.htm
[2011/12/18 14:49:17 | 000,001,920 | —- | C] () – C:\Users\Owner\Desktop\wdclogo.gif
[2011/12/16 22:37:16 | 000,000,950 | —- | C] () – C:\Users\Owner\Desktop\Core Temp.lnk
[2011/11/28 19:11:51 | 000,383,786 | RHS- | C] () – C:\bootmgr
[2011/11/23 22:09:25 | 000,001,945 | —- | C] () – C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HP SimpleSave Monitor.lnk
[2011/11/20 18:56:02 | 000,822,916 | —- | C] () – C:\Users\Owner\AppData\Local\census.cache
[2011/11/20 18:55:53 | 000,112,588 | —- | C] () – C:\Users\Owner\AppData\Local\ars.cache
[2011/11/20 18:49:32 | 000,000,036 | —- | C] () – C:\Users\Owner\AppData\Local\housecall.guid.cache
[2011/11/10 16:36:00 | 000,735,006 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/11/07 18:53:44 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/07/30 13:12:25 | 002,205,064 | —- | C] () – C:\ProgramData\shs_setup_4059-354328.exe
[2011/07/30 13:12:23 | 000,000,653 | —- | C] () – C:\ProgramData\SHSupdates.xml
[2011/07/29 19:38:38 | 001,896,720 | —- | C] () – C:\Users\Owner\AppData\Local\tmpIMG023.JPG
[2011/01/22 13:39:45 | 000,001,940 | —- | C] () – C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/12 03:58:23 | 000,000,000 | —- | C] () – C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/07/15 17:45:05 | 000,007,597 | —- | C] () – C:\Users\Owner\AppData\Local\Resmon.ResmonCfg
[2010/07/05 11:57:43 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2010/07/05 11:57:42 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2010/07/05 11:57:42 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2010/07/05 11:57:42 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2010/07/05 11:57:42 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2010/07/05 11:57:42 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2010/07/05 11:57:42 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2010/07/05 11:57:42 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2010/07/05 11:57:42 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2010/07/05 11:57:42 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2010/07/05 11:57:42 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2010/07/05 11:57:42 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2010/07/05 11:57:42 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2010/07/05 11:57:42 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2010/07/05 11:53:19 | 000,000,079 | —- | C] () – C:\Windows\EPNX510.ini
[2009/09/29 18:25:16 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
aswMBR
aswMBR version 0.9.9.1116 Copyright© 2011 AVAST Software
Run date: 2011-12-22 16:28:51
—————————–
16:28:51.643 OS Version: Windows x64 6.1.7601 Service Pack 1
16:28:51.643 Number of processors: 4 586 0x2502
16:28:51.643 ComputerName: OWNER-PC UserName: Owner
16:28:52.798 Initialize success
16:29:03.974 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
16:29:03.989 Disk 0 Vendor: WDC_WD10 01.0 Size: 953869MB BusType: 8
16:29:04.005 Disk 0 MBR read successfully
16:29:04.005 Disk 0 MBR scan
16:29:04.005 Disk 0 Windows 7 default MBR code
16:29:04.005 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
16:29:04.020 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 942118 MB offset 206848
16:29:04.052 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 11649 MB offset 1929664512
16:29:04.052 Service scanning
16:29:04.473 Service MpNWMon C:\Windows\system32\DRIVERS\MpNWMon.sys **LOCKED** 32
16:29:05.066 Modules scanning
16:29:05.066 Disk 0 trace - called modules:
16:29:05.066 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll
16:29:05.081 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007b63060]
16:29:05.081 3 CLASSPNP.SYS[fffff88001b6143f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800789d050]
16:29:05.097 Scan finished successfully
16:29:29.417 Disk 0 MBR has been saved successfully to "C:\Users\Owner\Desktop\MBR.dat"
16:29:29.417 The log file has been saved successfully to "C:\Users\Owner\Desktop\aswMBR.txt"