This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.zeroaccess.B [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL logfile created on: 2/16/2012 9:01:44 AM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Jeff\Documents\Laura\virus removal
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.97 Gb Total Physical Memory | 4.82 Gb Available Physical Memory | 80.76% Memory free
11.93 Gb Paging File | 10.85 Gb Available in Paging File | 90.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.80 Gb Total Space | 222.00 Gb Free Space | 49.03% Space Free | Partition Type: NTFS
Drive D: | 12.76 Gb Total Space | 2.13 Gb Free Space | 16.70% Space Free | Partition Type: NTFS

Computer Name: JEFF-PC | User Name: Jeff | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/02/16 08:59:49 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Jeff\My Documents\Laura\virus removal\OTL.exe
PRC - [2009/07/13 20:14:28 | 000,015,360 | —- | M] (Microsoft Corporation) – C:\Windows\SysWOW64\PING.EXE


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2010/02/10 19:01:52 | 000,240,640 | —- | M] (IDT, Inc.) [Auto | Stopped] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\stacsv64.exe – (STacSV)
SRV:64bit: - [2010/02/10 19:01:50 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Stopped] – C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_b87ff64c8b56b7db\AESTSr64.exe – (AESTFilters)
SRV:64bit: - [2010/01/07 09:09:00 | 001,926,448 | —- | M] (Validity Sensors, Inc.) [Auto | Stopped] – C:\Windows\SysNative\vcsFPService.exe – (vcsFPService)
SRV:64bit: - [2009/07/30 19:42:34 | 000,864,032 | —- | M] (Broadcom Corporation.) [Auto | Stopped] – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe – (btwdins)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\appmgmts.dll – (AppMgmt)
SRV:64bit: - [2009/07/13 20:39:56 | 000,010,752 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysNative\inetsrv\WMSvc.exe – (WMSVC)
SRV:64bit: - [2009/07/13 20:39:46 | 000,006,656 | —- | M] (Oak Technology Inc.) [Auto | Stopped] – C:\Windows\SysNative\rvscc.dll – (rwbackupsrv)
SRV:64bit: - [2009/07/08 15:49:02 | 000,030,520 | —- | M] (Hewlett-Packard) [Auto | Stopped] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2009/07/02 16:16:00 | 000,203,264 | —- | M] (AMD) [Auto | Stopped] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2009/06/03 04:13:02 | 000,721,712 | —- | M] (Validity Sensors, Inc.) [Auto | Stopped] – C:\Windows\SysNative\vfsFPService.exe – (vfsFPService)
SRV:64bit: - [2008/07/29 13:20:28 | 004,737,024 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe – (msvsmon90)
SRV - [2012/01/16 16:28:30 | 000,546,768 | —- | M] (Threat Expert Ltd.) [Auto | Stopped] – C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe – (Browser Defender Update Service)
SRV - [2012/01/13 14:53:18 | 000,652,360 | —- | M] (Malwarebytes Corporation) [Auto | Stopped] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/01/11 16:18:14 | 001,117,624 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe – (sdCoreService)
SRV - [2012/01/11 14:56:12 | 000,402,336 | —- | M] (PC Tools) [On_Demand | Stopped] – C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe – (sdAuxService)
SRV - [2011/11/29 21:17:50 | 000,138,248 | R— | M] (Symantec Corporation) [Unknown | Stopped] – C:\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\19.5.0.145\ccSvcHst.exe – (NIS)
SRV - [2011/08/12 16:13:26 | 000,087,040 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe – (PassThru Service)
SRV - [2011/07/07 18:31:08 | 000,195,336 | —- | M] (Microsoft Corporation.) [On_Demand | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE – (BBSvc)
SRV - [2011/07/01 14:01:18 | 000,151,552 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe – (IHA_MessageCenter)
SRV - [2011/06/15 16:33:20 | 000,249,648 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE – (BBUpdate)
SRV - [2010/11/20 07:19:20 | 000,397,824 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (WAS)
SRV - [2010/11/20 07:19:20 | 000,397,824 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll – (W3SVC)
SRV - [2010/11/20 07:18:03 | 000,061,440 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll – (AppHostSvc)
SRV - [2010/10/14 17:27:38 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Stopped] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2010/09/29 06:00:24 | 000,185,640 | —- | M] (SupportSoft, Inc.) [Auto | Stopped] – C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe – (tgsrvc_verizondm) SupportSoft Repair Service (verizondm)
SRV - [2010/09/29 06:00:16 | 000,206,120 | —- | M] (SupportSoft, Inc.) [Auto | Stopped] – C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe – (sprtsvc_verizondm) SupportSoft Sprocket Service (verizondm)
SRV - [2010/05/10 11:00:55 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 12:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2010/01/21 19:40:02 | 000,069,632 | —- | M] (Macromedia) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe – (Macromedia Licensing Service)
SRV - [2010/01/07 08:53:16 | 001,656,112 | —- | M] (Validity Sensors, Inc.) [Auto | Stopped] – C:\Windows\SysWOW64\vcsFPService.exe – (vcsFPService)
SRV - [2009/08/05 11:49:44 | 000,284,016 | —- | M] (Eastman Kodak Company) [Auto | Stopped] – C:\Program Files (x86)\Kodak\AiO\Center\ekdiscovery.exe – (Kodak AiO Network Discovery Service)
SRV - [2009/07/17 17:25:20 | 000,322,624 | —- | M] (DigitalPersona, Inc.) [Auto | Stopped] – C:\Program Files (x86)\DigitalPersona\Bin\DpHostW.exe – (DpHost)
SRV - [2009/06/10 16:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 18:03:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Stopped] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®
SRV - [2009/06/03 04:12:50 | 000,599,344 | —- | M] (Validity Sensors, Inc.) [Auto | Stopped] – C:\Windows\SysWOW64\vfsFPService.exe – (vfsFPService)
SRV - [2009/05/22 13:02:20 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [2006/09/14 07:56:06 | 000,102,400 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor5.0)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/02/11 18:10:05 | 000,175,736 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS – (SymEvent)
DRV:64bit: - [2012/01/11 16:19:08 | 000,230,952 | —- | M] (PC Tools) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\PCTSD64.sys – (PCTSD)
DRV:64bit: - [2011/12/10 15:24:08 | 000,023,152 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:64bit: - [2011/12/01 16:07:08 | 000,453,896 | —- | M] (PC Tools) [Kernel | Boot | Stopped] – C:\Windows\SysNative\drivers\pctDS64.sys – (pctDS)
DRV:64bit: - [2011/11/23 21:23:47 | 001,092,728 | R— | M] (Symantec Corporation) [File_System | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.sys – (SymEFA)
DRV:64bit: - [2011/11/23 20:50:27 | 000,738,936 | R— | M] (Symantec Corporation) [File_System | System | Stopped] – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys – (SRTSP)
DRV:64bit: - [2011/11/23 20:50:27 | 000,037,496 | R— | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys – (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/11/16 22:37:59 | 000,405,624 | R— | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\NISx64\1305000.091\symnets.sys – (SymNetS)
DRV:64bit: - [2011/11/16 22:17:49 | 000,190,072 | R— | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\NISx64\1305000.091\Ironx64.sys – (SymIRON)
DRV:64bit: - [2011/11/14 15:12:28 | 000,367,912 | —- | M] (PC Tools) [Kernel | Boot | Stopped] – C:\Windows\SysNative\drivers\PCTCore64.sys – (PCTCore)
DRV:64bit: - [2011/11/04 18:59:30 | 000,167,048 | R— | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.sys – (ccSet_NIS)
DRV:64bit: - [2011/09/28 13:14:02 | 000,070,760 | —- | M] (PC Tools) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\PCTBD64.sys – (PCTBD)
DRV:64bit: - [2011/08/16 01:51:40 | 000,451,192 | R— | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.sys – (SymDS)
DRV:64bit: - [2011/08/02 16:38:56 | 000,051,712 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 08:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 06:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 04:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/09/22 23:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/06/25 15:08:10 | 000,036,928 | —- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\htcnprot.sys – (htcnprot)
DRV:64bit: - [2010/02/10 19:06:12 | 000,286,768 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/02/10 19:04:08 | 002,978,296 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2010/02/10 19:01:54 | 000,487,936 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2009/12/19 09:11:40 | 000,314,400 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/11/01 18:16:50 | 000,033,736 | —- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ANDROIDUSB.sys – (HTCAND64)
DRV:64bit: - [2009/07/20 22:39:00 | 000,140,712 | —- | M] (JMicron Technology Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\jmcr.sys – (JMCR)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 19:35:32 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\serscan.sys – (StillCam)
DRV:64bit: - [2009/07/13 19:10:47 | 000,011,264 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\rootmdm.sys – (ROOTMODEM)
DRV:64bit: - [2009/07/08 15:49:08 | 000,030,008 | —- | M] (Hewlett-Packard) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2009/07/08 15:48:50 | 000,041,272 | —- | M] (Hewlett-Packard) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2009/07/02 16:51:00 | 006,036,480 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:64bit: - [2009/07/01 15:46:52 | 000,098,344 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwaudio.sys – (btwaudio)
DRV:64bit: - [2009/07/01 15:46:48 | 000,132,648 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwavdt.sys – (btwavdt)
DRV:64bit: - [2009/07/01 15:46:40 | 000,021,160 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwrchid.sys – (btwrchid)
DRV:64bit: - [2009/06/29 13:17:00 | 000,070,656 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\enecir.sys – (enecir)
DRV:64bit: - [2009/06/29 12:00:00 | 000,116,752 | —- | M] (ATI Research Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\AtiHdmi.sys – (AtiHdmiService)
DRV:64bit: - [2009/06/10 16:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 16:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 16:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 16:01:06 | 001,146,880 | —- | M] (LSI Corp) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\agrsm64.sys – (AgereSoftModem)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [2009/06/10 15:35:33 | 000,389,120 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64) Intel®
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/06/04 17:54:36 | 000,408,600 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2009/04/29 10:48:32 | 000,018,432 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV:64bit: - [2009/04/07 18:33:08 | 000,035,104 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwl2cap.sys – (btwl2cap)
DRV:64bit: - [2009/01/09 15:02:08 | 000,031,744 | —- | M] (Research in Motion Ltd) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimSerial_AMD64.sys – (RimVSerPort)
DRV:64bit: - [2008/06/27 06:51:10 | 000,088,632 | —- | M] (Adobe Systems, Inc.) [Kernel | Auto | Stopped] – C:\Windows\SysNative\drivers\adfs.sys – (adfs)
DRV:64bit: - [2008/05/20 19:33:36 | 000,028,416 | —- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys – (RimUsb)
DRV - [2012/02/13 13:06:50 | 002,048,632 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20120213.002\ex64.sys – (NAVEX15)
DRV - [2012/02/13 13:06:50 | 000,138,360 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys – (EraserUtilRebootDrv)
DRV - [2012/02/13 13:06:50 | 000,117,880 | —- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\VirusDefs\20120213.002\eng64.sys – (NAVENG)
DRV - [2012/02/10 16:27:58 | 000,488,568 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\IPSDefs\20120210.002\IDSviA64.sys – (IDSVia64)
DRV - [2012/02/10 01:00:00 | 000,482,936 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys – (eeCtrl)
DRV - [2011/11/28 23:48:55 | 001,157,240 | —- | M] (Symantec Corporation) [Kernel | System | Stopped] – C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\Definitions\BASHDefs\20120207.003\BHDrvx64.sys – (BHDrvx64)
DRV - [2009/07/13 20:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.0: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.1: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Jeff\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2012/02/11 15:50:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/11 15:51:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2012/02/11 15:46:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\IPSFFPlgn\ [2012/02/11 18:11:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.5.0.145\coFFPlgn\ [2012/02/11 18:10:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\ [2012/02/16 08:46:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/02/11 15:52:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\firefoxext [2012/02/11 15:50:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/02/11 15:51:01 | 000,000,000 | —D | M]

[2011/09/23 20:08:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions
[2011/05/30 08:36:59 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/11 15:23:31 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/02/11 15:52:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2012/02/11 15:52:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/03/27 17:06:04 | 000,067,032 | —- | M] (Adobe Systems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2011/04/05 23:19:44 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: WPI Detector 1.1 (Enabled) = C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Jeff\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

Hosts file not found
O2:64bit: - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
O2:64bit: - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (DigitalPersona Personal Extension) - {395610AE-C624-4f58-B89E-23733EA00F9A} - C:\Program Files (x86)\DigitalPersona\Bin\DpOtsPluginIe8.dll (DigitalPersona, Inc.)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\19.5.0.145\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\19.5.0.145\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (hpBHO Class) - {ABD3B5E1-B268-407B-A150-2641DAB8D898} - C:\Program Files (x86)\Common Files\Homepage Protection\HomepageProtection.dll (AOL Products)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files (x86)\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files (x86)\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files (x86)\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\19.5.0.145\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files (x86)\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\SysNative\spool\drivers\x64\3\EKIJ5000MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DpAgent] C:\Program Files (x86)\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
O4 - HKLM..\Run: [EKIJ5000StatusMonitor] C:\Windows\System32\spool\drivers\x64\3\EKIJ5000MUI.exe File not found
O4 - HKLM..\Run: [HPCam_Menu] c:\Program Files (x86)\Hewlett-Packard\Media\Webcam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [nOutSSdAWyv.exe] C:\ProgramData\nOutSSdAWyv.exe File not found
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple Inc.)
O4 - HKCU..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: WallpaperStyle = 2
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Send image to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files (x86)\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files (x86)\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000014 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000016 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000017 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1C11B948-582A-433F-A98D-A8C4D5CC64F2} http://kitchenplanner.ikea.com/US/Core/Pla…yerAX_Win32.cab (20-20 3D Viewer)
O16 - DPF: {7B19E477-0FF8-11d4-9914-005004D3B3DB} http://java.sun.com/products/plugin/1.2/ji…122_017-win.cab (JavaPlugin.Object)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0012-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.2.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{788905F3-EA77-4DC8-BA4E-82C457847F79}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF1645F8-1958-445A-8B02-111EFFAAF745}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{7bbce72e-61e1-11e0-aab4-00271333d765}\Shell - "" = AutoRun
O33 - MountPoints2\{7bbce72e-61e1-11e0-aab4-00271333d765}\Shell\AutoRun\command - "" = G:\TL-Bootstrap.exe
O33 - MountPoints2\{b32794d2-61d9-11e0-a871-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b32794d2-61d9-11e0-a871-806e6f6e6963}\Shell\AutoRun\command - "" = G:\TL-Bootstrap.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgchsva.exe /sync)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG10\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/02/16 08:46:06 | 000,070,760 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTBD64.sys
[2012/02/16 08:46:05 | 002,246,608 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDCore.dll
[2012/02/16 08:46:05 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\Windows\PCTBDRes.dll
[2012/02/16 08:46:05 | 000,149,456 | —- | C] (PC Tools) – C:\Windows\SGDetectionTool.dll
[2012/02/16 08:45:44 | 001,096,688 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctEFA64.sys
[2012/02/16 08:45:44 | 000,453,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctDS64.sys
[2012/02/16 08:45:44 | 000,339,608 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctgntdi64.sys
[2012/02/16 08:45:44 | 000,145,432 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2012/02/16 08:45:42 | 000,367,912 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTCore64.sys
[2012/02/16 08:45:41 | 000,014,776 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctBTFix64.sys
[2012/02/16 08:45:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012/02/16 08:45:39 | 000,092,896 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\pctplsg64.sys
[2012/02/15 08:26:47 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\NPE
[2012/02/11 18:10:05 | 000,175,736 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/02/11 18:10:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Symantec Shared
[2012/02/11 18:09:46 | 001,092,728 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.sys
[2012/02/11 18:09:46 | 000,738,936 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.sys
[2012/02/11 18:09:46 | 000,451,192 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.sys
[2012/02/11 18:09:46 | 000,405,624 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\symnets.sys
[2012/02/11 18:09:46 | 000,190,072 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\Ironx64.sys
[2012/02/11 18:09:46 | 000,167,048 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.sys
[2012/02/11 18:09:46 | 000,037,496 | R— | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.sys
[2012/02/11 18:09:38 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1305000.091
[2012/02/11 11:38:24 | 000,000,000 | —D | C] – C:\Program Files\Symantec
[2012/02/11 11:38:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64
[2012/02/11 11:38:07 | 000,000,000 | —D | C] – C:\Windows\SysNative\drivers\NISx64\1106000.020
[2012/02/11 11:38:05 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2012/02/11 11:38:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Norton Internet Security
[2012/02/11 11:37:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\NortonInstaller
[2012/02/11 10:54:07 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Threat Expert
[2012/02/11 09:03:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\PC Tools
[2012/02/11 09:01:25 | 000,230,952 | —- | C] (PC Tools) – C:\Windows\SysNative\drivers\PCTSD64.sys
[2012/02/11 09:01:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\PC Tools
[2012/02/11 09:00:10 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\TestApp
[2012/02/09 17:35:03 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2012/02/09 17:26:18 | 000,000,000 | —D | C] – C:\Windows\system64
[2012/02/09 12:12:55 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PH Computer Test Bank
[2012/02/09 12:12:47 | 000,000,000 | —D | C] – C:\PH Computer Test Bank
[2012/01/23 22:16:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/23 22:15:27 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/01/23 22:15:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/01/23 22:15:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/01/23 22:11:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/01/23 22:11:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\QuickTime

========== Files - Modified Within 30 Days ==========

[2012/02/16 08:45:42 | 000,002,245 | —- | M] () – C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2012/02/16 08:44:49 | 000,001,775 | —- | M] () – C:\Users\Jeff\Desktop\sdsetup.exe.lnk
[2012/02/16 08:35:42 | 000,000,000 | -HS- | M] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/16 08:34:43 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/02/16 08:34:30 | 511,066,111 | -HS- | M] () – C:\hiberfil.sys
[2012/02/14 09:27:01 | 002,009,417 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012/02/13 12:44:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/13 11:46:28 | 000,024,448 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/13 11:46:28 | 000,024,448 | —- | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/13 10:22:59 | 000,002,256 | —- | M] () – C:\{19A4AFEE-174D-48D5-B16F-C9394C60FD1B}
[2012/02/13 09:43:15 | 000,002,160 | —- | M] () – C:\{933F79E1-4F6E-4102-9947-89D2AF8D9E6A}
[2012/02/13 08:44:10 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/12 11:15:17 | 000,004,782 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012/02/11 21:47:41 | 000,001,471 | —- | M] () – C:\Users\Jeff\Desktop\IE.lnk
[2012/02/11 20:19:22 | 000,003,288 | —- | M] () – C:\{A5BF15BE-5972-46A1-B4D1-9F79A2F27578}
[2012/02/11 18:10:05 | 000,175,736 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/02/11 18:10:05 | 000,007,488 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/02/11 18:10:05 | 000,000,855 | —- | M] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/02/11 18:09:59 | 000,002,931 | —- | M] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/02/11 18:08:36 | 000,001,297 | —- | M] () – C:\Users\Jeff\Desktop\Norton Installation Files.lnk
[2012/02/11 08:54:25 | 001,853,311 | —- | M] () – C:\Users\Jeff\Desktop\ProcessExplorer.zip
[2012/02/09 22:32:16 | 000,965,500 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/09 22:32:16 | 000,793,426 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/02/09 22:32:16 | 000,169,908 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/02/09 18:37:06 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 18:23:41 | 000,000,456 | —- | M] () – C:\ProgramData\6xDqQWa1GdefSg
[2012/02/09 18:22:24 | 000,000,272 | —- | M] () – C:\ProgramData\~6xDqQWa1GdefSg
[2012/02/09 17:36:53 | 000,000,184 | —- | M] () – C:\ProgramData\~6xDqQWa1GdefSgr
[2012/02/09 17:35:05 | 000,000,677 | —- | M] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/02/09 17:33:32 | 000,000,362 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2012/02/09 17:32:38 | 005,208,840 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/08 11:49:18 | 000,001,854 | —- | M] () – C:\Users\Jeff\AppData\Roaming\GhostObjGAFix.xml
[2012/02/06 11:54:21 | 000,013,877 | —- | M] () – C:\Users\Jeff\Desktop\FLYERII - Shortcut.lnk
[2012/02/06 11:54:21 | 000,013,870 | —- | M] () – C:\Users\Jeff\Desktop\FLYERI - Shortcut.lnk
[2012/01/29 22:03:52 | 000,005,963 | —- | M] () – C:\Users\Jeff\Desktop\bills and if paid - Shortcut.lnk
[2012/01/29 10:32:40 | 000,000,328 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJeff.job
[2012/01/26 23:22:06 | 000,000,172 | —- | M] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\isolate.ini
[2012/01/25 16:46:43 | 000,002,344 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/01/24 11:58:10 | 000,135,763 | —- | M] () – C:\Users\Jeff\Desktop\COURSE SYLLABUS_MTE 507.pdf
[2012/01/23 22:16:32 | 000,001,783 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/01/23 22:11:36 | 000,001,845 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk

========== Files Created - No Company Name ==========

[2012/02/16 08:46:06 | 000,767,952 | —- | C] () – C:\Windows\BDTSupport.dll
[2012/02/16 08:46:05 | 000,003,488 | —- | C] () – C:\Windows\UDB.zip
[2012/02/16 08:46:05 | 000,000,882 | —- | C] () – C:\Windows\RegSDImport.xml
[2012/02/16 08:46:05 | 000,000,879 | —- | C] () – C:\Windows\RegISSImport.xml
[2012/02/16 08:46:05 | 000,000,131 | —- | C] () – C:\Windows\IDB.zip
[2012/02/16 08:45:42 | 000,002,245 | —- | C] () – C:\Users\Public\Desktop\PC Tools Spyware Doctor.lnk
[2012/02/13 10:22:57 | 000,002,256 | —- | C] () – C:\{19A4AFEE-174D-48D5-B16F-C9394C60FD1B}
[2012/02/13 09:43:15 | 000,002,160 | —- | C] () – C:\{933F79E1-4F6E-4102-9947-89D2AF8D9E6A}
[2012/02/12 11:16:03 | 000,004,782 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\VT20111023.022
[2012/02/11 22:00:00 | 000,002,491 | —- | C] () – C:\Users\Public\Desktop\Safari.lnk
[2012/02/11 22:00:00 | 000,002,344 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2012/02/11 22:00:00 | 000,002,076 | —- | C] () – C:\Users\Public\Desktop\Teaching ROBOTC for MINDSTORMS 2.0.lnk
[2012/02/11 22:00:00 | 000,002,009 | —- | C] () – C:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2012/02/11 22:00:00 | 000,001,845 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/02/11 22:00:00 | 000,001,783 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/02/11 22:00:00 | 000,001,082 | —- | C] () – C:\Users\Public\Desktop\HTC Sync.lnk
[2012/02/11 22:00:00 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\µTorrent.lnk
[2012/02/11 22:00:00 | 000,000,822 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/02/11 21:59:43 | 000,002,507 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 2.6.lnk
[2012/02/11 21:59:43 | 000,001,547 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012/02/11 21:59:43 | 000,001,246 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012/02/11 21:59:42 | 000,002,557 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office PowerPoint Viewer 2007.lnk
[2012/02/11 21:59:42 | 000,002,503 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2012/02/11 21:59:42 | 000,002,486 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012/02/11 21:59:42 | 000,002,420 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Plug-in Control Panel .lnk
[2012/02/11 21:59:42 | 000,002,059 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Web Platform Installer.lnk
[2012/02/11 21:59:42 | 000,001,562 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Try Microsoft Office for 60 days.lnk
[2012/02/11 21:59:42 | 000,001,458 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2012/02/11 21:59:42 | 000,001,403 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Basic 2008 Express Edition.lnk
[2012/02/11 21:59:42 | 000,001,374 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2012/02/11 21:59:42 | 000,001,352 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2012/02/11 21:59:42 | 000,001,345 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/02/11 21:59:42 | 000,001,330 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012/02/11 21:59:42 | 000,001,326 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012/02/11 21:59:42 | 000,001,305 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2012/02/11 21:59:42 | 000,001,210 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012/02/11 21:59:42 | 000,001,147 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Works Task Launcher.lnk
[2012/02/11 21:59:42 | 000,000,182 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pandora Internet Radio.url
[2012/02/11 21:59:41 | 000,002,519 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/02/11 21:59:41 | 000,002,465 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 8.lnk
[2012/02/11 21:59:41 | 000,002,453 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 8 Professional.lnk
[2012/02/11 21:59:41 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/02/11 21:59:41 | 000,002,276 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
[2012/02/11 21:59:41 | 000,002,270 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Trials for QuickBooks, Quicken and TurboTax.lnk
[2012/02/11 21:59:41 | 000,002,171 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle Designer 8.0.lnk
[2012/02/11 21:59:41 | 000,002,157 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 3.0.lnk
[2012/02/11 21:59:41 | 000,002,089 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help Center.lnk
[2012/02/11 21:59:41 | 000,002,054 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Advisor.lnk
[2012/02/11 21:59:41 | 000,001,523 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012/02/11 21:59:41 | 000,001,357 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012/02/11 21:59:41 | 000,001,266 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012/02/11 21:59:41 | 000,001,211 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012/02/11 21:59:41 | 000,001,173 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012/02/11 21:59:41 | 000,001,138 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DigitalPersona Personal.lnk
[2012/02/11 21:59:41 | 000,001,119 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 5.0.lnk
[2012/02/11 21:59:41 | 000,001,075 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5 (64 Bit).lnk
[2012/02/11 21:59:41 | 000,001,009 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat.com.lnk
[2012/02/11 21:59:41 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/02/11 21:47:13 | 000,001,471 | —- | C] () – C:\Users\Jeff\Desktop\IE.lnk
[2012/02/11 20:19:21 | 000,003,288 | —- | C] () – C:\{A5BF15BE-5972-46A1-B4D1-9F79A2F27578}
[2012/02/11 18:10:06 | 002,009,417 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\Cat.DB
[2012/02/11 18:10:05 | 000,007,488 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/02/11 18:10:05 | 000,000,855 | —- | C] () – C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/02/11 18:09:59 | 000,002,931 | —- | C] () – C:\Users\Public\Desktop\Norton Internet Security.lnk
[2012/02/11 18:09:38 | 000,007,496 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS64.cat
[2012/02/11 18:09:38 | 000,007,468 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.cat
[2012/02/11 18:09:38 | 000,007,462 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.cat
[2012/02/11 18:09:38 | 000,007,460 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA64.cat
[2012/02/11 18:09:38 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\symnet64.cat
[2012/02/11 18:09:38 | 000,007,458 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.cat
[2012/02/11 18:09:38 | 000,007,450 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\iron.cat
[2012/02/11 18:09:38 | 000,004,782 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymVTcer.dat
[2012/02/11 18:09:38 | 000,003,434 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymEFA.inf
[2012/02/11 18:09:38 | 000,002,852 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymDS.inf
[2012/02/11 18:09:38 | 000,001,441 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\SymNet.inf
[2012/02/11 18:09:38 | 000,001,438 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtsp64.inf
[2012/02/11 18:09:38 | 000,001,420 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\srtspx64.inf
[2012/02/11 18:09:38 | 000,000,853 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\ccSetx64.inf
[2012/02/11 18:09:38 | 000,000,772 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\Iron.inf
[2012/02/11 18:09:38 | 000,000,172 | —- | C] () – C:\Windows\SysNative\drivers\NISx64\1305000.091\isolate.ini
[2012/02/11 18:04:46 | 000,001,297 | —- | C] () – C:\Users\Jeff\Desktop\Norton Installation Files.lnk
[2012/02/11 11:38:07 | 000,007,402 | R— | C] () – C:\Windows\SysNative\drivers\NISx64\1106000.020\iron.cat
[2012/02/11 09:00:11 | 000,001,775 | —- | C] () – C:\Users\Jeff\Desktop\sdsetup.exe.lnk
[2012/02/11 08:54:34 | 001,853,311 | —- | C] () – C:\Users\Jeff\Desktop\ProcessExplorer.zip
[2012/02/09 18:37:06 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/09 17:35:15 | 000,000,184 | —- | C] () – C:\ProgramData\~6xDqQWa1GdefSgr
[2012/02/09 17:35:13 | 000,000,272 | —- | C] () – C:\ProgramData\~6xDqQWa1GdefSg
[2012/02/09 17:35:05 | 000,000,677 | —- | C] () – C:\Users\Jeff\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/02/09 17:34:43 | 000,000,456 | —- | C] () – C:\ProgramData\6xDqQWa1GdefSg
[2012/02/09 17:27:25 | 000,000,000 | -HS- | C] () – C:\Windows\SysNative\dds_trash_log.cmd
[2012/02/06 11:54:21 | 000,013,877 | —- | C] () – C:\Users\Jeff\Desktop\FLYERII - Shortcut.lnk
[2012/02/06 11:54:21 | 000,013,870 | —- | C] () – C:\Users\Jeff\Desktop\FLYERI - Shortcut.lnk
[2012/01/29 22:03:52 | 000,005,963 | —- | C] () – C:\Users\Jeff\Desktop\bills and if paid - Shortcut.lnk
[2012/01/24 11:58:10 | 000,135,763 | —- | C] () – C:\Users\Jeff\Desktop\COURSE SYLLABUS_MTE 507.pdf
[2011/10/17 19:54:35 | 000,009,302 | —- | C] () – C:\Users\Jeff\AppData\Roaming\Microsoft Excel.EML
[2011/08/09 18:43:34 | 000,001,854 | —- | C] () – C:\Users\Jeff\AppData\Roaming\GhostObjGAFix.xml
[2011/05/30 08:36:59 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2011/05/29 21:55:01 | 000,038,412 | —- | C] () – C:\Users\Jeff\AppData\Roaming\Microsoft Excel.ADR
[2011/04/22 19:17:07 | 000,764,614 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4508.3
[2011/04/22 19:17:03 | 000,758,762 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4508.2
[2011/04/22 19:17:02 | 000,763,339 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4508.1
[2011/04/22 19:17:00 | 003,598,734 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4508.JPG
[2011/04/22 19:16:59 | 003,598,734 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4508.0
[2011/01/12 10:47:42 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\ActPanel.dll
[2011/01/08 19:10:49 | 000,621,739 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4010.2
[2011/01/08 19:10:45 | 000,625,661 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4010.1
[2011/01/08 19:10:43 | 000,626,177 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4010.JPG
[2011/01/08 19:10:42 | 003,330,243 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_4010.0
[2011/01/04 18:37:04 | 000,001,940 | —- | C] () – C:\Users\Jeff\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/12/14 10:11:28 | 000,065,536 | —- | C] () – C:\Users\Jeff\AppData\Local\ie_runner_app.exe
[2010/09/26 20:21:39 | 003,026,761 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG_1860.JPG
[2010/08/17 08:32:32 | 000,025,757 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpHFE100381110_7_09[1].3
[2010/08/17 08:32:30 | 000,025,962 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpHFE100381110_7_09[1].2
[2010/08/17 08:32:29 | 000,025,740 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpHFE100381110_7_09[1].1
[2010/08/17 08:32:28 | 000,025,751 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpHFE100381110_7_09[1].JPG
[2010/08/17 08:32:28 | 000,025,751 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpHFE100381110_7_09[1].0
[2010/06/22 16:12:54 | 000,000,362 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2010/05/01 19:26:47 | 000,004,608 | —- | C] () – C:\Users\Jeff\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/18 13:14:01 | 000,000,770 | —- | C] () – C:\Windows\Brpfx04a.ini
[2010/02/18 13:14:01 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2010/02/18 13:13:16 | 000,000,419 | —- | C] () – C:\Windows\BRWMARK.INI
[2010/02/18 13:13:16 | 000,000,027 | —- | C] () – C:\Windows\BRPP2KA.INI
[2010/02/18 13:09:12 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2010/02/18 13:09:11 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2010/02/18 13:09:11 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2010/02/12 19:53:25 | 000,008,212 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1]_navi.JPG
[2010/02/12 19:53:20 | 000,219,103 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1].3
[2010/02/12 19:53:20 | 000,209,461 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1].2
[2010/02/12 19:53:18 | 000,554,841 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1].JPG
[2010/02/12 19:53:18 | 000,554,841 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1].0
[2010/02/12 19:53:18 | 000,210,018 | —- | C] () – C:\Users\Jeff\AppData\Local\tmpIMG00051[1].1
[2010/01/24 22:21:14 | 000,000,256 | —- | C] () – C:\Windows\SysWow64\pool.bin
[2010/01/23 10:46:45 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2010/01/22 10:43:55 | 000,053,248 | —- | C] () – C:\Windows\SysWow64\pxhpinst.exe
[2010/01/22 10:31:05 | 000,000,209 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/01/22 10:08:42 | 002,463,976 | —- | C] () – C:\Windows\SysWow64\NPSWF32.dll
[2010/01/21 19:18:50 | 000,959,716 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/01/21 18:45:56 | 000,023,113 | —- | C] () – C:\Windows\hpqins15.dat
[2009/10/25 21:27:20 | 000,013,312 | —- | C] () – C:\Windows\LPRES.DLL
[2009/08/09 01:54:43 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 001,498,564 | —- | C] () – C:\Windows\SysWow64\igkrng400.bin
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2007/11/14 18:17:34 | 000,204,800 | —- | C] () – C:\Windows\SysWow64\CogentBioSDK.dll
[2003/01/07 15:05:08 | 000,002,695 | —- | C] () – C:\Windows\SysWow64\OUTLPERF.INI

========== LOP Check ==========

[2010/02/20 19:11:30 | 000,000,000 | -HSD | M] – C:\Users\Jeff\AppData\Roaming\.#
[2010/09/21 20:48:38 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/02/11 15:35:40 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Digiarty
[2012/02/11 15:35:40 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\DigitalPersona
[2011/10/20 09:46:15 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\HTC
[2012/02/11 15:53:56 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\ICAClient
[2012/02/11 15:53:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PC-FAX TX
[2010/06/21 20:47:34 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Red Kawa
[2010/07/19 18:31:03 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Regensoft
[2010/01/24 22:20:55 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Research In Motion
[2012/02/11 15:53:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TechWizard
[2010/07/27 16:23:04 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Temp
[2012/02/11 09:00:10 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TestApp
[2010/09/11 00:53:26 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TestGen
[2012/02/11 15:53:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Thunderbird
[2011/03/06 13:00:38 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\upromise
[2012/02/11 15:53:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\uTorrent
[2011/01/26 16:01:30 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\W3i, LLC
[2010/06/23 15:34:46 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\WildTangent
[2011/10/22 08:22:31 | 000,032,542 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 143 bytes -> C:\Users\Jeff\AppData\Roaming\Microsoft Excel.EML:OECustomProperty
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84

< End of report >


OTL Extras logfile created on: 2/16/2012 9:01:44 AM - Run 1
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Users\Jeff\Documents\Laura\virus removal
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

5.97 Gb Total Physical Memory | 4.82 Gb Available Physical Memory | 80.76% Memory free
11.93 Gb Paging File | 10.85 Gb Available in Paging File | 90.88% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.80 Gb Total Space | 222.00 Gb Free Space | 49.03% Space Free | Partition Type: NTFS
Drive D: | 12.76 Gb Total Space | 2.13 Gb Free Space | 16.70% Space Free | Partition Type: NTFS

Computer Name: JEFF-PC | User Name: Jeff | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.js [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
.txt [@ = Reg Error: Value error.] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0645A454-AD44-4F0D-99CF-6B762735AD1F}" = aioprnt
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{0C6C4C8A-3B96-4681-90BA-0E15CDE96298}" = Microsoft SQL Server 2008 Management Studio
"{108C8C1D-DA02-4A6C-94CD-5603F6A6FC72}" = Microsoft SQL Server 2008 Management Studio
"{16AD84C0-E7A0-F64D-D55A-15D274C4439A}" = ccc-utility64
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{41BC9E31-0D39-462E-8E4C-767B21A3B1C3}" = MobileMe Control Panel
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5E11C972-1E76-45FE-8F92-14E0D1140B1B}" = iTunes
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62A20ECA-920E-4052-BF77-88C78DD20FAA}" = Validity Sensors DDK
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{75104836-CAC7-444E-A39E-3F54151942F5}" = Apple Mobile Device Support
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{83715090-142B-D305-36EC-7538A007D336}" = ATI Catalyst Install Manager
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{90A80D89-A0E4-33C1-B13D-B93CB3496867}" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{94D70749-4281-39AC-AD90-B56A0E0A402E}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = HP Integrated Module with Bluetooth wireless technology
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files
"{B67C01B3-8502-4BE7-AEAB-BBDE910AD3EE}" = Microsoft Web Platform Installer 2.0
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}" = Microsoft SQL Server 2008 Native Client
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D1829BE5-F305-4576-9593-C66FC7E0B008}" = iCloud
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DD3BF908-F6B0-45A5-BED3-79E8888DDA93}" = DigitalPersona Personal 4.10
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{DFB3AD2B-4EE2-3077-BF1D-3CA164BC5336}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F5C819A5-E068-4f7d-B91A-1BD18702AFFB}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32
"{F65B8208-5221-43D9-AA12-DDEA64EC4AF6}" = Validity Sensors software
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU
"OfficeTrial" = Microsoft Office Home and Student 60 day trial
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{01C5A10F-AD9B-405B-853A-6659841A1242}" = Microsoft SQL Server 2008 Policies
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{08DB3902-2CE0-474D-BCE3-0177766CE9F1}" = HP Support Assistant
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C19D563-5F25-4621-BF10-01F741BD283F}" = Microsoft SQL Server Compact 3.5 SP1 Design Tools English
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10934A28-0CC6-4B98-A14F-76B3546003AF}" = ksDIP
"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{16D0F2D2-242C-4885-BEF1-4B1655C141AE}" = Bing Bar
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196E77C5-F524-4B50-BD1A-2C21EEE9B8F7}" = Microsoft SQL Server 2008 Common Files
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{205A5182-EFC8-4C25-B61D-C164F8FF4048}" = BlackBerry Desktop Software 5.0.1
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{25569723-DC5A-4467-A639-79535BF01B71}" = Adobe Help Center 2.1
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{266D0EEA-E5A6-4A08-A0EE-5391D4EA44A7}" = Catalyst Control Center - Branding
"{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java™ 6 Update 24
"{27B0C2FD-9739-8D7D-6552-307C786D9097}" = Catalyst Control Center InstallProxy
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A2F3AE8-246A-4252-BB26-1BEB45627074}" = Microsoft SQL Server System CLR Types
"{2E7B6B00-5ECD-49A1-8FD4-4B647C5D8027}" = Adobe Captivate 3
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32A3A4F4-B792-11D6-A78A-00B0D0160230}" = Java™ SE Development Kit 6 Update 23
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{343666E2-A059-48AC-AD67-230BF74E2DB2}" = Apple Application Support
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38022B5C-0C69-389F-DA48-B87480B5705A}" = CCC Help Turkish
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3BBBF379-6C7E-0985-18F6-6C60D6C36EC6}" = CCC Help Portuguese
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{4313E16C-811B-469F-8815-6EB98085F8B2}" = SlingBoxWatchYourTVAnyWhere
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = PowerRecover
"{4815BD99-96A4-49FE-A885-DCF06E9E4E78}" = Microsoft SQL Server 2008 Database Engine Shared
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A6F34E2-09E5-4616-B227-4A26A488A6F9}" = Microsoft SQL Server 2008 Common Files
"{4B2F56AC-C043-C84F-3EF1-E6D6F21E934F}" = Catalyst Control Center Graphics Full Existing
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4E968D9C-21A7-4915-B698-F7AEB913541D}" = Microsoft SQL Server 2008 R2 Management Objects
"{4F2C2E34-5A3E-0E70-BDFC-A5B1E3C2FFAC}" = Catalyst Control Center Graphics Light
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{530AFAFF-6F0A-48BB-88D0-04F9658322D3}" = Adobe Premiere Elements 3.0
"{532715CE-CFD6-E4F8-53C3-2F1DE31C04DA}" = CCC Help Hungarian
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{558CC8A3-F1A2-9C31-7B90-F61E476B8622}" = CCC Help Dutch
"{56BA241F-580C-43D2-8403-947241AAE633}" = center
"{5C474A83-A45F-470C-9AC8-2BD1C251BF9A}" = Skype™ 4.1
"{5D76ABD5-262B-6D65-6C13-F38175C7A5AF}" = CCC Help Korean
"{5D92E608-E454-0C8C-D577-7F7C06151117}" = CCC Help Greek
"{5EFA68C8-CFFD-407F-8B17-7D7C61D2F93A}" = InstallIQ Updater
"{6289BE55-0CE4-44EE-8AB5-EC4DA57AFAA9}" = Teaching ROBOTC for MINDSTORMS 2.0
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{64CDE8F2-3791-46F5-BAD2-72FFF5252FAB}" = Microsoft SQL Server Compact 3.5 SP1 Query Tools English
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{689E0AB3-50B2-4E5A-9DCE-6DA9F5BE1314}" = BlackBerry® Media Sync
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6C1E7AA1-44E9-446D-AAB2-0DE6D9EFEAB1}" = Safari
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{6EACDDF4-4220-49A3-9204-984C86852C3D}" = Adobe Premiere Elements 3.0 Templates
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79EECA21-CDFA-6012-5E8B-6CF2623D647A}" = Catalyst Control Center Graphics Full New
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7BE6BC10-6737-CD9D-8363-F919B8D6D917}" = Catalyst Control Center Core Implementation
"{7EACD74C-147F-478C-9389-F9F52EE3C88A}" = LightScribe System Software
"{80813829-BE27-4799-8BC7-2F75A7B6CB50}" = IHA_MessageCenter
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{80FBA7A7-ABD1-4910-A916-023075C45593}" = CCC Help Danish
"{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8797DE34-22BC-CA33-6B67-A0CC2765B545}" = CCC Help German
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8136 8168 8169 Ethernet Driver
"{89D1C17B-90DE-650A-073A-A7FA7BC6ECE5}" = CCC Help French
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8B422518-2C90-4F72-9989-356EA3731669}" = Macromedia Captivate
"{8C0B406B-DF08-49EF-8702-FA45752C135F}" = Verizon Download Manager
"{8C664716-FD23-9902-A29E-863D056F46FC}" = CCC Help Russian
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8EDBA74D-0686-4C99-BFDD-F894678E5102}" = Adobe Common File Installer
"{8F36B221-F483-B7CE-4DDA-7BDA4D81E306}" = CCC Help English
"{8FB16749-1235-D027-AF25-1D22A9FEC0D5}" = CCC Help Thai
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90F6051D-A69F-4159-9203-7E20430E1056}" = HP MediaSmart SlingPlayer
"{91A3A4DE-656A-5C7A-5B61-75FB6D167A6A}" = CCC Help Polish
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D318C86-AF4C-409F-A6AC-7183FF4CF424}" = Internet TV for Windows Media Center
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D6D76A6-4328-49E8-97A7-531A74841DA5}" = Microsoft SQL Server 2008 Setup Support Files (English)
"{9EDB805A-E11C-8842-2393-FDFDA17963AC}" = CCC Help Chinese Traditional
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A16D1BBD-BE86-0183-4152-2E85FECC31F7}" = CCC Help Finnish
"{A19856E3-C9D7-988E-5B8C-70C87342B8DD}" = Catalyst Control Center Localization All
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = Brother MFL-Pro Suite MFC-685CW
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7B609FB-83D8-4FC3-8477-1BC65ECFE85B}" = Adobe Photoshop Elements 5.0
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-1033-0000-7760-000000000003}" = Adobe Acrobat 8 Professional
"{AC76BA86-7AD7-FFFF-7B44-A91000000001}" = Adobe Reader 9.1 MUI
"{AD777154-A573-4FCA-C730-D7C33437262C}" = CCC Help Czech
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B51605BF-6326-4553-AE96-6D7F1813D5F5}" = HP User Guides 0154
"{B53E61D7-7C80-40DF-82D2-CF5390D6D20A}" = HP Advisor
"{B66D2CC9-652D-EBE5-497F-74BBC1029FB4}" = CCC Help Japanese
"{B6A4D07E-725F-07CD-DE49-8AB76939631D}" = CCC Help Norwegian
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{BF930A5D-4F36-5158-C8DA-DECD5B51A78E}" = CCC Help Chinese Standard
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C688457E-03FD-4941-923B-A27F4D42A7DD}" = Microsoft SQL Server 2008 Browser
"{C6FCE95C-0072-40C0-9AB2-3EF88DA6CED9}" = Catalyst Control Center Graphics Previews Common
"{C965F01C-76EA-4BD7-973E-46236AE312D7}" = Sql Server Customer Experience Improvement Program
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CDC08463-9303-4BF1-BF8C-E1A2ECEE3248}" = Adobe Creative Suite 5 Web Premium
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D5B18B60-4FC3-42AD-A629-9CA10ACC06CD}" = HTC Sync
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DD622B1D-A78E-3FE8-9C8C-246F5764B0D0}" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE6B7599-D3EF-4436-8836-BAA0B0D7768D}" = aiofw
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF166A93-835F-DF13-E974-FD73E8D7F4F6}" = CCC Help Swedish
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E09F7D2B-C1C1-D80B-7775-6FFE9D713C60}" = CCC Help Spanish
"{E0F274B7-592B-4669-8FB8-8D9825A09858}" = KODAK AiO Home Center
"{E26EEBF8-3A50-8095-5877-AE243C8852EF}" = Catalyst Control Center Graphics Previews Vista
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EBFEEB3F-3E3B-4725-A4E0-376144CE4F76}" = Citrix XenApp Web Plugin
"{EC8049FF-B0E3-A963-408C-1B1D8F20DD55}" = CCC Help Italian
"{ED784556-66AA-3F17-9B58-7246ACB5C7E4}" = Microsoft Visual Basic 2010 Express - ENU
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F1DC7648-8623-442F-92B7-E118DF61872E}" = Microsoft SQL Server 2008 RsFx Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F3494AB6-6900-41C6-AF57-823626827ED8}" = Microsoft SQL Server 2008 Database Engine Shared
"{F3B912F5-EB57-45AA-B3D1-EB532BCF6EF8}" = HP Setup
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FD1D88FA-E5E0-BA76-73C8-7362E9703842}" = ccc-core-static
"{FDB3B167-F4FA-461D-976F-286304A57B2A}" = Adobe AIR
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE24086F-3B0C-4C47-A874-97A7B8E2FBBE}" = aioscnnr
"Adobe Acrobat 8 Professional" = Adobe Acrobat 8.1.0 Professional
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Photoshop Elements 5" = Adobe Photoshop Elements 5.0
"AviSynth" = AviSynth 2.5
"Browser Defender_is1" = Browser Defender 4.0
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"CUZ4_is1" = CAM UnZip 4.5
"DVD Decrypter" = DVD Decrypter (Remove Only)
"Free CD to MP3 Converter" = Free CD to MP3 Converter
"Google Chrome" = Google Chrome
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = HP MediaSmart Movie Themes
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"Java 2 SDK Standard Edition v1.2.2_017" = Java 2 SDK Standard Edition v1.2.2_017
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.60.1.1000
"Microsoft SQL Server 10" = Microsoft SQL Server 2008
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008
"Microsoft Visual Basic 2008 Express Edition with SP1 - ENU" = Microsoft Visual Basic 2008 Express Edition with SP1 - ENU
"Microsoft Visual Basic 2010 Express - ENU" = Microsoft Visual Basic 2010 Express - ENU
"Mozilla Thunderbird (3.1.10)" = Mozilla Thunderbird (3.1.10)
"nbi-nb-base-[removed].0" = NetBeans IDE 6.9.1
"NIS" = Norton Internet Security
"PremElem30" = Adobe Premiere Elements 3.0
"Spyware Doctor" = PC Tools Spyware Doctor 9.0
"TestGen" = TestGen
"uTorrent" = µTorrent
"Videora iPod Converter" = Videora iPod Converter 5.04
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinX DVD Ripper_is1" = WinX DVD Ripper 4.5.5
"YouTube Downloader App" = YouTube Downloader App 2.03

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5ab195f72cf24285" = Challenge 5 - Password Verifier
"PowerTeacher Gradebook" = PowerTeacher Gradebook
"UnityWebPlayer" = Unity Web Player
"Upromise TurboSaver" = Upromise TurboSaver (remove only)

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2/13/2012 9:43:00 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/13/2012 9:43:00 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/13/2012 9:43:01 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second

Error - 2/13/2012 9:43:01 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 28695667

Error - 2/13/2012 9:43:02 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 28695667

Error - 2/13/2012 9:45:17 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/13/2012 9:46:10 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/13/2012 10:02:15 AM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/13/2012 1:09:36 PM | Computer Name = Jeff-PC | Source = Bonjour Service | ID = 100
Description = Client application bug: DNSServiceResolve(Brother\032MFC-685CW._pdl-datastream._tcp.local.)
active for over two minutes. This places considerable burden on the network.

Error - 2/15/2012 1:51:04 PM | Computer Name = Jeff-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Safari.exe, version: 5.33.21.1, time stamp:
0x4d8810be Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x02c8d176 Faulting process id: 0x71c Faulting application
start time: 0x01ccec0a1adc6975 Faulting application path: C:\Program Files (x86)\Safari\Safari.exe
Faulting
module path: unknown Report Id: a1103588-57fd-11e1-847e-00269edd6f31

[ DigitalPersona Pro Events ]
Error - 8/27/2010 8:38:33 PM | Computer Name = Jeff-PC | Source = DigitalPersona Pro | ID = 17827841
Description = One-to-one fingerprint match failed.

[ Hewlett-Packard Events ]
Error - 10/24/2010 8:02:03 AM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = en-US Could not find file 'C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Logs\SystemInfoAA.xml'. mscorlib at System.IO.__Error.WinIOError(Int32
errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode
mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32
bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath,
Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode mode,
FileAccess access, FileShare share, Int32 bufferSize, FileOptions options, String
msgPath, Boolean bFromProxy) at System.IO.FileStream..ctor(String path, FileMode
mode, FileAccess access, FileShare share, Int32 bufferSize, FileOptions options)

at System.IO.StreamReader..ctor(String path, Encoding encoding, Boolean detectEncodingFromByteOrderMarks,
Int32 bufferSize) at System.IO.StreamReader..ctor(String path, Encoding encoding)

at System.IO.File.ReadAllText(String path, Encoding encoding) at n.a()

Error - 12/28/2010 8:47:44 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description =

Error - 8/9/2011 7:43:34 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\081109074331.xml
File not created by asset agent

Error - 8/23/2011 8:31:17 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\081123083114.xml
File not created by asset agent

Error - 9/13/2011 8:32:45 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091113083243.xml
File not created by asset agent

Error - 9/20/2011 7:09:33 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091120070930.xml
File not created by asset agent

Error - 10/18/2011 8:00:08 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\101118080005.xml
File not created by asset agent

Error - 11/8/2011 8:56:06 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\111108075603.xml
File not created by asset agent

Error - 11/22/2011 10:02:41 PM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\111122090239.xml
File not created by asset agent

Error - 1/18/2012 9:52:36 AM | Computer Name = Jeff-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\011218085233.xml
File not created by asset agent

[ Media Center Events ]
Error - 11/29/2010 5:03:13 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:03:13 PM - Error connecting to the internet. 4:03:13 PM - Unable
to contact server..

Error - 11/29/2010 5:03:34 PM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:03:18 PM - Error connecting to the internet. 4:03:18 PM - Unable
to contact server..

Error - 12/4/2010 5:30:41 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:30:41 AM - Error connecting to the internet. 4:30:41 AM - Unable
to contact server..

Error - 12/4/2010 5:30:52 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:30:46 AM - Error connecting to the internet. 4:30:46 AM - Unable
to contact server..

Error - 12/11/2010 5:50:28 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:50:28 AM - Error connecting to the internet. 4:50:28 AM - Unable
to contact server..

Error - 12/11/2010 5:50:35 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 4:50:33 AM - Error connecting to the internet. 4:50:33 AM - Unable
to contact server..

Error - 6/9/2011 5:54:09 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 5:54:09 AM - Error connecting to the internet. 5:54:09 AM - Unable
to contact server..

Error - 6/9/2011 5:54:17 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 5:54:14 AM - Error connecting to the internet. 5:54:14 AM - Unable
to contact server..

Error - 6/16/2011 7:41:20 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 7:41:20 AM - Error connecting to the internet. 7:41:20 AM - Unable
to contact server..

Error - 6/16/2011 7:41:32 AM | Computer Name = Jeff-PC | Source = MCUpdate | ID = 0
Description = 7:41:25 AM - Error connecting to the internet. 7:41:25 AM - Unable
to contact server..

[ System Events ]
Error - 2/16/2012 9:35:10 AM | Computer Name = Jeff-PC | Source = DCOM | ID = 10005
Description =

Error - 2/16/2012 9:35:15 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Provider
Host service which failed to start because of the following error: %%1068

Error - 2/16/2012 9:35:18 AM | Computer Name = Jeff-PC | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 2/16/2012 9:36:49 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7001
Description = The PnP-X IP Bus Enumerator service depends on the Function Discovery
Provider Host service which failed to start because of the following error: %%1068

Error - 2/16/2012 9:40:56 AM | Computer Name = Jeff-PC | Source = DCOM | ID = 10005
Description =

Error - 2/16/2012 9:40:56 AM | Computer Name = Jeff-PC | Source = DCOM | ID = 10005
Description =

Error - 2/16/2012 9:45:36 AM | Computer Name = Jeff-PC | Source = DCOM | ID = 10005
Description =

Error - 2/16/2012 9:51:59 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7031
Description = The Extensible Authentication Protocol service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
120000 milliseconds: Restart the service.

Error - 2/16/2012 9:51:59 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7031
Description = The User Profile Service service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 120000 milliseconds:
Restart the service.

Error - 2/16/2012 9:51:59 AM | Computer Name = Jeff-PC | Source = Service Control Manager | ID = 7031
Description = The Windows Management Instrumentation service terminated unexpectedly.
It has done this 1 time(s). The following corrective action will be taken in
120000 milliseconds: Restart the service.


< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • Please subscribe to this topic, if you haven't already.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK

Download CKScanner by askey127 from Here & save it to your Desktop.
  • Right-click and Run as Administrator CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
———-

Download Combofix from either of the links below, and save it to your desktop.
Link 1
Link 2

**Note: It is important that it is saved directly to your desktop**

——————————————————————–

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

——————————————————————–

Right-Click and Run as Administrator on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI