Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Priuschat forum virus, rundll32.exe, redirects


  • Please log in to reply

#1
shindouhikaru888

shindouhikaru888

    New Member

  • Member
  • Pip
  • 2 posts
Hi, i'm sure i received a virus after visiting the priuschat forum, and after some googling i noticed others had this problem as well. I've scanned my computer with Avira premium security suite and Malwarebyte and removed all the viruses that they successfully scan. However, since i have a hybrid graphic cards, i noticed my computer asking if i should use my ATI graphic card for rundll32.exe often, and i noticed i have a few redirects clicking sites from google search.

OTL log:

OTL logfile created on: 10/26/2011 5:35:35 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Sunny\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 37.76% Memory free
7.82 Gb Paging File | 4.51 Gb Available in Paging File | 57.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 394.45 Gb Free Space | 87.72% Space Free | Partition Type: NTFS

Computer Name: SUNNY-VAIO | User Name: Sunny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/10/26 17:33:37 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sunny\Desktop\OTL.exe
PRC - [2011/07/03 21:00:41 | 000,243,360 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10u_ActiveX.exe
PRC - [2011/06/28 08:26:26 | 000,567,464 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe
PRC - [2011/06/28 08:26:26 | 000,428,200 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe
PRC - [2011/06/28 08:26:26 | 000,340,136 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe
PRC - [2011/06/28 08:26:26 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/05/24 18:21:46 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011/05/24 18:21:46 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2010/12/27 15:05:24 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/27 15:05:13 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/12/23 19:24:52 | 000,206,224 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
PRC - [2010/12/23 19:24:52 | 000,095,632 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
PRC - [2010/11/27 03:55:44 | 000,648,032 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
PRC - [2010/11/27 03:55:44 | 000,398,176 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
PRC - [2010/11/17 21:30:12 | 000,673,168 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
PRC - [2010/09/27 23:41:54 | 000,081,296 | ---- | M] (Sony Corporation) -- C:\Program Files\Sony\VAIO Care\VCSpt.exe
PRC - [2010/09/27 18:12:36 | 000,864,000 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
PRC - [2010/09/22 21:11:26 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2010/09/13 21:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/13 21:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/08/13 18:19:04 | 000,273,672 | ---- | M] (Microsoft Corp.) -- C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\mswinext.exe
PRC - [2010/07/29 22:39:24 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010/06/30 15:31:05 | 000,492,384 | ---- | M] (Digital Delivery Networks, Inc.) -- C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe
PRC - [2010/06/23 08:39:54 | 000,046,080 | ---- | M] () -- C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe
PRC - [2010/05/18 16:38:46 | 000,075,776 | ---- | M] (Sony of America Corporation) -- C:\Program Files\Sony\VAIO Care\listener.exe
PRC - [2009/12/03 10:12:12 | 000,976,320 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe
PRC - [2008/09/18 13:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe


========== Modules (No Company Name) ==========

MOD - [2011/10/25 09:47:12 | 000,159,744 | ---- | M] () -- C:\Users\Sunny\AppData\Local\SysUserusb\odbcEventCtrl.dll
MOD - [2011/10/13 05:02:48 | 000,401,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\6c1567259547084fc25ef4941b184be5\System.Xml.Linq.ni.dll
MOD - [2011/10/13 05:02:47 | 002,516,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\2ce656ab44ac6cc82d78a16cea56b087\System.Data.Linq.ni.dll
MOD - [2011/10/13 05:02:18 | 000,082,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn.Contra#\49c0850ff20d17128d372aec3efddba2\System.AddIn.Contract.ni.dll
MOD - [2011/10/13 03:43:00 | 002,347,008 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8dba8803fad87c39c0afbdce6c19fdd0\System.Runtime.Serialization.ni.dll
MOD - [2011/10/13 03:41:54 | 000,055,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Vsa\427cfa4ca740c895f172ca51283f4ebd\Microsoft.Vsa.ni.dll
MOD - [2011/10/13 03:41:53 | 002,332,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\b6811aa41cca1457c8f24e848c9e94e4\Microsoft.JScript.ni.dll
MOD - [2011/10/13 03:41:51 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c1d4760b74a5601754f0a61b22b2610e\IAStorUtil.ni.dll
MOD - [2011/10/13 03:41:51 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\2abaab1dfbdf0db8f4bf0378d8599c98\IAStorCommon.ni.dll
MOD - [2011/10/13 03:41:45 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\6d859463c9e6a7423ddb335211a79dda\System.Core.ni.dll
MOD - [2011/10/13 03:41:42 | 000,633,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\cf525dfab6205fc09e6cb3a69b9ad36d\System.AddIn.ni.dll
MOD - [2011/10/13 03:36:04 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5672e6b9d976feca51deb06d8dd1df0e\PresentationFramework.Aero.ni.dll
MOD - [2011/10/13 03:35:50 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll
MOD - [2011/10/13 03:35:49 | 000,628,224 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\fd6d00c3c7d56a2e3651769081e8f412\System.EnterpriseServices.ni.dll
MOD - [2011/10/13 03:35:49 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\834be57d8ab824b4ebcbf01161791d70\System.Transactions.ni.dll
MOD - [2011/10/13 03:35:48 | 006,618,624 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\45a20172acfdcc160ecb6bd358179c31\System.Data.ni.dll
MOD - [2011/10/13 03:35:38 | 014,322,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09e39322b47f9b4e8dd2199ff03acb2e\PresentationFramework.ni.dll
MOD - [2011/10/13 03:35:26 | 012,431,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll
MOD - [2011/10/13 03:35:21 | 001,586,688 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll
MOD - [2011/10/13 03:35:18 | 012,216,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2dc021a8311197516e4fa325b292f21\PresentationCore.ni.dll
MOD - [2011/10/13 03:35:09 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll
MOD - [2011/10/13 03:35:05 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll
MOD - [2011/10/13 03:35:02 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll
MOD - [2011/10/13 03:35:01 | 007,949,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll
MOD - [2011/10/13 03:34:52 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll
MOD - [2011/03/21 17:30:20 | 000,067,872 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/03/15 07:13:46 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2011/03/02 02:43:15 | 000,271,440 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Data.SqlServerCe\3.5.1.0__89845dcd8080cc91\System.Data.SqlServerCe.dll
MOD - [2010/06/01 10:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2010/03/24 21:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/06/10 16:23:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/06/10 16:23:17 | 002,933,248 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/01/24 01:52:03 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/12/09 19:26:26 | 000,923,024 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Smart Network\VSNService.exe -- (VSNService)
SRV:64bit: - [2010/12/06 12:14:50 | 000,584,080 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Power Management\SPMService.exe -- (VAIO Power Management)
SRV:64bit: - [2010/11/18 12:23:44 | 001,310,096 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Sony\VAIO Update 5\VUAgent.exe -- (VUAgent)
SRV:64bit: - [2010/11/02 16:49:46 | 001,515,792 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV:64bit: - [2010/11/02 16:39:08 | 000,340,240 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- (MyWiFiDHCPDNS)
SRV:64bit: - [2010/11/02 16:34:14 | 000,836,880 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV:64bit: - [2010/10/25 20:55:26 | 000,387,896 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Network Service Manager\VcmINSMgr.exe -- (VcmINSMgr)
SRV:64bit: - [2010/10/25 20:26:34 | 000,101,152 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe -- (VcmXmlIfHelper)
SRV:64bit: - [2010/10/25 20:12:24 | 000,549,168 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe -- (VcmIAlzMgr)
SRV:64bit: - [2010/09/27 18:13:22 | 000,303,872 | ---- | M] (Sony Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\SPF\SpfService64.exe -- (SpfService)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/12 18:15:34 | 000,257,936 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files\Sony\VAIO Care\VCPerfService.exe -- (SampleCollector)
SRV:64bit: - [2010/07/29 22:39:24 | 000,951,584 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/06/28 08:26:26 | 000,567,464 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avfwsvc.exe -- (AntiVirFirewallService)
SRV - [2011/06/28 08:26:26 | 000,428,200 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE -- (AntiVirWebService)
SRV - [2011/06/28 08:26:26 | 000,340,136 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc.exe -- (AntiVirMailService)
SRV - [2011/06/28 08:26:26 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/05/24 18:21:46 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/02 03:14:56 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/12/27 15:05:24 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/12/27 15:05:13 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/12/23 19:24:52 | 000,095,632 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe -- (VAIO Event Service)
SRV - [2010/11/27 03:55:44 | 000,398,176 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2010/10/12 18:52:48 | 000,423,280 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDms.exe -- (SOHDms)
SRV - [2010/09/27 18:12:36 | 000,864,000 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe -- (VCFw)
SRV - [2010/09/13 21:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/09/10 11:47:30 | 000,108,400 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHCImp.exe -- (SOHCImp)
SRV - [2010/09/10 11:47:30 | 000,067,952 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDs.exe -- (SOHDs)
SRV - [2010/06/23 08:39:54 | 000,046,080 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\DDNi\Oasis2Service 1.0\Oasis2Service.exe -- (Oasis2Service)
SRV - [2010/03/18 14:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/09/18 13:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/06/28 08:26:26 | 000,131,336 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avfwot.sys -- (avfwot)
DRV:64bit: - [2011/06/28 08:26:26 | 000,123,784 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avipbb.sys -- (avipbb)
DRV:64bit: - [2011/06/28 08:26:26 | 000,101,984 | ---- | M] (Avira GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avfwim.sys -- (avfwim)
DRV:64bit: - [2011/06/28 08:26:26 | 000,088,288 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\avgntflt.sys -- (avgntflt)
DRV:64bit: - [2011/03/11 01:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/18 16:36:58 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/01/24 02:01:14 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdpmd64.sys -- (intelkmd)
DRV:64bit: - [2011/01/24 02:01:14 | 012,252,192 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/01/24 01:52:38 | 008,283,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/01/24 01:52:38 | 000,295,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/01/24 01:48:15 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud) Intel®
DRV:64bit: - [2011/01/13 06:03:27 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2011/01/06 02:21:39 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/12/27 15:05:12 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/12/27 00:48:45 | 000,098,816 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\risdsnxc64.sys -- (risdsnpe)
DRV:64bit: - [2010/12/17 15:11:39 | 000,102,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimssne64.sys -- (rimspci)
DRV:64bit: - [2010/12/01 08:02:22 | 000,042,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDKMD.sys -- (wdkmd)
DRV:64bit: - [2010/11/18 15:21:11 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010/11/18 15:16:26 | 001,388,080 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/11/09 06:16:36 | 008,500,736 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETwNs64.sys -- (NETwNs64) ___ Intel®
DRV:64bit: - [2010/11/02 15:47:54 | 000,021,544 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/11/02 15:47:53 | 000,344,616 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (btwampfl)
DRV:64bit: - [2010/11/02 15:47:53 | 000,135,720 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2010/11/02 15:47:53 | 000,102,952 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2010/11/02 15:47:16 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2010/09/30 16:00:06 | 000,180,736 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc)
DRV:64bit: - [2010/09/30 16:00:06 | 000,080,384 | ---- | M] (Renesas Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub)
DRV:64bit: - [2010/09/23 03:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/04/26 15:20:29 | 000,012,032 | ---- | M] (Sony Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SFEP.sys -- (SFEP)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:21:48 | 000,038,400 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:64bit: - [2009/06/10 16:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTDPV6.SYS -- (SrvHsfV92)
DRV:64bit: - [2009/06/10 16:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS -- (SrvHsfWinac)
DRV:64bit: - [2009/06/10 16:01:11 | 000,292,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VSTAZL6.SYS -- (SrvHsfHDA)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/10 15:35:02 | 000,281,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\e1y60x64.sys -- (e1yexpress) Intel®
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/26 17:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV - [2011/06/28 08:26:26 | 000,131,336 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\avfwot.sys -- (avfwot)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://sony.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/...015&form=ZGAPHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://sony.msn.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "http://www.bing.com/...15&form=ZGAPHP"
FF - prefs.js..keyword.URL: "http://www.bing.com/...form=ZGAADF&q="

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\Firefox [2011/03/02 04:11:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/03/02 04:11:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/03/02 04:12:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/28 21:29:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2011/05/28 21:29:33 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sunny\AppData\Roaming\Mozilla\Extensions
[2011/07/04 00:16:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sunny\AppData\Roaming\Mozilla\Firefox\Profiles\wzqmrjuj.default\extensions
[2011/07/04 00:12:08 | 000,001,919 | ---- | M] () -- C:\Users\Sunny\AppData\Roaming\Mozilla\Firefox\Profiles\wzqmrjuj.default\searchplugins\bing-zugo.xml
[2011/05/28 21:29:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/04/14 11:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg64.dll (Google Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.0.2282.0\npwinext.dll (Microsoft Corporation)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [ISBMgr.exe] C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKCU..\Run: [EPSON NX420 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIGCA.EXE /FU "C:\Windows\TEMP\E_S6095.tmp" /EF "HKCU" File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [odbcEventCtrl] C:\Users\Sunny\AppData\Local\SysUserusb\odbcEventCtrl.dll ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html File not found
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira GmbH)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira GmbH)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira GmbH)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 129.107.45.80 129.107.31.80
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{76DCA238-E0D8-4D4A-877A-D3C3A844F21A}: DhcpNameServer = 129.107.45.80 129.107.31.80
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/10/26 17:33:28 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Sunny\Desktop\OTL.exe
[2011/10/26 12:46:27 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{D205A67A-2729-4F5A-A2E6-93A22628BE71}
[2011/10/26 12:46:16 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{A56D7A41-FDFB-4603-981F-48E5DF32EDA1}
[2011/10/26 10:06:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{27E92E39-5234-44FA-A83E-924422C96672}
[2011/10/26 10:06:21 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{005AB576-3FF6-484B-A3C4-4199DF59D860}
[2011/10/26 00:35:50 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1001B26D-6A5C-409A-A142-A61B5D9941CC}
[2011/10/26 00:35:40 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3FCDAD24-FC40-4AD8-BCD5-E01B8FFF032B}
[2011/10/25 23:34:03 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{7D75E3F5-3F17-45F7-83B5-F5E12290A0E7}
[2011/10/25 23:33:52 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{082CC8B9-2F78-4D40-B038-4C9BF31123D7}
[2011/10/25 19:41:20 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8CB4DCA5-36A6-4390-8FED-219FBE95F58A}
[2011/10/25 19:41:08 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EE0C6FE2-EC5A-48B1-995B-CD2B768B0AF3}
[2011/10/25 19:31:36 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Roaming\Malwarebytes
[2011/10/25 19:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/25 19:31:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/10/25 19:31:28 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/10/25 19:31:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/25 19:30:47 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Sunny\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/25 18:34:46 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F92ADF19-B958-43C0-A2C9-BFF39E833D53}
[2011/10/25 18:34:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EE5EE730-A766-49F7-9C40-3383FB81BFD3}
[2011/10/25 16:28:09 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\SysUserusb
[2011/10/25 11:17:05 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{AA2FEA93-A65E-49AE-9BAA-42A744B7CDD8}
[2011/10/25 11:16:53 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8A1F4CC8-81F8-4F80-BC59-155DC052DE50}
[2011/10/24 00:22:24 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{ED5021B8-0522-447B-83B6-94A058567523}
[2011/10/24 00:21:59 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{0299B718-5D4B-4F5B-992C-D63215907D21}
[2011/10/22 12:20:06 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1CCB3DC8-EA5B-4642-A5B8-1E5967C4762F}
[2011/10/22 12:19:54 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{45D324C6-9AA8-40E1-B11A-A727E64E8480}
[2011/10/22 00:19:53 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{6B8EAF1C-5213-4E7F-9EFB-486F6CFCAA2E}
[2011/10/21 22:47:15 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{144B11F2-CD61-4B38-8066-A726384DBEBA}
[2011/10/21 09:45:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{9CE549FF-8D6C-49A2-B0C5-EF51F9A869C6}
[2011/10/21 09:45:22 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8D915766-D150-4514-9A5A-6B6E637017A7}
[2011/10/20 10:40:49 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B2F6FD2F-F7D4-415A-B0B6-EA9C11F2517E}
[2011/10/20 10:40:36 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{5B98AD58-8D44-4D40-AE9A-12A47B8C9863}
[2011/10/20 00:27:15 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{28C9E6E1-EE36-48E8-8BA4-6C4EF497D1E9}
[2011/10/20 00:27:04 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1DFC57B0-AD0B-4E80-9F6A-D814636A34A7}
[2011/10/19 09:55:55 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B795E689-7CDE-411D-AD47-23DA0EF8A31C}
[2011/10/19 09:55:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{5FD43D8B-4EBC-42F8-B4FD-4F1D0318301E}
[2011/10/19 08:08:38 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{6DE14232-66AC-435B-8188-DB21B99E53F1}
[2011/10/19 08:08:25 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{BEBB72ED-BA4D-4C3F-AFA3-60A0C9619D34}
[2011/10/19 01:00:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8465A10B-AF74-4DD4-83AF-510EE1A7E0D1}
[2011/10/19 00:59:59 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{D1003C77-FB3C-4BE4-B349-1FFBC06A0354}
[2011/10/18 23:09:41 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{684927D6-1D2E-4F4F-AA6B-0493725530B1}
[2011/10/18 23:09:21 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{996D8DA2-013E-4DAD-8DD5-A3D17A39BDAB}
[2011/10/18 19:02:25 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EE27D001-9149-4970-9E7D-53111773F38D}
[2011/10/18 19:02:14 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{923CF87D-450D-4DC9-A0DB-83F603CF85AC}
[2011/10/18 17:36:37 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{AEF93057-5003-4995-97FC-3060D7389A76}
[2011/10/18 11:30:17 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{DA0F61C4-8BC5-495C-AFA1-A343250C61A9}
[2011/10/18 11:30:06 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{C829742B-0A9A-42EF-9728-B697997121C9}
[2011/10/17 22:58:40 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8A05A9B8-73E4-452E-B5EC-63FA97053511}
[2011/10/17 22:58:28 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{BFF19FC5-A72C-410F-B5BD-8CC8B5C0670B}
[2011/10/17 20:07:00 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8E6FFE68-B558-4741-BBAA-A2E95A2DF62C}
[2011/10/17 20:06:48 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{DFD7689A-0C00-49AB-9C39-627F3841403D}
[2011/10/17 17:20:35 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EA09D78A-A066-466C-9290-EEE98402F5E0}
[2011/10/17 17:20:21 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{966CCCA8-4208-41B7-8DC6-B1A8EC97B049}
[2011/10/17 03:57:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{6B362F8B-470A-4147-86F3-E662CBFBFA8D}
[2011/10/17 03:17:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{C0698FE0-ED82-41EF-91DD-CC9D6DBDFB9A}
[2011/10/17 03:17:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{7BB5F28D-E828-4E5A-AC84-82A7A9A56F80}
[2011/10/16 23:55:15 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E5A81276-9404-435C-AE59-85E4F82470C8}
[2011/10/16 11:55:08 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{9E60B8EA-E2B1-4937-9F1F-8222117DCA95}
[2011/10/16 01:27:30 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3AC8F1D2-50A5-41AE-9051-95F60E8E792B}
[2011/10/16 01:27:15 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{579DD369-4011-4BC9-A4DB-F62FD99AA687}
[2011/10/15 10:16:59 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{81BD176A-B6A8-4116-B804-858AF74CE6F5}
[2011/10/15 10:16:43 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1E2A0706-06B0-432A-9B3B-2828AD9638C7}
[2011/10/14 22:36:07 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3AADEB58-D77B-4F97-A20E-752ECAEFC704}
[2011/10/14 10:01:32 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8C97DA7A-515F-476A-832A-3FA9F9341ECD}
[2011/10/14 10:01:15 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{6246298E-B205-4E3C-99E6-68857FDF0883}
[2011/10/14 00:13:50 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{A0A2D5B6-0F29-45C7-B366-138F997277E9}
[2011/10/14 00:13:37 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{87A10F37-CC56-42B8-B735-401FDF85DCDF}
[2011/10/13 19:48:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{81773610-A4D4-44E4-9B7A-C272A5DD4DDC}
[2011/10/13 19:48:31 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EC6917A4-C9C2-4FB9-98C3-1078716958A3}
[2011/10/13 16:28:54 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{82A54752-D412-4B40-8466-1A22B6DA6248}
[2011/10/13 03:30:21 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{FC2F0D8F-3A36-403B-BD26-AD663C82CE9C}
[2011/10/13 03:30:06 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{A51F9373-93CD-4044-9309-5A0447A6B48C}
[2011/10/12 22:51:02 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{56722B49-7C90-47AF-86D5-8DE827D190C8}
[2011/10/12 22:50:50 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{682E4C15-8FBD-477F-9E13-CD67D7439535}
[2011/10/12 17:00:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E8CD7785-0F8D-4B15-A37D-CD5354E29B9A}
[2011/10/12 17:00:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{73D9C8FB-288F-40D6-84B7-79BDEF9C584C}
[2011/10/12 10:21:08 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{610D5D92-A7F9-4933-AF15-DEEC823C14D3}
[2011/10/12 10:20:54 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{50AA2E69-AB21-42EF-8A76-F3CA34F2B618}
[2011/10/11 22:57:57 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{158BEE0B-A1CA-4E27-9194-F5EA3D259309}
[2011/10/11 22:57:42 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{FF922E50-F172-43FD-B0E8-2B12AD4C8695}
[2011/10/11 11:07:18 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{480E6639-2027-4E9A-A074-7D2AB3CF9F3A}
[2011/10/11 11:07:07 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{FA907F3E-1025-4007-BD4B-0FF6CAB38478}
[2011/10/11 09:04:25 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{4F926128-31E8-4D9B-8379-2EE8339D7977}
[2011/10/11 09:04:13 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{A7C562C1-303F-4B6C-A048-C6F5CEE579A4}
[2011/10/10 10:09:24 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{2F5D5BC0-CDAA-40A8-919D-B5F05F70DF7A}
[2011/10/10 10:09:12 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{460F39D1-5A9D-41E4-8CF1-4C2C42540C19}
[2011/10/10 07:28:05 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{64908667-1F45-4327-8D0F-32C9DF8BEDFF}
[2011/10/10 07:27:52 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F7D69A63-B06C-4CFA-B62C-BCBFD8AE1DB4}
[2011/10/10 02:03:06 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{D4C1EBCE-72CD-45FB-94A5-C2A48DCDECD5}
[2011/10/10 02:02:53 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{7B8DF8DB-D89E-4D14-8E8A-63880A8F7129}
[2011/10/10 00:04:06 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{004BC9FF-FF37-41E4-A410-8AB60FBFE9DF}
[2011/10/10 00:03:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{995D9248-78FA-4025-9871-D1EA1DDF23EA}
[2011/10/08 22:52:49 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{4EC6E162-6BCE-411E-A49A-4E535DAC6D4A}
[2011/10/08 22:52:35 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{19A6817C-9A05-4FA0-9C70-DEAB67EDA89C}
[2011/10/08 00:33:22 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{9148745D-FB22-4DF3-8A39-14EF7E12EE3E}
[2011/10/08 00:33:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E18C816A-DBEE-43C7-831B-08A0B832C5E3}
[2011/10/06 20:07:41 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{D60B47A6-CFD5-4A63-A33F-FBF6EE17A4C8}
[2011/10/06 20:07:03 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{320E855A-F358-4587-9991-9BB78C66FDAB}
[2011/10/05 22:54:01 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{BE22BD45-FDED-4881-9403-2E52734835F9}
[2011/10/05 22:52:11 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F41C21C4-BE16-4FCB-9508-514B1830DA38}
[2011/10/05 11:56:44 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{58B30B73-8DFD-48ED-B3AD-9FA74A378D6C}
[2011/10/05 11:56:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{DEB9F10C-2756-4F63-B102-B296B39D536C}
[2011/10/05 09:59:29 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{92713E96-692B-4CDE-AB91-67A2573403C9}
[2011/10/05 09:59:17 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{781B8D28-4091-4A06-93F1-805E7D112F66}
[2011/10/05 00:52:03 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{4486B7F6-1676-438D-BBAE-85CCC6C238ED}
[2011/10/05 00:51:51 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{4ADFE436-A241-41FD-A061-0B911F0EB7E0}
[2011/10/04 21:51:20 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{D7B8A96D-8A4D-459B-A222-2889DE0B5B5B}
[2011/10/04 21:51:07 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B28BC2E0-6AD4-4FC1-837B-D60B4D74060D}
[2011/10/03 23:05:57 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{88E988E1-4622-4713-B047-3AE3C47D4327}
[2011/10/03 23:05:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E99E44A5-DFC1-41D6-92BA-7B9EAFCE5AEB}
[2011/10/03 18:41:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{ACFD6AF4-B5AF-4110-9CD7-81F4356B1CF6}
[2011/10/03 18:41:23 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3C94261A-211C-4EAF-B3AD-DFF37C80F677}
[2011/10/03 10:27:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F3D01F2E-4C2C-4871-B3B0-50B6D57DE5F5}
[2011/10/03 10:27:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{14028118-8EAA-4685-A56A-CF26A041871C}
[2011/10/02 23:36:59 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{FA56ED07-1BBB-4A8D-A18A-183A75B4956F}
[2011/10/02 23:36:47 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{4548D96A-15B9-4315-BFD9-6350B3FE17B0}
[2011/10/02 19:48:31 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{CE2AB4AA-3C04-46EF-9874-54440F2078C6}
[2011/10/02 19:48:16 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F0334354-173D-40A5-9E5E-90B53213DA1C}
[2011/10/02 18:23:22 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{613E4152-14A3-4A75-829E-DDBA4506BF53}
[2011/10/02 18:23:08 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{903C974F-81A9-468B-A0F5-425C535B8F73}
[2011/10/02 14:30:40 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{7BB07461-5798-4C16-9CBA-CC0E57728194}
[2011/10/02 14:30:18 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{DE5E1899-0DB8-47C7-9D03-89B51E69C0FC}
[2011/10/02 09:22:58 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F2C0C8FC-7ECD-47BD-97BF-A8216263BBD7}
[2011/10/02 09:22:45 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{FFDF69FD-A1A2-4597-9BE6-624D7FBBBD66}
[2011/10/02 01:27:42 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{19624B99-6F38-4F02-B2EF-7057EB5A73D7}
[2011/10/02 01:27:27 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3D386602-E9EB-4AB3-95E9-74A244C37DB8}
[2011/09/30 23:37:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{A3F1EF7D-F34D-4ED6-BF7D-CDC918EC807D}
[2011/09/30 23:37:21 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{AE137062-7C2E-4FA7-A84A-321268BD7ADC}
[2011/09/30 17:10:47 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{5E46E111-797D-4E69-9EC8-08EA31AC5B6D}
[2011/09/30 17:10:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{29B27ABE-7DB1-48ED-B6DC-99DECE9BAD3F}
[2011/09/29 22:42:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{43A035D4-9C72-4911-81FB-57B3CC34FC0E}
[2011/09/29 22:41:58 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{AF41CB35-14A0-4306-8B99-98BEB0D0DCDA}
[2011/09/29 19:52:34 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B102AF05-275E-44A6-AFB4-1F266C676942}
[2011/09/29 19:52:23 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{36AACB2E-F1AA-47A0-AED5-E07AD991421D}
[2011/09/29 19:06:09 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{19B00C8D-8C16-4852-B137-455C41C43471}
[2011/09/29 19:05:54 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1283ED28-CCFB-4711-99BF-2590044330E8}
[2011/09/29 17:37:54 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{14E47B2E-7D3C-4890-82A2-56A8B5599331}
[2011/09/29 17:37:43 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{0AD155AF-F921-48A1-AB9B-1A396526B519}
[2011/09/28 23:07:33 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{BC989353-4FB6-4CE5-89D6-4D1FA26B117C}
[2011/09/28 23:07:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{282977E4-36B8-4D20-BA65-64A461AC2C64}
[2011/09/28 19:46:09 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{0D571F3A-9E02-49F5-A84A-78B41427F0B2}
[2011/09/28 19:45:58 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1CDC7CDF-9D81-480E-B5DA-572E63F483C7}
[2011/09/28 17:30:04 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{1E5985BD-D085-4814-AD21-5190C6DE136D}
[2011/09/28 17:29:52 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E21E2D1F-362F-4755-9EB6-5681DE8A83B3}
[2011/09/28 13:18:39 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{EDF9A3E2-CA1A-42E8-B8EB-7A3690F8C36B}
[2011/09/28 13:18:27 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B01701D0-CA8E-4E0C-8890-36F52E419194}
[2011/09/28 09:59:12 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E39A22FE-3F8A-4F16-91F6-920C865D59A1}
[2011/09/28 09:58:59 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{C78C8950-6AA1-4AF5-8375-FC83B5DE831B}
[2011/09/27 23:23:08 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{B349EB25-6390-43AD-ABF8-323CB1A93D7C}
[2011/09/27 23:22:55 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{F42CF7C5-F652-448C-B71E-2A4DFE6FFB4B}
[2011/09/27 22:50:10 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{8EA93AF7-AF53-41BD-9372-DF4AEBA42B70}
[2011/09/27 22:49:56 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{621DF72B-7805-48F9-AA7C-A66A12A0AC02}
[2011/09/27 17:17:57 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{3640437C-77BC-4401-B061-B34A6867FE5E}
[2011/09/27 17:17:44 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{C4F998F7-A4FD-494F-8ACB-71D824962422}
[2011/09/27 08:52:35 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{75401963-F1DD-45F8-85AB-B53FF95B1671}
[2011/09/27 08:52:25 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{E0E8CC3D-FAA7-4F94-A4C0-07B49555FA21}
[2011/09/26 22:54:56 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{60FEE69A-0F05-4A25-A5D1-B300DAFED605}
[2011/09/26 22:54:42 | 000,000,000 | ---D | C] -- C:\Users\Sunny\AppData\Local\{6E5FB1E5-BD5B-495D-8500-3CABFB9E9D1A}
[4 C:\Users\Sunny\Desktop\*.tmp files -> C:\Users\Sunny\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/26 17:33:37 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Sunny\Desktop\OTL.exe
[2011/10/26 17:16:56 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/26 17:16:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/10/26 12:54:14 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/26 12:54:14 | 000,013,872 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/26 12:49:29 | 000,726,316 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/26 12:49:29 | 000,624,178 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/10/26 12:49:29 | 000,106,522 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/10/26 12:45:30 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/26 10:05:07 | 547,086,805 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/10/25 19:31:32 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 19:31:07 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Sunny\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/21 02:13:29 | 000,036,096 | ---- | M] () -- C:\Users\Sunny\Documents\history review.rtf
[2011/10/20 19:11:27 | 000,000,162 | -H-- | M] () -- C:\Users\Sunny\Desktop\~$er assignment topics.rtf
[2011/10/18 23:42:58 | 000,031,014 | ---- | M] () -- C:\Users\Sunny\Desktop\beer assignment topics.rtf
[2011/10/18 17:56:15 | 000,000,162 | -H-- | M] () -- C:\Users\Sunny\Desktop\~$ff 11.rtf
[2011/10/17 15:20:53 | 000,000,162 | -H-- | M] () -- C:\Users\Sunny\Documents\~$story review.rtf
[2011/10/17 13:34:34 | 000,272,667 | ---- | M] () -- C:\Users\Sunny\Documents\mySCE.mht
[2011/10/13 03:29:03 | 000,436,904 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/12 00:02:11 | 000,142,869 | ---- | M] () -- C:\test.xml
[2011/10/06 01:17:00 | 000,033,103 | ---- | M] () -- C:\Users\Sunny\Desktop\tsiss.rtf
[2011/10/04 00:38:59 | 000,001,778 | ---- | M] () -- C:\Users\Sunny\Documents\burn.rtf
[2011/10/04 00:21:12 | 000,001,564 | ---- | M] () -- C:\Users\Sunny\Documents\turner.rtf
[2011/10/03 19:24:23 | 000,000,238 | ---- | M] () -- C:\Users\Sunny\Documents\nw.rtf
[2011/10/03 01:54:40 | 000,000,394 | ---- | M] () -- C:\Users\Sunny\Desktop\hist review.rtf
[2011/10/02 01:17:11 | 000,000,580 | ---- | M] () -- C:\Users\Sunny\Documents\preamble.rtf
[2011/09/29 17:46:47 | 000,000,162 | -H-- | M] () -- C:\Users\Sunny\Desktop\~$cumentjjj.rtf
[2011/09/29 17:42:57 | 000,000,162 | -H-- | M] () -- C:\Users\Sunny\Desktop\~$tsiss.rtf
[2011/09/29 14:25:44 | 000,000,188 | ---- | M] () -- C:\Users\Sunny\Desktop\Documentjjj.rtf
[2011/09/29 02:14:15 | 000,034,858 | ---- | M] () -- C:\Users\Sunny\Documents\six glasses 3.rtf
[2011/09/29 02:12:18 | 000,033,698 | ---- | M] () -- C:\Users\Sunny\Desktop\six glasses 2.rtf
[2011/09/29 02:10:47 | 000,034,560 | ---- | M] () -- C:\Users\Sunny\Desktop\6 glasses.rtf
[2011/09/29 02:08:34 | 000,044,723 | ---- | M] () -- C:\Users\Sunny\Desktop\ff 11.rtf
[2011/09/29 02:07:16 | 000,037,279 | ---- | M] () -- C:\Users\Sunny\Documents\Document2.rtf
[2011/09/26 23:53:13 | 000,006,009 | ---- | M] () -- C:\Users\Sunny\Desktop\fs 10.rtf
[4 C:\Users\Sunny\Desktop\*.tmp files -> C:\Users\Sunny\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/25 19:31:32 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/20 19:11:27 | 000,000,162 | -H-- | C] () -- C:\Users\Sunny\Desktop\~$er assignment topics.rtf
[2011/10/18 19:11:07 | 000,031,014 | ---- | C] () -- C:\Users\Sunny\Desktop\beer assignment topics.rtf
[2011/10/18 17:56:15 | 000,000,162 | -H-- | C] () -- C:\Users\Sunny\Desktop\~$ff 11.rtf
[2011/10/17 15:20:53 | 000,000,162 | -H-- | C] () -- C:\Users\Sunny\Documents\~$story review.rtf
[2011/10/17 13:34:31 | 000,272,667 | ---- | C] () -- C:\Users\Sunny\Documents\mySCE.mht
[2011/10/17 12:42:21 | 000,036,096 | ---- | C] () -- C:\Users\Sunny\Documents\history review.rtf
[2011/10/04 00:38:59 | 000,001,778 | ---- | C] () -- C:\Users\Sunny\Documents\burn.rtf
[2011/10/04 00:21:12 | 000,001,564 | ---- | C] () -- C:\Users\Sunny\Documents\turner.rtf
[2011/10/03 19:24:23 | 000,000,238 | ---- | C] () -- C:\Users\Sunny\Documents\nw.rtf
[2011/10/03 01:54:40 | 000,000,394 | ---- | C] () -- C:\Users\Sunny\Desktop\hist review.rtf
[2011/10/02 01:17:11 | 000,000,580 | ---- | C] () -- C:\Users\Sunny\Documents\preamble.rtf
[2011/09/29 17:46:47 | 000,000,162 | -H-- | C] () -- C:\Users\Sunny\Desktop\~$cumentjjj.rtf
[2011/09/29 17:42:57 | 000,000,162 | -H-- | C] () -- C:\Users\Sunny\Desktop\~$tsiss.rtf
[2011/09/29 15:35:31 | 000,033,103 | ---- | C] () -- C:\Users\Sunny\Desktop\tsiss.rtf
[2011/09/29 14:25:44 | 000,000,188 | ---- | C] () -- C:\Users\Sunny\Desktop\Documentjjj.rtf
[2011/09/29 00:18:52 | 000,034,858 | ---- | C] () -- C:\Users\Sunny\Documents\six glasses 3.rtf
[2011/09/28 18:36:48 | 000,033,698 | ---- | C] () -- C:\Users\Sunny\Desktop\six glasses 2.rtf
[2011/09/28 00:46:51 | 000,034,560 | ---- | C] () -- C:\Users\Sunny\Desktop\6 glasses.rtf
[2011/09/27 00:53:01 | 000,044,723 | ---- | C] () -- C:\Users\Sunny\Desktop\ff 11.rtf
[2011/09/26 23:53:12 | 000,006,009 | ---- | C] () -- C:\Users\Sunny\Desktop\fs 10.rtf
[2011/09/13 17:53:31 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/09/13 17:53:31 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2011/09/13 17:53:31 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2011/09/13 17:53:31 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2011/09/13 17:53:31 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2011/09/13 17:53:31 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2011/09/13 17:53:31 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2011/09/13 17:53:31 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2011/09/13 17:53:31 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2011/09/13 17:53:31 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/09/13 17:53:31 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/09/13 17:53:31 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/09/13 17:53:31 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/09/13 17:53:31 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/09/13 17:53:31 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/09/13 17:53:31 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2011/09/13 17:46:03 | 000,000,045 | ---- | C] () -- C:\Windows\ENX420.ini
[2011/03/02 03:07:09 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/03/02 02:55:28 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblup.dat
[2011/01/24 01:20:34 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/01/24 01:20:33 | 000,960,940 | ---- | C] () -- C:\Windows\SysWow64\igkrng600.bin
[2011/01/24 01:20:32 | 000,206,952 | ---- | C] () -- C:\Windows\SysWow64\igfcg600m.bin
[2011/01/24 01:20:32 | 000,145,804 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng600.bin
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 16:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 16:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 16:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/09/12 13:01:07 | 000,032,594 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



Extras:

OTL Extras logfile created on: 10/26/2011 5:35:35 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Sunny\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.91 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 37.76% Memory free
7.82 Gb Paging File | 4.51 Gb Available in Paging File | 57.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 449.66 Gb Total Space | 394.45 Gb Free Space | 87.72% Space Free | Partition Type: NTFS

Computer Name: SUNNY-VAIO | User Name: Sunny | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06921707-E9C9-FFE9-F4B8-7821B944BD43}" = ATI Catalyst Install Manager
"{0E543634-7E25-4B8F-8D5B-97880E5E5088}" = Bonjour
"{115B60D5-BBDB-490E-AF2E-064D37A3CE01}" = Media Gallery
"{133D3F07-D558-46CE-80E8-F4D75DBBAD63}" = PMB VAIO Edition Plug-in
"{18155797-EF2E-4699-9A16-FE787C4C10DB}" = iTunes
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86416022FF}" = Java™ 6 Update 22 (64-bit)
"{28EF7372-9087-4AC3-9B9F-D9751FCDF830}" = Intel® Wireless Display
"{3210754C-77FE-95CE-6E04-E00656FEFF3E}" = ccc-utility64
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5AFD1F5C-8FDA-413C-AF38-F1E7BD10D72F}" = VAIO Media plus
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8F473675-D702-45F9-8EBC-342B40C17BF5}" = Apple Mobile Device Support
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{AF162E20-417F-4946-A06D-65734984957F}" = Intel® PROSet/Wireless WiFi Software
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"EPSON NX420 Series" = EPSON NX420 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0131D7EF-65FF-478F-8ABD-5ABEE24EC8EF}" = VAIO Messenger
"{02A6644F-4446-5A7E-1F82-0FEC36A79747}" = CCC Help Chinese Traditional
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{045AC5CB-B50B-A42D-486C-035607CE4E02}" = CCC Help Russian
"{07441A52-E208-478A-92B7-5C337CA8C131}" = Remote Play with PlayStation®3
"{08234a0d-cf39-4dca-99f0-0c5cb496da81}" = Bing Bar
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{100E6F6F-9FF2-5EA3-C752-12925E97D7C6}" = CCC Help Czech
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18AEAABF-9D55-C71E-CA2A-7A8F565B60B5}" = Catalyst Control Center Localization All
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1B500D37-E7CF-480B-8054-8A563594EC4E}" = OOBE
"{1C5EC8F6-5C5F-421F-85BE-919B5D0CAD4C}" = Adobe Flash Player 10 Plugin
"{1CAC7A41-583B-4483-9FA5-3E5465AFF8C2}" = Microsoft Default Manager
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216022FF}" = Java™ 6 Update 22
"{26C7D8E1-CF57-11DF-BFD4-005056C00008}" = DVD Architect Studio 5.0
"{270380EB-8812-42E1-8289-53700DB840D2}" = PMB VAIO Edition Plug-in
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29754381-2AA2-BA82-3924-6C162D33188F}" = CCC Help Norwegian
"{29B2ABA9-1029-307F-680D-9BB08D2F9877}" = Catalyst Control Center Graphics Previews Common
"{2AD737CF-C65D-11DF-9EC6-005056C00008}" = Vegas Movie Studio HD Platinum 10.0
"{2B253F8F-CF57-11DF-8136-005056C00008}" = MSVCRT Redists
"{2B679DE7-F7C4-7A7C-A50E-AC9577CA1997}" = CCC Help Greek
"{2F02831F-3A63-CE5A-3280-64B9E702547D}" = CCC Help Finnish
"{2F194E4F-C65D-11DF-8754-005056C00008}" = MSVCRT Redists
"{31ABC808-794B-4710-B3E4-85F77784882E}" = VAIO Hardware Diagnostics
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{36C5BBF0-E5BF-4DE1-B684-7E90B0C93FB5}" = VAIO Care
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{4498C074-9CB4-29F1-7F95-E02277ED7151}" = CCC Help Italian
"{46D67DD0-762F-73E8-A437-AA143275351F}" = CCC Help Swedish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{547C9EB4-4CA6-402F-9D1B-8BD30DC71E44}" = VAIO Sample Contents
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5A92468F-3ED8-4F96-A9E1-4F176C80EC29}" = VAIO Quick Web Access
"{5BEE8F1F-BD32-4553-8107-500439E43BD7}" = VAIO Update
"{5DC1D4DA-FCE0-93A1-7673-D673362185B5}" = CCC Help German
"{5DDAFB4B-C52E-468A-9E23-3B0CEEB671BF}" = VAIO Transfer Support
"{61438020-DDD4-42FA-99A2-50225441980A}" = ArcSoft Magic-i Visual Effects 2
"{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}" = Bing Rewards Client Installer
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{653B99EF-A8B6-ED63-3A1A-1EC64166181D}" = CCC Help English
"{6763869C-757B-6259-DA08-7C20FBC879B6}" = PX Profile Update
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6871ACC0-CFFD-11DF-B16B-005056C00008}" = ACID Music Studio 8.0
"{6B4DC9ED-2BDC-C0AA-7C32-09EA3B179365}" = CCC Help Polish
"{6BF03C88-C06A-48DC-B9A1-FE72B24E5FA9}" = VAIO Media plus Opening Movie
"{6CE4BE4F-CFFD-11DF-90D4-005056C00008}" = MSVCRT Redists
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{734B6C6C-4740-476F-BB0C-F7AF469EDBB2}" = Remote Play with PlayStation 3
"{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}" = VAIO - Remote Keyboard
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77C4850C-3592-4A2F-B652-ACB77A1EF77C}" = Bing Bar Platform
"{780EB6CF-E477-7E9C-2A6C-7B57149C0567}" = Catalyst Control Center Profiles Mobile
"{783D34F3-B6D1-B5AF-1287-E4A401F018FB}" = CCC Help Danish
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7C80D30A-AC02-4E3F-B95D-29F0E4FF937B}" = VAIO Wireless Wizard
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" =
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82F09B1C-F602-4552-9C40-5BD5F8EAF750}" =
"{8356CB97-A48F-44CB-837A-A12838DC4669}" = PMB VAIO Edition Plug-in
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{853A4763-6643-4604-8D64-28BDD8925F4C}" = Apple Application Support
"{855DDD3C-131E-42A8-BCBD-F9581F80CACB}" =
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87036FD9-6382-CA10-7D13-C864107CCF80}" = Catalyst Control Center InstallProxy
"{884A242B-BE5C-4F9F-9177-F44156A5D081}" = VAIO Help and Support
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CD97250-D00C-11DF-9095-005056C00008}" = Sound Forge Audio Studio 10.0
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}" = VAIO Media plus
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{928B06E4-DDAA-476A-926A-641620326327}" = Microsoft Search Enhancement Pack
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{93334540-D00C-11DF-BA0C-005056C00008}" = MSVCRT Redists
"{935E8A15-356D-F80F-2502-13829978B354}" = CCC Help Portuguese
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{995845A2-5767-429D-8986-694050AE1F34}" = Remote Keyboard
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" =
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB9B331D-4C3E-0A79-B13B-6D7E50842D86}" = CCC Help Japanese
"{AC76BA86-1033-0000-BA7E-000000000004}" = Adobe Acrobat 9 Standard
"{AC76BA86-1033-0000-BA7E-000000000004}_941" = Adobe Acrobat 9.4.1 - CPSID_83708
"{AC76BA86-1033-0000-BA7E-000000000004}{AC76BA86-1033-0000-BA7E-000000000004}" = Adobe Acrobat 9 Standard
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.0
"{ACB94B9B-55C4-53E5-49D5-03564996376D}" = CCC Help Thai
"{AF7EC896-0327-AA13-BA68-7C3F8180CC0B}" = CCC Help Korean
"{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}" = PMB
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{BAB41627-7B50-0929-5DA1-6235FBE0B55F}" = CCC Help Spanish
"{C0568315-035E-1749-81C2-14F1D54EE4D0}" = ccc-core-static
"{C1197078-16DF-D1CA-D6C3-3F2B59303FDB}" = CCC Help Chinese Standard
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6E893E7-E5EA-4CD5-917C-5443E753FCBD}" = VAIO Manual
"{C7477742-DDB4-43E5-AC8D-0259E1E661B1}" =
"{C793AD32-2BB8-4CC4-ABD3-A1469C21593C}" = ArcSoft WebCam Companion 4
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D3142304-5883-4B37-8690-ADDB3D1D8B7B}" = VAIO Care
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DD88F979-FA58-41AC-980C-A6E1A82B61D9}" = VAIO - Media Gallery
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DED73293-74DC-E8CD-9689-A000870D8A2E}" = CCC Help Hungarian
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3BE5DF1-0D65-4774-904E-0192ABF29AF9}" = Sony Photo Go 1.0b
"{E50FC5DB-7CBD-407D-A46E-0C13E45BC386}" = Oasis2Service 1.0
"{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English
"{E906AF6E-7F85-A58D-3E07-D3EF31CD3A22}" = CCC Help Dutch
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Display Audio Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F84906ED-BB54-4889-B131-FED9C9056FC8}" = Intel® Wireless Display
"{F8B48758-410A-4B09-A734-C5DEA282C7C9}" = VAIO Data Restore Tool
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FC56115C-FEB4-14CD-1C38-C090ED6AF58A}" = CCC Help French
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF1FC66F-536F-46BD-98E3-D8DA127A810E}" = PMB VAIO Edition Guide
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Application Manager for VAIO" = Application Manager for VAIO
"Avira AntiVir Desktop" = Avira Premium Security Suite
"EPSON Scanner" = EPSON Scan
"InstallShield_{270380EB-8812-42E1-8289-53700DB840D2}" = VAIO - PMB VAIO Edition Plug-in
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{FF1FC66F-536F-46BD-98E3-D8DA127A810E}" = VAIO - PMB VAIO Edition Guide
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"splashtop" = VAIO Quick Web Access
"VAIO Messenger" = VAIO Messenger
"VAIO Satisfaction Survey.3.0" = VAIO Satisfaction Survey.
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Messenger" = Yahoo! Messenger

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/18/2011 8:58:51 PM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/19/2011 9:46:28 AM | Computer Name = Sunny-VAIO | Source = ATIeRecord | ID = 16398
Description = ATI EEU failed to post message to CCC

Error - 10/21/2011 10:45:12 AM | Computer Name = Sunny-VAIO | Source = Application Error | ID = 1000
Description = Faulting application name: iexplore.exe, version: 8.0.7600.16869,
time stamp: 0x4e4f21db Faulting module name: iertutil.dll, version: 8.0.7600.16869,
time stamp: 0x4e4f373d Exception code: 0xc0000005 Fault offset: 0x0015b49d Faulting
process id: 0xed8 Faulting application start time: 0x01cc8fffeea973ca Faulting application
path: C:\Program Files (x86)\Internet Explorer\iexplore.exe Faulting module path:
C:\Windows\syswow64\iertutil.dll Report Id: 478497fb-fbf3-11e0-83af-8e33b649dbcb

[ System Events ]
Error - 9/14/2011 10:49:15 AM | Computer Name = Sunny-VAIO | Source = BugCheck | ID = 1001
Description =

Error - 9/15/2011 12:13:40 AM | Computer Name = Sunny-VAIO | Source = BROWSER | ID = 8032
Description =

Error - 9/15/2011 11:58:31 AM | Computer Name = Sunny-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:28:33 AM on ?9/?15/?2011 was unexpected.

Error - 9/15/2011 11:58:43 AM | Computer Name = Sunny-VAIO | Source = BugCheck | ID = 1001
Description =

Error - 9/15/2011 6:31:07 PM | Computer Name = Sunny-VAIO | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
will not be used. The driver has been unloaded.

Error - 9/16/2011 12:02:03 AM | Computer Name = Sunny-VAIO | Source = BROWSER | ID = 8032
Description =

Error - 9/16/2011 12:13:17 AM | Computer Name = Sunny-VAIO | Source = bowser | ID = 8003
Description =

Error - 9/16/2011 8:02:09 PM | Computer Name = Sunny-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 1:01:24 AM on ?9/?16/?2011 was unexpected.

Error - 9/16/2011 8:02:22 PM | Computer Name = Sunny-VAIO | Source = BugCheck | ID = 1001
Description =

Error - 9/16/2011 11:02:38 PM | Computer Name = Sunny-VAIO | Source = BTHUSB | ID = 327697
Description = The local Bluetooth adapter has failed in an undetermined manner and
will not be used. The driver has been unloaded.


< End of report >

Thanks
  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,790 posts
  • MVP
If one of the following will not run then just skip to the next one then go back and try the things that wouldn't run again after finishing the others.

Malwarebytes' Anti-Malware
:!: If you have a previous version of MalwareBytes', remove it via Add or Remove Programs and download a fresh copy. :!:

http://www.malwarebytes.org/mbam.php

SAVE Malwarebytes' Anti-Malware to your desktop.

Rightclick on Malwarebytes' Anti-Malware and select Run As Administrator and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.

* Once the program has loaded, select Perform Quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.

* Be sure that everything is checked, and click Remove Selected.

* When completed, a log will open in Notepad. Please save it to a convenient location.
* The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
* Post that log back here.



ComboFix

:!: It must be saved to your desktop, do not run it from your browser:!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.

A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then right click and Run as Administrator

If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.


Download aswMBR.exe ( 511KB ) to your desktop.
Right click aswMBR.exe and Run as Administrator

change the a-v scan to None.
uncheck trace disk IO calls
Click the "Scan" button to start scan
On completion of the scan (Note if the Fix button is enabled (not the FixMBR button) and tell me) click save log, save it to your desktop and post in your next reply

1. Double-click My Computer, and then right-click the hard disk that you want to check. C:
2. Click Properties, and then click Tools.
3. Under Error-checking, click Check Now. A dialog box that shows the Check disk options is displayed,
4. Check both boxes and then click Start.
You will receive the following message:
The disk check could not be performed because the disk check utility needs exclusive access to some Windows files on the disk. These files can be accessed by restarting Windows. Do you want to schedule the disk check to occur the next time you restart the computer?
Click Yes to schedule the disk check, but don't restart yet.

Right click on (My) Computer and select Manage (Continue) Then the Event Viewer. Next select Windows Logs. Right click on System and Clear Log, Clear. Repeat for Application. Reboot. The disk check will run and will probably take an hour or more to finish.


Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator. Then type (with an Enter after each line).

sfc /scannow

(SPACE after sfc. This will check your critical system files. If it asks for a CD and you don't have one or it doesn't like your CD just tell it to SKIP.)

sigverif

Press Start in the new window. This will check your drivers. If you just get a few when it finishes tell me what they are. If you get a lot just look for those with newish dates (since about the time the problem started.)


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe and Run AS Administrator
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Ron
  • 0

#3
shindouhikaru888

shindouhikaru888

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
nevermind i got my previous question fixed. What do you mean by "then repeat but select Application." Thanks.

Edited by shindouhikaru888, 27 October 2011 - 12:16 AM.

  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,790 posts
  • MVP
They may have changed the program since I last downloaded it. Just go ahead and let it do the scan.

Ron
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP