OTL logfile created on: 1/18/2011 11:17:31 AM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Users\Bill\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 74.00% Memory free
8.00 Gb Paging File | 7.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 202.52 Gb Free Space | 43.49% Space Free | Partition Type: NTFS
Computer Name: BILL-PC | User Name: Bill | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2011/01/18 11:16:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bill\Downloads\OTL.exe
PRC - [2011/01/13 03:47:34 | 003,396,624 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/01/13 03:47:33 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010/09/23 22:03:03 | 002,969,496 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
PRC - [2010/01/11 23:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/10/15 20:08:04 | 005,822,464 | ---- | M] (ASUSTeK Computer Inc.) -- C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe
========== Modules (SafeList) ========== MOD - [2011/01/18 11:16:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Bill\Downloads\OTL.exe
MOD - [2011/01/13 03:47:35 | 000,189,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/08/21 00:21:32 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2011/01/13 03:47:33 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2010/12/18 14:43:59 | 000,403,240 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/11 23:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2011/01/13 03:37:23 | 000,062,032 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:
64bit: - [2009/11/11 23:14:28 | 000,084,584 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2009/10/20 22:30:32 | 001,270,784 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:
64bit: - [2009/07/28 02:04:38 | 000,058,880 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV:
64bit: - [2009/07/16 22:38:40 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:
64bit: - [2009/07/13 20:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2009/07/13 20:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:
64bit: - [2009/06/10 15:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/07 15:30:28 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie.sys -- (AtiPcie) AMD PCI Express (3GIO)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bigseekpro.com/hypercam/{07211B3B-5BB5-42DC-8681-B2F276E0759B} IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.bigseekpro.com/hypercam/{07211B3B-5BB5-42DC-8681-B2F276E0759B}IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 57 22 ED FA 44 57 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\Program Files (x86)\HyperCam Toolbar\tbhelper.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
toolbar@ask.com:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..keyword.URL: "http://websearch.ask.com/redirect?client=ff&src=kw&tb=GAM1&o=15491&locale=en_US&apn_uid=116141FB-5152-4412-96C8-409B4571A73B&apn_ptnrs=HE&apn_sauid=2F879226-2C32-4C1F-A6C2-500283289690&apn_dtid=YYYYYYYYUS&q="
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/11 22:20:07 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/12/11 22:20:07 | 000,000,000 | ---D | M]
[2010/04/21 12:39:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bill\AppData\Roaming\Mozilla\Extensions
[2011/01/17 12:14:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\extensions
[2011/01/12 00:12:40 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/10/28 15:09:46 | 000,000,000 | ---D | M] (Zynga Toolbar) -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/10/21 19:33:01 | 000,000,000 | ---D | M] (Ask Toolbar) -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\extensions\toolbar@ask.com
[2010/10/25 09:03:25 | 000,000,000 | ---D | M] ("YoYo Games InstantPlay") -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\extensions\yyginstantplay@yoyogames.com
[2011/01/17 12:04:12 | 000,002,396 | ---- | M] () -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\searchplugins\askcom.xml
[2010/09/24 12:53:32 | 000,002,331 | ---- | M] () -- C:\Users\Bill\AppData\Roaming\Mozilla\Firefox\Profiles\khtjoato.default\searchplugins\bigseekpro.xml
[2010/11/01 15:15:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/30 22:16:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/09/08 20:57:28 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/11/01 15:15:31 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/09/15 03:50:38 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx ()
O2 - BHO: (Gamevance Text) - {BEAC7DC8-E106-4C6A-931E-5A42E7362883} - File not found
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files (x86)\HyperCam Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\HyperCam Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\Program Files (x86)\HyperCam Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:
64bit: - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - File not found
O9:
64bit: - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - File not found
O12 - Plugin for: .spop - C:\Program Files (x86)\Internet Explorer\Plugins\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.71.230 68.87.73.246
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/01/17 12:53:05 | 000,237,168 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/01/11 21:23:14 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/01/11 21:23:14 | 001,170,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10warp.dll
[2011/01/11 21:23:14 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/01/11 21:23:14 | 000,739,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d2d1.dll
[2011/01/11 21:23:13 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2011/01/11 21:23:13 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2011/01/11 21:23:13 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2011/01/11 21:23:13 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/01/11 21:23:13 | 001,074,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\DWrite.dll
[2011/01/11 21:23:13 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/01/11 21:23:12 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/01/11 21:23:12 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2011/01/11 21:23:12 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/01/11 21:23:12 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/01/11 21:23:12 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011/01/11 21:23:12 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/01/11 21:23:12 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1core.dll
[2011/01/11 21:23:11 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/01/11 21:23:11 | 000,258,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/01/11 21:23:11 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2011/01/11 21:23:11 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/01/11 21:23:11 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2011/01/11 21:23:11 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011/01/11 21:23:11 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2011/01/11 21:23:11 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/01/11 21:23:10 | 000,161,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\d3d10_1.dll
[2011/01/11 21:23:10 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/01/11 21:23:00 | 000,720,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbc32.dll
[2011/01/11 21:22:59 | 000,573,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbc32.dll
[2011/01/01 18:41:38 | 000,000,000 | ---D | C] -- C:\Users\Bill\Documents\Fiddler2
[2011/01/01 18:41:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fiddler2
[2010/12/27 16:34:50 | 000,000,000 | ---D | C] -- C:\Users\Bill\Documents\Danny's Minecraft
[2010/12/26 16:44:57 | 000,000,000 | ---D | C] -- C:\Users\Bill\AppData\Roaming\.minecraft
[2010/12/26 15:50:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LEGO Media
[2010/12/26 15:50:21 | 001,347,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSVBVM50.DLL
[2010/12/26 15:50:21 | 000,604,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\COMCTL32.OCX
[2010/12/26 15:50:21 | 000,075,536 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PICCLP32.OCX
[2010/12/26 15:50:21 | 000,050,896 | ---- | C] (TegoSoft Inc. Web Site:
http://www.tegosoft.com) -- C:\Windows\SysWow64\TEGODS.OCX
[2010/12/26 15:50:18 | 000,188,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WINGDE.DLL
[2010/12/26 15:50:18 | 000,092,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WING.DLL
[2010/12/26 15:50:18 | 000,036,864 | ---- | C] (Superscape VR plc) -- C:\Windows\SysWow64\SCLVideo.ax
[2010/12/26 15:50:18 | 000,028,672 | ---- | C] (Superscape VR plc) -- C:\Windows\SysWow64\SCLAudio.ax
[2010/12/26 15:50:18 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WING32.DLL
[2010/12/26 15:50:18 | 000,006,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WINGDIB.DRV
[2010/12/26 15:50:18 | 000,005,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WINGPAL.WND
[2010/12/26 15:50:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LEGO Media
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/01/18 11:16:13 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/01/18 11:16:13 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/01/18 11:12:20 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/18 11:08:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/01/18 11:08:51 | 3220,574,208 | -HS- | M] () -- C:\hiberfil.sys
[2011/01/17 21:51:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/17 13:04:19 | 000,093,696 | ---- | M] () -- C:\Users\Bill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/17 12:53:23 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/01/13 03:47:32 | 000,188,216 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/01/13 03:47:23 | 000,237,168 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/01/13 03:41:44 | 000,273,488 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/01/13 03:40:20 | 000,051,792 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/01/13 03:37:34 | 000,029,264 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/01/13 03:37:23 | 000,062,032 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/01/13 03:37:12 | 000,020,560 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/01/10 17:17:27 | 000,050,853 | ---- | M] () -- C:\Users\Bill\Desktop\george.jpg
[2011/01/10 12:49:30 | 000,834,193 | ---- | M] () -- C:\Users\Bill\Documents\Evie1.mine
[2011/01/04 17:54:20 | 000,202,689 | ---- | M] () -- C:\Users\Bill\Documents\NoKelsTheMansion.mine
[2010/12/31 23:08:59 | 473,731,944 | ---- | M] () -- C:\Users\Bill\Documents\clip0192.avi
[2010/12/31 23:02:26 | 639,251,228 | ---- | M] () -- C:\Users\Bill\Documents\clip0191.avi
[2010/12/31 22:52:56 | 1236,849,916 | ---- | M] () -- C:\Users\Bill\Documents\clip0189.avi
[2010/12/31 15:06:36 | 000,038,848 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/12/27 20:12:48 | 121,742,000 | ---- | M] () -- C:\Users\Bill\Documents\clip0188.avi
[2010/12/27 20:10:32 | 349,275,766 | ---- | M] () -- C:\Users\Bill\Documents\clip0187.avi
[2010/12/27 19:50:17 | 002,776,922 | ---- | M] () -- C:\Users\Bill\Documents\clip0185.avi
[2010/12/27 18:05:47 | 000,049,975 | ---- | M] () -- C:\Users\Bill\Documents\Evie's Game.mine
[2010/12/26 20:04:26 | 000,043,145 | ---- | M] () -- C:\Users\Bill\Desktop\Minecraft 1st Level (Rocky Sea).mine
[2010/12/26 15:52:03 | 000,413,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/01/10 17:17:26 | 000,050,853 | ---- | C] () -- C:\Users\Bill\Desktop\george.jpg
[2010/12/31 23:04:19 | 473,731,944 | ---- | C] () -- C:\Users\Bill\Documents\clip0192.avi
[2010/12/31 22:56:58 | 639,251,228 | ---- | C] () -- C:\Users\Bill\Documents\clip0191.avi
[2010/12/31 22:42:46 | 1236,849,916 | ---- | C] () -- C:\Users\Bill\Documents\clip0189.avi
[2010/12/27 20:11:02 | 121,742,000 | ---- | C] () -- C:\Users\Bill\Documents\clip0188.avi
[2010/12/27 20:04:48 | 349,275,766 | ---- | C] () -- C:\Users\Bill\Documents\clip0187.avi
[2010/12/27 19:49:20 | 002,776,922 | ---- | C] () -- C:\Users\Bill\Documents\clip0185.avi
[2010/12/27 19:39:48 | 000,834,193 | ---- | C] () -- C:\Users\Bill\Documents\Evie1.mine
[2010/12/27 17:37:36 | 000,049,975 | ---- | C] () -- C:\Users\Bill\Documents\Evie's Game.mine
[2010/12/27 15:12:14 | 000,202,689 | ---- | C] () -- C:\Users\Bill\Documents\NoKelsTheMansion.mine
[2010/12/26 17:52:48 | 000,043,145 | ---- | C] () -- C:\Users\Bill\Desktop\Minecraft 1st Level (Rocky Sea).mine
[2010/12/26 15:50:21 | 000,000,253 | ---- | C] () -- C:\Windows\Creator.INI
[2010/12/26 15:50:18 | 000,005,195 | ---- | C] () -- C:\Windows\SysWow64\DVA.386
[2010/09/23 22:53:16 | 000,000,092 | ---- | C] () -- C:\Users\Bill\AppData\Local\fusioncache.dat
[2010/09/23 22:50:30 | 000,749,320 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/07/31 16:40:33 | 000,093,696 | ---- | C] () -- C:\Users\Bill\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/17 18:22:22 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll
[2010/04/21 12:49:08 | 000,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/04/10 05:27:59 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010/04/10 05:27:59 | 000,013,368 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010/04/10 05:27:56 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2010/04/10 05:27:56 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2010/04/10 05:23:25 | 000,034,946 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2010/04/10 05:21:51 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010/04/10 05:21:47 | 000,028,386 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/04/03 07:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2001/07/13 06:04:00 | 000,373,248 | ---- | C] () -- C:\Windows\EyeCand3.INI
========== Alternate Data Streams ========== @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:472FDF93
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:C7504B28
@Alternate Data Stream - 95 bytes -> C:\ProgramData\TEMP:9ED07655
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:B409C3B4
@Alternate Data Stream - 175 bytes -> C:\ProgramData\TEMP:F9BCB534
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:140CF428
@Alternate Data Stream - 170 bytes -> C:\ProgramData\TEMP:0BAA671C
@Alternate Data Stream - 169 bytes -> C:\ProgramData\TEMP:57A1A321
@Alternate Data Stream - 169 bytes -> C:\ProgramData\TEMP:2344A07A
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:D1EA8A42
@Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:24E173A4
@Alternate Data Stream - 163 bytes -> C:\ProgramData\TEMP:73828A71
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:8643C5BE
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:A988B257
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:38673444
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:3A171849
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:20C69EEE
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:95DD2596
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:58FACC00
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:3DB0B938
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:AF2E5A21
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:7F7562E0
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F3F95A98
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:8004C9F0
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:FB2DC8A5
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CF2C9E8E
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2C321309
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:20240A47
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:82591FF7
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:B5B501E5
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:57648A0A
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:FAB17E8E
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:FEEDAD5B
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:0C0D563A
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:37A75597
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:89D63297
< End of report >