It might just be that coincidently a virus infected my pc at the same time as when I installed net nanny. Thanks in advance.
Edit: I got OTL onto the pc through a usb which i scanned ten times over. I only have the OTL logs. Well, here it is:
OTL logfile created on: 3/05/2010 9:28:29 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = E:\
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 104.33 Gb Total Space | 66.59 Gb Free Space | 63.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 7.88 Gb Total Space | 7.87 Gb Free Space | 99.91% Space Free | Partition Type: FAT32
Drive F: | 232.88 Gb Total Space | 97.68 Gb Free Space | 41.94% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: EDUCATION
Current User Name: Students
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/05/03 20:04:34 | 000,570,880 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
PRC - [2009/02/10 10:42:50 | 000,233,472 | ---- | M] (Vodafone Group) -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe
PRC - [2008/12/08 13:34:32 | 001,173,416 | ---- | M] (PC Tools) -- C:\Program Files\PC Tools Internet Security\pctsTray.exe
PRC - [2008/11/24 21:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
PRC - [2008/10/29 16:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/05/08 09:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) -- C:\Windows\System32\Crypserv.exe
PRC - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
PRC - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2008/01/11 16:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
PRC - [2007/12/26 07:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
PRC - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe
PRC - [2007/11/22 11:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) -- C:\Windows\System32\TODDSrv.exe
PRC - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (SafeList) ==========
MOD - [2010/05/03 20:04:34 | 000,570,880 | ---- | M] (OldTimer Tools) -- E:\OTL.exe
MOD - [2008/01/21 12:24:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx
MOD - [2008/01/21 12:23:44 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (LiveUpdate Notice Service)
SRV - File not found [Auto | Stopped] -- -- (LiveUpdate Notice Ex)
SRV - File not found [Disabled | Stopped] -- -- (.vipre_reset)
SRV - [2010/03/22 05:41:00 | 003,532,120 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2009/03/31 11:23:06 | 000,070,944 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\PC Tools Internet Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2009/02/10 10:42:50 | 000,233,472 | ---- | M] (Vodafone Group) [Auto | Running] -- C:\Program Files\Vodafone\Via The Phone\VodafoneConnectorService.exe -- (VodafoneConnectorService)
SRV - [2008/11/24 21:31:12 | 000,087,904 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe -- (SQLWriter)
SRV - [2008/11/24 21:31:10 | 029,263,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe -- (MSSQL$MSSMLBIZ) SQL Server (MSSMLBIZ)
SRV - [2008/11/24 21:31:08 | 000,239,968 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe -- (SQLBrowser)
SRV - [2008/11/24 21:31:08 | 000,045,408 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe -- (MSSQLServerADHelper)
SRV - [2008/05/08 09:29:38 | 000,122,880 | ---- | M] (CrypKey (Canada) Ltd.) [Auto | Running] -- C:\Windows\System32\Crypserv.exe -- (Crypkey License)
SRV - [2008/01/21 15:54:46 | 000,083,312 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe -- (TNaviSrv)
SRV - [2008/01/21 12:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/01/17 15:27:34 | 000,431,456 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV - [2008/01/11 16:50:16 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
SRV - [2007/12/26 07:07:14 | 000,040,960 | ---- | M] (TOSHIBA CORPORATION) [Auto | Running] -- C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe -- (ConfigFree Service)
SRV - [2007/12/03 16:03:52 | 000,126,976 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe -- (TOSHIBA SMART Log Service)
SRV - [2007/11/22 11:23:32 | 000,129,632 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\System32\TODDSrv.exe -- (TODDSrv)
SRV - [2007/10/29 23:35:40 | 000,937,984 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files\Jumpstart\jswpsapi.exe -- (jswpsapi)
SRV - [2006/08/23 15:39:48 | 000,049,152 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ==========
DRV - [2009/07/10 18:51:54 | 000,033,920 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\system32\Drivers\fsbts.sys -- (fsbts)
DRV - [2009/04/03 11:18:26 | 000,130,936 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\system32\drivers\PCTCore.sys -- (PCTCore)
DRV - [2009/03/10 22:18:16 | 000,103,552 | R--- | M] (QUALCOMM Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\qscvusb.sys -- (MobileAdapter)
DRV - [2008/12/23 02:47:52 | 000,138,240 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/12/18 12:16:56 | 000,073,840 | ---- | M] (PC Tools) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\PCTAppEvent.sys -- (PCTAppEvent)
DRV - [2008/12/11 08:38:22 | 000,159,600 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\System32\drivers\pctgntdi.sys -- (pctgntdi)
DRV - [2008/12/10 11:36:06 | 000,064,424 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pctplsg.sys -- (pctplsg)
DRV - [2008/12/10 11:36:04 | 000,095,656 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pctplfw.sys -- (pctplfw)
DRV - [2008/10/31 06:09:06 | 000,270,888 | R--- | M] (Sunbelt Software, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\SbFw.sys -- (SbFw)
DRV - [2008/09/23 23:35:30 | 000,035,552 | ---- | M] (F-Secure Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\fses.sys -- (FSES)
DRV - [2008/08/14 09:40:40 | 000,203,312 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SynTP.sys -- (SynTP)
DRV - [2008/07/29 04:05:04 | 000,919,552 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/06/23 08:44:54 | 000,062,464 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTSTOR.sys -- (RTSTOR)
DRV - [2008/06/21 03:54:54 | 000,065,576 | ---- | M] (Sunbelt Software, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SbFwIm.sys -- (SBFWIMCL)
DRV - [2008/03/18 02:45:54 | 000,019,584 | ---- | M] () [Kernel | System | Running] -- C:\Windows\system32\ckldrv.sys -- (NetworkX)
DRV - [2008/01/30 13:34:20 | 002,058,528 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/01/21 14:42:24 | 000,285,184 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\tos_sps32.sys -- (tos_sps32)
DRV - [2008/01/21 12:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 12:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 12:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 12:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 12:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 12:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 12:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 12:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 12:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 12:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2008/01/21 12:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 12:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 12:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 12:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 12:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 12:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 12:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 12:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 12:23:22 | 000,200,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTAZL3.SYS -- (HSFHWAZL)
DRV - [2008/01/21 12:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 12:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 12:23:21 | 000,073,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/01/21 12:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 12:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 12:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 12:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 12:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/12/17 10:45:20 | 000,018,432 | ---- | M] (Chicony Electronics Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UVCFTR_S.SYS -- (UVCFTR)
DRV - [2007/11/09 13:00:52 | 000,023,640 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\TVALZ_O.SYS -- (TVALZ)
DRV - [2007/11/01 02:51:26 | 000,985,600 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_DPV.sys -- (HSF_DPV)
DRV - [2007/11/01 02:47:54 | 000,208,896 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSXHWAZL.sys -- (HSXHWAZL)
DRV - [2007/11/01 02:47:08 | 000,661,504 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2007/10/18 00:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/09/30 16:03:12 | 000,308,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\iaStor.sys -- (iaStor)
DRV - [2007/09/13 16:23:50 | 001,925,632 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\igdkmd32.sys -- (igfx)
DRV - [2007/08/31 16:43:32 | 000,020,352 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\jswpslwf.sys -- (jswpslwf)
DRV - [2007/05/03 12:37:08 | 000,022,152 | ---- | M] (Maxtor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mxopswd.sys -- (MXOPSWD)
DRV - [2006/11/21 08:11:14 | 000,007,168 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\FwLnk.sys -- (FwLnk)
DRV - [2006/11/02 19:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 19:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 19:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 19:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 19:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 19:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 19:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 19:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 19:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 19:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 19:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 18:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 18:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 18:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 18:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 18:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 18:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 17:41:50 | 000,983,552 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2006/11/02 17:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/10/19 05:50:04 | 000,016,128 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV - [2002/07/17 14:20:32 | 000,084,832 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:4.9
FF - prefs.js..extensions.enabledItems: {0329E7D6-6F54-462D-93F6-F5C3118BADF2}:2.2.4
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\
FF - HKLM\software\mozilla\Firefox\Extensions\\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}: C:\Program Files\SpeedBit Video Downloader\SPFireFox [2010/04/15 10:56:00 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/15 10:16:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/15 16:11:21 | 000,000,000 | ---D | M]
[2009/11/03 14:47:38 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Mozilla\Extensions
[2009/09/17 15:38:22 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Mozilla\Extensions\MediaCoder
[2010/05/03 16:57:57 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions
[2010/04/15 10:34:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions\{0329E7D6-6F54-462D-93F6-F5C3118BADF2}
[2010/04/26 10:13:48 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/12/21 14:15:12 | 000,000,000 | ---D | M] (WOT) -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/15 16:40:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/03/12 16:26:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Students\AppData\Roaming\Mozilla\Firefox\Profiles\ezaf057h.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2009/11/17 16:16:45 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/04/14 17:51:19 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2009/02/09 15:05:22 | 000,002,236 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\askcom.xml
[2010/04/14 17:51:19 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/04/14 17:51:19 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/04/14 17:51:19 | 000,000,831 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
Hosts file not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (SBCONVERT Class) - {3017FB3E-9A77-4396-88C5-0EC9548FB42F} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O2 - BHO: (SearchPredictObj Class) - {389943B0-C3A2-4E69-82CB-8596A84CB3DC} - C:\Program Files\SearchPredict\SearchPredict.dll (Speedbit Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.3.4501.1418\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll (Google Inc.)
O2 - BHO: (GrabberObj Class) - {FF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\SpeedBit Video Downloader\Toolbar\Grabber.dll (Speedbit Ltd.)
O3 - HKLM\..\Toolbar: (SpeedBit Video Downloader) - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - C:\Program Files\SpeedBit Video Downloader\Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [ISTray] C:\Program Files\PC Tools Internet Security\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE (TOSHIBA Corporation)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe File not found
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetIcon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra Button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - Reg Error: Key error. File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - Reg Error: Value error. File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Value error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Value error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\microsoft shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Users\Students\Pictures\Gundam\Gundam_00_Wallpaper_2_by_CCJ-1.jpg
O24 - Desktop BackupWallPaper: C:\Users\Students\Pictures\Gundam\Gundam_00_Wallpaper_2_by_CCJ-1.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 07:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007/05/10 07:48:26 | 000,000,032 | ---- | M] () - F:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{2494d072-a5b7-11de-a226-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{33759c42-f506-11de-8d26-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{33759c42-f506-11de-8d26-001e3356292a}\Shell\AutoRun\command - "" = E:\VDFPcAssistant.exe -- File not found
O33 - MountPoints2\{3970ddf2-f2b2-11de-bb3a-001e3356292a}\Shell\AutoRun\command - "" = G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\winoper.exe -- File not found
O33 - MountPoints2\{3970ddf2-f2b2-11de-bb3a-001e3356292a}\Shell\open\command - "" = G:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013\winoper.exe -- File not found
O33 - MountPoints2\{6c139a67-a80b-11de-adad-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{6c139a69-a80b-11de-adad-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{7901dd5f-ecc0-11dd-b4e8-001e3356292a}\Shell\AutoRun\command - "" = E:\Launch.exe -- File not found
O33 - MountPoints2\{99a3dde9-a596-11de-ada9-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{99a3ddea-a596-11de-ada9-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{99a3ddea-a596-11de-ada9-001e3356292a}\Shell\AutoRun\command - "" = E:\VDFPcAssistant.exe -- File not found
O33 - MountPoints2\{f6720392-5356-11df-9bc7-001e3356292a}\Shell - "" = AutoRun
O33 - MountPoints2\{f6720392-5356-11df-9bc7-001e3356292a}\Shell\AutoRun\command - "" = E:\VDFPcAssistant.exe -- File not found
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Launch.exe -- [2004/10/21 20:38:02 | 000,126,976 | ---- | M] (Macrovision Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/01/21 12:34:27 | 000,000,000 | ---D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010/05/03 20:12:00 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/03 20:11:58 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/05/03 20:11:58 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/03 19:29:07 | 000,000,000 | ---D | C] -- C:\Users\Students\{3b53f51e-1882-4c43-9c9e-8e7aeecd74d1}
[2010/05/03 19:28:21 | 000,159,600 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctgntdi.sys
[2010/05/03 19:28:17 | 000,051,488 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfFsMon.sys
[2010/05/03 19:28:17 | 000,039,200 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfSysMon.sys
[2010/05/03 19:28:17 | 000,033,056 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfNetMon.sys
[2010/05/03 19:28:17 | 000,012,576 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\TfKbMon.sys
[2010/05/03 19:28:14 | 000,095,656 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplfw.sys
[2010/05/03 19:28:14 | 000,064,424 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\pctplsg.sys
[2010/05/03 19:28:08 | 000,000,000 | ---D | C] -- C:\Program Files\PC Tools Internet Security
[2010/05/03 19:28:08 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\PC Tools
[2010/05/03 18:21:58 | 000,248,128 | ---- | C] (ContentWatch, Inc.) -- C:\Windows\System32\wxIE.dll
[2010/05/03 18:21:55 | 001,880,064 | ---- | C] (ContentWatch, Inc.) -- C:\Windows\System32\AltaRecovery.exe
[2010/05/03 18:21:55 | 000,719,872 | ---- | C] (ContentWatch, Inc.) -- C:\Windows\System32\cwalsp.dll
[2010/05/03 18:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\ContentWatch
[2010/05/03 17:55:02 | 000,446,464 | ---- | C] (Blue Sky Software Corporation.) -- C:\Windows\System32\HHActiveX.dll
[2010/05/03 17:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\Norton
[2010/04/28 16:47:26 | 000,000,000 | ---D | C] -- C:\Users\Students\Desktop\56
[2010/04/23 15:51:34 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2010/04/23 14:46:28 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\VS Revo Group
[2010/04/23 14:45:38 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2010/04/23 10:05:00 | 000,000,000 | ---D | C] -- C:\Users\Students\Documents\Graboid
[2010/04/23 10:02:41 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\Graboid
[2010/04/23 10:02:13 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\MozillaControl
[2010/04/23 09:45:21 | 000,000,000 | ---D | C] -- C:\Program Files\Veoh Networks
[2010/04/19 16:47:38 | 000,000,000 | ---D | C] -- C:\Users\Students\Documents\My Chat Logs
[2010/04/19 16:46:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Messenger Plus!
[2010/04/19 16:41:03 | 000,000,000 | ---D | C] -- C:\Program Files\Messenger Plus! Live
[2010/04/19 16:34:46 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live SkyDrive
[2010/04/18 19:59:06 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\Locktime
[2010/04/18 19:52:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Locktime
[2010/04/17 17:42:28 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\ApplicationHistory
[2010/04/16 09:57:17 | 003,532,120 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des
[2010/04/16 09:56:20 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\INCA Shared
[2010/04/16 09:55:39 | 000,004,682 | ---- | C] (INCA Internet Co., Ltd.) -- C:\Windows\System32\npptNT2.sys
[2010/04/15 19:59:54 | 000,130,936 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTCore.sys
[2010/04/15 19:59:54 | 000,073,840 | ---- | C] (PC Tools) -- C:\Windows\System32\drivers\PCTAppEvent.sys
[2010/04/15 19:59:41 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PC Tools
[2010/04/15 18:12:08 | 000,000,000 | ---D | C] -- C:\Program Files\Outspark
[2010/04/15 17:27:55 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/04/15 16:55:59 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\PMB Files
[2010/04/15 16:55:54 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2010/04/15 16:55:30 | 000,000,000 | ---D | C] -- C:\Program Files\Pando Networks
[2010/04/15 10:59:24 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/04/15 10:55:47 | 000,000,000 | ---D | C] -- C:\Program Files\SearchPredict
[2010/04/15 10:55:45 | 000,000,000 | ---D | C] -- C:\Program Files\SpeedBit Video Downloader
[2010/04/15 10:07:19 | 000,000,000 | ---D | C] -- C:\Windows\System32\URTTEMP
[2010/04/15 09:18:46 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\BitDefender
[2010/04/15 09:17:48 | 000,000,000 | ---D | C] -- C:\ProgramData\BitDefender
[2010/04/15 09:17:48 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender
[2010/04/15 09:13:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender
[2010/04/14 18:08:36 | 000,000,000 | ---D | C] -- C:\Program Files\Webroot
[2010/04/14 17:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\MSSOAP
[2010/04/14 17:41:56 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\MSSoap
[2010/04/13 21:03:33 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\Ubisoft
[2010/04/13 17:57:34 | 000,000,000 | ---D | C] -- C:\Users\Students\Documents\Cakewalk
[2010/04/13 17:57:34 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\Cakewalk
[2010/04/13 17:49:59 | 000,000,000 | ---D | C] -- C:\Program Files\Sibelius Software
[2010/04/13 17:49:59 | 000,000,000 | ---D | C] -- C:\Users\Students\Documents\Scores
[2010/04/13 17:34:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Identities
[2010/04/13 17:27:17 | 000,000,000 | ---D | C] -- C:\Program Files\Cakewalk
[2010/04/13 17:25:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Cakewalk
[2010/04/13 15:06:37 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\PCToolsFirewallPlus
[2010/04/13 15:06:36 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Roaming\PCToolsSpamMonitorPlus
[2010/04/13 14:29:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft DirectX SDK (February 2010)
[2010/04/12 22:59:39 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/04/12 14:29:18 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\phhwsmfmm
[2010/04/11 21:42:11 | 000,000,000 | ---D | C] -- C:\Users\Students\AppData\Local\Thinstall
[2010/04/03 14:20:14 | 000,000,000 | ---D | C] -- C:\ProgramData\PopCap Games
[2010/03/27 16:19:59 | 000,000,000 | ---D | C] -- C:\Users\Students\Desktop\Emoticons
[2010/03/13 16:54:36 | 000,000,000 | ---D | C] -- C:\Users\Students\Desktop\Jules DS Card (unofficial)
[1 C:\Users\Students\Desktop\*.tmp files -> C:\Users\Students\Desktop\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/05/03 21:32:37 | 009,961,472 | -HS- | M] () -- C:\Users\Students\ntuser.dat
[2010/05/03 21:22:32 | 000,019,752 | ---- | M] () -- C:\Users\Students\Desktop\Geography Half-Yearly Revision.docx
[2010/05/03 20:31:33 | 000,666,000 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/05/03 20:31:32 | 000,784,636 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/05/03 20:31:32 | 000,132,260 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/05/03 20:12:03 | 000,000,847 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/03 20:05:10 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/05/03 20:05:10 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/05/03 20:05:04 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/05/03 20:03:06 | 000,524,288 | -HS- | M] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TMContainer00000000000000000001.regtrans-ms
[2010/05/03 20:03:06 | 000,065,536 | -HS- | M] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TM.blf
[2010/05/03 20:03:05 | 002,640,575 | -H-- | M] () -- C:\Users\Students\AppData\Local\IconCache.db
[2010/05/03 19:28:17 | 000,001,920 | ---- | M] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2010/05/03 18:48:08 | 000,439,344 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/05/03 18:43:38 | 000,001,356 | ---- | M] () -- C:\Users\Students\AppData\Local\d3d9caps.dat
[2010/05/03 18:30:57 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/05/03 18:30:54 | 000,000,368 | ---- | M] () -- C:\Windows\tasks\AWC Startup.job
[2010/05/03 18:27:03 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/03 18:27:02 | 000,000,272 | ---- | M] () -- C:\Windows\tasks\SpeedOptimizer Startup.job
[2010/05/03 18:06:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/03 17:55:05 | 000,000,020 | ---- | M] () -- C:\Windows\NNS.INI
[2010/05/03 16:52:52 | 000,002,627 | ---- | M] () -- C:\Users\Students\Desktop\Microsoft Office Word 2007.lnk
[2010/05/03 16:49:31 | 000,131,072 | ---- | M] () -- C:\Windows\ocsetup_install_NetFx3.etl
[2010/05/02 13:47:12 | 000,002,595 | ---- | M] () -- C:\Users\Students\Desktop\Microsoft Office PowerPoint 2007.lnk
[2010/04/29 16:55:32 | 000,111,143 | ---- | M] () -- C:\Users\Students\Desktop\10am May 02 10.pdf
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/29 08:07:04 | 000,248,128 | ---- | M] (ContentWatch, Inc.) -- C:\Windows\System32\wxIE.dll
[2010/04/29 08:06:56 | 001,880,064 | ---- | M] (ContentWatch, Inc.) -- C:\Windows\System32\AltaRecovery.exe
[2010/04/27 09:22:52 | 000,719,872 | ---- | M] (ContentWatch, Inc.) -- C:\Windows\System32\cwalsp.dll
[2010/04/25 22:18:20 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\SmartDefrag.job
[2010/04/23 17:11:39 | 000,000,052 | ---- | M] () -- C:\Windows\System32\ashttpstats.csv
[2010/04/23 17:03:14 | 000,000,025 | ---- | M] () -- C:\Users\Students\AppData\Roaming\bdfvconp.ini
[2010/04/23 17:01:18 | 000,524,288 | -HS- | M] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TMContainer00000000000000000002.regtrans-ms
[2010/04/23 16:16:50 | 000,524,288 | -HS- | M] () -- C:\Users\Students\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010/04/23 16:16:50 | 000,065,536 | -HS- | M] () -- C:\Users\Students\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/04/16 09:03:40 | 000,000,635 | ---- | M] () -- C:\Users\Students\Desktop\Flyff.lnk
[2010/04/15 18:12:02 | 000,000,873 | ---- | M] () -- C:\Users\Public\Desktop\Fiesta.lnk
[2010/04/15 17:36:27 | 000,002,303 | ---- | M] () -- C:\Users\Students\Desktop\Sibelius 5.lnk
[2010/04/15 10:59:48 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/04/15 10:59:48 | 000,065,536 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/04/15 10:30:10 | 000,000,016 | ---- | M] () -- C:\Windows\System32\asdict.dat
[2010/04/15 10:30:10 | 000,000,004 | ---- | M] () -- C:\Windows\System32\aspdict-en.dat
[2010/04/15 10:16:31 | 000,000,385 | ---- | M] () -- C:\Windows\System32\user_gensett.xml
[2010/04/15 09:55:25 | 000,000,132 | ---- | M] () -- C:\Windows\System32\rezumatenoi.dat
[2010/04/15 09:31:21 | 000,072,200 | ---- | M] (BitDefender LLC) -- C:\Windows\System32\drivers\BdfNdisf6.sys
[2010/04/14 18:18:56 | 000,350,680 | R--- | M] () -- C:\Windows\System32\drivers\etc\HOSTS.bak
[2010/04/14 18:10:10 | 000,000,275 | ---- | M] () -- C:\Windows\win.ini
[2010/04/14 18:04:59 | 000,000,164 | ---- | M] () -- C:\Windows\install.dat
[2010/04/14 17:53:49 | 000,001,074 | ---- | M] () -- C:\Users\Students\Desktop\Revo Uninstaller.lnk
[2010/04/13 18:12:25 | 000,000,699 | ---- | M] () -- C:\Users\Students\Desktop\Photoshop CS4.lnk
[2010/04/13 17:55:24 | 000,134,128 | ---- | M] () -- C:\Users\Students\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/04/13 07:22:12 | 000,004,590 | RHS- | M] () -- C:\Users\Students\ntuser.pol
[2010/03/22 05:41:00 | 003,532,120 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\System32\GameMon.des
[2010/03/16 09:19:26 | 000,081,920 | ---- | M] () -- C:\Windows\System32\wxcode_msw28u_wxjson_CW.dll
[2010/03/16 09:19:16 | 001,073,152 | ---- | M] () -- C:\Windows\System32\wxcode_msw28u_wxcurl_CW.dll
[2010/03/16 09:17:02 | 000,975,872 | ---- | M] () -- C:\Windows\System32\libxml2_CW.dll
[2010/03/16 09:13:14 | 000,151,552 | ---- | M] () -- C:\Windows\System32\libexpat.dll
[2010/03/16 08:54:14 | 002,916,352 | ---- | M] () -- C:\Windows\System32\wxmsw28u_core_vc_CW.dll
[2010/03/16 08:54:14 | 001,236,992 | ---- | M] () -- C:\Windows\System32\wxbase28u_vc_CW.dll
[2010/03/16 08:54:14 | 000,716,800 | ---- | M] () -- C:\Windows\System32\wxmsw28u_adv_vc_CW.dll
[2010/03/16 08:54:14 | 000,524,288 | ---- | M] () -- C:\Windows\System32\wxmsw28u_xrc_vc_CW.dll
[2010/03/16 08:54:14 | 000,499,712 | ---- | M] () -- C:\Windows\System32\wxmsw28u_html_vc_CW.dll
[2010/03/16 08:54:14 | 000,135,168 | ---- | M] () -- C:\Windows\System32\wxbase28u_xml_vc_CW.dll
[2010/03/16 08:54:14 | 000,135,168 | ---- | M] () -- C:\Windows\System32\wxbase28u_net_vc_CW.dll
[2010/03/16 08:54:14 | 000,110,592 | ---- | M] () -- C:\Windows\System32\wxmsw28u_media_vc_CW.dll
[2010/02/06 10:17:26 | 000,100,864 | ---- | M] () -- C:\Users\Students\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Files Created - No Company Name ==========
[2010/05/03 20:12:03 | 000,000,847 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/03 19:28:17 | 000,001,920 | ---- | C] () -- C:\Users\Public\Desktop\PC Tools Internet Security.lnk
[2010/05/03 18:21:57 | 000,975,872 | ---- | C] () -- C:\Windows\System32\libxml2_CW.dll
[2010/05/03 18:21:57 | 000,151,552 | ---- | C] () -- C:\Windows\System32\libexpat.dll
[2010/05/03 18:21:53 | 001,073,152 | ---- | C] () -- C:\Windows\System32\wxcode_msw28u_wxcurl_CW.dll
[2010/05/03 18:21:53 | 000,524,288 | ---- | C] () -- C:\Windows\System32\wxmsw28u_xrc_vc_CW.dll
[2010/05/03 18:21:53 | 000,110,592 | ---- | C] () -- C:\Windows\System32\wxmsw28u_media_vc_CW.dll
[2010/05/03 18:21:53 | 000,081,920 | ---- | C] () -- C:\Windows\System32\wxcode_msw28u_wxjson_CW.dll
[2010/05/03 18:21:52 | 002,916,352 | ---- | C] () -- C:\Windows\System32\wxmsw28u_core_vc_CW.dll
[2010/05/03 18:21:52 | 001,236,992 | ---- | C] () -- C:\Windows\System32\wxbase28u_vc_CW.dll
[2010/05/03 18:21:52 | 000,716,800 | ---- | C] () -- C:\Windows\System32\wxmsw28u_adv_vc_CW.dll
[2010/05/03 18:21:52 | 000,499,712 | ---- | C] () -- C:\Windows\System32\wxmsw28u_html_vc_CW.dll
[2010/05/03 18:21:52 | 000,135,168 | ---- | C] () -- C:\Windows\System32\wxbase28u_xml_vc_CW.dll
[2010/05/03 18:21:52 | 000,135,168 | ---- | C] () -- C:\Windows\System32\wxbase28u_net_vc_CW.dll
[2010/05/03 17:55:41 | 000,019,752 | ---- | C] () -- C:\Users\Students\Desktop\Geography Half-Yearly Revision.docx
[2010/05/03 17:55:05 | 000,000,020 | ---- | C] () -- C:\Windows\NNS.INI
[2010/05/02 16:33:27 | 000,182,342 | ---- | C] () -- C:\Users\Students\Desktop\Capture.JPG
[2010/05/02 16:03:36 | 000,800,124 | ---- | C] () -- C:\Users\Students\Desktop\poster.docx
[2010/05/02 14:14:32 | 000,072,743 | ---- | C] () -- C:\Users\Students\Desktop\26634_327828743004_746343004_3685296_3666231_n.jpg
[2010/05/02 13:45:10 | 000,128,422 | ---- | C] () -- C:\Users\Students\Desktop\IMGA0056.JPG
[2010/05/02 13:45:10 | 000,126,391 | ---- | C] () -- C:\Users\Students\Desktop\IMGA0055.JPG
[2010/05/02 13:45:10 | 000,120,588 | ---- | C] () -- C:\Users\Students\Desktop\IMGA0054.JPG
[2010/05/02 13:45:10 | 000,118,885 | ---- | C] () -- C:\Users\Students\Desktop\IMGA0053.JPG
[2010/05/01 21:01:31 | 000,000,890 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/01 21:01:29 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/01 20:41:34 | 043,942,518 | ---- | C] () -- C:\Users\Students\Desktop\Hosanna Hillsong Live _Saviour King_ - Brooke Fraser.flv
[2010/05/01 17:54:17 | 000,012,832 | ---- | C] () -- C:\Users\Students\Desktop\solution 1.docx
[2010/05/01 17:31:20 | 000,016,792 | ---- | C] () -- C:\Users\Students\Desktop\Doc1.docx
[2010/05/01 15:14:11 | 000,050,041 | ---- | C] () -- C:\Users\Students\Desktop\LOLLEGEND.jpg
[2010/04/30 16:00:55 | 004,747,040 | ---- | C] () -- C:\Users\Students\Desktop\In Christ Alone.mp3
[2010/04/29 16:55:31 | 000,111,143 | ---- | C] () -- C:\Users\Students\Desktop\10am May 02 10.pdf
[2010/04/29 16:29:00 | 009,016,143 | ---- | C] () -- C:\Users\Students\Desktop\In Christ Alone.flv
[2010/04/29 16:28:40 | 003,211,538 | ---- | C] () -- C:\Users\Students\Desktop\Jesus saves.mp3
[2010/04/29 16:28:29 | 004,674,927 | ---- | C] () -- C:\Users\Students\Desktop\You Alone Can Rescue.mp3
[2010/04/29 16:28:13 | 004,009,118 | ---- | C] () -- C:\Users\Students\Desktop\The Saving One.mp3
[2010/04/23 17:03:14 | 000,000,025 | ---- | C] () -- C:\Users\Students\AppData\Roaming\bdfvconp.ini
[2010/04/23 16:19:43 | 000,524,288 | -HS- | C] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TMContainer00000000000000000002.regtrans-ms
[2010/04/23 16:19:43 | 000,524,288 | -HS- | C] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TMContainer00000000000000000001.regtrans-ms
[2010/04/23 16:19:43 | 000,065,536 | -HS- | C] () -- C:\Users\Students\ntuser.dat{6077c319-4e9f-11df-b661-8f3e559008b8}.TM.blf
[2010/04/16 09:55:39 | 000,005,174 | ---- | C] () -- C:\Windows\System32\nppt9x.vxd
[2010/04/16 09:03:40 | 000,000,635 | ---- | C] () -- C:\Users\Students\Desktop\Flyff.lnk
[2010/04/15 18:12:02 | 000,000,873 | ---- | C] () -- C:\Users\Public\Desktop\Fiesta.lnk
[2010/04/15 17:44:18 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2010/04/15 17:44:16 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010/04/15 10:59:48 | 000,131,072 | ---- | C] () -- C:\Windows\ocsetup_install_NetFx3.etl
[2010/04/15 10:59:48 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_NetFx3.perf
[2010/04/15 10:59:48 | 000,065,536 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_NetFx3.dpx
[2010/04/15 10:30:10 | 000,000,016 | ---- | C] () -- C:\Windows\System32\asdict.dat
[2010/04/15 10:30:10 | 000,000,004 | ---- | C] () -- C:\Windows\System32\aspdict-en.dat
[2010/04/15 10:25:11 | 000,000,052 | ---- | C] () -- C:\Windows\System32\ashttpstats.csv
[2010/04/15 10:16:31 | 000,000,385 | ---- | C] () -- C:\Windows\System32\user_gensett.xml
[2010/04/15 09:37:45 | 000,000,132 | ---- | C] () -- C:\Windows\System32\rezumatenoi.dat
[2010/04/14 18:04:54 | 000,000,164 | ---- | C] () -- C:\Windows\install.dat
[2010/04/14 17:53:49 | 000,001,074 | ---- | C] () -- C:\Users\Students\Desktop\Revo Uninstaller.lnk
[2010/04/13 18:12:25 | 000,000,699 | ---- | C] () -- C:\Users\Students\Desktop\Photoshop CS4.lnk
[2010/04/13 17:50:56 | 000,002,303 | ---- | C] () -- C:\Users\Students\Desktop\Sibelius 5.lnk
[2010/03/13 21:35:01 | 000,408,064 | ---- | C] () -- C:\Users\Students\Desktop\Pokesav HGSS - ENG.org.exe
[2009/11/12 16:39:51 | 002,392,064 | ---- | C] () -- C:\Windows\System32\videotrans.dll
[2009/11/12 16:39:47 | 000,215,040 | ---- | C] () -- C:\Windows\System32\videoformat.dll
[2009/11/12 16:39:46 | 000,017,920 | ---- | C] () -- C:\Windows\System32\videocore.dll
[2009/11/12 16:39:44 | 000,061,440 | ---- | C] () -- C:\Windows\System32\imgscaler.dll
[2009/11/12 16:39:44 | 000,022,016 | ---- | C] () -- C:\Windows\System32\img_utils.dll
[2009/11/05 19:46:46 | 000,059,392 | R--- | C] () -- C:\Windows\System32\streamhlp.dll
[2009/10/19 16:11:31 | 000,000,068 | ---- | C] () -- C:\Windows\spwdr.INI
[2009/10/19 15:54:25 | 000,000,105 | ---- | C] () -- C:\Windows\Crypkey.ini
[2009/10/19 15:53:54 | 000,019,584 | ---- | C] () -- C:\Windows\System32\Ckldrv.sys
[2009/10/19 15:53:54 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2009/09/19 08:59:30 | 000,043,520 | ---- | C] () -- C:\Windows\System32\CmdLineExt03.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/03/07 17:09:50 | 000,033,920 | ---- | C] () -- C:\Windows\System32\drivers\fsbts.sys
[2008/11/01 19:35:33 | 000,000,145 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2008/11/01 19:35:33 | 000,000,040 | ---- | C] () -- C:\Windows\BRDIAG.INI
[2008/11/01 19:35:33 | 000,000,023 | ---- | C] () -- C:\Windows\Brownie.ini
[2008/11/01 19:35:30 | 000,077,824 | ---- | C] () -- C:\Windows\System32\BROSNMP.DLL
[2008/11/01 19:35:30 | 000,026,624 | ---- | C] () -- C:\Windows\System32\BRGSRC32.DLL
[2008/11/01 19:35:30 | 000,004,608 | ---- | C] () -- C:\Windows\System32\BRGSRC16.DLL
[2008/11/01 19:35:29 | 000,009,013 | ---- | C] () -- C:\Windows\HL-2040.INI
[2008/11/01 19:34:17 | 000,000,410 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2008/10/27 20:41:26 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2008/10/27 20:41:26 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2008/10/27 20:41:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2008/10/27 20:41:26 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2008/10/27 20:41:26 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2008/10/27 20:41:26 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2008/10/27 20:23:16 | 000,128,113 | ---- | C] () -- C:\Windows\System32\csellang.ini
[2008/10/27 20:23:16 | 000,045,056 | ---- | C] () -- C:\Windows\System32\csellang.dll
[2008/10/27 20:23:16 | 000,009,484 | ---- | C] () -- C:\Windows\System32\tosmreg.ini
[2008/10/27 20:23:16 | 000,007,671 | ---- | C] () -- C:\Windows\System32\cseltbl.ini
[2008/02/12 10:10:35 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2008/02/12 09:16:12 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/02/12 09:05:13 | 001,238,832 | ---- | C] () -- C:\Windows\System32\igmedkrn.dll
[2008/02/12 09:05:13 | 000,249,856 | ---- | C] () -- C:\Windows\System32\igfxTMM.dll
[2008/02/12 09:05:13 | 000,147,456 | ---- | C] () -- C:\Windows\System32\igfxCoIn_v1329.dll
[2008/02/12 09:05:13 | 000,104,636 | ---- | C] () -- C:\Windows\System32\igmedcompkrn.dll
[2008/01/28 17:01:42 | 000,057,344 | ---- | C] () -- C:\Windows\System32\SmartFaceVCapt.dll
[2008/01/28 17:01:06 | 000,471,040 | ---- | C] () -- C:\Windows\System32\SmartFaceVCP.dll
[2008/01/28 16:53:02 | 006,701,056 | ---- | C] () -- C:\Windows\System32\FaceHI.dll
[2008/01/28 16:53:02 | 000,995,328 | ---- | C] () -- C:\Windows\System32\FaceRec.dll
[2008/01/28 16:53:02 | 000,126,976 | ---- | C] () -- C:\Windows\System32\SmartFaceVCtrl.dll
[2008/01/28 16:52:28 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IppLib.dll
[2006/11/02 22:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 17:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2009/11/10 15:15:24 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Any Video Converter
[2010/01/17 14:44:15 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Any Video Converter Professional
[2009/09/23 18:55:09 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Apowersoft
[2010/04/15 09:18:46 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\BitDefender
[2009/11/27 16:01:17 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\BitTorrent
[2009/11/10 15:31:32 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Broad Intelligence
[2010/04/13 17:58:02 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Cakewalk
[2009/12/27 16:51:52 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\CoSoSys
[2009/09/12 21:27:10 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\F-Secure
[2009/10/04 09:46:40 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\fizzy
[2009/11/02 18:36:52 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\fretsonfire
[2009/11/23 16:21:19 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\FVZilla
[2009/11/21 14:07:32 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\GetRightToGo
[2009/11/01 09:18:53 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Hide IP NG
[2010/01/12 08:00:28 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Image Zone Express
[2009/11/14 08:30:33 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\IObit
[2009/06/20 19:23:25 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\LEGO Company
[2009/10/01 20:00:20 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\LimeWire
[2009/12/29 08:54:12 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Local Settings
[2010/04/18 19:59:06 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Locktime
[2009/10/01 20:38:15 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\MusE
[2010/04/13 11:31:02 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\NCH Swift Sound
[2009/09/16 18:14:02 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\PandoraRecovery
[2010/04/13 15:06:37 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\PCToolsFirewallPlus
[2010/04/13 15:06:36 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\PCToolsSpamMonitorPlus
[2009/09/13 15:59:39 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\PeerNetworking
[2009/09/12 19:35:07 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Printer Info Cache
[2010/04/12 20:43:41 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\QuickScan
[2009/11/21 17:01:30 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\River Past G5
[2009/01/12 09:48:01 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\School Zone Preferences
[2009/11/01 09:45:19 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Shareaza
[2009/09/18 19:57:27 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\SpeedBit
[2010/03/25 19:06:54 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Thinstall
[2008/10/28 19:42:17 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\TOSHIBA
[2009/11/10 16:20:37 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\TrojanHunter
[2010/04/13 21:03:33 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Ubisoft
[2009/11/20 19:13:43 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Ulead Systems
[2009/11/20 21:00:59 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\uTorrent
[2009/11/20 16:34:07 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\VSO
[2009/12/29 08:54:12 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\WinMount
[2010/01/21 07:44:03 | 000,000,000 | ---D | M] -- C:\Users\Students\AppData\Roaming\Xilisoft Corporation
[2010/05/03 18:30:54 | 000,000,368 | ---- | M] () -- C:\Windows\Tasks\AWC Startup.job
[2010/05/03 18:30:57 | 000,032,582 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2010/04/25 22:18:20 | 000,000,382 | ---- | M] () -- C:\Windows\Tasks\SmartDefrag.job
[2010/05/03 18:27:02 | 000,000,272 | ---- | M] () -- C:\Windows\Tasks\SpeedOptimizer Startup.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/19 07:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2010/04/23 17:11:41 | 000,006,608 | ---- | M] () -- C:\bdlog.txt
[2008/01/21 12:24:42 | 000,333,203 | RHS- | M] () -- C:\bootmgr
[2008/02/12 08:50:12 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/09/19 07:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2008/02/12 09:01:06 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2008/02/12 09:01:06 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2010/05/03 20:04:55 | 2450,755,584 | -HS- | M] () -- C:\pagefile.sys
[2010/04/14 17:56:01 | 000,000,000 | -H-- | M] () -- C:\ProgramData.LOG1
[2010/04/14 17:56:01 | 000,000,000 | -H-- | M] () -- C:\ProgramData.LOG2
[2010/04/23 15:51:34 | 000,000,104 | ---- | M] () -- C:\VundoFix.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/21 12:24:42 | 000,242,744 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\rsaenh.dll
[2008/01/21 12:24:38 | 000,225,792 | ---- | M] (Microsoft Corporation) Unable to obtain MD5 -- C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2008/01/21 13:14:18 | 016,846,848 | ---- | M] () -- C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/21 13:14:08 | 000,106,496 | ---- | M] () -- C:\Windows\System32\config\DEFAULT.SAV
[2008/01/21 13:14:18 | 000,020,480 | ---- | M] () -- C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 20:34:08 | 010,133,504 | ---- | M] () -- C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 20:34:08 | 001,826,816 | ---- | M] () -- C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/15 09:31:21 | 000,072,200 | ---- | M] (BitDefender LLC) -- C:\Windows\System32\drivers\BdfNdisf6.sys
[2010/02/21 07:18:40 | 000,411,136 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\http.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 21:32:31 | 000,105,984 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 21:32:36 | 000,212,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 21:32:33 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\mrxsmb20.sys
[2010/02/19 00:49:38 | 000,898,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tcpip.sys
[2010/02/18 21:52:00 | 000,025,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\drivers\tunnel.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 22528 bytes -> C:\Windows\System32\autochk.exe:BAK
@Alternate Data Stream - 176 bytes -> C:\Windows\MSI Package Builder 4 Starter.xml:MSI_Package_Builder
@Alternate Data Stream - 176 bytes -> C:\Windows\MSI Package Builder 4 Enterprise.xml:MSI_Package_Builder
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:8CE646EE
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:CF54F1CA
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:63238B95
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CD060F93
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:9F652F80
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:D74B6CF5
< End of report >
OTL Extras logfile created on: 3/05/2010 9:28:29 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = E:\
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 51.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 104.33 Gb Total Space | 66.59 Gb Free Space | 63.82% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 7.88 Gb Total Space | 7.87 Gb Free Space | 99.91% Space Free | Partition Type: FAT32
Drive F: | 232.88 Gb Total Space | 97.68 Gb Free Space | 41.94% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: EDUCATION
Current User Name: Students
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- E:\Julian's Programs\VLC\vlc.exe --started-from-file --playlist-enqueue "%1" File not found
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] -- C:\PROGRA~1\MICROS~2\Office12\ONENOTE.EXE "%L" [2009/11/08 09:17:22 | 000,000,000 | ---D | M]
Directory [PlayWithVLC] -- E:\Julian's Programs\VLC\vlc.exe --started-from-file --no-playlist-enqueue "%1" File not found
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{050E7113-8DEB-4096-864B-1D32F15EB4F9}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{31A26B5E-F671-458B-855A-5179F6CFD8C9}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{38362074-9C61-4DF3-B142-A05E35B4CBA8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{3BB8B156-C7AB-489D-896C-BE39E05055F3}" = lport=2869 | protocol=6 | dir=in | app=system |
"{5F942C13-1484-45D2-81FF-6E4A809D9CF5}" = lport=445 | protocol=6 | dir=in | app=system |
"{8853B779-A7D6-4C39-8B2F-E7B6876B00F5}" = rport=139 | protocol=6 | dir=out | app=system |
"{8A1B83A9-4187-4B5A-A98E-A2E14672E402}" = lport=138 | protocol=17 | dir=in | app=system |
"{8ADF04F7-4DE3-40BC-BF81-21A4152AD1BC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{8F15F84D-6E84-448C-839E-F71D5386313D}" = lport=139 | protocol=6 | dir=in | app=system |
"{9056D662-853C-44B0-B36E-AC816E6E0722}" = rport=137 | protocol=17 | dir=out | app=system |
"{A0041DBB-8A63-484E-973D-A878EF183A9B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{A86F9EFD-815A-4AB3-9E61-64FD2572116F}" = lport=137 | protocol=17 | dir=in | app=system |
"{AA61EFC8-43E3-401E-A844-02B97905857A}" = rport=138 | protocol=17 | dir=out | app=system |
"{BCE6E6A6-2052-4908-9939-8727754DE335}" = rport=445 | protocol=6 | dir=out | app=system |
"{C1418368-3F74-4FD7-9F51-A868B8449A97}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C2453F8B-B5A8-45B4-9E55-82C14C8EAF9D}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{D0176F7F-E813-4D21-8C0A-0695FF6EAADC}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{D8C9443F-698B-4C68-8DB0-14F6639E840F}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DF1B85F8-27FA-4A55-9C72-C5CC41F44B4C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EBC2072F-9403-439F-9336-025FE5EC2223}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{1976E623-AAE8-4CBA-B0A9-5E88AC324942}" = protocol=58 | dir=out | [email protected],-28546 |
"{37F299B2-CA30-4541-B858-A9A0B5E77405}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{3F6F9672-76B3-4D90-A4FB-612CBB188CB4}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{4A4FB270-9D3A-4355-B82E-79D8AD94F4EF}" = dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{4E4D39EF-1BE9-4AFD-AAC9-8B93EAE0D49D}" = protocol=6 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{50E3C990-937E-4B40-BAED-7E2C6B2982B4}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{5D145D3F-7D5B-49E1-8567-A70BA039DF36}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{5D2ACC7A-350B-4D21-9A6B-21829B33C4AA}" = protocol=1 | dir=in | [email protected],-28543 |
"{731004EE-3535-4E6D-A472-1AB4D8826291}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{851A00A5-E293-466C-ADE9-20C074FB8B6B}" = protocol=1 | dir=out | [email protected],-28544 |
"{91FCFF50-D437-4FE9-82BA-7464AFDB2FB2}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{9C6996EE-35CB-4A1E-9EF4-B1FCA7548578}" = dir=in | app=f:\julian's programs\power director 8\powerdirector\pdr.exe |
"{B3F41427-2764-4EB9-8449-97232A1B4B70}" = protocol=58 | dir=in | [email protected],-28545 |
"{BFA06CC2-E7F9-433D-82B9-518085D2416B}" = protocol=6 | dir=in | app=f:\julian's programs\downloads\utorrent.exe |
"{EF5F02A6-EEFD-4075-9446-3090A6D7E960}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{F52ADCF4-AE55-4AAC-BC6D-20A301679CD3}" = protocol=17 | dir=in | app=c:\program files\pando networks\media booster\pmb.exe |
"{FBB0BC4D-E6FD-48CA-B122-17E7B18ADEAE}" = protocol=17 | dir=in | app=f:\julian's programs\downloads\utorrent.exe |
"TCP Query User{1E921448-BFAA-4E7F-9BE6-1DF85A1BA510}F:\julian's programs\windows live messenger 8.5.exe" = protocol=6 | dir=in | app=f:\julian's programs\windows live messenger 8.5.exe |
"TCP Query User{27D899B2-11CB-4BFB-92A4-91E4D50EA5E9}C:\users\students\desktop\windows live messenger 8.5.exe" = protocol=6 | dir=in | app=c:\users\students\desktop\windows live messenger 8.5.exe |
"TCP Query User{28A23543-50F7-4CDE-96C5-CB77BB810397}F:\julian's programs\downloads\windows live messenger 14.0.exe" = protocol=6 | dir=in | app=f:\julian's programs\downloads\windows live messenger 14.0.exe |
"TCP Query User{886658E1-279B-4264-B512-15866DE9E636}F:\halo\halo.exe" = protocol=6 | dir=in | app=f:\halo\halo.exe |
"TCP Query User{889670F4-7B08-4547-BBD8-83F9BA3F1039}F:\julian's programs\downloads\windows live messenger 8.5.exe" = protocol=6 | dir=in | app=f:\julian's programs\downloads\windows live messenger 8.5.exe |
"TCP Query User{C7A4A967-26C2-4CE8-BCCA-8AA31CB55D32}E:\julian's programs\call of duty 4 - modern warfare\iw3mp.exe" = protocol=6 | dir=in | app=e:\julian's programs\call of duty 4 - modern warfare\iw3mp.exe |
"TCP Query User{CB977DB4-7FCF-4D31-8C9A-F7192C82A195}E:\julian's programs\age of empires iii\empire earth.exe" = protocol=6 | dir=in | app=e:\julian's programs\age of empires iii\empire earth.exe |
"TCP Query User{E487C19A-6CCC-4665-AF3F-3F8F06B47D6E}C:\program files\halo\halo.exe" = protocol=6 | dir=in | app=c:\program files\halo\halo.exe |
"UDP Query User{31021DF4-C14C-4124-9DE3-2D92BAEF9232}C:\users\students\desktop\windows live messenger 8.5.exe" = protocol=17 | dir=in | app=c:\users\students\desktop\windows live messenger 8.5.exe |
"UDP Query User{37F43579-89EB-434F-99C0-39BD0F4BA32F}E:\julian's programs\call of duty 4 - modern warfare\iw3mp.exe" = protocol=17 | dir=in | app=e:\julian's programs\call of duty 4 - modern warfare\iw3mp.exe |
"UDP Query User{61C6AD72-15E3-4D90-A4E3-35E0496BE520}F:\julian's programs\downloads\windows live messenger 8.5.exe" = protocol=17 | dir=in | app=f:\julian's programs\downloads\windows live messenger 8.5.exe |
"UDP Query User{7D2AFFAE-7EF4-4781-8DE2-48CE48387BB5}C:\program files\halo\halo.exe" = protocol=17 | dir=in | app=c:\program files\halo\halo.exe |
"UDP Query User{80D6152B-38A7-4C2E-8BBA-488A4836FCDB}E:\julian's programs\age of empires iii\empire earth.exe" = protocol=17 | dir=in | app=e:\julian's programs\age of empires iii\empire earth.exe |
"UDP Query User{F9896B66-804B-48D9-AFDC-4DFE9CA2314E}F:\julian's programs\downloads\windows live messenger 14.0.exe" = protocol=17 | dir=in | app=f:\julian's programs\downloads\windows live messenger 14.0.exe |
"UDP Query User{FF3FCDA9-4014-476F-BEA6-FA5051E6022C}F:\halo\halo.exe" = protocol=17 | dir=in | app=f:\halo\halo.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{0451FD8E-D80E-4BA6-AE02-EBE80A059CB0}" = Sibelius Scorch (ActiveX Only)
"{0D2E9DCB-9938-475E-B4DD-8851738852FF}" = AIO_Scan
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216012FF}" = Java 6 Update 13
"{2883F6F5-0509-43F3-868C-D50330DD9DD3}" = TOSHIBA Hardware Setup
"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (MSSMLBIZ)
"{32343DB6-9A52-40C9-87E4-5E7C79791C87}" = MSXML 4.0 SP2 and SOAP Toolkit 3.0
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java 6 Update 3
"{34A0FF07-F11A-4157-84A3-92F8AD688CBF}" = Vodafone Mobile Connect via the phone
"{37C866E4-AA67-4725-9E95-A39968DD7960}" = Camera Assistant Software for Toshiba
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4B1E87C3-00DE-4898-8E39-E390AAEF2391}" = TOSHIBA Supervisor Password
"{50120000-1105-0000-0000-0000000FF1CE}" = Microsoft Office 2007 Primary Interop Assemblies
"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)
"{56B4002F-671C-49F4-984C-C760FE3806B5}" = Microsoft SQL Server VSS Writer
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E6D6161-5509-4f55-9372-1E01792F843A}" = F300_Help
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76EF916E-0636-42E4-AA1F-694AF549EC59}" = Brother HL-2040
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{78C6A78A-8B03-48C8-A47C-78BA1FCA2307}" = TOSHIBA ConfigFree
"{7A7DC702-DEDE-42A8-8722-B3BA724D546F}" = Fax
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169, 8168, 8101E and 8102E Ethernet Network Card Driver for Windows Vista
"{8A5F34E2-37CF-4AD4-808C-2D413786E31A}" = Microsoft Visual C Runtime
"{8C6027FD-53DC-446D-BB75-CACD7028A134}" = HP Update
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A40409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office 2003 Web Components
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9588104D-4507-481E-8F4B-9F7C113915BE}" = Fiesta
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{978C25EE-5777-46e4-8988-732C297CBDBD}" = Status
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1FD9CE-0776-4f0b-A6F5-C6AB7B650CDF}" = Destinations
"{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}" = CD/DVD Drive Acoustic Silencer
"{A040AC77-C1AA-4CC9-8931-9F648AF178F6}" = VC 9.0 Runtime
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A3B7C670-4A1E-4EE2-950E-C875BC1965D0}" = Copy
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A939D341-5A04-4E0A-BB55-3E65B386432D}" = Microsoft Office Small Business Connectivity Components
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Atheros Wi-Fi Protected Setup Library
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B32C4059-6E7A-41EF-AD20-56DF1872B923}" = Business Contact Manager for Outlook 2007 SP2
"{B5FDA445-CAC4-4BA6-A8FB-A7212BD439DE}" = Microsoft XML Parser
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Disc Creator
"{BD68F46D-8A82-4664-8E68-F87C55BDEFD4}" = Microsoft SQL Server Native Client
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C23B8C30-E05E-4CB5-8188-F27CC3B2DD3E}" = Sibelius 5
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{C78EAC6F-7A73-452E-8134-DBB2165C5A68}" = QuickTime
"{C916D86C-AB76-49c7-B0E4-A946E0FD9BC2}" = HP Photosmart, Officejet, PSC and Deskjet All-In-One Driver Software 8.0.B
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09575B2-498D-4C8B-A9D2-623F78574F29}" = AIO_CDB_Software
"{E127B28D-1A2A-45C4-A74E-C817E0A74E3E}" = Fiesta
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E7112940-5F8E-4918-B9FE-251F2F8DC81F}" = AIO_CDB_ProductContext
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1568757-E564-4cb5-8980-9333119A4384}" = F300
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F214EAA4-A069-4BAF-9DA4-4DB8BEEDE485}" = DVD MovieFactory for TOSHIBA
"{F6AC5364-2FB7-437a-811A-D645F22AA6AC}" = F300Trb
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FF075778-6E50-47ed-991D-3B07FD4E3250}" = TrayApp
"7-Zip" = 7-Zip 4.65
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop CS4_is1" = Adobe Photoshop CS4
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"Any Video Converter Professional_is1" = Any Video Converter Professional 2.7.9
"AVS Update Manager_is1" = AVS Update Manager 1.0
"AVS4YOU Software Navigator_is1" = AVS4YOU Software Navigator 1.3
"AVS4YOU Video Converter 6_is1" = AVS Video Converter 6
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"Business Contact Manager" = Business Contact Manager for Outlook 2007 SP2
"DVD Decrypter" = DVD Decrypter (Remove Only)
"Early Maths" = Early Maths
"Glary Registry Repair_is1" = Glary Registry Repair 2.8
"HDMI" = Intel® Graphics Media Accelerator Driver
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft DirectX SDK (February 2010)" = Microsoft DirectX SDK (February 2010)
"Microsoft SQL Server 2005" = Microsoft SQL Server 2005
"Mozilla Firefox (3.5.9)" = Mozilla Firefox (3.5.9)
"PandoraRecovery" = PandoraRecovery (Remove Only)
"PC Tools Internet Security" = PC Tools Internet Security 2009
"Phonics" = Phonics
"Revo Uninstaller" = Revo Uninstaller 1.85
"Smart Defrag_is1" = Smart Defrag 1.20
"SpeedBit Video Downloader" = SpeedBit Video Downloader
"Sure Delete_is1" = Sure Delete 5.1.1
"Switch" = Switch Sound File Converter
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"VLC media player" = VLC media player 0.9.4
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Power Loader" = Power Challenge Game Plugin
========== Last 10 Event Log Errors ==========
Error: Unable to start EventLog service!
< End of report >
Edited by Justinn123, 03 May 2010 - 05:44 AM.