hansley
Topic Starter
Following my original post at Whatthetech's Browsers Thread I was prompted to follow a guide that led to my posting here.
To summarize, I recently found out that all my browsers (Chrome, Firefox, and even IE) keep crashing unexpectedly. Chrome takes a while to crash while Firefox crashes almost 1-2 minutes after opened.
I initally ran a Microsoft Safety Scanner upon which it removed 1 Trojan and then a Bit Defender's Deep System Scan which states all system are clean.
I, then, ran another Microsoft Safety Scanner and it removed another Trojan which led to my belief that the Trojan still exists somewhere in my system.
So I followed the steps that you have kindly provided and used the OTL scanner.
Here are my OTL.txt and Extras.txt from the OTL scan:
OTL.TXT
OTL logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS
Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Pidgin\pidgin.exe (The Pidgin developer community)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avutil-51.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avformat-53.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avcodec-53.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\txmlutil.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\framework.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\connector.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\SDL.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libcairo-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libgio-2.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libfontconfig-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpng14-14.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libexpat-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpangocairo-1.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\zlib1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\freetype6.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\spellchk.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppdisco.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppconsole.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ticker.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\win2ktrans.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\winprefs.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl-nss.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp_format.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\sendbutton.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\statenotify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\relnot.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmsn.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libqq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libgg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsilc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmxit.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsametime.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmyspace.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libnovell.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libirc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libbonjour.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsimple.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\log_reader.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\pidginrc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\notify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoo.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libxmpp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoojp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\markerline.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\offlinemsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libicq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\psychic.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\newline.dll ()
MOD - C:\Program Files (x86)\Pidgin\libjabber.dll ()
MOD - C:\Program Files (x86)\Pidgin\liboscar.dll ()
MOD - C:\Program Files (x86)\Pidgin\libymsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\convcolors.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\history.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\autoaccept.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\joinpart.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\idle.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\extplacement.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libaim.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\gtkbuddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\buddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\idletrack.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\iconaway.dll ()
MOD - C:\Program Files (x86)\Pidgin\exchndl.dll ()
MOD - C:\Program Files (x86)\Pidgin\spellcheck\libgtkspell-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\sqlite3.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilc-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilcclient-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libmeanwhile-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\libxml2-2.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Pidgin\libjson-glib-1.0.dll ()
MOD - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\MonitorEngRes.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ApplicationManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ACRHook.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ProtocolEngine.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\DeviceManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ErrorHandler.dll ()
MOD - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
MOD - C:\Program Files\ASUS\Six Engine\AsSpindownTimeout.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files\ASUS\Six Engine\pngio.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (Updatesrv) – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (Update Server) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV:64bit: - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (LVUVC64) Logitech HD Pro Webcam C910(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (CompFilter64) – C:\Windows\SysNative\drivers\lvbflt64.sys (Logitech Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (avckf) – C:\Windows\SysNative\drivers\avckf.sys (BitDefender)
DRV:64bit: - (avc3) – C:\Windows\SysNative\drivers\avc3.sys (BitDefender)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender)
DRV:64bit: - (Bdfndisf) – c:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys (BitDefender)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (bdfm) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (Bdvedisk) – C:\Windows\SysNative\drivers\bdvedisk.sys (BitDefender)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (DKRtWrt) – C:\Windows\SysNative\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KMWDFILTER) – C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (LGII2CDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\PII2CDriver.sys ()
DRV - (LGDDCDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\I2CDriver.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC B1 F2 F6 6B 40 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: [removed]:4.1.8
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.6.5
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDAPHFFEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDTBEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/01/09 22:56:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/01/09 22:58:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Firefox\components [2012/02/19 23:48:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins [2012/01/31 13:43:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\components [2012/02/20 15:08:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]
[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions
[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/29 23:45:45 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions
[2010/05/01 15:01:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/16 18:36:21 | 000,000,000 | —D | M] (FT SleekDark) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2011/12/25 10:57:04 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/29 16:56:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/12 12:33:56 | 000,000,000 | —D | M] (Chromifox Extreme) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxe@Triton
[2010/05/12 12:34:01 | 000,000,000 | —D | M] (Chromifox Companion) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxHelper@Triton
[2010/03/09 01:49:18 | 000,000,000 | —D | M] (Chromifox Basic) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\[removed]
[2012/02/29 23:45:27 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES (X86)\MOZILLA\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\sly\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Adobe Contribute CS5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npContribute.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: getPlusPlus for Adobe 16248 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Classic Blue Theme = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilkecpolncpdeefgdlnhmmdghkmonfkk\1.2_0\
CHR - Extension: Evernote Web Clipper = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.1.22.1457_0\
CHR - Extension: Gmail = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/01/28 12:08:32 | 000,007,354 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com #192.150.22.22
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com #192.150.14.21
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com #192.150.18.247
O1 - Hosts: 127.0.0.1 3dns-5.adobe.com #192.150.22.46
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com #192.150.11.30
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com #192.150.11.247
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com #192.150.22.30
O1 - Hosts: 127.0.0.1 adobe.activate.com #69.175.22.26
O1 - Hosts: 127.0.0.1 activate.adobe.com #192.150.22.40
O1 - Hosts: 109 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [googletalk] C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [taskhost.exe] C:\Users\sly\AppData\Roaming\System\taskhost.exe (Microsoft Corporation)
O4 - HKCU..\Run: [UpgradeChecker] C:\Users\sly\AppData\Roaming\Google Inc.\{87A61807-CF46-4468-8401-E0986FCB271A}\UpgradeChecker.exe (Promise Technology, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0AB410A2-FBE6-46EC-89B2-BFFB78C867CC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113C7E6C-950E-4621-B4EB-E2A87D3B157C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8503626F-D908-4BC5-9C21-AF42A88C37CF}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8C1AF6C-2D63-4D3D-A20D-4A000031F19A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell\AutoRun\command - "" = K:\INSTALL.EXE
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell\AutoRun\command - "" = M:\LaunchU3.exe -a
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell\AutoRun\command - "" = "K:\Adobe CS5\Set-up.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\Windows\SysWow64\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/01 11:52:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Google Inc
[2012/03/01 11:34:41 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{CAE59414-BCFE-4144-9E78-33CE034893A7}
[2012/03/01 11:34:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{AB2401EA-190B-4FDE-8963-F9138560F1F8}
[2012/03/01 00:46:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/01 00:46:46 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/02/29 23:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/02/29 23:45:25 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/29 23:33:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{971A30D9-E284-410E-98AA-C3DDDAA0DE46}
[2012/02/29 23:33:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BC2319CF-2001-4E36-9B37-2A2E4A3D1420}
[2012/02/29 08:31:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C7536067-4350-40E3-AC5C-81A216DB2FFA}
[2012/02/29 08:31:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C9713318-97F1-4C79-A467-EB79FB5B0F67}
[2012/02/28 22:08:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Help
[2012/02/28 22:04:23 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\TeamViewer
[2012/02/28 20:30:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{33D234F2-5FD3-4040-8189-72F81207340A}
[2012/02/28 20:30:22 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A1319534-0AF0-4699-81A7-94518F100241}
[2012/02/27 20:41:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C4CBAA1B-0E22-4914-A960-7D44D282A4AD}
[2012/02/27 20:41:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{065F7C43-7000-4074-9CF7-856B757E169F}
[2012/02/27 07:41:49 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{84E60DF3-7B51-417C-AC78-DF4977A5B71E}
[2012/02/27 07:41:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2E090832-0305-434D-8579-47155F6B3E0F}
[2012/02/26 12:26:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A57A52A-5AC2-4E5F-B9A9-168DE991909B}
[2012/02/26 12:26:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C87F948A-E3E8-44C9-9B06-5C0F88D30CCA}
[2012/02/25 15:37:29 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{175684E2-2717-44FB-A152-5594B342912A}
[2012/02/25 15:37:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A194CEE-97ED-4EF2-B2E3-B82299768885}
[2012/02/25 00:48:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4E61713D-A907-4BED-B2A3-2C9E797361A1}
[2012/02/25 00:48:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{79825E15-DC9C-4E50-8FC3-76F6EED7F96C}
[2012/02/24 07:05:45 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BDD89A75-1DCE-414A-A2F5-0C30ACB86281}
[2012/02/24 07:05:33 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{398718C1-44A3-40FC-A0D4-94C0E5E9FF3C}
[2012/02/23 18:57:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E0CE8F97-B0C2-4399-A893-F1E8A2C58736}
[2012/02/23 18:57:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{045F5F5F-E9D5-4A01-9F81-DC5F1B4EBB66}
[2012/02/22 23:05:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{859BE391-7D6D-4ABC-945C-A4A57AE07F82}
[2012/02/22 23:05:16 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5D118682-2527-43C7-A424-313B3B3A3122}
[2012/02/21 17:45:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{01A96671-7D41-4A2F-9680-BA30E1A84093}
[2012/02/21 17:45:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{214F46B1-8B65-4CA2-A2BF-06CC2DEE0F74}
[2012/02/20 20:25:08 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2CBD94CD-B65F-4652-ACD2-7D06FFED2426}
[2012/02/20 08:24:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BEBAC18E-1B2C-461F-81DA-20C0471B4D7B}
[2012/02/20 08:24:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F5962F4-D7D2-488E-861B-D1205BC337C8}
[2012/02/19 19:55:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{ECBB22B8-9AE4-4D60-9054-6C9AF43CEBB4}
[2012/02/19 19:55:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4FEC0536-7B23-469C-9ACF-93ADDBB526C7}
[2012/02/19 07:54:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1C7BF400-4F65-4DEE-BAF9-E215B32B8B6A}
[2012/02/19 07:54:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{889E9461-A852-4392-84CB-2E8667D47CEC}
[2012/02/18 13:33:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5245A670-6AE0-4044-8B6A-AC191CA82227}
[2012/02/18 13:33:17 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0C6A03D5-CC76-401C-ABC3-B660A38A06FB}
[2012/02/18 01:01:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1D50AF74-7F68-471F-A3B8-3090C18789FE}
[2012/02/18 01:01:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{20F161F3-DB0C-4041-9C99-D8943410985C}
[2012/02/17 08:48:59 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{70EF22B7-D3B8-443D-BC25-97C0CEA306D9}
[2012/02/17 08:48:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{987B3918-5D78-4B32-9463-2A8897359B84}
[2012/02/16 18:04:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{6F64E2F2-7262-4CD0-B12B-64B65CEBCD1C}
[2012/02/16 18:03:14 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{89E6E963-5F34-4396-8582-7C4302039F31}
[2012/02/15 18:09:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E330D309-9A52-4D48-AA56-BB6DC8BBCAC4}
[2012/02/15 18:09:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57C1C50D-C7D8-4F2E-8857-CFE58965C4EB}
[2012/02/14 19:54:22 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/14 19:54:22 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/14 19:54:21 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/14 19:54:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/14 19:54:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/14 19:54:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/14 19:54:21 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/14 19:54:21 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/14 19:54:21 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/14 19:54:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/14 19:54:20 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/14 18:08:43 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2012/02/14 18:08:42 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2012/02/14 18:08:42 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2012/02/14 18:08:39 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2012/02/14 18:03:25 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9A0538DD-4003-45E3-A1CD-E6591E129DE2}
[2012/02/14 18:03:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DABD846F-EEFF-4B36-83A0-7D2ADCBDA58A}
[2012/02/13 22:21:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57FECE42-E21B-47D2-B314-BDDA336CAEFB}
[2012/02/13 22:20:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{26C75DBB-ABE1-4B21-B2EE-E145C21FD632}
[2012/02/13 09:15:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A86E0609-FAF2-4962-ACB1-9B19D352D48E}
[2012/02/13 09:15:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{14A0188D-9F66-4A64-89BB-0167711D5ECA}
[2012/02/12 10:40:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4EA270CD-DE24-41F0-AE3E-917543D814D9}
[2012/02/12 10:40:00 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{200E6656-7B16-47DF-B555-72DBF0CA1D26}
[2012/02/11 22:39:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{589A6C85-52FF-4A79-BF17-0FD6B460BFA2}
[2012/02/11 22:39:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4AAF2A38-51C5-4D0F-86E4-373F46E2A3BB}
[2012/02/11 07:33:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{72AC5326-466C-46C8-A7EF-C24633283E27}
[2012/02/11 07:33:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{846A1738-02F9-4DD5-A89D-5B5633A5CBDD}
[2012/02/10 15:03:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8E5129DC-CFC1-4B50-BE9B-061E836A1AA9}
[2012/02/10 15:03:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9926D961-4888-4A1A-8E51-18AC522A6D4E}
[2012/02/10 00:14:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{D5F5A715-4A3D-4A22-B468-4DB6897A2DA3}
[2012/02/10 00:14:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4C4228D5-BD62-4E0D-B89B-BF9B965F2EE1}
[2012/02/09 07:14:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F80D8C4A-0E44-4775-8896-E7E7083987B8}
[2012/02/09 07:13:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DFABECFC-3F79-42DC-B26F-BD7F4A20B800}
[2012/02/08 17:39:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BE1B4DA1-503E-40B3-B809-4F8A5850B4D3}
[2012/02/08 17:39:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F98B7A1-94F3-4C98-B48B-500A8A054504}
[2012/02/07 17:48:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{22F7537F-383A-4CC0-A15D-B08AD0A8B67F}
[2012/02/07 17:48:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2253ECFB-E112-4F98-AA63-1DF681AFD71D}
[2012/02/06 21:58:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{701A4F6E-BD9F-45B9-88E1-EA0E8E67A05E}
[2012/02/06 21:58:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8A633E12-7965-4132-8173-989B89D77F04}
[2012/02/06 21:52:22 | 000,000,000 | —D | C] – C:\ProgramData\bdch
[2012/02/06 20:14:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A92AB1C-02B3-4FFB-B69B-F645580EDEFE}
[2012/02/06 08:14:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{85F1C51F-9DC3-4EED-8E8A-7D568A85D204}
[2012/02/06 08:14:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F588E6B7-6849-48F1-A970-2639BB6C9AF7}
[2012/02/05 12:12:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{39176875-37F2-4CE9-8CF1-5A08D7BEBECE}
[2012/02/05 12:12:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{69D93C8C-46E1-4307-8C97-48E283A1699A}
[2012/02/05 00:12:13 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0CD7477B-DD62-497D-B94F-675772293E6A}
[2012/02/05 00:12:01 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{15EF6C68-D7B0-4A68-8AE7-9A3CAFA5C46C}
[2012/02/04 12:11:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5737E8C5-B87E-4218-9EA9-F42886CDEEAE}
[2012/02/04 12:11:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8ED08EDF-6E0F-4081-8910-B4BCEF00FD98}
[2012/02/04 00:10:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{088ED07F-6F18-40D9-ABCC-8542CC6DE598}
[2012/02/04 00:10:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{52171174-8C5B-4195-9CA9-6C882E5B3FC3}
[2012/02/03 07:19:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{86E4D813-4C3D-4EFF-91B0-EE066EDAC3B5}
[2012/02/03 07:19:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{114E7C52-8843-4367-A385-8401DBAD1BD1}
[2012/02/02 11:25:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{EE8BB213-621F-4C7F-A866-19CCFA43301F}
[2012/02/02 11:24:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A979982-EDCB-4587-9177-6FCC5CFB6218}
[2012/02/01 22:54:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8638BE4E-8419-4C77-9FEC-19E0F1D172B1}
[2012/02/01 22:53:58 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{3A6C1013-00E5-48AD-91BD-F71290CE419D}
[2012/02/01 07:44:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F39178BB-C6E0-476E-A21E-8725D286F28F}
[2012/02/01 07:43:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{741C4826-DDFE-491B-A60D-3C5285B1C3F6}
[2012/01/31 13:18:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9B84A0E4-A949-4F45-B8DA-F8F194D94DC0}
[2012/01/31 13:18:39 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DF4EF07A-A10E-4DA8-8EB7-9095E6B6F9DE}
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:46:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 11:29:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000UA.job
[2012/03/01 08:28:36 | 000,753,670 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/01 08:28:36 | 000,632,930 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/01 08:28:36 | 000,110,564 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/29 23:45:22 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2012/02/29 23:45:22 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/02/20 15:08:38 | 000,002,095 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/02/18 14:29:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000Core.job
[2012/02/17 08:49:14 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/14 21:28:06 | 006,656,208 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/10 11:06:57 | 000,002,029 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/01 12:57:52 | 000,000,000 | -HS- | C] () – C:\DkHyperbootSync
[2012/03/01 12:05:30 | 000,003,304 | —- | C] () – C:\bootsqm.dat
[2012/03/01 00:56:23 | 001,124,574 | —- | C] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/31 13:43:51 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/10/25 10:03:18 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/25 10:03:15 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/14 23:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/08/19 01:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 01:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 01:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/05/23 07:39:24 | 000,542,363 | —- | C] () – C:\ProgramData\bdinstall.bin
[2010/12/14 20:05:42 | 000,001,456 | —- | C] () – C:\Users\sly\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/11/08 09:27:13 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2010/10/05 14:31:42 | 000,175,104 | —- | C] () – C:\Users\sly\AppData\Roaming\sly3SQLite3.dll
[2010/09/30 20:58:57 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/09/28 07:45:09 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/09/28 07:45:09 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/28 07:45:08 | 002,931,712 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2010/09/28 07:45:08 | 000,790,528 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/09/28 07:45:08 | 000,134,144 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/09/28 07:45:08 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/08 09:37:14 | 000,101,544 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2010/04/17 22:28:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/04/16 10:13:00 | 000,003,140 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/04/16 10:13:00 | 000,000,008 | RHS- | C] () – C:\ProgramData\A145BC7D98.sys
[2010/04/15 23:09:07 | 000,000,037 | —- | C] () – C:\Windows\SWFConverter.INI
[2010/04/15 23:04:06 | 000,000,091 | —- | C] () – C:\Users\sly\AppData\Local\fusioncache.dat
[2010/04/15 22:11:31 | 000,000,025 | —- | C] () – C:\Users\sly\AppData\Roaming\bdfvconp.ini
[2010/04/08 14:55:10 | 000,034,308 | —- | C] () – C:\Windows\SysWow64\BASSMOD.dll
========== LOP Check ==========
[2012/03/01 13:12:26 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\.purple
[2010/01/11 14:38:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Activision
[2009/08/10 23:32:15 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Amazon
[2011/05/23 08:12:44 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\BitDefender
[2010/06/29 13:15:30 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/22 10:34:38 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2009/12/16 14:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\cYo
[2012/03/01 00:57:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\DAEMON Tools Lite
[2012/01/04 17:08:04 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Eclipsit
[2012/03/01 00:49:25 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\FileZilla
[2010/06/09 09:47:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Genie-Soft
[2011/07/16 15:46:10 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\go
[2010/11/20 18:40:50 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\gtk-2.0
[2009/11/30 17:01:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\HDRsoft
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Image Zone Express
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Leadertech
[2010/10/15 23:33:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LightZone
[2010/07/17 00:14:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LolClient
[2011/10/25 09:33:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Origin
[2010/10/15 23:34:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PACE Anti-Piracy
[2011/07/27 13:44:47 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PandoraRecovery
[2009/10/29 16:56:49 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Printer Info Cache
[2010/04/08 14:56:55 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Publish Providers
[2011/05/23 08:03:34 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\QuickScan
[2010/10/16 13:35:35 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Research In Motion
[2010/04/08 14:55:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Sony
[2010/07/14 10:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2005/12/23 22:12:24 | 000,000,000 | RHSD | M] – C:\Users\sly\AppData\Roaming\System
[2012/03/01 08:07:16 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\TeamViewer
[2010/09/02 23:25:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Thunderbird
[2012/03/01 00:57:23 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\uTorrent
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\Tasks\GBM - Easy Layout Backup Job-Full.job
[2012/01/19 07:28:05 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/03/01 12:11:54 | 000,702,773 | —- | M] () – C:\bdlog.txt
[2011/04/20 08:29:01 | 012,054,781 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.log
[2011/04/20 08:29:01 | 000,133,272 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.reg
[2010/11/20 04:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2009/10/29 17:32:21 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2007/02/01 00:31:12 | 000,338,944 | —- | M] (Hewlett-Packard) – C:\hpzids40.dll
[2012/03/01 12:46:08 | 2137,120,767 | -HS- | M] () – C:\pagefile.sys
[2011/05/13 21:48:23 | 000,000,000 | —- | M] () – C:\pcversion.txt
[2009/08/08 01:38:25 | 000,000,473 | —- | M] () – C:\RHDSetup.log
[2011/10/25 10:31:35 | 000,019,518 | —- | M] () – C:\shared.log
[2009/08/08 01:50:13 | 000,000,057 | —- | M] () – C:\splash.idx
[2008/11/18 09:25:20 | 000,005,632 | -H– | M] () – C:\version
< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/10 15:20:50 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/04/20 10:56:10 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 1243 bytes -> C:\Users\sly\AppData\Local\Temp:kvGL6aJIXvCIAINCN9lmuG3
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS
Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] – Reg Error: Key error. File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.js [@ = jsfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{858CCC22-7029-4426-B4D5-58C38742EBD3}" = Diskeeper 2010 Pro Premier
"{8BBA6F77-4A79-4E90-BD82-E24669ACF221}" = Adobe Photoshop Lightroom 3.4.1 64-bit
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}" = BitDefender Total Security 2011
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"BitDefender" = BitDefender Total Security 2011
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.111
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"Shop for HP Supplies" = Shop for HP Supplies
"Wacom Tablet Driver" = Wacom Tablet
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{23C12370-3A82-4558-B727-F345B473AD87}" = BlackBerry Device Software Updater
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}" = Sony Sound Forge 9.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A0494B41-EBD7-4C0D-91B7-DC39741B27BB}" = Express Gate
"{A31951C5-DCD8-4DFE-A525-CFC701F54792}" = TurboV
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B369483E-0728-405C-8F8C-3427B263B01F}" = Content
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B9CA59A0-3B70-48F8-9054-67595DE6E72B}" = League of Legends
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C9A162C1-031F-4EBF-A3E6-C45F7FCCBB9E}_is1" = Genie Backup Assistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}" = Sony Noise Reduction Plug-In 2.0e
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA6FAB8D-E87A-4E8E-A3D3-B7B9F479C725}" = forteManager
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1845F1C-068C-F8F4-D31D-D3540D47C453}" = Adobe Download Assistant
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EF6E783C-339A-49EB-9872-DE0F131DE5DA}" = BlackBerry Device Software v5.0.0 for the BlackBerry 9000 smartphone
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB9DD41D-533E-42C6-8C27-B67086C04EC0}" = 11N Wireless USB Adapter
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Akamai" = Akamai NetSession Interface Service
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.5
"ASF-AVI-RM-WMV Repair_is1" = ASF-AVI-RM-WMV Repair 1.83
"AVS Screen Capture_is1" = AVS Screen Capture version 1.1.2
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 5
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.dmp.contentviewer" = Adobe Content Viewer
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"ESN Sonar-0.70.4" = ESN Sonar
"FileZilla Client" = FileZilla Client 3.5.2
"Free 3GP Video Converter_is1" = Free 3GP Video Converter version 3.2
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 3.2
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.4.0
"LaCie Device Updater" = LaCie Device Updater
"Logitech Vid" = Logitech Vid HD
"Microangelo Creation" = Microangelo Creation
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Mozilla Thunderbird 10.0.2 (x86 en-US)" = Mozilla Thunderbird 10.0.2 (x86 en-US)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Origin" = Origin
"PandoraRecovery" = PandoraRecovery (Remove Only)
"Picasa 3" = Picasa 3
"Pidgin" = Pidgin
"PunkBusterSvc" = PunkBuster Services
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Akamai" = Akamai NetSession Interface
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/1/2012 4:03:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf39b4bb2 Faulting process id:
0x2380 Faulting application start time: 0x01ccf781b84f0653 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: fd1ef90e-6374-11e1-be9d-002618360274
Error - 3/1/2012 4:19:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf7354bb2 Faulting process id:
0x138 Faulting application start time: 0x01ccf783f49675db Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 395d19a3-6377-11e1-be9d-002618360274
Error - 3/1/2012 4:35:02 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf6404bb2 Faulting process id:
0x590 Faulting application start time: 0x01ccf78631036f50 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 6f9256da-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:35:10 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf64f4bb2 Faulting process id:
0x1478 Faulting application start time: 0x01ccf78630ed75fe Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 749908b1-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:38:56 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf34518a7 Faulting process id: 0x3c8 Faulting application
start time: 0x01ccf786bbb4170f Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: fb09ace2-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:41:34 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf32818a7 Faulting process id: 0x2258 Faulting application
start time: 0x01ccf7871a929adc Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 59370686-637a-11e1-be9d-002618360274
Error - 3/1/2012 4:59:59 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf1bc18a7 Faulting process id: 0x2328 Faulting application
start time: 0x01ccf789ad4786a3 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: ebf28216-637c-11e1-9873-002618360274
Error - 3/1/2012 10:02:57 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf9a84b44 Faulting process id: 0x964 Faulting application
start time: 0x01ccf7b3f8741d44 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 3f04b251-63a7-11e1-9873-002618360274
Error - 3/1/2012 12:27:44 PM | Computer Name = hansley-pc | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ASP.NET State Service since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 3/1/2012 12:36:54 PM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: bdtkexec.exe, version: 14.0.28.143, time
stamp: 0x4dcd1deb Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7c92c Exception code: 0xc0000005 Fault offset: 0x0000000000029fa6 Faulting
process id: 0x1f78 Faulting application start time: 0x01ccf7c803d52445 Faulting application
path: C:\Program Files\BitDefender\BitDefender 2011\bdtkexec.exe Faulting module
path: C:\Windows\system32\ole32.dll Report Id: c09b7086-63bc-11e1-9873-002618360274
[ System Events ]
Error - 2/28/2012 12:52:14 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 2/28/2012 1:55:07 AM | Computer Name = hansley-pc | Source = BROWSER | ID = 8032
Description =
Error - 2/29/2012 12:29:43 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.
Error - 2/29/2012 12:29:44 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053
Error - 2/29/2012 12:11:17 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.
Error - 2/29/2012 12:11:18 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053
Error - 2/29/2012 8:23:38 PM | Computer Name = hansley-pc | Source = WMPNetworkSvc | ID = 866300
Description =
Error - 3/1/2012 4:43:37 AM | Computer Name = hansley-pc | Source = VDS Basic Provider | ID = 33554433
Description =
Error - 3/1/2012 4:54:04 AM | Computer Name = hansley-pc | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:51:13 AM on ?3/?1/?2012 was unexpected.
Error - 3/1/2012 8:34:17 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
< End of report >
To summarize, I recently found out that all my browsers (Chrome, Firefox, and even IE) keep crashing unexpectedly. Chrome takes a while to crash while Firefox crashes almost 1-2 minutes after opened.
I initally ran a Microsoft Safety Scanner upon which it removed 1 Trojan and then a Bit Defender's Deep System Scan which states all system are clean.
I, then, ran another Microsoft Safety Scanner and it removed another Trojan which led to my belief that the Trojan still exists somewhere in my system.
So I followed the steps that you have kindly provided and used the OTL scanner.
Here are my OTL.txt and Extras.txt from the OTL scan:
OTL.TXT
OTL logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS
Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\pchooklaunch32.exe (BitDefender S.R.L.)
PRC - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\bdimguiaux.exe (BitDefender S.R.L.)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Pidgin\pidgin.exe (The Pidgin developer community)
PRC - C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
PRC - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
PRC - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avutil-51.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avformat-53.dll ()
MOD - C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\avcodec-53.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\txmlutil.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\framework.dll ()
MOD - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\connector.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\SDL.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libcairo-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libgio-2.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libfontconfig-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpng14-14.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libexpat-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\libpangocairo-1.0-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\lib\gtk-2.0\2.10.0\engines\libwimp.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\zlib1.dll ()
MOD - C:\Program Files (x86)\Pidgin\Gtk\bin\freetype6.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\spellchk.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppdisco.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\xmppconsole.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ticker.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\win2ktrans.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\winprefs.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl-nss.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp_format.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\timestamp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\sendbutton.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\statenotify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\relnot.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\ssl.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmsn.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libqq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libgg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsilc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmxit.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsametime.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libmyspace.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libnovell.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libirc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libbonjour.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libsimple.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\log_reader.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\pidginrc.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\notify.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoo.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libxmpp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libyahoojp.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\markerline.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\offlinemsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libicq.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\psychic.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\newline.dll ()
MOD - C:\Program Files (x86)\Pidgin\libjabber.dll ()
MOD - C:\Program Files (x86)\Pidgin\liboscar.dll ()
MOD - C:\Program Files (x86)\Pidgin\libymsg.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\convcolors.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\history.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\autoaccept.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\joinpart.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\idle.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\extplacement.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\libaim.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\gtkbuddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\buddynote.dll ()
MOD - C:\Program Files (x86)\Pidgin\idletrack.dll ()
MOD - C:\Program Files (x86)\Pidgin\plugins\iconaway.dll ()
MOD - C:\Program Files (x86)\Pidgin\exchndl.dll ()
MOD - C:\Program Files (x86)\Pidgin\spellcheck\libgtkspell-0.dll ()
MOD - C:\Program Files (x86)\Pidgin\sqlite3.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilc-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libsilcclient-1-1-2.dll ()
MOD - C:\Program Files (x86)\Pidgin\libmeanwhile-1.dll ()
MOD - C:\Program Files (x86)\Pidgin\libxml2-2.dll ()
MOD - C:\Program Files (x86)\Yahoo!\Messenger\yui.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Pidgin\libjson-glib-1.0.dll ()
MOD - C:\Program Files (x86)\Drivers\Logitech\SetPoint\x86\SetPoint32.exe ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\Monitor.exe ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\MonitorEngRes.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ApplicationManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ACRHook.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ProtocolEngine.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\DeviceManager.dll ()
MOD - C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\ErrorHandler.dll ()
MOD - C:\Program Files\ASUS\Six Engine\SixEngine.exe ()
MOD - C:\Program Files\ASUS\Six Engine\AsSpindownTimeout.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\gs_encryption.dll ()
MOD - C:\Program Files (x86)\LaCie\Genie Backup Assistant\GSLogging.dll ()
MOD - C:\Windows\SysWOW64\AsIO.dll ()
MOD - C:\Program Files\ASUS\Six Engine\pngio.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (TabletServiceWacom) – C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV:64bit: - (Updatesrv) – C:\Program Files\BitDefender\BitDefender 2011\updatesrv.exe (BitDefender S.R.L.)
SRV:64bit: - (VSSERV) – C:\Program Files\BitDefender\BitDefender 2011\vsserv.exe (BitDefender S.R.L.)
SRV:64bit: - (Update Server) – C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe (BitDefender)
SRV:64bit: - (Diskeeper) – C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe (Diskeeper Corporation)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_7de0ed9.dll ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (getPlusHelper) getPlus® – C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll (NOS Microsystems Ltd.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (AsSysCtrlService) – C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.00\AsSysCtrlService.exe ()
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (LVUVC64) Logitech HD Pro Webcam C910(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (CompFilter64) – C:\Windows\SysNative\drivers\lvbflt64.sys (Logitech Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bdfsfltr) – C:\Windows\SysNative\drivers\bdfsfltr.sys (BitDefender)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (avckf) – C:\Windows\SysNative\drivers\avckf.sys (BitDefender)
DRV:64bit: - (avc3) – C:\Windows\SysNative\drivers\avc3.sys (BitDefender)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (bdfwfpf) – C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfwfpf.sys (BitDefender)
DRV:64bit: - (Bdfndisf) – c:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdfndisf6.sys (BitDefender)
DRV:64bit: - (ivusb) – C:\Windows\SysNative\drivers\ivusb.sys (Initio Corporation)
DRV:64bit: - (bdfm) – C:\Windows\SysNative\drivers\bdfm.sys (BitDefender S.R.L. Bucharest, ROMANIA)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (adfs) – C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (Bdvedisk) – C:\Windows\SysNative\drivers\bdvedisk.sys (BitDefender)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (DKRtWrt) – C:\Windows\SysNative\drivers\DKRtWrt.sys (Diskeeper Corporation)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (netr28ux) – C:\Windows\SysNative\drivers\netr28ux.sys (Ralink Technology Corp.)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ROOTMODEM) – C:\Windows\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (KMWDFILTER) – C:\Windows\SysNative\drivers\KMWDFILTER.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (RimVSerPort) – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (LGII2CDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\PII2CDriver.sys ()
DRV - (LGDDCDevice) – C:\Program Files (x86)\Drivers\LG Soft India\forteManager\bin\I2CDriver.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FC B1 F2 F6 6B 40 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3DEA5FE7-8C23-4836-9427-C0B06DAE5DC8}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1
FF - prefs.js..extensions.enabledItems: 6
FF - prefs.js..extensions.enabledItems: 2
FF - prefs.js..extensions.enabledItems: 48
FF - prefs.js..extensions.enabledItems: [removed]:2.0
FF - prefs.js..extensions.enabledItems: cfxHelper@Triton:1.2
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: [removed]:4.1.8
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:3.6.5
FF - prefs.js..extensions.enabledItems: cfxe@Triton:3.6.5
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDAPHFFEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\PROGRAM FILES\BITDEFENDER\BITDEFENDER 2011\BDTBEXT\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdaphffext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/01/09 22:56:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/01/09 22:58:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Firefox\components [2012/02/19 23:48:27 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins [2012/01/31 13:43:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\components [2012/02/20 15:08:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 10.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\BitDefender\BitDefender 2011\bdtbext\ [2011/12/23 10:00:21 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/12/20 02:24:08 | 000,000,000 | —D | M]
[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions
[2010/09/02 23:25:57 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/29 23:45:45 | 000,000,000 | —D | M] (No name found) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions
[2010/05/01 15:01:32 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/02/16 18:36:21 | 000,000,000 | —D | M] (FT SleekDark) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{a21cd440-41d6-11e0-9207-0800200c9a66}
[2011/12/25 10:57:04 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/10/29 16:56:48 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/05/12 12:33:56 | 000,000,000 | —D | M] (Chromifox Extreme) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxe@Triton
[2010/05/12 12:34:01 | 000,000,000 | —D | M] (Chromifox Companion) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\cfxHelper@Triton
[2010/03/09 01:49:18 | 000,000,000 | —D | M] (Chromifox Basic) – C:\Users\sly\AppData\Roaming\mozilla\Firefox\Profiles\ks3zdvup.default\extensions\[removed]
[2012/02/29 23:45:27 | 000,000,000 | —D | M] (Java Console) – C:\PROGRAM FILES (X86)\MOZILLA\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SLY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\KS3ZDVUP.DEFAULT\EXTENSIONS\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\sly\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\sly\AppData\Local\Google\Chrome\Application\17.0.963.56\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Adobe Contribute CS5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npContribute.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: getPlusPlus for Adobe 16248 (Enabled) = C:\Program Files (x86)\Mozilla\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: ESN Launch Mozilla Plugin (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll
CHR - plugin: ESN Sonar API (Enabled) = C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\sly\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Classic Blue Theme = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilkecpolncpdeefgdlnhmmdghkmonfkk\1.2_0\
CHR - Extension: Evernote Web Clipper = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.1.22.1457_0\
CHR - Extension: Gmail = C:\Users\sly\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2011/01/28 12:08:32 | 000,007,354 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com #192.150.22.22
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com #192.150.14.21
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com #192.150.18.247
O1 - Hosts: 127.0.0.1 3dns-5.adobe.com #192.150.22.46
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com #192.150.11.30
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com #192.150.11.247
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com #192.150.22.30
O1 - Hosts: 127.0.0.1 adobe.activate.com #69.175.22.26
O1 - Hosts: 127.0.0.1 activate.adobe.com #192.150.22.40
O1 - Hosts: 109 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Bitdefender Toolbar) - {381FFDE8-2394-4F90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ietoolbar.dll (BitDefender S.R.L.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BDAgent] C:\Program Files\BitDefender\BitDefender 2011\bdagent.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\ieshow.exe (BitDefender S.R.L.)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BitDefender Antiphishing Helper] C:\Program Files\BitDefender\BitDefender 2011\Antispam32\ieshow.exe (BitDefender S.R.L.)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\sly\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [GBMLite8AgentLaCie] C:\Program Files (x86)\LaCie\Genie Backup Assistant\GBMAgent.exe (Genie-soft)
O4 - HKCU..\Run: [googletalk] C:\Users\sly\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [taskhost.exe] C:\Users\sly\AppData\Roaming\System\taskhost.exe (Microsoft Corporation)
O4 - HKCU..\Run: [UpgradeChecker] C:\Users\sly\AppData\Roaming\Google Inc.\{87A61807-CF46-4468-8401-E0986FCB271A}\UpgradeChecker.exe (Promise Technology, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Se&nd; to OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105 File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0AB410A2-FBE6-46EC-89B2-BFFB78C867CC}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{113C7E6C-950E-4621-B4EB-E2A87D3B157C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8503626F-D908-4BC5-9C21-AF42A88C37CF}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F8C1AF6C-2D63-4D3D-A20D-4A000031F19A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O24 - Desktop WallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\sly\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{2c0b70e2-8142-11df-acab-002618360274}\Shell\AutoRun\command - "" = K:\INSTALL.EXE
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{5604181f-80bf-11e0-9db8-002618360274}\Shell\AutoRun\command - "" = M:\LaunchU3.exe -a
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell - "" = AutoRun
O33 - MountPoints2\{cdf6e30e-d4df-11de-b542-002618360274}\Shell\AutoRun\command - "" = "K:\Adobe CS5\Set-up.exe"
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\divxa32.acm (Kristal StudioDFileDescription)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.dvsd - C:\Windows\SysWow64\pdvcodec.dll (Matsushita Electric Industrial Co., Ltd.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.HFYU - C:\Windows\SysWow64\huffyuv.dll (Disappearing Inc.)
Drivers32: vidc.i263 - C:\Windows\SysWow64\I263_32.drv (Intel Corporation)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv41 - C:\Windows\SysWow64\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.VP60 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP61 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP62 - C:\Windows\SysWow64\vp6vfw.dll (On2.com)
Drivers32: VIDC.VP70 - C:\Windows\SysWow64\vp7vfw.dll (On2.com)
Drivers32: VIDC.X264 - C:\Windows\SysWow64\x264vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/01 11:52:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Google Inc
[2012/03/01 11:34:41 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{CAE59414-BCFE-4144-9E78-33CE034893A7}
[2012/03/01 11:34:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{AB2401EA-190B-4FDE-8963-F9138560F1F8}
[2012/03/01 00:46:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/03/01 00:46:46 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/02/29 23:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2012/02/29 23:45:25 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:25 | 000,149,280 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/29 23:33:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{971A30D9-E284-410E-98AA-C3DDDAA0DE46}
[2012/02/29 23:33:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BC2319CF-2001-4E36-9B37-2A2E4A3D1420}
[2012/02/29 08:31:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C7536067-4350-40E3-AC5C-81A216DB2FFA}
[2012/02/29 08:31:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C9713318-97F1-4C79-A467-EB79FB5B0F67}
[2012/02/28 22:08:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\Help
[2012/02/28 22:04:23 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Roaming\TeamViewer
[2012/02/28 20:30:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{33D234F2-5FD3-4040-8189-72F81207340A}
[2012/02/28 20:30:22 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A1319534-0AF0-4699-81A7-94518F100241}
[2012/02/27 20:41:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C4CBAA1B-0E22-4914-A960-7D44D282A4AD}
[2012/02/27 20:41:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{065F7C43-7000-4074-9CF7-856B757E169F}
[2012/02/27 07:41:49 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{84E60DF3-7B51-417C-AC78-DF4977A5B71E}
[2012/02/27 07:41:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2E090832-0305-434D-8579-47155F6B3E0F}
[2012/02/26 12:26:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A57A52A-5AC2-4E5F-B9A9-168DE991909B}
[2012/02/26 12:26:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{C87F948A-E3E8-44C9-9B06-5C0F88D30CCA}
[2012/02/25 15:37:29 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{175684E2-2717-44FB-A152-5594B342912A}
[2012/02/25 15:37:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A194CEE-97ED-4EF2-B2E3-B82299768885}
[2012/02/25 00:48:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4E61713D-A907-4BED-B2A3-2C9E797361A1}
[2012/02/25 00:48:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{79825E15-DC9C-4E50-8FC3-76F6EED7F96C}
[2012/02/24 07:05:45 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BDD89A75-1DCE-414A-A2F5-0C30ACB86281}
[2012/02/24 07:05:33 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{398718C1-44A3-40FC-A0D4-94C0E5E9FF3C}
[2012/02/23 18:57:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E0CE8F97-B0C2-4399-A893-F1E8A2C58736}
[2012/02/23 18:57:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{045F5F5F-E9D5-4A01-9F81-DC5F1B4EBB66}
[2012/02/22 23:05:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{859BE391-7D6D-4ABC-945C-A4A57AE07F82}
[2012/02/22 23:05:16 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5D118682-2527-43C7-A424-313B3B3A3122}
[2012/02/21 17:45:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{01A96671-7D41-4A2F-9680-BA30E1A84093}
[2012/02/21 17:45:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{214F46B1-8B65-4CA2-A2BF-06CC2DEE0F74}
[2012/02/20 20:25:08 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2CBD94CD-B65F-4652-ACD2-7D06FFED2426}
[2012/02/20 08:24:31 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BEBAC18E-1B2C-461F-81DA-20C0471B4D7B}
[2012/02/20 08:24:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F5962F4-D7D2-488E-861B-D1205BC337C8}
[2012/02/19 19:55:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{ECBB22B8-9AE4-4D60-9054-6C9AF43CEBB4}
[2012/02/19 19:55:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4FEC0536-7B23-469C-9ACF-93ADDBB526C7}
[2012/02/19 07:54:48 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1C7BF400-4F65-4DEE-BAF9-E215B32B8B6A}
[2012/02/19 07:54:32 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{889E9461-A852-4392-84CB-2E8667D47CEC}
[2012/02/18 13:33:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5245A670-6AE0-4044-8B6A-AC191CA82227}
[2012/02/18 13:33:17 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0C6A03D5-CC76-401C-ABC3-B660A38A06FB}
[2012/02/18 01:01:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1D50AF74-7F68-471F-A3B8-3090C18789FE}
[2012/02/18 01:01:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{20F161F3-DB0C-4041-9C99-D8943410985C}
[2012/02/17 08:48:59 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{70EF22B7-D3B8-443D-BC25-97C0CEA306D9}
[2012/02/17 08:48:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{987B3918-5D78-4B32-9463-2A8897359B84}
[2012/02/16 18:04:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{6F64E2F2-7262-4CD0-B12B-64B65CEBCD1C}
[2012/02/16 18:03:14 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{89E6E963-5F34-4396-8582-7C4302039F31}
[2012/02/15 18:09:30 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{E330D309-9A52-4D48-AA56-BB6DC8BBCAC4}
[2012/02/15 18:09:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57C1C50D-C7D8-4F2E-8857-CFE58965C4EB}
[2012/02/14 19:54:22 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/02/14 19:54:22 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/02/14 19:54:21 | 002,308,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/02/14 19:54:21 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/02/14 19:54:21 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/02/14 19:54:21 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/02/14 19:54:21 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/02/14 19:54:21 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/02/14 19:54:21 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/02/14 19:54:21 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/02/14 19:54:20 | 001,493,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/02/14 18:08:43 | 000,509,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntshrui.dll
[2012/02/14 18:08:42 | 000,515,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\timedate.cpl
[2012/02/14 18:08:42 | 000,478,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\timedate.cpl
[2012/02/14 18:08:39 | 000,634,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msvcrt.dll
[2012/02/14 18:03:25 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9A0538DD-4003-45E3-A1CD-E6591E129DE2}
[2012/02/14 18:03:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DABD846F-EEFF-4B36-83A0-7D2ADCBDA58A}
[2012/02/13 22:21:06 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{57FECE42-E21B-47D2-B314-BDDA336CAEFB}
[2012/02/13 22:20:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{26C75DBB-ABE1-4B21-B2EE-E145C21FD632}
[2012/02/13 09:15:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{A86E0609-FAF2-4962-ACB1-9B19D352D48E}
[2012/02/13 09:15:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{14A0188D-9F66-4A64-89BB-0167711D5ECA}
[2012/02/12 10:40:12 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4EA270CD-DE24-41F0-AE3E-917543D814D9}
[2012/02/12 10:40:00 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{200E6656-7B16-47DF-B555-72DBF0CA1D26}
[2012/02/11 22:39:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{589A6C85-52FF-4A79-BF17-0FD6B460BFA2}
[2012/02/11 22:39:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4AAF2A38-51C5-4D0F-86E4-373F46E2A3BB}
[2012/02/11 07:33:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{72AC5326-466C-46C8-A7EF-C24633283E27}
[2012/02/11 07:33:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{846A1738-02F9-4DD5-A89D-5B5633A5CBDD}
[2012/02/10 15:03:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8E5129DC-CFC1-4B50-BE9B-061E836A1AA9}
[2012/02/10 15:03:05 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9926D961-4888-4A1A-8E51-18AC522A6D4E}
[2012/02/10 00:14:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{D5F5A715-4A3D-4A22-B468-4DB6897A2DA3}
[2012/02/10 00:14:27 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4C4228D5-BD62-4E0D-B89B-BF9B965F2EE1}
[2012/02/09 07:14:07 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F80D8C4A-0E44-4775-8896-E7E7083987B8}
[2012/02/09 07:13:35 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DFABECFC-3F79-42DC-B26F-BD7F4A20B800}
[2012/02/08 17:39:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{BE1B4DA1-503E-40B3-B809-4F8A5850B4D3}
[2012/02/08 17:39:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{1F98B7A1-94F3-4C98-B48B-500A8A054504}
[2012/02/07 17:48:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{22F7537F-383A-4CC0-A15D-B08AD0A8B67F}
[2012/02/07 17:48:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{2253ECFB-E112-4F98-AA63-1DF681AFD71D}
[2012/02/06 21:58:43 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{701A4F6E-BD9F-45B9-88E1-EA0E8E67A05E}
[2012/02/06 21:58:21 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8A633E12-7965-4132-8173-989B89D77F04}
[2012/02/06 21:52:22 | 000,000,000 | —D | C] – C:\ProgramData\bdch
[2012/02/06 20:14:54 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0A92AB1C-02B3-4FFB-B69B-F645580EDEFE}
[2012/02/06 08:14:28 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{85F1C51F-9DC3-4EED-8E8A-7D568A85D204}
[2012/02/06 08:14:15 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F588E6B7-6849-48F1-A970-2639BB6C9AF7}
[2012/02/05 12:12:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{39176875-37F2-4CE9-8CF1-5A08D7BEBECE}
[2012/02/05 12:12:38 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{69D93C8C-46E1-4307-8C97-48E283A1699A}
[2012/02/05 00:12:13 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{0CD7477B-DD62-497D-B94F-675772293E6A}
[2012/02/05 00:12:01 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{15EF6C68-D7B0-4A68-8AE7-9A3CAFA5C46C}
[2012/02/04 12:11:36 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{5737E8C5-B87E-4218-9EA9-F42886CDEEAE}
[2012/02/04 12:11:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8ED08EDF-6E0F-4081-8910-B4BCEF00FD98}
[2012/02/04 00:10:44 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{088ED07F-6F18-40D9-ABCC-8542CC6DE598}
[2012/02/04 00:10:24 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{52171174-8C5B-4195-9CA9-6C882E5B3FC3}
[2012/02/03 07:19:26 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{86E4D813-4C3D-4EFF-91B0-EE066EDAC3B5}
[2012/02/03 07:19:11 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{114E7C52-8843-4367-A385-8401DBAD1BD1}
[2012/02/02 11:25:03 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{EE8BB213-621F-4C7F-A866-19CCFA43301F}
[2012/02/02 11:24:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{4A979982-EDCB-4587-9177-6FCC5CFB6218}
[2012/02/01 22:54:19 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{8638BE4E-8419-4C77-9FEC-19E0F1D172B1}
[2012/02/01 22:53:58 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{3A6C1013-00E5-48AD-91BD-F71290CE419D}
[2012/02/01 07:44:10 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{F39178BB-C6E0-476E-A21E-8725D286F28F}
[2012/02/01 07:43:53 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{741C4826-DDFE-491B-A60D-3C5285B1C3F6}
[2012/01/31 13:18:50 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{9B84A0E4-A949-4F45-B8DA-F8F194D94DC0}
[2012/01/31 13:18:39 | 000,000,000 | —D | C] – C:\Users\sly\AppData\Local\{DF4EF07A-A10E-4DA8-8EB7-9095E6B6F9DE}
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:54:18 | 000,011,136 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/01 12:46:13 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 11:29:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000UA.job
[2012/03/01 08:28:36 | 000,753,670 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/03/01 08:28:36 | 000,632,930 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/03/01 08:28:36 | 000,110,564 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/29 23:45:22 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2012/02/29 23:45:22 | 000,157,472 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/02/29 23:45:22 | 000,149,280 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\tasks\GBM - Easy Layout Backup Job-Full.job
[2012/02/20 15:08:38 | 000,002,095 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/02/18 14:29:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2825036124-2352061616-2705343857-1000Core.job
[2012/02/17 08:49:14 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/14 21:28:06 | 006,656,208 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/10 11:06:57 | 000,002,029 | —- | M] () – C:\Users\sly\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[43 E:\*.tmp files -> E:\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/01 12:57:52 | 000,000,000 | -HS- | C] () – C:\DkHyperbootSync
[2012/03/01 12:05:30 | 000,003,304 | —- | C] () – C:\bootsqm.dat
[2012/03/01 00:56:23 | 001,124,574 | —- | C] () – C:\cc_20120301_005612.reg
[2012/03/01 00:46:50 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/31 13:43:51 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/01/31 13:43:51 | 000,001,979 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/10/25 10:03:18 | 000,280,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/25 10:03:15 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/14 23:54:52 | 000,321,856 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/08/19 01:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 01:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 01:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/05/23 07:39:24 | 000,542,363 | —- | C] () – C:\ProgramData\bdinstall.bin
[2010/12/14 20:05:42 | 000,001,456 | —- | C] () – C:\Users\sly\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/11/08 09:27:13 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2010/10/05 14:31:42 | 000,175,104 | —- | C] () – C:\Users\sly\AppData\Roaming\sly3SQLite3.dll
[2010/09/30 20:58:57 | 000,000,132 | —- | C] () – C:\Users\sly\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/09/28 07:45:09 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2010/09/28 07:45:09 | 000,000,038 | —- | C] () – C:\Windows\avisplitter.ini
[2010/09/28 07:45:08 | 002,931,712 | —- | C] () – C:\Windows\SysWow64\x264vfw.dll
[2010/09/28 07:45:08 | 000,790,528 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/09/28 07:45:08 | 000,134,144 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/09/28 07:45:08 | 000,108,032 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/07/08 09:37:14 | 000,101,544 | —- | C] () – C:\Program Files\Common Files\LinkInstaller.exe
[2010/04/17 22:28:25 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/04/16 10:13:00 | 000,003,140 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2010/04/16 10:13:00 | 000,000,008 | RHS- | C] () – C:\ProgramData\A145BC7D98.sys
[2010/04/15 23:09:07 | 000,000,037 | —- | C] () – C:\Windows\SWFConverter.INI
[2010/04/15 23:04:06 | 000,000,091 | —- | C] () – C:\Users\sly\AppData\Local\fusioncache.dat
[2010/04/15 22:11:31 | 000,000,025 | —- | C] () – C:\Users\sly\AppData\Roaming\bdfvconp.ini
[2010/04/08 14:55:10 | 000,034,308 | —- | C] () – C:\Windows\SysWow64\BASSMOD.dll
========== LOP Check ==========
[2012/03/01 13:12:26 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\.purple
[2010/01/11 14:38:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Activision
[2009/08/10 23:32:15 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Amazon
[2011/05/23 08:12:44 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\BitDefender
[2010/06/29 13:15:30 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/22 10:34:38 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2009/12/16 14:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\cYo
[2012/03/01 00:57:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\DAEMON Tools Lite
[2012/01/04 17:08:04 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Eclipsit
[2012/03/01 00:49:25 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\FileZilla
[2010/06/09 09:47:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Genie-Soft
[2011/07/16 15:46:10 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\go
[2010/11/20 18:40:50 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\gtk-2.0
[2009/11/30 17:01:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\HDRsoft
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Image Zone Express
[2009/10/29 16:56:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Leadertech
[2010/10/15 23:33:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LightZone
[2010/07/17 00:14:24 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\LolClient
[2011/10/25 09:33:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Origin
[2010/10/15 23:34:37 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PACE Anti-Piracy
[2011/07/27 13:44:47 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\PandoraRecovery
[2009/10/29 16:56:49 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Printer Info Cache
[2010/04/08 14:56:55 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Publish Providers
[2011/05/23 08:03:34 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\QuickScan
[2010/10/16 13:35:35 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Research In Motion
[2010/04/08 14:55:32 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Sony
[2010/07/14 10:39:06 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2005/12/23 22:12:24 | 000,000,000 | RHSD | M] – C:\Users\sly\AppData\Roaming\System
[2012/03/01 08:07:16 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\TeamViewer
[2010/09/02 23:25:57 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\Thunderbird
[2012/03/01 00:57:23 | 000,000,000 | —D | M] – C:\Users\sly\AppData\Roaming\uTorrent
[2012/02/28 23:35:59 | 000,000,448 | —- | M] () – C:\Windows\Tasks\GBM - Easy Layout Backup Job-Full.job
[2012/01/19 07:28:05 | 000,032,640 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/03/01 12:11:54 | 000,702,773 | —- | M] () – C:\bdlog.txt
[2011/04/20 08:29:01 | 012,054,781 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.log
[2011/04/20 08:29:01 | 000,133,272 | —- | M] () – C:\BdUninstallTool2011.04.20-09.28.18.reg
[2010/11/20 04:40:07 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2009/10/29 17:32:21 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/03/01 12:05:30 | 000,003,304 | —- | M] () – C:\bootsqm.dat
[2012/03/01 00:56:31 | 001,124,574 | —- | M] () – C:\cc_20120301_005612.reg
[2012/03/01 12:57:52 | 000,000,000 | -HS- | M] () – C:\DkHyperbootSync
[2012/03/01 12:46:05 | 529,096,703 | -HS- | M] () – C:\hiberfil.sys
[2007/02/01 00:31:12 | 000,338,944 | —- | M] (Hewlett-Packard) – C:\hpzids40.dll
[2012/03/01 12:46:08 | 2137,120,767 | -HS- | M] () – C:\pagefile.sys
[2011/05/13 21:48:23 | 000,000,000 | —- | M] () – C:\pcversion.txt
[2009/08/08 01:38:25 | 000,000,473 | —- | M] () – C:\RHDSetup.log
[2011/10/25 10:31:35 | 000,019,518 | —- | M] () – C:\shared.log
[2009/08/08 01:50:13 | 000,000,057 | —- | M] () – C:\splash.idx
[2008/11/18 09:25:20 | 000,005,632 | -H– | M] () – C:\version
< %systemroot%\Fonts\*.com >
[2009/07/13 21:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 21:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 21:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 21:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 12:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 20:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/08/10 15:20:50 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/04/20 10:56:10 | 000,000,221 | -HS- | M] () – C:\Users\sly\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 1243 bytes -> C:\Users\sly\AppData\Local\Temp:kvGL6aJIXvCIAINCN9lmuG3
< End of report >
EXTRAS.TXT
OTL Extras logfile created on: 3/1/2012 1:04:55 PM - Run 1
OTL by OldTimer - Version 3.2.34.0 Folder = E:\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.99 Gb Total Physical Memory | 3.45 Gb Available Physical Memory | 57.59% Memory free
11.98 Gb Paging File | 8.35 Gb Available in Paging File | 69.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 155.62 Gb Free Space | 55.69% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 337.91 Gb Free Space | 36.28% Space Free | Partition Type: NTFS
Computer Name: HANSLEY-PC | User Name: sly | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = jsfile] – Reg Error: Key error. File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.js [@ = jsfile] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05EFBF37-0E52-4579-875C-7EEF0DFB4FCB}" = Network64
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{17016DA1-F040-4032-BD36-34DD317BC9D5}" = HP Photosmart All-In-One Driver Software 13.0 Rel. A
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}" = IconHandler 64 bit
"{55D55008-E5F6-47D6-B16F-B2A40D4D145F}" = 64 Bit HP CIO Components Installer
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{858CCC22-7029-4426-B4D5-58C38742EBD3}" = Diskeeper 2010 Pro Premier
"{8BBA6F77-4A79-4E90-BD82-E24669ACF221}" = Adobe Photoshop Lightroom 3.4.1 64-bit
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 285.62
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.11.0621
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.5.20
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B6CA7A3C-35FD-401F-9335-FFFD2BCD5FF3}" = BitDefender Total Security 2011
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F3F18612-7B5D-4C05-86C9-AB50F6F71727}" = KhalInstallWrapper
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"6af12c54-643b-4752-87d0-8335503010de_is1" = Nexus Mod Manager
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit
"BitDefender" = BitDefender Total Security 2011
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.111
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"KLiteCodecPack64_is1" = K-Lite Codec Pack (64-bit) v2.6.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"Shop for HP Supplies" = Shop for HP Supplies
"Wacom Tablet Driver" = Wacom Tablet
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0DEF8C02-2EAB-4BFE-A7E0-7990665DF1A9}" = C6100
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{1AED4ABF-0852-4B3F-9F87-00CF88F25CE0}" = IconHandler 32 bit
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{23C12370-3A82-4558-B727-F345B473AD87}" = BlackBerry Device Software Updater
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{28F8F8F0-C278-454A-9507-46B344AAD188}" = Corel Painter 11
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A7EF808-14F3-4E93-BE3A-1675EE5332A4}" = AIO_CDA_ProductContext
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A1B5D40-41E9-43FA-8C7B-A8667F5586EF}" = JMicron JMB36X Driver
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4BD5B5D2-406D-4bc5-BB10-2F0D1D367C95}" = c6100_Help
"{4E33D05D-76CF-5D3C-4D5D-7727530FA161}" = Adobe Content Viewer
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4F41AD68-89F2-4262-A32C-2F70B01FCE9E}" = Photo Story 3 for Windows
"{56B83336-FBC1-4C46-8613-90A9E3B440D6}" = EPU-6 Engine
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5B51BB5F-4E7C-4275-A653-E98534E9C1D2}" = Corel Painter 11 - ICA
"{5D9B17E4-5C34-45B2-9C95-8B9DB4CF7AF3}" = HP_Network_UserGuide
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6842DCCB-2840-4E46-8AF3-BEA9CFF3455B}" = Sony Sound Forge 9.0
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{76285C16-411A-488A-BCE3-C83CB933D8CF}" = Battlefield 3™
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7EC69F77-5494-4E1F-8BC6-956DAA5A91F2}" = Corel Painter 11 - IPM
"{7F6D7FD9-648D-4DD9-BB6E-3990C675ECA4}" = NVIDIA PhysX
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{840BF2FE-033D-437C-89D1-AAA206BA13B6}" = Langauge
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A0494B41-EBD7-4C0D-91B7-DC39741B27BB}" = Express Gate
"{A31951C5-DCD8-4DFE-A525-CFC701F54792}" = TurboV
"{A498D9EB-927B-459B-85D6-DD6EF8C2C564}" = erLT
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7AEE29F-839E-46B5-B347-6D430618129F}" = AIO_CDA_Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.2)
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B0069CFA-5BB9-4C03-B1C6-89CE290E5AFE}" = HP Update
"{B369483E-0728-405C-8F8C-3427B263B01F}" = Content
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B9CA59A0-3B70-48F8-9054-67595DE6E72B}" = League of Legends
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BDE646E8-86E0-50E1-37BC-0AEBB2185D76}" = Adobe Widget Browser
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C86E7C99-E4AD-79C7-375B-1AEF9A91EC2B}" = Acrobat.com
"{C9A162C1-031F-4EBF-A3E6-C45F7FCCBB9E}_is1" = Genie Backup Assistant
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D533C9D4-ED96-4191-B9C3-279C0DD6BABA}" = Sony Noise Reduction Plug-In 2.0e
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D86B0E2E-DF9A-441C-AF77-8D1A0FF00FA6}" = AIO_Scan
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA6FAB8D-E87A-4E8E-A3D3-B7B9F479C725}" = forteManager
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1845F1C-068C-F8F4-D31D-D3540D47C453}" = Adobe Download Assistant
"{E2883E8F-472F-4fb0-9522-AC9BF37916A7}" = Adobe Download Manager
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EF6E783C-339A-49EB-9872-DE0F131DE5DA}" = BlackBerry Device Software v5.0.0 for the BlackBerry 9000 smartphone
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}" = Logitech SetPoint
"{FA54AFB1-5745-4389-B8C1-9F7509672ED1}" = iPhone Configuration Utility
"{FB9DD41D-533E-42C6-8C27-B67086C04EC0}" = 11N Wireless USB Adapter
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Akamai" = Akamai NetSession Interface Service
"Amazon MP3 Downloader" = Amazon MP3 Downloader 1.0.5
"ASF-AVI-RM-WMV Repair_is1" = ASF-AVI-RM-WMV Repair 1.83
"AVS Screen Capture_is1" = AVS Screen Capture version 1.1.2
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS Video Editor_is1" = AVS Video Editor 5
"AVS Video Recorder_is1" = AVS Video Recorder 2.4
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.4
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.1
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"com.adobe.dmp.contentviewer" = Adobe Content Viewer
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1" = Adobe Widget Browser
"ESN Sonar-0.70.4" = ESN Sonar
"FileZilla Client" = FileZilla Client 3.5.2
"Free 3GP Video Converter_is1" = Free 3GP Video Converter version 3.2
"Free Video to MP3 Converter_is1" = Free Video to MP3 Converter version 3.2
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 6.4.0
"LaCie Device Updater" = LaCie Device Updater
"Logitech Vid" = Logitech Vid HD
"Microangelo Creation" = Microangelo Creation
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 10.0.2 (x86 en-US)" = Mozilla Firefox 10.0.2 (x86 en-US)
"Mozilla Thunderbird 10.0.2 (x86 en-US)" = Mozilla Thunderbird 10.0.2 (x86 en-US)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Origin" = Origin
"PandoraRecovery" = PandoraRecovery (Remove Only)
"Picasa 3" = Picasa 3
"Pidgin" = Pidgin
"PunkBusterSvc" = PunkBuster Services
"Uninstall_is1" = Uninstall 1.0.0.1
"uTorrent" = µTorrent
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"Akamai" = Akamai NetSession Interface
"Game Organizer" = EasyBits GO
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 3/1/2012 4:03:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf39b4bb2 Faulting process id:
0x2380 Faulting application start time: 0x01ccf781b84f0653 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: fd1ef90e-6374-11e1-be9d-002618360274
Error - 3/1/2012 4:19:12 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf7354bb2 Faulting process id:
0x138 Faulting application start time: 0x01ccf783f49675db Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 395d19a3-6377-11e1-be9d-002618360274
Error - 3/1/2012 4:35:02 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf6404bb2 Faulting process id:
0x590 Faulting application start time: 0x01ccf78631036f50 Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 6f9256da-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:35:10 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 9.0.8112.16421,
time stamp: 0x4d76255d Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0xf64f4bb2 Faulting process id:
0x1478 Faulting application start time: 0x01ccf78630ed75fe Faulting application path:
C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path: unknown
Report
Id: 749908b1-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:38:56 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf34518a7 Faulting process id: 0x3c8 Faulting application
start time: 0x01ccf786bbb4170f Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: fb09ace2-6379-11e1-be9d-002618360274
Error - 3/1/2012 4:41:34 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf32818a7 Faulting process id: 0x2258 Faulting application
start time: 0x01ccf7871a929adc Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 59370686-637a-11e1-be9d-002618360274
Error - 3/1/2012 4:59:59 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf1bc18a7 Faulting process id: 0x2328 Faulting application
start time: 0x01ccf789ad4786a3 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: ebf28216-637c-11e1-9873-002618360274
Error - 3/1/2012 10:02:57 AM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: firefox.exe, version: 10.0.2.4428, time
stamp: 0x4f3cdb2a Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0xf9a84b44 Faulting process id: 0x964 Faulting application
start time: 0x01ccf7b3f8741d44 Faulting application path: C:\Program Files (x86)\Mozilla\Mozilla
Firefox\firefox.exe Faulting module path: unknown Report Id: 3f04b251-63a7-11e1-9873-002618360274
Error - 3/1/2012 12:27:44 PM | Computer Name = hansley-pc | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ASP.NET State Service since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 3/1/2012 12:36:54 PM | Computer Name = hansley-pc | Source = Application Error | ID = 1000
Description = Faulting application name: bdtkexec.exe, version: 14.0.28.143, time
stamp: 0x4dcd1deb Faulting module name: ole32.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7c92c Exception code: 0xc0000005 Fault offset: 0x0000000000029fa6 Faulting
process id: 0x1f78 Faulting application start time: 0x01ccf7c803d52445 Faulting application
path: C:\Program Files\BitDefender\BitDefender 2011\bdtkexec.exe Faulting module
path: C:\Windows\system32\ole32.dll Report Id: c09b7086-63bc-11e1-9873-002618360274
[ System Events ]
Error - 2/28/2012 12:52:14 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
Error - 2/28/2012 1:55:07 AM | Computer Name = hansley-pc | Source = BROWSER | ID = 8032
Description =
Error - 2/29/2012 12:29:43 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.
Error - 2/29/2012 12:29:44 AM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053
Error - 2/29/2012 12:11:17 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Windows
Font Cache Service service to connect.
Error - 2/29/2012 12:11:18 PM | Computer Name = hansley-pc | Source = Service Control Manager | ID = 7000
Description = The Windows Font Cache Service service failed to start due to the
following error: %%1053
Error - 2/29/2012 8:23:38 PM | Computer Name = hansley-pc | Source = WMPNetworkSvc | ID = 866300
Description =
Error - 3/1/2012 4:43:37 AM | Computer Name = hansley-pc | Source = VDS Basic Provider | ID = 33554433
Description =
Error - 3/1/2012 4:54:04 AM | Computer Name = hansley-pc | Source = EventLog | ID = 6008
Description = The previous system shutdown at 12:51:13 AM on ?3/?1/?2012 was unexpected.
Error - 3/1/2012 8:34:17 AM | Computer Name = hansley-pc | Source = volsnap | ID = 393252
Description = The shadow copies of volume C: were aborted because the shadow copy
storage could not grow due to a user imposed limit.
< End of report >