fernipascual
Topic Starter
Hello:
My computer was infected with the VISTA 2011 virus some weeks ago. I cleaned it up using Malwarebytes and Superantispyware but want to make sure everything is gone.
I ran OTL two times. I did not realize the first time that the instructions said to run as administrator. I do not see the Extras.txt file of my second run so I am submitting the first run of Extras and second run of OTL.txt.
OTL logfile created on: 12/30/2011 12:49:03 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.94 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 49.65% Memory free
8.05 Gb Paging File | 5.80 Gb Available in Paging File | 72.09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.81 Gb Free Space | 57.45% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS
Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nando\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
SRV - (MBAMService) – C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) – c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Com4Qlb) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Comsift Service) – C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\CHDART64.sys (Conexant Systems Inc.)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (HpqRemHid) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (BrSerIf) – C:\Windows\SysNative\DRIVERS\BrSerIf.sys (Brother Industries Ltd.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files\Musicnotes\npmusicn64.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files (x86)\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.1.5.22: C:\Program Files (x86)\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/12/28 22:52:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.23\ [2011/12/28 22:52:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files (x86)\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files (x86)\Musicnotes\npsibelius.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shop to Win) - {3A90A078-4BB9-4568-9557-CDEEFCAE68A0} - C:\Program Files (x86)\Shop to Win 22\Shop to Win 22.dll (Shop To Win, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Shop To Win] C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{782025A6-9DD6-47D2-A122-2AB87DD5D2B7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6222EA1-2033-413C-B5E7-C27F1E5CD06E}: DhcpNameServer = 172.16.2.5 172.18.82.11 4.2.2.2
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSWOW64\Userinit.exe) -C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\HPOrganicDk.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/19 15:48:18 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{4874b439-ca97-11df-afee-001d725ed412}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.garmin.com/agent
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/30 12:20:53 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/28 23:07:02 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/28 22:52:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2011/12/28 22:52:16 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/12/28 22:52:08 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/12/28 22:51:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2011/12/28 22:49:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2011/12/28 22:44:47 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/12/20 21:59:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2011/12/20 21:20:40 | 000,000,000 | —D | C] – C:\Users\Nando\Documents\ShopToWin
[2011/12/20 21:20:15 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 22
[2011/12/20 21:19:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop to Win 22
[2011/12/20 21:19:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop To Win
[2011/12/18 16:29:27 | 001,653,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/12/18 16:29:27 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/12/18 11:25:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2011/12/18 11:24:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Portable Devices
[2011/12/18 11:24:58 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2011/12/18 11:20:32 | 000,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2011/12/18 11:20:32 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2011/12/18 11:20:29 | 001,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2011/12/18 11:20:29 | 000,411,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PhotoMetadataHandler.dll
[2011/12/18 11:20:29 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiagn.dll
[2011/12/18 11:20:29 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2011/12/18 11:20:29 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiagn.dll
[2011/12/18 11:20:28 | 000,792,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2011/12/18 11:20:28 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2011/12/18 11:20:28 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiag.exe
[2011/12/18 11:20:28 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2011/12/18 11:20:28 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiag.exe
[2011/12/18 11:19:19 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShextAutoplay.exe
[2011/12/18 11:19:19 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDShextAutoplay.exe
[2011/12/18 11:19:18 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BthMtpContextHandler.dll
[2011/12/18 11:19:14 | 002,727,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpdshext.dll
[2011/12/18 11:19:14 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpd_ci.dll
[2011/12/18 11:19:14 | 000,295,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtp.dll
[2011/12/18 11:19:14 | 000,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShServiceObj.dll
[2011/12/18 11:19:14 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtpUS.dll
[2011/12/18 11:19:14 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WpdUsb.sys
[2011/12/18 11:19:14 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdConns.dll
[2011/12/18 11:19:13 | 000,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceApi.dll
[2011/12/18 11:19:13 | 000,433,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDSp.dll
[2011/12/18 11:19:13 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDSp.dll
[2011/12/18 11:19:13 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceTypes.dll
[2011/12/18 11:19:13 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,113,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceClassExtension.dll
[2011/12/18 11:19:13 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceClassExtension.dll
[2011/12/18 10:42:01 | 000,103,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2011/12/18 10:42:01 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2011/12/18 10:42:00 | 003,815,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbon.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbonRes.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbonRes.dll
[2011/12/18 10:41:59 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbon.dll
[2011/12/17 20:47:26 | 000,479,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/12/17 20:47:26 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/12/17 20:47:24 | 001,555,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/12/17 20:47:00 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/17 20:46:59 | 000,316,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msshsq.dll
[2011/12/17 20:46:58 | 000,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/12/17 20:46:26 | 000,834,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/12/17 20:46:26 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/12/17 20:46:25 | 003,068,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xpsservices.dll
[2011/12/17 20:46:25 | 002,002,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/12/17 20:46:25 | 001,257,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFH264Dec.dll
[2011/12/17 20:46:25 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFH264Dec.dll
[2011/12/17 20:46:24 | 000,566,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2011/12/17 20:46:24 | 000,287,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2011/12/17 20:46:24 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/12/17 20:46:23 | 001,461,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OpcServices.dll
[2011/12/17 20:46:23 | 001,268,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2011/12/17 20:46:23 | 000,625,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2011/12/17 20:46:23 | 000,327,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/12/17 20:46:23 | 000,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/12/17 20:46:22 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xpsservices.dll
[2011/12/17 20:46:22 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\OpcServices.dll
[2011/12/17 20:46:22 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/12/17 20:46:21 | 003,548,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/12/17 20:46:21 | 001,032,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelinesvc.exe
[2011/12/17 20:46:21 | 000,377,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4src.dll
[2011/12/17 20:46:21 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winspool.drv
[2011/12/17 20:46:21 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/12/17 20:46:21 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4src.dll
[2011/12/17 20:46:21 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/12/17 20:46:20 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/12/17 20:46:20 | 001,204,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2011/12/17 20:46:20 | 000,748,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2011/12/17 20:46:20 | 000,278,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfplat.dll
[2011/12/17 20:46:20 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfplat.dll
[2011/12/17 20:46:18 | 000,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/12/17 20:46:17 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelineprxy.dll
[2011/12/17 20:46:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfps.dll
[2011/12/17 20:46:13 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfpmp.exe
[2011/12/17 20:45:55 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/12/17 20:45:52 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/12/17 20:45:38 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/12/17 20:45:31 | 000,559,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/17 20:45:31 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/17 20:45:29 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/12/17 20:45:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/12/17 20:45:29 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/12/17 20:45:28 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/12/17 20:45:27 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/17 20:45:27 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/12/17 20:45:27 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/12/17 20:45:27 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/12/17 20:45:27 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/12/17 20:45:27 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/12/17 20:45:27 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/12/17 20:45:26 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/12/17 20:45:25 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/12/17 20:45:25 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/12/17 20:45:25 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/17 20:45:25 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/17 20:45:25 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/17 20:45:25 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/12/17 20:45:24 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/17 20:45:24 | 000,710,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/17 20:45:23 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/12/17 20:45:23 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/17 20:45:23 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/17 20:45:22 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/17 20:45:18 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/12/17 20:45:08 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/12/17 20:45:08 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/12/17 20:45:08 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/12/17 20:45:08 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/12/17 20:43:46 | 004,699,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/12/17 20:33:31 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/12/17 20:33:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/12/17 20:33:31 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/12/17 20:33:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/12/17 20:33:31 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/12/17 20:33:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\vi-VN
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ca-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\ca-ES
[2011/12/17 15:21:33 | 000,000,000 | —D | C] – C:\Windows\SysNative\vi-VN
[2011/12/17 12:57:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2011/12/17 11:10:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/12/17 10:58:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Mechanic
[2011/12/17 10:57:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/17 08:52:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topckit_2011
[2011/12/16 23:32:40 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/12/16 23:06:28 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2011/12/16 23:06:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2011/12/16 23:06:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2011/12/16 23:06:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2011/12/16 23:05:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2011/12/16 23:05:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Surf Canyon
[2011/12/08 19:02:52 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Local\confobj90
[2011/12/07 18:41:31 | 000,252,296 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/03 09:36:22 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCP71.DLL
[2011/12/03 09:36:22 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCR71.DLL
[2011/12/03 09:36:21 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFC71.DLL
[2011/12/03 09:36:18 | 001,017,208 | —- | C] (CyberLink Corp.) – C:\Windows\SysWow64\CLVSD.ax
[2011/12/03 09:36:17 | 000,000,000 | —D | C] – C:\Program Files\Cucusoft
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/30 12:50:55 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/30 12:50:55 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/30 12:50:55 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/30 12:45:17 | 000,027,335 | —- | M] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2011/12/30 12:44:35 | 000,000,243 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/30 12:44:03 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:42:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/30 12:15:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 23:29:32 | 000,000,680 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2011/12/29 22:15:15 | 085,491,386 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:49 | 000,020,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\tasks\RMSchedule.job
[2011/12/28 22:52:34 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/27 11:43:38 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/27 11:42:44 | 000,000,419 | —- | M] () – C:\Windows\BRWMARK.INI
[2011/12/27 11:42:44 | 000,000,027 | —- | M] () – C:\Windows\BRPP2KA.INI
[2011/12/21 12:11:05 | 561,550,750 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 16:28:24 | 002,744,532 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/12/18 15:16:57 | 000,002,341 | —- | M] () – C:\Users\Nando\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/18 11:28:43 | 000,343,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/18 11:24:10 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | M] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | M] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:14:06 | 000,001,212 | —- | M] () – C:\Users\Nando\Desktop\exefix_vista.reg
[2011/12/17 09:06:24 | 000,000,732 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | M] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | M] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/15 19:47:05 | 000,000,334 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNando.job
[2011/12/14 23:16:54 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/12/14 20:09:07 | 000,010,492 | -HS- | M] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:09:06 | 000,010,492 | -HS- | M] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/12 14:07:00 | 000,040,408 | —- | M] () – C:\Windows\SysNative\CleanMFT64.exe
[2011/12/10 15:24:08 | 000,023,152 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/12/07 18:41:20 | 000,627,600 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2011/12/07 18:41:20 | 000,252,296 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/05 18:46:03 | 000,025,600 | —- | M] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/03 09:36:22 | 000,001,002 | —- | M] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/29 22:15:15 | 085,491,386 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:48 | 000,020,592 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/28 22:52:34 | 000,000,872 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/21 12:11:05 | 561,550,750 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 11:24:10 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | C] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | C] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | C] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:06:24 | 000,000,732 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | C] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | C] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/03 09:36:22 | 000,001,002 | —- | C] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2011/01/26 22:04:57 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/09 22:56:19 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2010/07/17 18:52:34 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/17 18:52:32 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/05/05 19:16:35 | 000,000,680 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2010/04/06 18:27:03 | 000,047,616 | —- | C] () – C:\Windows\SysWow64\pdf995mon64.dll
[2010/04/06 18:27:03 | 000,000,142 | —- | C] () – C:\Windows\wpd99.drv
[2010/03/13 11:53:13 | 000,763,832 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2010/03/07 16:14:19 | 000,023,114 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/06 22:47:17 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/03/06 22:46:53 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/03/06 22:46:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2010/03/04 20:15:04 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2010/03/04 20:09:34 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/03/04 20:09:34 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2010/03/03 16:54:45 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.dat
[2010/03/02 04:16:00 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2010/02/28 20:02:59 | 000,025,600 | —- | C] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/22 12:19:56 | 000,101,632 | —- | C] () – C:\Windows\hpqins13.dat
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2011/12/28 23:07:02 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/16 23:32:44 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/09/12 16:49:48 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Helios
[2010/04/06 18:27:51 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\pdf995
[2011/07/16 16:46:17 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\PlayFirst
[2011/12/17 10:57:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/18 11:47:53 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Registry Mechanic
[2010/05/27 19:27:18 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TaxCut
[2011/12/17 11:10:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/07/16 16:44:50 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\WildTangent
