lochabar
Topic Starter
Picked up PING.exe last night. Opens itself and runs about every 5 minutes. Malwarebytes was unable to fix this. I read a recent thread here about you guys helping someone else with this problem, and see that you asked the guy for several other utility scan reports. I have run and will include these in my initial post. Thanks in advance for any and all help.
Edit: I see that GMER log is asked for as an attachment. I tried but am being told i may not make attachments of this kind.
OTL report:
OTL logfile created on: 2/6/2012 11:58:39 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Loch\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 31.23% Memory free
6.50 Gb Paging File | 4.06 Gb Available in Paging File | 62.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29.19 Gb Total Space | 3.86 Gb Free Space | 13.21% Space Free | Partition Type: NTFS
Drive D: | 59.14 Gb Total Space | 11.68 Gb Free Space | 19.76% Space Free | Partition Type: NTFS
Drive E: | 119.85 Gb Total Space | 33.93 Gb Free Space | 28.31% Space Free | Partition Type: NTFS
Drive F: | 89.91 Gb Total Space | 12.87 Gb Free Space | 14.32% Space Free | Partition Type: NTFS
Computer Name: MARS3 | User Name: Loch | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Loch\Desktop\OTL.exe (OldTimer Tools)
PRC - E:\program files\firefox\firefox.exe (Mozilla Corporation)
PRC - E:\program files\firefox\plugin-container.exe (Mozilla Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Windows\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
PRC - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - E:\program files\Blaze Media Pro\NMSAccess32.exe ()
PRC - C:\Program Files\Mouse\Amoumain.exe ()
PRC - C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - E:\program files\firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\SysWOW64\CTXFIRES.DLL ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
MOD - E:\program files\evga\EVGA Precision\RTHAL.dll ()
MOD - E:\program files\evga\EVGA Precision\RTCore.dll ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecisionHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\RTFC.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSSHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTFC.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Program Files\Mouse\Amoumain.exe ()
MOD - C:\Program Files\Mouse\Amoures.dll ()
MOD - C:\Windows\SysWOW64\Amhooker.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (O&O Defrag) – C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (NETw5x32) – C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
SRV - (MBAMService) – E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) – E:\program files\Blaze Media Pro\NMSAccess32.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Amusbprt) – C:\Windows\SysNative\drivers\Amusbx64.sys (A4Tech Co.,Ltd.)
DRV:64bit: - (Amfilter) – C:\Windows\SysNative\drivers\Amfltx64.sys ((Standard mouse types))
DRV:64bit: - (RTL8187) – C:\Windows\SysNative\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RtlProt) – C:\Windows\SysNative\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (RTCore64) – E:\program files\evga\EVGA Precision\RTCore64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 86 70 2E 03 4A A3 CB 01 [binary data]
IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e2c58150-9d72-11dd-ad8b-0800200c9a66}:1.3.1
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: E:\program files\vlc2\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: E:\program files\firefox\components [2012/02/02 10:24:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: E:\program files\firefox\plugins [2012/01/12 17:54:39 | 000,000,000 | —D | M]
[2010/04/23 00:48:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Extensions
[2012/01/05 15:48:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions
[2010/04/23 11:42:43 | 000,000,000 | —D | M] (Black Steel) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions\{e2c58150-9d72-11dd-ad8b-0800200c9a66}
() (No name found) – C:\USERS\LOCH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q0RYV8O3.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
Hosts file not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WheelMouse] C:\Program Files\Mouse\Amoumain.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EVGAPrecision] E:\program files\evga\EVGA Precision\EVGAPrecisionWrapper.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [Creative MediaSource Go] C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab (HPSDDX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72B389E3-F247-4530-8240-CCE44F13CE2F}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93A74603-BBFE-4A3B-9214-61BBB91AB219}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O34 - HKLM BootExecute: (E BootExecute settings..)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: NETw5x32 - C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/06 11:53:14 | 000,607,260 | —- | C] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 02:25:18 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Malwarebytes
[2012/02/06 02:25:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/05 23:50:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/02/05 23:47:38 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\BigHugeEngine
[2012/02/05 23:39:37 | 000,000,000 | —D | C] – C:\Windows\system64
[2012/02/03 19:16:30 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\BigHugeEngine
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BOSS
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\BOSS
[2012/01/31 17:35:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
[2012/01/31 10:23:25 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2012/01/31 10:23:25 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2012/01/31 10:23:25 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2012/01/31 10:23:25 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2012/01/31 10:23:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2012/01/31 10:23:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Witcher 2
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\The Witcher 2
[2012/01/29 22:02:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2
[2012/01/16 18:25:31 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2012/01/16 18:23:42 | 006,004,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/01/16 18:23:42 | 003,028,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/01/16 18:23:42 | 002,562,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2012/01/16 18:23:42 | 000,118,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/01/16 18:23:42 | 000,063,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/01/16 18:23:03 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2012/01/16 18:22:00 | 025,432,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/01/16 18:22:00 | 009,622,336 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/01/16 18:22:00 | 007,677,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/01/16 18:21:59 | 019,348,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/01/16 18:21:58 | 017,483,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/01/16 18:21:58 | 014,863,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/01/16 18:21:58 | 001,715,008 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/01/16 18:21:58 | 001,454,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/01/16 18:21:57 | 017,498,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/01/16 18:21:57 | 007,974,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/01/16 18:21:57 | 005,868,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/01/16 18:21:57 | 002,660,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/01/16 18:21:57 | 002,506,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/01/16 18:21:57 | 002,374,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/01/16 18:21:57 | 002,206,016 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/01/16 18:21:56 | 025,137,472 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/01/16 18:21:56 | 002,403,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/01/16 18:21:56 | 002,095,424 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/01/16 18:21:55 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/01/16 18:21:55 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/01/16 18:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xtreme-G 290.53 Win7-Vista 64bit
[2012/01/16 18:20:41 | 000,000,000 | —D | C] – C:\NVIDIA
[2012/01/13 14:08:27 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\vlc
[2012/01/13 14:08:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/01/10 17:40:13 | 000,614,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\COMCTL32.OCX
[2012/01/10 17:40:13 | 000,053,248 | —- | C] (vbAccelerator) – C:\Windows\SysWow64\SSUBTMR6.DLL
[2012/01/10 17:40:13 | 000,010,752 | —- | C] (Almeida & Andrade Ltda) – C:\Windows\SysWow64\aamd532.dll
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Nexus Mod Manager
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\Black_Tree_Gaming
[2010/07/28 17:31:32 | 000,060,928 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll
[2010/07/28 17:31:30 | 000,012,800 | —- | C] ( ) – C:\Windows\SysWow64\killapps.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/06 11:53:48 | 000,879,683 | —- | M] () – C:\Users\Loch\Desktop\SecurityCheck.exe
[2012/02/06 11:53:26 | 000,302,592 | —- | M] () – C:\Users\Loch\Desktop\pwy6t2ip.exe
[2012/02/06 11:53:14 | 000,607,260 | —- | M] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:00:30 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/06 10:59:29 | 000,000,322 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2012/02/06 10:59:29 | 000,000,262 | —- | M] () – C:\Windows\tasks\RtlVistaStart.job
[2012/02/06 10:59:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/06 10:59:24 | 2616,549,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/06 10:59:23 | 000,653,029 | —- | M] () – C:\Windows\SysNative\oodbs.lor
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,000,788 | —- | M] () – C:\Windows\SysNative\DVCState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 02:31:23 | 000,000,370 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/02/06 02:25:14 | 000,000,789 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/05 23:51:02 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/05 23:49:49 | 000,000,997 | —- | M] () – C:\Users\Loch\Desktop\Reckoning - Shortcut.lnk
[2012/02/05 00:25:02 | 000,014,336 | —- | M] () – C:\Users\Loch\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/03 22:22:48 | 000,778,150 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/03 22:22:48 | 000,659,580 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/03 22:22:48 | 000,120,508 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/03 19:11:51 | 000,316,691 | LS\x00\x00\x00\x00
Edit: I see that GMER log is asked for as an attachment. I tried but am being told i may not make attachments of this kind.
OTL report:
OTL logfile created on: 2/6/2012 11:58:39 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Loch\Desktop
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 31.23% Memory free
6.50 Gb Paging File | 4.06 Gb Available in Paging File | 62.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 29.19 Gb Total Space | 3.86 Gb Free Space | 13.21% Space Free | Partition Type: NTFS
Drive D: | 59.14 Gb Total Space | 11.68 Gb Free Space | 19.76% Space Free | Partition Type: NTFS
Drive E: | 119.85 Gb Total Space | 33.93 Gb Free Space | 28.31% Space Free | Partition Type: NTFS
Drive F: | 89.91 Gb Total Space | 12.87 Gb Free Space | 14.32% Space Free | Partition Type: NTFS
Computer Name: MARS3 | User Name: Loch | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Loch\Desktop\OTL.exe (OldTimer Tools)
PRC - E:\program files\firefox\firefox.exe (Mozilla Corporation)
PRC - E:\program files\firefox\plugin-container.exe (Mozilla Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
PRC - C:\Windows\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Windows\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
PRC - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
PRC - C:\Windows\SysWOW64\PING.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - E:\program files\Blaze Media Pro\NMSAccess32.exe ()
PRC - C:\Program Files\Mouse\Amoumain.exe ()
PRC - C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
========== Modules (No Company Name) ==========
MOD - E:\program files\firefox\mozjs.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\SysWOW64\CTXFIRES.DLL ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSS.exe ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecision.exe ()
MOD - E:\program files\evga\EVGA Precision\RTHAL.dll ()
MOD - E:\program files\evga\EVGA Precision\RTCore.dll ()
MOD - E:\program files\evga\EVGA Precision\EVGAPrecisionHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\RTFC.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTSSHooks.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTUI.dll ()
MOD - E:\program files\evga\EVGA Precision\Bundle\OSDServer\RTFC.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - \\.\globalroot\systemroot\syswow64\mswsock.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
MOD - C:\Program Files\Mouse\Amoumain.exe ()
MOD - C:\Program Files\Mouse\Amoures.dll ()
MOD - C:\Windows\SysWOW64\Amhooker.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (O&O Defrag) – C:\Program Files\OO Software\Defrag\oodag.exe (O&O Software GmbH)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (NETw5x32) – C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
SRV - (MBAMService) – E:\program files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (NMSAccess) – E:\program files\Blaze Media Pro\NMSAccess32.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (ha20x2k) – C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (CT20XUT.SYS) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ossrv) – C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (emupia) – C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (CTHWIUT.SYS) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (ctprxy2k) – C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64k.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (Amusbprt) – C:\Windows\SysNative\drivers\Amusbx64.sys (A4Tech Co.,Ltd.)
DRV:64bit: - (Amfilter) – C:\Windows\SysNative\drivers\Amfltx64.sys ((Standard mouse types))
DRV:64bit: - (RTL8187) – C:\Windows\SysNative\drivers\RTL8187.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RtlProt) – C:\Windows\SysNative\drivers\RtlProt.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV - (RTCore64) – E:\program files\evga\EVGA Precision\RTCore64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 86 70 2E 03 4A A3 CB 01 [binary data]
IE - HKU\S-1-5-21-2080295074-847258215-3720127285-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6778
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {e2c58150-9d72-11dd-ad8b-0800200c9a66}:1.3.1
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: E:\program files\vlc2\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Components: E:\program files\firefox\components [2012/02/02 10:24:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0\extensions\\Plugins: E:\program files\firefox\plugins [2012/01/12 17:54:39 | 000,000,000 | —D | M]
[2010/04/23 00:48:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Extensions
[2012/01/05 15:48:30 | 000,000,000 | —D | M] (No name found) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions
[2010/04/23 11:42:43 | 000,000,000 | —D | M] (Black Steel) – C:\Users\Loch\AppData\Roaming\Mozilla\Firefox\Profiles\q0ryv8o3.default\extensions\{e2c58150-9d72-11dd-ad8b-0800200c9a66}
() (No name found) – C:\USERS\LOCH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Q0RYV8O3.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
Hosts file not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [WheelMouse] C:\Program Files\Mouse\Amoumain.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files (x86)\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EVGAPrecision] E:\program files\evga\EVGA Precision\EVGAPrecisionWrapper.exe ()
O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] E:\program files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] E:\program files\winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [Creative MediaSource Go] C:\Program Files (x86)\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
O4 - HKU\S-1-5-21-2080295074-847258215-3720127285-1001..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - %SystemRoot%\system32\wshbth.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - %SystemRoot%\system32\wshbth.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {A796D216-2DE1-4EA8-BABB-FE6E7C959098} http://www.hp.com/cpso-support-new/SDD/hpsddObjSigned.cab (HPSDDX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72B389E3-F247-4530-8240-CCE44F13CE2F}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{93A74603-BBFE-4A3B-9214-61BBB91AB219}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{04cb0790-4eac-11df-a39d-806e6f6e6963}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (OODBS)
O34 - HKLM BootExecute: (E BootExecute settings..)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: NETw5x32 - C:\Windows\SysNative\PID_08A0.dll (Oak Technology Inc.)
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FFDS - ff_vfw.dll ()
Drivers32: msacm.ac3acm - C:\Windows\SysWow64\ac3acm.acm (fccHandler)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3fhg - C:\Windows\SysWow64\mp3fhg.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: VIDC.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/02/06 11:53:14 | 000,607,260 | —- | C] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 02:25:18 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Malwarebytes
[2012/02/06 02:25:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/05 23:50:59 | 000,000,000 | —D | C] – C:\Windows\SysNative\Macromed
[2012/02/05 23:47:38 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\BigHugeEngine
[2012/02/05 23:39:37 | 000,000,000 | —D | C] – C:\Windows\system64
[2012/02/03 19:16:30 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\BigHugeEngine
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BOSS
[2012/01/31 17:57:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\BOSS
[2012/01/31 17:35:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
[2012/01/31 10:23:25 | 001,130,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dfshim.dll
[2012/01/31 10:23:25 | 000,320,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHost.exe
[2012/01/31 10:23:25 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHost.exe
[2012/01/31 10:23:25 | 000,109,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\PresentationHostProxy.dll
[2012/01/31 10:23:25 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netfxperf.dll
[2012/01/31 10:23:24 | 001,942,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dfshim.dll
[2012/01/31 10:23:24 | 000,048,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netfxperf.dll
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Witcher 2
[2012/01/29 22:07:26 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\The Witcher 2
[2012/01/29 22:02:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher 2
[2012/01/16 18:25:31 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2012/01/16 18:23:42 | 006,004,544 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcpl.dll
[2012/01/16 18:23:42 | 003,028,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvc64.dll
[2012/01/16 18:23:42 | 002,562,368 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvsvcr.dll
[2012/01/16 18:23:42 | 000,118,080 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvmctray.dll
[2012/01/16 18:23:42 | 000,063,296 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvshext.dll
[2012/01/16 18:23:03 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2012/01/16 18:22:00 | 025,432,896 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2012/01/16 18:22:00 | 009,622,336 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvwgf2umx.dll
[2012/01/16 18:22:00 | 007,677,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2012/01/16 18:21:59 | 019,348,800 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2012/01/16 18:21:58 | 017,483,072 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2012/01/16 18:21:58 | 014,863,680 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvd3dum.dll
[2012/01/16 18:21:58 | 001,715,008 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2012/01/16 18:21:58 | 001,454,912 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2012/01/16 18:21:57 | 017,498,432 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2012/01/16 18:21:57 | 007,974,208 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2012/01/16 18:21:57 | 005,868,352 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2012/01/16 18:21:57 | 002,660,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2012/01/16 18:21:57 | 002,506,048 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2012/01/16 18:21:57 | 002,374,464 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2012/01/16 18:21:57 | 002,206,016 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2012/01/16 18:21:56 | 025,137,472 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2012/01/16 18:21:56 | 002,403,136 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvapi64.dll
[2012/01/16 18:21:56 | 002,095,424 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvapi.dll
[2012/01/16 18:21:55 | 000,068,928 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2012/01/16 18:21:55 | 000,061,248 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2012/01/16 18:21:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xtreme-G 290.53 Win7-Vista 64bit
[2012/01/16 18:20:41 | 000,000,000 | —D | C] – C:\NVIDIA
[2012/01/13 14:08:27 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Roaming\vlc
[2012/01/13 14:08:22 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/01/10 17:40:13 | 000,614,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\COMCTL32.OCX
[2012/01/10 17:40:13 | 000,053,248 | —- | C] (vbAccelerator) – C:\Windows\SysWow64\SSUBTMR6.DLL
[2012/01/10 17:40:13 | 000,010,752 | —- | C] (Almeida & Andrade Ltda) – C:\Windows\SysWow64\aamd532.dll
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\Documents\Nexus Mod Manager
[2012/01/09 08:46:29 | 000,000,000 | —D | C] – C:\Users\Loch\AppData\Local\Black_Tree_Gaming
[2010/07/28 17:31:32 | 000,060,928 | —- | C] ( ) – C:\Windows\SysWow64\a3d.dll
[2010/07/28 17:31:30 | 000,012,800 | —- | C] ( ) – C:\Windows\SysWow64\killapps.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/06 11:53:48 | 000,879,683 | —- | M] () – C:\Users\Loch\Desktop\SecurityCheck.exe
[2012/02/06 11:53:26 | 000,302,592 | —- | M] () – C:\Users\Loch\Desktop\pwy6t2ip.exe
[2012/02/06 11:53:14 | 000,607,260 | —- | M] (Swearware) – C:\Users\Loch\Desktop\dds.scr
[2012/02/06 11:43:36 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Loch\Desktop\HiJackThis.exe
[2012/02/06 11:26:02 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Loch\Desktop\OTL.exe
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:04:41 | 000,014,016 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 11:00:30 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/06 10:59:29 | 000,000,322 | —- | M] () – C:\Windows\tasks\GlaryInitialize.job
[2012/02/06 10:59:29 | 000,000,262 | —- | M] () – C:\Windows\tasks\RtlVistaStart.job
[2012/02/06 10:59:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/06 10:59:24 | 2616,549,376 | -HS- | M] () – C:\hiberfil.sys
[2012/02/06 10:59:23 | 000,653,029 | —- | M] () – C:\Windows\SysNative\oodbs.lor
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,062,644 | —- | M] () – C:\Windows\SysNative\BMXState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 04:16:58 | 000,000,788 | —- | M] () – C:\Windows\SysNative\DVCState-{00000005-00000000-00000002-00001102-00000005-10031102}.rfx
[2012/02/06 02:31:23 | 000,000,370 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/02/06 02:25:14 | 000,000,789 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/05 23:51:02 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/02/05 23:49:49 | 000,000,997 | —- | M] () – C:\Users\Loch\Desktop\Reckoning - Shortcut.lnk
[2012/02/05 00:25:02 | 000,014,336 | —- | M] () – C:\Users\Loch\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/03 22:22:48 | 000,778,150 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/03 22:22:48 | 000,659,580 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/03 22:22:48 | 000,120,508 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/03 19:11:51 | 000,316,691 | LS\x00\x00\x00\x00