Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Constant BSoD


  • Please log in to reply

#1
Lucky Dearly

Lucky Dearly

    Member

  • Member
  • PipPipPip
  • 299 posts
Hey everybody, I've got a bit of a problem as of late. My pc has been crashing alot lately with blue screens of death. I dunno what to do

I'm posting an OTL log incase it's a virus or malware. I hope you guys can help me out

OTL logfile created on: 6/28/2012 1:03:23 AM - Run 5
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\nwofan\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 54.00% Memory free
6.00 Gb Paging File | 4.00 Gb Available in Paging File | 67.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.46 Gb Total Space | 29.37 Gb Free Space | 10.25% Space Free | Partition Type: NTFS
Drive D: | 11.63 Gb Total Space | 1.59 Gb Free Space | 13.64% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 614.91 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
I: Drive not present or media not loaded
Drive K: | 297.44 Gb Total Space | 24.88 Gb Free Space | 8.36% Space Free | Partition Type: NTFS

Computer Name: GAMERPC
Current User Name: nwofan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2012/06/19 12:35:50 | 000,529,232 | ---- | M] (Valve Corporation) -- C:\Program Files\Common Files\Steam\SteamService.exe
PRC - [2012/06/06 21:33:42 | 001,564,872 | ---- | M] (Ask) -- C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2012/05/30 10:18:07 | 004,331,392 | ---- | M] (AOL Inc.) -- C:\Program Files\AIM7\aim.exe
PRC - [2012/05/29 10:37:22 | 025,249,400 | ---- | M] (ooVoo LLC) -- C:\Program Files\ooVoo\ooVoo.exe
PRC - [2012/05/24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2012/04/27 19:05:40 | 000,613,208 | ---- | M] (IObit) -- C:\Program Files\IObit\Game Booster 3\gbtray.exe
PRC - [2012/04/19 08:50:10 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2012/04/19 08:50:10 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/04/03 22:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/03/14 17:38:14 | 000,913,752 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe
PRC - [2012/03/08 17:44:02 | 000,025,456 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2012/03/06 18:39:50 | 000,574,296 | ---- | M] (IObit) -- C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe
PRC - [2012/02/23 13:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
PRC - [2012/02/22 20:49:58 | 006,591,800 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2012/02/20 22:28:38 | 000,013,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe
PRC - [2012/02/01 19:07:56 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files\Steam\Steam.exe
PRC - [2011/12/19 17:32:26 | 000,394,672 | ---- | M] (Eastman Kodak Company) -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe
PRC - [2011/11/27 22:59:23 | 000,246,624 | ---- | M] () -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe
PRC - [2011/10/15 01:53:00 | 001,328,960 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011/08/10 12:35:20 | 000,227,184 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe
PRC - [2011/08/10 11:53:46 | 000,094,880 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2011/08/08 15:11:06 | 000,681,840 | ---- | M] () -- C:\Program Files\Motorola\MotoHelper\MotoHelperAgent.exe
PRC - [2011/07/28 16:08:12 | 001,259,376 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/07/11 14:47:06 | 000,074,752 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Winamp\winampa.exe
PRC - [2011/06/23 21:22:20 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2011/06/17 10:33:04 | 000,272,528 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\3.0.207\SSScheduler.exe
PRC - [2011/06/16 18:53:22 | 002,510,848 | ---- | M] (Eastman Kodak Company) -- C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe
PRC - [2011/05/03 14:50:59 | 000,123,320 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe
PRC - [2011/03/28 20:31:16 | 000,193,920 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2011/03/28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) -- C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/11/20 05:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 05:17:30 | 003,179,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sppsvc.exe
PRC - [2010/11/05 16:11:52 | 000,081,920 | R--- | M] (Nero AG) -- C:\Program Files\Motorola Media Link\NServiceEntry.exe
PRC - [2010/08/01 14:45:22 | 004,950,936 | ---- | M] (Pando Networks) -- C:\Program Files\Pando Networks\Pando\pando.exe
PRC - [2010/06/02 19:42:33 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\nwofan\Desktop\OTL.exe
PRC - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2010/03/08 00:27:49 | 000,041,800 | ---- | M] (AOL Inc.) -- C:\Program Files\Common Files\AOL\1241069855\ee\aolsoftware.exe
PRC - [2009/10/20 14:50:34 | 000,128,296 | ---- | M] (CyberLink Corp.) -- c:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
PRC - [2009/08/28 13:53:00 | 000,210,216 | ---- | M] (CyberLink) -- c:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/02/23 20:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files\MagicDisc\MagicDisc.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/02/19 09:12:18 | 000,537,256 | ---- | M] ( ) -- C:\Windows\System32\lxbkcoms.exe
PRC - [2006/10/23 05:50:35 | 000,046,640 | R--- | M] (AOL LLC) -- C:\Program Files\Common Files\AOL\acs\AOLacsd.exe


========== Modules (SafeList) ==========

MOD - [2011/08/11 16:37:26 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2011/07/15 21:27:30 | 000,290,816 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\KernelBase.dll
MOD - [2010/11/20 05:21:26 | 000,100,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sspicli.dll
MOD - [2010/11/20 05:21:04 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\samcli.dll
MOD - [2010/11/20 05:20:29 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\netutils.dll
MOD - [2010/11/20 05:18:12 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cfgmgr32.dll
MOD - [2010/11/20 04:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2010/06/02 19:42:33 | 000,571,904 | ---- | M] (OldTimer Tools) -- C:\Users\nwofan\Desktop\OTL.exe
MOD - [2009/07/13 18:16:13 | 000,092,160 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\sechost.dll
MOD - [2009/07/13 18:16:12 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\profapi.dll
MOD - [2009/07/13 18:15:13 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dwmapi.dll
MOD - [2009/07/13 18:15:11 | 000,064,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\devobj.dll
MOD - [2009/07/13 18:15:07 | 000,036,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cryptbase.dll
MOD - [2009/07/13 18:14:10 | 000,095,232 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2012/06/19 12:35:50 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/05/24 13:28:56 | 000,055,184 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2012/05/02 00:44:04 | 000,129,976 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/04/03 22:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/03/14 17:38:14 | 000,913,752 | ---- | M] (IObit) [Auto | Running] -- C:\Program Files\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
SRV - [2012/03/08 18:32:24 | 001,492,840 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe -- (fsssvc)
SRV - [2011/12/19 17:32:26 | 000,394,672 | ---- | M] (Eastman Kodak Company) [Auto | Running] -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011/11/28 19:00:02 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/11/27 22:59:23 | 000,246,624 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ToolbarUpdater.exe -- (vToolbarUpdater)
SRV - [2011/08/15 11:02:12 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2011/08/10 12:35:20 | 000,227,184 | ---- | M] () [Auto | Running] -- C:\Program Files\Motorola\MotoHelper\MotoHelperService.exe -- (MotoHelper)
SRV - [2011/08/10 11:53:46 | 000,094,880 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2011/06/17 10:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService)
SRV - [2011/05/03 14:56:02 | 000,126,392 | R--- | M] (Symantec Corporation) [Unknown | Stopped] -- C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe -- (PCCUJobMgr)
SRV - [2011/05/03 14:50:59 | 000,123,320 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\SymcPCCULaunchSvc.exe -- (Norton PC Checkup Application Launcher)
SRV - [2011/03/28 20:31:14 | 001,713,536 | ---- | M] (Microsoft Corp.) [Auto | Running] -- C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE -- (wlidsvc)
SRV - [2011/02/18 23:30:54 | 000,805,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\FntCache.dll -- (FontCache)
SRV - [2010/11/20 05:21:33 | 000,119,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpo.dll -- (Power)
SRV - [2010/11/20 05:21:24 | 000,053,760 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sppuinotify.dll -- (sppuinotify)
SRV - [2010/11/20 05:20:57 | 000,165,376 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\provsvc.dll -- (HomeGroupProvider)
SRV - [2010/11/20 05:19:28 | 000,194,560 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ListSvc.dll -- (HomeGroupListener)
SRV - [2010/11/20 05:18:30 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/20 05:18:06 | 000,088,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AxInstSv.dll -- (AxInstSV) ActiveX Installer (AxInstSV)
SRV - [2010/11/20 05:17:30 | 003,179,520 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\sppsvc.exe -- (sppsvc)
SRV - [2010/11/05 16:11:52 | 000,081,920 | R--- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Motorola Media Link\NServiceEntry.exe -- (DeviceMonitorService)
SRV - [2010/10/12 10:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/09/22 17:33:04 | 000,051,040 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2010/07/25 03:00:58 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/05/14 11:00:26 | 000,249,136 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe -- (SeaPort)
SRV - [2010/03/18 16:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpActivator)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetPipeActivator)
SRV - [2010/03/18 13:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetMsmqActivator)
SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2010/02/24 16:42:56 | 000,386,424 | ---- | M] (SupportSoft, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\supportsoft\bin\ssrc.exe -- (SupportSoft RemoteAssist)
SRV - [2009/07/13 18:16:21 | 000,185,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wwansvc.dll -- (WwanSvc)
SRV - [2009/07/13 18:16:17 | 000,151,552 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wbiosrvc.dll -- (WbioSrvc)
SRV - [2009/07/13 18:16:16 | 000,037,376 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\themeservice.dll -- (Themes)
SRV - [2009/07/13 18:16:13 | 000,043,520 | ---- | M] (Microsoft Corporation) [Unknown | Running] -- C:\Windows\System32\RpcEpMap.dll -- (RpcEptMapper)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (PNRPsvc)
SRV - [2009/07/13 18:16:12 | 000,269,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\pnrpsvc.dll -- (p2pimsvc)
SRV - [2009/07/13 18:16:12 | 000,020,480 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\pnrpauto.dll -- (PNRPAutoReg)
SRV - [2009/07/13 18:15:10 | 000,218,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\defragsvc.dll -- (defragsvc)
SRV - [2009/07/13 18:14:59 | 000,076,800 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\bdesvc.dll -- (BDESVC)
SRV - [2009/07/13 18:14:53 | 000,027,648 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\appidsvc.dll -- (AppIDSvc)
SRV - [2009/04/29 03:21:04 | 000,410,624 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\System32\XAudio32.dll -- (HsfXAudioService)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/02/19 09:12:18 | 000,537,256 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxbkcoms.exe -- (lxbk_device)
SRV - [2006/10/23 05:50:35 | 000,046,640 | R--- | M] (AOL LLC) [Auto | Running] -- C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe -- (AOL ACS)