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\Tasks\RMSchedule.job
[2011/12/30 12:40:47 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/30 21:36:06 | 000,000,434 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A178F131-5775-4EDE-B6A0-A3D250D9CA70}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/11/19 15:48:18 | 000,000,047 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/22 11:29:01 | 000,000,384 | -H– | M] () – C:\IPH.PH
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/12/30 12:42:38 | 245,358,591 | -HS- | M] () – C:\pagefile.sys
[2011/12/20 21:15:18 | 000,000,370 | —- | M] () – C:\rkill.log
[2011/12/20 21:20:42 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.20.19_log.txt
[2011/12/20 21:28:16 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.28.05_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011/12/17 14:48:06 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2011/05/24 18:09:34 | 000,003,072 | —- | M] () – C:\Windows\system32\Cache.db
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/19 18:59:19 | 000,000,286 | -HS- | M] () – C:\Users\Nando\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2010/12/12 16:20:00 | 000,512,992 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe
[2008/08/05 11:35:52 | 027,141,384 | —- | M] (Maxis, a division of Electronic Arts Inc.) – C:\Users\Nando\Desktop\SporeApp.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
OTL Extras logfile created on: 12/30/2011 12:24:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.94 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 38.95% Memory free
8.09 Gb Paging File | 5.51 Gb Available in Paging File | 68.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.34 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS
Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = D7 9C 35 A7 FA BC CC 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15133EB3-BAC9-474C-8F3F-B154E486D15C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{198930C5-8707-4EBA-8068-56C3B40AC958}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{215E8087-6F61-4A2B-BC04-41E8E1429FAA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{39350F15-CF71-4204-9EEA-D280D6F79EC8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3AE7C3FE-2358-4EDD-B7AC-7DF51F14D970}" = lport=139 | protocol=6 | dir=in | app=system |
"{462EF7E1-F0B5-47A4-AC22-41016C40F218}" = rport=139 | protocol=6 | dir=out | app=system |
"{489BED90-9315-49B8-9884-4D2DF3EEAA1D}" = rport=137 | protocol=17 | dir=out | app=system |
"{54790C89-38F2-4594-874C-1CAC651DF2E8}" = rport=445 | protocol=6 | dir=out | app=system |
"{551785C4-899D-4F0F-9C41-AD37CACB9BE9}" = rport=138 | protocol=17 | dir=out | app=system |
"{56345D86-61B4-42F3-9ED2-4BBE2C53830E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{624DE384-7D94-42D1-ABF0-A1FB656C5B1F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9D94C86C-4B1C-496B-A969-647E3DA1DDCE}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A9AF15C5-982F-4E28-B605-39979390CF8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A9BE3B48-2459-46A6-BC8D-FBC7C24BF610}" = lport=445 | protocol=6 | dir=in | app=system |
"{BE72380F-F0BE-449C-B6E4-2A8D2CD73F97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C9EC8183-ACA2-4BC4-A3AA-8D1838BB6A16}" = lport=138 | protocol=17 | dir=in | app=system |
"{D3939D16-5274-4531-90F5-3453B230C01F}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13498DC-A6C6-46E1-9908-4CACCEDB3D44}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EBB28CC8-E07B-4248-B46E-B0BF50C65116}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FFC6A871-2C4E-402F-99BF-20C9E0596505}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05377A32-4DF3-40BF-BC42-617A590E1F78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{0B9AEFC6-0715-410E-B23D-F06839F1A148}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{109647F6-8FDA-479B-B52D-DE2AC5911B61}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{10CD19CB-B12A-4088-BCB3-975B1D4E0BE6}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{11B73F2B-ED14-4AF3-85A6-025E1A67039D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{22EC7A86-E344-411E-B39E-EFDFBF5A6482}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{2F7B2ECF-7F5C-49CE-A6D8-55CA7CD841DD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{302650D1-FECF-4BD9-914E-2D573C5119AE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3197B78D-043F-4BA9-9405-8285904A61E9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{32CBB9C1-3A11-4D00-94C9-9D32BF0BA653}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{416D7402-714F-4290-99D4-AABB3CD5BB8C}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4ABD36B7-B516-4B2B-9846-334220638AB7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{5A735C20-3FA4-48CD-ABE7-3FD036B17215}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{5C4329C8-1FB4-40E9-ABDA-6EC7E0F4BB07}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{61F7AD8E-139E-42B7-9C5C-A7BD525CFFBC}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{74606898-9BF7-4492-814D-DB7F0BE8FE7F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{75A591D0-61D9-4D1A-852C-619D342EA3AF}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7EC89CF2-59BC-47F9-A740-25E6193D4B8B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{9480CE52-8E38-4CE8-8C2C-C8DCB9E8039D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{994FDA5B-6A99-44D9-B78D-98C669C66986}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A3ED1A51-F422-4E40-8557-1A2459E3444E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{A42972CF-C3D8-47DD-954C-95D54A3EA0CB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A63327CF-0C72-4639-AD8F-700B5C701A3F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A816440F-685A-45C5-9DAB-6427F13E0C93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{A86FE271-78A0-4E9A-83E1-806609A23B33}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AC5911B7-43B2-46EE-BBC2-3BFC4F624A82}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{ADF4889E-426E-4957-A315-4FBBF52243CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{C4F099C9-90DF-4323-B044-A2A15C6D7204}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{C9F24E41-583D-49A6-8A13-82BCB4B9D178}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{DA6D66EA-81F4-495D-AABB-D0AAC3D073C1}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{DED927DF-B9DE-4F68-81B3-D33123CB6504}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E1A31D5B-F679-4E5D-8CBC-08B6BAF4D9C7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EC8E8471-F49F-473E-A62B-66AFB26956AF}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{F2F05428-15BD-4F78-BBF6-F9EADCBC276D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"TCP Query User{31824B3D-BEA6-4578-A666-24E985B2F3D9}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{5828C114-88E7-40A6-8FFE-84271B674D7A}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{26A24AE4-039D-4CA4-87B4-2F86417001FF}" = Java™ 7 Update 1 (64-bit)
"{28D73032-5DAA-4F83-B154-85105DBCCB92}" = iTunes
"{41B19F41-8A6F-4422-AD69-CF3B408F382C}" = AVG 2012
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{64A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7 (64-bit)
"{64A3A4F4-B792-11D6-A78A-00B0D0170010}" = Java™ SE Development Kit 7 Update 1 (64-bit)
"{6D830209-41C2-4D6B-BA25-4EF98807D9FB}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A348C751-0EFF-4B9D-8065-B5339BEFBE27}" = HP Help and Support
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0F907A69-6332-4F87-AD74-3C91A627D2C6}" = H&R; Block Virginia 2009
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java™ 7
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40049394-98C6-409D-878D-E418B872D5D0}" = Comsift Service
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R; Block Deluxe + Efile + State 2009
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5D87C09F-512F-474A-A306-0FE3B89C396F}" = RuneScape Launcher 1.0.4
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92A196AE-9B4D-499C-94D4-18FA2061B3CE}_is1" = Shop To Win
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}" = HP User Guides 0090
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AIM_6" = AIM 6
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"FreeFileViewer_is1" = Free File Viewer 2011
"Google Chrome" = Google Chrome
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.4.3
"Pdf995" = Pdf995 (installed by H&R; Block)
"PdfEdit995" = PdfEdit995 (installed by H&R; Block)
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"Registry Mechanic_is1" = PC Tools Registry Mechanic 11.0
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Surf Canyon" = Fast Search
"TI-83 Plus Flash Debugger" = TI-83 Plus Flash Debugger
"Trusted Software Assistant_is1" = File Type Assistant
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Software Update" = Yahoo! Software Update
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 681802
Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 681802
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 682894
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 682894
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 684642
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 684642
Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 685905
[ Media Center Events ]
Error - 9/17/2010 9:02:48 PM | Computer Name = Nando-Laptop | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ OSession Events ]
Error - 12/8/2011 5:24:45 PM | Computer Name = Nando-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 816
seconds with 420 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 6/1/2010 6:18:25 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:26 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:27 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:29 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:30 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:32 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
< End of report >
My computer was infected with the VISTA 2011 virus some weeks ago. I cleaned it up using Malwarebytes and Superantispyware but want to make sure everything is gone.
I ran OTL two times. I did not realize the first time that the instructions said to run as administrator. I do not see the Extras.txt file of my second run so I am submitting the first run of Extras and second run of OTL.txt.
OTL logfile created on: 12/30/2011 12:49:03 PM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.94 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 49.65% Memory free
8.05 Gb Paging File | 5.80 Gb Available in Paging File | 72.09% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.81 Gb Free Space | 57.45% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS
Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Nando\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
PRC - C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
PRC - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.181\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Common Files\LightScribe\QtCore4.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\DRIVERS\xaudio64.exe (Conexant Systems, Inc.)
SRV - (vToolbarUpdater) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\9.0.1\ToolbarUpdater.exe ()
SRV - (MBAMService) – C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PCToolsSSDMonitorSvc) – C:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe (PC Tools)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\AVGIDSAgent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (PMBDeviceInfoProvider) – C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Sony Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (LiveUpdate) – c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (Com4Qlb) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Comsift Service) – C:\Program Files (x86)\Comsift\Comsift Service\Comsiftservice.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\DRIVERS\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\DRIVERS\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\DRIVERS\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\DRIVERS\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\DRIVERS\AVGIDSFilter.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSEH) – C:\Windows\SysNative\DRIVERS\AVGIDSEH.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\DRIVERS\AVGIDSDriver.Sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (HSFHWAZL) – C:\Windows\SysNative\DRIVERS\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (BCM43XV) – C:\Windows\SysNative\DRIVERS\bcmwl664.sys (Broadcom Corp.)
DRV:64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\CHDART64.sys (Conexant Systems Inc.)
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (HpqRemHid) – C:\Windows\SysNative\DRIVERS\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\DRIVERS\xaudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (ApfiltrService) – C:\Windows\SysNative\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\DRIVERS\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\DRIVERS\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\DRIVERS\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (BrSerIf) – C:\Windows\SysNative\DRIVERS\BrSerIf.sys (Brother Industries Ltd.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\DRIVERS\mdmxsdk.sys (Conexant)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…n&pf;=laptop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files\Musicnotes\npmusicn64.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.4: C:\Program Files (x86)\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.1.5.22: C:\Program Files (x86)\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2011/12/28 22:52:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\9.0.0.23\ [2011/12/28 22:52:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/07 16:14:31 | 000,000,000 | —D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Java Deployment Toolkit 7.0.0.147 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files (x86)\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files (x86)\Musicnotes\npsibelius.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7018.1622\swg64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Shop to Win) - {3A90A078-4BB9-4568-9557-CDEEFCAE68A0} - C:\Program Files (x86)\Shop to Win 22\Shop to Win 22.dll (Shop To Win, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Fast Search) - {5AB7104A-B71F-49AD-9154-F7F8806AE848} - C:\Program Files (x86)\Surf Canyon\surfcanyon.dll (Surf Canyon Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\9.0.0.23\AVG Secure Search_toolbar.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4:64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.dll (NVIDIA Corporation)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Users\Nando\Desktop\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [Shop To Win] C:\Program Files (x86)\Shop To Win\ShopToWin.exe (Jackpot Rewards)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.1.0)
O16 - DPF: {CAFEEFAC-0017-0000-0001-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{782025A6-9DD6-47D2-A122-2AB87DD5D2B7}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A6222EA1-2033-413C-B5E7-C27F1E5CD06E}: DhcpNameServer = 172.16.2.5 172.18.82.11 4.2.2.2
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\9.0.1\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\SYSWOW64\Userinit.exe) -C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\HPOrganicDk.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/11/19 15:48:18 | 000,000,047 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2005/09/11 10:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE – [ NTFS ]
O33 - MountPoints2\{4874b439-ca97-11df-afee-001d725ed412}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL http://www.garmin.com/agent
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\WINDOWS\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/30 12:20:53 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/28 23:07:02 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/28 22:52:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2011/12/28 22:52:16 | 000,000,000 | —D | C] – C:\ProgramData\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AVG Secure Search
[2011/12/28 22:52:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG Secure Search
[2011/12/28 22:52:08 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2011/12/28 22:51:28 | 000,000,000 | —D | C] – C:\Windows\SysWow64\drivers\AVG
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/12/28 22:50:43 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\AVG
[2011/12/28 22:49:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2011/12/28 22:44:47 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2011/12/20 21:59:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
[2011/12/20 21:59:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2011/12/20 21:20:40 | 000,000,000 | —D | C] – C:\Users\Nando\Documents\ShopToWin
[2011/12/20 21:20:15 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 22
[2011/12/20 21:19:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop to Win 22
[2011/12/20 21:19:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Shop To Win
[2011/12/18 16:29:27 | 001,653,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/12/18 16:29:27 | 000,876,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/12/18 11:25:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2011/12/18 11:24:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Portable Devices
[2011/12/18 11:24:58 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2011/12/18 11:20:32 | 000,449,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMPhoto.dll
[2011/12/18 11:20:32 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMPhoto.dll
[2011/12/18 11:20:29 | 001,209,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2011/12/18 11:20:29 | 000,411,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PhotoMetadataHandler.dll
[2011/12/18 11:20:29 | 000,262,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiagn.dll
[2011/12/18 11:20:29 | 000,245,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecsExt.dll
[2011/12/18 11:20:29 | 000,195,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiagn.dll
[2011/12/18 11:20:28 | 000,792,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2011/12/18 11:20:28 | 000,519,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2011/12/18 11:20:28 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxdiag.exe
[2011/12/18 11:20:28 | 000,321,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PhotoMetadataHandler.dll
[2011/12/18 11:20:28 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dxdiag.exe
[2011/12/18 11:19:19 | 000,034,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShextAutoplay.exe
[2011/12/18 11:19:19 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDShextAutoplay.exe
[2011/12/18 11:19:18 | 000,037,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BthMtpContextHandler.dll
[2011/12/18 11:19:14 | 002,727,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpdshext.dll
[2011/12/18 11:19:14 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpd_ci.dll
[2011/12/18 11:19:14 | 000,295,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtp.dll
[2011/12/18 11:19:14 | 000,110,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDShServiceObj.dll
[2011/12/18 11:19:14 | 000,077,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdMtpUS.dll
[2011/12/18 11:19:14 | 000,060,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceConnectApi.dll
[2011/12/18 11:19:14 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WpdUsb.sys
[2011/12/18 11:19:14 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WpdConns.dll
[2011/12/18 11:19:13 | 000,453,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceApi.dll
[2011/12/18 11:19:13 | 000,433,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WPDSp.dll
[2011/12/18 11:19:13 | 000,350,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WPDSp.dll
[2011/12/18 11:19:13 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceTypes.dll
[2011/12/18 11:19:13 | 000,196,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceWMDRM.dll
[2011/12/18 11:19:13 | 000,113,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PortableDeviceClassExtension.dll
[2011/12/18 11:19:13 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PortableDeviceClassExtension.dll
[2011/12/18 10:42:01 | 000,103,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAnimation.dll
[2011/12/18 10:42:01 | 000,092,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAnimation.dll
[2011/12/18 10:42:00 | 003,815,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbon.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbonRes.dll
[2011/12/18 10:42:00 | 001,164,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIRibbonRes.dll
[2011/12/18 10:41:59 | 003,023,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIRibbon.dll
[2011/12/17 20:47:26 | 000,479,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/12/17 20:47:26 | 000,288,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/12/17 20:47:24 | 001,555,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/12/17 20:47:00 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\csrsrv.dll
[2011/12/17 20:46:59 | 000,316,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msshsq.dll
[2011/12/17 20:46:58 | 000,451,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/12/17 20:46:26 | 000,834,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/12/17 20:46:26 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/12/17 20:46:25 | 003,068,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xpsservices.dll
[2011/12/17 20:46:25 | 002,002,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/12/17 20:46:25 | 001,257,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFH264Dec.dll
[2011/12/17 20:46:25 | 000,979,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFH264Dec.dll
[2011/12/17 20:46:24 | 000,566,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2011/12/17 20:46:24 | 000,287,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10core.dll
[2011/12/17 20:46:24 | 000,047,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/12/17 20:46:23 | 001,461,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\OpcServices.dll
[2011/12/17 20:46:23 | 001,268,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10.dll
[2011/12/17 20:46:23 | 000,625,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxgi.dll
[2011/12/17 20:46:23 | 000,327,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/12/17 20:46:23 | 000,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/12/17 20:46:22 | 001,554,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\xpsservices.dll
[2011/12/17 20:46:22 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\OpcServices.dll
[2011/12/17 20:46:22 | 000,428,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFHEAACdec.dll
[2011/12/17 20:46:22 | 000,135,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/12/17 20:46:21 | 003,548,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mf.dll
[2011/12/17 20:46:21 | 001,032,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelinesvc.exe
[2011/12/17 20:46:21 | 000,377,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4src.dll
[2011/12/17 20:46:21 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winspool.drv
[2011/12/17 20:46:21 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2011/12/17 20:46:21 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4src.dll
[2011/12/17 20:46:21 | 000,261,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2011/12/17 20:46:20 | 002,873,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mf.dll
[2011/12/17 20:46:20 | 001,204,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2011/12/17 20:46:20 | 000,748,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2011/12/17 20:46:20 | 000,278,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfplat.dll
[2011/12/17 20:46:20 | 000,209,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfplat.dll
[2011/12/17 20:46:18 | 000,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfps.dll
[2011/12/17 20:46:17 | 000,035,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\printfilterpipelineprxy.dll
[2011/12/17 20:46:13 | 000,098,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfps.dll
[2011/12/17 20:46:13 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfpmp.exe
[2011/12/17 20:45:55 | 000,555,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,735,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UIAutomationCore.dll
[2011/12/17 20:45:54 | 000,332,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleacc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\oleaccrc.dll
[2011/12/17 20:45:54 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaccrc.dll
[2011/12/17 20:45:52 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/12/17 20:45:38 | 000,180,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/12/17 20:45:31 | 000,559,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/12/17 20:45:31 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/12/17 20:45:29 | 000,174,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/12/17 20:45:29 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/12/17 20:45:29 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/12/17 20:45:28 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/12/17 20:45:27 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/12/17 20:45:27 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/12/17 20:45:27 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/12/17 20:45:27 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/12/17 20:45:27 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/12/17 20:45:27 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/12/17 20:45:27 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/12/17 20:45:26 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/12/17 20:45:25 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/12/17 20:45:25 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/12/17 20:45:25 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/12/17 20:45:25 | 000,105,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/12/17 20:45:25 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/12/17 20:45:25 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/12/17 20:45:24 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/12/17 20:45:24 | 000,710,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/12/17 20:45:23 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/12/17 20:45:23 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/12/17 20:45:23 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/12/17 20:45:22 | 000,108,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/12/17 20:45:18 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/12/17 20:45:08 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/12/17 20:45:08 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/12/17 20:45:08 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/12/17 20:45:08 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/12/17 20:43:46 | 004,699,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/12/17 20:33:31 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisdecd.dll
[2011/12/17 20:33:31 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisdecd.dll
[2011/12/17 20:33:31 | 000,289,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psisrndr.ax
[2011/12/17 20:33:31 | 000,217,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\psisrndr.ax
[2011/12/17 20:33:31 | 000,100,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSDvbNP.ax
[2011/12/17 20:33:31 | 000,069,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Mpeg2Data.ax
[2011/12/17 20:33:31 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSDvbNP.ax
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\vi-VN
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\eu-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ca-ES
[2011/12/17 15:21:34 | 000,000,000 | —D | C] – C:\Windows\SysNative\ca-ES
[2011/12/17 15:21:33 | 000,000,000 | —D | C] – C:\Windows\SysNative\vi-VN
[2011/12/17 12:57:17 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2011/12/17 11:10:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/12/17 10:58:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Mechanic
[2011/12/17 10:57:46 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/17 08:52:46 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topckit_2011
[2011/12/16 23:32:40 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/12/16 23:06:28 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2011/12/16 23:06:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2011/12/16 23:06:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2011/12/16 23:06:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2011/12/16 23:05:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2011/12/16 23:05:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Surf Canyon
[2011/12/08 19:02:52 | 000,000,000 | —D | C] – C:\Users\Nando\AppData\Local\confobj90
[2011/12/07 18:41:31 | 000,252,296 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:31 | 000,188,808 | —- | C] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/03 09:36:22 | 000,499,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCP71.DLL
[2011/12/03 09:36:22 | 000,348,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSVCR71.DLL
[2011/12/03 09:36:21 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFC71.DLL
[2011/12/03 09:36:18 | 001,017,208 | —- | C] (CyberLink Corp.) – C:\Windows\SysWow64\CLVSD.ax
[2011/12/03 09:36:17 | 000,000,000 | —D | C] – C:\Program Files\Cucusoft
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/30 12:50:55 | 000,703,388 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/12/30 12:50:55 | 000,604,502 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/12/30 12:50:55 | 000,104,170 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/12/30 12:45:17 | 000,027,335 | —- | M] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2011/12/30 12:44:35 | 000,000,243 | —- | M] () – C:\Users\Public\Documents\hpqp.ini
[2011/12/30 12:44:03 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:43:16 | 000,003,216 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/30 12:42:56 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2011/12/30 12:15:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/29 23:29:32 | 000,000,680 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2011/12/29 22:15:15 | 085,491,386 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:49 | 000,020,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\tasks\RMSchedule.job
[2011/12/28 22:52:34 | 000,000,872 | —- | M] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/27 11:43:38 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/12/27 11:42:44 | 000,000,419 | —- | M] () – C:\Windows\BRWMARK.INI
[2011/12/27 11:42:44 | 000,000,027 | —- | M] () – C:\Windows\BRPP2KA.INI
[2011/12/21 12:11:05 | 561,550,750 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 16:28:24 | 002,744,532 | —- | M] () – C:\Windows\SysNative\drivers\Cat.DB
[2011/12/18 15:16:57 | 000,002,341 | —- | M] () – C:\Users\Nando\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/12/18 11:28:43 | 000,343,440 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/18 11:24:10 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | M] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | M] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:14:06 | 000,001,212 | —- | M] () – C:\Users\Nando\Desktop\exefix_vista.reg
[2011/12/17 09:06:24 | 000,000,732 | —- | M] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | M] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | M] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/15 19:47:05 | 000,000,334 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForNando.job
[2011/12/14 23:16:54 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2011/12/14 20:09:07 | 000,010,492 | -HS- | M] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:09:06 | 000,010,492 | -HS- | M] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/12 14:07:00 | 000,040,408 | —- | M] () – C:\Windows\SysNative\CleanMFT64.exe
[2011/12/10 15:24:08 | 000,023,152 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/12/07 18:41:20 | 000,627,600 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\deployJava1.dll
[2011/12/07 18:41:20 | 000,252,296 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaws.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\javaw.exe
[2011/12/07 18:41:20 | 000,188,808 | —- | M] (Oracle Corporation) – C:\Windows\SysNative\java.exe
[2011/12/05 18:46:03 | 000,025,600 | —- | M] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/03 09:36:22 | 000,001,002 | —- | M] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/29 22:15:15 | 085,491,386 | —- | C] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2011/12/29 22:14:48 | 000,020,592 | —- | C] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2011/12/28 22:52:34 | 000,000,872 | —- | C] () – C:\Users\Public\Desktop\AVG 2012.lnk
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2011/12/28 22:51:28 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2011/12/28 16:09:29 | 000,000,697 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2011/12/21 12:11:05 | 561,550,750 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/12/20 21:59:33 | 000,000,828 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2011/12/18 11:24:10 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/12/18 11:23:32 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/12/17 11:10:47 | 000,002,296 | —- | C] () – C:\Users\Nando\Desktop\sdsetup[1].exe.lnk
[2011/12/17 11:04:34 | 000,000,552 | —- | C] () – C:\Users\Nando\AppData\Local\d3d8caps.dat
[2011/12/17 10:58:14 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\PC Tools Registry Mechanic.lnk
[2011/12/17 10:57:47 | 000,002,306 | —- | C] () – C:\Users\Nando\Desktop\rminstall[1].exe.lnk
[2011/12/17 09:06:24 | 000,000,732 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps64.dat
[2011/12/17 08:52:47 | 000,000,857 | —- | C] () – C:\Users\Public\Desktop\Topckit_2011.lnk
[2011/12/16 23:05:48 | 000,001,777 | —- | C] () – C:\Users\Nando\Desktop\Free Music Downloads.lnk
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\Users\Nando\AppData\Local\ux2b0dfc1t117w1mm6c04
[2011/12/14 20:01:53 | 000,010,492 | -HS- | C] () – C:\ProgramData\ux2b0dfc1t117w1mm6c04
[2011/12/03 09:36:22 | 000,001,002 | —- | C] () – C:\Users\Public\Desktop\Cucusoft DVD Ripper + Video Converter Ultimate.lnk
[2011/01/26 22:04:57 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/09 22:56:19 | 000,000,000 | —- | C] () – C:\Windows\iplayer.INI
[2010/07/17 18:52:34 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/17 18:52:32 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/05/05 19:16:35 | 000,000,680 | —- | C] () – C:\Users\Nando\AppData\Local\d3d9caps.dat
[2010/04/06 18:27:03 | 000,047,616 | —- | C] () – C:\Windows\SysWow64\pdf995mon64.dll
[2010/04/06 18:27:03 | 000,000,142 | —- | C] () – C:\Windows\wpd99.drv
[2010/03/13 11:53:13 | 000,763,832 | —- | C] () – C:\Windows\BDTSupport.dll.old
[2010/03/07 16:14:19 | 000,023,114 | —- | C] () – C:\Windows\hpqins15.dat
[2010/03/06 22:47:17 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/03/06 22:46:53 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/03/06 22:46:32 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2010/03/04 20:15:04 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.001
[2010/03/04 20:09:34 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/03/04 20:09:34 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2010/03/03 16:54:45 | 000,027,335 | —- | C] () – C:\Users\Nando\AppData\Roaming\nvModes.dat
[2010/03/02 04:16:00 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2010/02/28 20:02:59 | 000,025,600 | —- | C] () – C:\Users\Nando\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/02/22 12:19:56 | 000,101,632 | —- | C] () – C:\Windows\hpqins13.dat
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2011/12/28 23:07:02 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\AVG2012
[2011/12/16 23:32:44 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\FreeFileViewer
[2011/09/12 16:49:48 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Helios
[2010/04/06 18:27:51 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\pdf995
[2011/07/16 16:46:17 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\PlayFirst
[2011/12/17 10:57:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Product_RM
[2011/12/18 11:47:53 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\Registry Mechanic
[2010/05/27 19:27:18 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TaxCut
[2011/12/17 11:10:46 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\TestApp
[2011/07/16 16:44:50 | 000,000,000 | —D | M] – C:\Users\Nando\AppData\Roaming\WildTangent
[2011/12/29 22:11:56 | 000,000,266 | —- | M] () – C:\Windows\Tasks\RMSchedule.job
[2011/12/30 12:40:47 | 000,032,536 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/01/30 21:36:06 | 000,000,434 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{A178F131-5775-4EDE-B6A0-A3D250D9CA70}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/11/19 15:48:18 | 000,000,047 | —- | M] () – C:\AUTOEXEC.BAT
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/02/22 11:29:01 | 000,000,384 | -H– | M] () – C:\IPH.PH
[2006/12/02 02:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/12/30 12:42:38 | 245,358,591 | -HS- | M] () – C:\pagefile.sys
[2011/12/20 21:15:18 | 000,000,370 | —- | M] () – C:\rkill.log
[2011/12/20 21:20:42 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.20.19_log.txt
[2011/12/20 21:28:16 | 000,000,348 | —- | M] () – C:\TDSSKiller.2.6.22.0_20.12.2011_21.28.05_log.txt
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2011/12/17 14:48:06 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
[2011/05/24 18:09:34 | 000,003,072 | —- | M] () – C:\Windows\system32\Cache.db
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/19 18:59:19 | 000,000,286 | -HS- | M] () – C:\Users\Nando\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/12/30 12:21:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Nando\Desktop\OTL.exe
[2010/12/12 16:20:00 | 000,512,992 | —- | M] () – C:\Users\Nando\Desktop\sdsetup[1].exe
[2008/08/05 11:35:52 | 027,141,384 | —- | M] (Maxis, a division of Electronic Arts Inc.) – C:\Users\Nando\Desktop\SporeApp.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
OTL Extras logfile created on: 12/30/2011 12:24:03 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Nando\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19170)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.94 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 38.95% Memory free
8.09 Gb Paging File | 5.51 Gb Available in Paging File | 68.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.14 Gb Total Space | 163.34 Gb Free Space | 57.28% Space Free | Partition Type: NTFS
Drive D: | 12.95 Gb Total Space | 2.43 Gb Free Space | 18.76% Space Free | Partition Type: NTFS
Computer Name: NANDO-LAPTOP | User Name: Nando | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
http [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = D7 9C 35 A7 FA BC CC 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
"C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe" = C:\Program Files (x86)\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink – (EarthLink, Inc.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{15133EB3-BAC9-474C-8F3F-B154E486D15C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{198930C5-8707-4EBA-8068-56C3B40AC958}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{215E8087-6F61-4A2B-BC04-41E8E1429FAA}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{39350F15-CF71-4204-9EEA-D280D6F79EC8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{3AE7C3FE-2358-4EDD-B7AC-7DF51F14D970}" = lport=139 | protocol=6 | dir=in | app=system |
"{462EF7E1-F0B5-47A4-AC22-41016C40F218}" = rport=139 | protocol=6 | dir=out | app=system |
"{489BED90-9315-49B8-9884-4D2DF3EEAA1D}" = rport=137 | protocol=17 | dir=out | app=system |
"{54790C89-38F2-4594-874C-1CAC651DF2E8}" = rport=445 | protocol=6 | dir=out | app=system |
"{551785C4-899D-4F0F-9C41-AD37CACB9BE9}" = rport=138 | protocol=17 | dir=out | app=system |
"{56345D86-61B4-42F3-9ED2-4BBE2C53830E}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{624DE384-7D94-42D1-ABF0-A1FB656C5B1F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9D94C86C-4B1C-496B-A969-647E3DA1DDCE}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{A9AF15C5-982F-4E28-B605-39979390CF8C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A9BE3B48-2459-46A6-BC8D-FBC7C24BF610}" = lport=445 | protocol=6 | dir=in | app=system |
"{BE72380F-F0BE-449C-B6E4-2A8D2CD73F97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{C9EC8183-ACA2-4BC4-A3AA-8D1838BB6A16}" = lport=138 | protocol=17 | dir=in | app=system |
"{D3939D16-5274-4531-90F5-3453B230C01F}" = lport=137 | protocol=17 | dir=in | app=system |
"{E13498DC-A6C6-46E1-9908-4CACCEDB3D44}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{EBB28CC8-E07B-4248-B46E-B0BF50C65116}" = lport=2869 | protocol=6 | dir=in | app=system |
"{FFC6A871-2C4E-402F-99BF-20C9E0596505}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{05377A32-4DF3-40BF-BC42-617A590E1F78}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{0B9AEFC6-0715-410E-B23D-F06839F1A148}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{109647F6-8FDA-479B-B52D-DE2AC5911B61}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{10CD19CB-B12A-4088-BCB3-975B1D4E0BE6}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{11B73F2B-ED14-4AF3-85A6-025E1A67039D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{22EC7A86-E344-411E-B39E-EFDFBF5A6482}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{2F7B2ECF-7F5C-49CE-A6D8-55CA7CD841DD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{302650D1-FECF-4BD9-914E-2D573C5119AE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{3197B78D-043F-4BA9-9405-8285904A61E9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{32CBB9C1-3A11-4D00-94C9-9D32BF0BA653}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{416D7402-714F-4290-99D4-AABB3CD5BB8C}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4ABD36B7-B516-4B2B-9846-334220638AB7}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{5A735C20-3FA4-48CD-ABE7-3FD036B17215}" = dir=in | app=c:\program files (x86)\hp\quickplay\qpservice.exe |
"{5C4329C8-1FB4-40E9-ABDA-6EC7E0F4BB07}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{61F7AD8E-139E-42B7-9C5C-A7BD525CFFBC}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{74606898-9BF7-4492-814D-DB7F0BE8FE7F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{75A591D0-61D9-4D1A-852C-619D342EA3AF}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{7EC89CF2-59BC-47F9-A740-25E6193D4B8B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |
"{9480CE52-8E38-4CE8-8C2C-C8DCB9E8039D}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{994FDA5B-6A99-44D9-B78D-98C669C66986}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{A3ED1A51-F422-4E40-8557-1A2459E3444E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |
"{A42972CF-C3D8-47DD-954C-95D54A3EA0CB}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A63327CF-0C72-4639-AD8F-700B5C701A3F}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{A816440F-685A-45C5-9DAB-6427F13E0C93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{A86FE271-78A0-4E9A-83E1-806609A23B33}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AC5911B7-43B2-46EE-BBC2-3BFC4F624A82}" = dir=in | app=c:\program files (x86)\hp\quickplay\qp.exe |
"{ADF4889E-426E-4957-A315-4FBBF52243CB}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{C4F099C9-90DF-4323-B044-A2A15C6D7204}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |
"{C9F24E41-583D-49A6-8A13-82BCB4B9D178}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{DA6D66EA-81F4-495D-AABB-D0AAC3D073C1}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{DED927DF-B9DE-4F68-81B3-D33123CB6504}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{E1A31D5B-F679-4E5D-8CBC-08B6BAF4D9C7}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{EC8E8471-F49F-473E-A62B-66AFB26956AF}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{F2F05428-15BD-4F78-BBF6-F9EADCBC276D}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"TCP Query User{31824B3D-BEA6-4578-A666-24E985B2F3D9}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
"UDP Query User{5828C114-88E7-40A6-8FFE-84271B674D7A}C:\program files (x86)\google\google earth\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\plugin\geplugin.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{11192F89-510C-4E23-A62A-D3BEA9139596}" = HP QuickTouch 1.00 C3
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{209CDA54-D390-46A2-A97C-7BF61734418D}" = WeatherBug Gadget
"{26A24AE4-039D-4CA4-87B4-2F86417001FF}" = Java™ 7 Update 1 (64-bit)
"{28D73032-5DAA-4F83-B154-85105DBCCB92}" = iTunes
"{41B19F41-8A6F-4422-AD69-CF3B408F382C}" = AVG 2012
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{64A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7 (64-bit)
"{64A3A4F4-B792-11D6-A78A-00B0D0170010}" = Java™ SE Development Kit 7 Update 1 (64-bit)
"{6D830209-41C2-4D6B-BA25-4EF98807D9FB}" = AVG 2012
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90B5B05F-AFDA-4922-A153-45B14200BA77}" = SPBBC 64bit
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A348C751-0EFF-4B9D-8065-B5339BEFBE27}" = HP Help and Support
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"AVG" = AVG 2012
"Broadcom 802.11b Network Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Drivers" = NVIDIA Drivers
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{06E74B9B-631F-4378-BF3A-40D868450C05}" = HPPhotoSmartPhotobookHolidayPack1
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0F907A69-6332-4F87-AD74-3C91A627D2C6}" = H&R; Block Virginia 2009
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{12A76360-388E-4B27-ABEB-D5FC5378DD2A}" = HPPhotoSmartPhotobookWebPack1
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{172AEB5E-CBB2-4CDD-A4CF-388600825839}" = HPPhotoSmartPhotobookPlayfulPack1
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2284D904-C138-4B58-93EC-5C362AB5130A}" = The Sims™ Life Stories
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{26A24AE4-039D-4CA4-87B4-2F83217000FF}" = Java™ 7
"{2934DCB0-F8EE-11E0-A4A5-B8AC6F97B88E}" = Google Earth Plug-in
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java™ SE Development Kit 7
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{38EAC694-0D90-445F-8C17-8B50ADFE3162}" = Slingbox Flash Tour
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40049394-98C6-409D-878D-E418B872D5D0}" = Comsift Service
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CACFCD9-F71B-413A-8DF5-1A6419D5CDC6}" = Cards_Calendar_OrderGift_DoMorePlugout
"{53A19323-917A-4822-B27E-A57D1EF6E9FC}" = H&R; Block Deluxe + Efile + State 2009
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5D87C09F-512F-474A-A306-0FE3B89C396F}" = RuneScape Launcher 1.0.4
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{89E052B2-5CA5-4B7A-AF0C-28CA2836B030}" = HPPhotoSmartPhotobookModernPack1
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{92A196AE-9B4D-499C-94D4-18FA2061B3CE}_is1" = Shop To Win
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{97F4D62E-5AEB-4649-BABF-4712C6EF6845}" = DeductionPro 2009
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A07840FC-CE63-4CB8-8030-EF4B9805925A}" = HPPhotoSmartDiscLabel_PaperLabel
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A82000000003}" = Adobe Reader 8.2.5
"{AC95121F-1576-45B8-82F7-3911D27882E6}" = HPPhotoSmartPhotobookScrapbookPack1
"{ADFB9653-F44C-460C-BF58-189CC552DFFE}" = hpphotosmartdisclabelplugin
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support
"{B4E91E95-A5BA-4E50-A465-DB7EFEB176E8}" = HPPhotoSmartDiscLabel_PrintOnDisc
"{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}" = HP User Guides 0090
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B6EC7388-E277-4A5B-8C8F-71067A41BA64}" = TextPad 5
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{DD3C88A0-C53C-41D0-A21B-6D021981D23E}" = HPPhotoSmartDiscLabelContent1
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E80F62FF-5D3C-4A19-8409-9721F2928206}" = LiveUpdate (Symantec Corporation)
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F636EE9A-F9EC-4606-BCFA-77DD0E210788}" = HPPhotoSmartDiscLabel_Tattoo
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"AIM_6" = AIM 6
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"Cucusoft Ultimate DVD + Video Converter Suite_is1" = Cucusoft Ultimate DVD + Video Converter Suite [removed]
"FreeFileViewer_is1" = Free File Viewer 2011
"Google Chrome" = Google Chrome
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{004B0DCB-4C60-465B-8F01-44B0A4111187}" = SlingPlayer
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InterActual Player" = InterActual Player
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.0.1800
"McAfee Security Scan" = McAfee Security Scan Plus
"Musicnotes Combined Installer_is1" = Musicnotes Software Suite 1.4.3
"Pdf995" = Pdf995 (installed by H&R; Block)
"PdfEdit995" = PdfEdit995 (installed by H&R; Block)
"Picasa 3" = Picasa 3
"PsuedoLiveUpdate" = LiveUpdate (Symantec Corporation)
"Registry Mechanic_is1" = PC Tools Registry Mechanic 11.0
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Surf Canyon" = Fast Search
"TI-83 Plus Flash Debugger" = TI-83 Plus Flash Debugger
"Trusted Software Assistant_is1" = File Type Assistant
"ViewpointMediaPlayer" = Viewpoint Media Player
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Software Update" = Yahoo! Software Update
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 681802
Error - 2/12/2011 11:06:14 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 681802
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 682894
Error - 2/12/2011 11:06:15 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 682894
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 684642
Error - 2/12/2011 11:06:17 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 684642
Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 2/12/2011 11:06:18 AM | Computer Name = Nando-Laptop | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 685905
[ Media Center Events ]
Error - 9/17/2010 9:02:48 PM | Computer Name = Nando-Laptop | Source = MCUpdate | ID = 0
Description = DownloadPackgeTask.SubTasksComplete: failed downloading package SportsSchedule.
[ OSession Events ]
Error - 12/8/2011 5:24:45 PM | Computer Name = Nando-Laptop | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6565.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 816
seconds with 420 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 6/1/2010 6:18:25 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:26 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:27 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:28 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:29 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:30 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:31 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
Error - 6/1/2010 6:18:32 PM | Computer Name = Nando-Laptop | Source = disk | ID = 262151
Description = The device, \Device\Harddisk1\DR2, has a bad block.
< End of report >