Symptoms - the computer crashed once while using firefox.
- windows reports Com surrogate trying to make unauthorised changes. In the details a Quicktime file is referred to. This is still ocurring.
- windows defender removed a fake Pccleaner
- avast removed one file from the HP directory, on a pre start up scan. (Oops, I can't locate the log.)
- one time a message appeared on the LR corner of the screen saying that the copy of windows is not genuine, which in fact it is.
I have followes the steps of malware and spyware cleaning guide (TFC,ERUNT,Malwarebytes,GMER,OTL),
can someone have a look and let me know what's going on??
Thanks, Declan.
Here are the logs.
The GMER log is attached because it made the post too long. It has hundreds of entries that reference Comodo.
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4577
Windows 6.0.6002 Service Pack 2
Internet Explorer 8.0.6001.18943
09/09/2010 2:22:49
mbam-log-2010-09-09 (02-22-49).txt
Scan type: Quick scan
Objects scanned: 147984
Time elapsed: 7 minute(s), 48 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 09/09/2010 15:03:54 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Declan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 0000040A | Country: Spain | Language: ESP | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 47,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,41 Gb Total Space | 105,43 Gb Free Space | 47,19% Space Free | Partition Type: NTFS
Drive D: | 9,48 Gb Total Space | 1,64 Gb Free Space | 17,30% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DECLAN-PC
Current User Name: Declan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/09/09 15:01:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Declan\Desktop\OTL.exe
PRC - [2010/09/07 17:12:02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/07/26 18:42:57 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/06/01 19:00:52 | 001,778,480 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2010/06/01 19:00:40 | 002,039,240 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
PRC - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2009/06/03 20:43:18 | 000,217,170 | ---- | M] (IDT, Inc.) -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe
PRC - [2009/04/11 08:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/04/11 08:27:28 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\conime.exe
PRC - [2008/04/26 01:15:26 | 000,361,808 | ---- | M] () -- C:\WINDOWS\SMINST\BLService.exe
PRC - [2008/04/15 22:42:14 | 000,939,264 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Health Check\HPHC.exe
PRC - [2008/01/21 04:23:32 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/12/11 21:15:04 | 000,012,800 | ---- | M] (Agere Systems) -- C:\WINDOWS\System32\agrsmsvc.exe
========== Modules (SafeList) ==========
MOD - [2010/09/09 15:01:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Declan\Desktop\OTL.exe
MOD - [2010/07/14 13:30:14 | 000,018,688 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\sahook.dll
MOD - [2010/06/01 19:00:52 | 000,278,288 | ---- | M] (COMODO) -- C:\WINDOWS\System32\guard32.dll
MOD - [2009/04/11 08:28:21 | 002,241,536 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msi.dll
MOD - [2009/04/11 08:21:38 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
MOD - [2008/01/21 04:24:37 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msscript.ocx
MOD - [2008/01/21 04:24:15 | 000,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\sfc_os.dll
MOD - [2006/11/02 11:46:13 | 000,004,608 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\sfc.dll
MOD - [2006/11/02 11:46:07 | 000,015,872 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\msiltcfg.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010/09/07 17:11:59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/06/01 19:00:52 | 001,778,480 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2010/05/20 17:19:16 | 000,088,176 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2010/03/18 13:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/03 20:43:18 | 000,217,170 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_827e372d\stacsv.exe -- (STacSV)
SRV - [2009/02/18 20:38:43 | 000,129,880 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2008/04/26 01:15:26 | 000,361,808 | ---- | M] () [Auto | Running] -- C:\WINDOWS\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/02/03 21:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\WINDOWS\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008/01/21 04:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/12/11 21:15:04 | 000,012,800 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\System32\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\usbaapl.sys -- (USBAAPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2010/09/07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010/09/07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010/09/07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010/09/07 16:47:30 | 000,050,768 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2010/09/07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010/06/15 16:53:28 | 000,025,656 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\hpdskflt.sys -- (hpdskflt)
DRV - [2010/06/15 16:53:12 | 000,033,848 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2010/06/04 11:55:40 | 000,224,240 | ---- | M] (COMODO) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2010/06/01 19:00:06 | 000,075,944 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\inspect.sys -- (inspect)
DRV - [2010/06/01 19:00:06 | 000,030,112 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/06/03 20:43:18 | 000,407,040 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008/11/21 21:53:40 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\NETw5v32.sys -- (NETw5v32) Intel®
DRV - [2008/07/17 12:37:22 | 000,097,936 | ---- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\jmcr.sys -- (JMCR)
DRV - [2008/05/14 04:09:00 | 000,043,552 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/04/15 12:05:08 | 000,118,784 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/02/01 01:14:36 | 000,166,448 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/01/24 15:23:12 | 000,052,736 | ---- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\enecir.sys -- (enecir)
DRV - [2008/01/21 04:23:27 | 000,386,616 | ---- | M] (LSI Corporation, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\megasr.sys -- (MegaSR)
DRV - [2008/01/21 04:23:27 | 000,149,560 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\adpu320.sys -- (adpu320)
DRV - [2008/01/21 04:23:27 | 000,031,288 | ---- | M] (LSI Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\megasas.sys -- (megasas)
DRV - [2008/01/21 04:23:26 | 000,101,432 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\adpu160m.sys -- (adpu160m)
DRV - [2008/01/21 04:23:26 | 000,074,808 | ---- | M] (Silicon Integrated Systems) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\sisraid4.sys -- (SiSRaid4)
DRV - [2008/01/21 04:23:26 | 000,040,504 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\hpcisss.sys -- (HpCISSs)
DRV - [2008/01/21 04:23:25 | 000,300,600 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\adpahci.sys -- (adpahci)
DRV - [2008/01/21 04:23:25 | 000,089,656 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\lsi_sas.sys -- (LSI_SAS)
DRV - [2008/01/21 04:23:24 | 001,122,360 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\ql2300.sys -- (ql2300)
DRV - [2008/01/21 04:23:24 | 000,118,784 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\E1G60I32.sys -- (E1G60) Intel®
DRV - [2008/01/21 04:23:24 | 000,079,928 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\arcsas.sys -- (arcsas)
DRV - [2008/01/21 04:23:23 | 000,654,336 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VSTCNXT3.SYS -- (winachsf)
DRV - [2008/01/21 04:23:23 | 000,235,064 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iastorv.sys -- (iaStorV)
DRV - [2008/01/21 04:23:23 | 000,130,616 | ---- | M] (VIA Technologies Inc.,Ltd) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vsmraid.sys -- (vsmraid)
DRV - [2008/01/21 04:23:23 | 000,115,816 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\ulsata2.sys -- (ulsata2)
DRV - [2008/01/21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\lsi_scsi.sys -- (LSI_SCSI)
DRV - [2008/01/21 04:23:23 | 000,096,312 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\lsi_fc.sys -- (LSI_FC)
DRV - [2008/01/21 04:23:23 | 000,079,416 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\arc.sys -- (arc)
DRV - [2008/01/21 04:23:22 | 000,987,648 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VSTDPV3.SYS -- (HSF_DPV)
DRV - [2008/01/21 04:23:22 | 000,342,584 | ---- | M] (Emulex) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\elxstor.sys -- (elxstor)
DRV - [2008/01/21 04:23:22 | 000,200,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\VSTAZL3.SYS -- (HSFHWAZL)
DRV - [2008/01/21 04:23:21 | 000,422,968 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\adp94xx.sys -- (adp94xx)
DRV - [2008/01/21 04:23:21 | 000,102,968 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvraid.sys -- (nvraid)
DRV - [2008/01/21 04:23:21 | 000,045,112 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nvstor.sys -- (nvstor)
DRV - [2008/01/21 04:23:20 | 000,238,648 | ---- | M] (ULi Electronics Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\uliahci.sys -- (uliahci)
DRV - [2008/01/21 04:23:00 | 000,020,024 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\viaide.sys -- (viaide)
DRV - [2008/01/21 04:23:00 | 000,019,000 | ---- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\cmdide.sys -- (cmdide)
DRV - [2008/01/21 04:23:00 | 000,017,464 | ---- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\aliide.sys -- (aliide)
DRV - [2007/06/19 02:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/03 18:47:24 | 000,032,256 | ---- | M] (DiBcom SA) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\yuanmodbda2.sys -- (MODBDA2)
DRV - [2006/11/02 11:50:35 | 000,106,088 | ---- | M] (QLogic Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\ql40xx.sys -- (ql40xx)
DRV - [2006/11/02 11:50:35 | 000,098,408 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\ulsata.sys -- (UlSata)
DRV - [2006/11/02 11:50:19 | 000,045,160 | ---- | M] (IBM Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\nfrd960.sys -- (nfrd960)
DRV - [2006/11/02 11:50:17 | 000,041,576 | ---- | M] (Intel Corp./ICP vortex GmbH) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iirsp.sys -- (iirsp)
DRV - [2006/11/02 11:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\djsvs.sys -- (aic78xx)
DRV - [2006/11/02 11:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iteraid.sys -- (iteraid)
DRV - [2006/11/02 11:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\iteatapi.sys -- (iteatapi)
DRV - [2006/11/02 11:50:05 | 000,035,944 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\symc8xx.sys -- (Symc8xx)
DRV - [2006/11/02 11:50:03 | 000,034,920 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\sym_u3.sys -- (Sym_u3)
DRV - [2006/11/02 11:49:59 | 000,033,384 | ---- | M] (LSI Logic Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\mraid35x.sys -- (Mraid35x)
DRV - [2006/11/02 11:49:56 | 000,031,848 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\sym_hi.sys -- (Sym_hi)
DRV - [2006/11/02 10:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brserid.sys -- (Brserid) Brother MFC Serial Port Interface Driver (WDM)
DRV - [2006/11/02 10:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbser.sys -- (BrUsbSer)
DRV - [2006/11/02 10:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltup.sys -- (BrFiltUp)
DRV - [2006/11/02 10:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brfiltlo.sys -- (BrFiltLo)
DRV - [2006/11/02 10:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brserwdm.sys -- (BrSerWdm)
DRV - [2006/11/02 10:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\brusbmdm.sys -- (BrUsbMdm)
DRV - [2006/11/02 09:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\ntrigdigi.sys -- (ntrigdigi)
DRV - [2006/11/02 09:30:56 | 000,429,056 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\nvm60x32.sys -- (NVENETFD)
DRV - [2006/11/02 09:30:53 | 000,464,384 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\BCMWL6.SYS -- (BCM43XV)
DRV - [2001/04/13 19:18:24 | 000,188,276 | ---- | M] (Roland) [Kernel | Auto | Running] -- C:\Program Files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys -- (RVIEGVST)
DRV - [2001/04/13 19:16:38 | 000,187,992 | ---- | M] (Roland) [Kernel | Auto | Running] -- C:\Program Files\Roland\Virtual Sound Canvas DXi\RVIEg01.sys -- (RVIEG01)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...avilion&pf=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.2
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8
FF - prefs.js..keyword.URL: "http://es.search.yah...h?fr=mcafee&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/08/28 03:24:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/08/28 03:36:11 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/21 20:33:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/08/21 20:33:44 | 000,000,000 | ---D | M]
[2010/07/06 09:50:44 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\Mozilla\Extensions
[2010/09/09 01:30:35 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\Mozilla\Firefox\Profiles\a6rpqaoz.default\extensions
[2010/08/19 00:39:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Declan\AppData\Roaming\Mozilla\Firefox\Profiles\a6rpqaoz.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2010/07/10 11:26:57 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Declan\AppData\Roaming\Mozilla\Firefox\Profiles\a6rpqaoz.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/21 21:18:36 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Declan\AppData\Roaming\Mozilla\Firefox\Profiles\a6rpqaoz.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/08/21 11:51:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2008/06/30 13:44:08 | 000,324,976 | ---- | M] (Symantec Corporation) -- C:\Program Files\Mozilla Firefox\components\coFFPlgn.dll
[2010/07/06 11:04:42 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
[2010/06/26 09:47:12 | 000,003,996 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\drae.xml
[2010/06/26 09:47:12 | 000,000,751 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-es.xml
[2010/06/26 09:47:12 | 000,001,178 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-es.xml
[2010/06/26 09:47:12 | 000,001,102 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-es.xml
Hosts file not found
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [hpqSRMon] File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O9 - Extra Button: Mostrar u ocultar HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 192.168.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\WINDOWS\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/25 21:30:58 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0585224d-964c-11df-9d63-001eec89d268}\Shell\AutoRun\command - "" = ino6.com
O33 - MountPoints2\{0585224d-964c-11df-9d63-001eec89d268}\Shell\explore\Command - "" = ino6.com
O33 - MountPoints2\{0585224d-964c-11df-9d63-001eec89d268}\Shell\open\Command - "" = ino6.com
O33 - MountPoints2\{05852251-964c-11df-9d63-001eec89d268}\Shell\AutoRun\command - "" = 12gn6id2.exe
O33 - MountPoints2\{05852251-964c-11df-9d63-001eec89d268}\Shell\open\Command - "" = 12gn6id2.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
NetSvcs: ezSharedSvc - C:\WINDOWS\System32\ezsvc7.dll (EasyBits Sofware AS)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010/09/09 15:08:07 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Hewlett-Packard
[2010/09/09 15:02:20 | 000,574,976 | ---- | C] (OldTimer Tools) -- C:\Users\Declan\Desktop\OTL.exe
[2010/09/09 03:54:55 | 000,000,000 | ---D | C] -- C:\Users\Declan\Desktop\virus
[2010/09/09 02:14:19 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Malwarebytes
[2010/09/09 02:14:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2010/08/29 13:02:15 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\My Karaoke
[2010/08/29 10:20:38 | 003,063,561 | ---- | C] (Macromedia, Inc.) -- C:\Users\Public\Documents\MobileTV.exe
[2010/08/29 10:20:38 | 002,989,660 | ---- | C] (Macromedia, Inc.) -- C:\Users\Public\Documents\DVD.exe
[2010/08/29 10:20:37 | 002,864,396 | ---- | C] (Macromedia, Inc.) -- C:\Users\Public\Documents\MPV.exe
[2010/08/29 10:20:37 | 002,331,174 | ---- | C] (Macromedia, Inc.) -- C:\Users\Public\Documents\Karaoke.exe
[2010/08/29 10:20:37 | 002,231,606 | ---- | C] (Macromedia, Inc.) -- C:\Users\Public\Documents\Games.exe
[2010/08/29 10:20:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\ENU
[2010/08/29 10:19:58 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\MCE Logs
[2010/08/29 10:11:02 | 000,000,000 | ---D | C] -- C:\Program Files\HP DVB-T TV Tuner
[2010/08/28 16:53:55 | 000,000,000 | ---D | C] -- C:\Users\Declan\Desktop Toolbar
[2010/08/28 04:44:59 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2010/08/28 04:44:35 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/08/28 03:25:05 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2010/08/27 14:12:04 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\HP
[2010/08/27 14:04:06 | 000,000,000 | ---D | C] -- C:\ProgramData\WEBREG
[2010/08/27 13:58:45 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2010/08/27 13:57:59 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2010/08/27 13:57:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP
[2010/08/27 13:44:08 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2010/08/27 13:13:48 | 000,017,744 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010/08/27 13:13:37 | 000,165,584 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010/08/27 13:13:34 | 000,023,376 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010/08/27 13:13:32 | 000,046,672 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010/08/27 13:13:30 | 000,050,768 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010/08/27 13:12:40 | 000,038,848 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/08/27 13:12:39 | 000,167,592 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2010/08/27 13:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010/08/27 13:12:28 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/08/27 12:54:38 | 000,000,000 | ---D | C] -- C:\ProgramData\COMODO
[2010/08/27 12:49:03 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2010/08/27 12:46:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo Downloader
[2010/08/21 21:19:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\dwhelper
[2010/08/21 20:37:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Apple Computer
[2010/08/21 20:37:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Apple Computer
[2010/08/21 20:36:20 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2010/08/21 20:35:14 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/08/21 20:33:04 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/08/21 20:33:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2010/08/21 20:32:40 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Apple
[2010/08/21 18:45:58 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Steinberg
[2010/08/21 16:35:31 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2010/08/21 16:35:24 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2010/08/21 16:35:24 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2010/08/20 19:19:38 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 07 Miles Davis
[2010/08/20 19:19:00 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 01 How To Play And Improvise Jazz
[2010/08/20 19:18:34 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 02 Nothin' But Blues
[2010/08/20 19:18:10 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 03 II V I Progression
[2010/08/20 19:17:45 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 04 Movin' On
[2010/08/20 19:17:20 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 05 Time To Play Music
[2010/08/20 19:16:50 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Aebersold Vol 06 Charlie Parker ''All Bird''
[2010/08/20 19:16:00 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Jamey Aebersold - Vol. 020 - Jimmy Raney
[2010/08/20 19:14:10 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\WinRAR
[2010/08/20 11:40:52 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Notepad Notes
[2010/08/19 00:59:24 | 000,000,000 | ---D | C] -- C:\ProgramData\NCH Swift Sound
[2010/08/19 00:58:08 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\NCH Swift Sound
[2010/08/19 00:58:08 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Swift Sound
[2010/08/19 00:32:46 | 000,000,000 | ---D | C] -- C:\Program Files\JDownloader
[2010/08/18 21:44:43 | 000,000,000 | ---D | C] -- C:\Users\Declan\Cubase audio
[2010/08/18 21:27:16 | 000,000,000 | ---D | C] -- C:\Program Files\Steinberg
[2010/08/17 16:00:38 | 000,000,000 | ---D | C] -- C:\Users\Declan\generator manuals
[2010/08/16 17:33:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2010/08/16 17:31:53 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\OpenCandy
[2010/08/16 17:31:49 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\OpenCandy
[2010/08/16 17:29:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2010/08/16 17:29:45 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp
[2010/08/07 23:46:03 | 000,000,000 | ---D | C] -- C:\Program Files\Roland
[2010/08/07 23:45:19 | 000,000,000 | ---D | C] -- C:\Program Files\PowerTracks DirectX Plugins
[2010/08/07 23:45:04 | 000,000,000 | ---D | C] -- C:\RealBand
[2010/08/07 23:43:11 | 000,000,000 | ---D | C] -- C:\bb
[2010/08/06 08:59:11 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\NeroVision
[2010/08/03 10:10:55 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\vlc
[2010/07/22 22:16:23 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Spotify
[2010/07/22 22:16:23 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Spotify
[2010/07/22 22:16:21 | 000,000,000 | ---D | C] -- C:\Program Files\Spotify
[2010/07/21 17:47:49 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Youcam
[2010/07/21 14:01:49 | 000,000,000 | ---D | C] -- C:\Program Files\ContentaConverter-PREMIUM
[2010/07/21 13:52:23 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Nero
[2010/07/21 09:57:34 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\CyberLink
[2010/07/21 09:16:17 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\REAPER Media
[2010/07/19 16:59:47 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\Nero
[2010/07/19 16:42:20 | 000,000,000 | ---D | C] -- C:\ProgramData\LightScribe
[2010/07/19 15:05:06 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\skypePM
[2010/07/19 15:04:12 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Skype
[2010/07/19 15:03:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2010/07/19 15:03:26 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2010/07/19 15:03:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2010/07/19 11:50:52 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Ahead
[2010/07/19 11:47:41 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Nero
[2010/07/19 11:44:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2010/07/19 11:44:14 | 000,000,000 | ---D | C] -- C:\Program Files\Nero
[2010/07/19 11:44:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2010/07/19 11:36:12 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\REAPER
[2010/07/16 18:28:24 | 000,000,000 | ---D | C] -- C:\Users\Declan\Documents\power2go cd burn projects
[2010/07/16 18:03:17 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\CyberLink
[2010/07/09 17:27:12 | 000,000,000 | ---D | C] -- C:\Users\Declan\.thumbnails
[2010/07/09 01:53:33 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\dvdcss
[2010/07/08 20:00:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2010/07/08 20:00:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2010/07/08 20:00:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2010/07/08 19:31:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2010/07/06 16:53:47 | 000,000,000 | ---D | C] -- C:\Windows\System32\SRSLabs
[2010/07/06 16:51:48 | 000,000,000 | ---D | C] -- C:\Program Files\LSI SoftModem
[2010/07/06 11:36:46 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\gtk-2.0
[2010/07/06 11:32:53 | 000,000,000 | ---D | C] -- C:\Users\Declan\.gimp-2.6
[2010/07/06 11:32:51 | 000,000,000 | ---D | C] -- C:\Users\Declan\.gegl-0.0
[2010/07/06 11:32:10 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2010/07/06 11:22:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\L&H
[2010/07/06 11:21:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2010/07/06 11:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2010/07/06 11:20:33 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio
[2010/07/06 11:19:56 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2010/07/06 11:19:56 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2010/07/06 11:16:25 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010/07/06 11:15:45 | 000,000,000 | ---D | C] -- C:\IUware Online
[2010/07/06 11:07:49 | 000,000,000 | ---D | C] -- C:\Program Files\REAPER
[2010/07/06 11:07:05 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2010/07/06 11:06:15 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Foxit
[2010/07/06 11:05:44 | 000,000,000 | ---D | C] -- C:\Program Files\Foxit Software
[2010/07/06 10:58:35 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2010/07/06 10:47:23 | 000,000,000 | ---D | C] -- C:\Users\Declan\Desktop\RECENT ITEMS
[2010/07/06 10:37:44 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Adobe
[2010/07/06 10:24:41 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2010/07/06 10:24:38 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2010/07/06 10:23:57 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2010/07/06 10:23:32 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Seven Zip
[2010/07/06 10:20:23 | 000,000,000 | R--D | C] -- C:\Users\Declan\Programs
[2010/07/06 10:18:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LightScribe
[2010/07/06 10:15:04 | 012,021,852 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\idtcpl.cpl
[2010/07/06 10:15:04 | 003,567,616 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stlang.dll
[2010/07/06 10:15:04 | 000,536,576 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\idtmini1.exe
[2010/07/06 10:15:04 | 000,450,652 | ---- | C] (IDT, Inc.) -- C:\Windows\sttray.exe
[2010/07/06 10:14:13 | 000,175,104 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\staco.dll
[2010/07/06 10:13:56 | 000,914,432 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stapo.dll
[2010/07/06 10:13:56 | 000,483,840 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stapi32.dll
[2010/07/06 10:13:49 | 000,000,000 | ---D | C] -- C:\Program Files\IDT
[2010/07/06 10:13:18 | 000,000,000 | ---D | C] -- C:\Windows\JMCR_DIR
[2010/07/06 10:12:51 | 000,118,784 | ---- | C] (Realtek Corporation ) -- C:\Windows\System32\drivers\Rtlh86.sys
[2010/07/06 10:12:50 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2010/07/06 10:12:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\HPMDP
[2010/07/06 10:12:24 | 000,000,000 | ---D | C] -- C:\Program Files\Apoint2K
[2010/07/06 10:09:29 | 000,053,248 | ---- | C] (Windows XP Bundled build C-Centric Single User) -- C:\Windows\System32\CSVer.dll
[2010/07/06 10:09:29 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2010/07/06 10:07:40 | 000,054,824 | ---- | C] (Agere Systems) -- C:\Windows\System32\agrsmdel.exe
[2010/07/06 10:07:21 | 000,000,000 | ---D | C] -- C:\Windows\Options
[2010/07/06 10:04:12 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2010/07/06 10:00:43 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2010/07/06 09:50:32 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Mozilla
[2010/07/06 09:50:32 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Mozilla
[2010/07/06 09:50:25 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2010/07/06 03:58:46 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2010/07/06 02:15:38 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Symantec
[2010/07/06 02:11:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2010/07/06 02:02:43 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\QuickPlay
[2010/07/06 02:02:19 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Symantec
[2010/07/06 02:02:00 | 000,000,000 | R--D | C] -- C:\Users\Declan\Searches
[2010/07/06 02:01:40 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Identities
[2010/07/06 02:01:36 | 000,000,000 | R--D | C] -- C:\Users\Declan\Contacts
[2010/07/06 01:59:07 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Macromedia
[2010/07/06 01:56:01 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Adobe
[2010/07/06 01:55:49 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Hewlett-Packard
[2010/07/06 01:53:07 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\VirtualStore
[2010/07/06 01:53:05 | 000,000,000 | --SD | C] -- C:\Users\Declan\AppData\Roaming\Microsoft
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Videos
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Saved Games
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Pictures
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Music
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Links
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Favorites
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Downloads
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Documents
[2010/07/06 01:53:05 | 000,000,000 | R--D | C] -- C:\Users\Declan\Desktop
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\AppData\Local\Temporary Internet Files
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Templates
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Start Menu
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\SendTo
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Recent
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\PrintHood
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\NetHood
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Documents\My Videos
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Documents\My Pictures
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Documents\My Music
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\My Documents
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Local Settings
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\AppData\Local\History
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Cookies
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\Application Data
[2010/07/06 01:53:05 | 000,000,000 | -HSD | C] -- C:\Users\Declan\AppData\Local\Application Data
[2010/07/06 01:53:05 | 000,000,000 | -H-D | C] -- C:\Users\Declan\AppData
[2010/07/06 01:53:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Temp
[2010/07/06 01:53:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Local\Microsoft
[2010/07/06 01:53:05 | 000,000,000 | ---D | C] -- C:\Users\Declan\AppData\Roaming\Media Center Programs
========== Files - Modified Within 90 Days ==========
[2010/09/09 15:06:53 | 002,097,152 | -HS- | M] () -- C:\Users\Declan\NTUSER.DAT
[2010/09/09 15:01:57 | 000,574,976 | ---- | M] (OldTimer Tools) -- C:\Users\Declan\Desktop\OTL.exe
[2010/09/09 14:56:41 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/09/09 14:56:40 | 000,303,670 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2010/09/09 14:56:40 | 000,303,670 | ---- | M] () -- C:\ProgramData\nvModes.001
[2010/09/09 14:56:40 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/09/09 14:56:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/09/09 12:35:04 | 000,703,388 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2010/09/09 12:35:04 | 000,595,996 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2010/09/09 12:35:04 | 000,104,070 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2010/09/09 12:29:41 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/09/09 12:29:29 | 2143,272,960 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/09 03:56:51 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2010/09/09 03:56:46 | 000,524,288 | -HS- | M] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/09/09 03:56:46 | 000,065,536 | -HS- | M] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/09/09 03:56:39 | 004,041,607 | -H-- | M] () -- C:\Users\Declan\AppData\Local\IconCache.db
[2010/09/09 00:54:48 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2010/09/07 23:39:56 | 000,003,395 | ---- | M] () -- C:\Users\Declan\.recently-used.xbel
[2010/09/07 17:12:17 | 000,038,848 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/09/07 17:11:54 | 000,167,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2010/09/07 16:52:25 | 000,046,672 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010/09/07 16:52:03 | 000,165,584 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010/09/07 16:47:46 | 000,023,376 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010/09/07 16:47:30 | 000,050,768 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010/09/07 16:47:07 | 000,017,744 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010/09/07 01:05:57 | 000,151,040 | ---- | M] () -- C:\Users\Declan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/08/31 13:13:18 | 000,010,820 | R--- | M] () -- C:\Users\Declan\Documents\Teoría de la literatura 2º ciclo.pdf
[2010/08/29 13:02:15 | 002,331,174 | ---- | M] (Macromedia, Inc.) -- C:\Users\Public\Documents\Karaoke.exe
[2010/08/29 13:01:44 | 002,989,660 | ---- | M] (Macromedia, Inc.) -- C:\Users\Public\Documents\DVD.exe
[2010/08/29 10:56:57 | 002,864,396 | ---- | M] (Macromedia, Inc.) -- C:\Users\Public\Documents\MPV.exe
[2010/08/29 10:24:53 | 000,000,356 | ---- | M] () -- C:\Users\Declan\Desktop\Downloads - Shortcut (2).lnk
[2010/08/29 10:20:48 | 003,063,561 | ---- | M] (Macromedia, Inc.) -- C:\Users\Public\Documents\MobileTV.exe
[2010/08/29 10:20:37 | 002,231,606 | ---- | M] (Macromedia, Inc.) -- C:\Users\Public\Documents\Games.exe
[2010/08/28 19:25:56 | 000,029,696 | ---- | M] () -- C:\Users\Declan\Documents\Shu Lailo Laleilo.doc
[2010/08/28 19:16:55 | 000,002,593 | ---- | M] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2010/08/28 05:02:53 | 000,618,540 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.old
[2010/08/28 03:36:44 | 000,023,684 | ---- | M] () -- C:\Windows\hpqins15.dat
[2010/08/28 03:24:54 | 278,358,886 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2010/08/27 14:09:48 | 000,157,380 | ---- | M] () -- C:\Windows\hpoins27.dat
[2010/08/27 14:03:11 | 000,000,275 | ---- | M] () -- C:\Windows\win.ini
[2010/08/27 14:02:25 | 000,001,976 | ---- | M] () -- C:\Users\Public\Desktop\HP Photosmart Essential 2.5.lnk
[2010/08/27 14:00:19 | 000,001,932 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/08/27 13:59:07 | 000,001,102 | ---- | M] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/08/25 21:10:25 | 000,034,816 | ---- | M] () -- C:\Users\Declan\Documents\MANOS III.doc
[2010/08/21 18:35:55 | 000,000,831 | ---- | M] () -- C:\Users\Declan\Desktop\Cubase SX.lnk
[2010/08/18 21:34:21 | 000,110,240 | ---- | M] () -- C:\Users\Declan\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/08/18 21:33:17 | 000,396,520 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2010/08/07 23:45:17 | 000,000,558 | ---- | M] () -- C:\Users\Declan\Desktop\RealBand.lnk
[2010/08/07 23:45:17 | 000,000,479 | ---- | M] () -- C:\Users\Declan\Desktop\Band-in-a-Box.lnk
[2010/08/05 13:14:43 | 000,000,363 | ---- | M] () -- C:\Users\Declan\Desktop\Videos - Shortcut.lnk
[2010/08/03 10:10:39 | 000,000,819 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/07/28 14:05:36 | 000,001,748 | ---- | M] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/28 11:57:00 | 000,040,448 | ---- | M] () -- C:\Users\Declan\Documents\Pedido teclado Thomann.doc
[2010/07/21 13:52:23 | 000,001,024 | ---- | M] () -- C:\Users\Declan\.rnd
[2010/07/19 11:50:29 | 000,002,510 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2010/07/16 18:29:28 | 000,010,299 | ---- | M] () -- C:\Users\Declan\Documents\Flamenco recop LATIDOS FUERTES.p2g
[2010/07/15 16:47:13 | 000,000,056 | -H-- | M] () -- C:\Windows\System32\ezsidmv.dat
[2010/07/10 12:11:26 | 000,000,362 | ---- | M] () -- C:\Users\Declan\Desktop\Music - Shortcut.lnk
[2010/07/09 17:25:43 | 000,000,371 | ---- | M] () -- C:\Users\Declan\Desktop\Pictures - Shortcut.lnk
[2010/07/08 20:38:55 | 000,272,595 | ---- | M] () -- C:\Users\Declan\Documents\iroda soldering kit manual.pdf
[2010/07/08 19:53:10 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
[2010/07/07 13:27:44 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010/07/07 13:19:31 | 000,001,699 | ---- | M] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2010/07/06 23:26:07 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2010/07/06 11:32:36 | 000,000,858 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010/07/06 11:24:24 | 000,000,376 | ---- | M] () -- C:\Windows\ODBC.INI
[2010/07/06 11:07:53 | 000,000,736 | ---- | M] () -- C:\Users\Public\Desktop\REAPER.lnk
[2010/07/06 11:06:02 | 000,001,007 | ---- | M] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/07/06 11:06:02 | 000,000,983 | ---- | M] () -- C:\Users\Public\Desktop\Foxit Reader.lnk
[2010/07/06 11:02:08 | 000,000,858 | ---- | M] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinRAR - Shortcut.lnk
[2010/07/06 10:42:27 | 000,047,092 | ---- | M] () -- C:\Windows\System32\license.rtf
[2010/07/06 10:21:26 | 000,000,372 | ---- | M] () -- C:\Users\Declan\Desktop\Documents - Shortcut.lnk
[2010/07/06 10:21:16 | 000,000,447 | ---- | M] () -- C:\Users\Declan\Desktop\Programs - Shortcut.lnk
[2010/07/06 10:13:32 | 000,000,125 | ---- | M] () -- C:\Windows\xUninstall.bat
[2010/07/06 10:12:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
[2010/07/06 07:19:24 | 000,000,256 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2010/07/06 02:27:45 | 000,588,472 | ---- | M] (EasyBits Software AS) -- C:\Windows\System32\ezsvc7x.dll
[2010/07/06 02:24:46 | 000,524,288 | -HS- | M] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010/07/06 02:01:24 | 000,000,044 | ---- | M] () -- C:\Windows\System\hpsysdrv.dat
[2010/07/06 01:53:59 | 000,000,000 | RHS- | M] () -- C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND8331P02_E464624-033_4A_I30F8_SCompal_V99.87_F.24_T081125_WV3-1_L409_M2046_J250_7Intel_8676_92.00_#100706_N10EC8168;80864237_(FM193EA#ABU)_XMOBILE_CN10_Z_2F.24.MRK
[2010/07/06 01:53:05 | 000,000,020 | -HS- | M] () -- C:\Users\Declan\ntuser.ini
========== Files Created - No Company Name ==========
[2010/09/07 23:39:56 | 000,003,395 | ---- | C] () -- C:\Users\Declan\.recently-used.xbel
[2010/08/31 13:13:20 | 000,010,820 | R--- | C] () -- C:\Users\Declan\Documents\Teoría de la literatura 2º ciclo.pdf
[2010/08/29 10:24:53 | 000,000,356 | ---- | C] () -- C:\Users\Declan\Desktop\Downloads - Shortcut (2).lnk
[2010/08/28 19:25:55 | 000,029,696 | ---- | C] () -- C:\Users\Declan\Documents\Shu Lailo Laleilo.doc
[2010/08/28 03:35:39 | 000,023,684 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/08/28 03:29:44 | 000,000,000 | ---- | C] () -- C:\Users\Declan\AppData\Local\FnF4.txt
[2010/08/28 03:24:54 | 278,358,886 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2010/08/27 14:02:25 | 000,001,976 | ---- | C] () -- C:\Users\Public\Desktop\HP Photosmart Essential 2.5.lnk
[2010/08/27 14:00:19 | 000,001,932 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2010/08/27 13:59:07 | 000,001,102 | ---- | C] () -- C:\Users\Public\Desktop\HP Solution Center.lnk
[2010/08/27 13:52:30 | 000,157,380 | ---- | C] () -- C:\Windows\hpoins27.dat
[2010/08/27 13:52:30 | 000,001,181 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2010/08/27 13:52:30 | 000,000,932 | ---- | C] () -- C:\Windows\hpomdl27.dat
[2010/08/25 14:04:47 | 000,034,816 | ---- | C] () -- C:\Users\Declan\Documents\MANOS III.doc
[2010/08/21 18:35:55 | 000,000,831 | ---- | C] () -- C:\Users\Declan\Desktop\Cubase SX.lnk
[2010/08/20 16:07:53 | 000,000,133 | ---- | C] () -- C:\Users\Declan\Documents\The Musicians Library.url
[2010/08/20 16:07:50 | 032,224,469 | ---- | C] () -- C:\Users\Declan\Documents\Horace Silver - The Art Of Small Combo Jazz Playing, Composing & Arranging(36pp).pdf
[2010/08/20 15:20:48 | 007,599,240 | ---- | C] () -- C:\Users\Declan\Documents\BEYER ESCOLA PREPARATORIA PIANO.pdf
[2010/08/07 23:45:17 | 000,153,064 | ---- | C] () -- C:\Windows\System32\Pgchords.ttf
[2010/08/07 23:45:17 | 000,059,004 | ---- | C] () -- C:\Windows\System32\Pgtextj_.ttf
[2010/08/07 23:45:17 | 000,059,004 | ---- | C] () -- C:\Windows\System\Pgtextj_.ttf
[2010/08/07 23:45:17 | 000,051,864 | ---- | C] () -- C:\Windows\System32\Pgtextje.ttf
[2010/08/07 23:45:17 | 000,051,864 | ---- | C] () -- C:\Windows\System\Pgtextje.ttf
[2010/08/07 23:45:17 | 000,049,896 | ---- | C] () -- C:\Windows\System32\Pgtext.ttf
[2010/08/07 23:45:17 | 000,048,072 | ---- | C] () -- C:\Windows\System32\Pgjazz__.ttf
[2010/08/07 23:45:17 | 000,047,252 | ---- | C] () -- C:\Windows\System32\pgmus.ttf
[2010/08/07 23:45:17 | 000,000,558 | ---- | C] () -- C:\Users\Declan\Desktop\RealBand.lnk
[2010/08/07 23:45:17 | 000,000,479 | ---- | C] () -- C:\Users\Declan\Desktop\Band-in-a-Box.lnk
[2010/08/07 23:45:16 | 000,153,064 | ---- | C] () -- C:\Windows\System\Pgchords.ttf
[2010/08/07 23:45:16 | 000,049,896 | ---- | C] () -- C:\Windows\System\Pgtext.ttf
[2010/08/07 23:45:16 | 000,048,072 | ---- | C] () -- C:\Windows\System\Pgjazz__.ttf
[2010/08/07 23:45:16 | 000,047,252 | ---- | C] () -- C:\Windows\System\pgmus.ttf
[2010/08/05 13:14:43 | 000,000,363 | ---- | C] () -- C:\Users\Declan\Desktop\Videos - Shortcut.lnk
[2010/08/03 10:10:39 | 000,000,819 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/07/28 14:05:36 | 000,001,748 | ---- | C] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/07/28 11:56:59 | 000,040,448 | ---- | C] () -- C:\Users\Declan\Documents\Pedido teclado Thomann.doc
[2010/07/19 11:50:29 | 000,002,510 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart.lnk
[2010/07/19 11:47:07 | 000,001,024 | ---- | C] () -- C:\Users\Declan\.rnd
[2010/07/16 18:29:28 | 000,010,299 | ---- | C] () -- C:\Users\Declan\Documents\Flamenco recop LATIDOS FUERTES.p2g
[2010/07/15 16:47:13 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/07/10 11:41:16 | 000,151,040 | ---- | C] () -- C:\Users\Declan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/07/09 17:25:43 | 000,000,371 | ---- | C] () -- C:\Users\Declan\Desktop\Pictures - Shortcut.lnk
[2010/07/08 20:38:53 | 000,272,595 | ---- | C] () -- C:\Users\Declan\Documents\iroda soldering kit manual.pdf
[2010/07/08 19:53:10 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_HpqKbFiltr_01005.Wdf
[2010/07/07 13:27:44 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010/07/07 13:19:31 | 000,001,699 | ---- | C] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Notepad.lnk
[2010/07/07 13:18:54 | 000,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2010/07/07 13:18:51 | 000,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man
[2010/07/07 13:18:40 | 000,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf
[2010/07/07 13:18:38 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/07/07 13:18:37 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/07/07 13:18:35 | 003,662,128 | ---- | C] () -- C:\Windows\System32\locale.nls
[2010/07/07 13:18:35 | 000,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf
[2010/07/07 13:18:30 | 000,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf
[2010/07/07 13:18:14 | 000,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF
[2010/07/07 13:18:11 | 000,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs
[2010/07/07 13:17:15 | 000,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml
[2010/07/07 13:17:10 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
[2010/07/06 23:26:07 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2010/07/06 11:32:43 | 000,002,593 | ---- | C] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2010/07/06 11:32:36 | 000,000,858 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2010/07/06 11:24:24 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/07/06 11:07:53 | 000,000,736 | ---- | C] () -- C:\Users\Public\Desktop\REAPER.lnk
[2010/07/06 11:06:02 | 000,001,007 | ---- | C] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\Foxit Reader.lnk
[2010/07/06 11:06:02 | 000,000,983 | ---- | C] () -- C:\Users\Public\Desktop\Foxit Reader.lnk
[2010/07/06 11:02:08 | 000,000,858 | ---- | C] () -- C:\Users\Declan\Application Data\Microsoft\Internet Explorer\Quick Launch\WinRAR - Shortcut.lnk
[2010/07/06 10:24:01 | 000,000,256 | ---- | C] () -- C:\Users\Public\Documents\hpqp.ini
[2010/07/06 10:21:32 | 000,000,362 | ---- | C] () -- C:\Users\Declan\Desktop\Music - Shortcut.lnk
[2010/07/06 10:21:26 | 000,000,372 | ---- | C] () -- C:\Users\Declan\Desktop\Documents - Shortcut.lnk
[2010/07/06 10:21:16 | 000,000,447 | ---- | C] () -- C:\Users\Declan\Desktop\Programs - Shortcut.lnk
[2010/07/06 10:18:10 | 000,303,670 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/07/06 10:17:42 | 000,303,670 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2010/07/06 10:15:05 | 000,015,222 | ---- | C] () -- C:\Windows\System32\nbspkrs.ico
[2010/07/06 10:15:05 | 000,003,774 | ---- | C] () -- C:\Windows\System32\bltinmic.ico
[2010/07/06 10:15:05 | 000,003,774 | ---- | C] () -- C:\Windows\System32\2hps.ico
[2010/07/06 10:13:32 | 000,000,125 | ---- | C] () -- C:\Windows\xUninstall.bat
[2010/07/06 10:13:18 | 000,015,086 | ---- | C] () -- C:\Windows\System32\jmcr_xd.ico
[2010/07/06 10:13:18 | 000,015,086 | ---- | C] () -- C:\Windows\System32\jmcr_ms.ico
[2010/07/06 10:13:18 | 000,015,086 | ---- | C] () -- C:\Windows\System32\jmcr_mmc.ico
[2010/07/06 10:12:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_Apfiltr_01005.Wdf
[2010/07/06 10:05:46 | 2143,272,960 | -HS- | C] () -- C:\hiberfil.sys
[2010/07/06 04:43:39 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2010/07/06 04:43:37 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2010/07/06 03:56:53 | 000,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2010/07/06 02:50:30 | 002,501,921 | ---- | C] () -- C:\Windows\System32\wlan.tmf
[2010/07/06 02:02:37 | 000,000,000 | ---- | C] () -- C:\Users\Declan\AppData\Local\QSwitch.txt
[2010/07/06 02:02:37 | 000,000,000 | ---- | C] () -- C:\Users\Declan\AppData\Local\DSwitch.txt
[2010/07/06 02:02:37 | 000,000,000 | ---- | C] () -- C:\Users\Declan\AppData\Local\AtStart.txt
[2010/07/06 02:01:24 | 000,000,044 | ---- | C] () -- C:\Windows\System\hpsysdrv.dat
[2010/07/06 01:53:59 | 000,000,000 | RHS- | C] () -- C:\Windows\System32\drivers\103C_HP_cNB_Pavilion dv4 Notebook PC_Y5335KV_0U_QCND8331P02_E464624-033_4A_I30F8_SCompal_V99.87_F.24_T081125_WV3-1_L409_M2046_J250_7Intel_8676_92.00_#100706_N10EC8168;80864237_(FM193EA#ABU)_XMOBILE_CN10_Z_2F.24.MRK
[2010/07/06 01:53:05 | 002,097,152 | -HS- | C] () -- C:\Users\Declan\NTUSER.DAT
[2010/07/06 01:53:05 | 000,524,288 | -HS- | C] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms
[2010/07/06 01:53:05 | 000,524,288 | -HS- | C] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/07/06 01:53:05 | 000,262,144 | -H-- | C] () -- C:\Users\Declan\ntuser.dat.LOG1
[2010/07/06 01:53:05 | 000,065,536 | -HS- | C] () -- C:\Users\Declan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/07/06 01:53:05 | 000,000,020 | -HS- | C] () -- C:\Users\Declan\ntuser.ini
[2010/07/06 01:53:05 | 000,000,000 | -H-- | C] () -- C:\Users\Declan\ntuser.dat.LOG2
[2006/11/02 14:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 09:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2003/01/07 15:05:08 | 000,002,695 | ---- | C] () -- C:\Windows\System32\OUTLPERF.INI
========== LOP Check ==========
[2010/07/06 11:06:15 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\Foxit
[2010/09/07 23:39:56 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\gtk-2.0
[2010/08/19 00:58:08 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\NCH Swift Sound
[2010/08/16 17:31:49 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\OpenCandy
[2010/07/21 09:25:56 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\REAPER
[2010/09/01 17:35:25 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\Spotify
[2010/08/21 21:25:58 | 000,000,000 | ---D | M] -- C:\Users\Declan\AppData\Roaming\Steinberg
[2010/09/09 03:56:56 | 000,032,580 | ---- | M] () -- C:\WINDOWS\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2008/06/25 21:30:58 | 000,000,074 | ---- | M] () -- C:\autoexec.bat
[2009/04/11 08:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2006/09/18 23:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2010/09/09 12:29:29 | 2143,272,960 | -HS- | M] () -- C:\hiberfil.sys
[2010/09/09 12:29:28 | 2459,127,808 | -HS- | M] () -- C:\pagefile.sys
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/21 05:14:18 | 016,846,848 | ---- | M] () -- C:\WINDOWS\System32\config\COMPONENTS.SAV
[2008/01/21 05:14:08 | 000,106,496 | ---- | M] () -- C:\WINDOWS\System32\config\DEFAULT.SAV
[2008/01/21 05:14:18 | 000,020,480 | ---- | M] () -- C:\WINDOWS\System32\config\SECURITY.SAV
[2006/11/02 12:34:08 | 010,133,504 | ---- | M] () -- C:\WINDOWS\System32\config\SOFTWARE.SAV
[2006/11/02 12:34:08 | 001,826,816 | ---- | M] () -- C:\WINDOWS\System32\config\SYSTEM.SAV
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-07 08:35:21
< End of report >
OTL Extras logfile created on: 09/09/2010 15:03:54 - Run 1
OTL by OldTimer - Version 3.2.11.0 Folder = C:\Users\Declan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18943)
Locale: 0000040A | Country: Spain | Language: ESP | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 47,00% Memory free
4,00 Gb Paging File | 3,00 Gb Available in Paging File | 72,00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223,41 Gb Total Space | 105,43 Gb Free Space | 47,19% Space Free | Partition Type: NTFS
Drive D: | 9,48 Gb Total Space | 1,64 Gb Free Space | 17,30% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DECLAN-PC
Current User Name: Declan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 1
"InternetSettingsDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10539A62-D5D8-4920-86E2-042BA72BD9EC}" = dir=in | app=c:\program files\cyberlink\powerdirector\pdr.exe |
"{17B54CA4-6113-4B20-8A75-7C7CC3E481B6}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqcopy2.exe |
"{1E57CB5A-BABA-4FE7-A83B-F2416CD4851D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{254CFF87-318C-4E8C-8CE6-5DFA2C50621A}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{3CC48420-DFC4-47F8-81B9-CF45E624D802}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{619F92D5-3946-4BC0-B7C6-C1ABA25847E2}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgh.exe |
"{665CBDE8-9C86-4350-8264-A134F09444E8}" = dir=in | app=c:\program files\hp\digital imaging\smart web printing\smartwebprintexe.exe |
"{7B0C5D11-90DA-4C8C-9234-42E61736E960}" = dir=in | app=c:\program files\hp\quickplay\qp.exe |
"{7CFB7D5B-47C8-4E21-9783-C466ED5DD0C1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqkygrp.exe |
"{92A944AF-6253-45C5-8B57-70CE8AEBFEA7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqusgm.exe |
"{9A7B84CC-B7BB-4C06-8D79-7B1D73F33FCC}" = dir=in | app=c:\program files\hp\hp software update\hpwucli.exe |
"{9CE2CEC8-7C3B-4913-AEF2-D9BE04FDB194}" = dir=in | app=c:\program files\hp\quickplay\qpservice.exe |
"{CEF03202-88BC-43E0-B9AB-24BFBE1EEC0D}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{CFFAF50C-5750-4211-9636-2BBB591C5353}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{D2151713-23C5-467D-8231-F1CEFE18BAB7}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpiscnapp.exe |
"{DDAA58B6-CB69-4DB8-9DB8-2EE2D9FFA2D1}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqste08.exe |
"{ED5AF323-1BC6-4D28-9DD9-AF55B4F4957B}" = dir=in | app=c:\program files\hp\digital imaging\bin\hposid01.exe |
"{FFEB30E6-B7FD-48C6-8A88-3C623094767C}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqgpc01.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{22712FAD-DE04-4D50-82A6-3C7AC5D55AA2}" = HP User Guides 0101
"{228C6B46-64E2-404E-898A-EF0830603EF4}" = HPNetworkAssistant
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron JMB38X Flash Media Controller
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java 6 Update 20
"{30DAA715-5032-40F9-A0AE-95C9AEBB3E3F}" = HP QuickTouch 1.00 D2
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java 6 Update 5
"{340F521E-3576-4E1A-B75C-EB0ACF751379}" = HP Wireless Assistant
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.40 D3
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{35F83303-C0C0-46B7-B8A8-ADA7C2AC5645}" = muvee autoProducer 6.1
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3921A67A-5AB1-4E48-9444-C71814CF3027}" = VCRedistSetup
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45A136EC-88BF-4B95-99F5-C45D3930E1CC}" = HP MULTIPLE MODEM INSTALLER for VISTA
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{582287DA-0806-4AC0-BF19-C15E3A466034}" = LightScribe System Software 1.12.33.2
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5FCCD531-1B38-4A94-924C-127F722F1034}" = Nero 8
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{745877DC-8FFE-4E4C-ABBC-589B887A47D1}" = Virtual Sound Canvas DXi
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{9E2CCD5E-1990-4EF2-9B61-32F0BBACC29B}" = HP Active Support Library
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{AAD72731-807A-4B79-AE05-9190B7002B7B}" = ProtectSmart Hard Drive Protection
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AD72CFB4-C2BF-424E-9DF0-C7BAD1F30A11}" = Adobe Shockwave Player
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{C8FD5BC1-92EF-4C15-92A9-F9AC7F61985F}" = HP Update
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC6B1BB4-4E06-4A5B-A166-B371B551324B}" = COMODO Internet Security
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D642E38E-0D24-486C-9A2D-E316DD696F4B}" = Microsoft XML Parser
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{DA22A6BB-10B5-4595-BD59-1AD4023C8536}" = Virtual Sound Canvas VST
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agere Systems Soft Modem" = Agere Systems HDA Modem
"avast5" = avast! Free Antivirus
"BB_is1" = RealTracks Set 7
"ContentaConverter-PREMIUM" = Contenta Converter PREMIUM
"ERUNT_is1" = ERUNT 1.1j
"Foxit Reader" = Foxit Reader
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"JDownloader" = JDownloader
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.8)" = Mozilla Firefox (3.6.8)
"NVIDIA Drivers" = NVIDIA Drivers
"PG Music DirectX Plugins_is1" = PG Music DirectX Plugins 2.0.0.0
"REAPER" = REAPER
"Shop for HP Supplies" = Shop for HP Supplies
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.6
"Spotify" = Spotify
"Stamp" = Stamp ID3 Tag Editor
"Steinberg Cubase SX 1.01" = Steinberg Cubase SX 1.01
"VLC media player" = VLC media player 1.1.2
"WinGimp-2.0_is1" = GIMP 2.6.4
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 06/09/2010 19:05:09 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x6001bb69, process id 0x1758,
application start time 0x01cb4e17f2f97480.
Error - 06/09/2010 19:05:29 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x6001bb69, process id 0x11ec,
application start time 0x01cb4e17fed223b0.
Error - 06/09/2010 19:05:33 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x6001bb69, process id 0xa08,
application start time 0x01cb4e18015b66a0.
Error - 06/09/2010 19:06:06 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x6001bb69, process id 0x13c0,
application start time 0x01cb4e181036a770.
Error - 06/09/2010 19:06:10 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application DllHost.exe, version 6.0.6000.16386, time stamp
0x4549b14e, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x6001bb69, process id 0x858,
application start time 0x01cb4e1817142950.
Error - 07/09/2010 19:41:01 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application rundll32.exe, version 6.0.6000.16386, time stamp
0x4549b0e1, faulting module QuickTime.cpl, version 7.66.73.0, time stamp 0x4ba30659,
exception code 0xc0000409, fault offset 0x0000a90a, process id 0x1c88, application
start time 0x01cb4ee61e021a50.
Error - 07/09/2010 19:47:36 | Computer Name = Declan-PC | Source = Application Error | ID = 1000
Description = Faulting application MsiExec.exe, version 4.5.6002.18005, time stamp
0x49e01c42, faulting module QuickTime.qts_unloaded, version 0.0.0.0, time stamp
0x4ba307c0, exception code 0xc0000005, fault offset 0x5ff2bb69, process id 0x119c,
application start time 0x01cb4ee70c267550.
Error - 08/09/2010 18:31:41 | Computer Name = Declan-PC | Source = WinMgmt | ID = 10
Description =
Error - 08/09/2010 19:10:14 | Computer Name = Declan-PC | Source = WinMgmt | ID = 10
Description =
Error - 08/09/2010 19:12:30 | Computer Name = Declan-PC | Source = VSS | ID = 8194
Description =
[ System Events ]
Error - 20/07/2010 3:56:05 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 20/07/2010 20:10:36 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 20/07/2010 20:11:54 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 21/07/2010 7:03:34 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 21/07/2010 7:03:42 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 21/07/2010 7:27:03 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 21/07/2010 7:28:33 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 21/07/2010 14:05:15 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7000
Description =
Error - 21/07/2010 14:06:48 | Computer Name = Declan-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 22/07/2010 3:58:57 | Computer Name = Declan-PC | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.0.193 for the Network Card with network
address 0016EAB9DD9C has been denied by the DHCP server 192.168.0.1 (The DHCP Server
sent a DHCPNACK message).
< End of report >