========== Driver Services (SafeList) ==========

DRV - [2012/04/28 11:58:06 | 000,049,240 | ---- | M] (NCH Software) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stdriver32.sys -- (stdriver)
DRV - [2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/03/08 18:32:24 | 000,039,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV - [2012/02/22 03:34:36 | 000,022,400 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcaudrv.sys -- (mcaudrv_simple)
DRV - [2012/01/10 23:11:20 | 000,032,000 | ---- | M] (ManyCam LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcvidrv.sys -- (ManyCam)
DRV - [2011/10/15 01:53:00 | 010,327,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/04/04 14:55:38 | 000,020,480 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgp.sys -- (motccgp)
DRV - [2011/03/31 14:53:22 | 000,024,064 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2011/03/10 22:39:00 | 000,143,744 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2011/03/10 22:39:00 | 000,117,120 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2011/03/10 22:38:51 | 000,332,160 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\iaStorV.sys -- (iaStorV)
DRV - [2011/03/10 22:38:37 | 000,080,256 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\amdsata.sys -- (amdsata)
DRV - [2011/03/10 22:38:37 | 000,022,400 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\amdxata.sys -- (amdxata)
DRV - [2011/02/07 17:36:00 | 000,011,008 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motusbdevice.sys -- (motusbdevice)
DRV - [2011/01/01 10:12:18 | 000,081,168 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV - [2010/11/20 05:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 05:30:14 | 000,160,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vhdmp.sys -- (vhdmp)
DRV - [2010/11/20 05:30:10 | 000,173,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\rdyboost.sys -- (rdyboost)
DRV - [2010/11/20 05:29:53 | 000,014,208 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\hwpolicy.sys -- (hwpolicy)
DRV - [2010/11/20 03:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 03:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 03:07:39 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ndproxy.svs -- (NDProxy)
DRV - [2010/11/20 03:01:12 | 000,164,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\system32\drivers\1394ohci.sys -- (1394ohci)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:50:21 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\system32\drivers\CompositeBus.sys -- (CompositeBus)
DRV - [2010/11/20 02:29:49 | 000,050,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\appid.sys -- (AppID)
DRV - [2010/11/20 02:24:56 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | Unknown | Stopped] -- C:\Windows\System32\drivers\scfilter.sys -- (scfilter)
DRV - [2010/11/20 02:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/11/20 01:47:55 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\acpipmi.sys -- (AcpiPmi)
DRV - [2010/11/01 06:08:46 | 000,014,416 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys -- (WinRing0_1_2_0)
DRV - [2010/08/19 19:24:34 | 000,061,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\xusb21.sys -- (xusb21)
DRV - [2010/07/29 00:25:02 | 000,025,112 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ivusb.sys -- (ivusb)
DRV - [2010/04/01 14:31:50 | 000,023,424 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Motousbnet.sys -- (Motousbnet)
DRV - [2009/10/20 12:08:44 | 000,037,248 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmsflt.sys -- (swmsflt)
DRV - [2009/10/01 22:03:40 | 000,131,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/08/04 10:48:20 | 002,744,800 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVHDA.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/08/04 10:40:04 | 000,226,816 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SWNC5E00.sys -- (SWNC5E00) Sierra Wireless MUX NDIS Driver (#00)
DRV - [2009/08/04 10:39:02 | 000,157,440 | ---- | M] (Sierra Wireless Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\swmx00.sys -- (SWMX00) Sierra Wireless USB MUX Driver (#00)
DRV - [2009/07/30 17:12:54 | 000,287,392 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmf6232.sys -- (NVNET)
DRV - [2009/07/13 18:26:21 | 000,015,952 | ---- | M] (CMD Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2009/07/13 18:26:17 | 000,297,552 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpahci.sys -- (adpahci)
DRV - [2009/07/13 18:26:15 | 000,422,976 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adp94xx.sys -- (adp94xx)
DRV - [2009/07/13 18:26:15 | 000,159,312 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV - [2009/07/13 18:26:15 | 000,146,512 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\adpu320.sys -- (adpu320)
DRV - [2009/07/13 18:26:15 | 000,086,608 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arcsas.sys -- (arcsas)
DRV - [2009/07/13 18:26:15 | 000,076,368 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\arc.sys -- (arc)
DRV - [2009/07/13 18:26:15 | 000,014,400 | ---- | M] (Acer Laboratories Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2009/07/13 18:20:44 | 000,044,624 | ---- | M] (IBM Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\nfrd960.sys -- (nfrd960)
DRV - [2009/07/13 18:20:37 | 000,089,168 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas.sys -- (LSI_SAS)
DRV - [2009/07/13 18:20:36 | 000,235,584 | ---- | M] (LSI Corporation, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MegaSR.sys -- (MegaSR)
DRV - [2009/07/13 18:20:36 | 000,133,200 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\ksecpkg.sys -- (KSecPkg)
DRV - [2009/07/13 18:20:36 | 000,096,848 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2009/07/13 18:20:36 | 000,095,824 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_fc.sys -- (LSI_FC)
DRV - [2009/07/13 18:20:36 | 000,054,864 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV - [2009/07/13 18:20:36 | 000,041,040 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\iirsp.sys -- (iirsp)
DRV - [2009/07/13 18:20:36 | 000,030,800 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\megasas.sys -- (megasas)
DRV - [2009/07/13 18:20:28 | 000,453,712 | ---- | M] (Emulex) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\elxstor.sys -- (elxstor)
DRV - [2009/07/13 18:20:28 | 000,070,720 | ---- | M] (Adaptec, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\djsvs.sys -- (aic78xx)
DRV - [2009/07/13 18:20:28 | 000,067,152 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\HpSAMD.sys -- (HpSAMD)
DRV - [2009/07/13 18:20:28 | 000,046,160 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\fsdepends.sys -- (FsDepends)
DRV - [2009/07/13 18:19:11 | 000,141,904 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vsmraid.sys -- (vsmraid)
DRV - [2009/07/13 18:19:10 | 000,032,832 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vdrvroot.sys -- (vdrvroot)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/07/13 18:19:10 | 000,016,976 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2009/07/13 18:19:04 | 001,383,488 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql2300.sys -- (ql2300)
DRV - [2009/07/13 18:19:04 | 000,106,064 | ---- | M] (QLogic Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\ql40xx.sys -- (ql40xx)
DRV - [2009/07/13 18:19:04 | 000,077,888 | ---- | M] (Silicon Integrated Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\sisraid4.sys -- (SiSRaid4)
DRV - [2009/07/13 18:19:04 | 000,043,088 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\pcw.sys -- (pcw)
DRV - [2009/07/13 18:19:04 | 000,040,016 | ---- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\SiSRaid2.sys -- (SiSRaid2)
DRV - [2009/07/13 18:19:04 | 000,021,072 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV - [2009/07/13 18:17:54 | 000,369,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\cng.sys -- (CNG)
DRV - [2009/07/13 17:57:25 | 000,272,128 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\Brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2009/07/13 17:02:41 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rdpbus.sys -- (rdpbus)
DRV - [2009/07/13 17:01:41 | 000,007,168 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\RDPREFMP.sys -- (RDPREFMP)
DRV - [2009/07/13 16:55:00 | 000,049,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\agilevpn.sys -- (RasAgileVpn) WAN Miniport (IKEv2)
DRV - [2009/07/13 16:53:51 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\wfplwf.sys -- (WfpLwf)
DRV - [2009/07/13 16:52:44 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ndiscap.sys -- (NdisCap)
DRV - [2009/07/13 16:52:02 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifibus.sys -- (vwifibus)
DRV - [2009/07/13 16:51:35 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\umpass.sys -- (UmPass)
DRV - [2009/07/13 16:51:08 | 000,004,096 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mshidkmdf.sys -- (mshidkmdf)
DRV - [2009/07/13 16:46:55 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\MTConfig.sys -- (MTConfig)
DRV - [2009/07/13 16:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\serial.sys -- (Serial)
DRV - [2009/07/13 16:24:05 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\discache.sys -- (discache)
DRV - [2009/07/13 16:19:21 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\HidBatt.sys -- (HidBatt)
DRV - [2009/07/13 16:11:04 | 000,052,736 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\amdppm.sys -- (AmdPPM)
DRV - [2009/07/13 15:54:14 | 000,026,624 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 15:53:33 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbMdm.sys -- (BrUsbMdm)
DRV - [2009/07/13 15:53:33 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrUsbSer.sys -- (BrUsbSer)
DRV - [2009/07/13 15:53:32 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BrSerWdm.sys -- (BrSerWdm)
DRV - [2009/07/13 15:53:28 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltLo.sys -- (BrFiltLo)
DRV - [2009/07/13 15:53:28 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\BrFiltUp.sys -- (BrFiltUp)
DRV - [2009/07/13 15:13:47 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTBS23.SYS -- (VSTHWBS2)
DRV - [2009/07/13 15:13:46 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VSTDPV3.SYS -- (VST_DPV)
DRV - [2009/07/13 15:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/07/13 15:02:49 | 000,229,888 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\b57nd60x.sys -- (b57nd60x)
DRV - [2009/07/13 15:02:48 | 003,100,160 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\evbdx.sys -- (ebdrv)
DRV - [2009/07/13 15:02:48 | 000,430,080 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\bxvbdx.sys -- (b06bdrv)
DRV - [2009/07/10 13:01:06 | 000,025,856 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motoandroid.sys -- (motandroidusb)
DRV - [2009/06/22 22:34:38 | 000,212,000 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32)
DRV - [2009/05/22 16:08:32 | 000,029,696 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VClone.sys -- (VClone)
DRV - [2009/04/29 03:20:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio32.sys -- (XAudio)
DRV - [2009/02/24 19:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009/02/17 10:11:30 | 000,024,232 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV - [2009/02/13 05:58:30 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2009/02/13 05:57:28 | 000,661,504 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2009/02/13 05:56:32 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2009/01/29 17:18:00 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2009/01/29 17:11:20 | 000,006,016 | ---- | M] (Motorola Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motfilt.sys -- (BTCFilterService)
DRV - [2008/09/09 17:58:08 | 000,020,640 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Program Files\PC-Doctor for Windows\pcd5srvc.pkms -- (PCD5SRVC{BD6912E3-AC9D80E8-05040000})
DRV - [2008/08/14 08:57:42 | 000,074,720 | ---- | M] (Adobe Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\adfs.sys -- (adfs)
DRV - [2008/07/21 09:12:50 | 000,133,152 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008/05/22 02:39:34 | 000,015,360 | ---- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/05/06 17:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2007/11/02 15:51:30 | 000,006,400 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motswch.sys -- (MotoSwitchService)
DRV - [2007/07/03 15:05:00 | 000,162,944 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RT25USBAP.SYS -- (RT25USBAP)
DRV - [2007/02/15 17:57:04 | 000,034,760 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
DRV - [2007/02/08 06:45:14 | 000,029,184 | ---- | M] (Thesycon GmbH, Germany) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dsiarhwprog.sys -- (dsiarhwprog)
DRV - [2006/12/24 06:15:18 | 000,027,904 | ---- | M] (Compuware Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\xPADFL02.sys -- (XPADFL02)
DRV - [2006/11/29 15:24:57 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw) WAN Miniport (ATW)
DRV - [2005/12/12 10:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2005/08/17 07:47:48 | 000,073,696 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdserd.sys -- (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM)
DRV - [2005/08/17 07:46:26 | 000,093,872 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2005/08/17 07:46:20 | 000,008,272 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2005/08/17 07:45:00 | 000,058,352 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-tyc8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.wwe.com/
IE - HKCU\..\URLSearchHook: {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
IE - HKCU\..\URLSearchHook: {6f895323-a0d1-4844-b5d1-89e3962fa2b2} - C:\Program Files\searchresults7\searchresultsDx.dll (Ask.com)
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultthis.engineName: "IncrediMail MediaBar 4 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.aol.co...rud=15-06-2012"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-tyc8"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-tyc8"
FF - prefs.js..browser.search.param.yahoo-type: ""
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.wwe.com"
FF - prefs.js..keyword.URL: "http://www.ask.com/w...YYYYY^YY^US&q="


FF - HKLM\software\mozilla\Firefox\Extensions\\{6E19037A-12E3-4295-8915-ED48BC341614}: C:\Program Files\RelevantKnowledge
FF - HKLM\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2011/12/20 20:01:43 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011/12/25 14:36:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 12.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/12 17:13:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 12.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/13 16:52:54 | 000,000,000 | ---D | M]

[2010/07/24 21:13:09 | 000,000,000 | ---D | M] -- C:\Users\nwofan\AppData\Roaming\Mozilla\Extensions
[2012/06/21 23:32:19 | 000,000,000 | ---D | M] -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions
[2010/07/24 21:13:10 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/05/21 20:04:23 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/21 23:32:19 | 000,000,000 | ---D | M] (Search Results Toolbar) -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\{6f895323-a0d1-4844-b5d1-89e3962fa2b2}
[2012/06/13 02:03:11 | 000,000,000 | ---D | M] (IncrediMail MediaBar 4 Community Toolbar) -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\{90eee664-34b1-422a-a782-779af65cdf6d}
[2012/06/15 01:14:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\{c2f863cd-0429-48c7-bb54-db756a951760}
[2012/03/16 02:23:48 | 000,000,000 | ---D | M] -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\[email protected]
[2012/06/27 23:03:46 | 000,000,000 | ---D | M] -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\extensions\[email protected]
[2010/09/18 13:20:13 | 000,001,490 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\AIM Search.xml
[2012/06/15 01:16:12 | 000,002,562 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\aol-search-1.xml
[2010/09/23 00:04:58 | 000,002,342 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\aol-search.xml
[2011/07/13 17:56:04 | 000,002,354 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\aol-web-search.xml
[2012/06/27 23:03:50 | 000,002,577 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\askcom.xml
[2011/02/09 20:45:52 | 000,001,919 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\bing-zugo.xml
[2011/08/29 17:51:44 | 000,000,947 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\conduit.xml
[2010/08/09 19:14:28 | 000,002,059 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\daemon-search.xml
[2012/01/01 21:12:05 | 000,002,191 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\MyStart Search.xml
[2011/12/11 22:30:57 | 000,001,210 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Mozilla\Firefox\Profiles\hehyz5rf.default\searchplugins\search.xml
[2012/06/18 05:25:55 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/05 00:57:06 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/05/02 00:44:05 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2008/11/11 00:38:54 | 000,663,552 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
[2009/11/19 15:16:28 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npCouponPrinter.dll
[2012/03/04 00:42:50 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/11/19 15:16:29 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npMozCouponPrinter.dll
[2011/07/11 14:48:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
[2011/01/15 04:46:37 | 000,002,242 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\AOL Search.xml
[2012/06/21 23:32:40 | 000,002,275 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\ask.xml
[2012/03/16 02:23:05 | 000,002,288 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml
[2012/05/02 00:44:02 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
[2011/09/19 19:21:58 | 000,002,024 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml
[2012/05/02 00:44:02 | 000,002,040 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2011/11/23 20:05:46 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Search Results Toolbar) - {6f895323-a0d1-4844-b5d1-89e3962fa2b2} - C:\Program Files\searchresults7\searchresultsDx.dll (Ask.com)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Windows Live Messenger Companion Helper) - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.6406.1642\swg.dll (Google Inc.)
O2 - BHO: (AOL Messaging Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files\Google\Chrome Frame\Application\20.0.1132.43\npchrome_frame.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (AOL Messaging Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKLM\..\Toolbar: (Search Results Toolbar) - {6f895323-a0d1-4844-b5d1-89e3962fa2b2} - C:\Program Files\searchresults7\searchresultsDx.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AOL Messaging Toolbar) - {61539ECD-CC67-4437-A03C-9AACCBD14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS4ServiceManager] C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Conime] C:\Windows\System32\conime.exe File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1241069855\ee\aolsoftware.exe (AOL Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Recordpad] C:\Program Files\NCH Software\Recordpad\recordpad.exe (NCH Software)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe File not found
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKCU..\Run: [AIM] C:\Program Files\AIM7\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [ManyCam] C:\Program Files\ManyCam\Bin\ManyCam.exe (ManyCam LLC)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [Pando] C:\Program Files\Pando Networks\Pando\Pando.exe (Pando Networks)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Users\nwofan\Desktop\Emulators\uTorrent.exe ()
O4 - Startup: C:\Users\nwofan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Users\nwofan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O9 - Extra Button: @C:\Program Files\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Flash Decompiler SWF Capture tool - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Flash Decompiler SWF Capture tool menu - {86B4FC19-8FA4-4FD3-B243-9AEDB42FA2D5} - Reg Error: Key error. File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe (America Online, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: aol.com ([objects] * is out of zone range - 5)
O15 - HKCU\..Trusted Domains: microsoft.com ([update] http in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKCU\..Trusted Domains: windowsupdate.com ([]http in Trusted sites)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futur...y/FMSI_v420.cab (FuturemarkSystemInfoX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files\Google\Chrome Frame\Application\20.0.1132.43\npchrome_frame.dll (Google Inc.)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\8.0.1\ViProtocol.dll ()
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\Users\nwofan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\nwofan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) - C:\Windows\System32\livessp.dll (Microsoft Corp.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/18 14:12:18 | 000,000,088 | ---- | M] () - H:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2010/05/10 22:02:29 | 000,000,000 | ---D | M] - K:\Automatically Add to iTunes -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/06/28 01:01:09 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/06/27 13:31:24 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{9CFEA195-0A8F-460B-A5F3-9DF542D25BEF}
