This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Very Slow Laptop, Constantly Freezes [Closed]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently my laptop has begun to freeze during normal web browsing or running programs, Whenever i attempt to reboot the pc or turn it on it can take 4-5 attempts and 2 hours pass before it starts up correctly and loads. This began to occur about 2 weeks out of the blue. Here is my OTL.Text Log:

OTL logfile created on: 5/19/2012 5:10:39 AM - Run 1
OTL by OldTimer - Version 3.2.43.0 Folder = C:\Users\RJ\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.58 Gb Available Physical Memory | 57.57% Memory free
5.74 Gb Paging File | 4.57 Gb Available in Paging File | 79.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.39 Gb Total Space | 24.37 Gb Free Space | 10.91% Space Free | Partition Type: NTFS
Drive D: | 9.49 Gb Total Space | 1.70 Gb Free Space | 17.88% Space Free | Partition Type: NTFS
Drive E: | 505.37 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: RJS-PC | User Name: RJ | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\RJ\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
PRC - C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
PRC - C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\WTablet\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\SMINST\BLService.exe ()
PRC - C:\Program Files\DigitalPersona\Bin\DpAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
PRC - C:\Windows\System32\lxdxcoms.exe ( )
PRC - C:\Windows\System32\WacomTouchService.exe ()
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko11.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko12.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko10.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko6.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko9.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko8.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko7.dll ()
MOD - C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components\RadioWMPCoreGecko5.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\1ba19f8efcff8ad7f972aa38ab9a15f5\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\0a1195c6b5fab213527364c9e8b26ef0\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\cfb60f99da570cc494e27e0e8ee747e2\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\381fb23cb39e1a61e13b8770eb9800ba\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\f1aa2385c0109f3059e0e6ba8b58ff68\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\9dff86a62a525ec8dc827fe9f50298b7\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\0309936a8e1672d39b9cf14463ce69f9\mscorlib.ni.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabXpcom.dll ()
MOD - C:\Program Files\Orbitdownloader\addons\OneClickYouTubeDownloader\components\GrabKernel.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3009.39983__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Wizard\2.0.3009.40157__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.3009.40180__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3009.39941__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3009.39997__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3009.40172__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3009.40135__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3009.39975__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3009.40094__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3009.39962__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3009.40202__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3009.40208__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3009.39955__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3009.40143__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3009.40201__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3009.40149__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3009.40142__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3009.40200__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3009.40102__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3009.40163__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3009.40004__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3009.40116__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3009.40102__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.3009.40173__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Dashboard\2.0.3009.40136__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3009.40010__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3009.40095__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3009.39963__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3009.40129__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3009.40017__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3009.40094__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3009.40016__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3009.40101__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3009.40115__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3009.40128__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2939.23687__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2939.23679__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2939.23767__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2939.23710__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2939.23768__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2939.23668__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2939.23689__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2939.23743__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2939.23764__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2939.23662__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2939.23802__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2939.23763__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2939.23667__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerXpress.Graphics.Shared\2.0.2939.23762__90ba9c70f846762e\CLI.Aspect.PowerXpress.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2939.23717__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2939.23693__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2939.23687__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2939.23679__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2939.23707__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2939.23717__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2939.23718__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2939.23688__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2939.23734__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2939.23718__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2965.22300__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2939.23739__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2939.23740__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2939.23738__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2939.23742__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2939.23708__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MultiVPU4.Graphics.Shared\2.0.2939.23715__90ba9c70f846762e\CLI.Aspect.MultiVPU4.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2939.23735__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2939.23719__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2939.23741__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2939.23711__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2939.23665__90ba9c70f846762e\AEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2939.23719__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2939.23709__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2939.23687__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3009.40217__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3009.40228__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3009.39933__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3009.39969__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.3009.40186__90ba9c70f846762e\CLI.Component.Systemtray.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3009.40194__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3009.39933__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3009.40193__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2939.23713__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2939.23678__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2939.23679__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2939.23694__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2939.23712__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.2939.23677__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3009.39949__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.3009.39934__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2939.23689__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3009.40194__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2939.23711__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2939.23746__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3009.39931__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3009.39932__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()


========== Win32 Services (SafeList) ==========

SRV - (ExpressInvoiceService) – C:\Program Files\NCH Software\ExpressInvoice\expressinvoice.exe (NCH Software)
SRV - (IHA_MessageCenter) – C:\Program Files\Verizon\IHA_MessageCenter\Bin\Verizon_IHAMessageCenter.exe (Verizon)
SRV - (QBCFMonitorService) – C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe (Intuit)
SRV - (QBVSS) – C:\Program Files\Common Files\Intuit\DataProtect\QBIDPService.exe (Intuit Inc.)
SRV - (QBFCService) – C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe (Intuit Inc.)
SRV - (PSI_SVC_2) – c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (BrYNSvc) – C:\Program Files\Browny02\BrYNSvc.exe (Brother Industries, Ltd.)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (aswUpdSv) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (TabletServicePen) – C:\Windows\System32\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (Recovery Service for Windows) – C:\Windows\SMINST\BLService.exe ()
SRV - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV - (lxdx_device) – C:\Windows\System32\lxdxcoms.exe ( )
SRV - (lxdxCATSCustConnectService) – C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxdxserv.exe ()
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (WacomTouchService) – C:\Windows\System32\WacomTouchService.exe ()
SRV - (AdobeActiveFileMonitor6.0) – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()


========== Driver Services (SafeList) ==========

DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (a15pbh6n) – File not found
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (sptd) – C:\Windows\System32\drivers\sptd.sys ()
DRV - (msvad_simple) – C:\Windows\System32\drivers\povrtdev.sys (MediaMall Technologies, Inc.)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (GCCUSBD) – C:\Windows\System32\drivers\GCCUSD.sys (GCC)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek Corporation )
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (enecir) – C:\Windows\System32\drivers\enecir.sys (ENE TECHNOLOGY INC.)
DRV - (Wacomhidfilter) – C:\Windows\System32\drivers\wacomhidfilter.sys (Wacom Technology)
DRV - (wacomvhid) – C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (ATSWPDRV) AuthenTec TruePrint USB Driver (SwipeSensor) – C:\Windows\System32\drivers\atswpdrv.sys (AuthenTec, Inc.)
DRV - (HpqRemHid) – C:\Windows\System32\drivers\HpqRemHid.sys (Hewlett-Packard Development Company, L.P.)
DRV - (BVRPMPR5) – C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (HpqKbFiltr) – C:\Windows\System32\drivers\HpqKbFiltr.sys (Hewlett-Packard Development Company, L.P.)
DRV - (WacomVTHid) – C:\Windows\System32\drivers\WacomVTHid.sys (Wacom Technology)
DRV - (wacommousefilter) – C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (WacomVKHid) – C:\Windows\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (Hardlock) – C:\Windows\System32\drivers\hardlock.sys (Aladdin Knowledge Systems Ltd.)
DRV - (smserial) – C:\Windows\System32\drivers\smserial.sys (Motorola Inc.)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvm60x32.sys (NVIDIA Corporation)
DRV - (AtiPcie) ATI PCI Express (3GIO) – C:\Windows\System32\drivers\AtiPcie.sys (ATI Technologies Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {0AA7CBA3-1D01-48D3-A736-66BF76170ECD}
IE - HKLM\..\SearchScopes\{07EE76FD-F63A-42B0-B905-3C51D0BBBF96}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\..\SearchScopes\{0AA7CBA3-1D01-48D3-A736-66BF76170ECD}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvnb

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…ion&pf;=cnnb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {CF739809-1C6C-47C0-85B9-569DBB141420}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?FORM=I…q={searchTerms}
IE - HKCU\..\SearchScopes\{07EE76FD-F63A-42B0-B905-3C51D0BBBF96}: "URL" = http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\..\SearchScopes\{080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC}: "URL" = http://searchservice.myspace.com/index.cfm…amp;orig=IMC-IE
IE - HKCU\..\SearchScopes\{0AA7CBA3-1D01-48D3-A736-66BF76170ECD}: "URL" = http://search.yahoo.com/search?p={searchTe…&fr;=hp-pvnb
IE - HKCU\..\SearchScopes\{4F11ACBB-393F-4c86-A214-FF3D0D155CC3}: "URL" = http://search.burn4free-toolbar.com/search…rc=search-field
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" = http://toolbar.ask.com/toolbarv/askRedirec…erms}&crm;=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1.15 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2866295&SearchSource;=3&q;={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Elf 1.15 Customized Web Search"
FF - prefs.js..browser.startup.homepage: "http://search.conduit.com/?ctid=CT2866295&SearchSource;=13"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll File not found
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\RJ\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\RJ\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\RJ\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn2 [2008/04/30 01:51:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/13 17:00:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/05/13 17:00:33 | 000,000,000 | —D | M]

[2009/04/28 21:34:30 | 000,000,000 | —D | M] (No name found) – C:\Users\RJ\AppData\Roaming\Mozilla\Extensions
[2009/04/28 21:34:30 | 000,000,000 | —D | M] (No name found) – C:\Users\RJ\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/05/16 16:58:34 | 000,000,000 | —D | M] (No name found) – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions
[2009/09/03 07:17:10 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/30 15:40:39 | 000,000,000 | —D | M] (Elf 1.15 Community Toolbar) – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}
[2012/05/16 16:58:34 | 000,000,000 | —D | M] (Ant Video Downloader) – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\[removed]
[2009/02/14 08:50:59 | 000,000,000 | —D | M] ("Magic's Video - Downloader") – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\extensions\[removed]
[2009/03/15 23:31:02 | 000,000,682 | —- | M] () – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\searchplugins\ask.xml
[2011/03/21 16:08:28 | 000,000,919 | —- | M] () – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\searchplugins\conduit.xml
[2009/03/29 22:38:31 | 000,001,632 | —- | M] () – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\searchplugins\live-search.xml
[2008/12/12 11:23:54 | 000,002,158 | —- | M] () – C:\Users\RJ\AppData\Roaming\Mozilla\Firefox\Profiles\f7ieqmeg.default\searchplugins\MySpace.xml
[2011/04/06 18:03:11 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/05/26 17:37:13 | 000,000,000 | —D | M] (OneClick YouTube Downloader) – C:\PROGRAM FILES\ORBITDOWNLOADER\ADDONS\ONECLICKYOUTUBEDOWNLOADER
[2011/06/20 23:57:04 | 001,347,952 | —- | M] () (No name found) – C:\USERS\RJ\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\F7IEQMEG.DEFAULT\EXTENSIONS\[removed]
[2011/05/26 17:54:51 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2008/09/03 17:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\mozilla firefox\plugins\npbittorrent.dll
[2010/01/01 01:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Live Search (Enabled)
CHR - default_search_provider: search_url = http://search.live.com/results.aspx?FORM=I…q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\RJ\AppData\Local\Google\Chrome\Application\17.0.963.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\RJ\AppData\Local\Google\Chrome\Application\17.0.963.83\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\RJ\AppData\Local\Google\Chrome\Application\17.0.963.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: BitTorrent (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Google Update (Enabled) = C:\Users\RJ\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\RJ\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\RJ\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\

O1 HOSTS File: ([2012/01/15 00:19:58 | 000,000,722 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: – REMOVED –
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PimpFish Toolbar Opcode Handler) - {29C88E20-4234-41B9-A9DB-982958C95FB1} - C:\Program Files\PimpFish\PimpFish.dll (Zabersoft)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (PimpFish) - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll (Zabersoft)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (PimpFish) - {D593DE91-7B41-45C2-830E-E9A99AB142AA} - C:\Program Files\PimpFish\PimpFish.dll (Zabersoft)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [BrStsMon00] C:\Program Files\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail.com/mail/w3/resources/…NPUplden-us.cab (MSN Photo Upload Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: vzTCPConfig http://www2.verizon.net/help/fios_settings…vzTCPConfig.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{674CE540-27A7-4FEE-A8A6-702E5E0839F2}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\intu-help-qb5 {867FCB77-9823-4cd6-8210-D85F968D466F} - C:\Program Files\Intuit\QuickBooks 2012\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\qbwc {FC598A64-626C-4447-85B8-53150405FD57} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\RJ\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\RJ\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/30 01:18:05 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{0eec6cfc-5672-11de-8e25-00238b2ef4e0}\Shell\AutoRun\command - "" = H:\t.com
O33 - MountPoints2\{0eec6cfc-5672-11de-8e25-00238b2ef4e0}\Shell\explore\Command - "" = H:\t.com
O33 - MountPoints2\{0eec6cfc-5672-11de-8e25-00238b2ef4e0}\Shell\open\Command - "" = H:\t.com
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: aux - wdmaud.drv (Microsoft Corporation)
Drivers32: midi - wdmaud.drv (Microsoft Corporation)
Drivers32: midimapper - midimap.dll (Microsoft Corporation)
Drivers32: mixer - wdmaud.drv (Microsoft Corporation)
Drivers32: msacm.imaadpcm - imaadp32.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.msadpcm - msadp32.acm (Microsoft Corporation)
Drivers32: msacm.msg711 - msg711.acm (Microsoft Corporation)
Drivers32: msacm.msgsm610 - msgsm32.acm (Microsoft Corporation)
Drivers32: MSVideo8 - VfWWDM32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - DivX.dll (DivX, Inc.)
Drivers32: vidc.i420 - iyuv_32.dll (Microsoft Corporation)
Drivers32: VIDC.IV41 - IR41_32.AX (Intel Corporation)
Drivers32: VIDC.IYUV - iyuv_32.dll (Microsoft Corporation)
Drivers32: vidc.mrle - msrle32.dll (Microsoft Corporation)
Drivers32: vidc.msvc - msvidc32.dll (Microsoft Corporation)
Drivers32: VIDC.UYVY - msyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YUY2 - msyuv.dll (Microsoft Corporation)
Drivers32: vidc.yv12 - DivX.dll (DivX, Inc.)
Drivers32: VIDC.YVU9 - tsbyuv.dll (Microsoft Corporation)
Drivers32: VIDC.YVYU - msyuv.dll (Microsoft Corporation)
Drivers32: wave - wdmaud.drv (Microsoft Corporation)
Drivers32: wave1 - wdmaud.drv (Microsoft Corporation)
Drivers32: wavemapper - msacm32.drv (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/05/19 03:24:03 | 000,000,000 | -HSD | C] – C:\found.005
[2012/05/18 23:57:13 | 000,000,000 | -HSD | C] – C:\found.004
[2012/05/15 19:34:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/05/15 19:34:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Business Related Programs
[2012/05/15 19:34:09 | 000,000,000 | —D | C] – C:\Program Files\NCH Software
[2012/05/15 19:34:07 | 000,000,000 | —D | C] – C:\ProgramData\NCH Software
[2012/05/15 19:32:16 | 000,000,000 | —D | C] – C:\Users\RJ\Desktop\XinInvoice3.0Setup
[2012/05/15 18:05:35 | 000,000,000 | —D | C] – C:\Users\RJ\AppData\Local\Intuit
[2012/05/15 17:57:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickBooks
[2012/05/15 17:52:16 | 000,000,000 | —D | C] – C:\ProgramData\Nuance
[2012/05/15 17:52:15 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Intuit
[2012/05/15 17:52:14 | 000,000,000 | —D | C] – C:\Program Files\Intuit
[2012/05/15 17:50:22 | 000,000,000 | —D | C] – C:\ProgramData\SQL Anywhere 11
[2012/05/15 17:50:21 | 000,000,000 | —D | C] – C:\ProgramData\COMMON FILES
[2012/05/15 17:36:59 | 000,000,000 | —D | C] – C:\Windows\Intuit
[2012/05/15 16:46:28 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\Invoice Expert Backups
[2012/05/15 16:45:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Invoice Expert
[2012/05/15 16:45:33 | 000,000,000 | —D | C] – C:\ProgramData\Invoice Expert
[2012/05/15 16:45:21 | 000,000,000 | —D | C] – C:\Program Files\Invoice Expert
[2012/05/15 16:31:53 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\Quicken
[2012/05/15 16:13:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\AnswerWorks 5.0
[2012/05/15 16:13:09 | 004,200,024 | —- | C] (Amyuni Technologies
http://www.amyuni.com) – C:\Windows\System32\cdintf400.dll
[2012/05/15 16:12:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quicken 2012
[2012/05/15 16:12:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Intuit
[2012/05/15 16:11:31 | 000,000,000 | —D | C] – C:\Program Files\Quicken
[2012/05/15 16:11:31 | 000,000,000 | —D | C] – C:\Users\RJ\AppData\Roaming\Intuit
[2012/05/15 16:10:44 | 000,000,000 | —D | C] – C:\ProgramData\Intuit
[2012/05/13 18:20:01 | 000,000,000 | -HSD | C] – C:\found.003
[2012/05/13 12:20:18 | 000,000,000 | —D | C] – C:\Users\RJ\Desktop\YourKreationLogos
[2012/05/09 17:49:13 | 000,000,000 | -HSD | C] – C:\found.002
[2012/05/06 13:56:23 | 000,000,000 | —D | C] – C:\Users\RJ\Desktop\CS5 Complete
[2012/05/03 22:27:44 | 000,000,000 | —D | C] – C:\AdvancedTshirts
[2012/05/03 22:10:01 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\My Palettes
[2012/05/03 21:58:06 | 000,000,000 | —D | C] – C:\Users\RJ\AppData\Roaming\Corel
[2012/05/03 21:58:04 | 000,000,000 | —D | C] – C:\ProgramData\Protexis
[2012/05/03 21:49:06 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\Corel
[2012/05/03 21:47:41 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\Visual Studio 2008
[2012/05/03 21:47:16 | 000,000,000 | —D | C] – C:\Users\RJ\AppData\Local\Microsoft Help
[2012/05/03 21:37:50 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SDKs
[2012/05/03 21:37:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Visual Studio 9.0
[2012/05/03 21:33:05 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Corel
[2012/05/03 21:31:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Protexis
[2012/05/03 21:30:27 | 000,000,000 | —D | C] – C:\ProgramData\Corel
[2012/05/03 21:20:59 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Corel
[2012/05/03 21:17:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X6
[2012/05/03 21:16:49 | 000,000,000 | —D | C] – C:\Program Files\Corel
[2012/05/03 21:13:59 | 000,000,000 | —D | C] – C:\ProgramData\CorelDRAW Graphics Suite X6
[2012/04/29 12:02:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2012/04/29 12:01:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DivX Shared
[2012/04/29 12:00:06 | 000,000,000 | —D | C] – C:\ProgramData\DivX
[2012/04/28 20:03:27 | 000,000,000 | —D | C] – C:\Users\RJ\Documents\YourKreation
[2012/01/07 17:58:12 | 000,270,336 | —- | C] (Microsoft Corporation) – C:\Users\RJ\AppData\Local\xbv.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/05/19 04:08:15 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2012/05/19 04:03:17 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/19 04:03:17 | 000,003,216 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/19 03:58:49 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/05/19 03:58:05 | 2949,812,224 | -HS- | M] () – C:\hiberfil.sys
[2012/05/19 03:44:36 | 200,308,904 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/05/16 18:07:04 | 000,003,954 | —- | M] () – C:\Users\RJ\Desktop\33cxg5s.jpg
[2012/05/16 17:47:21 | 000,102,324 | —- | M] () – C:\Users\RJ\Desktop\3271293517_60d17a4f2c_z.jpg
[2012/05/16 17:26:21 | 000,076,127 | —- | M] () – C:\Users\RJ\Desktop\1046987-Cartoon-Cheese-Head-Sports-Fan-Poster-Art-Print.jpg
[2012/05/16 17:19:03 | 000,032,610 | —- | M] () – C:\Users\RJ\Desktop\Disney-Cartoon-Goofy-Wallpapers31.jpg
[2012/05/16 17:16:03 | 000,029,726 | —- | M] () – C:\Users\RJ\Desktop\Cheesehead_Mickey.jpg
[2012/05/16 16:37:24 | 003,798,072 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/05/15 19:34:11 | 000,000,947 | —- | M] () – C:\Users\Public\Desktop\Express Invoice.lnk
[2012/05/15 17:58:40 | 000,000,095 | —- | M] () – C:\Windows\QBChanUtil_Trigger.ini
[2012/05/15 17:57:50 | 000,002,251 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/05/15 17:57:50 | 000,002,054 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk
[2012/05/15 17:57:50 | 000,001,936 | —- | M] () – C:\Users\Public\Desktop\QuickBooks Pro 2012.lnk
[2012/05/15 17:57:50 | 000,001,867 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
[2012/05/15 17:47:03 | 000,640,142 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/05/15 17:47:03 | 000,118,362 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/05/15 17:33:05 | 000,000,504 | —- | M] () – C:\Users\RJ\AppData\Roaming\wklnhst.dat
[2012/05/15 16:45:35 | 000,000,831 | —- | M] () – C:\Users\RJ\Desktop\Invoice Expert XE.lnk
[2012/05/15 16:13:08 | 000,001,575 | —- | M] () – C:\Users\Public\Desktop\Quicken Deluxe 2012.lnk
[2012/05/15 16:13:07 | 000,000,353 | —- | M] () – C:\Users\Public\Desktop\Free Credit Report and Score.url
[2012/05/15 16:12:50 | 000,000,120 | —- | M] () – C:\Windows\QUICKEN.INI
[2012/05/15 16:00:26 | 000,000,370 | —- | M] () – C:\Windows\tasks\At1.job
[2012/05/13 22:53:53 | 000,542,855 | —- | M] () – C:\Users\RJ\Desktop\whitesockshellokitty.jpg
[2012/05/13 17:50:30 | 000,153,088 | —- | M] () – C:\Users\RJ\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/05/13 16:39:26 | 000,166,337 | —- | M] () – C:\Users\RJ\Documents\made in the 80's.ai
[2012/05/13 16:37:10 | 000,686,756 | —- | M] () – C:\Users\RJ\Desktop\MADEINTHE80'S.jpg
[2012/05/13 12:18:42 | 203,125,840 | —- | M] () – C:\Users\RJ\yourkreationfaded2.psd
[2012/05/12 22:08:22 | 002,346,205 | —- | M] () – C:\Users\RJ\Desktop\dotted_cracked_concrete_9290255.JPG
[2012/05/12 18:33:46 | 000,027,030 | —- | M] () – C:\Users\RJ\Desktop\white-sox-logo-2.png
[2012/05/12 18:33:25 | 000,060,040 | —- | M] () – C:\Users\RJ\Desktop\03_Chicago_White_Sox_baseball_coloring_at-coloring-pages-book-for-kids-boys.gif
[2012/05/12 16:12:00 | 000,022,817 | —- | M] () – C:\Users\RJ\Desktop\wdw_football_game_121905.jpg
[2012/05/09 20:05:22 | 000,178,274 | —- | M] () – C:\Users\RJ\Desktop\306-Youth-Ministry-T-Shirt.png
[2012/05/08 17:12:38 | 000,056,415 | —- | M] () – C:\Users\RJ\Desktop\ABUMTHING12K1.jpg
[2012/05/08 17:07:09 | 000,691,430 | —- | M] () – C:\Users\RJ\Desktop\thing12.jpg
[2012/05/08 15:50:14 | 000,704,478 | —- | M] () – C:\Users\RJ\Desktop\thing1.jpg
[2012/05/08 15:36:35 | 000,053,817 | —- | M] () – C:\Users\RJ\Desktop\thing1_and_thing2.gif
[2012/05/08 01:11:26 | 000,000,866 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/24 19:08:34 | 002,101,326 | —- | M] () – C:\Users\RJ\Desktop\Priceguide.eps
[2012/04/19 12:55:25 | 000,007,620 | —- | M] () – C:\Users\RJ\AppData\Local\d3d9caps.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/05/16 18:07:04 | 000,003,954 | —- | C] () – C:\Users\RJ\Desktop\33cxg5s.jpg
[2012/05/16 17:47:20 | 000,102,324 | —- | C] () – C:\Users\RJ\Desktop\3271293517_60d17a4f2c_z.jpg
[2012/05/16 17:26:19 | 000,076,127 | —- | C] () – C:\Users\RJ\Desktop\1046987-Cartoon-Cheese-Head-Sports-Fan-Poster-Art-Print.jpg
[2012/05/16 17:19:02 | 000,032,610 | —- | C] () – C:\Users\RJ\Desktop\Disney-Cartoon-Goofy-Wallpapers31.jpg
[2012/05/16 17:16:01 | 000,029,726 | —- | C] () – C:\Users\RJ\Desktop\Cheesehead_Mickey.jpg
[2012/05/15 19:34:11 | 000,000,959 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Invoice.lnk
[2012/05/15 19:34:11 | 000,000,947 | —- | C] () – C:\Users\Public\Desktop\Express Invoice.lnk
[2012/05/15 17:57:50 | 000,002,251 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
[2012/05/15 17:57:50 | 000,002,054 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk
[2012/05/15 17:57:50 | 000,001,936 | —- | C] () – C:\Users\Public\Desktop\QuickBooks Pro 2012.lnk
[2012/05/15 17:57:50 | 000,001,867 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk
[2012/05/15 17:50:23 | 000,000,095 | —- | C] () – C:\Windows\QBChanUtil_Trigger.ini
[2012/05/15 16:45:35 | 000,000,831 | —- | C] () – C:\Users\RJ\Desktop\Invoice Expert XE.lnk
[2012/05/15 16:13:07 | 000,001,575 | —- | C] () – C:\Users\Public\Desktop\Quicken Deluxe 2012.lnk
[2012/05/15 16:13:07 | 000,000,353 | —- | C] () – C:\Users\Public\Desktop\Free Credit Report and Score.url
[2012/05/15 16:11:17 | 000,000,120 | —- | C] () – C:\Windows\QUICKEN.INI
[2012/05/13 22:53:51 | 000,542,855 | —- | C] () – C:\Users\RJ\Desktop\whitesockshellokitty.jpg
[2012/05/13 16:39:13 | 000,166,337 | —- | C] () – C:\Users\RJ\Documents\made in the 80's.ai
[2012/05/13 16:37:08 | 000,686,756 | —- | C] () – C:\Users\RJ\Desktop\MADEINTHE80'S.jpg
[2012/05/13 12:17:11 | 203,125,840 | —- | C] () – C:\Users\RJ\yourkreationfaded2.psd
[2012/05/12 22:08:10 | 002,346,205 | —- | C] () – C:\Users\RJ\Desktop\dotted_cracked_concrete_9290255.JPG
[2012/05/12 18:33:44 | 000,027,030 | —- | C] () – C:\Users\RJ\Desktop\white-sox-logo-2.png
[2012/05/12 18:33:23 | 000,060,040 | —- | C] () – C:\Users\RJ\Desktop\03_Chicago_White_Sox_baseball_coloring_at-coloring-pages-book-for-kids-boys.gif
[2012/05/12 16:03:34 | 000,022,817 | —- | C] () – C:\Users\RJ\Desktop\wdw_football_game_121905.jpg
[2012/05/10 19:40:14 | 018,316,494 | —- | C] () – C:\Users\RJ\Desktop\grungesset20.eps
[2012/05/09 20:05:21 | 000,178,274 | —- | C] () – C:\Users\RJ\Desktop\306-Youth-Ministry-T-Shirt.png
[2012/05/08 17:12:36 | 000,056,415 | —- | C] () – C:\Users\RJ\Desktop\ABUMTHING12K1.jpg
[2012/05/08 17:07:07 | 000,691,430 | —- | C] () – C:\Users\RJ\Desktop\thing12.jpg
[2012/05/08 15:50:12 | 000,704,478 | —- | C] () – C:\Users\RJ\Desktop\thing1.jpg
[2012/05/08 15:36:31 | 000,053,817 | —- | C] () – C:\Users\RJ\Desktop\thing1_and_thing2.gif
[2012/05/08 01:11:26 | 000,000,866 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/04/24 19:08:22 | 002,101,326 | —- | C] () – C:\Users\RJ\Desktop\Priceguide.eps
[2012/02/23 21:17:09 | 000,028,672 | —- | C] () – C:\Windows\System32\uninstallMn.exe
[2012/02/23 21:17:07 | 000,024,576 | —- | C] () – C:\Windows\System32\usbapi.dll
[2012/02/23 19:08:37 | 000,028,672 | —- | C] () – C:\Windows\System32\hlduinst.exe
[2012/02/23 19:08:35 | 000,153,088 | —- | C] () – C:\Windows\System32\UNWISE.EXE
[2012/02/23 18:50:14 | 000,000,879 | —- | C] () – C:\Windows\System32\GC3LNG.INI
[2012/01/07 17:58:13 | 000,009,540 | -HS- | C] () – C:\Users\RJ\AppData\Local\84slry06q467xi6bh5spm50h0u6a86278krr3334f8la12
[2012/01/07 17:58:13 | 000,009,540 | -HS- | C] () – C:\ProgramData\84slry06q467xi6bh5spm50h0u6a86278krr3334f8la12
[2011/03/07 20:24:19 | 000,129,024 | —- | C] () – C:\Windows\System32\AVERM.dll
[2010/11/14 15:00:29 | 000,000,141 | —- | C] () – C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc

========== LOP Check ==========

[2009/05/27 17:44:26 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Atari
[2011/09/03 23:29:17 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Audacity
[2012/05/13 16:47:43 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\BitTorrent
[2010/04/23 17:36:43 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\DAEMON Tools Pro
[2009/02/12 21:07:00 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\DigitalPersona
[2012/02/23 19:10:19 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\EUROSYSTEMS
[2010/03/10 00:21:34 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Facebook
[2009/08/22 13:17:31 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\FrostWire
[2010/04/18 14:40:53 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\GrabPro
[2012/01/14 20:36:27 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Guitar Pro 6
[2009/09/23 22:29:41 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\HandBrake
[2009/10/12 21:55:29 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Image Zone Express
[2009/05/27 17:42:45 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Leadertech
[2009/05/30 13:32:44 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\LimeWire
[2010/03/31 21:37:18 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Listing Factory 2009
[2009/05/05 23:02:05 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\MPEG Streamclip
[2009/10/17 19:28:34 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\MRTalk
[2009/11/30 01:13:48 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Opera
[2012/05/16 21:03:37 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Orbit
[2009/10/12 21:55:29 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Printer Info Cache
[2011/05/26 17:37:37 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\ProgSense
[2011/11/02 20:31:51 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\REAPER
[2012/02/24 17:23:52 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\TeamViewer
[2011/05/26 12:54:10 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\TechWizard
[2009/11/11 23:51:47 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Template
[2009/12/09 23:28:20 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\uTorrent
[2010/01/27 16:18:43 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Vso
[2011/12/22 18:09:17 | 000,000,000 | —D | M] – C:\Users\RJ\AppData\Roaming\Zabersoft
[2012/05/15 16:00:26 | 000,000,370 | —- | M] () – C:\Windows\Tasks\At1.job
[2012/05/19 04:14:31 | 000,032,544 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/04/24 19:48:47 | 000,000,000 | —- | M] () – C:\AILog.txt
[2008/04/30 01:18:05 | 000,000,074 | —- | M] () – C:\autoexec.bat
[2008/01/20 19:24:42 | 000,333,203 | RHS- | M] () – C:\bootmgr
[2006/09/18 14:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2008/04/11 11:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 11:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 11:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 11:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 11:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 11:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 11:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 11:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 11:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 11:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2009/03/15 21:18:58 | 000,000,115 | —- | M] () – C:\FtpCmd.txt
[2008/04/11 11:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/05/19 03:58:05 | 2949,812,224 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 09:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 11:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2012/02/26 14:08:22 | 000,064,229 | —- | M] () – C:\INSTALL.LOG
[2008/04/11 09:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 09:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 09:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 09:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 09:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 09:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 09:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 11:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 09:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 09:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2010/12/04 23:26:23 | 000,000,738 | -H– | M] () – C:\IPH.PH
[2008/09/03 17:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\npbittorrent.dll
[2012/01/08 00:53:00 | 000,000,929 | —- | M] () – C:\nuke-M.log
[2012/05/19 03:58:03 | 3263,598,592 | -HS- | M] () – C:\pagefile.sys
[2012/01/08 00:56:03 | 000,000,405 | —- | M] () – C:\rkill.log
[2008/04/11 11:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 11:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 11:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2006/11/02 05:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 05:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 05:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2006/11/02 05:37:12 | 000,030,808 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2006/09/18 14:37:34 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/01/20 19:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 05:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2008/02/27 17:15:28 | 000,115,200 | —- | M] () – C:\Windows\system32\spool\prtprocs\w32x86\lxdxdrpp.dll
[2006/10/26 19:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2009/02/06 19:03:18 | 000,307,576 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2008/01/20 19:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
[2012/02/26 14:08:36 | 000,050,467 | —- | M] () – C:\Program Files\INSTALL.LOG

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2008/01/20 20:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 20:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 20:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 03:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 03:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/04/30 22:23:53 | 000,076,825 | —- | M] () – C:\Users\RJ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\batfuzz-3[1].jpg
[2009/02/13 00:31:04 | 000,000,286 | -HS- | M] () – C:\Users\RJ\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/08/31 19:38:18 | 000,711,680 | —- | M] (GCC) – C:\Users\RJ\Desktop\VLCD3.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-05-07 10:04:24

========== Alternate Data Streams ==========

@Alternate Data Stream - 158 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:010ADD2C

< End of report >
Hi and Welcome!! :) My name is Jeff. I would be more than happy to take a look at your malware results logs and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

IMPORTANT NOTE : Please do not delete anything unless instructed to.
DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.
Doing so could make your system inoperable and could require a full reinstall of your OS losing all your programs and data.


Vista and Windows 7 users:
These tools MUST be run from the executable (.exe) every time you run them
with Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

First we need to make all files and folders VISIBLE:

  • Go to start>control panel>folder options>view
  • Choose to "show hidden files and folders,"
  • Uncheck the "hide protected operating system files" and the "hide extensions for know file types" boxes.
  • Close the window with OK
———

Please download aswMBR to your desktop.

  • Right click and Run as Administrator the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-
yes i still need assistance, im sorry for the delay i was away on business. I will run the program and post the results in the morning. Thank You!
I tried running the program a number of times all day and my computer keeps rebooting midway thorugh stating an unexpected error occured. When its running though it does show an infection was found
Hi,

Try to run aswMBR in Safe Mode. If it runs through post that log that is made. If it just will not complete the scan please do the following:

Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • when the window opens, click on Change Parameters
  • under ”Additional options”, put a check mark in the box next to “Detect TDLFS File System”
  • click OK
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
    • Then click Continue > Reboot now
  • Attach the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)
———-

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI