drivers32
%SYSTEMDRIVE%*.*
%systemroot%Fonts*.com
%systemroot%Fonts*.dll
%systemroot%Fonts*.ini
%systemroot%Fonts*.ini2
%systemroot%Fonts*.exe
%systemroot%system32spoolprtprocsw32x86*.*
%systemroot%REPAIR*.bak1
%systemroot%REPAIR*.ini
%systemroot%system32*.jpg
%systemroot%*.jpg
%systemroot%*.png
%systemroot%*.scr
%systemroot%*._sy
%APPDATA%AdobeUpdate*.*
%ALLUSERSPROFILE%Favorites*.*
%APPDATA%Microsoft*.*
%PROGRAMFILES%*.*
%APPDATA%Update*.*
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%System32config*.sav
%PROGRAMFILES%bak. /s
%systemroot%system32bak. /s
%ALLUSERSPROFILE%Start Menu*.lnk /x
%systemroot%system32configsystemprofile*.dat /x
%systemroot%*.config
%systemroot%system32*.db
%PROGRAMFILES%Internet Explorer*.dat
%APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x
%USERPROFILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs
netsvcs
drivers32
%SYSTEMDRIVE%*.*
%systemroot%Fonts*.com
%systemroot%Fonts*.dll
%systemroot%Fonts*.ini
%systemroot%Fonts*.ini2
%systemroot%Fonts*.exe
%systemroot%system32spoolprtprocsw32x86*.*
%systemroot%REPAIR*.bak1
%systemroot%REPAIR*.ini
%systemroot%system32*.jpg
%systemroot%*.jpg
%systemroot%*.png
%systemroot%*.scr
%systemroot%*._sy
%APPDATA%AdobeUpdate*.*
%ALLUSERSPROFILE%Favorites*.*
%APPDATA%Microsoft*.*
%PROGRAMFILES%*.*
%APPDATA%Update*.*
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%System32config*.sav
%PROGRAMFILES%bak. /s
%systemroot%system32bak. /s
%ALLUSERSPROFILE%Start Menu*.lnk /x
%systemroot%system32configsystemprofile*.dat /x
%systemroot%*.config
%systemroot%system32*.db
%PROGRAMFILES%Internet Explorer*.dat
%APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x
%USERPROFILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rsOTL logfile created on: 6/1/2012 5:38:29 PM - Run 3
OTL by OldTimer - Version 3.2.45.0 Folder = C:UserscdooDownloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.92 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 45.03% Memory free
7.83 Gb Paging File | 5.72 Gb Available in Paging File | 73.10% Paging File free
Paging file location(s): ?:pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:windows | %ProgramFiles% = C:Program Files (x86)
Drive C: | 654.69 Gb Total Space | 270.55 Gb Free Space | 41.32% Space Free | Partition Type: NTFS
Drive D: | 29.00 Gb Total Space | 26.41 Gb Free Space | 91.06% Space Free | Partition Type: NTFS
Drive F: | 702.82 Mb Total Space | 497.21 Mb Free Space | 70.75% Space Free | Partition Type: UDF
Computer Name: CDOO-PC | User Name: cdoo | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:UserscdooDownloadsOTL(1).exe (OldTimer Tools)
PRC - C:Program Files (x86)Mozilla Firefoxfirefox.exe (Mozilla Corporation)
PRC - C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
PRC - C:Program FilesAVAST SoftwareAvastAvastUI.exe (AVAST Software)
PRC - C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
PRC - C:UserscdooAppDataRoamingDropboxbinDropbox.exe (Dropbox, Inc.)
PRC - C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe (Microsoft Corporation)
PRC - C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe (Microsoft Corporation)
PRC - C:Program Files (x86)LenovoOnekey TheaterOnekeySupport.exe ()
PRC - C:Program Files (x86)LenovoVeriFacePManage.exe (Lenovo)
PRC - C:Program Files (x86)OpenOffice.org 3programsoffice.exe (OpenOffice.org)
PRC - C:Program Files (x86)OpenOffice.org 3programsoffice.bin (OpenOffice.org)
PRC - C:Program Files (x86)DDNiOasis2Service 1.0Oasis2Service.exe ()
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
PRC - C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
PRC - C:Program Files (x86)LenovoYouCamYCMMirage.exe (CyberLink)
PRC - C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
PRC - C:Program Files (x86)USB Camera2VM332_STI.EXE (Vimicro)
========== Modules (No Company Name) ==========
MOD - C:WindowsSysWOW64MacromedFlashNPSWF32_11_2_202_235.dll ()
MOD - C:Program Files (x86)Mozilla Firefoxmozjs.dll ()
MOD - C:Program FilesAVAST SoftwareAvastaswOtl.dll ()
MOD - C:Program Files (x86)OpenOffice.org 3programlibxml2.dll ()
MOD - C:Program Files (x86)Common FilesAppleApple Application Supportzlib1.dll ()
MOD - C:Program Files (x86)Common FilesAppleApple Application Supportlibxml2.dll ()
MOD - C:Program Files (x86)LenovoOnekey TheaterOnekeySupport.exe ()
MOD - C:Program Files (x86)LenovoVeriFaceChooseLang.dll ()
MOD - C:Program Files (x86)LenovoOnekey TheaterWindowsApiHookDll32.dll ()
MOD - C:Program Files (x86)LenovoOnekey TheaterActiveDetect32.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) -- C:Program FilesAVAST SoftwareAvastAvastSvc.exe (AVAST Software)
SRV:64bit: - (Mcx2Svc) -- C:WindowsSysNativeMcx2Svc.dll (Microsoft Corporation)
SRV:64bit: - (EvtEng) Intel® -- C:Program FilesIntelWiFibinEvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) -- C:Program FilesIntelWiFibinPanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) Intel® -- C:Program FilesCommon FilesIntelWirelessCommonRegSrvc.exe (Intel® Corporation)
SRV:64bit: - (RtLedService) -- C:Program FilesRealtekRtLEDRtLEDService.exe (Realtek Semiconductor Corp.)
SRV:64bit: - (wlcrasvc) -- C:Program FilesWindows LiveMeshwlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:Program FilesWindows DefenderMpSvc.dll (Microsoft Corporation)
SRV:64bit: - (RemoteAccess) -- C:WindowsSysNativemprdim.dll (Microsoft Corporation)
SRV:64bit: - (SharedAccess) -- C:WindowsSysNativeipnathlp.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:WindowsSysWOW64MacromedFlashFlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) -- C:Program Files (x86)Mozilla Maintenance Servicemaintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeARMservice) -- C:Program Files (x86)Common FilesAdobeARM1.0armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) -- C:Program Files (x86)Microsoft Application Virtualization Clientsftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:Program Files (x86)Microsoft Application Virtualization Clientsftlist.exe (Microsoft Corporation)
SRV - (Oasis2Service) -- C:Program Files (x86)DDNiOasis2Service 1.0Oasis2Service.exe ()
SRV - (UNS) Intel® -- C:Program Files (x86)IntelIntel® Management Engine ComponentsUNSUNS.exe (Intel Corporation)
SRV - (LMS) Intel® -- C:Program Files (x86)IntelIntel® Management Engine ComponentsLMSLMS.exe (Intel Corporation)
SRV - (HPSLPSVC) -- C:Program Files (x86)HPDigital ImagingbinHPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (clr_optimization_v4.0.30319_32) -- C:WindowsMicrosoft.NETFrameworkv4.0.30319mscorsvw.exe (Microsoft Corporation)
SRV - (RemoteAccess) -- C:WindowsSysWOW64mprdim.dll (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:WindowsMicrosoft.NETFrameworkv2.0.50727mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) -- C:WindowsMicrosoft.NETFramework64v2.0.50727mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswSnx) -- C:windowsSysNativedriversaswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:windowsSysNativedriversaswSP.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:WindowsSysNativedriversaswRdr2.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:windowsSysNativedriversaswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:WindowsSysNativedriversaswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:windowsSysNativedriversaswFsBlk.sys (AVAST Software)
DRV:64bit: - (Fs_Rec) -- C:windowsSysNativedriversfs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) -- C:WindowsSysNativedriversusbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Sftvol) -- C:WindowsSysNativedriversSftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) -- C:WindowsSysNativedriversSftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) -- C:WindowsSysNativedriversSftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) -- C:WindowsSysNativedriversSftfslh.sys (Microsoft Corporation)
DRV:64bit: - (LHDmgr) -- C:WindowsSysNativedriversLhdX64.sys (Lenovo.)
DRV:64bit: - (ACPIVPC) -- C:WindowsSysNativedriversAcpiVpc.sys (Lenovo Corporation)
DRV:64bit: - (fbfmon) -- C:WindowsSysNativedriversfbfmon.sys (Lenovo)
DRV:64bit: - (BPntDrv) -- C:WindowsSysNativedriversBPntDrv.sys (Lenovo)
DRV:64bit: - (igfx) -- C:WindowsSysNativedriversigdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsata) -- C:WindowsSysNativedriversamdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:WindowsSysNativedriversamdxata.sys (Advanced Micro Devices)
DRV:64bit: - (iaStor) -- C:WindowsSysNativedriversiaStor.sys (Intel Corporation)
DRV:64bit: - (vm332avs) -- C:WindowsSysNativedriversvm332avs.sys (Vimicro Corporation)
DRV:64bit: - (SynTP) -- C:WindowsSysNativedriversSynTP.sys (Synaptics Incorporated)
DRV:64bit: - (clwvd) -- C:WindowsSysNativedriversclwvd.sys (CyberLink Corporation)
DRV:64bit: - (wdkmd) -- C:WindowsSysNativedriversWDKMD.sys (Intel Corporation)
DRV:64bit: - (RSUSBVSTOR) -- C:WindowsSysNativedriversrtsuvstor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (TsUsbFlt) -- C:WindowsSysNativedriversTsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:WindowsSysNativedriversHpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) -- C:WindowsSysNativedriversTsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) ___ Intel® -- C:WindowsSysNativedriversNETwNs64.sys (Intel Corporation)
DRV:64bit: - (MEIx64) Intel® -- C:WindowsSysNativedriversHECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® -- C:WindowsSysNativedriversIntcDAud.sys (Intel® Corporation)
DRV:64bit: - (vm2uvcflt) -- C:WindowsSysNativedriversvm2uvcflt.sys (Vimicro Corporation)
DRV:64bit: - (RTL8167) -- C:WindowsSysNativedriversRt64win7.sys (Realtek )
DRV:64bit: - (wsvd) -- C:WindowsSysNativedriverswsvd.sys (CyberLink)
DRV:64bit: - (amdsbs) -- C:WindowsSysNativedriversamdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:WindowsSysNativedriverslsi_sas2.sys (LSI Corporation)
DRV:64bit: - (crcdisk) -- C:WindowsSysNativedriverscrcdisk.sys (Microsoft Corporation)
DRV:64bit: - (stexstor) -- C:WindowsSysNativedriversstexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) -- C:WindowsSysNativedriversWSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) -- C:WindowsSysNativedriversserscan.sys (Microsoft Corporation)
DRV:64bit: - (ws2ifsl) -- C:WindowsSysNativedriversws2ifsl.sys (Microsoft Corporation)
DRV:64bit: - (cdfs) -- C:WindowsSysNativedriverscdfs.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:WindowsSysNativedriversevbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:WindowsSysNativedriversbxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:WindowsSysNativedriversb57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:WindowsSysNativedrivershcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:WindowsSysNativedriversGEARAspiWDM.sys (GEAR Software Inc.)
DRV - (WIMMount) -- C:WindowsSysWOW64driverswimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://lenovo.msn.com
IE:64bit: - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...mp;sourceid=ie7
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLMSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://lenovo.msn.com
IE - HKLM..SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM..SearchScopes{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...mp;sourceid=ie7
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.google.co...r...N&bmod=LENN
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Secondary Start Pages = http://www.lenovo.com [binary data]
IE - HKCUSOFTWAREMicrosoftInternet ExplorerMain,Start Page = http://www.google.co...r...N&bmod=LENN
IE - HKCU..SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU..SearchScopes{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU..SearchScopes{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...amp;rlz=1I7LENN
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyEnable" = 0
IE - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - user.js - File not found
FF:64bit: - HKLMSoftwareMozillaPlugins@adobe.com/FlashPlayer: C:windowssystem32MacromedFlashNPSWF64_11_2_202_235.dll File not found
FF:64bit: - HKLMSoftwareMozillaPlugins@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLMSoftwareMozillaPlugins@Microsoft.com/NpCtrl,version=1.0: c:Program FilesMicrosoft Silverlight5.1.10411.0npctrl.dll ( Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@adobe.com/FlashPlayer: C:windowsSysWOW64MacromedFlashNPSWF32_11_2_202_235.dll ()
FF - HKLMSoftwareMozillaPlugins@Apple.com/iTunes,version=: File not found
FF - HKLMSoftwareMozillaPlugins@Apple.com/iTunes,version=1.0: C:Program Files (x86)iTunesMozilla Pluginsnpitunes.dll ()
FF - HKLMSoftwareMozillaPlugins@Google.com/GoogleEarthPlugin: C:Program Files (x86)GoogleGoogle Earthpluginnpgeplugin.dll (Google)
FF - HKLMSoftwareMozillaPlugins@java.com/JavaPlugin: C:Program Files (x86)Javajre6binplugin2npjp2.dll (Sun Microsystems, Inc.)
FF - HKLMSoftwareMozillaPlugins@microsoft.com/GENUINE: disabled File not found
FF - HKLMSoftwareMozillaPlugins@Microsoft.com/NpCtrl,version=1.0: c:Program Files (x86)Microsoft Silverlight5.1.10411.0npctrl.dll ( Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@microsoft.com/SharePoint,version=14.0: C:PROGRA~2MICROS~1Office14NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@microsoft.com/WLPG,version=15.4.3502.0922: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@microsoft.com/WLPG,version=15.4.3508.1109: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@microsoft.com/WLPG,version=15.4.3538.0513: C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll (Microsoft Corporation)
FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=3: C:Program Files (x86)GoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - HKLMSoftwareMozillaPlugins@tools.google.com/Google Update;version=9: C:Program Files (x86)GoogleUpdate1.3.21.111npGoogleUpdate3.dll (Google Inc.)
FF - HKLMSoftwareMozillaPluginsAdobe Reader: C:Program Files (x86)AdobeReader 10.0ReaderAIRnppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionswrc@avast.com: C:Program FilesAVAST SoftwareAvastWebRepFF [2012/04/23 17:50:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaFirefoxExtensionssmartwebprinting@hp.com: C:Program Files (x86)HPDigital ImagingSmart Web PrintingMozillaAddOn3 [2011/07/12 08:00:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 12.0extensionsComponents: C:Program Files (x86)Mozilla Firefoxcomponents [2012/04/26 06:06:31 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINEsoftwaremozillaMozilla Firefox 12.0extensionsPlugins: C:Program Files (x86)Mozilla Firefoxplugins
FF - HKEY_CURRENT_USERsoftwaremozillaFirefoxExtensionssmartwebprinting@hp.com: C:Program Files (x86)HPDigital ImagingSmart Web PrintingMozillaAddOn3 [2011/07/12 08:00:11 | 000,000,000 | ---D | M]
[2011/07/09 13:23:42 | 000,000,000 | ---D | M] (No name found) -- C:UserscdooAppDataRoamingMozillaExtensions
[2011/07/09 13:23:42 | 000,000,000 | ---D | M] (No name found) -- C:UserscdooAppDataRoamingMozillaExtensionsexpress@postbox-inc.com
[2012/05/26 06:52:53 | 000,000,000 | ---D | M] (No name found) -- C:UserscdooAppDataRoamingMozillaFirefoxProfilesxibgbrp1.defaultextensio
ns
[2011/09/26 20:24:54 | 000,000,000 | ---D | M] (Disconnect) -- C:UserscdooAppDataRoamingMozillaFirefoxProfilesxibgbrp1.defaultextensio
nsdisconnect@disconnect.me
[2012/04/25 06:46:04 | 000,000,000 | ---D | M] (No name found) -- C:Program Files (x86)Mozilla Firefoxextensions
[2012/05/26 06:48:50 | 000,086,131 | ---- | M] () (No name found) -- C:USERSCDOOAPPDATAROAMINGMOZILLAFIREFOXPROFILESXIBGBRP1.DEFAULTEXTENSIO
NS{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
[2011/07/08 17:44:34 | 000,058,343 | ---- | M] () (No name found) -- C:USERSCDOOAPPDATAROAMINGMOZILLAFIREFOXPROFILESXIBGBRP1.DEFAULTEXTENSIO
NS{446C03E0-2C35-11DB-A98B-0800200C9A66}.XPI
[2011/07/08 15:21:32 | 000,330,316 | ---- | M] () (No name found) -- C:USERSCDOOAPPDATAROAMINGMOZILLAFIREFOXPROFILESXIBGBRP1.DEFAULTEXTENSIO
NSPERSONAS@CHRISTOPHER.BEARD.XPI
[2012/05/26 06:48:50 | 000,079,908 | ---- | M] () (No name found) -- C:USERSCDOOAPPDATAROAMINGMOZILLAFIREFOXPROFILESXIBGBRP1.DEFAULTEXTENSIO
NSPRINTEDIT@DW-DEV.XPI
[2012/04/26 06:06:31 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:Program Files (x86)mozilla firefoxcomponentsbrowsercomps.dll
[2012/04/25 06:45:56 | 000,002,252 | ---- | M] () -- C:Program Files (x86)mozilla firefoxsearchpluginsbing.xml
[2012/04/25 06:45:56 | 000,002,040 | ---- | M] () -- C:Program Files (x86)mozilla firefoxsearchpluginstwitter.xml
========== Chrome ==========
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo....p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yah...d={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:Program Files (x86)GoogleChromeApplication15.0.874.106gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:windowsSysWOW64MacromedFlashNPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:Program Files (x86)QuickTimepluginsnpqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:Program Files (x86)Javajre6binnew_pluginnpjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:Program Files (x86)AdobeReader 10.0ReaderBrowsernppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:Program Files (x86)Microsoft Silverlight4.0.60831.0npctrl.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:PROGRA~2MICROS~1Office14NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:Program Files (x86)GoogleChromeApplication15.0.874.106ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:Program Files (x86)GoogleChromeApplication15.0.874.106pdf.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:Program Files (x86)GoogleGoogle Earthpluginnpgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:Program Files (x86)GoogleUpdate1.3.21.69npGoogleUpdate3.dll
CHR - plugin: Windows Liveu0099 Photo Gallery (Enabled) = C:Program Files (x86)Windows LivePhoto GalleryNPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:Program Files (x86)iTunesMozilla Pluginsnpitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: avast! WebRep = C:UserscdooAppDataLocalGoogleChromeUser DataDefaultExtensionsicmlaeflemplmjndnaapfdbbnpncnbda6.0.1289_0
CHR - Extension: Inside Lane Theme = C:UserscdooAppDataLocalGoogleChromeUser DataDefaultExtensionsphhlfoncoemedejjabkgniaajejikmpd1_0
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:WindowsSysNativedriversetchosts
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program Files (x86)Javajre6binssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:ProgramDataPartnerPartner.dll (Google Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM..Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:Program FilesAVAST SoftwareAvastaswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM..Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:Program FilesAVAST SoftwareAvastaswWebRepIE.dll (AVAST Software)
O3 - HKLM..Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..Run: [Energy Management] C:Program Files (x86)LenovoEnergy ManagementEnergy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..Run: [EnergyUtility] C:Program Files (x86)LenovoEnergy Managementutility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..Run: [HotKeysCmds] C:WindowsSysNativehkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IgfxTray] C:WindowsSysNativeigfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [IntelWireless] C:Program FilesCommon FilesIntelWirelessCommoniFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..Run: [Lenovo EE Boot Optimizer] C:Program Files (x86)LenovoBoot OptimizerPopWnd.exe (Lenovo)
O4:64bit: - HKLM..Run: [OnekeyStudio] C:Program Files (x86)LenovoOnekey TheaterOnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..Run: [Persistence] C:WindowsSysNativeigfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..Run: [RtHDVCpl] C:Program FilesRealtekAudioHDARAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..Run: [UpdatePRCShortCut] C:Program FilesLenovoOneKey AppOneKey RecoveryMUITransferMUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..Run: [332BigDog] C:Program Files (x86)USB Camera2VM332_STI.EXE (Vimicro)
O4 - HKLM..Run: [APSDaemon] C:Program Files (x86)Common FilesAppleApple Application SupportAPSDaemon.exe (Apple Inc.)
O4 - HKLM..Run: [avast] C:Program FilesAVAST SoftwareAvastavastUI.exe (AVAST Software)
O4 - HKLM..Run: [UpdateP2GShortCut] C:Program Files (x86)LenovoPower2GoMUITransferMUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..Run: [UpdatePRCShortCut] C:Program FilesLenovoOneKey AppOneKey RecoveryMUITransferMUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..Run: [VeriFaceManager] C:Program Files (x86)LenovoVeriFacePManage.exe (Lenovo)
O4 - HKLM..Run: [YouCam Mirage] C:Program Files (x86)LenovoYouCamYCMMirage.exe (CyberLink)
O4 - HKLM..Run: [YouCam Tray] C:Program Files (x86)LenovoYouCamYouCam.exe (CyberLink Corp.)
O4 - HKCU..Run: [DW6] C:Program Files (x86)The Weather Channel FWDesktopDesktopWeather.exe (The Weather Channel Interactive, Inc.)
O4 - Startup: C:UserscdooAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupDropbox.lnk = C:UserscdooAppDataRoamingDropboxbinDropbox.exe (Dropbox, Inc.)
O4 - Startup: C:UserscdooAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupOpenOffice.org 3.3.lnk = C:Program Files (x86)OpenOffice.org 3programquickstart.exe ()
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktop = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesExplorer: NoActiveDesktopChanges = 1
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorAdmin = 5
O6 - HKLMSOFTWAREMicrosoftWindowsCurrentVersionpoliciesSystem: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:Program Files (x86)EvernoteEvernoteEvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:Program Files (x86)GoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Add to Evernote 4.0 - C:Program Files (x86)EvernoteEvernoteEvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Google Sidewiki... - res://C:Program Files (x86)GoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html File not found
O9 - Extra Button: @C:Program Files (x86)EvernoteEvernoteResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:Program Files (x86)EvernoteEvernoteEvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:Program Files (x86)EvernoteEvernoteResource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:Program Files (x86)EvernoteEvernoteEvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10:64bit: - NameSpace_Catalog5Catalog_Entries64\000000000008 [] - C:Program FilesBonjourmdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5Catalog_Entries\000000000008 [] - C:Program Files (x86)BonjourmdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLMSystemCCSServicesTcpipParameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLMSystemCCSServicesTcpipParametersInterfaces{D86E90F5-498A-47B0-A21A-2C429DA4A366}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18:64bit: - ProtocolHandlerlivecall - No CLSID value found
O18:64bit: - ProtocolHandlermsdaipp - No CLSID value found
O18:64bit: - ProtocolHandlermsdaipp\0x00000001 - No CLSID value found
O18:64bit: - ProtocolHandlermsdaippoledb - No CLSID value found
O18:64bit: - ProtocolHandlermsnim - No CLSID value found
O18:64bit: - ProtocolHandlermso-offdap11 - No CLSID value found
O18:64bit: - ProtocolHandlerwlmailhtml - No CLSID value found
O18:64bit: - ProtocolHandlerwlpg - No CLSID value found
O18 - ProtocolHandlermsdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18 - ProtocolHandlermsdaippoledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:Program Files (x86)Common FilesSystemOle DBMSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - ProtocolFiltertext/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:windowsexplorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:Windowssystem32userinit.exe) - C:WindowsSysNativeuserinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:windowsSysNativeSystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:windowsSysWow64explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:windowsSysWow64userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - WinlogonNotifyigfxcui: DllName - (igfxdev.dll) - C:windowsSysNativeigfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM..comfile [open] -- "%1" %*
O35:64bit: - HKLM..exefile [open] -- "%1" %*
O35 - HKLM..comfile [open] -- "%1" %*
O35 - HKLM..exefile [open] -- "%1" %*
O37:64bit: - HKLM...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM...exe [@ = exefile] -- "%1" %*
O37 - HKLM...com [@ = comfile] -- "%1" %*
O37 - HKLM...exe [@ = exefile] -- "%1" %*
O38 - SubSystemsWindows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystemsWindows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystemsWindows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:WindowsSystem32l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.clmp3enc - C:Program Files (x86)LenovoPower2GoCLMP3Enc.ACM (CyberLink Corp.)
Drivers32: msacm.l3acm - C:WindowsSysWOW64l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:windowsSysWow64iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/01 08:31:10 | 000,000,000 | ---D | C] -- C:UserscdooDocumentsBedford Valley Special_files
[2012/05/16 07:19:19 | 000,000,000 | ---D | C] -- C:UserscdooAppDataLocalElevatedDiagnostics
[2012/05/13 05:26:34 | 000,000,000 | ---D | C] -- C:ProgramDataMicrosoftWindowsStart MenuProgramsMicrosoft Silverlight
[2012/05/13 05:25:18 | 000,000,000 | ---D | C] -- C:Program FilesMicrosoft Silverlight
[2012/05/13 05:25:18 | 000,000,000 | ---D | C] -- C:Program Files (x86)Microsoft Silverlight
[2012/05/09 05:52:23 | 001,544,704 | ---- | C] (Microsoft Corporation) -- C:windowsSysNativeDWrite.dll
[2012/05/09 05:52:21 | 005,559,664 | ---- | C] (Microsoft Corporation) -- C:windowsSysNativentoskrnl.exe
[2012/05/09 05:52:20 | 003,913,072 | ---- | C] (Microsoft Corporation) -- C:windowsSysWow64ntoskrnl.exe
[2012/05/09 05:52:19 | 003,968,368 | ---- | C] (Microsoft Corporation) -- C:windowsSysWow64ntkrnlpa.exe
[2012/05/04 20:04:06 | 008,744,608 | ---- | C] (Adobe Systems Incorporated) -- C:windowsSysWow64FlashPlayerInstaller.exe
========== Files - Modified Within 30 Days ==========
[2012/06/01 17:04:00 | 000,000,830 | ---- | M] () -- C:windowstasksAdobe Flash Player Updater.job
[2012/06/01 16:53:00 | 000,000,912 | ---- | M] () -- C:windowstasksGoogleUpdateTaskMachineUA.job
[2012/06/01 15:40:33 | 000,021,280 | -H-- | M] () -- C:windowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/01 15:40:33 | 000,021,280 | -H-- | M] () -- C:windowsSysNative7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/01 15:39:45 | 000,727,334 | ---- | M] () -- C:windowsSysNativePerfStringBackup.INI
[2012/06/01 15:39:45 | 000,624,864 | ---- | M] () -- C:windowsSysNativeperfh009.dat
[2012/06/01 15:39:45 | 000,106,950 | ---- | M] () -- C:windowsSysNativeperfc009.dat
[2012/06/01 15:37:20 | 000,409,285 | ---- | M] () -- C:windowsSysNativefastboot.set
[2012/06/01 15:35:10 | 000,000,908 | ---- | M] () -- C:windowstasksGoogleUpdateTaskMachineCore.job
[2012/06/01 15:34:19 | 000,067,584 | --S- | M] () -- C:windowsbootstat.dat
[2012/06/01 10:26:20 | 3153,727,488 | -HS- | M] () -- C:hiberfil.sys
[2012/06/01 08:31:11 | 000,136,448 | ---- | M] () -- C:UserscdooDocumentsBedford Valley Special.htm
[2012/05/10 19:57:37 | 000,001,133 | ---- | M] () -- C:UserscdooApplication DataMicrosoftInternet ExplorerQuick LaunchLaunch Microsoft Office Outlook.lnk
[2012/05/10 18:46:17 | 000,318,024 | ---- | M] () -- C:windowsSysNativeFNTCACHE.DAT
[2012/05/04 20:04:12 | 000,419,488 | ---- | M] (Adobe Systems Incorporated) -- C:windowsSysWow64FlashPlayerApp.exe
[2012/05/04 20:04:11 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:windowsSysWow64FlashPlayerCPLApp.cpl
[2012/05/04 20:04:06 | 008,744,608 | ---- | M] (Adobe Systems Incorporated) -- C:windowsSysWow64FlashPlayerInstaller.exe
========== Files Created - No Company Name ==========
[2012/06/01 08:31:10 | 000,136,448 | ---- | C] () -- C:UserscdooDocumentsBedford Valley Special.htm
[2011/10/16 13:20:15 | 000,026,018 | ---- | C] () -- C:UserscdooAppDataRoamingUserTile.png
[2011/10/15 16:32:28 | 000,206,296 | ---- | C] () -- C:windowshpwins28.dat.temp
[2011/10/15 16:32:28 | 000,000,418 | ---- | C] () -- C:windowshpwmdl28.dat.temp
[2011/07/25 14:28:52 | 000,000,376 | ---- | C] () -- C:windowsODBC.INI
[2011/07/12 07:49:28 | 000,201,452 | ---- | C] () -- C:windowshpoins40.dat
[2011/07/11 18:26:11 | 000,649,057 | ---- | C] () -- C:windowshpoins40.dat.temp
[2011/07/11 18:02:38 | 000,000,992 | ---- | C] () -- C:windowshpomdl40.dat.temp
[2011/07/09 14:31:22 | 000,743,662 | ---- | C] () -- C:windowsSysWow64PerfStringBackup.INI
[2011/07/09 02:22:13 | 000,000,235 | ---- | C] () -- C:ProgramDataMicrosoft.SqlServer.Compact.351.32.bc
[2011/06/02 19:32:10 | 000,300,328 | ---- | C] () -- C:windowsit50.dll
[2011/06/02 19:32:10 | 000,259,368 | ---- | C] () -- C:windowsFastBR.dll
[2011/06/02 19:32:10 | 000,218,408 | ---- | C] () -- C:windowsImage.dll
[2011/06/02 19:32:10 | 000,202,024 | ---- | C] () -- C:windowsHardDisk.dll
[2011/06/02 19:32:10 | 000,177,448 | ---- | C] () -- C:windowsdisk.dll
[2011/06/02 19:32:10 | 000,010,068 | ---- | C] () -- C:windowsGT.EXE
[2011/06/02 19:32:10 | 000,003,443 | ---- | C] () -- C:windowsUTILITYDRV.SYS
[2011/06/02 19:32:09 | 000,259,368 | ---- | C] () -- C:windowsCopyFile.dll
[2011/06/02 19:32:09 | 000,110,592 | ---- | C] () -- C:windowsBootseqwWmi.exe
[2011/06/02 19:32:09 | 000,081,920 | ---- | C] () -- C:windowsBootseqw32.exe
[2011/06/02 19:32:09 | 000,049,152 | ---- | C] () -- C:windowsCHGBOOTW.EXE
[2011/06/02 19:32:09 | 000,008,704 | ---- | C] () -- C:windowsAccess32.sys
[2011/06/02 10:49:01 | 002,086,240 | ---- | C] () -- C:windowsSysWow64LenovoVeriface.Interface.dll
[2011/06/02 10:49:01 | 001,500,512 | ---- | C] () -- C:windowsSysWow64Apblend.dll
[2011/06/02 10:49:01 | 001,171,456 | ---- | C] () -- C:windowsSysWow64PicNotify.dll
[2011/06/02 10:49:01 | 000,466,944 | ---- | C] () -- C:windowsSysWow64Lenovo.VerifaceStub.dll
[2011/06/02 10:48:55 | 001,044,480 | ---- | C] () -- C:windowsSysWow643DImageRenderer.dll
[2011/06/02 10:34:21 | 000,001,823 | ---- | C] () -- C:windowsvm332Rmv.ini
[2011/06/02 10:34:21 | 000,001,823 | ---- | C] () -- C:windowsSysWow64vm332Rmv.ini
[2011/04/13 23:01:25 | 000,963,116 | ---- | C] () -- C:windowsSysWow64igkrng600.bin
[2011/04/13 23:01:22 | 000,216,876 | ---- | C] () -- C:windowsSysWow64igfcg600m.bin
[2011/04/13 23:01:19 | 000,145,804 | ---- | C] () -- C:windowsSysWow64igcompkrng600.bin
[2011/04/13 22:51:06 | 000,066,856 | ---- | C] () -- C:windowsSysWow64SynTPEnhPS.dll
========== LOP Check ==========
[2011/07/31 20:10:25 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingAnthropics
[2011/07/10 19:55:31 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingArcSyncConfig
[2012/06/01 15:37:04 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingDropbox
[2011/07/25 14:25:50 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingeM Client
[2011/08/27 11:37:54 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoaminggtk-2.0
[2011/08/27 13:29:03 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingooVoo Details
[2011/07/09 15:19:03 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingOpenOffice.org
[2011/07/09 13:23:33 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingPostbox
[2011/08/15 20:20:21 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingrinsebyreal
[2011/10/10 05:49:58 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingSammsoft
[2011/07/11 13:55:32 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingSBG901
[2012/06/01 10:24:39 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingSoftGrid Client
[2011/07/23 09:44:30 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingSpotify
[2011/07/09 09:26:06 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingThunderbird
[2011/07/09 14:32:12 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingTP
[2011/07/08 17:01:13 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoamingWindows Live Writer
[2011/10/18 14:29:50 | 000,000,000 | ---D | M] -- C:UserscdooAppDataRoaming{90140011-0066-0409-0000-0000000FF1CE}
[2011/12/20 07:01:29 | 000,032,626 | ---- | M] () -- C:windowsTasksSCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%*.* >
[2011/08/19 23:18:36 | 000,000,082 | -HS- | M] () -- C:desktop.ini
[2012/06/01 15:35:04 | 000,468,570 | ---- | M] () -- C:FaceProv.log
[2012/06/01 10:26:20 | 3153,727,488 | -HS- | M] () -- C:hiberfil.sys
[2011/06/02 19:32:12 | 000,000,028 | ---- | M] () -- C:IPGPLDOK.TXT
[2011/06/02 10:51:43 | 000,000,064 | ---- | M] () -- C:Lenovo EE Boot Optimizer.log
[2012/06/01 15:34:16 | 4204,969,984 | -HS- | M] () -- C:pagefile.sys
[2009/12/14 17:19:04 | 000,000,334 | ---- | M] () -- C:Pat Metheny-Ornette Coleman - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:Pearl Jam - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:Pete Townshend - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Peter Gabriel - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:Pink Floyd - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:Playlists - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:Poncho Sanchez - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:Pretenders - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,269 | ---- | M] () -- C:Primus - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,269 | ---- | M] () -- C:Prince - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Prince Buster - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,264 | ---- | M] () -- C:Queen - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,270 | ---- | M] () -- C:R.E.M - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:Radiohead - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Ray Charles - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,316 | ---- | M] () -- C:Red Hot Chili Peppers - Shortcut.lnk
[2011/06/02 10:23:54 | 000,002,269 | ---- | M] () -- C:RHDSetup.log
[2009/12/14 17:19:04 | 000,000,301 | ---- | M] () -- C:Robbie Robertson - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:Robert Johnson - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Robert Palmer - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Roberta Flack - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Rod Stewart - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,301 | ---- | M] () -- C:Rufus Wainwright - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,261 | ---- | M] () -- C:Rush - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Rusted Root - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:Sam Cooke - Shortcut.lnk
[2009/12/13 13:45:56 | 000,000,633 | ---- | M] () -- C:Sample Music.lnk
[2009/12/14 17:19:04 | 000,000,272 | ---- | M] () -- C:Santana - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:Seals & Crofts - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Sheryl Crow - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,304 | ---- | M] () -- C:Simon & Garfunkel - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:Simply Red - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,304 | ---- | M] () -- C:Smashing Pumpkins - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Sonic Youth - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Sonny Rollins - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,269 | ---- | M] () -- C:Spirit - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:Spyro Gyra - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,272 | ---- | M] () -- C:Squeeze - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:Stan Getz - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:Steely Dan - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:Steve Earle - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,349 | ---- | M] () -- C:Steve Earle-The Del McCoury Band - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Steve Winwood - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,364 | ---- | M] () -- C:Stevie Ray Vaughan and Double Trouble - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,264 | ---- | M] () -- C:Sting - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,292 | ---- | M] () -- C:Talking Heads - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,325 | ---- | M] () -- C:The Allman Brothers Band - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,283 | ---- | M] () -- C:The B-52's - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,286 | ---- | M] () -- C:The Badlees - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:The Beach Boys - Shortcut.lnk
[2010/05/17 09:20:54 | 000,000,821 | ---- | M] () -- C:The Beatles - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,301 | ---- | M] () -- C:The Black Crowes - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,295 | ---- | M] () -- C:The Black Keys - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,277 | ---- | M] () -- C:The Cars - Shortcut.lnk
[2009/12/14 17:19:04 | 000,000,280 | ---- | M] () -- C:The Clash - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,295 | ---- | M] () -- C:The Commodores - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,277 | ---- | M] () -- C:The Cure - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,319 | ---- | M] () -- C:The Dave Matthews Band - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,280 | ---- | M] () -- C:The Doors - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,334 | ---- | M] () -- C:The Flying Burrito Brothers - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,340 | ---- | M] () -- C:The Good, the Bad & the Queen - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,304 | ---- | M] () -- C:The Grateful Dead - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,298 | ---- | M] () -- C:Various Artists - Shortcut.lnk
[2009/12/14 17:19:06 | 000,000,310 | ---- | M] () -- C:Waiting for the Sun - Shortcut.lnk
[2007/01/06 01:37:00 | 002,055,068 | ---- | M] () -- C:Warranty and Customer Support.pdf
< %systemroot%Fonts*.com >
[2009/07/14 01:32:31 | 000,026,040 | ---- | M] () -- C:windowsFontsGlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | ---- | M] () -- C:windowsFontsGlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | ---- | M] () -- C:windowsFontsGlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | ---- | M] () -- C:windowsFontsGlobalUserInterface.CompositeFont
< %systemroot%Fonts*.dll >
< %systemroot%Fonts*.ini >
[2009/06/10 16:49:50 | 000,000,065 | ---- | M] () -- C:windowsFontsdesktop.ini
< %systemroot%Fonts*.ini2 >
< %systemroot%Fonts*.exe >
< %systemroot%system32spoolprtprocsw32x86*.* >
< %systemroot%REPAIR*.bak1 >
< %systemroot%REPAIR*.ini >
< %systemroot%system32*.jpg >
< %systemroot%*.jpg >
< %systemroot%*.png >
< %systemroot%*.scr >
[2012/03/06 19:15:19 | 000,041,184 | ---- | M] (AVAST Software) -- C:windowsavastSS.scr
[2011/05/13 16:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:windowsWLXPGSS.SCR
< %systemroot%*._sy >
< %APPDATA%AdobeUpdate*.* >
< %ALLUSERSPROFILE%Favorites*.* >
< %APPDATA%Microsoft*.* >
< %PROGRAMFILES%*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () -- C:Program Files (x86)desktop.ini
< %APPDATA%Update*.* >
< %systemroot%*. /mp /s >
< %systemroot%System32config*.sav >
< %PROGRAMFILES%bak. /s >
< %systemroot%system32bak. /s >
< %ALLUSERSPROFILE%Start Menu*.lnk /x >
< %systemroot%system32configsystemprofile*.dat /x >
< %systemroot%*.config >
< %systemroot%system32*.db >
< %PROGRAMFILES%Internet Explorer*.dat >
< %APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x >
[2011/07/08 15:23:24 | 000,000,221 | -HS- | M] () -- C:UserscdooAppDataRoamingMicrosoftInternet ExplorerQuick Launchdesktop.ini
< %USERPROFILE%Desktop*.exe >
< %PROGRAMFILES%Common Files*.* >
< %systemroot%*.src >
< %systemroot%install*.* >
< %systemroot%system32DLL*.* >
< %systemroot%system32HelpFiles*.* >
< %systemroot%system32rundll*.* >
< %systemroot%winn32*.* >
< %systemroot%Java*.* >
< %systemroot%system32test*.* >
< %systemroot%system32Rundll32*.* >
< %systemroot%AppPatchCustom*.* >
< HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU >
< HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 105 bytes -> C:ProgramDataTemp:5C321E34
< End of report >
ok i dont think i sent the correct thing and am trying again..sorry
netsvcs
drivers32
%SYSTEMDRIVE%*.*
%systemroot%Fonts*.com
%systemroot%Fonts*.dll
%systemroot%Fonts*.ini
%systemroot%Fonts*.ini2
%systemroot%Fonts*.exe
%systemroot%system32spoolprtprocsw32x86*.*
%systemroot%REPAIR*.bak1
%systemroot%REPAIR*.ini
%systemroot%system32*.jpg
%systemroot%*.jpg
%systemroot%*.png
%systemroot%*.scr
%systemroot%*._sy
%APPDATA%AdobeUpdate*.*
%ALLUSERSPROFILE%Favorites*.*
%APPDATA%Microsoft*.*
%PROGRAMFILES%*.*
%APPDATA%Update*.*
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%System32config*.sav
%PROGRAMFILES%bak. /s
%systemroot%system32bak. /s
%ALLUSERSPROFILE%Start Menu*.lnk /x
%systemroot%system32configsystemprofile*.dat /x
%systemroot%*.config
%systemroot%system32*.db
%PROGRAMFILES%Internet Explorer*.dat
%APPDATA%MicrosoftInternet ExplorerQuick Launch*.lnk /x
%USERPROFILE%Desktop*.exe
%PROGRAMFILES%Common Files*.*
%systemroot%*.src
%systemroot%install*.*
%systemroot%system32DLL*.*
%systemroot%system32HelpFiles*.*
%systemroot%system32rundll*.*
%systemroot%winn32*.*
%systemroot%Java*.*
%systemroot%system32test*.*
%systemroot%system32Rundll32*.*
%systemroot%AppPatchCustom*.*
HKEY_LOCAL_MACHINESOFTWAREPoliciesMicrosoftWindowsWindowsUpdateAU
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionWindowsUpdateAuto UpdateResultsInstall|LastSuccessTime /rs