Hi there Elise thanks so much for your help....
I've ran the OTL scan and below are the results:
OTL.TxtOTL logfile created on: 3/18/2010 3:07:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Users\Safran\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.62 Gb Total Space | 38.14 Gb Free Space | 39.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 100.00 Mb Total Space | 69.81 Mb Free Space | 69.81% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 55.66 Gb Total Space | 22.20 Gb Free Space | 39.88% Space Free | Partition Type: NTFS
Computer Name: SAFRAN-PC
Current User Name: Safran
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/03/18 15:06:02 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\Safran\Desktop\OTL.exe
PRC - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/11/18 12:47:14 | 001,243,088 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsTray.exe
PRC - [2009/11/09 03:17:50 | 000,180,224 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsSvc.exe
PRC - [2009/10/31 05:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/10/30 11:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) -- C:\Program Files\Spyware Doctor\pctsAuxs.exe
PRC - [2009/10/14 13:36:56 | 002,793,304 | ---- | M] () -- C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe
PRC - [2009/10/14 13:34:18 | 000,560,472 | ---- | M] () -- C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
PRC - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2009/09/23 13:38:18 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/07/14 01:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/05/21 18:25:15 | 001,501,064 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\itype.exe
PRC - [2009/05/21 18:25:15 | 000,448,400 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
========== Modules (SafeList) ========== MOD - [2010/03/18 15:06:02 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\Safran\Desktop\OTL.exe
MOD - [2009/12/08 13:12:24 | 000,014,544 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2009/07/14 01:16:15 | 000,099,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2009/07/14 01:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/14 01:16:13 | 000,050,688 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2009/07/14 01:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/14 01:16:03 | 000,022,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2009/07/14 01:15:35 | 000,288,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2009/07/14 01:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/14 01:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/14 01:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/14 01:15:02 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2009/07/14 01:03:50 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV - File not found [Auto | Stopped] -- -- (BrowserQuest Service)
SRV - [2009/12/08 14:25:28 | 000,093,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/30 11:18:16 | 000,359,624 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
SRV - [2009/10/07 01:47:34 | 000,154,136 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2009/09/23 13:38:18 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2009/07/14 01:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/14 01:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/14 01:16:17 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2009/07/14 01:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/14 01:16:15 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2009/07/14 01:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/14 01:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 01:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 01:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/14 01:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/14 01:16:12 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2009/07/14 01:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/14 01:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/07/14 01:15:36 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2009/07/14 01:15:21 | 000,797,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2009/07/14 01:15:11 | 000,253,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2009/07/14 01:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/14 01:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/14 01:14:58 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2009/07/14 01:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/07/14 01:14:29 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
========== Driver Services (SafeList) ========== DRV - [2010/03/07 00:29:02 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2009/11/09 11:20:12 | 000,207,792 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/11/09 03:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2009/11/04 02:59:00 | 000,017,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB)
DRV - [2009/10/16 07:24:58 | 001,183,232 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTL85n86.sys -- (RTL85n86)
DRV - [2009/10/07 08:49:40 | 006,756,632 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvuvc.sys -- (LVUVC) Logitech QuickCam E3500(UVC)
DRV - [2009/10/07 08:47:56 | 000,266,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\lvrs.sys -- (LVRS)
DRV - [2009/10/07 01:46:36 | 000,025,752 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/09/27 23:12:22 | 009,509,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/09/23 01:19:31 | 000,294,912 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcvmm.sys -- (vpcvmm)
DRV - [2009/09/23 01:19:31 | 000,055,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV - [2009/09/23 01:18:08 | 000,078,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpcusb.sys -- (vpcusb)
DRV - [2009/09/23 01:18:07 | 000,165,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vpchbus.sys -- (vpcbus)
DRV - [2009/07/14 01:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\cmdide.sys -- (cmdide)
DRV - [2009/07/14 01:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/14 01:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/14 01:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/14 01:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/14 01:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/14 01:26:15 | 000,079,952 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV - [2009/07/14 01:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/14 01:26:15 | 000,023,616 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\amdxata.sys -- (amdxata)
DRV - [2009/07/14 01:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\aliide.sys -- (aliide)
DRV - [2009/07/14 01:20:44 | 000,142,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvstor.sys -- (nvstor)
DRV - [2009/07/14 01:20:44 | 000,117,312 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nvraid.sys -- (nvraid)
DRV - [2009/07/14 01:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/14 01:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/14 01:20:36 | 000,332,352 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iaStorV.sys -- (iaStorV)
DRV - [2009/07/14 01:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/14 01:20:36 | 000,133,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/07/14 01:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/14 01:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/14 01:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/14 01:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/14 01:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/14 01:20:36 | 000,013,904 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2009/07/14 01:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/14 01:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/14 01:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/14 01:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/14 01:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/14 01:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/14 01:19:10 | 000,159,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vhdmp.sys -- (vhdmp)
DRV - [2009/07/14 01:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 01:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/14 01:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/14 01:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/14 01:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\viaide.sys -- (viaide)
DRV - [2009/07/14 01:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/14 01:19:04 | 000,173,648 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2009/07/14 01:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/14 01:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/14 01:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/14 01:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/14 01:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/14 01:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/14 00:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/14 00:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009/07/14 00:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
DRV - [2009/07/14 00:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/13 23:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/13 23:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/13 23:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/13 23:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/13 23:52:00 | 000,163,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\1394ohci.sys -- (1394ohci)
DRV - [2009/07/13 23:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/13 23:51:23 | 000,080,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2009/07/13 23:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/13 23:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/13 23:45:26 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2009/07/13 23:36:52 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2009/07/13 23:33:50 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2009/07/13 23:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 23:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 23:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/13 23:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009/07/13 23:16:36 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\acpipmi.sys -- (AcpiPmi)
DRV - [2009/07/13 23:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/13 22:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 22:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/13 22:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/13 22:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/13 22:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/13 22:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/13 22:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/07/13 22:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/13 22:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/13 22:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009/05/09 01:14:21 | 000,030,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehpIE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 10 A6 4B D0 0F AC CA 01 [binary data]
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\Safran-PC_Guest\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehpIE - HKU\Safran-PC_Guest\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\Safran-PC_Guest\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D0 D3 BA DD 1B B3 CA 01 [binary data]
IE - HKU\Safran-PC_Guest\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Safran-PC_Sanya\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\Safran-PC_Sanya\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://uk.msn.com/?ocid=iehpIE - HKU\Safran-PC_Sanya\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\Safran-PC_Sanya\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 00 58 D8 99 31 AB CA 01 [binary data]
IE - HKU\Safran-PC_Sanya\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/03/12 23:32:19 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/03/17 02:46:51 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2010/03/11 21:22:55 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\Safran-PC_Sanya\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKU\S-1-5-21-1823437180-114209430-2017350500-1000..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\Safran-PC_Sanya..\Run: [QuickTime Task] C:\Users\Sanya\AppData\Local\Temp\QTTask.exe File not found
O4 - HKU\Safran-PC_Sanya..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\Safran-PC_Guest\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Safran-PC_Sanya\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 21:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{ae6e634a-107b-11df-b427-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{ae6e634a-107b-11df-b427-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Launcher.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010/03/18 15:05:55 | 000,556,032 | ---- | C] (OldTimer Tools) -- C:\Users\Safran\Desktop\OTL.exe
[2010/03/17 11:24:15 | 000,356,352 | ---- | C] (eSellerate Inc.) -- C:\Windows\eSellerateEngine.dll
[2010/03/17 11:24:15 | 000,081,920 | ---- | C] (eSellerate Inc.) -- C:\Windows\eSellerateControl350.dll
[2010/03/17 11:24:14 | 000,000,000 | ---D | C] -- C:\Program Files\Win 32.Malware.Jeefo Removal Tool[2]
[2010/03/17 02:41:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/03/17 02:41:43 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010/03/17 02:41:43 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2010/03/17 00:01:08 | 000,233,136 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2010/03/17 00:01:08 | 000,098,600 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctwfpfilter.sys
[2010/03/17 00:01:07 | 000,207,792 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2010/03/17 00:01:07 | 000,087,784 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/03/17 00:01:04 | 000,070,408 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2010/03/17 00:00:50 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\PC Tools
[2010/03/17 00:00:50 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/03/17 00:00:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/03/16 23:57:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Google Updater
[2010/03/16 23:39:33 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\Threat Expert
[2010/03/16 23:35:13 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll.old
[2010/03/16 23:31:41 | 000,000,000 | ---D | C] -- C:\Program Files\Spyware Doctor
[2010/03/16 19:16:24 | 000,056,816 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2010/03/16 19:16:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2010/03/16 17:57:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010/03/16 17:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2010/03/16 17:56:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/03/16 17:56:02 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/03/16 17:54:42 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2010/03/16 16:03:56 | 000,000,000 | R--D | C] -- C:\Users\Safran\Documents\New Briefcase
[2010/03/12 23:32:26 | 000,000,000 | ---D | C] -- C:\Program Files\Yahoo!
[2010/03/12 23:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2010/03/11 21:25:52 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/03/11 21:20:54 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\temp
[2010/03/11 21:13:56 | 000,161,792 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2010/03/11 21:13:56 | 000,136,704 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2010/03/11 21:13:56 | 000,031,232 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2010/03/11 21:13:49 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/03/11 21:09:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/03/11 21:08:54 | 000,212,480 | ---- | C] (SteelWerX) -- C:\Windows\SWXCACLS.exe
[2010/03/07 17:20:17 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\Microsoft Games
[2010/03/07 16:30:24 | 000,000,000 | ---D | C] -- C:\ProgramData\HPSSUPPLY
[2010/03/07 00:58:05 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\DAEMON Tools Images
[2010/03/07 00:50:43 | 000,000,000 | ---D | C] -- C:\Program Files\InstallShield Installation Information
[2010/03/07 00:41:10 | 000,000,000 | ---D | C] -- C:\Program Files\Activision
[2010/03/07 00:37:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2010/03/07 00:28:49 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite
[2010/03/06 23:17:51 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\DAEMON Tools Lite
[2010/03/06 23:17:43 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Lite
[2010/03/06 20:42:44 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\DAEMON Tools Pro
[2010/03/06 20:42:44 | 000,000,000 | ---D | C] -- C:\ProgramData\DAEMON Tools Pro
[2010/03/05 18:50:18 | 000,074,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_4.dll
[2010/03/05 18:50:17 | 000,528,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_6.dll
[2010/03/05 18:50:17 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_6.dll
[2010/03/05 18:50:17 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_7.dll
[2010/03/05 18:50:16 | 005,501,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dcsx_42.dll
[2010/03/05 18:50:16 | 001,974,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_42.dll
[2010/03/05 18:50:16 | 000,515,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_5.dll
[2010/03/05 18:50:16 | 000,238,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_5.dll
[2010/03/05 18:50:15 | 004,178,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_41.dll
[2010/03/05 18:50:15 | 002,036,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_40.dll
[2010/03/05 18:50:15 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_42.dll
[2010/03/05 18:50:15 | 001,846,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_41.dll
[2010/03/05 18:50:15 | 000,517,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_4.dll
[2010/03/05 18:50:15 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_42.dll
[2010/03/05 18:50:15 | 000,453,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_41.dll
[2010/03/05 18:50:15 | 000,452,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_40.dll
[2010/03/05 18:50:15 | 000,235,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_4.dll
[2010/03/05 18:50:15 | 000,235,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx11_42.dll
[2010/03/05 18:50:15 | 000,069,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_3.dll
[2010/03/05 18:50:15 | 000,022,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_6.dll
[2010/03/05 18:50:14 | 004,379,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_40.dll
[2010/03/05 18:50:14 | 000,514,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_3.dll
[2010/03/05 18:50:14 | 000,509,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_2.dll
[2010/03/05 18:50:14 | 000,235,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_3.dll
[2010/03/05 18:50:14 | 000,070,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_2.dll
[2010/03/05 18:50:14 | 000,068,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_1.dll
[2010/03/05 18:50:14 | 000,023,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_5.dll
[2010/03/05 18:50:13 | 003,851,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_39.dll
[2010/03/05 18:50:13 | 003,850,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_38.dll
[2010/03/05 18:50:13 | 001,493,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_39.dll
[2010/03/05 18:50:13 | 001,491,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_38.dll
[2010/03/05 18:50:13 | 000,507,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_1.dll
[2010/03/05 18:50:13 | 000,479,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAudio2_0.dll
[2010/03/05 18:50:13 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_39.dll
[2010/03/05 18:50:13 | 000,467,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_38.dll
[2010/03/05 18:50:13 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_2.dll
[2010/03/05 18:50:13 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_1.dll
[2010/03/05 18:50:13 | 000,238,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine3_0.dll
[2010/03/05 18:50:13 | 000,065,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\XAPOFX1_0.dll
[2010/03/05 18:50:13 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_4.dll
[2010/03/05 18:50:13 | 000,025,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_3.dll
[2010/03/05 18:50:12 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DX9_37.dll
[2010/03/05 18:50:12 | 003,734,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_36.dll
[2010/03/05 18:50:12 | 001,420,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_37.dll
[2010/03/05 18:50:12 | 001,374,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_36.dll
[2010/03/05 18:50:12 | 000,462,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_37.dll
[2010/03/05 18:50:12 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_36.dll
[2010/03/05 18:50:12 | 000,267,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_10.dll
[2010/03/05 18:50:11 | 003,727,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_35.dll
[2010/03/05 18:50:11 | 003,497,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_34.dll
[2010/03/05 18:50:11 | 003,495,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_33.dll
[2010/03/05 18:50:11 | 001,358,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_35.dll
[2010/03/05 18:50:11 | 001,124,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_34.dll
[2010/03/05 18:50:11 | 001,123,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\D3DCompiler_33.dll
[2010/03/05 18:50:11 | 000,444,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_35.dll
[2010/03/05 18:50:11 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_34.dll
[2010/03/05 18:50:11 | 000,443,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10_33.dll
[2010/03/05 18:50:11 | 000,267,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_9.dll
[2010/03/05 18:50:11 | 000,266,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_8.dll
[2010/03/05 18:50:11 | 000,261,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_7.dll
[2010/03/05 18:50:11 | 000,081,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_3.dll
[2010/03/05 18:50:11 | 000,017,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\X3DAudio1_2.dll
[2010/03/05 18:50:10 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_31.dll
[2010/03/05 18:50:10 | 000,440,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx10.dll
[2010/03/05 18:50:10 | 000,255,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_6.dll
[2010/03/05 18:50:10 | 000,251,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_5.dll
[2010/03/05 18:50:10 | 000,237,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_4.dll
[2010/03/05 18:50:10 | 000,015,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_1.dll
[2010/03/05 18:50:09 | 000,236,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_3.dll
[2010/03/05 18:50:09 | 000,230,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_2.dll
[2010/03/05 18:50:09 | 000,229,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_1.dll
[2010/03/05 18:50:09 | 000,062,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_2.dll
[2010/03/05 18:50:09 | 000,062,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xinput1_1.dll
[2010/03/05 18:50:06 | 002,332,368 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_29.dll
[2010/03/05 18:50:06 | 002,323,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_28.dll
[2010/03/05 18:50:06 | 002,319,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_27.dll
[2010/03/05 18:50:06 | 000,230,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\xactengine2_0.dll
[2010/03/05 18:50:06 | 000,014,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\x3daudio1_0.dll
[2010/03/05 18:50:05 | 002,337,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_25.dll
[2010/03/05 18:50:05 | 002,297,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_26.dll
[2010/03/05 18:50:05 | 002,222,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3dx9_24.dll
[2010/03/05 18:47:03 | 000,000,000 | -H-D | C] -- C:\Windows\msdownld.tmp
[2010/03/05 18:46:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\directx
[2010/03/04 11:57:23 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\Nero
[2010/03/04 11:53:21 | 000,000,000 | ---D | C] -- C:\Users\Safran\Desktop\Extras
[2010/03/04 11:27:56 | 000,000,000 | ---D | C] -- C:\Program Files\Registry Easy
[2010/03/04 01:19:40 | 000,293,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\browserchoice.exe
[2010/03/01 20:27:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/03/01 20:27:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2010/03/01 20:22:57 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2010/03/01 20:22:57 | 000,153,376 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/03/01 20:22:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/03/01 20:22:57 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/03/01 20:02:36 | 000,212,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\RichTx32.ocx
[2010/03/01 20:02:36 | 000,124,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSWinSck.ocx
[2010/03/01 20:02:33 | 001,753,088 | ---- | C] (Exontrol Inc.) -- C:\Windows\System32\ExGrid.dll
[2010/03/01 20:02:33 | 000,614,400 | ---- | C] (Exontrol Inc.) -- C:\Windows\System32\ExButton.dll
[2010/03/01 20:02:33 | 000,602,112 | ---- | C] (Exontrol Inc.) -- C:\Windows\System32\ExMenu.dll
[2010/03/01 20:02:33 | 000,516,096 | ---- | C] (Exontrol Inc.) -- C:\Windows\System32\ExTab.dll
[2010/03/01 20:02:33 | 000,356,352 | ---- | C] (eSellerate Inc.) -- C:\Windows\System32\eSellerateEngine.dll
[2010/03/01 20:02:33 | 000,307,200 | ---- | C] (Exontrol Inc.) -- C:\Windows\System32\ExPMenu.dll
[2010/03/01 20:02:33 | 000,118,784 | ---- | C] (eSellerate Inc.) -- C:\Windows\System32\eWebControl.dll
[2010/03/01 20:02:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\eSellerate
[2010/03/01 20:02:32 | 001,388,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.004
[2010/03/01 20:02:32 | 000,368,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbar332.dll
[2010/03/01 20:02:32 | 000,326,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.005
[2010/03/01 20:02:32 | 000,147,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.002
[2010/03/01 20:02:32 | 000,140,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\COMDLG32.OCX
[2010/03/01 20:02:32 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.003
[2010/03/01 20:02:31 | 000,598,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.000
[2010/03/01 20:02:31 | 000,164,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\temp.001
[2010/03/01 20:02:31 | 000,000,000 | ---D | C] -- C:\Program Files\AnswersThatWork
[2010/03/01 18:38:17 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\Nero
[2010/03/01 18:24:14 | 000,000,000 | ---D | C] -- C:\Program Files\Nero
[2010/03/01 18:23:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2010/02/24 20:32:06 | 000,000,000 | ---D | C] -- C:\$AVG
[2010/02/24 20:31:48 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG Security Toolbar
[2010/02/24 20:31:24 | 000,000,000 | ---D | C] -- C:\ProgramData\avg9
[2010/02/24 19:54:09 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\WinRAR
[2010/02/24 19:53:31 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2010/02/24 12:55:43 | 000,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2010/02/24 12:55:20 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\uTorrent
[2010/02/23 20:57:31 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2010/02/23 20:57:29 | 000,641,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CPFilters.dll
[2010/02/23 20:57:29 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\psisdecd.dll
[2010/02/23 20:57:29 | 000,417,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msdri.dll
[2010/02/23 20:57:29 | 000,204,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MSNP.ax
[2010/02/23 20:57:20 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2010/02/22 23:32:04 | 000,000,000 | ---D | C] -- C:\Users\Safran\Documents\SightSpeed Recordings
[2010/02/22 20:58:13 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\AVS4YOU
[2010/02/22 20:58:12 | 000,000,000 | ---D | C] -- C:\ProgramData\AVS4YOU
[2010/02/22 20:58:08 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\microsoft
[2010/02/22 20:57:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\AVSMedia
[2010/02/22 20:57:14 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc70.dll
[2010/02/22 20:57:14 | 000,487,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcp70.dll
[2010/02/22 20:57:13 | 000,344,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msvcr70.dll
[2010/02/22 20:57:13 | 000,024,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msxml3a.dll
[2010/02/22 20:57:13 | 000,000,000 | ---D | C] -- C:\Program Files\AVS4YOU
[2010/02/22 20:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/02/22 20:03:43 | 000,000,000 | ---D | C] -- C:\Users\Safran\Documents\Clone2Go DVD Ripper
[2010/02/22 20:03:36 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\Clone2Go DVD Ripper
[2010/02/22 20:03:33 | 000,000,000 | ---D | C] -- C:\Program Files\Clone2Go DVD Ripper
[2010/02/21 03:08:07 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2010/02/20 18:40:10 | 000,000,000 | R--D | C] -- C:\Users\Safran\Documents\Scanned Documents
[2010/02/20 16:33:38 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\ElevatedDiagnostics
[2010/02/20 01:04:34 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2010/02/19 23:58:06 | 000,000,000 | ---D | C] -- C:\Program Files\MSECache
[2010/02/18 19:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2010/02/18 19:38:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2010/02/18 19:38:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2010/02/18 17:20:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010/02/17 19:10:17 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Roaming\Google
[2010/02/17 19:10:17 | 000,000,000 | ---D | C] -- C:\Users\Safran\AppData\Local\Google
[2010/02/17 14:40:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2010/02/17 14:40:10 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2010/02/17 14:07:04 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2010/02/16 23:36:54 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office Outlook Connector
[2010/02/16 23:36:23 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010/02/16 23:36:05 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010/03/18 15:10:07 | 001,835,008 | -HS- | M] () -- C:\Users\Safran\ntuser.dat
[2010/03/18 15:06:02 | 000,556,032 | ---- | M] (OldTimer Tools) -- C:\Users\Safran\Desktop\OTL.exe
[2010/03/18 14:47:48 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/18 14:47:48 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/18 14:42:05 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/03/18 14:39:35 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/03/18 14:39:24 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/03/18 14:39:24 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\lvuvc.hs
[2010/03/18 14:39:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/03/18 14:39:03 | 1408,688,128 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/18 00:42:32 | 001,149,836 | -H-- | M] () -- C:\Users\Safran\AppData\Local\IconCache.db
[2010/03/18 00:20:01 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/03/17 11:24:15 | 000,002,283 | ---- | M] () -- C:\Users\Safran\Desktop\Win 32.Malware.Jeefo Removal Tool[2].lnk
[2010/03/17 11:11:47 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2010/03/17 11:11:45 | 000,153,376 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2010/03/16 21:29:16 | 000,000,513 | ---- | M] () -- C:\Windows\win.ini
[2010/03/16 20:48:56 | 000,109,600 | ---- | M] () -- C:\Users\Safran\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/16 19:19:42 | 000,056,816 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2010/03/16 18:48:08 | 000,031,707 | ---- | M] () -- C:\Users\Safran\Desktop\jangs.docx
[2010/03/16 18:10:20 | 000,000,162 | -H-- | M] () -- C:\Users\Safran\Desktop\~$jangs.docx
[2010/03/16 18:03:50 | 000,410,656 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/03/16 17:44:29 | 000,717,892 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/03/16 17:44:29 | 000,624,240 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/03/16 17:44:29 | 000,109,352 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/03/13 00:43:48 | 000,197,047 | ---- | M] () -- C:\Windows\hpoins30.dat
[2010/03/13 00:41:50 | 000,002,125 | ---- | M] () -- C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk
[2010/03/13 00:36:59 | 000,002,069 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/03/13 00:21:37 | 000,019,500 | ---- | M] () -- C:\Windows\hpqins13.dat
[2010/03/12 23:31:30 | 000,001,273 | ---- | M] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/03/12 22:12:16 | 000,196,398 | ---- | M] () -- C:\Windows\hpoins30.dat.temp
[2010/03/11 21:23:04 | 000,000,215 | ---- | M] () -- C:\Windows\system.ini
[2010/03/11 21:22:55 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2010/03/11 00:01:48 | 000,023,698 | ---- | M] () -- C:\Windows\System32\MRT.INI
[2010/03/07 00:48:17 | 000,002,054 | ---- | M] () -- C:\Users\Safran\Desktop\Rome - Total War.lnk
[2010/03/07 00:48:10 | 000,000,248 | ---- | M] () -- C:\Windows\RomeTW.ini
[2010/03/07 00:29:02 | 000,691,696 | ---- | M] () -- C:\Windows\System32\drivers\sptd.sys
[2010/03/07 00:17:34 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/03/07 00:17:34 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TM.blf
[2010/03/07 00:17:33 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/03/05 17:38:15 | 000,000,315 | ---- | M] () -- C:\Users\Safran\AppData\Roaming\default.rss
[2010/03/05 17:38:06 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2010/03/04 11:31:51 | 000,000,042 | ---- | M] () -- C:\Windows\System32\RegistryEasy.lie
[2010/03/01 20:22:49 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deploytk.dll
[2010/03/01 20:22:49 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2010/03/01 18:24:28 | 000,002,654 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2010/03/01 15:45:42 | 000,000,913 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/02/25 00:50:35 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/25 00:50:35 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/25 00:50:35 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TM.blf
[2010/02/24 19:51:51 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/02/24 19:51:51 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/02/24 10:16:06 | 000,181,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2010/02/23 20:53:03 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/23 20:53:03 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/23 20:53:03 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TM.blf
[2010/02/21 03:36:44 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/21 03:36:44 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/21 03:36:44 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TM.blf
[2010/02/20 19:40:13 | 000,077,620 | ---- | M] () -- C:\Windows\hpqins05.dat
[2010/02/20 18:59:46 | 000,023,113 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010/02/20 17:14:05 | 002,529,622 | ---- | M] () -- C:\Users\Safran\AppData\Local\[j0009]-[p08].bmp
[2010/02/20 17:09:56 | 002,529,622 | ---- | M] () -- C:\Users\Safran\AppData\Local\[j0008]-[p10].bmp
[2010/02/20 17:07:04 | 002,529,622 | ---- | M] () -- C:\Users\Safran\AppData\Local\[j0007]-[p10].bmp
[2010/02/18 21:44:59 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/18 21:44:59 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/18 21:44:59 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TM.blf
[2010/02/18 20:30:21 | 000,000,990 | ---- | M] () -- C:\Users\Public\Desktop\PS3 Media Server.lnk
[2010/02/18 20:06:23 | 000,001,023 | ---- | M] () -- C:\Users\Public\Desktop\Logitech Vid.lnk
[2010/02/18 15:52:43 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/18 15:52:43 | 000,524,288 | -HS- | M] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/18 15:52:43 | 000,065,536 | -HS- | M] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TM.blf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/03/17 11:24:15 | 000,002,283 | ---- | C] () -- C:\Users\Safran\Desktop\Win 32.Malware.Jeefo Removal Tool[2].lnk
[2010/03/17 00:01:08 | 000,007,387 | ---- | C] () -- C:\Windows\System32\drivers\pctgntdi.cat
[2010/03/17 00:01:07 | 000,007,412 | ---- | C] () -- C:\Windows\System32\drivers\PCTAppEvent.cat
[2010/03/17 00:01:07 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctcore.cat
[2010/03/17 00:01:04 | 000,007,383 | ---- | C] () -- C:\Windows\System32\drivers\pctplsg.cat
[2010/03/16 23:57:46 | 000,000,868 | ---- | C] () -- C:\Windows\tasks\Google Software Updater.job
[2010/03/16 23:35:14 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll.old
[2010/03/16 18:10:20 | 000,000,162 | -H-- | C] () -- C:\Users\Safran\Desktop\~$jangs.docx
[2010/03/16 18:10:19 | 000,031,707 | ---- | C] () -- C:\Users\Safran\Desktop\jangs.docx
[2010/03/13 00:41:50 | 000,002,125 | ---- | C] () -- C:\Users\Public\Desktop\HP Photosmart Essential 3.5.lnk
[2010/03/13 00:39:26 | 000,197,047 | ---- | C] () -- C:\Windows\hpoins30.dat
[2010/03/13 00:39:25 | 000,000,587 | ---- | C] () -- C:\Windows\hpomdl30.dat
[2010/03/13 00:17:23 | 000,019,500 | ---- | C] () -- C:\Windows\hpqins13.dat
[2010/03/12 23:31:30 | 000,001,273 | ---- | C] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/03/12 23:31:05 | 000,002,069 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/03/11 21:13:56 | 000,261,632 | ---- | C] () -- C:\Windows\PEV.exe
[2010/03/11 21:13:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/03/11 21:13:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/03/11 21:13:56 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/03/11 21:13:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/03/07 00:48:17 | 000,002,054 | ---- | C] () -- C:\Users\Safran\Desktop\Rome - Total War.lnk
[2010/03/07 00:48:10 | 000,000,248 | ---- | C] () -- C:\Windows\RomeTW.ini
[2010/03/07 00:29:02 | 000,691,696 | ---- | C] () -- C:\Windows\System32\drivers\sptd.sys
[2010/03/07 00:17:03 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/03/07 00:17:03 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/03/07 00:17:03 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{a9595bc3-297e-11df-a7f4-001e9071aa2e}.TM.blf
[2010/03/04 11:31:51 | 000,000,042 | ---- | C] () -- C:\Windows\System32\RegistryEasy.lie
[2010/03/01 20:46:08 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/03/01 18:24:28 | 000,002,654 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2010/02/24 23:55:32 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/24 23:55:32 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/24 23:55:32 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{dac47147-219f-11df-944b-001e9071aa2e}.TM.blf
[2010/02/24 19:51:51 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2010/02/24 19:51:51 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2010/02/24 12:55:43 | 000,000,913 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2010/02/23 20:53:03 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/23 20:53:03 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/23 20:53:03 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{54376346-20bd-11df-bfa8-001e9071aa2e}.TM.blf
[2010/02/21 03:22:26 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/21 03:22:26 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/21 03:22:26 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{40f77e41-1e98-11df-9308-001e9071aa2e}.TM.blf
[2010/02/20 19:39:07 | 000,077,620 | ---- | C] () -- C:\Windows\hpqins05.dat
[2010/02/20 18:59:12 | 000,023,113 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/02/20 17:14:04 | 002,529,622 | ---- | C] () -- C:\Users\Safran\AppData\Local\[j0009]-[p08].bmp
[2010/02/20 17:09:55 | 002,529,622 | ---- | C] () -- C:\Users\Safran\AppData\Local\[j0008]-[p10].bmp
[2010/02/20 17:07:02 | 002,529,622 | ---- | C] () -- C:\Users\Safran\AppData\Local\[j0007]-[p10].bmp
[2010/02/18 20:30:21 | 000,000,990 | ---- | C] () -- C:\Users\Public\Desktop\PS3 Media Server.lnk
[2010/02/18 19:33:00 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/18 19:33:00 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/18 19:33:00 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\ntuser.dat{0b01a0c3-1cc4-11df-a461-001e9071aa2e}.TM.blf
[2010/02/18 15:52:43 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TMContainer00000000000000000002.regtrans-ms
[2010/02/18 15:52:43 | 000,524,288 | -HS- | C] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TMContainer00000000000000000001.regtrans-ms
[2010/02/18 15:52:43 | 000,065,536 | -HS- | C] () -- C:\Users\Safran\NTUSER.DAT{8b64d964-1ca5-11df-b2e0-001e9071aa2e}.TM.blf
[2010/02/17 14:46:01 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/17 14:45:59 | 000,000,880 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/05 21:30:07 | 000,000,315 | ---- | C] () -- C:\Users\Safran\AppData\Roaming\default.rss
[2010/02/03 03:09:16 | 000,023,698 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/02/03 01:12:34 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/02/03 00:31:25 | 000,039,426 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2009/10/07 08:24:22 | 000,082,289 | ---- | C] () -- C:\Windows\System32\lvcoinst.ini
[2009/10/07 01:46:36 | 000,025,752 | ---- | C] () -- C:\Windows\System32\drivers\LVPr2Mon.sys
[2009/10/07 01:23:08 | 000,013,584 | ---- | C] () -- C:\Windows\System32\drivers\iKeyLFT2.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/13 23:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 23:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 179 bytes -> C:\ProgramData\TEMP:D2F2F703
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:443E07A5
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >
Extras.TxtOTL Extras logfile created on: 3/18/2010 3:07:58 PM - Run 1
OTL by OldTimer - Version 3.1.37.2 Folder = C:\Users\Safran\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
3.00 Gb Paging File | 2.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.62 Gb Total Space | 38.14 Gb Free Space | 39.07% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 100.00 Mb Total Space | 69.81 Mb Free Space | 69.81% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 55.66 Gb Total Space | 22.20 Gb Free Space | 39.88% Space Free | Partition Type: NTFS
Computer Name: SAFRAN-PC
Current User Name: Safran
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~3\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{07287123-B8AC-41CE-8346-3D777245C35B}" = Bonjour
"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode
"{13F3917B56CD4C25848BDC69916971BB}" = DivX Converter
"{1451DE6B-ABE1-4F62-BE9A-B363A17588A2}" = QuickTime
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{18D10072035C4515918F7E37EAFAACFC}" = AutoUpdate
"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java 6 Update 18
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery
"{33CF58F5-48D8-4575-83D6-96F574E4D83A}" = Nero DriveSpeed
"{359CFC0A-BEB1-440D-95BA-CF63A86DA34F}" = Nero Recode
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{368BA326-73AD-4351-84ED-3C0A7A52CC53}" = Nero Rescue Agent
"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3FA365DF-2D68-45ED-8F83-8C8A33E65143}" = Apple Application Support
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{43E39830-1826-415D-8BAE-86845787B54B}" = Nero Vision
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport
"{4FBCEA31-5D18-4212-9231-DE7CF1BE7DBB}" = Logitech Vid
"{53567be2-d074-4cb1-88d4-5ecb7843d565}" = Nero 9 Trial
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{595A3116-40BB-4E0F-A2E8-D7951DA56270}" = NeroExpress
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{62AC81F6-BDD3-4110-9D36-3E9EAAB40999}" = Nero CoverDesigner
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{7059BDA7-E1DB-442C-B7A1-6144596720A4}" = HP Update
"{75247E38-5C9B-45D6-ADF8-E11CB56B4990}" = Network
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748AC8C-18E3-43BB-959B-088FAEA16FB2}" = Nero StartSmart
"{7829DB6F-A066-4E40-8912-CB07887C20BB}" = Nero BurnRights
"{7B63B2922B174135AFC0E1377DD81EC2}" = DivX Codec
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{869200DB-287A-4DC0-B02B-2B6787FBCD4C}" = Nero DiscSpeed
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8ADFC4160D694100B5B8A22DE9DCABD9}" = DivX Player
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{94A065E8-455D-41C1-AF1F-F0C1AF8F50F3}" = Microsoft IntelliType Pro 7.0
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95120000-0122-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DC11D9A-6DCD-4064-8363-63914A0122AB}" = C4500
"{9E82B934-9A25-445B-B8DF-8012808074AC}" = Nero PhotoSnap
"{A209525B-3377-43F4-B886-32F6B6E7356F}" = Nero WaveEditor
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A96E97134CA649888820BCDE5E300BBD}" = H.264 Decoder
"{AA6F009F-0CCD-4DD6-A462-28419C101D54}" = HP Photosmart C4500 All-In-One Driver Software 13.0 Rel. 4
"{AAC389499AEF40428987B3D30CFC76C9}" = MKV Splitter
"{AADEA55D-C834-4BCB-98A3-4B8D1C18F4EE}" = Apple Mobile Device Support
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3
"{AEF9DC35ADDF4825B049ACBFD1C6EB37}" = AAC Decoder
"{B13A7C41581B411290FBC0395694E2A9}" = DivX Converter
"{B1ADF008-E898-4FE2-8A1F-690D9A06ACAF}" = DolbyFiles
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B7050CBDB2504B34BC2A9CA0A692CC29}" = DivX Plus Web Player
"{B78120A0-CF84-4366-A393-4D0A59BC546C}" = Menu Templates - Starter Kit
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C5A7CB6C-E76D-408F-BA0E-85605420FE9D}" = SoundTrax
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CC8E94A2-55C7-4460-953C-2A790180578C}" = LightScribe System Software
"{CF408B76-8698-4298-B549-5E6A94931B64}" = PS_AIO_04_C4500_Software_Min
"{D025A639-B9C9-417D-8531-208859000AF8}" = NeroBurningROM
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D9DCF92E-72EB-412D-AC71-3B01276E5F8B}" = Nero ShowTime
"{DA703982C580418795BF4001AA9D7061}" = DivX Plus Media Foundation Components
"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting
"{E498385E-1C51-459A-B45F-1721E37AA1A0}" = Movie Templates - Starter Kit
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F1861F30-3419-44DB-B2A1-C274825698B3}" = Nero Disc Copy Gadget
"{F439D7AF-03F3-4F8E-AEC4-571BFE977C61}" = iTunes
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FBCDFD61-7DCF-4E71-9226-873BA0053139}" = Nero InfoTool
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"CCleaner" = CCleaner
"Clone2Go DVD Ripper_is1" = Clone2Go DVD Ripper 1.8.6
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"DivX Plus DirectShow Filters" = DivX Plus DirectShow Filters
"DVDFab 6_is1" = DVDFab 6.2.0.5
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Updater" = Google Updater
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"HP Smart Web Printing" = HP Smart Web Printing 4.51
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}" = Rome - Total War
"Magic ISO Maker v5.5 (build 0276)" = Magic ISO Maker v5.5 (build 0276)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"NVIDIA Drivers" = NVIDIA Drivers
"PowerISO" = PowerISO
"Registry Easy_is1" = Registry Easy v5.6
"Shop for HP Supplies" = Shop for HP Supplies
"Spyware Doctor" = Spyware Doctor 7.0
"The Ultimate Troubleshooter" = The Ultimate Troubleshooter
"uTorrent" = µTorrent
"Win 32.Malware.Jeefo Removal Tool[2]_is1" = Win 32.Malware.Jeefo Removal Tool[2]
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1823437180-114209430-2017350500-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"blinkx beat" = blinkx beat
========== Last 10 Event Log Errors ========== [ Application Events ]
Error - 3/18/2010 10:40:14 AM | Computer Name = Safran-PC | Source = ESENT | ID = 486
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: An attempt to move the file "C:\Users\Safran\AppData\Local\Microsoft\Windows
Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edbtmp.log"
to "C:\Users\Safran\AppData\Local\Microsoft\Windows Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edb.log"
failed with system error 5 (0x00000005): "Access is denied. ". The move file operation
will fail with error -1032 (0xfffffbf8).
Error - 3/18/2010 10:40:14 AM | Computer Name = Safran-PC | Source = ESENT | ID = 413
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: Unable to create a new logfile
because the database cannot write to the log drive. The drive may be read-only,
out of disk space, misconfigured, or corrupted. Error -1032.
Error - 3/18/2010 10:40:16 AM | Computer Name = Safran-PC | Source = ESENT | ID = 486
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: An attempt to move the file "C:\Users\Safran\AppData\Local\Microsoft\Windows
Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edbtmp.log"
to "C:\Users\Safran\AppData\Local\Microsoft\Windows Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edb.log"
failed with system error 5 (0x00000005): "Access is denied. ". The move file operation
will fail with error -1032 (0xfffffbf8).
Error - 3/18/2010 10:40:16 AM | Computer Name = Safran-PC | Source = ESENT | ID = 413
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: Unable to create a new logfile
because the database cannot write to the log drive. The drive may be read-only,
out of disk space, misconfigured, or corrupted. Error -1032.
Error - 3/18/2010 10:40:18 AM | Computer Name = Safran-PC | Source = ESENT | ID = 486
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: An attempt to move the file "C:\Users\Safran\AppData\Local\Microsoft\Windows
Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edbtmp.log"
to "C:\Users\Safran\AppData\Local\Microsoft\Windows Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edb.log"
failed with system error 5 (0x00000005): "Access is denied. ". The move file operation
will fail with error -1032 (0xfffffbf8).
Error - 3/18/2010 10:40:18 AM | Computer Name = Safran-PC | Source = ESENT | ID = 413
Description = wlcomm (4196) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: Unable to create a new logfile
because the database cannot write to the log drive. The drive may be read-only,
out of disk space, misconfigured, or corrupted. Error -1032.
Error - 3/18/2010 10:40:28 AM | Computer Name = Safran-PC | Source = ESENT | ID = 486
Description = wlcomm (4900) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: An attempt to move the file "C:\Users\Safran\AppData\Local\Microsoft\Windows
Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edbtmp.log"
to "C:\Users\Safran\AppData\Local\Microsoft\Windows Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edb.log"
failed with system error 5 (0x00000005): "Access is denied. ". The move file operation
will fail with error -1032 (0xfffffbf8).
Error - 3/18/2010 10:40:28 AM | Computer Name = Safran-PC | Source = ESENT | ID = 413
Description = wlcomm (4900) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: Unable to create a new logfile
because the database cannot write to the log drive. The drive may be read-only,
out of disk space, misconfigured, or corrupted. Error -1032.
Error - 3/18/2010 10:40:30 AM | Computer Name = Safran-PC | Source = ESENT | ID = 486
Description = wlcomm (4900) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: An attempt to move the file "C:\Users\Safran\AppData\Local\Microsoft\Windows
Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edbtmp.log"
to "C:\Users\Safran\AppData\Local\Microsoft\Windows Live Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\DBStore\LogFiles\edb.log"
failed with system error 5 (0x00000005): "Access is denied. ". The move file operation
will fail with error -1032 (0xfffffbf8).
Error - 3/18/2010 10:40:30 AM | Computer Name = Safran-PC | Source = ESENT | ID = 413
Description = wlcomm (4900) C:\Users\Safran\AppData\Local\Microsoft\Windows Live
Contacts\{bbebe508-05e7-40ab-86ce-772b8e5afaae}\: Unable to create a new logfile
because the database cannot write to the log drive. The drive may be read-only,
out of disk space, misconfigured, or corrupted. Error -1032.
[ OSession Events ]
Error - 2/20/2010 10:38:12 AM | Computer Name = Safran-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 96 seconds with 0 seconds of active time. This session ended with a crash.
Error - 2/20/2010 10:39:44 AM | Computer Name = Safran-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 28 seconds with 0 seconds of active time. This session ended with a crash.
Error - 2/20/2010 10:40:54 AM | Computer Name = Safran-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6500.5000, Microsoft Office Version: 12.0.6425.1000. This session
lasted 12 seconds with 0 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 3/16/2010 9:43:33 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 3/16/2010 9:43:33 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 3/16/2010 9:43:33 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
service which failed to start because of the following error: %%1068
Error - 3/16/2010 9:45:16 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7001
Description = The PnP-X IP Bus Enumerator service depends on the Function Discovery
Provider Host service which failed to start because of the following error: %%1068
Error - 3/16/2010 9:46:44 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%193
Error - 3/16/2010 9:47:57 PM | Computer Name = Safran-PC | Source = DCOM | ID = 10016
Description =
Error - 3/17/2010 4:06:18 PM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%193
Error - 3/17/2010 4:07:25 PM | Computer Name = Safran-PC | Source = DCOM | ID = 10016
Description =
Error - 3/18/2010 10:39:24 AM | Computer Name = Safran-PC | Source = Service Control Manager | ID = 7000
Description = The Google Update Service (gupdate) service failed to start due to
the following error: %%193
Error - 3/18/2010 10:40:35 AM | Computer Name = Safran-PC | Source = DCOM | ID = 10016
Description =
< End of report >