Hello,
I'm not sure if this is relevant to this forum, but Firefox keeps closing on my computer, in particular when I access hotmail or yahoo mail.
The computer also won't turn off in the normal way (i.e. via Start/turn off) and Norton seems to 'encounter problems' and then shut down. They look like standard malware symptoms to me, but I've no idea what.
I've run OTL and have posted the results below. OTL also generated an Extras file. Should I post this too?
Would appreciate some help.
RSP
OTL logfile created on: 23/11/2014 11:01:40 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Sarl York Edward\Bureau
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: Royaume-Uni | Language: ENG | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 71.13% Memory free
3.85 Gb Paging File | 3.48 Gb Available in Paging File | 90.41% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 94.61 Gb Free Space | 63.48% Space Free | Partition Type: NTFS
Drive E: | 14.43 Gb Total Space | 9.70 Gb Free Space | 67.23% Space Free | Partition Type: FAT32
Drive F: | 14.43 Gb Total Space | 12.41 Gb Free Space | 86.00% Space Free | Partition Type: FAT32
Computer Name: WILLIAMWOTTENGE | User Name: Sarl York Edward | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/11/23 11:54:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarl York Edward\Bureau\OTL.exe
PRC - [2014/09/21 10:17:47 | 000,265,040 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\21.6.0.32\n360.exe
PRC - [2014/09/05 20:11:56 | 000,153,072 | ---- | M] (Coupons.com Inc.) -- C:\Program Files\Coupon Printer\CouponPrinterService.exe
PRC - [2014/07/11 16:14:20 | 000,118,272 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2014/07/11 15:58:08 | 007,241,728 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2013/10/08 16:46:36 | 000,208,424 | ---- | M] (Haufe-Lexware GmbH & Co. KG) -- C:\Program Files\Lexware\Update Manager\LxUpdateManager.exe
PRC - [2013/09/26 12:18:02 | 001,620,520 | ---- | M] (Haufe-Lexware GmbH & Co. KG) -- C:\Program Files\Fichiers communs\Lexware\LxWebAccess\LxWebAccess.exe
PRC - [2012/07/05 14:11:14 | 000,008,192 | ---- | M] (Microsoft) -- C:\Program Files\Fichiers communs\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe
PRC - [2012/05/17 08:59:56 | 000,053,248 | ---- | M] (Sage (UK) Limited) -- C:\Program Files\Fichiers communs\Sage SData\Sage.SData.Service.exe
PRC - [2008/04/14 02:34:03 | 001,037,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2005/11/09 15:40:32 | 000,110,592 | ---- | M] ( ) -- C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe
PRC - [2005/11/09 15:19:38 | 000,634,880 | ---- | M] (Maxtor Corporation) -- C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe
========== Modules (No Company Name) ==========
MOD - [2014/03/26 13:17:29 | 000,680,960 | ---- | M] () -- C:\windows\assembly\GAC_32\Sage.Central.AutoUpdateManager\1.0.0.0__021b26c6762d83c5\Sage.Central.AutoUpdateManager.dll
MOD - [2014/03/26 13:16:37 | 000,061,440 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Common.Web.Server\1.0.0.0__c59b718b5ca510a8\Sage.Common.Web.Server.dll
MOD - [2014/03/26 13:16:36 | 000,258,048 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Integration.Server\1.0.0.0__3f422f0ff54abde1\Sage.Integration.Server.dll
MOD - [2014/03/26 13:16:36 | 000,077,824 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Utilities\1.0.0.0__c59b718b5ca510a8\Sage.Utilities.dll
MOD - [2014/03/26 13:16:36 | 000,032,768 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Integration.Server.Model\1.0.0.0__3f422f0ff54abde1\Sage.Integration.Server.Model.dll
MOD - [2014/03/26 13:16:36 | 000,032,768 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Integration.Server.Feeds\1.0.0.0__3f422f0ff54abde1\Sage.Integration.Server.Feeds.dll
MOD - [2014/03/26 13:16:35 | 000,851,968 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Common.Syndication\1.0.0.0__c59b718b5ca510a8\Sage.Common.Syndication.dll
MOD - [2014/03/26 13:16:34 | 000,010,240 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\Sage.Integration.Diagnostics\1.0.0.0__3f422f0ff54abde1\Sage.Integration.Diagnostics.dll
MOD - [2014/02/15 09:00:23 | 018,109,440 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\dd733c6f1f9f50f3517d48da5bea80d2\System.ServiceModel.ni.dll
MOD - [2014/02/15 08:57:53 | 000,649,728 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Transactions\fc7255cccb69c45a808b3d7e6abf55c5\System.Transactions.ni.dll
MOD - [2014/02/15 08:57:52 | 001,021,440 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\469dd20488c4a9606abe21189a3c1ab9\System.Runtime.DurableInstancing.ni.dll
MOD - [2014/02/15 08:57:51 | 000,143,360 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\27bdc6196968e44234654e30e1028750\SMDiagnostics.ni.dll
MOD - [2014/02/15 08:57:50 | 002,658,304 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\fa954900a6cf3a095efadfa4c683a32c\System.Runtime.Serialization.ni.dll
MOD - [2014/02/15 08:57:47 | 000,393,216 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\05be173cbacba4b7604a67a267acdfe4\System.Xml.Linq.ni.dll
MOD - [2014/02/15 08:57:46 | 001,801,728 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d116eda30a35c490e59221b0ebac6fcd\System.Xaml.ni.dll
MOD - [2014/02/15 08:57:37 | 000,011,776 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\211925af2639b2445fda3b8c040e5a8a\Microsoft.VisualC.ni.dll
MOD - [2014/02/15 08:57:24 | 000,194,048 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\d7785512895a0427dad1bef2155b7ffc\CustomMarshalers.ni.dll
MOD - [2014/02/15 08:57:10 | 011,906,048 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\90e490c25be955a75f133cb359569009\System.Web.ni.dll
MOD - [2014/02/14 15:06:08 | 013,199,360 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\2781e84862746a34f026d0ee179eed2b\System.Windows.Forms.ni.dll
MOD - [2014/02/14 15:05:53 | 001,667,584 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\243ff1822abc8282cb8fee37538170b4\System.Drawing.ni.dll
MOD - [2014/02/14 15:05:46 | 001,014,272 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\991c4e11f571a4074b9c4a5841222338\System.Configuration.ni.dll
MOD - [2014/02/14 15:05:44 | 007,053,824 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Core\a4b5a1a06d2d7f77258943c8c228a5e0\System.Core.ni.dll
MOD - [2014/02/14 15:05:34 | 005,628,928 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System.Xml\850fa7110c7423c324762c1ad3130219\System.Xml.ni.dll
MOD - [2014/02/14 15:05:21 | 009,099,776 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\System\4c906eb82e6f56aea01b2a7291fab7ea\System.ni.dll
MOD - [2014/02/14 15:05:03 | 014,416,896 | ---- | M] () -- C:\windows\assembly\NativeImages_v4.0.30319_32\mscorlib\4e62d1d9b7dd2c2d14915abb73c22d50\mscorlib.ni.dll
MOD - [2014/02/14 14:57:01 | 000,141,312 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\f254328a10638e87223d401b39197c91\System.Configuration.Install.ni.dll
MOD - [2014/02/14 14:56:56 | 000,978,944 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4b6e70acd99dc22e29b7fc8f9ac340c4\System.Configuration.ni.dll
MOD - [2014/02/14 14:56:55 | 000,212,992 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8cd995f00848816e3ec49dc326e3d49b\System.ServiceProcess.ni.dll
MOD - [2014/02/14 14:51:15 | 005,462,016 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\7faf645dc46781225cb722edf9e1e738\System.Xml.ni.dll
MOD - [2014/02/14 14:49:31 | 007,977,984 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\4b0455ae94e3cecca4bb3ba8c96828c9\System.ni.dll
MOD - [2014/02/14 14:49:08 | 011,497,984 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\dae02331a443fb52216ca83292cb2f21\mscorlib.ni.dll
MOD - [2014/02/01 13:30:46 | 000,861,184 | ---- | M] () -- C:\Program Files\LeapFrog\LeapFrog Connect\platforms\qwindows.dll
MOD - [2013/09/26 12:20:40 | 000,176,168 | ---- | M] () -- C:\Program Files\Lexware\Update Manager\Haufe.Core.Diagnostics.Logging.Targets.Etw.dll
MOD - [2013/09/26 12:20:40 | 000,043,048 | ---- | M] () -- C:\Program Files\Lexware\Update Manager\Haufe.Core.Diagnostics.Etw.dll
MOD - [2012/06/18 15:24:30 | 000,260,096 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_05.dll
MOD - [2012/04/08 14:10:06 | 000,040,960 | ---- | M] () -- C:\windows\assembly\GAC_MSIL\System.ServiceProcess.resources\2.0.0.0_fr_b03f5f7f11d50a3a\System.ServiceProcess.resources.dll
MOD - [2007/08/21 12:32:44 | 000,098,304 | ---- | M] () -- C:\WINDOWS\system32\redmonnt.dll
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - File not found [Disabled | Stopped] -- C:\Documents and Settings\All Users\Application Data\DatacardService\DCService.exe -- (DCService.exe)
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2014/11/11 10:12:02 | 000,114,288 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/09/21 10:17:47 | 000,265,040 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\21.6.0.32\N360.exe -- (N360)
SRV - [2014/09/05 20:11:56 | 000,153,072 | ---- | M] (Coupons.com Inc.) [Auto | Running] -- C:\Program Files\Coupon Printer\CouponPrinterService.exe -- (CouponPrinterService)
SRV - [2014/07/11 15:58:08 | 007,241,728 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2014/06/23 06:13:07 | 000,262,320 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/05 14:11:14 | 000,008,192 | ---- | M] (Microsoft) [Auto | Running] -- C:\Program Files\Fichiers communs\Sage\Central\AutoUpdateClient\Sage.Central.AutoUpdateManager.Service.exe -- (Sage AutoUpdate Manager Service)
SRV - [2012/05/17 08:59:56 | 000,053,248 | ---- | M] (Sage (UK) Limited) [Auto | Running] -- C:\Program Files\Fichiers communs\Sage SData\Sage.SData.Service.exe -- (Sage SData Service)
SRV - [2012/04/02 14:36:58 | 000,096,768 | ---- | M] (Freemake) [Disabled | Stopped] -- C:\Documents and Settings\All Users\Application Data\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe -- (Freemake Improver)
SRV - [2011/07/20 03:18:24 | 000,440,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2011/05/25 12:06:20 | 000,037,664 | ---- | M] (Apple Inc.) [Disabled | Stopped] -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2009/12/28 16:25:40 | 000,036,864 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Belkin\F7D4101\V1\wlansrv.exe -- (WLANBelkinService)
SRV - [2006/10/26 13:03:08 | 000,145,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE -- (ose)
SRV - [2005/11/14 01:06:04 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe -- (IDriverT)
SRV - [2005/11/09 16:44:08 | 000,184,320 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe -- (MaxBackServiceInt)
SRV - [2005/11/09 15:40:32 | 000,110,592 | ---- | M] ( ) [Auto | Running] -- C:\Program Files\Maxtor\OneTouch\Utils\SyncServices.exe -- (NTService1)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbfake.sys -- (hwusbfake)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbmdm.sys -- (hwdatacard)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_jubusenum.sys -- (huawei_enumerator)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\ewfiltertdidriver.sys -- (filtertdidriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ewusbnet.sys -- (ewusbnet)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - [2014/11/21 05:39:10 | 001,636,696 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20141120.039\navex15.sys -- (NAVEX15)
DRV - [2014/11/21 05:39:10 | 000,095,704 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20141120.039\naveng.sys -- (NAVENG)
DRV - [2014/11/19 18:28:38 | 000,453,264 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20141121.001\IDSXpx86.sys -- (IDSxpx86)
DRV - [2014/10/03 19:19:32 | 001,138,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20141118.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2014/09/08 21:09:46 | 000,378,672 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2014/09/08 21:09:46 | 000,111,408 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2014/08/26 02:20:22 | 000,664,792 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\srtsp.sys -- (SRTSP)
DRV - [2014/08/26 02:20:22 | 000,032,984 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\srtspx.sys -- (SRTSPX)
DRV - [2014/08/06 19:48:16 | 000,209,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\ironx86.sys -- (SymIRON)
DRV - [2014/04/01 06:14:56 | 000,142,936 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2014/03/04 04:18:12 | 000,936,152 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\symefa.sys -- (SymEFA)
DRV - [2014/02/18 01:32:41 | 000,423,256 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\symtdi.sys -- (SYMTDI)
DRV - [2013/09/26 02:50:25 | 000,127,064 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\ccsetx86.sys -- (ccSet_N360)
DRV - [2013/09/10 02:47:26 | 000,367,704 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\1506000.020\symds.sys -- (SymDS)
DRV - [2012/04/08 14:18:34 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pssdk42.sys -- (PSSDK42)
DRV - [2012/04/08 14:18:33 | 000,053,312 | ---- | M] (microOLAP Technologies LTD) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\pssdklbf.sys -- (PSSDKLBF)
DRV - [2012/01/10 10:07:36 | 000,179,200 | R--- | M] (Dexetek ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\DxVGrb.sys -- (DxVGrb)
DRV - [2011/04/13 13:56:34 | 000,057,144 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Trusteer\Rapport\store\exts\RapportCerberus\25973\RapportCerberus_25973.sys -- (RapportCerberus_25973)