[2012/06/27 13:31:12 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{48D2D124-61B8-4F96-9F54-5E648B3B80AC}
[2012/06/27 01:30:34 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{74FE9A35-106C-4CA7-AA36-E115AC6B4285}
[2012/06/27 01:30:21 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{DDCC2B4D-68A3-4F3E-811A-636AE4B2BA35}
[2012/06/26 13:29:48 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{CAD1B8E0-898E-42FA-8875-E8B33C2BE9E0}
[2012/06/26 13:29:25 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{88ED21D3-24D3-440A-8ECC-D34D39215124}
[2012/06/26 01:28:44 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{F0D088AE-19DC-4CE2-BF10-0ECAC8CF7B29}
[2012/06/25 13:27:27 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{E5A36BED-99F9-4F78-873C-7ECF61FA4CA9}
[2012/06/25 13:27:03 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{361623E6-4568-42EF-B65B-4C4B094B1C52}
[2012/06/24 21:42:30 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{53FC5C89-1D49-4BAA-BFC6-24A6CDFC030B}
[2012/06/24 21:42:19 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{8365A66D-50BC-403F-BA2C-9DDC36B06BCD}
[2012/06/24 09:41:06 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{E05DD40D-326B-4688-B946-D5181984AB0D}
[2012/06/24 09:40:24 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{4EBB0131-328C-4C3D-B042-C6236A2DC8AA}
[2012/06/23 11:01:20 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{F7BA63C8-E7BE-414F-BE67-8C642CC67C01}
[2012/06/23 11:00:36 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{0DF0F0E0-6E5B-4B2B-8612-BDE92FF25ED8}
[2012/06/23 03:30:48 | 000,000,000 | ---D | C] -- C:\Program Files\Pinball
[2012/06/22 14:28:20 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{DE2ECA40-3F62-4287-AE61-A2606735C718}
[2012/06/22 14:27:54 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{D9DD1FF5-B277-4342-BBE1-55669F9ACD9D}
[2012/06/22 02:03:28 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{068022A6-16D7-4CDA-BE9B-9460A7DA461A}
[2012/06/21 23:32:38 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Roaming\Ask.com
[2012/06/21 23:31:34 | 000,000,000 | ---D | C] -- C:\Program Files\searchresults7
[2012/06/21 14:02:13 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{39480C4F-3A9E-4E4B-8B30-33BB01112C08}
[2012/06/21 14:01:35 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{919163E1-6133-48D0-87A6-4508A62135C5}
[2012/06/21 00:51:13 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\Macromedia
[2012/06/20 18:03:57 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{D749794D-1752-4AB6-A353-3047007AF186}
[2012/06/20 18:03:36 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{7467DCD0-1905-40C3-881F-67AE40EFEFC5}
[2012/06/20 02:38:02 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{F9933F48-41D9-44E1-84AD-5AADC65A2AB9}
[2012/06/19 14:37:21 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{7FA16A91-9820-4DA0-ADF1-CF10DEE761A0}
[2012/06/19 14:37:09 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{DEEEA518-A0FC-436A-9573-C93427FB5A9E}
[2012/06/19 02:37:26 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/06/19 02:35:59 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{F4A22FC0-E4CE-491D-A121-4CC4AF2ABEFC}
[2012/06/19 02:35:15 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{BDD42ADA-CD98-4211-BDE1-A43CDC1F8FBF}
[2012/06/19 02:00:54 | 001,973,368 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\Users\nwofan\avg_remover_stf_x86_2012_2125.exe
[2012/06/19 01:17:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\OpenOffice.org 3.4 (en-US) Installation Files
[2012/06/18 14:34:30 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{EB59FC41-EEB6-4F75-B609-2EC52CF3FFA6}
[2012/06/17 14:33:47 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{6BF77242-1B6B-4DC3-B14A-352936811DF2}
[2012/06/17 02:01:37 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Roaming\Firestorm
[2012/06/17 02:01:36 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\Firestorm
[2012/06/17 01:58:59 | 000,000,000 | ---D | C] -- C:\Program Files\Firestorm-Release
[2012/06/16 14:32:56 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{9FDE28CA-8AB8-4157-BB81-2F09A1CF0687}
[2012/06/16 03:05:58 | 000,000,000 | ---D | C] -- C:\Program Files\SecondLifeViewer
[2012/06/15 14:32:18 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{8641FC7E-2C72-4CA8-993A-8EF8DC363EFC}
[2012/06/15 01:16:22 | 000,021,848 | ---- | C] (IObit) -- C:\Windows\System32\RegistryDefragBootTime.exe
[2012/06/14 14:31:29 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{ADC1B6EF-17FE-43D4-B94E-6DAC931AA6F5}
[2012/06/14 14:31:17 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{701201CB-529C-43F8-BB4B-9EE23401F2EF}
[2012/06/14 02:29:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{3D7762A7-D619-4238-8317-77DD1F4C4396}
[2012/06/14 02:28:48 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{33F10C7B-9D58-41A6-84F8-48B579828583}
[2012/06/13 14:27:45 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{4EA111D1-B9E4-4FFE-B51D-389C114F7782}
[2012/06/13 14:27:16 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{FEB2640E-6990-41CD-B9AC-585B5084E8D6}
[2012/06/12 17:19:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/06/12 17:19:04 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/06/12 17:13:31 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2012/06/12 16:09:28 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{57B38D50-CBB0-406B-A012-FCA08045D6FE}
[2012/06/12 16:09:17 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{7A6F5763-1D0D-4F10-ADB2-F3E8F7FE8C24}
[2012/06/12 04:08:40 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{B0E0337B-69FF-4E90-AD0C-BDC839DBDCCD}
[2012/06/12 04:08:26 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{0EEA1329-4A0A-4A7A-BCC7-363881F5C04F}
[2012/06/11 16:08:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{08782E13-40EF-4F02-A329-F05AD2C43EE3}
[2012/06/11 16:07:56 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{1DB441B6-9FFF-4D10-A759-7806C5F0CFE1}
[2012/06/11 11:52:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Software Update Utility
[2012/06/11 04:07:09 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{3655D63A-254A-439D-9B4C-0302D8338E34}
[2012/06/10 16:06:18 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{182DE0B4-99DF-428B-B5D7-34E82E688C9D}
[2012/06/10 16:05:50 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{83986386-499B-4C57-8779-5F20077F882F}
[2012/06/10 02:38:39 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{B38C6DB9-4B46-46B4-916C-E4F11FB99546}
[2012/06/10 02:38:26 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{D6791BA1-0828-42DA-83EC-0B338D17DBD6}
[2012/06/09 14:37:06 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{3A7AD554-57E2-4625-AE53-85F5ABA5352F}
[2012/06/09 14:36:46 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{7B1340E2-9AFD-45B1-A813-CCB883C1CB2F}
[2012/06/08 16:32:38 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{93372941-A025-4CE1-8D33-3DCDA23E1587}
[2012/06/08 16:32:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{17960C8D-0917-41E7-A5AF-2866B7C1DEB7}
[2012/06/08 03:32:42 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{363656FC-89A6-41EF-A81A-4A3644F329A9}
[2012/06/07 20:39:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wrye Bash
[2012/06/07 15:31:56 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{32EB9A41-98C3-4749-9EA0-B00A12D338A1}
[2012/06/07 15:31:44 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{1A1D2DCC-97C7-4CF4-8706-7AC0A95042A7}
[2012/06/07 13:25:16 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\ID Vault
[2012/06/07 13:25:05 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Roaming\ID Vault
[2012/06/07 05:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2012/06/07 05:20:09 | 000,000,000 | ---D | C] -- C:\Program Files\AOL OnePoint
[2012/06/07 05:19:34 | 000,000,000 | ---D | C] -- C:\ProgramData\White Sky, Inc
[2012/06/07 03:31:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{506DB3B4-982F-484B-A47A-BEAA89AA1518}
[2012/06/06 15:30:37 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{9D77FF78-7064-40CB-9FD5-B3A4022BD473}
[2012/06/06 15:30:25 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{BC378DC5-CC52-4897-B7B9-0D38ACB93BA7}
[2012/06/06 03:29:48 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{B8153561-B24C-47D0-AF1D-589B9E2E0170}
[2012/06/06 03:29:35 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{5CA0661C-C99E-48FC-A33D-DF99578EFE42}
[2012/06/05 15:29:01 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{6875DBAA-1846-4674-910C-EC50783EEA22}
[2012/06/05 15:28:16 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{1D35BE95-578B-4D3C-B983-499B0F65ACC8}
[2012/06/05 03:27:40 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{2F995986-342F-4C89-BD28-0FD84AF5F636}
[2012/06/04 15:26:25 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{6EA878B8-2540-45B4-AE62-5A1249931D55}
[2012/06/04 15:26:07 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{D6A678BF-BD37-4583-8EBF-AB16937EB0AA}
[2012/06/04 01:04:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\Documents\My Cheat Tables
[2012/06/04 01:03:49 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Roaming\OpenCandy
[2012/06/03 20:48:55 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\join.me
[2012/06/03 16:12:20 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{DB7ADF47-6CAA-4DCD-8AC8-87704B9DED77}
[2012/06/03 16:12:01 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{0498B7AE-4041-4FFB-858B-F88047EE5E27}
[2012/06/03 02:53:15 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{3B0C0742-ABD1-4487-81EB-874CC626878C}
[2012/06/02 14:52:35 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{61B07F18-F2A7-4524-B7BE-D863F4117B33}
[2012/06/02 14:52:09 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{4E85D5B9-6D2D-4813-8B11-C67425550116}
[2012/06/01 23:11:08 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{67E4D2A8-5DAA-445C-87C2-E6CFE123367A}
[2012/06/01 11:10:19 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{532C47F7-8574-4E0B-9857-3A13610D05BB}
[2012/06/01 11:09:59 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{B096022C-6F14-4D4E-BF91-FE0BBC749FA4}
[2012/05/31 22:37:02 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{B1BB94AF-E924-45D1-BADD-6DC7518A6CC6}
[2012/05/31 10:36:05 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{A8779D4D-7F11-4228-8C9B-DD5D66709555}
[2012/05/31 10:35:38 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{026DCDC8-29CD-429C-9F36-87568D07A505}
[2012/05/30 15:57:50 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{816EC4EC-9A44-49ED-9A9C-5619654E4121}
[2012/05/30 15:57:29 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{5EB8003C-5BCF-44D0-A185-70A1A7262A60}
[2012/05/30 00:31:36 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{8BD14F6E-9C63-4C73-95E8-62B9D404003F}
[2012/05/29 12:30:27 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{328251D4-AFC5-44E9-95B6-EC2D59F1CE2F}
[2012/05/29 12:30:01 | 000,000,000 | ---D | C] -- C:\Users\nwofan\AppData\Local\{5A5CEDC4-E94D-4CD2-A820-51E900B7967E}
[2009/10/08 20:01:16 | 000,323,584 | ---- | C] ( ) -- C:\Windows\System32\LXBKhcp.dll
[2006/11/06 16:37:46 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxbkpmui.dll
[2006/11/06 16:35:50 | 001,224,704 | ---- | C] ( ) -- C:\Windows\System32\lxbkserv.dll
[2006/11/06 16:28:08 | 000,421,888 | ---- | C] ( ) -- C:\Windows\System32\lxbkcomm.dll
[2006/11/06 16:26:14 | 000,585,728 | ---- | C] ( ) -- C:\Windows\System32\lxbklmpm.dll
[2006/11/06 16:24:44 | 000,397,312 | ---- | C] ( ) -- C:\Windows\System32\lxbkiesc.dll
[2006/11/06 16:21:48 | 000,094,208 | ---- | C] ( ) -- C:\Windows\System32\lxbkpplc.dll
[2006/11/06 16:20:48 | 000,684,032 | ---- | C] ( ) -- C:\Windows\System32\lxbkcomc.dll
[2006/11/06 16:20:14 | 000,163,840 | ---- | C] ( ) -- C:\Windows\System32\lxbkprox.dll
[2006/11/06 16:12:44 | 000,413,696 | ---- | C] ( ) -- C:\Windows\System32\lxbkinpa.dll
[2006/11/06 16:11:58 | 000,991,232 | ---- | C] ( ) -- C:\Windows\System32\lxbkusb1.dll
[2006/11/06 16:07:04 | 000,696,320 | ---- | C] ( ) -- C:\Windows\System32\lxbkhbn3.dll
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/06/28 01:09:34 | 008,876,032 | ---- | M] () -- C:\Users\nwofan\ntuser.dat
[2012/06/28 01:04:57 | 000,014,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/28 01:04:57 | 000,014,048 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/28 00:52:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/28 00:51:41 | 001,048,576 | -HS- | M] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.2.regtrans-ms
[2012/06/28 00:51:41 | 001,048,576 | -HS- | M] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.1.regtrans-ms
[2012/06/28 00:51:41 | 001,048,576 | -HS- | M] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.0.regtrans-ms
[2012/06/28 00:51:41 | 000,065,536 | -HS- | M] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.blf
[2012/06/28 00:51:34 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/06/28 00:51:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/28 00:51:19 | 2414,780,416 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/28 00:28:01 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/27 23:51:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1868571618-3835447236-223175164-1000UA.job
[2012/06/27 23:19:01 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/06/27 23:19:01 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/06/27 21:51:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1868571618-3835447236-223175164-1000Core.job
[2012/06/27 18:01:07 | 000,000,023 | ---- | M] () -- C:\Windows\BlendSettings.ini
[2012/06/27 04:49:19 | 004,888,335 | -H-- | M] () -- C:\Users\nwofan\AppData\Local\IconCache.db
[2012/06/25 01:27:04 | 000,001,009 | ---- | M] () -- C:\Users\Public\Desktop\ManyCam.lnk
[2012/06/23 16:17:40 | 000,175,664 | ---- | M] () -- C:\Users\nwofan\AppData\Local\GDIPFONTCACHEV1.DAT
[2012/06/23 08:34:30 | 002,473,544 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/06/23 03:31:08 | 000,001,822 | ---- | M] () -- C:\Users\Public\Desktop\Start Visual Pinball.lnk
[2012/06/21 03:00:00 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\ErrorEND.job
[2012/06/21 01:12:35 | 000,001,110 | ---- | M] () -- C:\Users\nwofan\Desktop\SkyrimLauncher.exe - Shortcut.lnk
[2012/06/20 09:02:01 | 000,778,834 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2012/06/20 09:02:01 | 000,660,068 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/20 09:02:01 | 000,120,996 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/19 03:50:56 | 000,001,155 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/19 02:35:16 | 000,001,126 | ---- | M] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.lnk
[2012/06/19 02:00:57 | 001,973,368 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Users\nwofan\avg_remover_stf_x86_2012_2125.exe
[2012/06/19 01:52:14 | 001,632,470 | ---- | M] () -- C:\Users\nwofan\AVGInstLog.cab
[2012/06/18 23:15:41 | 000,014,994 | ---- | M] () -- C:\Users\nwofan\AppData\Roaming\wklnhst.dat
[2012/06/17 02:01:24 | 000,001,237 | ---- | M] () -- C:\Users\Public\Desktop\Firestorm-Release.lnk
[2012/06/16 03:06:46 | 000,001,045 | ---- | M] () -- C:\Users\Public\Desktop\Second Life Viewer.lnk
[2012/06/13 21:47:19 | 000,028,046 | ---- | M] () -- C:\Users\nwofan\Two Tone Badge.JPG
[2012/06/13 16:52:55 | 000,001,951 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/06/12 17:21:03 | 000,001,715 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/12 17:13:47 | 000,001,777 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/12 16:23:31 | 000,002,479 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2012/06/11 20:32:55 | 000,002,119 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/06/11 11:52:51 | 000,001,830 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
[2012/06/08 20:59:31 | 000,004,027 | ---- | M] () -- C:\Users\nwofan\RP for today.rtf
[2012/06/07 20:11:46 | 000,001,005 | ---- | M] () -- C:\Users\Public\Desktop\Nexus Mod Manager.lnk
[2012/06/07 00:38:14 | 002,886,982 | ---- | M] () -- C:\Users\nwofan\For Two-Tone.bmp
[2012/06/03 20:48:58 | 000,000,968 | ---- | M] () -- C:\Users\nwofan\Desktop\join.me.lnk
[2012/06/03 15:23:47 | 006,441,984 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mbb
[2012/06/03 15:23:46 | 002,968,576 | R--- | M] () -- C:\Users\Public\Documents\ESBK.mb
[2012/06/02 19:30:53 | 000,072,426 | ---- | M] () -- C:\Users\nwofan\Documents\1338670826_hindy-poo_riootterforhisfriend.jpg
[2012/05/30 15:59:03 | 000,001,777 | ---- | M] () -- C:\Users\Public\Desktop\ooVoo.lnk
[2012/05/29 17:01:23 | 000,112,293 | ---- | M] () -- C:\Users\nwofan\Documents\screencap 2.png
[2012/05/29 14:00:15 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2012/05/29 10:28:18 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/06/28 00:51:41 | 001,048,576 | -HS- | C] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.2.regtrans-ms
[2012/06/28 00:51:41 | 001,048,576 | -HS- | C] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.1.regtrans-ms
[2012/06/28 00:51:41 | 001,048,576 | -HS- | C] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.0.regtrans-ms
[2012/06/28 00:51:41 | 000,065,536 | -HS- | C] () -- C:\Users\nwofan\ntuser.dat{c0c83a86-2b82-11e1-9be5-00038a000015}.TxR.blf
[2012/06/25 01:27:04 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\ManyCam.lnk
[2012/06/23 03:31:08 | 000,001,822 | ---- | C] () -- C:\Users\Public\Desktop\Start Visual Pinball.lnk
[2012/06/19 03:50:56 | 000,001,155 | ---- | C] () -- C:\Users\nwofan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/19 02:35:16 | 000,001,126 | ---- | C] () -- C:\Users\Public\Desktop\OpenOffice.org 3.4.lnk
[2012/06/19 02:01:53 | 000,063,600 | ---- | C] () -- C:\Users\nwofan\avgremover_msilog.txt
[2012/06/19 02:01:10 | 000,624,165 | ---- | C] () -- C:\Users\nwofan\avgremover.log
[2012/06/19 01:52:14 | 001,632,470 | ---- | C] () -- C:\Users\nwofan\AVGInstLog.cab
[2012/06/17 02:01:24 | 000,001,237 | ---- | C] () -- C:\Users\Public\Desktop\Firestorm-Release.lnk
[2012/06/16 03:06:46 | 000,001,045 | ---- | C] () -- C:\Users\Public\Desktop\Second Life Viewer.lnk
[2012/06/13 21:47:09 | 000,028,046 | ---- | C] () -- C:\Users\nwofan\Two Tone Badge.JPG
[2012/06/13 16:52:55 | 000,001,951 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/06/12 17:21:03 | 000,001,715 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/12 17:13:47 | 000,001,777 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/06/11 11:52:50 | 000,001,830 | ---- | C] () -- C:\Users\Public\Desktop\AIM.lnk
[2012/06/08 20:59:30 | 000,004,027 | ---- | C] () -- C:\Users\nwofan\RP for today.rtf
[2012/06/07 00:33:59 | 002,886,982 | ---- | C] () -- C:\Users\nwofan\For Two-Tone.bmp
[2012/06/03 20:48:57 | 000,000,968 | ---- | C] () -- C:\Users\nwofan\Desktop\join.me.lnk
[2012/06/02 19:30:53 | 000,072,426 | ---- | C] () -- C:\Users\nwofan\Documents\1338670826_hindy-poo_riootterforhisfriend.jpg
[2012/05/29 17:01:21 | 000,112,293 | ---- | C] () -- C:\Users\nwofan\Documents\screencap 2.png
[2012/05/29 10:28:18 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_motoandroid_01007.Wdf
[2012/01/06 01:52:37 | 001,936,528 | ---- | C] () -- C:\Windows\System32\ltmm15.dll
[2011/07/11 11:53:36 | 000,000,020 | ---- | C] () -- C:\Windows\System32\NDADMIND.DLL
[2011/06/29 22:42:32 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/03/23 20:48:06 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2010/08/16 14:41:08 | 000,000,385 | ---- | C] () -- C:\Windows\SMB2ed.ini
[2010/06/30 00:12:16 | 000,013,312 | ---- | C] () -- C:\Windows\LPRES.DLL
[2010/03/18 17:59:06 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/02/28 00:44:32 | 000,139,152 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2009/11/10 12:37:57 | 000,016,896 | ---- | C] () -- C:\Windows\System32\tupvcumd.dll
[2009/11/10 12:37:57 | 000,014,848 | ---- | C] () -- C:\Windows\System32\drivers\tupvckmd.sys
[2009/10/20 12:08:44 | 000,037,248 | ---- | C] () -- C:\Windows\System32\drivers\swmsflt.sys
[2009/10/08 20:05:10 | 000,000,325 | ---- | C] () -- C:\Windows\Lexstat.ini
[2009/10/08 20:01:16 | 000,274,432 | ---- | C] () -- C:\Windows\System32\LXBKinst.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/07/14 18:12:53 | 000,044,544 | ---- | C] () -- C:\Windows\System32\GIF89.DLL
[2009/07/13 16:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/05/04 04:20:01 | 000,003,766 | -HS- | C] () -- C:\Windows\System32\KGyGaAvL.sys
[2009/05/04 04:20:01 | 000,000,088 | RHS- | C] () -- C:\Windows\System32\08751F20E9.sys
[2009/05/04 03:05:26 | 000,000,882 | ---- | C] () -- C:\Windows\DC.ini
[2008/12/16 17:30:52 | 000,327,680 | ---- | C] () -- C:\Windows\System32\pythoncom25.dll
[2008/12/16 17:30:52 | 000,102,400 | ---- | C] () -- C:\Windows\System32\pywintypes25.dll
[2008/10/07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2007/03/09 01:12:32 | 000,027,648 | -HS- | C] () -- C:\Windows\System32\AVSredirect.dll
[2007/03/06 03:14:48 | 000,085,504 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2007/03/06 03:14:48 | 000,000,547 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll.manifest
[2007/02/07 17:57:50 | 000,039,899 | ---- | C] () -- C:\Windows\System32\rtsicis.ini
[2007/01/22 08:49:34 | 000,344,064 | ---- | C] () -- C:\Windows\System32\lxbkcoin.dll
[2006/11/30 13:34:24 | 000,413,696 | ---- | C] () -- C:\Windows\System32\lxbkutil.dll
[2006/03/06 11:41:02 | 000,073,728 | ---- | C] () -- C:\Windows\System32\AMV_DecDLL.dll
[2005/10/05 12:19:32 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxbkvs.dll
[2005/09/13 16:27:10 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxbkcnv5.dll
[2005/09/13 16:27:10 | 000,061,440 | ---- | C] () -- C:\Windows\System32\lxbkcnv4.dll
[2004/09/16 14:26:40 | 000,012,634 | ---- | C] () -- C:\Windows\System32\drivers\ADFUUD.SYS

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:C980DA7D
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 109 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP