This is the OTL.txt
OTL logfile created on: 21/10/2011 20:54:32 - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Joey\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.75 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 65.62% Memory free
5.70 Gb Paging File | 4.22 Gb Available in Paging File | 74.07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.88 Gb Total Space | 39.07 Gb Free Space | 17.53% Space Free | Partition Type: NTFS
Drive D: | 9.00 Gb Total Space | 1.22 Gb Free Space | 13.54% Space Free | Partition Type: NTFS
Drive F: | 1021.00 Mb Total Space | 1016.93 Mb Free Space | 99.60% Space Free | Partition Type: FAT32
Computer Name: VERA-PC | User Name: Joey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/10/21 20:53:39 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Joey\Downloads\OTL.exe
PRC - [2011/09/27 21:34:02 | 000,894,304 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe
PRC - [2011/09/27 20:08:40 | 000,745,880 | ---- | M] (Spigot, Inc.) -- C:\Program Files\Application Updater\ApplicationUpdater.exe
PRC - [2011/09/20 12:39:48 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2011/09/08 13:41:20 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2011/08/25 15:02:06 | 000,476,480 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe
PRC - [2011/08/25 14:58:30 | 000,291,064 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe
PRC - [2011/08/15 16:18:14 | 001,955,208 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe
PRC - [2011/08/15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011/08/03 16:55:42 | 000,160,344 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
PRC - [2011/08/03 16:54:52 | 000,033,648 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mfeann.exe
PRC - [2011/08/03 16:54:28 | 000,166,024 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
PRC - [2011/07/19 09:57:00 | 000,148,520 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2011/05/12 11:48:20 | 000,324,928 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2009/08/27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/06/02 18:57:40 | 000,238,984 | ---- | M] (Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\pthosttr.exe
PRC - [2008/06/02 18:32:16 | 000,018,944 | ---- | M] (Hewlett-Packard Development Company, L.P) -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
PRC - [2008/05/30 17:36:20 | 000,256,512 | ---- | M] (SafeBoot International) -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
PRC - [2008/05/21 01:47:18 | 000,065,296 | ---- | M] (Bioscrypt Inc.) -- c:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe
PRC - [2008/05/14 18:55:14 | 000,077,824 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe
PRC - [2008/05/14 18:54:36 | 010,244,096 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe
PRC - [2008/05/13 12:47:28 | 001,624,616 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
PRC - [2008/05/13 12:47:28 | 000,727,592 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
PRC - [2008/05/12 14:28:12 | 000,576,024 | ---- | M] (PDF Complete Inc) -- C:\Program Files\PDF Complete\pdfsvc.exe
PRC - [2008/03/31 22:41:22 | 000,091,440 | ---- | M] ( Hewlett-Packard Development Company, L.P.) -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\VolCtrl.exe
PRC - [2007/12/11 13:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2007/10/19 08:28:24 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEADISRV.EXE
PRC - [2007/10/12 10:33:38 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\TalkTalk\bin\sprtsvc.exe
PRC - [2007/10/12 10:33:16 | 000,202,016 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\TalkTalk\bin\sprtcmd.exe
PRC - [2007/08/02 15:42:14 | 000,148,768 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files\Common Files\SupportSoft\bin\tgsrvc.exe
PRC - [2007/05/16 00:08:40 | 000,182,576 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe
PRC - [2007/05/16 00:08:38 | 000,095,024 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\acevents.exe
PRC - [2007/05/16 00:08:08 | 000,293,168 | ---- | M] (ActivIdentity) -- C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
PRC - [2007/01/05 03:48:52 | 000,112,152 | R--- | M] (InterVideo) -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
========== Modules (No Company Name) ========== MOD - [2011/10/13 17:54:58 | 011,804,672 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\e00630ec1e225a2376fdd430645e20f7\System.Web.ni.dll
MOD - [2011/10/13 17:54:44 | 000,771,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6d2f689baff5da3df134fdec0742a13c\System.Runtime.Remoting.ni.dll
MOD - [2011/10/13 17:53:49 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
MOD - [2011/10/13 17:53:40 | 000,025,600 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll
MOD - [2011/10/13 17:28:53 | 005,450,752 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll
MOD - [2011/10/13 17:27:59 | 012,430,848 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
MOD - [2011/10/13 17:27:46 | 001,587,200 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
MOD - [2011/10/13 17:27:20 | 002,295,296 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\8adb45c62e4c797bd4c706afe9e8bfb9\System.Core.ni.dll
MOD - [2011/10/13 17:27:13 | 000,368,128 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\231b0b42eff55de5c7d7debe555c16b7\PresentationFramework.Aero.ni.dll
MOD - [2011/10/13 17:27:11 | 014,328,832 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94f892556ec9fa7a508fc9d214ceaedf\PresentationFramework.ni.dll
