Thank you so much for your help,
After running the aswMBR, below is the report it conducted
aswMBR version 0.9.5.256 Copyright© 2011 AVAST Software
Run date: 2011-06-01 22:56:21
—————————–
22:56:21.741 OS Version: Windows x64 6.1.7600
22:56:21.742 Number of processors: 4 586 0x2505
22:56:21.742 ComputerName: OWNER-PC UserName: owner
22:56:23.634 Initialize success
22:56:26.531 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
22:56:26.534 Disk 0 Vendor: ST950032 0001 Size: 476940MB BusType: 3
22:56:26.553 Disk 0 MBR read successfully
22:56:26.556 Disk 0 MBR scan
22:56:26.558 Disk 0 unknown MBR code
22:56:26.561 Service scanning
22:56:27.481 Disk 0 trace - called modules:
22:56:27.489 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys iaStor.sys
22:56:27.493 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004c1e790]
22:56:27.499 3 CLASSPNP.SYS[fffff880013ca43f] -> nt!IofCallDriver -> [0xfffffa8004967300]
22:56:27.502 5 ACPI.sys[fffff88000f5e781] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa800496d050]
22:56:27.506 Scan finished successfully
22:57:02.606 Disk 0 MBR has been saved successfully to "C:\Users\owner\Desktop\MBR.dat"
22:57:02.607 The log file has been saved successfully to "C:\Users\owner\Desktop\aswMBR.txt"
After running the OLT reports below are the results
OTL.txt
OTL logfile created on: 6/1/2011 10:59:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\owner\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 2.15 Gb Available Physical Memory | 56.61% Memory free
7.61 Gb Paging File | 5.82 Gb Available in Paging File | 76.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 432.81 Gb Total Space | 376.31 Gb Free Space | 86.95% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\McAfee Security Scan\2.0.189\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Toshiba\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Windows\SysWOW64\regsvr32.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Toshiba\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
========== Modules (SafeList) ==========
MOD - C:\Users\owner\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:
64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:
64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:
64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:
64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (N360) – C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\ccSvcHst.exe (Symantec Corporation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.189\McCHSvc.exe (McAfee, Inc.)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (GameConsoleService) – C:\Program Files (x86)\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (cfWiMAXService) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe (TOSHIBA CORPORATION)
SRV - (TMachInfo) – C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (SRTSP) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPX) Symantec Real Time Storage Protection (PEL) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (SymNetS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys (Symantec Corporation)
DRV:
64bit: - (SymEFA) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys (Symantec Corporation)
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (SymDS) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys (Symantec Corporation)
DRV:
64bit: - (SymIRON) – C:\Windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys (Symantec Corporation)
DRV:
64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (RTL8192Ce) – C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation )
DRV:
64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:
64bit: - (CnxtHdAudService) – C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:
64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atipmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (L1C) – C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:
64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:
64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:
64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (FwLnk) – C:\Windows\SysNative\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV:
64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:
64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:
64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (NAVEX15) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\EX64.SYS (Symantec Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\VirusDefs\20110601.021\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (BHDrvx64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\BASHDefs\20110518.001\BHDrvx64.sys (Symantec Corporation)
DRV - (IDSVia64) – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\Definitions\IPSDefs\20110531.001\IDSviA64.sys (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshiba.ca/welcome
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshiba.ca/welcome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshiba.ca/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.toshiba.ca/welcome
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.toshiba.ca/welcome
IE - HKCU\..\URLSearchHook: {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\IPSFFPlgn\ [2011/05/20 12:15:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_5.1.0.29\coFFPlgn\ [2011/05/20 12:14:09 | 000,000,000 | —D | M]
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (brincome browser plug-in) - {38BA8B8B-651F-7E28-0D9B-EE755739F882} - C:\Windows\SysWOW64\.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll ()
O2 - BHO: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (YouTube Downloader Toolbar) - {F3FEE66E-E034-436a-86E4-9690573BEE8A} - C:\Program Files (x86)\YouTube Downloader Toolbar\IE\4.3\youtubedownloaderToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360 Premier Edition\Engine\5.1.0.29\CoIEPlg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [] File not found
O4:
64bit: - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [cAudioFilterAgent] C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe (Conexant Systems, Inc.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:
64bit: - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosNC] C:\Program Files\TOSHIBA\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:
64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [messenger.exe] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files (x86)\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [vuqzcrshbnd] C:\windows\SysWow64\.dll ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/05/25 15:51:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\CrashDumps
[2011/05/24 19:05:29 | 000,000,000 | —D | C] – C:\Users\owner\Desktop\Payroll
[2011/05/24 14:21:41 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\Diskdump.sys
[2011/05/23 17:18:13 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/05/23 17:16:55 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apps
[2011/05/23 17:16:54 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Deployment
[2011/05/20 20:01:04 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Diagnostics
[2011/05/20 12:16:17 | 000,000,000 | —D | C] – C:\Users\owner\Documents\Symantec
[2011/05/20 12:14:45 | 000,174,200 | —- | C] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\drivers\GEARAspiWDM.sys
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2011/05/20 12:14:45 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2011/05/20 12:14:21 | 000,912,504 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.sys
[2011/05/20 12:14:21 | 000,744,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.sys
[2011/05/20 12:14:21 | 000,450,680 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.sys
[2011/05/20 12:14:21 | 000,382,584 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnets.sys
[2011/05/20 12:14:21 | 000,171,128 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\Ironx64.sys
[2011/05/20 12:14:21 | 000,040,568 | R— | C] (Symantec Corporation) – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.sys
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64
[2011/05/20 12:14:11 | 000,000,000 | —D | C] – C:\windows\SysNative\drivers\N360x64\0501000.01D
[2011/05/20 12:14:09 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360 Premier Edition
[2011/05/20 12:14:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton 360 Premier Edition
[2011/05/20 12:12:12 | 000,000,000 | —D | C] – C:\ProgramData\PCSettings
[2011/05/20 12:09:42 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2011/05/18 19:14:21 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\poqexec.exe
[2011/05/18 19:14:21 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\poqexec.exe
[2011/05/11 16:41:56 | 005,509,504 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2011/05/11 16:41:55 | 003,957,632 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2011/05/11 16:41:55 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2011/05/11 16:41:53 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbport.sys
[2011/05/11 16:41:53 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\usbd.sys
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Roaming\Apple Computer
[2011/05/08 14:16:35 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple Computer
[2011/05/08 14:16:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/08 14:16:11 | 000,125,872 | —- | C] (GEAR Software Inc.) – C:\windows\SysNative\GEARAspi64.dll
[2011/05/08 14:16:11 | 000,106,928 | —- | C] (GEAR Software Inc.) – C:\windows\SysWow64\GEARAspi.dll
[2011/05/08 14:16:11 | 000,000,000 | —D | C] – C:\windows\SysNative\DRVSTORE
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/05/08 14:15:57 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/05/08 14:15:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime
[2011/05/08 14:15:00 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2011/05/08 14:14:49 | 000,000,000 | —D | C] – C:\Users\owner\AppData\Local\Apple
[2011/05/08 14:14:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/05/08 14:14:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/05/08 14:14:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2011/05/08 14:14:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Apple
[2011/05/08 14:12:07 | 081,790,248 | —- | C] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe
========== Files - Modified Within 30 Days ==========
[2011/06/01 22:57:02 | 000,000,512 | —- | M] () – C:\Users\owner\Desktop\MBR.dat
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:40:18 | 000,016,304 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\windows\tasks\XSPYO.job
[2011/06/01 22:32:46 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/05/31 23:22:00 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/31 10:48:13 | 000,727,182 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/05/31 10:48:13 | 000,624,622 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/05/31 10:48:13 | 000,106,708 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/05/29 20:22:45 | 000,002,413 | —- | M] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/24 14:21:16 | 001,314,858 | —- | M] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/23 17:22:00 | 000,000,856 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:45 | 000,174,200 | —- | M] (Symantec Corporation) – C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2011/05/20 12:14:45 | 000,007,488 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | M] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | M] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:04 | 000,001,324 | —- | M] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | M] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | M] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/17 06:30:14 | 000,767,488 | —- | M] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | M] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:12:53 | 081,790,248 | —- | M] (Apple Inc.) – C:\Users\owner\Documents\iTunes64Setup.exe
========== Files Created - No Company Name ==========
[2011/06/01 22:57:02 | 000,000,512 | —- | C] () – C:\Users\owner\Desktop\MBR.dat
[2011/05/23 17:18:15 | 000,002,413 | —- | C] () – C:\Users\owner\Desktop\Google Chrome.lnk
[2011/05/23 17:17:34 | 000,000,908 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000UA.job
[2011/05/23 17:17:34 | 000,000,856 | —- | C] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-2098616504-1272640990-4009146662-1000Core.job
[2011/05/20 12:14:52 | 001,314,858 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Cat.DB
[2011/05/20 12:14:45 | 000,007,488 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2011/05/20 12:14:45 | 000,000,855 | —- | C] () – C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2011/05/20 12:14:32 | 000,002,651 | —- | C] () – C:\Users\Public\Desktop\Norton 360.lnk
[2011/05/20 12:14:21 | 000,000,000 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS64.cat
[2011/05/20 12:14:12 | 000,003,373 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA.inf
[2011/05/20 12:14:12 | 000,002,792 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymDS.inf
[2011/05/20 12:14:12 | 000,001,446 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymNet.inf
[2011/05/20 12:14:12 | 000,001,438 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.inf
[2011/05/20 12:14:12 | 000,001,422 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.inf
[2011/05/20 12:14:12 | 000,000,772 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\Iron.inf
[2011/05/20 12:14:11 | 000,007,492 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\iron.cat
[2011/05/20 12:14:11 | 000,007,462 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtspx64.cat
[2011/05/20 12:14:11 | 000,007,460 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\SymEFA64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\symnet64.cat
[2011/05/20 12:14:11 | 000,007,458 | R— | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\srtsp64.cat
[2011/05/20 12:14:11 | 000,000,172 | —- | C] () – C:\windows\SysNative\drivers\N360x64\0501000.01D\isolate.ini
[2011/05/20 12:09:42 | 000,001,324 | —- | C] () – C:\Users\owner\Desktop\Norton Installation Files.lnk
[2011/05/20 11:19:25 | 000,050,320 | —- | C] () – C:\windows\SysWow64\wtwmdelvyeht.exe
[2011/05/20 11:19:23 | 000,468,054 | —- | C] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
[2011/05/20 11:19:22 | 000,106,496 | RHS- | C] () – C:\windows\SysWow64\iprtprio9.dll
[2011/05/20 11:19:22 | 000,000,314 | -HS- | C] () – C:\windows\tasks\XSPYO.job
[2011/05/17 06:30:14 | 000,767,488 | —- | C] () – C:\windows\SysWow64\.dll
[2011/05/09 11:35:31 | 000,000,000 | -H– | C] () – C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/08 14:16:28 | 000,001,794 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/05/08 14:15:05 | 000,001,856 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/08 14:14:49 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/04/15 19:19:57 | 000,743,534 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/02/25 12:22:27 | 000,000,000 | —- | C] () – C:\windows\NDSTray.INI
[2011/02/25 12:06:11 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2010/07/06 22:06:46 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2010/02/22 22:15:02 | 000,001,105 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2010/02/20 12:22:24 | 000,870,560 | —- | C] () – C:\windows\SysWow64\igkrng575.bin
[2010/02/20 12:22:24 | 000,127,868 | —- | C] () – C:\windows\SysWow64\igcompkrng575.bin
[2010/02/20 12:22:24 | 000,104,636 | —- | C] () – C:\windows\SysWow64\igfcg575m.bin
[2010/02/20 11:27:36 | 000,208,896 | —- | C] () – C:\windows\SysWow64\iglhsip32.dll
[2010/02/20 11:27:36 | 000,143,360 | —- | C] () – C:\windows\SysWow64\iglhcp32.dll
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/31 23:55:57 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\SoftGrid Client
[2011/05/15 15:57:26 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\Toshiba
[2011/04/15 19:21:06 | 000,000,000 | —D | M] – C:\Users\owner\AppData\Roaming\TP
[2011/05/30 19:09:42 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/01 22:32:49 | 000,000,314 | -HS- | M] () – C:\Windows\Tasks\XSPYO.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/07/06 22:09:10 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/06/01 22:32:39 | 3063,029,760 | -HS- | M] () – C:\hiberfil.sys
[2011/06/01 22:32:45 | 4084,039,680 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/17 04:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2011/05/20 11:19:23 | 000,468,054 | —- | M] () – C:\Program Files (x86)\Drivers_pack_v4.55.63_fix.exe
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/15 11:15:16 | 000,000,221 | -HS- | M] () – C:\Users\owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2009/06/10 17:20:04 | 000,000,802 | —- | M] () – C:\Windows\addins\FXSEXT.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2011/04/15 10:41:37 | 000,000,402 | -HS- | M] () – C:\Users\owner\Favorites\desktop.ini
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
< %SystemRoot%\system32\fonts\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >