My computer started acting strange the other day. It was continually filling the recycle bin with versions of a .pdf file I had created the day before. It would create almost one of these files per second. The recycle bin would fill up with these files and the system would slow down - both from the cpu being slammed with making all these files, and from the recycle bin's size leaving me w/o much ram. I deleted the file in my directory - the one that seemed to be replicated over and over in the recycle bin, and the problem went away.
But today so far I've gotten two blue-screens, once when I was doing nothing and the other time when I was saving a file to disk.
Here is my OTL log:
----------------------------------------
OTL logfile created on: 9/15/2011 2:19:52 PM - Run 5
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\Gabriel\Desktop
An unknown product Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.46 Gb Total Physical Memory | 0.48 Gb Available Physical Memory | 19.48% Memory free
4.92 Gb Paging File | 2.97 Gb Available in Paging File | 60.26% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 287.15 Gb Total Space | 49.75 Gb Free Space | 17.32% Space Free | Partition Type: NTFS
Drive Q: | 9.77 Gb Total Space | 3.04 Gb Free Space | 31.14% Space Free | Partition Type: NTFS
Computer Name: GABRIEL-W500 | User Name: Gabriel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Gabriel\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
PRC - C:\Program Files\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CrashPlan\CrashPlanService.exe (CrashPlan)
PRC - C:\Program Files\CrashPlan\CrashPlanTray.exe (Code 42 Software, Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
PRC - C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated)
PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtblfs.exe (Kaspersky Lab)
PRC - C:\Program Files\Lenovo\ZOOM\TpScrex.exe (Lenovo Group Limited)
PRC - c:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
PRC - C:\Windows\System32\DTS.exe ()
PRC - C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
PRC - C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Windows\UnsignedThemesSvc.exe (The Within Network, LLC)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
PRC - C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
PRC - C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe ()
PRC - C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
PRC - C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe (Lenovo Group Limited)
PRC - C:\Program Files\RotateImage\RCIMGDIR.exe (Ricoh co.,Ltd.)
PRC - C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
PRC - C:\Windows\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files\Mozilla Firefox\js3250.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\86a2ec5efbcfcd1105475364d7975b15\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0d43c5e77ee7b8466700b16d7e7d4bb7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\9e87dd8fe5d0f925d80a6a6eaf74fdb9\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\3da7c6c1a0f26ae91883fd8b03ec192d\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\16b68fcaff063835ae0ee348a1201f2a\mscorlib.ni.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Program Files\IZArc\IZArcCM.dll ()
MOD - C:\Program Files\ThinkPad\Utilities\US\PWMRT32V.DLL ()
MOD - C:\Program Files\ThinkPad\Bluetooth Software\BTKeyInd.dll ()
MOD - C:\Program Files\Lenovo\Message Center Plus\MCPLaunch.exe ()
========== Win32 Services (SafeList) ==========
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Hamachi2Svc) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (MediaMall Server) -- C:\Program Files\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
SRV - (CrashPlanService) -- C:\Program Files\CrashPlan\CrashPlanService.exe (CrashPlan)
SRV - (AVP) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Autodesk Licensing Service) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (SUService) -- c:\Program Files\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (EvtEng) Intel® -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV - (RegSrvc) Intel® -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV - (LMS) Intel® -- C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
SRV - (dtsvc) -- C:\Windows\System32\DTS.exe ()
SRV - (ADMonitor) -- C:\Windows\System32\ADMonitor.exe ()
SRV - (ATService) -- C:\Windows\System32\AtService.exe (AuthenTec, Inc.)
SRV - (ThinkVantage Registry Monitor Service) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe (Lenovo Group Limited)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (Power Manager DBC Service) -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE (Lenovo)
SRV - (IAANTMON) Intel® -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (RoxMediaDB10) -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (UNS) Intel® -- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
SRV - (TPHKSVC) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV - (StorSvc) -- C:\Windows\System32\StorSvc.dll (Microsoft Corporation)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) -- C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (UnsignedThemes) -- C:\Windows\UnsignedThemesSvc.exe (The Within Network, LLC)
SRV - (LENOVO.MICMUTE) -- C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV - (btwdins) -- C:\Program Files\ThinkPad\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (HsfXAudioService) -- C:\Windows\System32\XAudio32.dll (Conexant Systems, Inc.)
SRV - (mi-raysat_3dsmax2010_32) -- C:\Program Files\Autodesk\3ds Max Design 2010\mentalray\satellite\raysat_3dsmax2010_32server.exe ()
SRV - (Autodesk Network Licensing Service) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe (Autodesk, Inc.)
SRV - (BcmSqlStartupSvc) -- C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Microsoft Corporation)
SRV - (IviRegMgr) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (PCDSRVC{3037D694-FD904ACA-06020101}_0) -- c:\Program Files\PC-Doctor\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (vmbus) -- C:\Windows\system32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) -- C:\Windows\system32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) -- C:\Windows\system32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (VMBusHID) -- C:\Windows\system32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (s3cap) -- C:\Windows\system32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (Lbd) -- C:\Windows\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (btusbflt) -- C:\Windows\System32\drivers\btusbflt.sys (Broadcom Corporation.)
DRV - (e1yexpress) Intel® -- C:\Windows\System32\drivers\e1y6232.sys (Intel Corporation)
DRV - (KLIF) -- C:\Windows\System32\drivers\klif.sys (Kaspersky Lab)
DRV - (psadd) -- C:\Windows\System32\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV - (klbg) -- C:\Windows\system32\drivers\klbg.sys (Kaspersky Lab)
DRV - (msvad_simple) -- C:\Windows\System32\drivers\povrtdev.sys (MediaMall Technologies, Inc.)
DRV - (klmouflt) -- C:\Windows\System32\drivers\klmouflt.sys (Kaspersky Lab)
DRV - (hamachi) -- C:\Windows\System32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (intelkmd) -- C:\Windows\System32\drivers\igdpmd32.sys (Intel Corporation)
DRV - (NETw5s32) Intel® -- C:\Windows\System32\drivers\NETw5s32.sys (Intel Corporation)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (KLIM6) -- C:\Windows\System32\drivers\klim6.sys (Kaspersky Lab)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (kl1) -- C:\Windows\System32\drivers\kl1.sys (Kaspersky Lab)
DRV - (ATSwpWDF) -- C:\Windows\System32\drivers\ATSwpWDF.sys (AuthenTec, Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (TPPWRIF) -- C:\Windows\System32\drivers\TPPWR32V.SYS (Lenovo Group Limited)
DRV - (CnxtHdAudService) -- C:\Windows\System32\drivers\CHDRT32.sys (Conexant Systems Inc.)
DRV - (vwifimp) -- C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (TPM) -- C:\Windows\System32\drivers\tpm.sys (Microsoft Corporation)
DRV - (netw5v32) Intel® -- C:\Windows\System32\drivers\netw5v32.sys (Intel Corporation)
DRV - (uxpatch) -- C:\Windows\System32\drivers\uxpatch.sys ()
DRV - (5U875UVC) -- C:\Windows\System32\drivers\5U875.sys (Ricoh co.,Ltd.)
DRV - (TVTI2C) -- C:\Windows\System32\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV - (iaNvStor) Intel® -- C:\Windows\system32\DRIVERS\iaNvStor.sys (Intel Corporation)
DRV - (pavboot) -- C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (Shockprf) -- C:\Windows\System32\DRIVERS\Apsx86.sys (Lenovo.)
DRV - (TPDIGIMN) -- C:\Windows\System32\DRIVERS\ApsHM86.sys (Lenovo.)
DRV - (HECI) Intel® -- C:\Windows\System32\drivers\HECI.sys (Intel Corporation)
DRV - (XAudio) -- C:\Windows\System32\drivers\XAudio32.sys (Conexant Systems, Inc.)
DRV - (VCSVADHWSer) Avnex Virtual Audio Device (WDM) -- C:\Windows\System32\drivers\vcsvad.sys (Avnex)
DRV - (lenovo.smi) -- C:\Windows\System32\drivers\smiif32.sys (Lenovo Group Limited)
DRV - (PAC7302) -- C:\Windows\System32\drivers\PAC7302.SYS (PixArt Imaging Inc.)
DRV - (regi) -- C:\Windows\System32\drivers\regi.sys (InterVideo)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://m.www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:9.0.0.736
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {e001c731-5e37-4538-a5cb-8168736a2360}:0.9.9.30
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.775: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.775: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=1.0.0.0: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.775: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/08 12:04:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.22\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/08 12:04:39 | 000,000,000 | ---D | M]
[2010/02/04 16:39:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gabriel\AppData\Roaming\Mozilla\Extensions
[2011/09/14 19:29:16 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Gabriel\AppData\Roaming\Mozilla\Firefox\Profiles\61ra9znk.default\extensions
[2010/08/20 14:04:34 | 000,000,000 | ---D | M] ("BitDefender QuickScan") -- C:\Users\Gabriel\AppData\Roaming\Mozilla\Firefox\Profiles\61ra9znk.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011/06/22 09:40:30 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/06/09 10:42:00 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2010/04/18 12:07:34 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/02 14:51:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/02 11:14:58 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/01/13 09:29:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/17 22:01:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/22 09:40:30 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2010/02/06 10:47:55 | 000,000,000 | ---D | M] (Kaspersky URL Advisor) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/13 15:46:00 | 000,063,488 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
O1 HOSTS File: ([2010/08/28 09:07:22 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\ievkbd.dll (Kaspersky Lab)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O3: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\avp.exe (Kaspersky Lab)
O4 - HKLM..\Run: [FingerPrintSoftware] C:\Program Files\Lenovo Fingerprint Software\fpapp.exe (AuthenTec)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe (Intel Corporation)
O4 - HKLM..\Run: [LENOVO.TPFNF6R] C:\Program Files\Lenovo\HOTKEY\tpfnf6r.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Message Center Plus] C:\Program Files\LENOVO\Message Center Plus\MCPLaunch.exe ()
O4 - HKLM..\Run: [PAC7302_Monitor] C:\Windows\PixArt\Pac7302\Monitor.exe (PixArt Imaging Incorporation)
O4 - HKLM..\Run: [picon] C:\Program Files\Common Files\Intel\Privacy Icon\PrivacyIconClient.exe (Intel Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [Orb] C:\Program Files\Winamp Remote\bin\OrbTray.exe (Orb Networks)
O4 - HKCU..\Run: [PlayOn] C:\Program Files\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
O4 - HKCU..\Run: [Steam] c:\program files\steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [Windows Live Sync] "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe" /background File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O9 - Extra Button: @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\ThinkPad\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\klwtbbho.dll (Kaspersky Lab)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} http://navigatela.la...ad/mgaxctrl.cab (Autodesk MapGuide ActiveX Control)
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} http://www-307.ibm.c...rt/IbmEgath.cab (IBM Access Support)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72C32C4B-597A-4FC1-8E49-96AA5E393656}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{739DBB35-D90A-4942-9415-A42119EFECEC}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) -C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2010\mzvkbd3.dll (Kaspersky Lab)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/15 14:18:39 | 000,581,632 | ---- | C] (OldTimer Tools) -- C:\Users\Gabriel\Desktop\OTL.exe
[2011/09/15 08:32:42 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{AD12E913-5EAE-4DB4-AE68-0E2152CD7A47}
[2011/09/15 08:32:20 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{556A9F47-F112-430F-8F16-CF26B9F313FC}
[2011/09/14 20:31:51 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{0B967661-87D8-499F-8DEC-5567E4C104E1}
[2011/09/14 20:31:29 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{FC3B6228-F453-488D-BD81-05211A33FCB4}
[2011/09/14 08:30:47 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{82253016-143E-45D7-B261-9954210E32D1}
[2011/09/14 08:30:25 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{0DEA37AA-613A-4626-8B7F-326BEB193681}
[2011/09/13 16:38:28 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{BC316BD0-99C7-4682-A322-03A440D41DB0}
[2011/09/13 16:37:55 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{4AEA0655-3310-4C51-8415-0EC4FDD8B5C1}
[2011/09/13 00:12:27 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{B35AFC48-3DA5-4B0F-A19C-B6429BC92CCA}
[2011/09/13 00:12:05 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{034E6575-341A-4E84-809B-81D4B6662484}
[2011/09/12 12:11:37 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{FD60C494-3373-42DA-A8EF-7EF274469992}
[2011/09/12 12:11:14 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F0BE7467-DE4C-47B9-B730-1BFA041946C1}
[2011/09/12 00:10:45 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{2AF9F219-AD2E-4615-A443-87A0591CD360}
[2011/09/11 12:10:07 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{5AEB428A-9606-4F43-82AC-42445F49386F}
[2011/09/11 00:08:43 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{461B91E4-2C6C-438D-B889-1BB2C3225B58}
[2011/09/11 00:08:21 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{960AA049-9C81-4DBF-B00C-EF426494F0D1}
[2011/09/10 12:07:52 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{30EADEF7-8C01-4DF5-911A-11BEBF94AAF5}
[2011/09/10 12:07:30 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{1F78526D-7246-4822-BE45-1E6550F9D448}
[2011/09/10 00:07:02 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{7FF9F591-713D-4C50-80C5-ADB7926D37A1}
[2011/09/09 12:06:23 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3F047A88-90BD-47BB-A215-D88E9CE0E4CC}
[2011/09/09 12:06:00 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F70B818E-51E7-4D8C-9B5C-8ACF1FFA9606}
[2011/09/09 00:05:31 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{361ADB9B-CF31-4466-AF7D-F7928747AC75}
[2011/09/08 12:03:42 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{B72BC340-EE7E-4728-92EA-AE0DE58F888A}
[2011/09/08 12:03:22 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3F99DE22-BBFE-4E66-96C5-C85882DBEB0A}
[2011/09/07 23:55:28 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{04EC72D2-C203-429D-A85E-117A919DD1D3}
[2011/09/07 11:54:49 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{35365413-30EB-4B81-887A-E1AC2CEB6F4D}
[2011/09/07 11:54:27 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{D7A95126-A248-480A-B4F6-B6A2F89F6A2A}
[2011/09/06 23:53:58 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{A5D71AFD-192A-494E-85B1-4A88B45B44AD}
[2011/09/06 23:53:35 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3E26A962-0228-49D5-8C85-A972E2E9B3D0}
[2011/09/06 11:53:06 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{73CD4A81-8323-4D47-BAA7-5B0FC600713F}
[2011/09/06 11:52:43 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{91D23E2A-4275-40E9-B7C7-FEF410BFFC16}
[2011/09/05 23:52:04 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{70EC5E09-8A4A-4C69-81BD-86C571D5E49E}
[2011/09/05 23:51:38 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F5208900-B115-4505-BFBF-3594BFBC05CE}
[2011/09/05 11:50:47 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{FC4946F4-2CCF-4A35-B3A9-38AFF481EE9C}
[2011/09/05 11:50:23 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{D288FF03-DE40-46C7-9FDC-53E586D877A3}
[2011/09/04 23:49:54 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{E89E54BB-2B5E-4D8E-B3FA-ACD8644E7D3C}
[2011/09/04 11:48:57 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{D24469A7-870C-49A2-B580-642C4D901A8C}
[2011/09/04 11:48:31 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{4F0F4CD5-CD36-495F-A7F0-865C91297D9B}
[2011/09/03 22:54:23 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{1855F0F5-1F96-4561-81C1-FCF4AFAB6835}
[2011/09/03 10:53:46 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3D279FA7-D71A-480A-9B45-FF5784A0C575}
[2011/09/03 10:53:24 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{EF0A3744-CDA4-4667-9B1C-45BEC1177EB0}
[2011/09/02 18:36:53 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3B180E4A-4D2F-4653-91B9-07D745E5DC1B}
[2011/09/02 18:36:30 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{4F97D301-5F9E-42FB-B04A-490CC3EC7740}
[2011/09/02 06:35:10 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{0B18CDF5-7131-4C01-84DE-D5D6FD693B41}
[2011/09/02 06:34:48 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{548900A1-CDBA-4F1B-B00D-0CB4E8F3D074}
[2011/09/01 18:34:09 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{CDF6F05E-844F-4B3D-8A9A-580D369341AB}
[2011/09/01 18:33:57 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{1C1F8EEF-91B5-4F87-85C0-64A983055713}
[2011/09/01 17:08:24 | 000,000,000 | ---D | C] -- C:\Windows\en
[2011/09/01 16:52:53 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{D2ACDF30-6F38-47F7-A405-4E98E03693AE}
[2011/09/01 16:52:35 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{E40E6746-90FD-4790-B0BE-1A243393218B}
[2011/08/31 20:54:04 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{78DEE4F5-8923-4113-AF8F-BFC4A8640621}
[2011/08/31 20:53:36 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{B682973C-31F0-4079-A8E3-2E31C305AB73}
[2011/08/31 20:44:40 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{536A6663-41B3-4EA1-B267-2C5E87867280}
[2011/08/31 20:44:18 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{8E6C1069-4747-47A2-8BC5-BA3CFDE44343}
[2011/08/31 11:57:07 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{5AB1AAFF-84A4-40DF-86C8-25721381242A}
[2011/08/31 11:56:14 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{3755D724-0DC6-4ABB-ABF0-4C39F3320D00}
[2011/08/31 08:57:02 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{79B02E6E-E9F4-4A01-ADAB-F0953763883D}
[2011/08/31 08:56:43 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{4EE68900-CF08-47DF-B77B-0A041517B43F}
[2011/08/30 09:58:30 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{92DA4C6A-1615-4806-8DC9-EB26C71ED664}
[2011/08/30 09:57:50 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{87A0EFD0-9CD6-476E-B79B-300AD0E8AD06}
[2011/08/29 09:18:47 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{8A14606C-F76A-4D66-A8CA-84CC89878191}
[2011/08/29 09:18:14 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{495BF466-230B-4FC0-BE11-EF3A1D990034}
[2011/08/28 23:07:01 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{C713275A-5383-45A5-8C16-74002A3D7279}
[2011/08/28 23:06:43 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F9143A10-C1E8-40AF-93CE-074C2F9740F5}
[2011/08/28 11:30:34 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{DCF3FC9C-A0C8-4AFD-93A5-216728A45797}
[2011/08/28 11:30:22 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{41CEBE1E-37F8-4B7C-AE41-31C446C09282}
[2011/08/27 09:16:21 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{B2AC89D1-E2B9-41FF-96FE-9B60D6FE55A8}
[2011/08/27 09:15:52 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{10BF00EA-C51A-4EFC-AE45-BE01E5B3F4B6}
[2011/08/26 11:40:18 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F9CE5760-BEED-44A7-A8DF-D07A7876DD78}
[2011/08/26 11:39:48 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{5B4007E6-74B1-4604-BE14-7FEEAB05D3CC}
[2011/08/25 11:20:41 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{C7307764-5CE4-484F-A256-385F35A06005}
[2011/08/25 11:20:12 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{C11364BC-EADC-46C2-A220-F626FAAC6D6E}
[2011/08/24 21:38:44 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{9D0991B5-3E4B-4B87-92DC-3766E9EB7472}
[2011/08/24 21:38:28 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{2E154C52-DBB5-4386-AA47-A79B49E87DD9}
[2011/08/24 12:42:18 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{66B87676-6487-4C54-8311-6D6150C850AF}
[2011/08/24 12:41:52 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{BF58BE51-D6BB-4B73-9811-32678F162A46}
[2011/08/24 09:00:49 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{31B19665-3109-4527-B2C2-86BCCB77FD13}
[2011/08/24 09:00:31 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{CE38C063-49FA-43C3-AB0D-F77E78ECB9B9}
[2011/08/23 08:51:20 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{0E73A0DE-3DFF-4010-B912-FF9D419125E8}
[2011/08/23 08:50:56 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{9562F813-4293-410E-907C-A45748E4690F}
[2011/08/22 18:06:23 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{CB7E7240-FC55-4DCB-85A7-A0A906E81496}
[2011/08/22 18:05:55 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{8D175CDA-73A1-4C47-8C57-9CF16C3519B9}
[2011/08/21 19:32:42 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{1705FE1A-8E9E-49A4-818A-38746653EF2C}
[2011/08/21 19:32:23 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{E695FEA1-C24E-4D6F-9DA6-78FBDA30B194}
[2011/08/20 03:04:48 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{80AB11C4-E9A7-4ADD-A1A0-9F5671AF4AE9}
[2011/08/20 03:04:20 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{F126E260-6611-49F6-A3ED-CC5013BAFFDA}
[2011/08/19 12:08:40 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{D814FEA6-91E9-4C81-BC2A-A065DEDF1955}
[2011/08/19 12:08:12 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{7A2C1592-5227-421C-959E-7F9EFF202965}
[2011/08/19 08:48:02 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{EAEADFDE-32DC-4D55-A0C6-2300371957B4}
[2011/08/19 08:47:47 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{BE2FDC3D-A8DB-42B1-BC55-CDC6CD87F16D}
[2011/08/18 09:30:04 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{0554D38F-3DAA-4CBC-95CF-3A6008AB9067}
[2011/08/18 09:29:42 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{CD123272-A4AF-4865-B13B-9E468B690148}
[2011/08/18 08:37:37 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{A50864C1-A9BB-40DC-AD0C-BD63E033E25E}
[2011/08/18 08:37:06 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{17A0787D-7330-418C-837A-47879C5B13EA}
[2011/08/17 21:03:19 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{C6BEC685-67B3-4D3D-AB68-AA055BD79C6D}
[2011/08/17 21:03:03 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{1373D496-BD7B-4E70-A171-4E2836A4FB6E}
[2011/08/17 12:56:28 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{645C3B2E-E0DE-4C72-A23D-3CB52A2B8752}
[2011/08/17 12:55:48 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{25D34919-C3BD-4EB6-B4F5-8DC34676E1CB}
[2011/08/17 09:27:26 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{52DE8134-BB83-4402-B006-259E714D8D74}
[2011/08/17 09:26:57 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{9B0494E3-67B7-4B2A-9069-7977E920AAB4}
[2011/08/16 19:10:52 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{809D4697-3C0F-4250-9012-1F54EEA25E29}
[2011/08/16 19:10:27 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\{9AEA8609-3A1D-4AC9-A176-5CB0DAC2C62B}
[2011/08/16 15:58:59 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Roaming\ATI
[2011/08/16 15:58:59 | 000,000,000 | ---D | C] -- C:\Users\Gabriel\AppData\Local\ATI
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/15 14:18:41 | 000,581,632 | ---- | M] (OldTimer Tools) -- C:\Users\Gabriel\Desktop\OTL.exe
[2011/09/15 14:17:07 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/09/15 14:02:07 | 000,016,976 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/15 14:02:07 | 000,016,976 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/15 14:00:59 | 000,674,024 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/09/15 14:00:59 | 000,125,122 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/09/15 13:53:39 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/15 13:53:36 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/15 13:53:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/15 13:53:12 | 1981,816,832 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/15 13:34:16 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/15 13:03:08 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\Windows\System32\drivers\SBREDrv.sys
[2011/09/15 12:30:12 | 367,691,540 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/09/12 10:35:14 | 000,115,369 | ---- | M] () -- C:\Windows\System32\drivers\klin.dat
[2011/09/12 10:35:14 | 000,097,961 | ---- | M] () -- C:\Windows\System32\drivers\klick.dat
[2011/09/03 11:30:27 | 000,002,297 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/15 13:53:39 | 000,000,384 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/09/15 12:30:12 | 367,691,540 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/06/03 18:04:16 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/03/30 12:25:55 | 000,000,133 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/02/22 21:47:12 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2010/09/24 16:13:17 | 000,000,362 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/08/30 21:58:43 | 000,015,880 | ---- | C] () -- C:\Windows\System32\lsdelete.exe
[2010/08/27 15:52:26 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2010/08/27 15:52:26 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/08/27 15:52:26 | 000,077,312 | ---- | C] () -- C:\Windows\MBR.exe
[2010/08/27 15:52:26 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/08/27 15:52:25 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/08/20 12:44:43 | 000,007,619 | ---- | C] () -- C:\Users\Gabriel\AppData\Local\Resmon.ResmonCfg
[2010/04/18 13:11:31 | 000,870,128 | ---- | C] () -- C:\Users\Gabriel\AppData\Roaming\mcs.rma
[2010/04/18 13:11:31 | 000,000,004 | ---- | C] () -- C:\Users\Gabriel\AppData\Roaming\1A511F
[2010/03/15 08:12:58 | 000,016,384 | ---- | C] () -- C:\Windows\System32\FileOps.exe
[2010/03/14 09:49:58 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/03/14 09:39:33 | 000,000,883 | ---- | C] () -- C:\Windows\System32\SP7302.INI
[2010/02/01 05:56:50 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2010/01/29 12:13:17 | 000,115,369 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2010/01/29 12:13:17 | 000,097,961 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2010/01/27 19:43:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/01/27 19:43:32 | 000,982,220 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2010/01/27 19:43:31 | 000,439,300 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2010/01/27 19:43:31 | 000,134,592 | ---- | C] () -- C:\Windows\System32\igfcg500.bin
[2010/01/27 19:43:31 | 000,092,216 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin
[2010/01/27 19:43:31 | 000,000,542 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2010/01/27 19:43:30 | 000,197,655 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2009/09/09 20:01:40 | 000,027,675 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2009/09/01 00:32:20 | 000,098,304 | ---- | C] () -- C:\Windows\System32\DTS.exe
[2009/09/01 00:32:16 | 000,106,496 | ---- | C] () -- C:\Windows\System32\ADMonitor.exe
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 16:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/13 21:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:33:53 | 000,528,752 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 19:05:48 | 000,674,024 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 19:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 19:05:48 | 000,125,122 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 19:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 19:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 19:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 16:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 16:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/07/13 02:07:46 | 000,025,448 | ---- | C] () -- C:\Windows\System32\drivers\uxpatch.sys
[2009/06/10 14:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/06/04 16:51:10 | 000,000,542 | ---- | C] () -- C:\Windows\System32\atipblup.dat
[2006/09/28 15:55:34 | 000,053,248 | ---- | C] () -- C:\Windows\System32\PhysXLoader.dll
[2006/09/26 15:01:40 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2006/09/08 10:01:50 | 000,045,056 | R--- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
========== LOP Check ==========
[2011/08/02 01:29:22 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Autodesk
[2010/04/07 15:12:51 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Avnex
[2011/04/22 15:38:04 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\CrashPlan
[2010/05/11 13:31:18 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\EPSON
[2010/06/20 17:26:04 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ooVoo Details
[2010/08/19 16:55:13 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\QuickScan
[2011/05/20 14:14:13 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\Update
[2011/09/09 13:03:14 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\uTorrent
[2010/05/19 19:55:08 | 000,000,000 | ---D | M] -- C:\Users\Gabriel\AppData\Roaming\ZumoDrive
[2011/09/15 13:53:39 | 000,000,384 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2011/03/19 08:48:47 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/07/08 17:54:01 | 000,032,596 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/09/15 14:17:07 | 000,000,382 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
< End of report >
---------------------------------
I hope I constructed this post correctly if not sorry - Any help would be greatly appreciated - thanks in advance! -GR