OTL logfile created on: 2/3/2010 1:26:05 PM - Run 1
OTL by OldTimer - Version 3.1.27.1 Folder = C:\Users\Cornel\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18882)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 25.00% Memory free
8.00 Gb Paging File | 3.00 Gb Available in Paging File | 36.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 325.63 Gb Total Space | 207.81 Gb Free Space | 63.82% Space Free | Partition Type: NTFS
Drive D: | 9.72 Gb Total Space | 1.30 Gb Free Space | 13.37% Space Free | Partition Type: NTFS
Drive E: | 335.35 Gb Total Space | 334.60 Gb Free Space | 99.78% Space Free | Partition Type: NTFS
Drive F: | 620.36 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive K: | 2.35 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive M: | 74.50 Gb Total Space | 21.62 Gb Free Space | 29.01% Space Free | Partition Type: FAT32
Computer Name: DESKTOPPCHOME
Current User Name: Cornel
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ========== PRC - [2010/02/03 13:24:57 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\Cornel\Downloads\OTL.exe
PRC - [2010/02/01 22:03:00 | 000,279,296 | ---- | M] () -- C:\Users\Cornel\AppData\Local\tdltim\tultsftav.exe
PRC - [2010/02/01 22:02:58 | 000,279,296 | ---- | M] () -- C:\Users\Cornel\AppData\Local\ewgyhv\tejisftav.exe
PRC - [2010/01/28 17:09:31 | 002,757,512 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010/01/28 17:09:28 | 000,040,384 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/01/15 08:44:10 | 000,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/12/12 08:55:52 | 002,043,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG8\avgtray.exe
PRC - [2009/11/19 22:12:14 | 000,623,960 | ---- | M] (Research In Motion Limited) -- C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe
PRC - [2009/11/18 12:47:14 | 001,243,088 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Spyware Doctor\pctsTray.exe
PRC - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe
PRC - [2009/11/01 18:29:28 | 000,136,176 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.2.183.13\GoogleCrashHandler.exe
PRC - [2009/10/09 13:11:12 | 025,623,336 | R--- | M] (Skype Technologies S.A.) -- C:\Program Files (x86)\Skype\Phone\Skype.exe
PRC - [2009/10/09 13:11:12 | 000,078,008 | R--- | M] (Skype Technologies) -- C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
PRC - [2009/08/28 09:57:14 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe
PRC - [2009/02/23 18:43:12 | 000,576,000 | ---- | M] (MagicISO, Inc.) -- C:\Program Files (x86)\MagicDisc\MagicDisc.exe
PRC - [2008/09/15 10:34:16 | 007,218,472 | R--- | M] (Dassault Systèmes SolidWorks Corp.) -- C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe
PRC - [2008/08/15 13:26:26 | 000,067,128 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
PRC - [2008/08/14 16:15:46 | 002,407,184 | ---- | M] () -- C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
PRC - [2008/08/14 16:11:48 | 000,565,008 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
PRC - [2008/08/14 16:11:14 | 000,447,248 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2008/07/26 07:25:36 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2008/06/05 09:19:18 | 000,479,232 | ---- | M] (Nikon Corporation) -- C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
PRC - [2008/05/15 08:17:34 | 000,181,544 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer3\TeamViewer_Host.exe
PRC - [2008/01/25 13:32:56 | 000,689,416 | ---- | M] (Logitech, Inc.) -- C:\Program Files (x86)\Logitech\QuickCam\LU\LogitechUpdate.exe
PRC - [2008/01/25 13:32:48 | 000,191,240 | ---- | M] (Logitech, Inc.) -- c:\Program Files (x86)\Logitech\QuickCam\LU\LULnchr.exe
PRC - [2007/11/19 17:54:04 | 000,079,136 | ---- | M] (Hewlett-Packard Company) -- c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/08/23 01:35:00 | 000,243,064 | ---- | M] (Symantec Corporation) -- c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/07/12 19:36:12 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/07/12 19:36:10 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/05/08 19:24:20 | 000,054,840 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe
PRC - [2007/04/18 10:01:34 | 000,065,536 | ---- | M] (Hewlett-Packard Company) -- C:\hp\support\hpsysdrv.exe
PRC - [2007/04/07 05:56:47 | 000,132,760 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe
PRC - [2005/02/02 10:44:24 | 000,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\hp\KBD\kbd.exe
PRC - [2002/02/14 16:13:22 | 000,323,584 | ---- | M] () -- C:\Program Files (x86)\Infinite Mind LC\eyeQ\ARLaunch.exe
========== Modules (SafeList) ========== MOD - [2010/02/03 13:24:57 | 000,548,864 | ---- | M] (OldTimer Tools) -- C:\Users\Cornel\Downloads\OTL.exe
MOD - [2009/10/30 11:18:16 | 000,147,024 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Spyware Doctor\PCTGMhk.dll
MOD - [2009/09/09 22:54:58 | 000,245,824 | ---- | M] (PC Tools) -- C:\Program Files (x86)\Spyware Doctor\smum32.dll
MOD - [2008/07/26 07:25:24 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\Windows\Temp\logishrd\LVPrcInj01.dll
MOD - [2008/01/20 21:50:03 | 000,450,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\comdlg32.dll
MOD - [2008/01/20 21:48:06 | 001,684,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2010/01/28 17:09:28 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV:
64bit: - [2010/01/28 17:09:28 | 000,040,384 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV:
64bit: - [2010/01/28 17:09:28 | 000,040,384 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:
64bit: - [2008/07/26 07:25:24 | 000,187,928 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:
64bit: - [2008/07/26 07:23:54 | 000,255,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe -- (LVCOMSer)
SRV:
64bit: - [2008/05/08 13:16:36 | 000,425,216 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysNative\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV:
64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2007/12/20 09:41:56 | 000,036,096 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\uxtuneup.dll -- (UxTuneUp)
SRV:
64bit: - [2007/10/18 06:37:22 | 000,412,672 | ---- | M] () [Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.exe -- (XAudioService)
SRV - [2009/11/06 14:29:22 | 001,141,712 | ---- | M] (PC Tools) [Auto | Running] -- C:\Program Files (x86)\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2009/10/02 04:25:50 | 000,120,640 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2009/09/14 20:20:30 | 000,079,360 | ---- | M] (SolidWorks) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe -- (SolidWorks Licensing Service)
SRV - [2009/08/28 09:57:14 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG8\avgwdsvc.exe -- (avg8wd)
SRV - [2009/08/24 07:16:12 | 000,378,368 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2009/05/28 09:48:33 | 000,133,104 | ---- | M] (Google Inc.) [Auto | Stopped] -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate1c9dfa364ced4fd) Google Update Service (gupdate1c9dfa364ced4fd)
SRV - [2009/05/28 09:47:30 | 000,183,280 | ---- | M] (Google) [Auto | Stopped] -- C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc)
SRV - [2008/09/09 05:01:32 | 000,079,144 | ---- | M] (Dassault Systèmes SolidWorks Corp.) [On_Demand | Stopped] -- C:\Program Files (x86)\SolidWorks Corp\SolidWorks\swScheduler\DTSCoordinatorService.exe -- (CoordinatorServiceHost)
SRV - [2008/07/27 13:01:49 | 000,093,184 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
SRV - [2008/05/15 08:17:34 | 000,181,544 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer3\TeamViewer_Host.exe -- (TeamViewer)
SRV - [2008/05/13 13:30:49 | 000,085,096 | ---- | M] (Autodesk) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe -- (Autodesk Licensing Service)
SRV - [2008/05/08 19:34:10 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service)
SRV - [2008/05/08 13:08:41 | 000,068,096 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe -- (Macromedia Licensing Service)
SRV - [2008/02/28 14:31:48 | 000,057,920 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2008/02/27 07:24:12 | 000,020,480 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2007/12/20 09:41:56 | 000,029,440 | ---- | M] (TuneUp Software GmbH) [Auto | Running] -- C:\Windows\SysWOW64\uxtuneup.dll -- (UxTuneUp)
SRV - [2007/11/19 17:54:04 | 000,079,136 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService)
SRV - [2007/09/19 20:30:52 | 000,065,536 | ---- | M] (Hewlett-Packard) [Auto | Running] -- c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe -- (HP Health Check Service)
SRV - [2007/08/23 01:35:00 | 003,192,184 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- c:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE -- (LiveUpdate)
SRV - [2007/08/23 01:35:00 | 000,243,064 | ---- | M] (Symantec Corporation) [Auto | Running] -- c:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe -- (Automatic LiveUpdate Scheduler)
SRV - [2007/07/12 19:36:12 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel(R)
SRV - [2007/05/24 06:08:44 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2007/01/24 14:11:46 | 000,428,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/01/24 14:11:34 | 000,206,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)
SRV - [2006/11/02 08:34:14 | 000,000,000 | ---D | M] [Unknown | Stopped] -- C:\Windows\SysWOW64\Msdtc -- (MSDTC)
SRV - [2006/11/02 01:35:15 | 000,060,994 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vds.mof -- (vds)
SRV - [2006/11/02 01:35:15 | 000,055,846 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\wbem\vss.mof -- (VSS)
SRV - [2005/04/03 23:41:10 | 000,069,632 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2010/01/28 16:57:59 | 000,051,280 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:
64bit: - [2010/01/28 16:57:40 | 000,120,912 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:
64bit: - [2010/01/28 16:54:45 | 000,028,752 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:
64bit: - [2010/01/28 16:54:30 | 000,063,568 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2010/01/28 16:54:07 | 000,022,096 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:
64bit: - [2009/11/09 11:20:10 | 000,218,056 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
DRV:
64bit: - [2009/10/02 04:25:36 | 000,087,384 | ---- | M] () [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:
64bit: - [2009/08/28 09:58:05 | 000,033,416 | ---- | M] () [File_System | System | Running] -- C:\Windows\SysNative\Drivers\avgmfx64.sys -- (AvgMfx64)
DRV:
64bit: - [2009/08/28 09:57:58 | 000,427,016 | ---- | M] () [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\avgldx64.sys -- (AvgLdx64)
DRV:
64bit: - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\mcdbus.sys -- (mcdbus)
DRV:
64bit: - [2009/01/09 15:02:08 | 000,031,744 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\RimSerial_AMD64.sys -- (RimVSerPort)
DRV:
64bit: - [2008/07/26 10:26:32 | 000,050,072 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:
64bit: - [2008/07/26 10:25:46 | 000,790,424 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lvrs64.sys -- (LVRS64)
DRV:
64bit: - [2008/07/26 10:22:32 | 002,624,408 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV:
64bit: - [2008/07/26 10:22:20 | 000,015,768 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lv302a64.sys -- (lvpepf64)
DRV:
64bit: - [2008/07/26 07:24:40 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2Mon)
DRV:
64bit: - [2008/07/26 07:24:40 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2M64)
DRV:
64bit: - [2008/07/24 17:46:08 | 000,072,216 | ---- | M] () [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:
64bit: - [2008/05/20 19:33:36 | 000,028,416 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:
64bit: - [2008/02/28 14:31:08 | 000,011,552 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lmimirr.sys -- (lmimirr)
DRV:
64bit: - [2008/02/12 06:50:14 | 000,286,208 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAXHWBS3.sys -- (CAXHWBS3)
DRV:
64bit: - [2008/02/12 06:48:10 | 000,740,864 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_CNXT.sys -- (winachsf)
DRV:
64bit: - [2008/02/12 06:47:08 | 001,481,216 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\CAX_DP.sys -- (HSF_DP)
DRV:
64bit: - [2008/01/20 21:49:47 | 000,011,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\RootMdm.sys -- (ROOTMODEM)
DRV:
64bit: - [2008/01/20 21:47:28 | 000,046,080 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:
64bit: - [2008/01/20 21:47:04 | 000,098,816 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbaudio.sys -- (usbaudio) USB Audio Driver (WDM)
DRV:
64bit: - [2008/01/20 21:46:52 | 000,019,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\usb8023x.sys -- (usb_rndisx)
DRV:
64bit: - [2007/10/18 06:37:10 | 000,010,240 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\xaudio64.sys -- (XAudio)
DRV:
64bit: - [2007/10/03 11:18:20 | 000,136,704 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2007/07/12 11:35:44 | 000,381,976 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iastor.sys -- (iaStor)
DRV:
64bit: - [2007/06/13 08:49:46 | 001,493,120 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\ZS211.sys -- (ZSMC211) ZSMC USB PC Camera (ZS0211)
DRV:
64bit: - [2006/06/19 09:27:24 | 000,017,024 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\mdmxsdk.sys -- (mdmxsdk)
DRV - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/02/28 14:31:50 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
DRV - [2006/09/18 16:36:40 | 000,003,066 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysWOW64\wbem\tcpip.mof -- (Tcpip)
DRV - [2006/09/18 16:35:23 | 000,001,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\wbem\mpsdrv.mof -- (mpsdrv)
DRV - [2006/06/19 09:26:50 | 000,094,208 | ---- | M] (Conexant) [Kernel | Auto | Running] -- C:\Windows\SysWOW64\mdmxsdk.dll -- (mdmxsdk)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktopIE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktopIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktopIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktop IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=81&bd=Pavilion&pf=desktopIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
========== FireFox ========== FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "
www.spiegel.de"FF - prefs.js..extensions.enabledItems:
piclens@cooliris.com:1.11.5
FF - prefs.js..extensions.enabledItems:
moveplayer@movenetworks.com:1.0.0.071303000006
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files (x86)\AVG\AVG8\Toolbar\Firefox\avg@igeared [2009/06/24 08:08:32 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/01/15 08:44:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/01/15 08:44:12 | 000,000,000 | ---D | M]
[2008/06/19 10:42:56 | 000,000,000 | ---D | M] -- C:\Users\Cornel\AppData\Roaming\Mozilla\Extensions
[2010/02/03 11:02:38 | 000,000,000 | ---D | M] -- C:\Users\Cornel\AppData\Roaming\Mozilla\Firefox\Profiles\7kklvoj5.default\extensions
[2008/07/23 07:14:50 | 000,000,000 | ---D | M] (Live PageRank) -- C:\Users\Cornel\AppData\Roaming\Mozilla\Firefox\Profiles\7kklvoj5.default\extensions\{8061ddcf-3632-4287-8d8a-133e219ae838}
[2009/06/22 16:04:33 | 000,000,000 | ---D | M] -- C:\Users\Cornel\AppData\Roaming\Mozilla\Firefox\Profiles\7kklvoj5.default\extensions\moveplayer@movenetworks.com
[2009/10/30 09:28:23 | 000,000,000 | ---D | M] -- C:\Users\Cornel\AppData\Roaming\Mozilla\Firefox\Profiles\7kklvoj5.default\extensions\piclens@cooliris.com
[2009/10/30 09:28:23 | 000,000,000 | ---D | M] -- C:\Users\Cornel\AppData\Roaming\Mozilla\Firefox\Profiles\7kklvoj5.default\extensions\piclens@cooliris.com-trash
[2008/06/19 10:42:44 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2008/09/05 18:58:42 | 000,155,648 | ---- | M] (Dassault Systèmes SolidWorks Corp.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npEModelPlugin.dll
[2008/10/13 17:51:32 | 000,221,184 | ---- | M] (CNN) -- C:\Program Files (x86)\Mozilla Firefox\plugins\NPTURNMED.dll
O1 HOSTS File: ([2010/02/02 10:01:51 | 000,001,302 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 swp2009.com
O1 - Hosts: 127.0.0.1 spyprotect2009.com
O1 - Hosts: 127.0.0.1 sp-protect2009.com
O1 - Hosts: 127.0.0.1 sys-protection.com
O1 - Hosts: 127.0.0.1 sysguard2009.com
O1 - Hosts: 127.0.0.1 os-protection.com
O1 - Hosts: 127.0.0.1 spy-protect-2009.com
O1 - Hosts: 127.0.0.1 spywprotect.com
O1 - Hosts: 127.0.0.1 adwareguard.net
O1 - Hosts: 127.0.0.1 antivirus-win.com
O1 - Hosts: 127.0.0.1 spywrprotect-2009.com
O1 - Hosts: 127.0.0.1 sysprotect.net
O1 - Hosts: 127.0.0.1 spwprotect2009.com
O1 - Hosts: 127.0.0.1 spy-protec.com
O1 - Hosts: 127.0.0.1 spyware-protector-2009.com
O1 - Hosts: 127.0.0.1 browser-security.microsoft.com
O1 - Hosts: 127.0.0.1 antiwareprotect.com
O1 - Hosts: 127.0.0.1 antivguardian.com
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (no name) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - No CLSID value found.
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 8\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files (x86)\AVG\AVG8\Toolbar\IEToolbar.dll ()
O4:
64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (X86)\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [NvCplDaemon] C:\Windows\SysNative\NvCpl.DLL ()
O4:
64bit: - HKLM..\Run: [NvMediaCenter] C:\Windows\SysNative\NvMcTray.DLL ()
O4:
64bit: - HKLM..\Run: [NvSvc] C:\Windows\SysNative\nvsvc64.DLL ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files (x86)\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BlackBerryAutoUpdate] C:\Program Files (x86)\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe (Research In Motion Limited)
O4 - HKLM..\Run: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe (Hewlett-Packard)
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [ISTray] C:\Program Files (x86)\Spyware Doctor\pctsTray.exe (PC Tools)
O4 - HKLM..\Run: [KBD] C:\hp\KBD\KbdStub.exe ()
O4 - HKLM..\Run: [LogitechCommunicationsManager] C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe ()
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe ()
O4 - HKLM..\Run: [OsdMaestro] c:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD64.exe (OsdMaestro)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SolidWorks_CheckForUpdates] C:\Program Files (x86)\Common Files\SolidWorks Installation Manager\Scheduler\sldIMScheduler.exe (Dassault Systèmes SolidWorks Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre1.6.0_01\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [BTBFirstRun] C:\Program Files (x86)\Hewlett-Packard\SDP\HPRun.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [fgvevnay] C:\Users\Cornel\AppData\Local\tdltim\tultsftav.exe ()
O4 - HKCU..\Run: [ggmdmmjv] C:\Users\Cornel\AppData\Local\ewgyhv\tejisftav.exe ()
O4 - HKCU..\Run: [Skype] C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - Startup: C:\Users\Cornel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe (MagicISO, Inc.)
O4 - Startup: C:\Users\Cornel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SolidWorks Task Scheduler Engine.lnk = C:\Program Files (x86)\SolidWorks Corp\SolidWorks\swScheduler\swBOEngine.exe (Dassault Systèmes SolidWorks Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O8:
64bit: - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_01\bin\ssv.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/8/b/d/8bd77752-5704-4d68-a152-f7252adaa4f2/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_01-windows-i586.cab (Java Plug-in 1.6.0_01)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/RACtrl.cab (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 72.240.13.5 72.240.13.6 72.240.1.205
O18:
64bit: - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\bwfile-8876480 {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files (x86)\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll (Logitech Inc.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\intu-help-qb1 {9B0F96C7-2E4B-433e-ABF3-043BA1B54AE3} - C:\Program Files (x86)\Intuit\QuickBooks 2008\HelpAsyncPluggableProtocol.dll (TODO:
)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - AppInit_DLLs: (avgrssta.dll) - C:\Windows\SysNative\avgrssta.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img32.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img32.jpg
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/11/24 05:36:33 | 000,000,025 | R--- | M] () - F:\Autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2006/12/01 03:38:11 | 000,000,080 | R--- | M] () - K:\AUTORUN.INF -- [ UDF ]
O32 - AutoRun File - [2005/11/15 12:08:04 | 000,000,036 | -H-- | M] () - M:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{9f13eff8-1d28-11dd-863f-001fc62a301a}\Shell - "" = AutoRun
O33 - MountPoints2\{9f13eff8-1d28-11dd-863f-001fc62a301a}\Shell\AutoRun\command - "" = K:\SolidWorks-Tutorial.exe -- [2007/12/30 22:25:24 | 002,690,858 | R--- | M] (Macromedia, Inc.)
O33 - MountPoints2\{b19b8979-083b-11dd-bc75-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b19b8979-083b-11dd-bc75-806e6f6e6963}\Shell\AutoRun\command - "" = F:\start.exe -- [2008/11/24 05:36:43 | 002,707,136 | R--- | M] (Research In Motion)
O33 - MountPoints2\{d8f740f9-d445-11de-98ca-001fc62a301a}\Shell - "" = AutoRun
O33 - MountPoints2\{d8f740f9-d445-11de-98ca-001fc62a301a}\Shell\AutoRun\command - "" = P:\LaunchU3.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2010/02/03 10:56:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TrendMicro
[2010/02/02 19:43:49 | 000,000,000 | ---D | C] -- C:\Users\Cornel\AppData\Roaming\PC Tools
[2010/02/02 19:43:49 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2010/02/02 13:03:57 | 000,152,672 | ---- | C] (ALWIL Software) -- C:\Windows\SysWow64\aswBoot.exe
[2010/02/02 13:03:57 | 000,038,848 | ---- | C] (ALWIL Software) -- C:\Windows\SysWow64\avastSS.scr
[2010/02/02 12:24:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2010/02/02 12:24:39 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2010/02/02 11:44:20 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2010/02/02 11:44:20 | 000,165,840 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2010/02/02 11:44:20 | 000,149,456 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2010/02/02 11:44:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spyware Doctor
[2010/02/02 11:44:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2010/02/02 11:43:53 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2010/02/01 22:03:18 | 000,000,000 | ---D | C] -- C:\Users\Cornel\AppData\Local\tdltim
[2010/02/01 22:03:17 | 000,000,000 | ---D | C] -- C:\Users\Cornel\AppData\Local\ewgyhv
[2010/01/28 14:32:13 | 000,000,000 | ---D | C] -- C:\Users\Cornel\AppData\Roaming\vlc
[2010/01/22 10:06:44 | 000,916,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wininet.dll
[2010/01/22 10:06:44 | 000,594,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeeds.dll
[2010/01/22 10:06:44 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iedkcs32.dll
[2010/01/22 10:06:44 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2010/01/22 10:06:43 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2010/01/22 10:06:43 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2010/01/22 10:06:43 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2010/01/22 10:06:43 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2010/01/22 10:06:43 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2010/01/22 10:06:43 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2010/01/22 10:06:43 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedsbs.dll
[2010/01/22 10:06:43 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jsproxy.dll
[2010/01/22 10:06:43 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2010/01/22 10:06:42 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2010/01/22 10:06:42 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2010/01/14 18:02:57 | 000,156,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\t2embed.dll
[2010/01/14 18:02:57 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\fontsub.dll
[3 C:\Users\Cornel\AppData\Local\*.tmp files -> C:\Users\Cornel\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/02/03 13:30:49 | 004,194,304 | -HS- | M] () -- C:\Users\Cornel\NTUSER.DAT
[2010/02/03 12:51:34 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job
[2010/02/03 12:36:47 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/02/03 12:36:47 | 000,003,744 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/02/03 12:34:02 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/03 11:59:57 | 000,214,528 | ---- | M] () -- C:\Users\Cornel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/03 11:00:06 | 000,002,515 | ---- | M] () -- C:\Users\Cornel\Desktop\HiJackThis.lnk
[2010/02/03 09:13:39 | 055,048,281 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm
[2010/02/02 22:44:31 | 000,002,617 | ---- | M] () -- C:\Users\Cornel\Desktop\Outlook.lnk
[2010/02/02 22:43:00 | 000,694,964 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2010/02/02 22:43:00 | 000,598,350 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2010/02/02 22:43:00 | 000,101,988 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2010/02/02 22:38:26 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/02 22:36:37 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2010/02/02 22:36:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2010/02/02 22:35:13 | 000,524,288 | -HS- | M] () -- C:\Users\Cornel\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/02/02 22:35:13 | 000,065,536 | -HS- | M] () -- C:\Users\Cornel\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/02/02 22:35:01 | 003,582,273 | -H-- | M] () -- C:\Users\Cornel\AppData\Local\IconCache.db
[2010/02/02 19:43:56 | 000,001,775 | ---- | M] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/02/02 13:05:00 | 000,001,798 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/02/02 13:04:52 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2010/02/02 12:50:42 | 000,001,356 | ---- | M] () -- C:\Users\Cornel\AppData\Local\d3d9caps.dat
[2010/02/02 10:08:20 | 000,511,112 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2010/01/29 17:25:42 | 000,000,390 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job
[2010/01/28 17:09:46 | 000,038,848 | ---- | M] (ALWIL Software) -- C:\Windows\SysWow64\avastSS.scr
[2010/01/28 17:09:26 | 000,152,672 | ---- | M] (ALWIL Software) -- C:\Windows\SysWow64\aswBoot.exe
[2010/01/28 16:57:59 | 000,051,280 | ---- | M] () -- C:\Windows\SysNative\drivers\aswTdi.sys
[2010/01/28 16:57:40 | 000,120,912 | ---- | M] () -- C:\Windows\SysNative\drivers\aswSP.sys
[2010/01/28 16:54:45 | 000,028,752 | ---- | M] () -- C:\Windows\SysNative\drivers\aswRdr.sys
[2010/01/28 16:54:30 | 000,063,568 | ---- | M] () -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/01/28 16:54:07 | 000,022,096 | ---- | M] () -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/01/28 15:35:50 | 001,502,995 | ---- | M] () -- C:\Users\Cornel\Desktop\gasgebi2.wmv
[2010/01/28 15:07:59 | 002,890,688 | ---- | M] () -- C:\Users\Cornel\Desktop\guggi.avi
[2010/01/28 15:03:24 | 000,397,882 | ---- | M] () -- C:\Users\Cornel\Desktop\gag.avi
[2010/01/28 15:01:16 | 002,701,184 | ---- | M] () -- C:\Users\Cornel\Desktop\gaggi.mpg
[2010/01/28 15:01:10 | 000,344,040 | ---- | M] () -- C:\Users\Cornel\Desktop\gassi.mpg
[2010/01/28 14:52:38 | 002,874,896 | ---- | M] () -- C:\Users\Cornel\Desktop\gasgebi.mpg
[2010/01/28 14:31:38 | 000,000,888 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/01/25 12:39:00 | 002,345,174 | ---- | M] () -- C:\Users\Cornel\Desktop\RaceOilCooler1-15.stp
[2010/01/19 19:55:42 | 000,142,495 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\microavi.avg
[3 C:\Users\Cornel\AppData\Local\*.tmp files -> C:\Users\Cornel\AppData\Local\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/02/03 10:56:07 | 000,002,515 | ---- | C] () -- C:\Users\Cornel\Desktop\HiJackThis.lnk
[2010/02/02 19:44:06 | 000,306,648 | ---- | C] () -- C:\Windows\SysNative\drivers\pctgntdi64.sys
[2010/02/02 19:44:06 | 000,132,048 | ---- | C] () -- C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2010/02/02 19:44:06 | 000,007,357 | ---- | C] () -- C:\Windows\SysNative\drivers\pctgntdi64.cat
[2010/02/02 19:43:56 | 000,001,775 | ---- | C] () -- C:\Users\Public\Desktop\Spyware Doctor.lnk
[2010/02/02 19:43:54 | 000,092,896 | ---- | C] () -- C:\Windows\SysNative\drivers\pctplsg64.sys
[2010/02/02 19:43:54 | 000,007,353 | ---- | C] () -- C:\Windows\SysNative\drivers\pctplsg64.cat
[2010/02/02 13:05:00 | 000,001,798 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/02/02 13:04:59 | 000,120,912 | ---- | C] () -- C:\Windows\SysNative\drivers\aswSP.sys
[2010/02/02 13:04:59 | 000,022,096 | ---- | C] () -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2010/02/02 13:04:55 | 000,028,752 | ---- | C] () -- C:\Windows\SysNative\drivers\aswRdr.sys
[2010/02/02 13:04:54 | 000,051,280 | ---- | C] () -- C:\Windows\SysNative\drivers\aswTdi.sys
[2010/02/02 13:04:52 | 000,063,568 | ---- | C] () -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2010/02/02 13:04:06 | 000,422,820 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI150F.txt
[2010/02/02 13:04:03 | 000,013,810 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI150F.txt
[2010/02/02 12:47:43 | 000,139,860 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI0888.txt
[2010/02/02 12:47:41 | 000,014,176 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI0888.txt
[2010/02/02 12:43:25 | 000,139,940 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI053A.txt
[2010/02/02 12:43:23 | 000,014,208 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI053A.txt
[2010/02/02 12:37:15 | 000,011,566 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI008C.txt
[2010/02/02 12:36:58 | 000,000,002 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI004E.txt
[2010/02/02 12:36:56 | 000,012,046 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI004E.txt
[2010/02/02 12:36:31 | 000,011,518 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI7FFC.txt
[2010/02/02 12:36:05 | 000,011,582 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI7FA7.txt
[2010/02/02 12:35:55 | 000,011,534 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI7F87.txt
[2010/02/02 12:35:36 | 000,011,470 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI7F49.txt
[2010/02/02 12:34:02 | 000,010,580 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI7E16.txt
[2010/02/02 12:24:51 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2010/02/02 11:44:20 | 001,152,444 | ---- | C] () -- C:\Windows\UDB.zip
[2010/02/02 11:44:20 | 000,767,952 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2010/02/02 11:44:20 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2010/02/02 11:44:20 | 000,000,880 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2010/02/02 11:44:20 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2010/02/02 11:44:16 | 000,218,056 | ---- | C] () -- C:\Windows\SysNative\drivers\PCTCore64.sys
[2010/02/02 11:44:16 | 000,007,353 | ---- | C] () -- C:\Windows\SysNative\drivers\pctcore64.cat
[2010/02/02 11:44:12 | 000,011,440 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI57F2.txt
[2010/02/02 11:44:12 | 000,001,824 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI57F2.txt
[2010/02/02 11:44:11 | 000,011,456 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistUI57EE.txt
[2010/02/02 11:44:11 | 000,001,832 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_vcredistMSI57EE.txt
[2010/01/28 15:35:45 | 001,502,995 | ---- | C] () -- C:\Users\Cornel\Desktop\gasgebi2.wmv
[2010/01/28 15:07:53 | 002,890,688 | ---- | C] () -- C:\Users\Cornel\Desktop\guggi.avi
[2010/01/28 15:03:23 | 000,397,882 | ---- | C] () -- C:\Users\Cornel\Desktop\gag.avi
[2010/01/28 15:01:02 | 002,701,184 | ---- | C] () -- C:\Users\Cornel\Desktop\gaggi.mpg
[2010/01/28 14:58:06 | 000,344,040 | ---- | C] () -- C:\Users\Cornel\Desktop\gassi.mpg
[2010/01/28 14:52:15 | 002,874,896 | ---- | C] () -- C:\Users\Cornel\Desktop\gasgebi.mpg
[2010/01/28 14:31:38 | 000,000,888 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2010/01/25 12:39:00 | 002,345,174 | ---- | C] () -- C:\Users\Cornel\Desktop\RaceOilCooler1-15.stp
[2010/01/22 10:06:47 | 009,238,016 | ---- | C] () -- C:\Windows\SysNative\mshtml.dll
[2010/01/22 10:06:46 | 012,462,592 | ---- | C] () -- C:\Windows\SysNative\ieframe.dll
[2010/01/22 10:06:45 | 002,334,208 | ---- | C] () -- C:\Windows\SysNative\iertutil.dll
[2010/01/22 10:06:44 | 001,483,776 | ---- | C] () -- C:\Windows\SysNative\urlmon.dll
[2010/01/22 10:06:44 | 001,147,904 | ---- | C] () -- C:\Windows\SysNative\wininet.dll
[2010/01/22 10:06:44 | 000,459,776 | ---- | C] () -- C:\Windows\SysNative\iedkcs32.dll
[2010/01/22 10:06:44 | 000,243,712 | ---- | C] () -- C:\Windows\SysNative\occache.dll
[2010/01/22 10:06:43 | 001,538,560 | ---- | C] () -- C:\Windows\SysNative\inetcpl.cpl
[2010/01/22 10:06:43 | 000,700,928 | ---- | C] () -- C:\Windows\SysNative\msfeeds.dll
[2010/01/22 10:06:43 | 000,252,416 | ---- | C] () -- C:\Windows\SysNative\iepeers.dll
[2010/01/22 10:06:43 | 000,162,816 | ---- | C] () -- C:\Windows\SysNative\ieUnatt.exe
[2010/01/22 10:06:43 | 000,132,096 | ---- | C] () -- C:\Windows\SysNative\iesysprep.dll
[2010/01/22 10:06:43 | 000,072,192 | ---- | C] () -- C:\Windows\SysNative\iernonce.dll
[2010/01/22 10:06:43 | 000,071,680 | ---- | C] () -- C:\Windows\SysNative\msfeedsbs.dll
[2010/01/22 10:06:43 | 000,070,656 | ---- | C] () -- C:\Windows\SysNative\ie4uinit.exe
[2010/01/22 10:06:43 | 000,031,744 | ---- | C] () -- C:\Windows\SysNative\jsproxy.dll
[2010/01/22 10:06:43 | 000,012,288 | ---- | C] () -- C:\Windows\SysNative\msfeedssync.exe
[2010/01/22 10:06:42 | 001,638,912 | ---- | C] () -- C:\Windows\SysNative\mshtml.tlb
[2010/01/22 10:06:42 | 000,219,136 | ---- | C] () -- C:\Windows\SysNative\ieui.dll
[2010/01/22 10:06:42 | 000,077,312 | ---- | C] () -- C:\Windows\SysNative\iesetup.dll
[2010/01/20 08:43:58 | 000,442,368 | ---- | C] () -- C:\Windows\SysNative\winhttp.dll
[2010/01/19 19:58:47 | 000,656,384 | ---- | C] () -- C:\Windows\SysNative\kerberos.dll
[2010/01/19 19:58:47 | 000,338,944 | ---- | C] () -- C:\Windows\SysNative\schannel.dll
[2010/01/14 18:02:57 | 000,189,440 | ---- | C] () -- C:\Windows\SysNative\t2embed.dll
[2010/01/14 18:02:57 | 000,096,256 | ---- | C] () -- C:\Windows\SysNative\fontsub.dll
[2009/09/14 20:27:15 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2009/09/04 11:48:46 | 000,000,600 | ---- | C] () -- C:\Users\Cornel\AppData\Local\PUTTY.RND
[2009/09/03 13:37:49 | 000,007,149 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_depcheck_NETFX20_EXP_35.txt
[2009/09/03 13:37:47 | 000,031,614 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx20install.txt
[2009/09/03 13:37:47 | 000,000,754 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx20error.txt
[2009/09/03 12:55:27 | 000,005,108 | ---- | C] () -- C:\Users\Cornel\AppData\Local\setup.log
[2009/09/03 12:54:11 | 002,531,226 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_NET_Framework35_x64_MSI294B.txt
[2009/06/19 13:36:28 | 000,069,339 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_depcheckdotnetfx30.txt
[2009/06/19 13:36:18 | 000,000,596 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx3error.txt
[2009/06/19 13:36:17 | 000,057,338 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx3install.txt
[2009/03/18 18:23:05 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Services
[2009/03/18 18:23:05 | 000,000,268 | RH-- | C] () -- C:\Users\Cornel\AppData\Roaming\Sci-Fi
[2009/03/18 18:23:05 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLer.DAT
[2009/03/18 13:31:28 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Sampler Instruments
[2009/03/18 13:31:28 | 000,000,268 | RH-- | C] () -- C:\Users\Cornel\AppData\Roaming\Rule Actions
[2009/03/18 13:31:28 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2008/09/16 05:09:27 | 000,001,356 | ---- | C] () -- C:\Users\Cornel\AppData\Local\d3d9caps.dat
[2008/07/16 09:43:36 | 000,000,310 | ---- | C] () -- C:\Users\Cornel\AppData\Roaming\APUSet.xml
[2008/07/16 09:43:35 | 000,006,045 | ---- | C] () -- C:\Users\Cornel\AppData\Roaming\PrimoPDFSet.xml
[2008/06/05 20:05:28 | 000,039,776 | ---- | C] () -- C:\Windows\SysWow64\drivers\STREAM.SYS
[2008/06/05 19:06:33 | 000,002,508 | ---- | C] () -- C:\Windows\unvpeye.ini
[2008/05/16 09:27:25 | 000,214,528 | ---- | C] () -- C:\Users\Cornel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/05/13 20:01:29 | 000,027,841 | ---- | C] () -- C:\Users\Cornel\AppData\Roaming\Comma Separated Values (Windows).ADR
[2008/05/12 07:05:28 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2008/05/09 07:24:14 | 000,708,868 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2008/05/08 16:36:21 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/05/08 15:03:32 | 001,880,288 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_NET_Framework35_x64_MSI220F.txt
[2008/05/08 15:03:06 | 000,356,859 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_depcheck_NETFX_EXP_35.txt
[2008/05/08 15:03:03 | 000,479,270 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx35install.txt
[2008/05/08 15:03:03 | 000,025,264 | ---- | C] () -- C:\Users\Cornel\AppData\Local\uxeventlog.txt
[2008/05/08 15:03:03 | 000,000,002 | ---- | C] () -- C:\Users\Cornel\AppData\Local\dd_dotnetfx35error.txt
[2008/05/08 13:18:32 | 000,000,068 | ---- | C] () -- C:\Windows\eyeQ Screen Saver.ini
[2008/04/28 11:13:33 | 000,000,310 | ---- | C] () -- C:\Windows\primopdf.ini
[2008/02/28 14:30:08 | 000,008,784 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2008/02/22 16:11:39 | 000,000,342 | ---- | C] () -- C:\ProgramData\hpzinstall.log
[2008/02/22 16:04:04 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll
[2008/02/22 16:04:04 | 000,102,400 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2002/05/27 20:52:36 | 000,106,496 | ---- | C] () -- C:\Windows\japi.dll
[2001/06/24 04:32:44 | 000,172,032 | ---- | C] () -- C:\Windows\japi2.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:A8ADE5D8
< End of report >