DRV - [2011/04/08 08:17:38 | 000,066,360 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportEI.sys -- (RapportEI)
DRV - [2011/04/08 08:17:38 | 000,053,816 | ---- | M] (Trusteer Ltd.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\RapportKELL.sys -- (RapportKELL)
DRV - [2011/04/08 08:17:36 | 000,158,904 | ---- | M] (Trusteer Ltd.) [Kernel | System | Running] -- C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys -- (RapportPG)
DRV - [2010/10/20 12:24:22 | 000,302,720 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\V0700Afx.sys -- (V0700Afx)
DRV - [2010/10/17 23:00:00 | 000,322,304 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\V0700Vid.sys -- (V0700Vid)
DRV - [2010/08/31 09:28:56 | 000,147,040 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV - [2009/11/06 07:26:36 | 000,642,432 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcmwlhigh5.sys -- (BCMH43XX)
DRV - [2009/10/02 08:59:16 | 000,489,952 | ---- | M] (ITETech ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AF15BDA.sys -- (AF15BDA)
DRV - [2008/04/13 19:46:22 | 000,015,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\MPE.sys -- (MPE)
DRV - [2006/07/11 13:38:30 | 000,020,480 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2006/07/11 13:38:28 | 000,057,856 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2006/03/17 09:18:58 | 000,392,960 | R--- | M] (Sensaura) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\senfilt.sys -- (SenFiltService)
DRV - [2005/04/06 13:05:24 | 000,015,360 | ---- | M] (Maxtor Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mxopswd.sys -- (MXOPSWD)
DRV - [2004/08/13 02:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.msn.com/?p...97&ocid=UP97DHP
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 55 66 AE 52 3C CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.order.3: "Bing "
FF - prefs.js..browser.startup.homepage: "http://uk.msn.com/?p....google.co.uk/"
FF - prefs.js..extensions.enabledAddons: 2020Player_IKEA%402020Technologies.com:5.0.94.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:33.1
FF - prefs.js..keyword.URL: "http://www.bing.com/...7DF&PC=UP97&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_14_0_0_125.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.2: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@xunlei.com/DapCtrl: C:\Program Files\Fichiers communs\Thunder Network\KanKan\npDapCtrl.2.3.7201.375.(310).dll (ShenZhen Thunder Networking Technologies Ltd.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2012/04/13 13:14:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn\ [2014/11/23 08:56:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 33.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/05/09 09:05:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sarl York Edward\Application Data\Mozilla\Extensions
[2011/05/09 09:05:27 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sarl York Edward\Application Data\Mozilla\Extensions\[email protected]
[2014/08/09 15:30:02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Sarl York Edward\Application Data\Mozilla\Firefox\Profiles\a9pd4jm0.default-1378115927906\extensions
[2014/08/09 15:30:02 | 000,000,000 | ---D | M] (20-20 3D Viewer - IKEA) -- C:\Documents and Settings\Sarl York Edward\Application Data\Mozilla\Firefox\Profiles\a9pd4jm0.default-1378115927906\extensions\[email protected]
[2014/05/16 05:47:00 | 000,006,057 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Application Data\Mozilla\Firefox\Profiles\a9pd4jm0.default-1378115927906\searchplugins\bingp.xml
[2014/11/11 10:11:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/11/11 10:12:08 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2013/04/07 10:19:18 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\21.6.0.32\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\21.6.0.32\ips\ipsbho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\21.6.0.32\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (TerraTec Home Cinema) - {AD6E6555-FB2C-47D4-8339-3E2965509877} - C:\Program Files\TerraTec\TerraTec Home Cinema\ThcDeskBand.dll (TerraTec Electronic GmbH)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [LexwareInfoService] C:\Program Files\Lexware\Update Manager\LxUpdateManager.exe (Haufe-Lexware GmbH & Co. KG)
O4 - HKLM..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\OneTouch\Utils\OneTouch.exe (Maxtor Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1296281020859 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A16B10F-0DC3-4FF8-8757-BC0178BABDFF}: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{304248DE-D864-4DA2-BC1F-37647F12762F}: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{434BAE2E-E7AE-4FDF-AED9-92FF05DFE4D4}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{589E56EB-0645-46EB-8220-C47F606F3023}: DhcpNameServer = 192.168.2.1 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CAE209F7-72D9-4EBD-9ECC-667C5384A88C}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\system32\mshtml.dll ()
O18 - Protocol\Handler\haufereader - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Fichiers communs\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop Components:0 (Ma page d'accueil) - About:Home
O24 - Desktop WallPaper: C:\Documents and Settings\Sarl York Edward\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Sarl York Edward\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/21 08:26:24 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/11/23 11:00:52 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Sarl York Edward\Bureau\OTL.exe
[2014/11/11 10:11:43 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
========== Files - Modified Within 30 Days ==========
[2014/11/23 11:54:54 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Sarl York Edward\Bureau\OTL.exe
[2014/11/23 10:23:11 | 000,000,875 | ---- | M] () -- C:\windows\BRWMARK.INI
[2014/11/23 10:22:15 | 000,001,002 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2014/11/23 10:13:09 | 000,545,360 | ---- | M] () -- C:\windows\System32\perfh00C.dat
[2014/11/23 10:13:09 | 000,475,510 | ---- | M] () -- C:\windows\System32\perfh009.dat
[2014/11/23 10:13:09 | 000,091,660 | ---- | M] () -- C:\windows\System32\perfc00C.dat
[2014/11/23 10:13:09 | 000,077,202 | ---- | M] () -- C:\windows\System32\perfc009.dat
[2014/11/23 08:54:42 | 000,000,244 | ---- | M] () -- C:\windows\tasks\Notification de fin de service de Microsoft Windows XP - à la connexion.job
[2014/11/23 08:54:38 | 000,002,048 | --S- | M] () -- C:\windows\bootstat.dat
[2014/11/22 17:14:39 | 000,113,664 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/11/19 13:25:38 | 000,002,575 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Bureau\Microsoft Office Word 2007.lnk
[2014/11/18 11:47:30 | 000,002,529 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Bureau\Microsoft Office Excel 2007.lnk
[2014/11/17 12:37:03 | 000,012,598 | ---- | M] () -- C:\windows\System32\wpa.dbl
[2014/11/14 18:11:18 | 004,065,015 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\PIIEYorkLimited.pdf
[2014/11/14 18:10:01 | 004,065,926 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Télécopie pleine page.pdf
[2014/11/09 14:37:08 | 000,000,102 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Dry Beds Now.cue
[2014/11/09 14:31:26 | 034,892,801 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Dry Beds Now.mp3
[2014/11/08 15:00:00 | 000,000,238 | ---- | M] () -- C:\windows\tasks\Notification de fin de service de Microsoft Windows XP -mensuellement.job
[2014/11/07 14:34:55 | 017,445,872 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\DryBedsNow.mp3
[2014/11/06 11:09:06 | 000,263,229 | ---- | M] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\R5N7UV-BoardingPass.pdf
[2014/11/05 14:38:01 | 000,000,284 | ---- | M] () -- C:\windows\tasks\AppleSoftwareUpdate.job
========== Files Created - No Company Name ==========
[2014/11/14 18:11:17 | 004,065,015 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\PIIEYorkLimited.pdf
[2014/11/14 18:09:53 | 004,065,926 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Télécopie pleine page.pdf
[2014/11/09 14:37:08 | 000,000,102 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Dry Beds Now.cue
[2014/11/09 14:30:09 | 034,892,801 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\Dry Beds Now.mp3
[2014/11/07 14:34:54 | 017,445,872 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\DryBedsNow.mp3
[2014/11/06 11:09:06 | 000,263,229 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Mes documents\R5N7UV-BoardingPass.pdf
[2014/09/15 15:21:43 | 000,000,000 | -H-- | C] () -- C:\windows\uccspecc.sys
[2014/03/26 12:56:32 | 000,000,538 | ---- | C] () -- C:\windows\ODBC.INI
[2012/04/14 15:21:23 | 002,082,478 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3763518644-895795467-4165139698-1006-0.dat
[2012/04/14 15:21:21 | 000,190,078 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2011/05/01 18:00:51 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Application Data\CoreAVC.ini
[2008/09/17 07:13:40 | 000,001,514 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Application Data\SAS7_000.DAT
[2008/01/30 11:18:03 | 000,000,040 | --S- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2007/12/24 16:40:20 | 000,122,030 | R--- | C] () -- C:\Documents and Settings\Sarl York Edward\Backup Status
[2007/12/19 11:17:35 | 000,113,664 | ---- | C] () -- C:\Documents and Settings\Sarl York Edward\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2011/04/30 14:21:43 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/14 02:33:41 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 10:53:55 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/14 02:33:48 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014/01/26 19:24:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2009/03/07 13:24:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\F-Secure
[2012/04/13 13:16:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Freemake
[2008/06/11 13:52:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\fssg
[2012/04/08 13:56:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Graboid Inc
[2011/04/30 14:32:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Haufe
[2013/12/22 12:58:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Leapfrog
[2011/04/30 14:37:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Lexware
[2007/12/19 08:03:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Maxtor
[2011/09/16 11:20:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\mquadr.at
[2008/09/16 15:49:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2010/05/28 17:01:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2014/03/26 13:36:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sage
[2008/09/18 09:35:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2008/01/30 11:19:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SlySoft
[2014/09/29 10:51:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/01/29 15:07:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TerraTec
[2012/01/07 15:02:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Thunder Network
[2011/07/21 11:19:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\tmp
[2011/04/02 04:58:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Trusteer
[2011/02/12 15:47:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/12/05 18:30:32 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{D423354A-E70D-49AC-B74E-9DB73BB8ACA3}
[2014/10/01 12:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\avidemux
[2011/12/03 13:45:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\co.uk.myphotobook.creator.001F9DF2D0BAABEB11F42CCEE43224607B61109C.1
[2007/12/17 10:44:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\F-Secure
[2011/05/09 09:05:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Haufe Mediengruppe
[2014/01/29 10:01:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\HMRC
[2013/04/14 07:18:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\ImgBurn
[2011/04/30 14:37:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Lexware
[2013/02/11 15:26:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\LiveCAD3
[2012/08/19 06:16:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Notepad++
[2008/09/16 15:54:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Nuance
[2011/09/21 10:32:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Orange
[2013/08/04 06:16:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\pdfforge
[2007/12/20 16:16:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\ScanSoft
[2011/09/21 10:05:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Schnellstart-DVD
[2014/02/27 10:26:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\TeamViewer
[2011/08/02 11:18:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Telekom
[2011/08/02 11:34:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Telekom Internet Manager
[2011/01/29 15:04:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\TerraTec
[2012/02/11 07:35:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Tific
[2011/04/02 04:59:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Sarl York Edward\Application Data\Trusteer
========== Purity Check ==========
< End of report >