Results of screen317's Security Check version 0.99.64
Windows Vista Service Pack 1 x86 (UAC is enabled)
Out of date service pack!!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
AVG AntiVirus Free Edition 2013
Norton 360
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Java™ 6 Update 6
Java version out of Date!
Adobe Flash Player 9
Flash Player out of Date!
Adobe Reader 9
Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Norton ccSvcHst.exe
AVG avgwdsvc.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 9 %
Defragment your hard drive soon! (Do NOT defrag if SSD!)
````````````````````End of Log``````````````````````
OTL logfile created on: 6/7/2013 7:38:10 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Luci\Desktop
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.54 Gb Available Physical Memory | 53.58% Memory free
5.95 Gb Paging File | 4.77 Gb Available in Paging File | 80.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 224.20 Gb Total Space | 197.47 Gb Free Space | 88.07% Space Free | Partition Type: NTFS
Drive E: | 1.91 Gb Total Space | 0.25 Gb Free Space | 13.35% Space Free | Partition Type: FAT
Unable to calculate disk information.
Computer Name: LUCI-PC | User Name: Luci | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Luci\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Google\Google Toolbar\Update\gtb231C.tmp.exe (Google Inc.)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgemcx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcfgex.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\TSS.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba Registration\Registration.exe (DataLode, Inc.)
PRC - C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
PRC - C:\Program Files\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll ()
MOD - C:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll ()
MOD - C:\Program Files\Google\Google Desktop Search\gzlib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll ()
MOD - C:\Program Files\Toshiba\FlashCards\BlackPng.dll ()
MOD - C:\Program Files\Toshiba\PCDiag\NotifyPCD.dll ()
MOD - C:\Program Files\Toshiba\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Program Files\Toshiba\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Program Files\Toshiba\TOSHIBA Disc Creator\NotifyTDC.dll ()
========== Services (SafeList) ==========
SRV - (Partner Service) – C:\ProgramData\Partner\partner.exe (Google Inc.)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Symantec Core LC) – C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ()
SRV - (TMachInfo) – C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TNaviSrv) – C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (GameConsoleService) – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (ConfigFree Service) – C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (IAANTMON) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE (Symantec Corporation)
SRV - (Automatic LiveUpdate Scheduler) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe (Symantec Corporation)
SRV - (LiveUpdate Notice) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (CLTNetCnService) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (TosCoSrv) – C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\Toshiba\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (comHost) – C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe (Symantec Corporation)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (SymEvent) – C:\Windows\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (SymIM) – C:\Windows\System32\drivers\SymIMV.sys (Symantec Corporation)
DRV - (IDSvix86) – C:\ProgramData\Symantec\Definitions\SymcData\ipsdefs\20080215.001\IDSvix86.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20080213.036\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20080213.036\NAVENG.SYS (Symantec Corporation)
DRV - (SYMTDI) – C:\Windows\System32\drivers\symtdi.sys (Symantec Corporation)
DRV - (SYMREDRV) – C:\Windows\System32\drivers\symredrv.sys (Symantec Corporation)
DRV - (SRTSPL) – C:\Windows\System32\drivers\srtspl.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\System32\drivers\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\System32\drivers\srtspx.sys (Symantec Corporation)
DRV - (SPBBCDrv) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (RTL8187B) – C:\Windows\System32\drivers\rtl8187B.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (CO_Mon) – C:\Windows\System32\drivers\CO_Mon.sys (Symantec Corporation)
DRV - (RtlProt) – C:\Windows\System32\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\System32\drivers\KR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\System32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKLM\..\SearchScopes,DefaultScope = {31430E5C-6BB3-4916-A0D6-9508400F7AF0}
IE - HKLM\..\SearchScopes\{31430E5C-6BB3-4916-A0D6-9508400F7AF0}: "URL" =
http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSHB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/ig/redirectdomain?br…B&bmod;=TSHB
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {31430E5C-6BB3-4916-A0D6-9508400F7AF0}
IE - HKCU\..\SearchScopes\{31430E5C-6BB3-4916-A0D6-9508400F7AF0}: "URL" =
http://www.google.com/search?sourceid=ie7&…1I7TSHB_enUS539
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Reg Error: Value error.) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Common Files\Symantec Shared\IDS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\partner.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll (Symantec Corporation)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [cfFncEnabler.exe] cfFncEnabler.exe File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [osCheck] C:\Program Files\Norton 360\osCheck.exe (Symantec Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\Toshiba\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files\TOSHIBA\TOSHIBA Service Station\TSS.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TP CfgWiz] C:\Program Files\Common Files\Symantec Shared\OPC\{C86EA115-FACD-4aa8-BFA2-398C677D0936}\SymCuw.exe (Symantec Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [951738463] C:\Program Files\Toshiba Registration\Registration.exe (DataLode, Inc.)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (Sun Microsystems, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10001D4B-21D5-4585-978D-4B039C159A7C}: DhcpNameServer = 8.8.8.8 8.8.4.4 [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\toshiba_1920x1200-2.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\toshiba_1920x1200-2.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/06/07 19:36:02 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Luci\Desktop\OTL.exe
[2013/06/07 19:01:18 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\Macromedia
[2013/06/07 19:01:16 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\Adobe
[2013/06/07 18:59:47 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\Google
[2013/06/07 18:50:27 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\AVG2013
[2013/06/07 18:49:33 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\TuneUp Software
[2013/06/07 18:49:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/06/07 18:49:13 | 000,000,000 | -H-D | C] – C:\$AVG
[2013/06/07 18:49:12 | 000,000,000 | —D | C] – C:\ProgramData\AVG2013
[2013/06/07 18:47:43 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2013/06/07 18:44:41 | 000,000,000 | -H-D | C] – C:\ProgramData\Common Files
[2013/06/07 18:44:41 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\MFAData
[2013/06/07 18:44:41 | 000,000,000 | —D | C] – C:\ProgramData\MFAData
[2013/06/07 18:44:41 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\Avg2013
[2013/06/07 18:44:12 | 004,463,288 | —- | C] (AVG Technologies) – C:\Users\Luci\Desktop\avg_free_stb_all_2013_3343_cnet.exe
[2013/06/07 18:20:12 | 000,000,000 | —D | C] – C:\Windows\System32\WindowsPowerShell
[2013/06/07 17:19:15 | 000,105,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll
[2013/06/07 17:19:15 | 000,097,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardapi.dll
[2013/06/07 17:19:14 | 000,622,080 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardagt.exe
[2013/06/07 17:19:14 | 000,043,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2013/06/07 17:19:14 | 000,037,384 | —- | C] (Microsoft Corporation) – C:\Windows\System32\infocardcpl.cpl
[2013/06/07 17:19:14 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\icardres.dll
[2013/06/07 17:19:13 | 000,781,344 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationNative_v0300.dll
[2013/06/07 17:19:11 | 000,326,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2013/06/07 17:14:55 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2013/06/07 17:14:49 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscorier.dll
[2013/06/07 17:14:46 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mscories.dll
[2013/06/07 17:13:10 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msshsq.dll
[2013/06/07 17:11:14 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrsmgr.dll
[2013/06/07 17:11:06 | 000,040,448 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrs.exe
[2013/06/07 17:11:06 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrshost.exe
[2013/06/07 17:11:06 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmprovhost.exe
[2013/06/07 17:11:06 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wsmplpxy.dll
[2013/06/07 17:11:06 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrssrv.dll
[2013/06/07 17:11:04 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wevtfwd.dll
[2013/06/07 17:11:04 | 000,079,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecutil.exe
[2013/06/07 17:11:04 | 000,056,320 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wecapi.dll
[2013/06/07 17:11:04 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmRes.dll
[2013/06/07 17:11:04 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\pwrshplugin.dll
[2013/06/07 17:11:00 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManMigrationPlugin.dll
[2013/06/07 17:11:00 | 000,246,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSManHTTPConfig.exe
[2013/06/07 17:11:00 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winrscmd.dll
[2013/06/07 17:11:00 | 000,214,016 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmWmiPl.dll
[2013/06/07 17:11:00 | 000,145,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WsmAuto.dll
[2013/06/07 17:09:15 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2013/06/07 17:09:14 | 000,241,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PortableDeviceApi.dll
[2013/06/07 17:09:12 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dnscacheugc.exe
[2013/06/07 17:09:09 | 002,452,872 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dat
[2013/06/07 17:09:07 | 000,671,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2013/06/07 17:09:07 | 000,467,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/06/07 17:09:07 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2013/06/07 17:09:07 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2013/06/07 17:09:07 | 000,380,928 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieapfltr.dll
[2013/06/07 17:09:07 | 000,230,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieaksie.dll
[2013/06/07 17:09:07 | 000,193,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2013/06/07 17:09:06 | 001,383,424 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/06/07 17:09:06 | 000,078,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieencode.dll
[2013/06/07 17:09:06 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/06/07 17:09:06 | 000,026,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/06/07 17:08:56 | 000,104,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netiohlp.dll
[2013/06/07 17:08:55 | 000,027,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\NETSTAT.EXE
[2013/06/07 17:08:55 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ARP.EXE
[2013/06/07 17:08:55 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ROUTE.EXE
[2013/06/07 17:08:55 | 000,017,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netevent.dll
[2013/06/07 17:08:55 | 000,011,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MRINFO.EXE
[2013/06/07 17:08:55 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\finger.exe
[2013/06/07 17:08:55 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\HOSTNAME.EXE
[2013/06/07 17:08:27 | 008,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2013/06/07 17:08:09 | 000,292,864 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2013/06/07 17:08:09 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2013/06/07 17:08:09 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2013/06/07 17:08:09 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dciman32.dll
[2013/06/07 17:07:58 | 002,868,224 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mf.dll
[2013/06/07 17:07:58 | 002,386,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMVCORE.DLL
[2013/06/07 17:07:55 | 003,600,272 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2013/06/07 17:07:55 | 003,548,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2013/06/07 17:07:49 | 000,302,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlansec.dll
[2013/06/07 17:07:49 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wlanmsm.dll
[2013/06/07 17:07:49 | 000,127,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\L2SecHC.dll
[2013/06/07 17:07:43 | 002,042,368 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2013/06/07 17:07:42 | 000,562,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdtcprx.dll
[2013/06/07 17:07:42 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\xolehlp.dll
[2013/06/07 17:07:36 | 000,081,920 | —- | C] (Radius Inc.) – C:\Windows\System32\iccvid.dll
[2013/06/07 17:07:35 | 001,136,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42.dll
[2013/06/07 17:07:34 | 001,161,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc42u.dll
[2013/06/07 17:07:30 | 000,157,184 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2013/06/07 17:07:24 | 004,240,384 | —- | C] (Microsoft) – C:\Windows\System32\GameUXLegacyGDFs.dll
[2013/06/07 17:07:24 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Apphlpdm.dll
[2013/06/07 17:07:15 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelinesvc.exe
[2013/06/07 17:07:14 | 000,183,296 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdohlp.dll
[2013/06/07 17:07:14 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasrecst.dll
[2013/06/07 17:07:14 | 000,054,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasads.dll
[2013/06/07 17:07:14 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iasdatastore.dll
[2013/06/07 17:07:14 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\System32\printfilterpipelineprxy.dll
[2013/06/07 17:07:14 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iashost.exe
[2013/06/07 17:07:06 | 000,866,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpmde.dll
[2013/06/07 17:07:02 | 000,954,752 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40.dll
[2013/06/07 17:07:01 | 000,954,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mfc40u.dll
[2013/06/07 17:06:59 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amxread.dll
[2013/06/07 17:06:59 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\System32\apilogen.dll
[2013/06/07 17:06:48 | 000,357,376 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskschd.dll
[2013/06/07 17:06:47 | 000,345,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmicmiplugin.dll
[2013/06/07 17:06:47 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Windows\System32\taskcomp.dll
[2013/06/07 17:06:35 | 000,429,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\EncDec.dll
[2013/06/07 17:06:35 | 000,323,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbe.dll
[2013/06/07 17:06:35 | 000,177,664 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2013/06/07 17:06:35 | 000,153,088 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sbeio.dll
[2013/06/07 17:06:32 | 000,303,616 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmpeffects.dll
[2013/06/07 17:06:28 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\consent.exe
[2013/06/07 17:06:25 | 002,927,104 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/06/07 17:06:21 | 000,425,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PhotoMetadataHandler.dll
[2013/06/07 17:06:21 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WindowsCodecsExt.dll
[2013/06/07 17:06:16 | 000,714,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\timedate.cpl
[2013/06/07 17:06:14 | 000,062,464 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\Windows\System32\l3codeca.acm
[2013/06/07 17:06:13 | 000,317,952 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MP4SDECD.DLL
[2013/06/07 17:06:07 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2013/06/07 17:05:54 | 000,147,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Faultrep.dll
[2013/06/07 17:05:53 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2013/06/07 17:05:52 | 001,169,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\sdclt.exe
[2013/06/07 17:05:44 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dataclen.dll
[2013/06/07 17:05:44 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\System32\cdd.dll
[2013/06/07 17:03:29 | 000,523,776 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2013/06/07 17:03:29 | 000,511,488 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2013/06/07 17:03:29 | 000,472,576 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2013/06/07 17:03:29 | 000,472,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2013/06/07 17:03:29 | 000,347,136 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2013/06/07 17:03:29 | 000,346,624 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2013/06/07 17:03:28 | 000,329,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdrm.dll
[2013/06/07 17:03:28 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2013/06/07 17:03:28 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2013/06/07 17:03:09 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.tlb
[2013/06/07 17:03:09 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\System32\amcompat.tlb
[2013/06/07 17:00:55 | 000,996,352 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMNetMgr.dll
[2013/06/07 17:00:55 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\logagent.exe
[2013/06/07 17:00:44 | 000,310,784 | —- | C] (Microsoft Corporation) – C:\Windows\System32\unregmp2.exe
[2013/06/07 17:00:43 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\spwmp.dll
[2013/06/07 17:00:43 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dxmasf.dll
[2013/06/07 17:00:42 | 000,004,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdxm.ocx
[2013/06/07 17:00:18 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2013/06/07 17:00:18 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avicap32.dll
[2013/06/07 17:00:11 | 000,351,232 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WSDApi.dll
[2013/06/07 17:00:07 | 001,645,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\connect.dll
[2013/06/07 17:00:05 | 000,375,808 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winsrv.dll
[2013/06/07 17:00:05 | 000,049,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\csrsrv.dll
[2013/06/07 16:56:06 | 000,604,672 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WMSPDMOD.DLL
[2013/06/07 16:44:45 | 000,000,000 | —D | C] – C:\Users\Luci\Documents\My Google Gadgets
[2013/06/07 16:44:42 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\Toshiba
[2013/06/07 16:44:39 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\Google
[2013/06/07 16:44:34 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\Symantec
[2013/06/07 16:44:12 | 000,000,000 | R–D | C] – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2013/06/07 16:44:12 | 000,000,000 | R–D | C] – C:\Users\Luci\Searches
[2013/06/07 16:44:12 | 000,000,000 | R–D | C] – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2013/06/07 16:44:04 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Roaming\Identities
[2013/06/07 16:44:01 | 000,000,000 | R–D | C] – C:\Users\Luci\Contacts
[2013/06/07 16:44:00 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\VirtualStore
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\AppData\Local\Temporary Internet Files
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Templates
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Start Menu
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\SendTo
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Recent
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\PrintHood
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\NetHood
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Documents\My Videos
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Documents\My Pictures
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Documents\My Music
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\My Documents
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Local Settings
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\AppData\Local\History
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Cookies
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\Application Data
[2013/06/07 16:43:37 | 000,000,000 | -HSD | C] – C:\Users\Luci\AppData\Local\Application Data
[2013/06/07 16:43:36 | 000,000,000 | –SD | C] – C:\Users\Luci\AppData\Roaming\Microsoft
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Videos
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Saved Games
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Pictures
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Music
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Links
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Favorites
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Downloads
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Documents
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\Desktop
[2013/06/07 16:43:36 | 000,000,000 | R–D | C] – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2013/06/07 16:43:36 | 000,000,000 | -H-D | C] – C:\Users\Luci\AppData
[2013/06/07 16:43:36 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\Temp
[2013/06/07 16:43:36 | 000,000,000 | —D | C] – C:\Users\Luci\AppData\Local\Microsoft
[2013/06/07 15:37:20 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2013/06/07 15:27:33 | 000,000,000 | —D | C] – C:\ProgramData\Partner
[2013/06/07 15:18:42 | 000,000,000 | —D | C] – C:\DOCS
[2013/06/07 15:14:37 | 000,279,376 | —- | C] (TOSHIBA Corporation) – C:\Windows\System32\drivers\tos_sps32.sys
[2013/06/07 15:14:34 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2013/06/07 15:14:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Toshiba Shared
[2013/06/07 15:14:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TOSHIBA DVD PLAYER
[2013/06/07 15:09:34 | 001,069,056 | —- | C] (The OpenSSL Project,
http://www.openssl.org/) – C:\Windows\System32\libeay32.dll
[2013/06/07 15:09:34 | 000,364,544 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtlLib.dll
[2013/06/07 15:09:33 | 000,155,648 | —- | C] (TODO: ) – C:\Windows\System32\IpLib.dll
[2013/06/07 15:09:33 | 000,025,896 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\System32\drivers\RtlProt.sys
[2013/06/07 15:07:33 | 000,290,304 | —- | C] (Realtek Semiconductor Corporation ) – C:\Windows\System32\drivers\rtl8187B.sys
[2013/06/07 15:07:32 | 000,290,304 | —- | C] (Realtek Semiconductor Corporation ) – C:\Windows\System\rtl8187B.sys
[2013/06/07 15:07:32 | 000,000,000 | —D | C] – C:\Program Files\REALTEK RTL8187B Wireless LAN Driver
[2013/06/07 15:07:32 | 000,000,000 | —D | C] – C:\Windows\OPTIONS
[2013/06/07 15:03:50 | 000,000,000 | —D | C] – C:\Program Files\Synaptics
[2013/06/07 15:02:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® Matrix Storage Manager
[2013/06/07 15:01:54 | 000,000,000 | —D | C] – C:\Windows\System32\ENU
[2013/06/07 15:01:53 | 001,034,776 | —- | C] (Intel Corporation) – C:\Windows\System32\imsmudlg.exe
[2013/06/07 14:59:46 | 000,000,000 | —D | C] – C:\Windows\System32\RTCOM
[2013/06/07 14:59:14 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\Windows\DIFxAPI.dll
[2013/06/07 14:59:13 | 001,196,032 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlUpd.exe
[2013/06/07 14:59:13 | 000,694,272 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkPgExt.dll
[2013/06/07 14:59:13 | 000,532,480 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RTSndMgr.cpl
[2013/06/07 14:59:13 | 000,339,968 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSXT.dll
[2013/06/07 14:59:13 | 000,285,216 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkApoApi.dll
[2013/06/07 14:59:13 | 000,185,776 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSTSHD.dll
[2013/06/07 14:59:13 | 000,167,936 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSHP360.dll
[2013/06/07 14:59:13 | 000,135,168 | —- | C] (SRS Labs, Inc.) – C:\Windows\System32\SRSWOW.dll
[2013/06/07 14:59:13 | 000,031,232 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkCoInst.dll
[2013/06/07 14:59:12 | 006,037,504 | —- | C] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
[2013/06/07 14:59:12 | 002,168,320 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\System32\RtkAPO.dll
[2013/06/07 14:59:12 | 000,520,192 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2013/06/07 14:59:12 | 000,315,392 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\HideWin.exe
[2013/06/07 14:59:12 | 000,140,288 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\System32\FMAPO.dll
[2013/06/07 14:59:12 | 000,126,976 | —- | C] (Waves Audio Ltd.) – C:\Windows\System32\maxxaudioapo.dll
[2013/06/07 14:56:28 | 000,920,088 | —- | C] (Intel® Corporation) – C:\Windows\System32\igxpun.exe
[2013/06/07 14:56:28 | 000,319,456 | —- | C] (Microsoft Corporation) – C:\Windows\System32\difxapi.dll
[2013/06/07 14:56:28 | 000,000,000 | —D | C] – C:\Windows\System32\Lang
[2013/06/07 14:52:16 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office Suite Activation Assistant
[2013/06/07 14:44:20 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2013/06/07 14:44:12 | 000,032,592 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msonpmon.dll
[2013/06/07 14:43:42 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DESIGNER
[2013/06/07 14:43:31 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2013/06/07 14:43:31 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2013/06/07 14:42:23 | 000,000,000 | —D | C] – C:\Windows\SHELLNEW
[2013/06/07 14:42:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft Help
[2013/06/07 14:41:25 | 000,000,000 | RH-D | C] – C:\MSOCache
[2013/06/07 14:40:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2013/06/07 14:40:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works
[2013/06/07 14:40:11 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Works
[2013/06/07 14:35:54 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/06/07 14:29:00 | 000,000,000 | -HSD | C] – C:\System Volume Information
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/06/07 19:36:07 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Luci\Desktop\OTL.exe
[2013/06/07 19:33:01 | 000,890,839 | —- | M] () – C:\Users\Luci\Desktop\SecurityCheck.exe
[2013/06/07 19:23:20 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/07 19:22:00 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/07 19:14:01 | 000,000,104 | —- | M] () – C:\Users\Luci\Desktop\Internet - Shortcut.lnk
[2013/06/07 18:59:45 | 000,000,954 | —- | M] () – C:\Users\Luci\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/07 18:49:33 | 000,000,853 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/07 18:44:25 | 000,595,684 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/06/07 18:44:25 | 000,101,350 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/06/07 18:33:36 | 004,463,288 | —- | M] (AVG Technologies) – C:\Users\Luci\Desktop\avg_free_stb_all_2013_3343_cnet.exe
[2013/06/07 18:24:21 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/07 18:24:21 | 000,003,616 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/07 18:23:23 | 000,321,080 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2013/06/07 18:23:10 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/06/07 18:22:41 | 3080,753,152 | -HS- | M] () – C:\hiberfil.sys
[2013/06/07 16:43:59 | 000,000,016 | RHS- | M] () – C:\Windows\System32\drivers\fbd.sys
[2013/06/07 15:46:17 | 000,047,092 | —- | M] () – C:\Windows\System32\license.rtf
[2013/06/07 15:28:18 | 000,000,004 | RHS- | M] () – C:\Windows\System32\drivers\taishop.sys
[2013/06/07 15:11:42 | 000,014,586 | —- | M] () – C:\Windows\System32\results.xml
[2013/06/07 15:04:15 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/06/07 14:59:14 | 000,319,456 | —- | M] (Microsoft Corporation) – C:\Windows\DIFxAPI.dll
[2013/06/07 14:59:12 | 000,315,392 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\HideWin.exe
[2013/06/07 14:52:19 | 000,001,189 | —- | M] () – C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/06/07 19:32:58 | 000,890,839 | —- | C] () – C:\Users\Luci\Desktop\SecurityCheck.exe
[2013/06/07 19:14:01 | 000,000,104 | —- | C] () – C:\Users\Luci\Desktop\Internet - Shortcut.lnk
[2013/06/07 19:12:54 | 000,000,886 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/07 19:12:54 | 000,000,882 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/07 18:59:45 | 000,000,954 | —- | C] () – C:\Users\Luci\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2013/06/07 18:49:33 | 000,000,853 | —- | C] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/06/07 17:11:01 | 000,201,184 | —- | C] () – C:\Windows\System32\winrm.vbs
[2013/06/07 17:11:01 | 000,004,675 | —- | C] () – C:\Windows\System32\wsmanconfig_schema.xml
[2013/06/07 17:11:01 | 000,002,426 | —- | C] () – C:\Windows\System32\WsmTxt.xsl
[2013/06/07 17:07:50 | 002,501,921 | —- | C] () – C:\Windows\System32\wlan.tmf
[2013/06/07 16:44:13 | 000,000,960 | —- | C] () – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2013/06/07 16:44:11 | 000,000,955 | —- | C] () – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2013/06/07 16:44:01 | 000,000,926 | —- | C] () – C:\Users\Luci\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Mail.lnk
[2013/06/07 16:43:59 | 000,000,016 | RHS- | C] () – C:\Windows\System32\drivers\fbd.sys
[2013/06/07 16:43:37 | 000,000,258 | —- | C] () – C:\Users\Luci\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2013/06/07 16:43:37 | 000,000,240 | —- | C] () – C:\Users\Luci\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2013/06/07 15:28:18 | 000,000,004 | RHS- | C] () – C:\Windows\System32\drivers\taishop.sys
[2013/06/07 15:24:11 | 000,000,715 | —- | C] () – C:\Users\Public\Desktop\TOSHIBA Resources.lnk
[2013/06/07 15:24:08 | 000,000,903 | —- | C] () – C:\Users\Public\Desktop\Voice & Video Calls.lnk
[2013/06/07 15:11:42 | 000,014,586 | —- | C] () – C:\Windows\System32\results.xml
[2013/06/07 15:10:57 | 3080,753,152 | -HS- | C] () – C:\hiberfil.sys
[2013/06/07 15:09:33 | 000,131,072 | —- | C] () – C:\Windows\System32\EnumDevLib.dll
[2013/06/07 15:04:15 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2013/06/07 15:00:29 | 000,000,553 | —- | C] () – C:\Windows\USetup.iss
[2013/06/07 14:52:19 | 000,001,189 | —- | C] () – C:\Users\Public\Desktop\Microsoft Office - 60 Day Trial.lnk
[2013/06/07 14:40:51 | 000,001,924 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2013/06/07 14:40:32 | 000,001,027 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
========== ZeroAccess Check ==========
[2006/11/02 05:51:16 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2011/01/21 08:46:32 | 011,582,464 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/03/02 21:36:24 | 000,615,424 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2008/01/20 19:33:39 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/06/07 18:50:27 | 000,000,000 | —D | M] – C:\Users\Luci\AppData\Roaming\AVG2013
[2013/06/07 18:49:33 | 000,000,000 | —D | M] – C:\Users\Luci\AppData\Roaming\TuneUp Software
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/10/28 23:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/28 23:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\explorer.exe
[2008/10/28 23:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 20:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/10/27 19:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 19:34:05 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SERVICES.EXE >
[2008/01/20 19:34:36 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\System32\services.exe
[2008/01/20 19:34:36 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
< MD5 for: SVCHOST.EXE >
[2008/01/20 19:33:13 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/20 19:33:13 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 19:34:37 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/20 19:34:37 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >
[2008/01/20 19:34:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\System32\winlogon.exe
[2008/01/20 19:34:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true >
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
========== Base Services ==========
SRV - [2006/11/02 02:46:02 | 000,024,576 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\aelupsvc.dll – (AeLookupSvc)
SRV - [2008/01/20 19:33:54 | 000,033,280 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\appinfo.dll – (Appinfo)
SRV - [2008/01/20 19:33:53 | 000,059,392 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\alg.exe – (ALG)
SRV - [2008/01/20 19:34:49 | 000,758,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\qmgr.dll – (BITS)
SRV - [2008/01/20 19:33:27 | 000,328,704 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\BFE.DLL – (BFE)
SRV - [2009/06/15 05:57:59 | 000,009,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (KeyIso)
SRV - [2008/04/17 22:48:39 | 000,269,312 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\es.dll – (EventSystem)
SRV - [2008/01/20 19:34:20 | 000,081,920 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\System32\browser.dll – (Browser)
SRV - [2008/01/20 19:34:19 | 000,128,000 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\cryptsvc.dll – (CryptSvc)
SRV - [2009/03/02 21:39:32 | 000,551,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (DcomLaunch)
SRV - [2008/01/20 19:33:37 | 000,204,288 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dhcpcsvc.dll – (Dhcp)
SRV - [2011/03/02 07:49:43 | 000,086,528 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dnsrslvr.dll – (Dnscache)
SRV - [2008/01/20 19:34:51 | 000,057,344 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\eapsvc.dll – (EapHost)
SRV - [2006/11/02 02:46:05 | 000,025,600 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\hidserv.dll – (hidserv)
SRV - [2008/01/20 19:33:46 | 000,288,256 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\System32\ipnathlp.dll – (SharedAccess)
SRV - [2008/06/18 20:31:48 | 000,361,984 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2008/01/20 19:34:03 | 000,310,784 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\swprv.dll – (swprv)
SRV - [2008/01/20 19:34:43 | 000,045,056 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\mmcss.dll – (MMCSS)
SRV - [2008/01/20 19:33:50 | 000,274,432 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\netman.dll – (Netman)
SRV - [2008/01/20 19:34:04 | 000,237,056 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\netprofm.dll – (netprofm)
SRV - [2008/01/20 19:33:15 | 000,168,448 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nlasvc.dll – (NlaSvc)
SRV - [2008/01/20 19:34:35 | 000,018,432 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nsisvc.dll – (nsi)
SRV - [2008/01/20 19:33:36 | 000,221,696 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\umpnpmgr.dll – (PlugPlay)
SRV - [2010/08/17 06:32:33 | 000,126,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\spoolsv.exe – (Spooler)
SRV - [2009/06/15 05:57:59 | 000,009,728 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (ProtectedStorage)
SRV - [2008/06/25 20:29:02 | 000,565,248 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\emdmgmt.dll – (EMDMgmt)
SRV - [2008/01/20 19:34:00 | 000,090,624 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\rasauto.dll – (RasAuto)
SRV - [2008/01/20 19:34:20 | 000,260,608 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\rasmans.dll – (RasMan)
SRV - [2009/03/02 21:39:32 | 000,551,424 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (RpcSs)
SRV - [2008/01/20 19:34:19 | 000,019,968 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\seclogon.dll – (seclogon)
SRV - [2009/06/15 05:57:59 | 000,009,728 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\lsass.exe – (SamSs)
SRV - [2008/01/20 19:33:06 | 000,061,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wscsvc.dll – (wscsvc)
SRV - [2008/01/20 19:34:44 | 000,122,880 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\srvsvc.dll – (LanmanServer)
SRV - [2009/07/10 05:21:29 | 000,247,808 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\shsvcs.dll – (ShellHWDetection)
SRV - [2008/01/20 19:34:50 | 002,623,488 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\SLsvc.exe – (slsvc)
SRV - [2010/11/06 04:09:57 | 000,603,648 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\schedsvc.dll – (Schedule)
SRV - [2008/01/20 19:34:43 | 000,242,688 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\tapisrv.dll – (TapiSrv)
SRV - [2009/07/10 05:21:29 | 000,247,808 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\shsvcs.dll – (Themes)
SRV - [2008/01/20 19:33:40 | 000,153,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\profsvc.dll – (ProfSvc)
SRV - [2008/01/20 19:33:20 | 001,054,720 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\VSSVC.exe – (VSS)
SRV - [2008/01/20 19:34:43 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\audiosrv.dll – (Audiosrv)
SRV - [2008/01/20 19:34:43 | 000,314,368 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\audiosrv.dll – (AudioEndpointBuilder)
SRV - [2008/01/20 19:32:53 | 000,104,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sdrsvc.dll – (SDRSVC)
SRV - [2008/01/20 19:33:00 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2008/01/20 19:33:18 | 001,013,760 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wevtsvc.dll – (Eventlog)
SRV - [2008/01/20 19:34:35 | 000,393,216 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\MPSSVC.dll – (MpsSvc)
SRV - [2008/01/20 19:33:06 | 000,452,608 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wiaservc.dll – (stisvc)
SRV - [2008/01/20 19:34:08 | 000,071,680 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\msiexec.exe – (msiserver)
SRV - [2008/01/20 19:34:49 | 000,161,792 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wbem\WMIsvc.dll – (Winmgmt)
SRV - [2008/01/20 19:34:55 | 001,695,232 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wuaueng.dll – (wuauserv)
SRV - [2008/01/20 19:34:03 | 000,175,104 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\dot3svc.dll – (dot3svc)
SRV - [2009/07/11 12:32:52 | 000,513,024 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wlansvc.dll – (Wlansvc)
SRV - [2009/06/10 05:12:29 | 000,160,256 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wkssvc.dll – (LanmanWorkstation)
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: TOSHIBA MK2555GSX
Partitions: 3
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - Removable Media
Interface type: USB
Media Type: Removable Media
Model: SanDisk U3 Cruzer Micro USB Device
Partitions: 1
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 1.00GB
Starting Offset: 1048576
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 224.00GB
Starting Offset: 1573912576
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 7.00GB
Starting Offset: 242311233536
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: MS-DOS V4 Huge
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 2.00GB
Starting Offset: 125440
Hidden sectors: 0
< >
[2006/11/02 05:58:10 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2006/11/02 05:58:10 | 000,011,226 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2013/06/07 19:12:54 | 000,000,882 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2013/06/07 19:12:54 | 000,000,886 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
< End of report >