MOD - [2011/10/13 17:26:48 | 012,216,832 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll
MOD - [2011/10/13 17:26:31 | 003,325,952 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll
MOD - [2011/10/13 17:26:26 | 007,950,848 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
MOD - [2011/10/13 17:26:04 | 011,490,816 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/09/30 16:12:40 | 000,412,728 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\ppgooglenaclpluginchrome.dll
MOD - [2011/09/30 16:12:39 | 003,696,184 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
MOD - [2011/09/30 16:11:13 | 000,142,568 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\avutil-51.dll
MOD - [2011/09/30 16:11:12 | 000,253,320 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\avformat-53.dll
MOD - [2011/09/30 16:11:10 | 002,403,240 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\avcodec-53.dll
MOD - [2011/09/29 21:06:57 | 008,587,936 | ---- | M] () -- C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
MOD - [2011/09/08 13:41:26 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2011/08/28 22:19:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2010/11/17 14:16:56 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2008/05/13 12:40:50 | 000,126,976 | ---- | M] () -- C:\Program Files\WIDCOMM\Bluetooth Software\BTKeyInd.dll
MOD - [2007/08/14 21:59:54 | 006,365,184 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtGui4.dll
MOD - [2007/07/12 21:55:52 | 000,131,072 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2007/07/12 21:55:28 | 001,581,056 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtCore4.dll
========== Win32 Services (SafeList) ========== SRV - [2011/09/27 20:08:40 | 000,745,880 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2011/09/08 13:41:20 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2011/08/25 14:58:30 | 000,291,064 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe -- (RumorServer)
SRV - [2011/08/25 14:58:30 | 000,291,064 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe -- (myAgtSvc)
SRV - [2011/08/15 16:18:10 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011/08/03 16:55:42 | 000,160,344 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV - [2011/08/03 16:54:28 | 000,166,024 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe -- (McShield)
SRV - [2011/07/19 09:57:00 | 000,148,520 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/05/12 11:48:20 | 000,324,928 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\McAfee\SiteAdvisor Enterprise\McSACore.exe -- (McAfee SiteAdvisor Enterprise Service)
SRV - [2011/02/28 19:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/08/27 17:09:10 | 001,253,376 | ---- | M] (MAGIX AG) [Unknown | Running] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs)
SRV - [2008/08/07 11:10:02 | 003,276,800 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance)
SRV - [2008/06/02 18:32:16 | 000,018,944 | ---- | M] (Hewlett-Packard Development Company, L.P) [Auto | Running] -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe -- (HP ProtectTools Service)
SRV - [2008/05/30 17:36:20 | 000,256,512 | ---- | M] (SafeBoot International) [Auto | Running] -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe -- (HpFkCryptService)
SRV - [2008/05/21 01:42:40 | 000,111,888 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2008/05/21 01:42:34 | 000,137,488 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll -- (ASChannel)
SRV - [2008/05/14 18:55:14 | 000,077,824 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files\Hewlett-Packard\File Sanitizer\HPFSService.exe -- (HPFSService)
SRV - [2008/05/12 14:28:12 | 000,576,024 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2008/01/21 03:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/11 13:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2007/10/19 08:28:24 | 000,086,016 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)
SRV - [2007/10/12 10:33:38 | 000,202,016 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\TalkTalk\bin\sprtsvc.exe -- (sprtsvc_TalkTalk) SupportSoft Sprocket Service (TalkTalk)
SRV - [2007/08/02 15:42:16 | 000,382,320 | ---- | M] (SupportSoft, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\SupportSoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2007/08/02 15:42:14 | 000,148,768 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe -- (tgsrvc_TalkTalk) SupportSoft Repair Service (TalkTalk)
SRV - [2007/05/16 00:08:40 | 000,182,576 | ---- | M] (ActivIdentity) [Auto | Running] -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe -- (accoca)
SRV - [2007/01/05 03:48:52 | 000,112,152 | R--- | M] (InterVideo) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe -- (IviRegMgr)
========== Driver Services (SafeList) ========== DRV - [2011/07/19 09:57:00 | 000,461,864 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\windows\system32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/07/19 09:57:00 | 000,338,040 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/07/19 09:57:00 | 000,180,008 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (MfeAVFK)
DRV - [2011/07/19 09:57:00 | 000,164,776 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/07/19 09:57:00 | 000,119,808 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/07/19 09:57:00 | 000,087,808 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/07/19 09:57:00 | 000,064,712 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/07/19 09:57:00 | 000,059,288 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfebopk.sys -- (MfeBOPK)
DRV - [2011/07/03 14:23:37 | 000,022,528 | --S- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PsSdk30.drv -- (PsSdk30)
DRV - [2011/06/15 09:23:56 | 000,060,156 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009/12/15 15:29:52 | 000,055,304 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfetdik.sys -- (mfetdik)
DRV - [2009/12/15 15:29:42 | 000,034,248 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdk.sys -- (MfeRKDK)
DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008/05/30 17:37:06 | 000,051,376 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\windows\System32\drivers\SbAlg.sys -- (SbAlg)
DRV - [2008/05/30 17:37:02 | 000,012,928 | ---- | M] (SafeBoot International) [File_System | Boot | Running] -- C:\windows\System32\drivers\SbFsLock.sys -- (SbFsLock)
DRV - [2008/05/30 17:37:00 | 000,012,496 | ---- | M] (SafeBoot International) [Kernel | System | Running] -- C:\windows\System32\drivers\rsvlock.sys -- (RsvLock)
DRV - [2008/05/30 17:36:58 | 000,108,752 | ---- | M] () [Kernel | Boot | Running] -- C:\windows\System32\drivers\SafeBoot.sys -- (SafeBoot)
DRV - [2008/05/21 11:35:06 | 003,552,768 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008/04/28 10:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\AtiPcie.sys -- (AtiPcie) ATI PCI Express (3GIO)
DRV - [2008/04/14 22:39:06 | 000,009,344 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2008/04/10 18:27:34 | 001,804,160 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2uvc.sys -- (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2008/04/07 19:13:46 | 000,025,448 | ---- | M] (Hewlett-Packard Corporation) [Kernel | Boot | Running] -- C:\windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
DRV - [2008/04/07 19:13:42 | 000,034,664 | ---- | M] (Hewlett-Packard Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2008/02/29 17:13:38 | 001,202,560 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/01/21 03:23:26 | 000,045,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...&bd=all&pf=cmnbIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.h...&bd=all&pf=cmnb IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.h...&bd=all&pf=cmnbIE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..\URLSearchHook: {90b49673-5506-483e-b92b-ca0265bd9ca8} - No CLSID value found
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Joey\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Joey\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\electronicarts.com/GameFacePlugin: C:\Users\Joey\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll (Electronic Arts)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor Enterprise\ [2011/08/31 19:29:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2011/09/17 19:45:00 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{C00439FC-907D-4B3F-8367-ED427CB3A5DC}: C:\Users\Joey\AppData\Local\{C00439FC-907D-4B3F-8367-ED427CB3A5DC} [2011/02/04 18:40:52 | 000,000,000 | ---D | M]
[2011/01/09 20:18:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Joey\AppData\Roaming\Mozilla\Extensions
[2011/01/09 20:18:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Joey\AppData\Roaming\Mozilla\Extensions\
[email protected] ========== Chrome ========== CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url =
http://uk.search.yah...p={searchTerms}CHR - default_search_provider: suggest_url =
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\gcswf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\PFiles\Plugins\np-mswmp.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Joey\AppData\Local\Google\Chrome\Application\14.0.835.202\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Joey\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Unity Player (Enabled) = C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Game Face Plugin (Enabled) = C:\Users\Joey\AppData\Roaming\Electronic Arts\Game Face\npGameFacePlugin.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Chelsea FC = C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\eanaknlfmaafbcpmaoencjmlmfaflkck\1.4_0\
O1 HOSTS File: ([2011/07/01 11:45:51 | 000,000,888 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 209.172.52.74 search.yahoo.com
O1 - Hosts: 209.172.52.74 www.bing.com
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (BHO_Startup Class) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110917133556.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files\IObit Toolbar\IE\4.7\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..\Toolbar\WebBrowser: (no name) - {90B49673-5506-483E-B92B-CA0265BD9CA8} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [accrdsub] c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [File Sanitizer] C:\Program Files\Hewlett-Packard\File Sanitizer\CoreShredder.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [MVS Splash] C:\Program Files\McAfee\Managed VirusScan\DesktopUI\XTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\soundmax.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TalkTalk] C:\Program Files\TalkTalk\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe (InterVideo Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006..\Run: [AdobeBridge] C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe (Adobe Systems, Inc.)
O4 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006..\Run: [Speech Recognition] C:\windows\Speech\Common\sapisvr.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006..\Run: [Xzebimezoc] rundll32.exe "C:\Users\Joey\AppData\Local\dpskbsc.dll",Startup File not found
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKLM\..Trusted Domains: //about.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Exclude.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //FWEvent.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //LanguageSelection.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Message.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryCmd.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyAgttryNag.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //MyNotification.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //NOCLessUpdate.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //quarantine.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //ScanNow.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //strings.vbs/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Template.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //Update.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: //VirFound.htm/ ([]myui in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafee.com ([*] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([betavscan] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([vs] https in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] http in Trusted sites)
O15 - HKLM\..Trusted Domains: mcafeeasap.com ([www] https in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1979 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1979 ([http] in Local intranet)
O15 - HKU\S-1-5-21-3688371679-3231779085-4022764246-1006\..Trusted Ranges: Range1979 ([http] in Local intranet)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx1.hotmail....NPUplden-gb.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4AD2F94C-3743-4A52-B03A-974EE6D2C0CD}: NameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EDCFC6B0-6F11-4654-B0F2-9AB6BAAADAB0}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\myrm {4D034FC3-013F-4b95-B544-44D49ABE3E76} - C:\Program Files\McAfee\Managed VirusScan\Agent\MyRmProt5.0.0.811.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files\McAfee\SiteAdvisor Enterprise\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (APSHook.dll) -C:\windows\System32\APSHook.dll (Bioscrypt Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Joey\Pictures\solo-sea-570.jpg
O24 - Desktop BackupWallPaper: C:\Users\Joey\Pictures\solo-sea-570.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\OblivionLauncher.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\steambackup2.EXE
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2011/10/21 20:45:57 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\Callum
[2011/10/21 19:26:54 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/21 19:26:51 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/10/20 18:18:03 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\as2rpg
[2011/10/20 17:41:43 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\rpg game
[2011/10/19 20:12:51 | 000,000,000 | ---D | C] -- C:\Users\Joey\.soulsplit
[2011/10/19 15:57:27 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\20051104-server
[2011/10/15 21:25:39 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\Meh
[2011/10/14 18:21:25 | 000,000,000 | ---D | C] -- C:\Users\Joey\Documents\.settings
[2011/10/13 20:44:13 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/10/13 19:28:39 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2011/10/13 19:20:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2011/10/13 18:57:02 | 000,000,000 | ---D | C] -- C:\Program Files\AdobeFlashProCS5.5
[2011/10/10 15:48:45 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\LogMeIn Hamachi
[2011/10/10 15:47:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/10/10 15:47:33 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2011/10/10 07:43:20 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[2011/10/10 07:43:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
[2011/10/10 07:43:18 | 000,000,000 | ---D | C] -- C:\Program Files\IObit Toolbar
[2011/10/10 07:41:37 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\Game
[2011/10/08 21:01:27 | 000,399,736 | ---- | C] (BitTorrent, Inc.) -- C:\Users\Joey\uTorrent.exe
[2011/10/08 15:58:48 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{B28AC5BF-5B63-4DFB-9DB9-27414EA531DE}
[2011/10/08 15:58:36 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{18E447B2-4192-493A-901A-A1D665356B86}
[2011/10/07 19:06:42 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Roaming\.minecraft
[2011/10/07 18:28:10 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\gctmp
[2011/10/07 18:27:51 | 000,000,000 | ---D | C] -- C:\Program Files\Game Cam V2
[2011/10/07 17:29:37 | 000,000,000 | ---D | C] -- C:\Program Files\Minecraft
[2011/10/07 17:03:17 | 000,000,000 | ---D | C] -- C:\Users\Joey\Documents\My WeGame Videos
[2011/10/07 17:03:17 | 000,000,000 | ---D | C] -- C:\Users\Joey\Documents\My WeGame Screenshots
[2011/10/07 16:47:48 | 000,000,000 | ---D | C] -- C:\ProgramData\WeGame
[2011/10/07 16:46:59 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\WeGame
[2011/10/07 16:46:58 | 000,000,000 | ---D | C] -- C:\Program Files\WeGame
[2011/10/07 15:41:45 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{1CD2FE77-7DF1-4B35-9D13-CE2EB8522C00}
[2011/10/07 15:41:33 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{D59E2715-52B3-4E72-BBAA-53D64AF8F14F}
[2011/10/06 19:31:31 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\AMD
[2011/10/06 19:31:22 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2011/10/06 19:31:15 | 000,000,000 | ---D | C] -- C:\Program Files\AMD APP
[2011/10/06 19:30:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2011/10/06 19:30:13 | 000,000,000 | ---D | C] -- C:\ProgramData\AMD
[2011/10/06 19:16:27 | 000,000,000 | ---D | C] -- C:\ATI
[2011/10/06 18:18:20 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{1628AC15-B031-428E-A2BD-78E316DB750F}
[2011/10/06 18:18:07 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{899E40C3-2A37-4202-BD1F-5400B7D2DD1C}
[2011/10/04 19:38:59 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{C07242AF-F3BD-4E97-9439-33FE8C6974F7}
[2011/10/04 19:38:47 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{BF5CDC11-FDEA-483E-854C-186AFF7600F5}
[2011/10/03 17:06:16 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{358EB5A6-9C01-4919-BA16-A532139125A8}
[2011/10/03 17:06:03 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{C4136C83-491E-4BF6-8DFE-A2109A38DE75}
[2011/10/02 17:38:54 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{834130C8-50F6-4F44-AE45-274C6D74E8DB}
[2011/10/02 17:38:42 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{59806853-90DB-4F36-9A1D-3910DB2F2BC2}
[2011/10/01 14:38:32 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{9826CC3B-48F3-43FB-9814-692DFCC3B483}
[2011/10/01 14:38:20 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{39304BBF-A373-4EEB-A3D8-1ECB0CA7FBCA}
[2011/09/30 17:58:16 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{C6A99372-B53A-453F-B0C3-C0CA60C1952E}
[2011/09/30 15:34:01 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{D05BB804-C465-4873-BD8B-B626D3096280}
[2011/09/28 20:41:03 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{0327A231-7457-46BF-AD7A-BD91C0FA0EDF}
[2011/09/28 20:40:51 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{13A88C11-21B9-4AA2-B0EE-2B78E6358DD4}
[2011/09/27 17:15:50 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{7DDD476F-CFA0-407C-9C3E-13EE4071A2AD}
[2011/09/27 17:15:38 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{2D4B71CC-6DCA-4170-B9C9-60B6795EE87F}
[2011/09/26 20:26:12 | 000,000,000 | ---D | C] -- C:\Users\Joey\Desktop\TP
[2011/09/26 16:45:10 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{93FC7C1B-94D2-4CDF-8D20-05BA18769E7B}
[2011/09/26 16:44:58 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{7A97A2B6-DFF4-4C2B-8E0C-254AE7ED10BB}
[2011/09/25 20:02:23 | 000,000,000 | ---D | C] -- C:\Program Files\Paint.NET
[2011/09/25 20:01:47 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\Paint.NET
[2011/09/25 15:32:13 | 000,000,000 | ---D | C] -- C:\Users\Joey\Minecraft
[2011/09/23 15:33:42 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{9C85AC37-1004-4ABB-BCEC-DAF82BCD6900}
[2011/09/23 15:33:28 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{394F08D7-89C9-4050-AD79-B90C8D0EB4DF}
[2011/09/22 19:08:10 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{E179A1E3-02B3-4F9D-8B3A-FFD51EFC29F7}
[2011/09/22 19:07:55 | 000,000,000 | ---D | C] -- C:\Users\Joey\AppData\Local\{335CC9C4-2CC6-476D-BE77-F460438D9B33}
[2009/01/30 22:31:59 | 000,180,224 | ---- | C] ( ) -- C:\windows\System32\rsnp2uvc.dll
[2009/01/30 22:31:58 | 000,176,128 | ---- | C] ( ) -- C:\windows\System32\csnp2uvc.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/10/21 19:28:09 | 000,002,521 | ---- | M] () -- C:\Users\Joey\Desktop\HiJackThis.lnk
[2011/10/21 19:20:45 | 000,694,754 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2011/10/21 19:20:45 | 000,142,954 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2011/10/21 19:13:43 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/21 19:13:43 | 000,003,216 | -H-- | M] () -- C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/21 19:13:36 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2011/10/21 19:13:32 | 2949,505,024 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/20 22:10:56 | 000,000,012 | ---- | M] () -- C:\windows\bthservsdp.dat
[2011/10/20 21:26:55 | 000,000,035 | ---- | M] () -- C:\Users\Joey\jagex_runescape_preferences.dat
[2011/10/20 21:25:59 | 000,000,129 | ---- | M] () -- C:\Users\Joey\jagex_runescape_preferences2.dat
[2011/10/20 18:07:49 | 000,009,755 | ---- | M] () -- C:\Users\Joey\Documents\platformgame2.fla
[2011/10/20 18:07:06 | 000,001,391 | ---- | M] () -- C:\Users\Joey\Documents\platformgame2.swf
[2011/10/20 18:04:42 | 000,001,299 | ---- | M] () -- C:\Users\Joey\Documents\platformgame1.swf
[2011/10/19 15:55:21 | 000,000,852 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3688371679-3231779085-4022764246-1006Core1cc8e6f1fefa1c7.job
[2011/10/18 18:59:45 | 000,002,771 | ---- | M] () -- C:\Users\Joey\Documents\anim1wave.swf
[2011/10/18 18:59:35 | 000,377,863 | ---- | M] () -- C:\Users\Joey\Documents\pointandclickadventure1.fla
[2011/10/18 18:55:05 | 000,082,719 | ---- | M] () -- C:\Users\Joey\Documents\pointandclickadventure1.swf
[2011/10/18 18:01:21 | 000,000,882 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore1cc8db78f8afcf3.job
[2011/10/16 20:41:28 | 000,014,916 | ---- | M] () -- C:\Users\Joey\Documents\escapechapter1.fla
[2011/10/16 20:25:23 | 000,002,043 | ---- | M] () -- C:\Users\Joey\Documents\escapechapter1.swf
[2011/10/16 17:50:01 | 000,017,590 | ---- | M] () -- C:\Users\Joey\Documents\anim1wave.fla
[2011/10/16 17:01:48 | 000,004,394 | ---- | M] () -- C:\Users\Joey\Documents\testanim.swf
[2011/10/16 16:46:09 | 000,022,851 | ---- | M] () -- C:\Users\Joey\Documents\testanim.fla
[2011/10/16 14:25:00 | 000,000,829 | ---- | M] () -- C:\Users\Joey\Documents\.actionScriptProperties
[2011/10/16 14:25:00 | 000,000,474 | ---- | M] () -- C:\Users\Joey\Documents\.project
[2011/10/15 21:47:13 | 000,092,672 | ---- | M] () -- C:\Users\Joey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/15 21:28:11 | 000,009,917 | ---- | M] () -- C:\Users\Joey\Documents\platformgame1.fla
[2011/10/15 20:07:59 | 000,000,600 | ---- | M] () -- C:\Users\Joey\AppData\Local\PUTTY.RND
[2011/10/14 22:10:22 | 000,133,177 | ---- | M] () -- C:\Users\Joey\Documents\dressupnearlydone.fla
[2011/10/14 22:09:35 | 000,133,136 | ---- | M] () -- C:\Users\Joey\Documents\dressup3.fla
[2011/10/14 22:08:04 | 000,021,886 | ---- | M] () -- C:\Users\Joey\Documents\dressup3.swf
[2011/10/14 18:25:06 | 000,002,080 | ---- | M] () -- C:\Users\Joey\Documents\dressup3.html
[2011/10/14 18:21:23 | 000,004,365 | ---- | M] () -- C:\Users\Joey\Documents\AuthortimeSharedAssets.fla
[2011/10/14 18:20:32 | 000,129,311 | ---- | M] () -- C:\Users\Joey\Documents\dressup1.fla
[2011/10/14 17:20:22 | 000,085,271 | ---- | M] () -- C:\Users\Joey\Documents\dressup2.fla
[2011/10/14 17:13:42 | 000,018,615 | ---- | M] () -- C:\Users\Joey\Documents\dressup1.swf
[2011/10/13 21:12:40 | 000,020,050 | ---- | M] () -- C:\Users\Joey\Documents\Untitled-3.fla
[2011/10/13 20:07:18 | 000,000,352 | ---- | M] () -- C:\windows\tasks\AdobeAAMUpdater-1.0-vera-PC-Joey.job
[2011/10/13 20:06:59 | 000,007,263 | ---- | M] () -- C:\Users\Joey\Documents\Untitled-2.fla
[2011/10/13 17:22:53 | 000,453,920 | ---- | M] () -- C:\windows\System32\FNTCACHE.DAT
[2011/10/07 18:39:26 | 000,001,523 | ---- | M] () -- C:\Users\Joey\Application Data\Microsoft\Internet Explorer\Quick Launch\MinecraftSP - Shortcut.lnk
[2011/10/07 18:25:06 | 000,001,523 | ---- | M] () -- C:\Users\Joey\Desktop\MinecraftSP - Shortcut.lnk
[2011/10/05 16:02:34 | 000,001,999 | ---- | M] () -- C:\Users\Joey\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/10/05 16:02:33 | 000,002,037 | ---- | M] () -- C:\Users\Joey\Desktop\Google Chrome.lnk
[2011/09/30 20:38:35 | 000,000,938 | ---- | M] () -- C:\Users\Joey\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2011/09/25 20:11:35 | 000,002,722 | ---- | M] () -- C:\Users\Joey\.recently-used.xbel
[2011/09/25 20:03:50 | 000,000,934 | ---- | M] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/09/25 17:41:23 | 000,003,741 | ---- | M] () -- C:\Users\Joey\pack.png
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/10/21 19:26:54 | 000,002,521 | ---- | C] () -- C:\Users\Joey\Desktop\HiJackThis.lnk
[2011/10/20 18:06:01 | 000,001,391 | ---- | C] () -- C:\Users\Joey\Documents\platformgame2.swf
[2011/10/20 18:05:41 | 000,009,755 | ---- | C] () -- C:\Users\Joey\Documents\platformgame2.fla
[2011/10/19 15:55:21 | 000,000,852 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-3688371679-3231779085-4022764246-1006Core1cc8e6f1fefa1c7.job
[2011/10/18 18:59:44 | 000,002,771 | ---- | C] () -- C:\Users\Joey\Documents\anim1wave.swf
[2011/10/18 18:01:21 | 000,000,882 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore1cc8db78f8afcf3.job
[2011/10/17 21:46:19 | 000,082,719 | ---- | C] () -- C:\Users\Joey\Documents\pointandclickadventure1.swf
[2011/10/16 21:01:05 | 000,377,863 | ---- | C] () -- C:\Users\Joey\Documents\pointandclickadventure1.fla
[2011/10/16 19:47:46 | 000,002,043 | ---- | C] () -- C:\Users\Joey\Documents\escapechapter1.swf
[2011/10/16 19:04:03 | 000,014,916 | ---- | C] () -- C:\Users\Joey\Documents\escapechapter1.fla
[2011/10/16 17:50:00 | 000,017,590 | ---- | C] () -- C:\Users\Joey\Documents\anim1wave.fla
[2011/10/16 17:01:48 | 000,004,394 | ---- | C] () -- C:\Users\Joey\Documents\testanim.swf
[2011/10/16 16:46:08 | 000,022,851 | ---- | C] () -- C:\Users\Joey\Documents\testanim.fla
[2011/10/15 21:26:35 | 000,001,299 | ---- | C] () -- C:\Users\Joey\Documents\platformgame1.swf
[2011/10/15 21:17:20 | 000,009,917 | ---- | C] () -- C:\Users\Joey\Documents\platformgame1.fla
[2011/10/14 22:10:21 | 000,133,177 | ---- | C] () -- C:\Users\Joey\Documents\dressupnearlydone.fla
[2011/10/14 18:25:06 | 000,002,080 | ---- | C] () -- C:\Users\Joey\Documents\dressup3.html
[2011/10/14 18:25:05 | 000,021,886 | ---- | C] () -- C:\Users\Joey\Documents\dressup3.swf
[2011/10/14 18:21:25 | 000,000,829 | ---- | C] () -- C:\Users\Joey\Documents\.actionScriptProperties
[2011/10/14 18:21:25 | 000,000,474 | ---- | C] () -- C:\Users\Joey\Documents\.project
[2011/10/14 18:21:23 | 000,004,365 | ---- | C] () -- C:\Users\Joey\Documents\AuthortimeSharedAssets.fla
[2011/10/14 18:21:15 | 000,133,136 | ---- | C] () -- C:\Users\Joey\Documents\dressup3.fla
[2011/10/14 17:20:22 | 000,085,271 | ---- | C] () -- C:\Users\Joey\Documents\dressup2.fla
[2011/10/14 17:00:12 | 000,018,615 | ---- | C] () -- C:\Users\Joey\Documents\dressup1.swf
[2011/10/14 16:43:18 | 000,129,311 | ---- | C] () -- C:\Users\Joey\Documents\dressup1.fla
[2011/10/13 21:12:40 | 000,020,050 | ---- | C] () -- C:\Users\Joey\Documents\Untitled-3.fla
[2011/10/13 20:07:18 | 000,000,352 | ---- | C] () -- C:\windows\tasks\AdobeAAMUpdater-1.0-vera-PC-Joey.job
[2011/10/13 20:06:58 | 000,007,263 | ---- | C] () -- C:\Users\Joey\Documents\Untitled-2.fla
[2011/10/13 19:18:13 | 000,000,874 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/10 21:54:51 | 000,000,923 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2011/10/09 16:03:07 | 000,000,600 | ---- | C] () -- C:\Users\Joey\AppData\Local\PUTTY.RND
[2011/10/07 18:39:26 | 000,001,523 | ---- | C] () -- C:\Users\Joey\Application Data\Microsoft\Internet Explorer\Quick Launch\MinecraftSP - Shortcut.lnk
[2011/09/25 20:11:35 | 000,002,722 | ---- | C] () -- C:\Users\Joey\.recently-used.xbel
[2011/09/25 20:03:50 | 000,000,946 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2011/09/25 20:03:50 | 000,000,934 | ---- | C] () -- C:\Users\Public\Desktop\Paint.NET.lnk
[2011/09/25 17:41:23 | 000,003,741 | ---- | C] () -- C:\Users\Joey\pack.png
[2011/09/23 15:54:07 | 000,001,523 | ---- | C] () -- C:\Users\Joey\Desktop\MinecraftSP - Shortcut.lnk
[2011/09/14 11:47:40 | 000,053,760 | ---- | C] () -- C:\windows\System32\OVDecode.dll
[2011/08/11 12:47:43 | 000,000,127 | ---- | C] () -- C:\windows\System32\MRT.INI
[2011/07/03 21:57:02 | 000,000,680 | ---- | C] () -- C:\Users\Joey\AppData\Local\d3d9caps.dat
[2011/07/03 14:23:37 | 000,022,528 | --S- | C] () -- C:\windows\System32\drivers\PsSdk30.drv
[2011/06/25 21:38:01 | 000,001,676 | -H-- | C] () -- C:\Users\Joey\AppData\Local\GDIPFONT298ROMV32.DAT
[2011/06/07 17:49:17 | 000,175,616 | ---- | C] () -- C:\windows\System32\unrar.dll
[2011/06/07 17:49:15 | 000,000,038 | ---- | C] () -- C:\windows\avisplitter.ini
[2011/06/07 17:49:01 | 002,712,064 | ---- | C] () -- C:\windows\System32\x264vfw.dll
[2011/06/07 17:49:01 | 000,631,808 | ---- | C] () -- C:\windows\System32\xvidcore.dll
[2011/06/07 17:49:01 | 000,243,200 | ---- | C] () -- C:\windows\System32\xvidvfw.dll
[2011/06/07 17:49:00 | 000,080,896 | ---- | C] () -- C:\windows\System32\ff_vfw.dll
[2011/02/04 23:22:25 | 000,006,551 | ---- | C] () -- C:\Users\Joey\AppData\Roaming\UserTile.png
[2011/02/04 18:40:53 | 000,000,120 | ---- | C] () -- C:\Users\Joey\AppData\Local\Flizehez.dat
[2011/02/04 18:40:53 | 000,000,000 | ---- | C] () -- C:\Users\Joey\AppData\Local\Mqogijefedawevev.bin
[2011/01/30 01:18:10 | 000,000,752 | ---- | C] () -- C:\windows\AnimatorDV.INI
[2011/01/04 22:44:16 | 000,092,672 | ---- | C] () -- C:\Users\Joey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/02 08:33:54 | 000,015,360 | ---- | C] () -- C:\windows\System32\bdmjpeg.dll
[2010/09/02 08:32:52 | 000,058,368 | ---- | C] () -- C:\windows\System32\bdmpegv.dll
[2009/09/11 22:17:15 | 000,117,248 | ---- | C] () -- C:\windows\System32\EhStorAuthn.dll
[2009/09/11 22:17:15 | 000,107,612 | ---- | C] () -- C:\windows\System32\StructuredQuerySchema.bin
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\windows\System32\OGAEXEC.exe
[2009/02/21 20:44:23 | 000,000,376 | ---- | C] () -- C:\windows\ODBC.INI
[2009/02/21 18:51:34 | 000,000,750 | ---- | C] () -- C:\windows\{D084B1A9-153B-409D-AEBF-C40FCEF925EA}_WiseFW.ini
[2009/01/31 05:09:05 | 000,000,012 | ---- | C] () -- C:\windows\bthservsdp.dat
[2009/01/30 23:55:34 | 000,018,904 | ---- | C] () -- C:\windows\System32\StructuredQuerySchemaTrivial.bin
[2009/01/30 22:31:59 | 001,804,160 | ---- | C] () -- C:\windows\System32\drivers\snp2uvc.sys
[2009/01/30 22:31:59 | 000,028,160 | ---- | C] () -- C:\windows\System32\drivers\sncduvc.sys
[2009/01/30 22:31:59 | 000,015,497 | ---- | C] () -- C:\windows\snp2uvc.ini
[2008/11/06 15:23:12 | 000,003,584 | ---- | C] () -- C:\windows\System32\wceprv.dll
[2008/10/22 05:29:06 | 000,173,550 | ---- | C] () -- C:\windows\System32\xlive.dll.cat
[2008/06/26 07:56:29 | 000,204,800 | ---- | C] () -- C:\windows\System32\IVIresizeW7.dll
[2008/06/26 07:56:29 | 000,200,704 | ---- | C] () -- C:\windows\System32\IVIresizeA6.dll
[2008/06/26 07:56:29 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeP6.dll
[2008/06/26 07:56:29 | 000,192,512 | ---- | C] () -- C:\windows\System32\IVIresizeM6.dll
[2008/06/26 07:56:29 | 000,188,416 | ---- | C] () -- C:\windows\System32\IVIresizePX.dll
[2008/06/26 07:56:29 | 000,020,480 | ---- | C] () -- C:\windows\System32\IVIresize.dll
[2008/06/26 07:25:27 | 000,000,000 | ---- | C] () -- C:\windows\HPMProp.INI
[2008/06/26 06:39:46 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2008/05/30 17:36:58 | 000,108,752 | ---- | C] () -- C:\windows\System32\drivers\SafeBoot.sys
[2008/05/21 10:38:12 | 000,159,744 | ---- | C] () -- C:\windows\System32\atitmmxx.dll
[2008/05/21 10:09:24 | 003,107,788 | ---- | C] () -- C:\windows\System32\atiumdva.dat
[2008/03/06 11:40:54 | 000,168,883 | ---- | C] () -- C:\windows\System32\atiicdxx.dat
[2008/03/04 20:02:00 | 000,090,112 | ---- | C] () -- C:\windows\System32\atibrtmon.exe
[2007/04/27 10:43:58 | 000,120,200 | ---- | C] () -- C:\windows\System32\DLLDEV32i.dll
[2006/11/02 13:57:28 | 000,067,584 | --S- | C] () -- C:\windows\bootstat.dat
[2006/11/02 13:47:37 | 000,453,920 | ---- | C] () -- C:\windows\System32\FNTCACHE.DAT
[2006/11/02 13:35:32 | 000,005,632 | ---- | C] () -- C:\windows\System32\sysprepMCE.dll
[2006/11/02 11:33:01 | 000,694,754 | ---- | C] () -- C:\windows\System32\perfh009.dat
[2006/11/02 11:33:01 | 000,287,440 | ---- | C] () -- C:\windows\System32\perfi009.dat
[2006/11/02 11:33:01 | 000,142,954 | ---- | C] () -- C:\windows\System32\perfc009.dat
[2006/11/02 11:33:01 | 000,030,674 | ---- | C] () -- C:\windows\System32\perfd009.dat
[2006/11/02 11:23:21 | 000,215,943 | ---- | C] () -- C:\windows\System32\dssec.dat
[2006/11/02 09:58:30 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2006/11/02 09:19:00 | 000,000,741 | ---- | C] () -- C:\windows\System32\NOISE.DAT
[2006/11/02 08:40:29 | 000,013,750 | ---- | C] () -- C:\windows\System32\pacerprf.ini
[2006/11/02 08:25:31 | 000,673,088 | ---- | C] () -- C:\windows\System32\mlang.dat
[2006/03/09 10:58:00 | 001,060,424 | ---- | C] () -- C:\windows\System32\WdfCoInstaller01000.dll
[2005/04/03 23:30:00 | 000,110,592 | ---- | C] () -- C:\windows\System32\scardsyn.dll
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\windows\System32\OUTLPERF.INI
[2001/11/14 14:56:00 | 001,802,240 | ---- | C] () -- C:\windows\System32\lcppn21.dll
[1998/05/07 04:10:00 | 000,069,632 | ---- | C] () -- C:\windows\System32\ODMA32.dll
========== LOP Check ========== [2011/10/16 16:16:08 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\.minecraft
[2011/07/25 14:53:50 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\BANDISOFT
[2011/02/12 21:41:17 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Blender Foundation
[2011/10/13 20:44:13 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/01/24 19:44:38 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Daynmo
[2011/09/05 16:05:03 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\DriverCure
[2011/04/25 19:40:29 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Electronic Arts
[2011/10/19 16:37:04 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\FileZilla
[2011/02/18 17:15:19 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\GameTuts
[2011/09/25 20:11:35 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\gtk-2.0
[2011/01/24 23:03:46 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\LEGO Company
[2011/09/29 19:56:24 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\MAGIX
[2011/07/06 17:23:30 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Obzyt
[2011/07/03 23:35:12 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Opguse
[2011/02/04 23:22:25 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\PeerNetworking
[2011/08/29 17:22:24 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\PFStaticIP
[2011/03/10 21:13:13 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Publish Providers
[2011/02/28 17:32:26 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Qyhy
[2011/06/23 19:03:03 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Registry Mechanic
[2011/03/10 21:13:04 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Sony
[2011/09/05 16:05:02 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\SpeedMaxPc
[2011/10/09 17:32:23 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\SystemRequirementsLab
[2011/08/24 14:17:36 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\TeamViewer
[2011/09/03 15:55:18 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Tunngle
[2011/05/15 14:07:49 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Unity
[2011/07/03 23:24:09 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Urqy
[2011/10/16 21:04:50 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\uTorrent
[2011/01/09 20:34:59 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Vivox
[2011/03/19 23:40:13 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\WhiteSmoke
[2011/07/11 17:18:51 | 000,000,000 | ---D | M] -- C:\Users\Joey\AppData\Roaming\Ylnuy
[2011/08/11 20:30:58 | 000,000,000 | ---D | M] -- C:\Users\vera\AppData\Roaming\IMVU
[2011/07/18 12:06:58 | 000,000,000 | ---D | M] -- C:\Users\vera\AppData\Roaming\IMVUClient
[2009/03/22 20:56:26 | 000,000,000 | ---D | M] -- C:\Users\vera\AppData\Roaming\InterVideo
[2011/09/05 16:32:07 | 000,000,370 | ---- | M] () -- C:\windows\Tasks\RegAce Scheduled Scan - Joey.job
[2011/08/31 14:03:43 | 000,032,622 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT
[2011/08/31 13:14:07 | 000,000,282 | -H-- | M] () -- C:\windows\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job
[2011/08/31 13:39:04 | 000,000,244 | -H-- | M] () -- C:\windows\Tasks\{810401E2-DDE0-454e-B0E2-AA89C9E5967C}.job
[2011/08/31 13:10:04 | 000,000,282 | -H-- | M] () -- C:\windows\Tasks\{BBAEAEAF-1275-40e2-BD6C-BC8F88BD114A}.job
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.exe >[2007/11/07 08:03:18 | 000,562,688 | ---- | M] (Microsoft Corporation) -- C:\install.exe
< MD5 for: EXPLORER.EXE >[2008/10/29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2011/10/07 18:29:24 | 000,004,608 | ---- | M] () MD5=5D5682BC4894D7EA6B5B6466B2D5F60C -- C:\Users\Joey\AppData\Local\Xenocode\ApplianceCaches\GameCamV2.exe_v049D98E1\Native\STUBEXE\@WINDIR@\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/21 03:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SVCHOST.EXE >[2008/01/21 03:23:43 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/21 03:23:43 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >[2008/01/21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/21 03:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/21 03:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< C:\Windows\assembly\tmp\U\*.* /s > ========== Alternate Data Streams ========== @Alternate Data Stream - 64 bytes -> C:\Users\Joey\Documents\Test.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Joey\Documents\clip0006.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Joey\Documents\clip0005.avi:TOC.WMV
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >