For the last few weeks or months, y computer has slown down tremendously. When i try to google something. 7 times out of 10 Google will ask me to veryify that the request was not machine driven. The error message in googl;e is something like, "your computer/network is suspected of sending automated queries......"
Also for some applications the following message appears.
There is no disk in the drive. Please insert a disk into drive\Decice\Harddisk2\DR5
Cancel/try again/continue
Please help it seems that something is slowing me down but not sure what. have added all the logs you asked for. Please try and help.
thanks
harsha
OTL logfile created on: 3/28/2012 9:43:13 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = F:\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19190)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 52.89% Memory free
9.24 Gb Paging File | 7.86 Gb Available in Paging File | 85.05% Paging File free
Paging file location(s): d:\pagefile.sys 6500 7417 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 154.83 Gb Total Space | 64.78 Gb Free Space | 41.84% Space Free | Partition Type: NTFS
Drive D: | 7.30 Gb Total Space | 0.87 Gb Free Space | 11.87% Space Free | Partition Type: NTFS
Drive E: | 303.63 Gb Total Space | 57.61 Gb Free Space | 18.97% Space Free | Partition Type: NTFS
Drive F: | 2794.51 Gb Total Space | 2072.35 Gb Free Space | 74.16% Space Free | Partition Type: NTFS
Drive I: | 74.53 Gb Total Space | 15.11 Gb Free Space | 20.28% Space Free | Partition Type: NTFS
Computer Name: THATHIPOOH-PC | User Name: Thathi Pooh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/25 22:55:32 | 000,594,432 | ---- | M] (OldTimer Tools) -- F:\Downloads\OTL.com
PRC - [2012/02/23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
PRC - [2012/02/15 03:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\Thathi Pooh\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/06/01 20:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
PRC - [2011/06/01 20:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
PRC - [2011/06/01 20:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
PRC - [2011/04/17 04:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\5.2.0.13\ccsvchst.exe
PRC - [2011/01/24 22:36:28 | 000,085,272 | ---- | M] (Memeo Inc.) -- C:\Program Files\Memeo\AutoBackup\MemeoUpdater.exe
PRC - [2011/01/24 22:35:36 | 000,025,824 | ---- | M] (Memeo) -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
PRC - [2011/01/24 22:35:30 | 000,324,320 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\InstantBackup.exe
PRC - [2009/12/29 11:27:16 | 000,995,328 | ---- | M] (D-Link Corp.) -- C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
PRC - [2009/10/19 18:39:38 | 000,122,880 | ---- | M] (Wireless Service) -- C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
PRC - [2009/07/07 19:49:20 | 000,040,960 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
PRC - [2009/04/11 10:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007/02/23 16:32:56 | 000,126,976 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
PRC - [2006/09/15 13:21:54 | 000,675,840 | ---- | M] (Sonix) -- C:\Windows\vsnp2std.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/16 22:48:58 | 001,711,616 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll
MOD - [2012/02/16 22:47:36 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll
MOD - [2012/02/16 22:47:33 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll
MOD - [2012/02/16 22:47:30 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\2598077ccea480c6120d3a1ad4455be0\System.Web.ni.dll
MOD - [2012/02/16 22:47:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll
MOD - [2012/02/16 22:45:40 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll
MOD - [2012/02/16 22:45:26 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll
MOD - [2012/02/16 22:45:18 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll
MOD - [2012/02/16 22:45:08 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\029217106fa24787ff7a61b754f8ebf7\System.Data.ni.dll
MOD - [2012/02/16 22:44:28 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll
MOD - [2011/11/03 08:52:31 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll
MOD - [2011/11/03 08:52:30 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/06/01 20:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll
MOD - [2011/06/01 20:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\Memeo.Progress.dll
MOD - [2011/06/01 20:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll
MOD - [2011/06/01 20:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll
MOD - [2011/01/24 22:35:58 | 002,896,608 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\Memeo.Client.UI.dll
MOD - [2011/01/24 22:35:54 | 000,026,848 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll
MOD - [2011/01/24 22:35:30 | 000,324,320 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\InstantBackup.exe
MOD - [2010/10/28 11:56:40 | 000,315,392 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\ANPDApi.dll
MOD - [2010/03/23 02:59:46 | 000,504,293 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\sqlite3.dll
MOD - [2009/10/19 18:59:12 | 000,274,432 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\wlanapp.dll
MOD - [2009/03/30 08:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2008/12/27 20:55:46 | 000,089,600 | ---- | M] () -- C:\Program Files\Griffin Technology\iTalk Sync\CopyHook.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/01/04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/06/01 20:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService)
SRV - [2011/04/17 04:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe -- (N360)
SRV - [2011/01/24 22:35:36 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService)
SRV - [2009/10/07 16:50:26 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2009/08/21 09:27:26 | 000,126,976 | ---- | M] (Wireless Service) [Auto | Stopped] -- C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe -- (D_Link_DWA-125)
SRV - [2009/07/07 19:49:20 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe -- (D_Link_DWA-125_WPS)
SRV - [2009/03/06 12:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Disabled | Stopped] -- C:\Windows\System32\atashost.exe -- (atashost)
SRV - [2008/02/18 14:36:14 | 001,553,704 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2008/01/21 06:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/07 00:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/06/03 15:39:32 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\BlackBYTE Free Speech Vista\bin\blackbyteserv.exe -- (OpenVPNService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS -- (SYMNDISV)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS -- (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012/03/06 16:04:10 | 000,368,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120327.002\IDSvix86.sys -- (IDSVix86)
DRV - [2012/03/02 22:58:02 | 000,820,856 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120317.002\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/02/04 14:03:59 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/02/04 14:03:59 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/11/01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 10:07:24 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2011/11/01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/11/01 10:07:24 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/08/04 10:11:05 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120327.037\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/08/04 10:11:05 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120327.037\NAVENG.SYS -- (NAVENG)
DRV - [2011/06/26 04:56:44 | 000,028,256 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\appliand.sys -- (appliandMP)
DRV - [2011/06/26 04:56:44 | 000,028,256 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\appliand.sys -- (appliand)
DRV - [2011/06/05 09:29:31 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/05/06 14:30:36 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio)
DRV - [2011/05/06 14:30:28 | 000,011,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio)
DRV - [2011/04/21 05:37:49 | 000,331,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symtdiv.sys -- (SYMTDIv)
DRV - [2011/03/31 07:00:09 | 000,516,216 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\srtsp.sys -- (SRTSP)
DRV - [2011/03/31 07:00:09 | 000,050,168 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/03/15 06:31:23 | 000,744,568 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symefa.sys -- (SymEFA)
DRV - [2011/01/27 10:47:10 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symds.sys -- (SymDS)
DRV - [2011/01/27 09:07:05 | 000,136,312 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\ironx86.sys -- (SymIRON)
DRV - [2009/12/30 11:21:18 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/09/21 11:31:17 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/09/15 13:47:44 | 000,798,208 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Dnetr28u.sys -- (netr28u)
DRV - [2009/07/11 21:14:09 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2009/03/06 18:09:52 | 000,012,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\anodlwf.sys -- (anodlwf)
DRV - [2008/12/10 12:37:46 | 000,135,680 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/09/06 13:42:34 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0801.sys -- (tap0801)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/02/18 14:36:14 | 000,038,312 | ---- | M] (Nero AG) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm)
DRV - [2008/02/18 14:36:14 | 000,036,648 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass)
DRV - [2008/02/18 14:36:14 | 000,016,040 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2008/02/18 14:36:04 | 000,118,952 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2008/01/24 01:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tapvpn.sys -- (tapvpn)
DRV - [2007/11/07 00:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2007/03/30 14:41:54 | 012,033,024 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {40439b93-f815-4122-8073-d03bed94c303}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://theacademic.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {C8929A7D-4606-4CB4-B62E-C8F77551274C}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{C8929A7D-4606-4CB4-B62E-C8F77551274C}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=1I7ADFA_en
IE - HKCU\..\SearchScopes\{EF20B2D8-708C-44D9-8DDD-50C16AE2EB0B}: "URL" = http://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.theacademic.org/"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/05 20:40:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/02/01 16:55:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_6_3 [2012/03/28 19:40:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/01/27 12:04:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/18 22:34:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/05 23:43:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/01/27 12:04:53 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter
[2009/10/16 12:42:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Extensions
[2012/02/17 01:27:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions
[2012/02/17 01:27:38 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/04/27 16:44:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/12 22:09:34 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\engine@conduit.com
[2012/02/24 17:33:29 | 000,002,359 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\searchplugins\google-us.xml
[2011/11/11 08:41:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/03/28 19:40:45 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\COFFPLGN_2011_7_6_3
[2012/02/01 16:55:17 | 000,000,000 | ---D | M] (Symantec Intrusion Prevention) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPLGN
() (No name found) -- C:\USERS\THATHI POOH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0T6EJE54.DEFAULT\EXTENSIONS\AMZNUWL2@AMAZON.COM.XPI
[2012/03/18 22:34:03 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/12 09:21:55 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/12 09:21:55 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2006/09/19 01:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.2.0.13\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.2.0.13\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.2.0.13\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [D-Link D-Link DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Memeo AutoSync] C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WZCSLDR2] C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe (Wireless Service)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EPSON Stylus CX4300 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICAR.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [replay_telecorder_skype] File not found
O4 - Startup: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Thathi Pooh\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7239AC13-6A83-4F8E-8635-CA6376FFF840}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {88485281-8b4b-4f8d-9ede-82e29a064277} - C:\Program Files\MarkAny\ContentSafer\MACSMANAGER.dll (MarkAny Cooperation.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/21 23:42:49 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/02/15 08:53:50 | 000,000,027 | ---- | M] () - F:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{02d73188-6e96-11de-8cf0-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{02d73188-6e96-11de-8cf0-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{40661170-ceca-11de-a27e-00241d3c93ea}\Shell\AutoRun\command - "" = H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe
O33 - MountPoints2\{40661170-ceca-11de-a27e-00241d3c93ea}\Shell\open\command - "" = H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe
O33 - MountPoints2\{61edb4dd-471d-11df-8c96-00241d3c93ea}\Shell\AutoRun\command - "" = H:\installer.exe
O33 - MountPoints2\{61edb4dd-471d-11df-8c96-00241d3c93ea}\Shell\verb\command - "" = H:\installer.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\AutoRun\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\explore\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\open\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{98530c59-3d67-11e0-9a33-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{98530c59-3d67-11e0-9a33-00241d3c93ea}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{dd9b73f0-5c20-11e0-8ffe-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{dd9b73f0-5c20-11e0-8ffe-00241d3c93ea}\Shell\AutoRun\command - "" = I:\MI.exe
O33 - MountPoints2\{dda79276-c3f3-11df-9ad1-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{dda79276-c3f3-11df-9ad1-00241d3c93ea}\Shell\AutoRun\command - "" = H:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor Ver.4.lnk - - File not found
MsConfig - StartUpFolder: C:^Users^Thathi Pooh^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
MsConfig - StartUpReg: BitComet - hkey= - key= - File not found
MsConfig - StartUpReg: EPSON Stylus CX4300 Series - hkey= - key= - File not found
MsConfig - StartUpReg: Freecorder FLV Service - hkey= - key= - File not found
MsConfig - StartUpReg: LGODDFU - hkey= - key= - C:\Program Files\lg_fwupdate\fwupdate.exe (BL)
MsConfig - StartUpReg: MAAgent - hkey= - key= - C:\Program Files\MarkAny\ContentSafer\MaAgent.exe ((주)마크애니)
MsConfig - StartUpReg: NBKeyScan - hkey= - key= - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe (Nero AG)
MsConfig - StartUpReg: nmapp - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: WinampAgent - hkey= - key= - File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: atashost - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vsmon - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.scg726 - C:\Windows\System32\scg726.acm (SHARP Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: vidc.tscc - C:\Program Files\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/28 13:21:56 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7D695D29-6484-43EB-B1BD-7110B9A8E311}
[2012/03/28 13:21:53 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BDE602FB-3B87-40BE-8456-463CD39B9F3B}
[2012/03/27 18:21:17 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F5E319AF-C924-43BD-B80C-D62B20D21409}
[2012/03/27 18:21:15 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9D3F587A-7BA0-4C5F-9B21-629FB070CA47}
[2012/03/27 06:21:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F6D5E598-1539-4C8E-8481-D6E332E1C196}
[2012/03/27 06:21:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{482E3238-416B-48B9-AC1F-E978522D2D2A}
[2012/03/26 18:21:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F9F08BD6-0C63-4379-B051-DC59A8776C13}
[2012/03/26 18:21:02 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6BD09716-63B6-408A-85BD-D150DEFC846C}
[2012/03/25 23:16:33 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\NPE
[2012/03/25 22:57:16 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
[2012/03/25 22:35:20 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{668CD80F-6ECD-47F5-A02B-38CAC8236CB9}
[2012/03/25 22:35:17 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{3108BF1B-E8FC-4567-A104-9BDEA5D38733}
[2012/03/25 10:35:00 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8D2CE574-1A73-4941-9D69-A9E0B1D2D87A}
[2012/03/25 10:34:58 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BCDACD9E-E440-44A4-B1BE-2B79DEE97A92}
[2012/03/23 08:55:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{34900CBD-36FE-44A5-8E57-0849EDE6E21F}
[2012/03/23 08:55:53 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9FF6C2F0-7882-4AD6-AA3B-BD92DBFEB856}
[2012/03/22 23:12:12 | 004,435,968 | ---- | C] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2012/03/21 22:41:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{01DFFBD0-DC5E-4AA7-A42E-B907DDB58E8D}
[2012/03/21 22:41:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8E63CA75-82FE-4CC8-AACD-4C6B5961BA16}
[2012/03/21 10:40:47 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EE7B63F6-AF1B-44A5-85D9-DB91FE94D8A5}
[2012/03/21 10:40:41 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EBF02A46-4484-4C9A-8389-4E52002D76A2}
[2012/03/21 00:49:22 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/03/20 19:02:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7E0C0C25-1F7B-4968-B2CF-B15A53DD96CD}
[2012/03/20 19:02:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{C34007F6-F872-4BF3-8D92-29458F899653}
[2012/03/19 16:15:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{42CB6140-F353-4564-BCB1-37531C1AF931}
[2012/03/19 16:15:57 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0A753374-1BE7-41E9-8DAF-F6FA37A7EB7F}
[2012/03/18 22:31:50 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6092210E-4B8E-49C6-B5A5-D726ECC0083D}
[2012/03/18 22:31:48 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{496D5248-CC1A-4C7F-A825-1B144EA3ADB4}
[2012/03/18 08:10:13 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{4F7EBEE0-8452-45B3-98AB-EB834B77E08C}
[2012/03/18 08:10:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{AC66D9C4-8DF8-40F7-AA58-5ADB579DC16C}
[2012/03/17 18:57:45 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{56B71737-6409-49E7-814B-F8E59E1A1D1C}
[2012/03/17 18:57:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{3D5BCF3A-6F93-48FF-B46E-1287822FC492}
[2012/03/16 19:49:20 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{597A2263-EC71-4AF7-9DF6-4CDF07B92689}
[2012/03/16 19:48:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8571F740-F200-4F31-B13A-4D3EC9255CA3}
[2012/03/15 21:48:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EB2666CE-DE88-47A9-B5A5-E470F6FEA868}
[2012/03/15 21:48:03 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BD1DFF17-F6E8-415B-B1E7-A2125355BF75}
[2012/03/14 22:02:39 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F111861F-A0FD-482E-99DB-0E66E764F180}
[2012/03/14 22:02:36 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6A1E0C12-02C4-4860-8FC5-9A6446B07F05}
[2012/03/14 07:05:13 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{711EEC27-62D6-4F45-B9C1-89B3CA59320A}
[2012/03/14 07:05:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{54823A60-D0B3-4BD1-AFF0-04B9C25F21C2}
[2012/03/14 01:12:54 | 002,044,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/03/14 01:12:52 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2012/03/14 01:12:52 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012/03/14 01:12:52 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012/03/14 01:12:52 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2012/03/14 01:12:52 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012/03/14 01:12:14 | 000,613,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2012/03/13 19:05:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{863071F3-88F4-423F-AB11-D014565DC175}
[2012/03/13 19:05:04 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{E7E7CAE1-19E5-47C2-940D-652062A22D77}
[2012/03/10 22:15:43 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{377A917D-B500-4AF8-8C13-8B5CFFF26BE4}
[2012/03/10 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{51575192-76B8-4076-9AC8-3D8AB5568E2B}
[2012/03/10 12:42:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/03/10 12:41:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/03/10 12:41:49 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/03/10 10:15:25 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{97168F73-6032-447F-BCCF-9BBAE12317A2}
[2012/03/10 10:15:21 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{04C010AC-774B-4601-BA7D-EAFD2E032FAC}
[2012/03/09 11:58:36 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{AF2D79A9-901D-4DBE-BCAB-251048D3A556}
[2012/03/09 11:58:28 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{92E8A794-6F62-447B-97CD-EEF9E7837683}
[2012/03/08 23:30:25 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{2EE81C7B-48DB-4396-94DB-7E71DD57A505}
[2012/03/08 23:30:22 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{DD81E67A-3F42-4E1D-8DC9-8C8EFF41BEB4}
[2012/03/08 10:28:30 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{37CA2DE7-B888-4E48-A407-4DF3C61E730A}
[2012/03/08 10:28:28 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7E489A2B-8C67-4F6A-B186-FF7528486C43}
[2012/03/07 22:28:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{B9E2249A-CE19-4918-A925-3A1B6AAE2A0D}
[2012/03/07 22:28:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{646A9D54-173F-4C7C-A932-55CD11882634}
[2012/03/07 10:27:52 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{D311C485-1A3D-4159-B75D-DEFA85B798C9}
[2012/03/07 10:27:50 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{80ED6C17-AF4E-40F1-81BF-75F90D89013B}
[2012/03/05 21:33:44 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9724CD62-8715-473E-A7E3-AC1B6A09FB13}
[2012/03/05 21:33:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{4A803C46-0459-46EB-A625-3A2F10034D7D}
[2012/03/04 18:37:54 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0E625902-4031-42B3-B884-730F3A1CF2CE}
[2012/03/04 18:37:47 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{2135EB0B-ECEB-4CA0-834E-D2D53577EBD1}
[2012/03/03 13:05:45 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BFB2DC2E-F49B-4F24-B411-7C405055EF1D}
[2012/03/03 13:05:43 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{13843259-C6A7-438B-BC62-127E7F7A2DB0}
[2012/03/02 08:59:18 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{FA0642B0-CA18-4E07-AF3C-9171F4B55972}
[2012/03/02 08:59:16 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{DE688002-CCF6-4539-AC64-FDD04B0FE96C}
[2012/03/01 20:58:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{073DFFC2-C934-44C9-B0CC-6848FC66DCB1}
[2012/03/01 20:58:57 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{A7F26472-FC77-4082-8601-B6F89BEB917C}
[2012/03/01 08:56:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{CF5E07F8-4E52-4379-AD20-70B31F350CFB}
[2012/03/01 08:56:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{281C50A9-BEE9-4511-864B-98625E806E2C}
[2012/02/29 19:47:14 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{52C38772-5E6B-4EFA-89C5-9EB49831195D}
[2012/02/29 19:47:12 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0320F406-0F0C-4085-8F89-3CA75AEA7101}
[2012/02/28 18:58:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{C6C0836C-8E46-42BC-B6FE-ACBE072C3C95}
[2012/02/28 18:58:40 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F74C2738-9B70-4A9E-9713-33AD309AE07E}
========== Files - Modified Within 30 Days ==========
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 20:56:01 | 000,644,550 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/28 20:56:01 | 000,120,604 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/28 20:28:03 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{59258D2C-2DBF-4D9B-A91F-9F4134F4135C}.job
[2012/03/28 20:06:36 | 000,002,569 | ---- | M] () -- C:\Users\Thathi Pooh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2012/03/28 19:43:02 | 000,003,284 | ---- | M] () -- C:\Windows\System32\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:43:02 | 000,003,284 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:42:21 | 000,000,007 | ---- | M] () -- C:\Windows\System32\ANIWZCSUSERNAME
[2012/03/28 19:40:39 | 000,000,007 | ---- | M] () -- C:\Windows\System32\ANIWZCSUSERNAME{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:40:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/25 22:57:48 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
[2012/03/22 23:12:12 | 004,435,968 | ---- | M] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2012/03/21 01:08:35 | 000,000,947 | ---- | M] () -- C:\Users\Thathi Pooh\Desktop\Dropbox.lnk
[2012/03/21 00:49:39 | 000,000,927 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/03/14 10:32:42 | 000,265,120 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/03/10 12:45:05 | 000,001,245 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2012/03/10 12:42:34 | 000,001,624 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/03/08 22:54:19 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
========== Files Created - No Company Name ==========
[2012/03/21 01:08:34 | 000,000,947 | ---- | C] () -- C:\Users\Thathi Pooh\Desktop\Dropbox.lnk
[2012/03/21 00:49:38 | 000,000,927 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/03/10 12:42:34 | 000,001,624 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/07/13 23:08:28 | 000,747,592 | ---- | C] () -- C:\Windows\System32\pwNative.exe
[2011/07/13 23:08:27 | 000,016,472 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys
[2011/07/13 23:08:04 | 000,011,104 | ---- | C] () -- C:\Windows\System32\pwdspio.sys
[2011/05/12 22:30:09 | 000,001,940 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/16 17:43:01 | 000,000,253 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANICONFIG_{7239AC13-6A83-4F8E-8635-CA6376FFF840}.ini
[2011/03/15 17:12:54 | 000,000,000 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Local\Schedule8.dat
[2011/02/10 05:54:58 | 003,973,120 | ---- | C] () -- C:\Windows\System32\ffmpeg2.exe
[2010/10/28 11:58:31 | 000,003,284 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2010/10/28 11:53:35 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\anodlwf.sys
[2010/10/28 11:53:34 | 000,013,931 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/03/25 22:57:48 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2012/03/18 22:34:03 | 000,125,880 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2012/03/18 22:34:03 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2012/03/18 22:34:02 | 000,016,824 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2012/03/18 22:34:02 | 000,269,240 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () Unable to obtain MD5 -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () Unable to obtain MD5 -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2011/07/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2011/07/14 17:50:51 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2011/07/15 13:47:51 | 000,000,000 | ---D | M] -- C:\Program Files\Applian Director
[2011/07/16 23:21:55 | 000,000,000 | ---D | M] -- C:\Program Files\Applian Technologies
[2011/01/14 11:12:40 | 000,000,000 | ---D | M] -- C:\Program Files\BlackBYTE Free Speech Vista
[2011/10/15 11:23:15 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2011/07/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/09/08 01:11:03 | 000,000,000 | ---D | M] -- C:\Program Files\coolpro2
[2009/11/07 01:51:06 | 000,000,000 | ---D | M] -- C:\Program Files\Creative
[2009/07/25 22:38:56 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2010/10/28 11:53:34 | 000,000,000 | ---D | M] -- C:\Program Files\D-Link
[2009/07/28 00:27:12 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2011/05/28 14:43:53 | 000,000,000 | ---D | M] -- C:\Program Files\e-Sword
[2010/08/20 12:26:08 | 000,000,000 | ---D | M] -- C:\Program Files\EPSON
[2011/11/04 00:30:46 | 000,000,000 | ---D | M] -- C:\Program Files\Everything
[2011/04/09 22:55:48 | 000,000,000 | ---D | M] -- C:\Program Files\FOTOBOOK
[2011/05/24 20:30:05 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2011/03/06 21:53:44 | 000,000,000 | ---D | M] -- C:\Program Files\Griffin Technology
[2011/11/02 05:51:42 | 000,000,000 | ---D | M] -- C:\Program Files\iExplorer
[2011/05/24 20:18:18 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield
Also for some applications the following message appears.
There is no disk in the drive. Please insert a disk into drive\Decice\Harddisk2\DR5
Cancel/try again/continue
Please help it seems that something is slowing me down but not sure what. have added all the logs you asked for. Please try and help.
thanks
harsha
OTL logfile created on: 3/28/2012 9:43:13 PM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = F:\Downloads
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19190)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 52.89% Memory free
9.24 Gb Paging File | 7.86 Gb Available in Paging File | 85.05% Paging File free
Paging file location(s): d:\pagefile.sys 6500 7417 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 154.83 Gb Total Space | 64.78 Gb Free Space | 41.84% Space Free | Partition Type: NTFS
Drive D: | 7.30 Gb Total Space | 0.87 Gb Free Space | 11.87% Space Free | Partition Type: NTFS
Drive E: | 303.63 Gb Total Space | 57.61 Gb Free Space | 18.97% Space Free | Partition Type: NTFS
Drive F: | 2794.51 Gb Total Space | 2072.35 Gb Free Space | 74.16% Space Free | Partition Type: NTFS
Drive I: | 74.53 Gb Total Space | 15.11 Gb Free Space | 20.28% Space Free | Partition Type: NTFS
Computer Name: THATHIPOOH-PC | User Name: Thathi Pooh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/25 22:55:32 | 000,594,432 | ---- | M] (OldTimer Tools) -- F:\Downloads\OTL.com
PRC - [2012/02/23 12:30:40 | 000,059,240 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Internet Services\ubd.exe
PRC - [2012/02/15 03:03:14 | 024,246,216 | ---- | M] (Dropbox, Inc.) -- C:\Users\Thathi Pooh\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/06/01 20:42:28 | 000,071,432 | ---- | M] (Memeo) -- C:\Program Files\Seagate\Seagate Dashboard\MemeoDashboard.exe
PRC - [2011/06/01 20:42:28 | 000,014,088 | ---- | M] (Memeo) -- C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe
PRC - [2011/06/01 20:16:54 | 002,260,992 | ---- | M] (Axentra Corporation) -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\HipServAgent.exe
PRC - [2011/04/17 04:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\5.2.0.13\ccsvchst.exe
PRC - [2011/01/24 22:36:28 | 000,085,272 | ---- | M] (Memeo Inc.) -- C:\Program Files\Memeo\AutoBackup\MemeoUpdater.exe
PRC - [2011/01/24 22:35:36 | 000,025,824 | ---- | M] (Memeo) -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe
PRC - [2011/01/24 22:35:30 | 000,324,320 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\InstantBackup.exe
PRC - [2009/12/29 11:27:16 | 000,995,328 | ---- | M] (D-Link Corp.) -- C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe
PRC - [2009/10/19 18:39:38 | 000,122,880 | ---- | M] (Wireless Service) -- C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe
PRC - [2009/07/07 19:49:20 | 000,040,960 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe
PRC - [2009/04/11 10:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2007/02/23 16:32:56 | 000,126,976 | ---- | M] (SAMSUNG ELECTRONICS) -- C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
PRC - [2006/09/15 13:21:54 | 000,675,840 | ---- | M] (Sonix) -- C:\Windows\vsnp2std.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/16 22:48:58 | 001,711,616 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6310a2050033b0b567428ca55bda4a1b\Microsoft.VisualBasic.ni.dll
MOD - [2012/02/16 22:47:36 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d0cf808e33a5123b33010b933d3b1597\System.ServiceProcess.ni.dll
MOD - [2012/02/16 22:47:33 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll
MOD - [2012/02/16 22:47:30 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\2598077ccea480c6120d3a1ad4455be0\System.Web.ni.dll
MOD - [2012/02/16 22:47:06 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll
MOD - [2012/02/16 22:45:40 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll
MOD - [2012/02/16 22:45:26 | 012,430,848 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\65450889f3742aada2a6c0cf8e6173e3\System.Windows.Forms.ni.dll
MOD - [2012/02/16 22:45:18 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\137696d0416b65dbc1561152971488b4\System.Drawing.ni.dll
MOD - [2012/02/16 22:45:08 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\029217106fa24787ff7a61b754f8ebf7\System.Data.ni.dll
MOD - [2012/02/16 22:44:28 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll
MOD - [2011/11/03 08:52:31 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll
MOD - [2011/11/03 08:52:30 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/06/01 20:46:02 | 000,030,984 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\Plugins\Memeo.Dashboard.SeagateSharePlusPlugin.dll
MOD - [2011/06/01 20:42:24 | 000,108,296 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\Memeo.Progress.dll
MOD - [2011/06/01 20:16:54 | 000,971,776 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libxml2.dll
MOD - [2011/06/01 20:16:54 | 000,241,664 | ---- | M] () -- C:\Program Files\Seagate\Seagate Dashboard\HipServAgent\libupnp.dll
MOD - [2011/01/24 22:35:58 | 002,896,608 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\Memeo.Client.UI.dll
MOD - [2011/01/24 22:35:54 | 000,026,848 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\Memeo.Client.DriveDetection.dll
MOD - [2011/01/24 22:35:30 | 000,324,320 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\InstantBackup.exe
MOD - [2010/10/28 11:56:40 | 000,315,392 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\ANPDApi.dll
MOD - [2010/03/23 02:59:46 | 000,504,293 | ---- | M] () -- C:\Program Files\Memeo\AutoBackup\sqlite3.dll
MOD - [2009/10/19 18:59:12 | 000,274,432 | ---- | M] () -- C:\Program Files\D-Link\DWA-125 revA\wlanapp.dll
MOD - [2009/03/30 08:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2008/12/27 20:55:46 | 000,089,600 | ---- | M] () -- C:\Program Files\Griffin Technology\iTalk Sync\CopyHook.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/01/04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/06/01 20:42:28 | 000,014,088 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Seagate\Seagate Dashboard\SeagateDashboardService.exe -- (SeagateDashboardService)
SRV - [2011/04/17 04:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\5.2.0.13\ccSvcHst.exe -- (N360)
SRV - [2011/01/24 22:35:36 | 000,025,824 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Memeo\AutoBackup\MemeoBackgroundService.exe -- (MemeoBackgroundService)
SRV - [2009/10/07 16:50:26 | 000,185,640 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files\TeamViewer\Version4\TeamViewer_Service.exe -- (TeamViewer4)
SRV - [2009/08/21 09:27:26 | 000,126,976 | ---- | M] (Wireless Service) [Auto | Stopped] -- C:\Program Files\D-Link\DWA-125 revA\ANIWZCSdS.exe -- (D_Link_DWA-125)
SRV - [2009/07/07 19:49:20 | 000,040,960 | ---- | M] () [Auto | Running] -- C:\Program Files\D-Link\DWA-125 revA\ANIWConnService.exe -- (D_Link_DWA-125_WPS)
SRV - [2009/03/06 12:59:12 | 000,020,376 | ---- | M] (WebEx Communications, Inc.) [Disabled | Stopped] -- C:\Windows\System32\atashost.exe -- (atashost)
SRV - [2008/02/18 14:36:14 | 001,553,704 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe -- (InCDsrv)
SRV - [2008/01/21 06:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/07 00:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/06/03 15:39:32 | 000,016,384 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\BlackBYTE Free Speech Vista\bin\blackbyteserv.exe -- (OpenVPNService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMNDISV.SYS -- (SYMNDISV)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\N360\0308000.029\SYMFW.SYS -- (SYMFW)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012/03/06 16:04:10 | 000,368,248 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20120327.002\IDSvix86.sys -- (IDSVix86)
DRV - [2012/03/02 22:58:02 | 000,820,856 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20120317.002\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/02/04 14:03:59 | 000,374,392 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/02/04 14:03:59 | 000,106,104 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/11/01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 10:07:24 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2011/11/01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/11/01 10:07:24 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/08/04 10:11:05 | 001,576,312 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120327.037\NAVEX15.SYS -- (NAVEX15)
DRV - [2011/08/04 10:11:05 | 000,086,136 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20120327.037\NAVENG.SYS -- (NAVENG)
DRV - [2011/06/26 04:56:44 | 000,028,256 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\appliand.sys -- (appliandMP)
DRV - [2011/06/26 04:56:44 | 000,028,256 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\appliand.sys -- (appliand)
DRV - [2011/06/05 09:29:31 | 000,126,584 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2011/05/06 14:30:36 | 000,016,472 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio)
DRV - [2011/05/06 14:30:28 | 000,011,104 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio)
DRV - [2011/04/21 05:37:49 | 000,331,384 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symtdiv.sys -- (SYMTDIv)
DRV - [2011/03/31 07:00:09 | 000,516,216 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\srtsp.sys -- (SRTSP)
DRV - [2011/03/31 07:00:09 | 000,050,168 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\srtspx.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV - [2011/03/15 06:31:23 | 000,744,568 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symefa.sys -- (SymEFA)
DRV - [2011/01/27 10:47:10 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\symds.sys -- (SymDS)
DRV - [2011/01/27 09:07:05 | 000,136,312 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\0502000.00D\ironx86.sys -- (SymIRON)
DRV - [2009/12/30 11:21:18 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/09/21 11:31:17 | 000,027,136 | ---- | M] (NCH Swift Sound) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nchssvad.sys -- (NCHSSVAD)
DRV - [2009/09/15 13:47:44 | 000,798,208 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Dnetr28u.sys -- (netr28u)
DRV - [2009/07/11 21:14:09 | 000,016,608 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2009/03/06 18:09:52 | 000,012,800 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\drivers\anodlwf.sys -- (anodlwf)
DRV - [2008/12/10 12:37:46 | 000,135,680 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtlh86.sys -- (RTL8169)
DRV - [2008/09/06 13:42:34 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tap0801.sys -- (tap0801)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/02/18 14:36:14 | 000,038,312 | ---- | M] (Nero AG) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\InCDRm.sys -- (incdrm)
DRV - [2008/02/18 14:36:14 | 000,036,648 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\Windows\System32\drivers\InCDPass.sys -- (InCDPass)
DRV - [2008/02/18 14:36:14 | 000,016,040 | ---- | M] (Nero AG) [Recognizer | System | Unknown] -- C:\Windows\System32\drivers\InCDrec.sys -- (InCDrec)
DRV - [2008/02/18 14:36:04 | 000,118,952 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\Windows\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2008/01/24 01:25:32 | 000,027,136 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tapvpn.sys -- (tapvpn)
DRV - [2007/11/07 00:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2007/03/30 14:41:54 | 012,033,024 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {40439b93-f815-4122-8073-d03bed94c303}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
IE - HKLM\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us
IE - HKLM\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKLM\..\SearchScopes\{EEE7E0A3-AE64-4dc8-84D1-F5D7BAF2DB0C}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50winampie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://theacademic.org/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {C8929A7D-4606-4CB4-B62E-C8F77551274C}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src=IE-SearchBox&Form=IE8SRC
IE - HKCU\..\SearchScopes\{40439b93-f815-4122-8073-d03bed94c303}: "URL" = http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&query={searchTerms}&invocationType=tb50-ie-shoutcast-chromesbox-en-us
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/web?&o=101881&l=dis&q={SEARCHTERMS}
IE - HKCU\..\SearchScopes\{C8929A7D-4606-4CB4-B62E-C8F77551274C}: "URL" = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}&rlz=1I7ADFA_en
IE - HKCU\..\SearchScopes\{EF20B2D8-708C-44D9-8DDD-50C16AE2EB0B}: "URL" = http://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.theacademic.org/"
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.3.448: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2010/09/05 20:40:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2012/02/01 16:55:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn_2011_7_6_3 [2012/03/28 19:40:45 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_9.0 [2012/01/27 12:04:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/18 22:34:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/11/05 23:43:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/01/27 12:04:53 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{380AE6CB-09B9-4373-B360-D01C2462A6E7}: C:\Program Files\BullGuard Ltd\BullGuard\backup\thunderbirdbkplugin
FF - HKEY_CURRENT_USER\software\mozilla\Thunderbird\Extensions\\{0E810812-F4BB-4309-942A-755587587A5E}: C:\Program Files\BullGuard Ltd\BullGuard\antispam\tbspamfilter
[2009/10/16 12:42:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Extensions
[2012/02/17 01:27:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions
[2012/02/17 01:27:38 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/04/27 16:44:56 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/05/12 22:09:34 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\extensions\engine@conduit.com
[2012/02/24 17:33:29 | 000,002,359 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\Mozilla\Firefox\Profiles\0t6eje54.default\searchplugins\google-us.xml
[2011/11/11 08:41:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/03/28 19:40:45 | 000,000,000 | ---D | M] (Norton Toolbar) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\COFFPLGN_2011_7_6_3
[2012/02/01 16:55:17 | 000,000,000 | ---D | M] (Symantec Intrusion Prevention) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPLGN
() (No name found) -- C:\USERS\THATHI POOH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0T6EJE54.DEFAULT\EXTENSIONS\AMZNUWL2@AMAZON.COM.XPI
[2012/03/18 22:34:03 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/04/12 17:29:19 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/02/12 09:21:55 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/12 09:21:55 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2006/09/19 01:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\5.2.0.13\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\5.2.0.13\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\5.2.0.13\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [D-Link D-Link DWA-125] C:\Program Files\D-Link\DWA-125 revA\AirGCFG.exe (D-Link Corp.)
O4 - HKLM..\Run: [LanguageShortcut] C:\Program Files\CyberLink\PowerDVD\Language\Language.exe ()
O4 - HKLM..\Run: [Memeo AutoSync] C:\Program Files\Memeo\AutoSync\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Memeo Instant Backup] C:\Program Files\Memeo\AutoBackup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKLM..\Run: [Seagate Dashboard] C:\Program Files\Seagate\Seagate Dashboard\MemeoLauncher.exe ()
O4 - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [WZCSLDR2] C:\Program Files\D-Link\DWA-125 revA\WZCSLDR2.exe (Wireless Service)
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [EPSON Stylus CX4300 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATICAR.EXE (SEIKO EPSON CORPORATION)
O4 - HKCU..\Run: [MobileDocuments] C:\Program Files\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKCU..\Run: [replay_telecorder_skype] File not found
O4 - Startup: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Thathi Pooh\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (Reg Error: Value error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7239AC13-6A83-4F8E-8635-CA6376FFF840}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {88485281-8b4b-4f8d-9ede-82e29a064277} - C:\Program Files\MarkAny\ContentSafer\MACSMANAGER.dll (MarkAny Cooperation.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/21 23:42:49 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/02/15 08:53:50 | 000,000,027 | ---- | M] () - F:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{02d73188-6e96-11de-8cf0-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{02d73188-6e96-11de-8cf0-806e6f6e6963}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{40661170-ceca-11de-a27e-00241d3c93ea}\Shell\AutoRun\command - "" = H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe
O33 - MountPoints2\{40661170-ceca-11de-a27e-00241d3c93ea}\Shell\open\command - "" = H:\SYSTEM\S-1-5-21-1482476501-1644491937-682003330-1013\system32.exe
O33 - MountPoints2\{61edb4dd-471d-11df-8c96-00241d3c93ea}\Shell\AutoRun\command - "" = H:\installer.exe
O33 - MountPoints2\{61edb4dd-471d-11df-8c96-00241d3c93ea}\Shell\verb\command - "" = H:\installer.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\AutoRun\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\explore\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{83193d41-bcc2-11de-98bd-00241d3c93ea}\Shell\open\command - "" = H:\U3ROM/system32.exe
O33 - MountPoints2\{98530c59-3d67-11e0-9a33-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{98530c59-3d67-11e0-9a33-00241d3c93ea}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{dd9b73f0-5c20-11e0-8ffe-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{dd9b73f0-5c20-11e0-8ffe-00241d3c93ea}\Shell\AutoRun\command - "" = I:\MI.exe
O33 - MountPoints2\{dda79276-c3f3-11df-9ad1-00241d3c93ea}\Shell - "" = AutoRun
O33 - MountPoints2\{dda79276-c3f3-11df-9ad1-00241d3c93ea}\Shell\AutoRun\command - "" = H:\NokiaPCIA_Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^ImageMixer 3 SE Camera Monitor Ver.4.lnk - - File not found
MsConfig - StartUpFolder: C:^Users^Thathi Pooh^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE - (Microsoft Corporation)
MsConfig - StartUpReg: AppleSyncNotifier - hkey= - key= - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
MsConfig - StartUpReg: BitComet - hkey= - key= - File not found
MsConfig - StartUpReg: EPSON Stylus CX4300 Series - hkey= - key= - File not found
MsConfig - StartUpReg: Freecorder FLV Service - hkey= - key= - File not found
MsConfig - StartUpReg: LGODDFU - hkey= - key= - C:\Program Files\lg_fwupdate\fwupdate.exe (BL)
MsConfig - StartUpReg: MAAgent - hkey= - key= - C:\Program Files\MarkAny\ContentSafer\MaAgent.exe ((주)마크애니)
MsConfig - StartUpReg: NBKeyScan - hkey= - key= - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe (Nero AG)
MsConfig - StartUpReg: nmapp - hkey= - key= - Reg Error: Value error. File not found
MsConfig - StartUpReg: WinampAgent - hkey= - key= - File not found
MsConfig - State: "services" - 2
MsConfig - State: "startup" - 2
SafeBootMin: AppMgmt - Service
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - Service
SafeBootNet: atashost - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: vsmon - Service
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {3C3901C5-3455-3E0A-A214-0B093A5070A6} - .NET Framework
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\Windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.scg726 - C:\Windows\System32\scg726.acm (SHARP Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - ff_vfw.dll File not found
Drivers32: vidc.tscc - C:\Program Files\MpcStar\Codecs\tscc\tsccvid.dll (TechSmith Corporation)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\System32\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/03/28 13:21:56 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7D695D29-6484-43EB-B1BD-7110B9A8E311}
[2012/03/28 13:21:53 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BDE602FB-3B87-40BE-8456-463CD39B9F3B}
[2012/03/27 18:21:17 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F5E319AF-C924-43BD-B80C-D62B20D21409}
[2012/03/27 18:21:15 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9D3F587A-7BA0-4C5F-9B21-629FB070CA47}
[2012/03/27 06:21:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F6D5E598-1539-4C8E-8481-D6E332E1C196}
[2012/03/27 06:21:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{482E3238-416B-48B9-AC1F-E978522D2D2A}
[2012/03/26 18:21:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F9F08BD6-0C63-4379-B051-DC59A8776C13}
[2012/03/26 18:21:02 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6BD09716-63B6-408A-85BD-D150DEFC846C}
[2012/03/25 23:16:33 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\NPE
[2012/03/25 22:57:16 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
[2012/03/25 22:35:20 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{668CD80F-6ECD-47F5-A02B-38CAC8236CB9}
[2012/03/25 22:35:17 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{3108BF1B-E8FC-4567-A104-9BDEA5D38733}
[2012/03/25 10:35:00 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8D2CE574-1A73-4941-9D69-A9E0B1D2D87A}
[2012/03/25 10:34:58 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BCDACD9E-E440-44A4-B1BE-2B79DEE97A92}
[2012/03/23 08:55:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{34900CBD-36FE-44A5-8E57-0849EDE6E21F}
[2012/03/23 08:55:53 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9FF6C2F0-7882-4AD6-AA3B-BD92DBFEB856}
[2012/03/22 23:12:12 | 004,435,968 | ---- | C] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2012/03/21 22:41:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{01DFFBD0-DC5E-4AA7-A42E-B907DDB58E8D}
[2012/03/21 22:41:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8E63CA75-82FE-4CC8-AACD-4C6B5961BA16}
[2012/03/21 10:40:47 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EE7B63F6-AF1B-44A5-85D9-DB91FE94D8A5}
[2012/03/21 10:40:41 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EBF02A46-4484-4C9A-8389-4E52002D76A2}
[2012/03/21 00:49:22 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/03/20 19:02:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7E0C0C25-1F7B-4968-B2CF-B15A53DD96CD}
[2012/03/20 19:02:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{C34007F6-F872-4BF3-8D92-29458F899653}
[2012/03/19 16:15:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{42CB6140-F353-4564-BCB1-37531C1AF931}
[2012/03/19 16:15:57 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0A753374-1BE7-41E9-8DAF-F6FA37A7EB7F}
[2012/03/18 22:31:50 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6092210E-4B8E-49C6-B5A5-D726ECC0083D}
[2012/03/18 22:31:48 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{496D5248-CC1A-4C7F-A825-1B144EA3ADB4}
[2012/03/18 08:10:13 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{4F7EBEE0-8452-45B3-98AB-EB834B77E08C}
[2012/03/18 08:10:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{AC66D9C4-8DF8-40F7-AA58-5ADB579DC16C}
[2012/03/17 18:57:45 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{56B71737-6409-49E7-814B-F8E59E1A1D1C}
[2012/03/17 18:57:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{3D5BCF3A-6F93-48FF-B46E-1287822FC492}
[2012/03/16 19:49:20 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{597A2263-EC71-4AF7-9DF6-4CDF07B92689}
[2012/03/16 19:48:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{8571F740-F200-4F31-B13A-4D3EC9255CA3}
[2012/03/15 21:48:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{EB2666CE-DE88-47A9-B5A5-E470F6FEA868}
[2012/03/15 21:48:03 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BD1DFF17-F6E8-415B-B1E7-A2125355BF75}
[2012/03/14 22:02:39 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F111861F-A0FD-482E-99DB-0E66E764F180}
[2012/03/14 22:02:36 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{6A1E0C12-02C4-4860-8FC5-9A6446B07F05}
[2012/03/14 07:05:13 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{711EEC27-62D6-4F45-B9C1-89B3CA59320A}
[2012/03/14 07:05:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{54823A60-D0B3-4BD1-AFF0-04B9C25F21C2}
[2012/03/14 01:12:54 | 002,044,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/03/14 01:12:52 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2012/03/14 01:12:52 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2012/03/14 01:12:52 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2012/03/14 01:12:52 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2012/03/14 01:12:52 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2012/03/14 01:12:14 | 000,613,376 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpencom.dll
[2012/03/13 19:05:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{863071F3-88F4-423F-AB11-D014565DC175}
[2012/03/13 19:05:04 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{E7E7CAE1-19E5-47C2-940D-652062A22D77}
[2012/03/10 22:15:43 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{377A917D-B500-4AF8-8C13-8B5CFFF26BE4}
[2012/03/10 22:15:41 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{51575192-76B8-4076-9AC8-3D8AB5568E2B}
[2012/03/10 12:42:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/03/10 12:41:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/03/10 12:41:49 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/03/10 10:15:25 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{97168F73-6032-447F-BCCF-9BBAE12317A2}
[2012/03/10 10:15:21 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{04C010AC-774B-4601-BA7D-EAFD2E032FAC}
[2012/03/09 11:58:36 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{AF2D79A9-901D-4DBE-BCAB-251048D3A556}
[2012/03/09 11:58:28 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{92E8A794-6F62-447B-97CD-EEF9E7837683}
[2012/03/08 23:30:25 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{2EE81C7B-48DB-4396-94DB-7E71DD57A505}
[2012/03/08 23:30:22 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{DD81E67A-3F42-4E1D-8DC9-8C8EFF41BEB4}
[2012/03/08 10:28:30 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{37CA2DE7-B888-4E48-A407-4DF3C61E730A}
[2012/03/08 10:28:28 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{7E489A2B-8C67-4F6A-B186-FF7528486C43}
[2012/03/07 22:28:11 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{B9E2249A-CE19-4918-A925-3A1B6AAE2A0D}
[2012/03/07 22:28:09 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{646A9D54-173F-4C7C-A932-55CD11882634}
[2012/03/07 10:27:52 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{D311C485-1A3D-4159-B75D-DEFA85B798C9}
[2012/03/07 10:27:50 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{80ED6C17-AF4E-40F1-81BF-75F90D89013B}
[2012/03/05 21:33:44 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{9724CD62-8715-473E-A7E3-AC1B6A09FB13}
[2012/03/05 21:33:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{4A803C46-0459-46EB-A625-3A2F10034D7D}
[2012/03/04 18:37:54 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0E625902-4031-42B3-B884-730F3A1CF2CE}
[2012/03/04 18:37:47 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{2135EB0B-ECEB-4CA0-834E-D2D53577EBD1}
[2012/03/03 13:05:45 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{BFB2DC2E-F49B-4F24-B411-7C405055EF1D}
[2012/03/03 13:05:43 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{13843259-C6A7-438B-BC62-127E7F7A2DB0}
[2012/03/02 08:59:18 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{FA0642B0-CA18-4E07-AF3C-9171F4B55972}
[2012/03/02 08:59:16 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{DE688002-CCF6-4539-AC64-FDD04B0FE96C}
[2012/03/01 20:58:59 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{073DFFC2-C934-44C9-B0CC-6848FC66DCB1}
[2012/03/01 20:58:57 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{A7F26472-FC77-4082-8601-B6F89BEB917C}
[2012/03/01 08:56:07 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{CF5E07F8-4E52-4379-AD20-70B31F350CFB}
[2012/03/01 08:56:05 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{281C50A9-BEE9-4511-864B-98625E806E2C}
[2012/02/29 19:47:14 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{52C38772-5E6B-4EFA-89C5-9EB49831195D}
[2012/02/29 19:47:12 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{0320F406-0F0C-4085-8F89-3CA75AEA7101}
[2012/02/28 18:58:42 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{C6C0836C-8E46-42BC-B6FE-ACBE072C3C95}
[2012/02/28 18:58:40 | 000,000,000 | ---D | C] -- C:\Users\Thathi Pooh\AppData\Local\{F74C2738-9B70-4A9E-9713-33AD309AE07E}
========== Files - Modified Within 30 Days ==========
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 20:56:01 | 000,644,550 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/03/28 20:56:01 | 000,120,604 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/03/28 20:28:03 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{59258D2C-2DBF-4D9B-A91F-9F4134F4135C}.job
[2012/03/28 20:06:36 | 000,002,569 | ---- | M] () -- C:\Users\Thathi Pooh\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2007.lnk
[2012/03/28 19:43:02 | 000,003,284 | ---- | M] () -- C:\Windows\System32\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:43:02 | 000,003,284 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:42:21 | 000,000,007 | ---- | M] () -- C:\Windows\System32\ANIWZCSUSERNAME
[2012/03/28 19:40:39 | 000,000,007 | ---- | M] () -- C:\Windows\System32\ANIWZCSUSERNAME{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2012/03/28 19:40:34 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/03/25 22:57:48 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
[2012/03/22 23:12:12 | 004,435,968 | ---- | M] (Google Inc.) -- C:\Windows\System32\GPhotos.scr
[2012/03/21 01:08:35 | 000,000,947 | ---- | M] () -- C:\Users\Thathi Pooh\Desktop\Dropbox.lnk
[2012/03/21 00:49:39 | 000,000,927 | ---- | M] () -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/03/14 10:32:42 | 000,265,120 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/03/10 12:45:05 | 000,001,245 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2012/03/10 12:42:34 | 000,001,624 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/03/08 22:54:19 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
========== Files Created - No Company Name ==========
[2012/03/21 01:08:34 | 000,000,947 | ---- | C] () -- C:\Users\Thathi Pooh\Desktop\Dropbox.lnk
[2012/03/21 00:49:38 | 000,000,927 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/03/10 12:42:34 | 000,001,624 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/07/13 23:08:28 | 000,747,592 | ---- | C] () -- C:\Windows\System32\pwNative.exe
[2011/07/13 23:08:27 | 000,016,472 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys
[2011/07/13 23:08:04 | 000,011,104 | ---- | C] () -- C:\Windows\System32\pwdspio.sys
[2011/05/12 22:30:09 | 000,001,940 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/03/16 17:43:01 | 000,000,253 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANICONFIG_{7239AC13-6A83-4F8E-8635-CA6376FFF840}.ini
[2011/03/15 17:12:54 | 000,000,000 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Local\Schedule8.dat
[2011/02/10 05:54:58 | 003,973,120 | ---- | C] () -- C:\Windows\System32\ffmpeg2.exe
[2010/10/28 11:58:31 | 000,003,284 | ---- | C] () -- C:\Users\Thathi Pooh\AppData\Roaming\ANIWZCS{7239AC13-6A83-4F8E-8635-CA6376FFF840}
[2010/10/28 11:53:35 | 000,012,800 | ---- | C] () -- C:\Windows\System32\drivers\anodlwf.sys
[2010/10/28 11:53:34 | 000,013,931 | ---- | C] () -- C:\Windows\System32\RaCoInst.dat
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
[2012/03/25 22:57:48 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Thathi Pooh\Desktop\aswMBR.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2012/03/18 22:34:03 | 000,125,880 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2012/03/18 22:34:03 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2012/03/18 22:34:02 | 000,016,824 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2012/03/18 22:34:02 | 000,269,240 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () Unable to obtain MD5 -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/03/28 21:40:36 | 000,003,712 | -H-- | M] () Unable to obtain MD5 -- C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2011/07/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2011/07/14 17:50:51 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2011/07/15 13:47:51 | 000,000,000 | ---D | M] -- C:\Program Files\Applian Director
[2011/07/16 23:21:55 | 000,000,000 | ---D | M] -- C:\Program Files\Applian Technologies
[2011/01/14 11:12:40 | 000,000,000 | ---D | M] -- C:\Program Files\BlackBYTE Free Speech Vista
[2011/10/15 11:23:15 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2011/07/17 00:16:00 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/09/08 01:11:03 | 000,000,000 | ---D | M] -- C:\Program Files\coolpro2
[2009/11/07 01:51:06 | 000,000,000 | ---D | M] -- C:\Program Files\Creative
[2009/07/25 22:38:56 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2010/10/28 11:53:34 | 000,000,000 | ---D | M] -- C:\Program Files\D-Link
[2009/07/28 00:27:12 | 000,000,000 | ---D | M] -- C:\Program Files\DIFX
[2011/05/28 14:43:53 | 000,000,000 | ---D | M] -- C:\Program Files\e-Sword
[2010/08/20 12:26:08 | 000,000,000 | ---D | M] -- C:\Program Files\EPSON
[2011/11/04 00:30:46 | 000,000,000 | ---D | M] -- C:\Program Files\Everything
[2011/04/09 22:55:48 | 000,000,000 | ---D | M] -- C:\Program Files\FOTOBOOK
[2011/05/24 20:30:05 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2011/03/06 21:53:44 | 000,000,000 | ---D | M] -- C:\Program Files\Griffin Technology
[2011/11/02 05:51:42 | 000,000,000 | ---D | M] -- C:\Program Files\iExplorer
[2011/05/24 20:18:18 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield