here is the resulting log:
OTL logfile created on: 9/23/2012 6:03:54 PM - Run 2
OTL by OldTimer - Version 3.2.64.0 Folder = C:\Users\cwestmas2011\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.98 Gb Total Physical Memory | 6.38 Gb Available Physical Memory | 79.90% Memory free
15.96 Gb Paging File | 13.05 Gb Available in Paging File | 81.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 918.22 Gb Total Space | 852.49 Gb Free Space | 92.84% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Computer Name: CWESTMAS2011-PC | User Name: cwestmas2011 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/20 22:08:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
PRC - [2012/09/18 07:54:35 | 000,690,888 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_265_ActiveX.exe
PRC - [2012/09/07 17:04:46 | 000,676,936 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/09/07 17:04:46 | 000,399,432 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/09/07 17:04:44 | 000,766,536 | —- | M] (Malwarebytes Corporation) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/08/02 16:06:28 | 000,173,056 | —- | M] (Dell Products, LP.) – C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
PRC - [2012/07/27 13:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/06/11 16:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE
PRC - [2012/04/30 15:15:14 | 007,968,008 | —- | M] (AVM Software Inc.) – C:\Program Files (x86)\Paltalk Messenger\paltalk.exe
PRC - [2012/02/01 11:50:58 | 000,968,048 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
PRC - [2011/11/25 16:32:36 | 000,687,400 | —- | M] (Nero AG) – C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011/09/06 11:29:20 | 004,259,648 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
PRC - [2011/08/18 09:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
PRC - [2011/08/18 09:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2011/08/17 12:29:52 | 000,480,880 | —- | M] () – C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
PRC - [2011/08/01 11:56:48 | 000,460,096 | —- | M] (SoftThinks - Dell) – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
PRC - [2010/11/17 09:35:40 | 001,440,240 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
PRC - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
PRC - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/13 17:32:30 | 000,283,160 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/03/10 15:26:30 | 000,237,568 | —- | M] (Alcor Micro Corp.) – C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe
PRC - [2009/03/30 16:00:54 | 000,221,184 | —- | M] (Brother Industries, Ltd.) – C:\Program Files (x86)\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/14 03:30:26 | 000,475,136 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\09557e6c5a83a1cb68c7c50a841c8064\IAStorUtil.ni.dll
MOD - [2012/06/14 03:26:39 | 014,340,608 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\e717a230496832656b05b515eb9f3bc5\PresentationFramework.ni.dll
MOD - [2012/06/14 03:26:28 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:26:24 | 001,591,808 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/06/14 03:26:18 | 012,237,824 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\14a87218ea49639f38097e278b98a3da\PresentationCore.ni.dll
MOD - [2012/05/10 10:36:25 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\220b0516e45e7f9bbf6a631490c1243a\IAStorCommon.ni.dll
MOD - [2012/05/10 10:36:11 | 002,297,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\dfd33f59a5803a3c73cf408362e6e0b7\System.Core.ni.dll
MOD - [2012/05/10 07:52:14 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\8e56489276063ededde74e597a121df3\PresentationFramework.Aero.ni.dll
MOD - [2012/05/10 07:52:05 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 07:51:23 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/10 07:51:20 | 005,452,800 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/10 07:51:18 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/10 07:51:17 | 007,967,232 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/10 07:51:12 | 011,492,864 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/04/30 15:15:21 | 001,837,808 | —- | M] () – C:\Program Files (x86)\Paltalk Messenger\Images.dll
MOD - [2012/04/30 15:15:18 | 000,048,368 | —- | M] () – C:\Program Files (x86)\Paltalk Messenger\ctrlkey.dll
MOD - [2012/02/01 11:50:58 | 000,968,048 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
MOD - [2012/02/01 11:44:34 | 008,151,040 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtGui4.dll
MOD - [2012/02/01 11:44:34 | 002,278,400 | —- | M] () – C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\QtCore4.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/18 09:05:54 | 002,751,808 | —- | M] () – C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
MOD - [2011/08/17 12:29:52 | 000,480,880 | —- | M] () – C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe
MOD - [2010/11/24 21:44:02 | 000,375,280 | —- | M] () – c:\Program Files (x86)\Common Files\Roxio Shared\DLLShared\SQLite352.dll
MOD - [2010/11/17 09:35:40 | 001,440,240 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\Roxio Burn.exe
MOD - [2010/11/17 09:35:34 | 000,514,544 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
MOD - [2010/11/17 09:35:28 | 000,657,904 | —- | M] () – C:\Program Files (x86)\Roxio\OEM\Roxio Burn\BBEngineAS.dll
MOD - [2009/02/27 17:38:20 | 000,139,264 | R— | M] () – C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2012/08/24 23:46:28 | 000,383,608 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files\mcafee\virusscan\mcods.exe – (McODS)
SRV:
64bit: - [2012/06/22 07:38:04 | 000,177,144 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Windows\SysNative\mfevtps.exe – (mfevtp)
SRV:
64bit: - [2012/06/22 07:34:52 | 000,218,320 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe – (mfefire)
SRV:
64bit: - [2012/06/22 07:33:12 | 000,237,920 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe – (McShield)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (MSK80Service)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McProxy)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Disabled | Stopped] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McOobeSv)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McNASvc)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (McNaiAnn)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe – (mcmscsvc)
SRV:
64bit: - [2012/05/11 06:31:46 | 000,200,728 | —- | M] (McAfee, Inc.) [Auto | Running] – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe – (McMPFSvc)
SRV:
64bit: - [2011/06/21 19:57:42 | 000,341,296 | —- | M] (Nitro PDF Software) [Auto | Running] – C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe – (NitroReaderDriverReadSpool2)
SRV:
64bit: - [2011/03/08 16:00:50 | 000,224,704 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – c:\Program Files\mcafee\msc\McAWFwk.exe – (McAWFwk)
SRV:
64bit: - [2010/09/22 17:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:
64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/09/21 23:15:41 | 000,250,288 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/10 11:38:18 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/09/07 17:04:46 | 000,676,936 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe – (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | —- | M] (Malwarebytes Corporation) [Auto | Running] – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe – (MBAMScheduler)
SRV - [2012/08/02 16:06:28 | 000,173,056 | —- | M] (Dell Products, LP.) [Auto | Running] – C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe – (DellDigitalDelivery)
SRV - [2012/07/27 13:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/17 12:18:00 | 000,562,688 | —- | M] () [Auto | Stopped] – C:\Program Files (x86)\DefaultTab\DefaultTabSearch.exe – (DefaultTabSearch)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/06/11 16:22:16 | 000,240,208 | —- | M] (Microsoft Corporation.) [On_Demand | Running] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\SeaPort.EXE – (BBUpdate)
SRV - [2012/06/11 16:22:16 | 000,193,616 | —- | M] (Microsoft Corporation.) [Auto | Stopped] – C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BBSvc.EXE – (BBSvc)
SRV - [2011/11/25 16:32:36 | 000,687,400 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Nero\Update\NASvc.exe – (NAUpdate)
SRV - [2011/11/08 13:16:25 | 001,045,256 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2011/08/18 09:05:46 | 001,692,480 | —- | M] (SoftThinks SAS) [Auto | Running] – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe – (SftService)
SRV - [2010/11/25 04:34:18 | 000,219,632 | —- | M] (Sonic Solutions) [Auto | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatch12OEM.exe – (RoxWatch12)
SRV - [2010/11/25 04:33:18 | 001,116,656 | —- | M] (Sonic Solutions) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxMediaDB12OEM.exe – (RoxMediaDB12OEM)
SRV - [2010/09/13 17:32:32 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)
SRV - [2010/08/25 19:28:54 | 002,823,000 | —- | M] (Dell, Inc.) [Auto | Running] – C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe – (NOBU)
SRV - [2010/03/18 14:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 13:48:14 | 000,602,392 | —- | M] (Yahoo! Inc.) [Auto | Running] – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe – (YahooAUService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2012/09/15 08:25:48 | 000,095,392 | —- | M] (Symantec Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\SMR310.SYS – (SMR310)
DRV:
64bit: - [2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] – C:\Windows\SysNative\drivers\mbam.sys – (MBAMProtector)
DRV:
64bit: - [2012/08/21 13:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:
64bit: - [2012/06/22 07:40:58 | 000,069,672 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\cfwids.sys – (cfwids)
DRV:
64bit: - [2012/06/22 07:38:16 | 000,335,784 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfewfpk.sys – (mfewfpk)
DRV:
64bit: - [2012/06/22 07:36:54 | 000,106,112 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\mferkdet.sys – (mferkdet)
DRV:
64bit: - [2012/06/22 07:36:12 | 000,752,672 | —- | M] (McAfee, Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\mfehidk.sys – (mfehidk)
DRV:
64bit: - [2012/06/22 07:35:02 | 000,513,456 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfefirek.sys – (mfefirek)
DRV:
64bit: - [2012/06/22 07:34:22 | 000,300,392 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeavfk.sys – (mfeavfk)
DRV:
64bit: - [2012/06/22 07:34:00 | 000,169,320 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\mfeapfk.sys – (mfeapfk)
DRV:
64bit: - [2012/04/20 16:40:58 | 000,196,440 | —- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HipShieldK.sys – (HipShieldK)
DRV:
64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:
64bit: - [2011/11/08 14:49:54 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2011/11/08 14:49:54 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2011/07/19 12:35:00 | 000,015,360 | —- | M] (June Fabrics Technology Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\pneteth.sys – (pneteth)
DRV:
64bit: - [2010/11/20 20:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:
64bit: - [2010/11/20 20:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2010/11/20 20:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:
64bit: - [2010/11/11 10:10:50 | 000,155,752 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nvhda64v.sys – (NVHDA)
DRV:
64bit: - [2010/10/15 18:28:18 | 000,317,440 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:
64bit: - [2010/09/21 20:59:38 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (MEIx64)
DRV:
64bit: - [2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:
64bit: - [2010/06/08 05:36:18 | 000,406,056 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\k57nd60a.sys – (k57nd60a)
DRV:
64bit: - [2010/05/20 16:42:44 | 003,058,168 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:
64bit: - [2010/03/19 02:00:00 | 000,055,856 | —- | M] (Sonic Solutions) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:
64bit: - [2010/02/27 08:32:14 | 000,158,976 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:
64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/07/13 18:18:06 | 000,281,088 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BrSerIb.sys – (BrSerIb)
DRV:
64bit: - [2009/06/10 13:41:10 | 000,015,360 | —- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BrUsbSIb.sys – (BrUsbSIb)
DRV:
64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2006/11/01 11:51:00 | 000,151,656 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysNative\drivers\WimFltr.sys – (WimFltr)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE:
64bit: - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:
64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS
IE:
64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?PC=msnHomeST&OCID;=msnHomepage
IE - HKCU\..\SearchScopes,DefaultScope = {9CC0CE6A-33A7-F5FF-A61D-F0902379161B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?client=i…FF-E75EAECF2AF8
IE - HKCU\..\SearchScopes\{3D77D279-C46D-41A1-BD31-190D1666D714}: "URL" =
http://www.mysearchresults.com/search?&…q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{8F428628-7435-4175-A65D-27BA8813145A}: "URL" =
http://search.yahoo.com/search?p={searchte…37,17118,0,18,0
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" =
http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9CC0CE6A-33A7-F5FF-A61D-F0902379161B}: "URL" =
http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{CF739809-1C6C-47C0-85B9-569DBB141420}: "URL" =
http://toolbar.ask.com/toolbarv/askRedirec…amp;toolbar=FRW
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.msn.com"
FF - prefs.js..extensions.enabledAddons: {ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}:1.1
FF - prefs.js..extensions.enabledAddons: [removed]:1.0.0
FF - prefs.js..keyword.URL: "
http://dts.search-results.com/sr?src=ffb&appid;=169&systemid;=406&sr;=0&q;="
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.19: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 11:38:19 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK [2012/09/21 19:34:37 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/10 11:38:19 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/09/15 09:57:57 | 000,000,000 | —D | M] (No name found) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Extensions
[2012/09/23 21:11:25 | 000,000,000 | —D | M] (No name found) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions
[2012/09/15 09:49:58 | 000,000,000 | —D | M] (PinPhotoZoom - Eaisly zoom photos in Pinterest!) – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\extensions\{ebc3cfe3-606b-4470-98ae-4dd305d4c0b9}
[2012/09/20 20:29:59 | 000,001,982 | —- | M] () – C:\Users\cwestmas2011\AppData\Roaming\Mozilla\Firefox\Profiles\vc2rmakq.default\searchplugins\search-here.xml
[2012/07/01 14:32:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) – C:\USERS\CWESTMAS2011\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\VC2RMAKQ.DEFAULT\EXTENSIONS\[removed]
[2012/09/10 11:38:19 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/10 11:38:17 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/10 11:38:17 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Nitro PDF Plug-In (Enabled) = C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\cwestmas2011\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: RivalGaming = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\adhmhclafdhfabmmglbcngpddpdeijgd\
CHR - Extension: YouTube = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: DefaultTab = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdidombaedgpfiiedeimiebkmbilgmlc\1.1.8_0\
CHR - Extension: PinPhotoZoom plugin for chrome = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbdamgnimlipjnpgiakiojcbbmcmiibn\1.1_0\
CHR - Extension: Gmail = C:\Users\cwestmas2011\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/21 20:11:07 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (PinPhotoZoom) - {4a0c8953-9d4e-4790-b732-2b9fc9ebce05} - C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom\64\AutocompletePro64.dll (SimplyGen)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (PinPhotoZoom) - {4a0c8953-9d4e-4790-b732-2b9fc9ebce05} - C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom\AutocompletePro.dll (SimplyGen)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (DefaultTab Browser Helper) - {7F6AFBF1-E065-4627-A2FD-810366367D01} - C:\Users\cwestmas2011\AppData\Roaming\DefaultTab\DefaultTab\DefaultTabBHO.dll File not found
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.391.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:
64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroLauncher] C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe ()
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - Startup: C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk = C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files (x86)\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_27)
O16:
64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.5.1)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EE91BDD2-159C-4FBE-B47A-2393B104EA7A}: DhcpNameServer = [removed] [removed] [removed]
O18:
64bit: - Protocol\Handler\cozi - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:
64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/09/23 21:11:24 | 000,000,000 | —D | C] – C:\_OTL
[2012/09/23 19:33:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2012/09/23 03:00:41 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/09/23 03:00:41 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/09/23 03:00:41 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/09/23 03:00:41 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/09/23 03:00:41 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/09/23 03:00:41 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/09/23 03:00:41 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/09/23 03:00:41 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/09/23 03:00:41 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/09/23 03:00:41 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/09/23 03:00:40 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/09/23 03:00:40 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/09/23 03:00:40 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/09/23 03:00:40 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/09/23 03:00:39 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/09/23 00:37:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/09/22 23:00:26 | 000,448,512 | —- | C] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\TFC.exe
[2012/09/21 20:14:19 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/09/21 20:11:18 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/09/21 20:04:55 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/09/21 20:04:55 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/09/21 20:04:55 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/09/21 20:04:51 | 000,000,000 | —D | C] – C:\Qoobox
[2012/09/21 20:04:40 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/09/21 20:02:04 | 004,754,290 | R— | C] (Swearware) – C:\Users\cwestmas2011\Desktop\ComboFix.exe
[2012/09/21 20:01:35 | 000,940,544 | —- | C] (Apache Software Foundation) – C:\Users\cwestmas2011\AppData\Local\log4cxx.dll
[2012/09/21 19:33:12 | 000,196,440 | —- | C] (McAfee, Inc.) – C:\Windows\SysNative\drivers\HipShieldK.sys
[2012/09/20 22:26:17 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\cwestmas2011\Desktop\aswMBR.exe
[2012/09/20 22:08:13 | 000,600,064 | —- | C] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
[2012/09/20 21:20:55 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\cwestmas2011\Desktop\HiJackThis.exe
[2012/09/20 20:38:45 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/09/20 20:18:05 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PC Cleaners
[2012/09/20 20:17:32 | 004,584,312 | —- | C] (PC Cleaners) – C:\Windows\uninst.exe
[2012/09/20 20:17:31 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PCPro
[2012/09/20 20:17:31 | 000,000,000 | —D | C] – C:\ProgramData\PC1Data
[2012/09/19 23:25:27 | 000,008,704 | —- | C] (ScanSpyware.net) – C:\Windows\SysWow64\ssbtsr.exe
[2012/09/19 23:25:27 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\ScanSpyware
[2012/09/19 23:25:27 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ScanSpyware
[2012/09/19 23:25:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\ScanSpyware
[2012/09/19 20:42:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/09/19 20:42:41 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2012/09/18 12:09:54 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2012/09/18 09:59:44 | 000,000,000 | —D | C] – C:\Windows\SysNative\%LOCALAPPDATA%
[2012/09/18 09:05:32 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Local\CrashDumps
[2012/09/17 22:24:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/09/17 22:24:05 | 000,033,240 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/09/17 22:23:23 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/09/17 22:23:21 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/09/15 10:04:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeFileViewer
[2012/09/15 10:00:47 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Malwarebytes
[2012/09/15 10:00:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/15 10:00:38 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/09/15 10:00:37 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/15 10:00:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/15 09:57:56 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivalGaming
[2012/09/15 09:57:51 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Yahoo!
[2012/09/15 09:57:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2012/09/15 09:50:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\File Type Assistant
[2012/09/15 09:50:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\FreeFileViewer
[2012/09/15 09:50:03 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Shop to Win 17
[2012/09/15 09:50:02 | 000,000,000 | —D | C] – C:\ProgramData\Tarma Installer
[2012/09/15 09:49:57 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom
[2012/09/15 09:49:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\PinPhotoZoom
[2012/09/15 09:49:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\DefaultTab
[2012/09/15 09:49:51 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Roaming\DefaultTab
[2012/09/15 08:25:48 | 000,095,392 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR310.SYS
[2012/09/15 08:25:44 | 000,000,000 | —D | C] – C:\Users\cwestmas2011\AppData\Local\NPE
[2012/09/15 08:25:44 | 000,000,000 | —D | C] – C:\ProgramData\Norton
[2012/09/13 07:04:15 | 000,000,000 | R–D | C] – C:\Users\cwestmas2011\Desktop\MySyncUPFiles
[2012/09/12 02:37:49 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2012/09/12 02:37:49 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/12 02:37:48 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\RNDISMP.sys
[2012/09/12 02:37:47 | 000,574,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10level9.dll
[2012/09/11 21:00:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/09/11 21:00:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
========== Files - Modified Within 30 Days ==========
[2012/09/23 20:47:00 | 000,000,884 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/23 18:01:16 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/23 18:01:15 | 000,000,936 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job
[2012/09/23 18:01:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/09/23 00:39:30 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 00:39:30 | 000,021,296 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 00:36:56 | 000,778,834 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/23 00:36:56 | 000,660,068 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/09/23 00:36:56 | 000,120,996 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/09/23 00:32:10 | 2133,676,031 | -HS- | M] () – C:\hiberfil.sys
[2012/09/22 23:00:28 | 000,448,512 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\TFC.exe
[2012/09/21 23:15:41 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/09/21 23:15:41 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/21 20:44:29 | 000,458,240 | —- | M] () – C:\Users\cwestmas2011\Desktop\CKScanner.exe
[2012/09/21 20:11:07 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/09/21 20:02:21 | 004,754,290 | R— | M] (Swearware) – C:\Users\cwestmas2011\Desktop\ComboFix.exe
[2012/09/20 22:54:39 | 000,000,512 | —- | M] () – C:\Users\cwestmas2011\Desktop\MBR.dat
[2012/09/20 22:26:34 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\cwestmas2011\Desktop\aswMBR.exe
[2012/09/20 22:08:23 | 000,600,064 | —- | M] (OldTimer Tools) – C:\Users\cwestmas2011\Desktop\OTL.exe
[2012/09/20 21:21:01 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\cwestmas2011\Desktop\HiJackThis.exe
[2012/09/20 20:38:46 | 000,002,414 | —- | M] () – C:\Users\cwestmas2011\Desktop\Google Chrome.lnk
[2012/09/20 20:17:20 | 004,584,312 | —- | M] (PC Cleaners) – C:\Windows\uninst.exe
[2012/09/20 08:26:35 | 000,000,805 | —- | M] () – C:\Windows\ScanSpyware.INI
[2012/09/19 23:25:27 | 000,001,185 | —- | M] () – C:\Users\cwestmas2011\Desktop\Diagnose & Fix.lnk
[2012/09/19 23:25:27 | 000,001,171 | —- | M] () – C:\Users\cwestmas2011\Desktop\ScanSpyware.lnk
[2012/09/19 20:42:43 | 000,000,784 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 22:24:10 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/17 08:18:23 | 000,000,148 | —- | M] () – C:\Users\cwestmas2011\Desktop\Personal Credit Cards, First Bankcard, a division of First National Bank of Omaha (2).url
[2012/09/15 10:04:17 | 000,001,109 | —- | M] () – C:\Users\cwestmas2011\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/09/15 10:00:38 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 08:25:48 | 000,095,392 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\drivers\SMR310.SYS
[2012/09/14 14:53:22 | 000,000,097 | —- | M] () – C:\Windows\SysWow64\PDFWRITR.INI
[2012/09/14 14:53:22 | 000,000,097 | —- | M] () – C:\Windows\SysWow64\__PDF.INI
[2012/09/10 08:36:38 | 000,001,064 | —- | M] () – C:\Users\cwestmas2011\Desktop\trends - Shortcut.lnk
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/09/06 20:00:11 | 000,001,118 | —- | M] () – C:\Users\cwestmas2011\Desktop\Poker Income - Shortcut.lnk
[2012/09/06 20:00:01 | 000,001,145 | —- | M] () – C:\Users\cwestmas2011\Desktop\Gambling Income - Shortcut.lnk
[2012/09/04 09:54:42 | 000,000,221 | —- | M] () – C:\Users\cwestmas2011\Desktop\LenderX.url
[2012/08/29 15:14:23 | 000,000,126 | —- | M] () – C:\Windows\VSS.EService.INI
[2012/08/29 11:10:20 | 000,001,307 | —- | M] () – C:\Users\cwestmas2011\Desktop\CNLVZoningOrdinanceCombined - Shortcut.lnk
[2012/08/27 13:48:25 | 000,000,186 | —- | M] () – C:\Users\cwestmas2011\Desktop\The Appraisal Hub, LLC Home - Nationwide Real Estate Appraisal Management Company.url
========== Files Created - No Company Name ==========
[2012/09/21 20:44:01 | 000,458,240 | —- | C] () – C:\Users\cwestmas2011\Desktop\CKScanner.exe
[2012/09/21 20:04:55 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/09/21 20:04:55 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/09/21 20:04:55 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/09/21 20:04:55 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/09/21 20:04:55 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/09/20 22:54:39 | 000,000,512 | —- | C] () – C:\Users\cwestmas2011\Desktop\MBR.dat
[2012/09/20 20:38:46 | 000,002,414 | —- | C] () – C:\Users\cwestmas2011\Desktop\Google Chrome.lnk
[2012/09/20 20:37:05 | 000,000,936 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job
[2012/09/20 20:37:05 | 000,000,884 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/20 08:26:35 | 000,000,805 | —- | C] () – C:\Windows\ScanSpyware.INI
[2012/09/19 23:25:27 | 000,001,185 | —- | C] () – C:\Users\cwestmas2011\Desktop\Diagnose & Fix.lnk
[2012/09/19 23:25:27 | 000,001,171 | —- | C] () – C:\Users\cwestmas2011\Desktop\ScanSpyware.lnk
[2012/09/19 20:42:43 | 000,000,784 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/09/17 22:24:10 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/09/17 08:18:23 | 000,000,148 | —- | C] () – C:\Users\cwestmas2011\Desktop\Personal Credit Cards, First Bankcard, a division of First National Bank of Omaha (2).url
[2012/09/15 10:00:38 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/15 09:50:47 | 000,001,109 | —- | C] () – C:\Users\cwestmas2011\Application Data\Microsoft\Internet Explorer\Quick Launch\FreeFileViewer.lnk
[2012/09/10 08:36:38 | 000,001,064 | —- | C] () – C:\Users\cwestmas2011\Desktop\trends - Shortcut.lnk
[2012/09/06 20:00:11 | 000,001,118 | —- | C] () – C:\Users\cwestmas2011\Desktop\Poker Income - Shortcut.lnk
[2012/09/06 20:00:01 | 000,001,145 | —- | C] () – C:\Users\cwestmas2011\Desktop\Gambling Income - Shortcut.lnk
[2012/09/04 09:54:42 | 000,000,221 | —- | C] () – C:\Users\cwestmas2011\Desktop\LenderX.url
[2012/08/29 11:10:20 | 000,001,307 | —- | C] () – C:\Users\cwestmas2011\Desktop\CNLVZoningOrdinanceCombined - Shortcut.lnk
[2012/08/27 13:48:25 | 000,000,186 | —- | C] () – C:\Users\cwestmas2011\Desktop\The Appraisal Hub, LLC Home - Nationwide Real Estate Appraisal Management Company.url
[2011/11/22 16:24:28 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PDFWRITR.INI
[2011/11/22 16:24:28 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\__PDF.INI
[2011/11/19 07:25:53 | 000,000,126 | —- | C] () – C:\Windows\VSS.EService.INI
[2011/11/15 14:09:12 | 000,000,740 | —- | C] () – C:\Windows\Brpfx04a.ini
[2011/11/15 14:09:12 | 000,000,093 | —- | C] () – C:\Windows\brpcfx.ini
[2011/11/15 14:08:54 | 000,000,426 | —- | C] () – C:\Windows\BRWMARK.INI
[2011/11/15 14:06:51 | 000,106,496 | —- | C] () – C:\Windows\SysWow64\BrMuSNMP.dll
[2011/11/15 14:06:51 | 000,000,066 | —- | C] () – C:\Windows\Brfaxrx.ini
[2011/11/15 14:06:50 | 000,000,000 | —- | C] () – C:\Windows\brdfxspd.dat
[2011/11/15 14:06:32 | 000,045,056 | —- | C] () – C:\Windows\SysWow64\BRTCPCON.DLL
[2011/11/15 14:06:21 | 000,000,114 | —- | C] () – C:\Windows\SysWow64\BRLMW03A.INI
[2011/11/15 14:04:54 | 000,031,767 | —- | C] () – C:\Windows\maxlink.ini
[2011/11/11 22:57:48 | 000,430,080 | —- | C] ( ) – C:\Windows\SysWow64\LMUD1P32comc.dll
[2011/11/11 20:41:32 | 000,421,888 | —- | C] ( ) – C:\Windows\SysWow64\lexlog.dll
[2011/11/11 19:40:33 | 000,000,145 | —- | C] () – C:\Windows\Apexwin.ini
[2011/11/11 19:39:04 | 000,343,040 | —- | C] () – C:\Windows\SysWow64\lffpx7.dll
[2011/11/11 19:39:04 | 000,116,736 | —- | C] () – C:\Windows\SysWow64\lfkodak.dll
[2011/11/11 19:39:03 | 000,017,920 | —- | C] () – C:\Windows\SysWow64\Implode.dll
[2011/11/11 19:38:57 | 000,495,616 | —- | C] () – C:\Windows\SysWow64\Tx32.dll
[2011/11/11 19:38:57 | 000,000,260 | —- | C] () – C:\Windows\SysWow64\ic32.ini
[2011/11/11 19:38:43 | 000,004,608 | —- | C] () – C:\Windows\SysWow64\Cp5.dll
[2011/11/11 19:38:42 | 000,000,086 | —- | C] () – C:\Windows\LHOUSE.INI
[2011/11/11 19:38:39 | 000,514,832 | —- | C] () – C:\Windows\SysWow64\LEAD45.DLL
[2011/11/11 19:38:39 | 000,467,348 | —- | C] () – C:\Windows\SysWow64\TGDRAW16.DLL
[2011/11/11 19:38:39 | 000,201,065 | —- | C] () – C:\Windows\SysWow64\TGDXF16.DLL
[2011/11/11 19:38:39 | 000,193,842 | —- | C] () – C:\Windows\SysWow64\TGENT16.DLL
[2011/11/11 19:38:39 | 000,152,384 | —- | C] () – C:\Windows\SysWow64\TGCURV16.DLL
[2011/11/11 19:38:39 | 000,136,200 | —- | C] () – C:\Windows\SysWow64\TGSOLD16.DLL
[2011/11/11 19:38:39 | 000,127,656 | —- | C] () – C:\Windows\SysWow64\TG2D16.DLL
[2011/11/11 19:38:39 | 000,083,240 | —- | C] () – C:\Windows\SysWow64\TGCIRC16.DLL
[2011/11/11 19:38:39 | 000,081,770 | —- | C] () – C:\Windows\SysWow64\TGCLIP16.DLL
[2011/11/11 19:38:39 | 000,070,784 | —- | C] () – C:\Windows\SysWow64\TG3D16.DLL
[2011/11/11 19:38:39 | 000,070,632 | —- | C] () – C:\Windows\SysWow64\TGPOLY16.DLL
[2011/11/11 19:38:39 | 000,062,976 | —- | C] () – C:\Windows\SysWow64\TGSURF16.DLL
[2011/11/11 19:38:39 | 000,062,464 | —- | C] () – C:\Windows\SysWow64\TGKERN16.DLL
[2011/11/11 19:38:39 | 000,059,872 | —- | C] () – C:\Windows\SysWow64\TGARC16.DLL
[2011/11/11 19:38:39 | 000,053,864 | —- | C] () – C:\Windows\SysWow64\TGSPHR16.DLL
[2011/11/11 19:38:39 | 000,049,256 | —- | C] () – C:\Windows\SysWow64\TGTRF16.DLL
[2011/11/11 19:38:39 | 000,044,032 | —- | C] () – C:\Windows\SysWow64\TGTOOL16.DLL
[2011/11/11 19:38:39 | 000,042,464 | —- | C] () – C:\Windows\SysWow64\TGDBAS16.DLL
[2011/11/11 19:38:39 | 000,030,768 | —- | C] () – C:\Windows\SysWow64\TGCONV16.DLL
[2011/11/11 19:38:39 | 000,030,144 | —- | C] () – C:\Windows\SysWow64\TGTRIG16.DLL
[2011/11/11 19:38:39 | 000,027,304 | —- | C] () – C:\Windows\SysWow64\TGAREA16.DLL
[2011/11/11 19:38:39 | 000,026,408 | —- | C] () – C:\Windows\SysWow64\TGTRIA16.DLL
[2011/11/11 19:38:39 | 000,025,612 | —- | C] () – C:\Windows\SysWow64\TGVOL16.DLL
[2011/11/11 19:12:41 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/11/08 13:16:51 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2011/11/08 13:16:51 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2011/11/08 13:16:51 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2011/11/08 13:16:50 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2011/11/08 13:16:50 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2011/02/10 09:10:51 | 000,772,558 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/09 21:03:48 | 000,000,326 | —- | C] () – C:\Windows\primopdf.ini
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
========== LOP Check ==========
[2012/04/05 13:31:08 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ACI
[2012/09/21 20:09:25 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\DefaultTab
[2011/11/11 19:39:09 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\EServices
[2012/05/19 07:56:19 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Fingertapps
[2011/11/11 23:28:17 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\GetRightToGo
[2011/12/07 11:57:19 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Nitro PDF
[2012/07/01 14:34:57 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\OpenCandy
[2012/07/01 14:36:43 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Paltalk
[2012/09/20 20:18:05 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PC Cleaners
[2011/12/07 11:58:02 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PC-FAX TX
[2011/11/13 17:52:50 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PCDr
[2012/09/20 20:18:06 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PCPro
[2012/09/15 09:49:57 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PinPhotoZoom
[2012/01/06 15:23:44 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PokerCreations
[2012/09/14 14:47:14 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\PrimoPDF
[2012/01/19 12:50:25 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ScanSoft
[2012/09/19 23:25:30 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\ScanSpyware
[2012/03/04 14:53:32 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\SouthPointPoker
[2012/01/19 12:50:31 | 000,000,000 | —D | M] – C:\Users\cwestmas2011\AppData\Roaming\Zeon
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\drivers\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\SysNative\DriverStore\FileRepository\machine.inf_amd64_neutral_a2f120466549d68b\AGP440.sys
[2009/07/13 18:52:21 | 000,061,008 | —- | M] (Microsoft Corporation) MD5=608C14DBA7299D8CB6ED035A68A15799 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.1.7601.17514_none_1838f2aad55063bb\AGP440.sys
< MD5 for: ATAPI.SYS >
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\erdnt\cache64\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\drivers\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\SysNative\DriverStore\FileRepository\mshdc.inf_amd64_neutral_aad30bdeec04ea5e\atapi.sys
[2009/07/13 18:52:21 | 000,024,128 | —- | M] (Microsoft Corporation) MD5=02062C0B390B7729EDC9E69C680A6F3C – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.1.7601.17514_none_3b5e2d89382958dd\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\erdnt\cache86\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\SysWOW64\cngaudit.dll
[2009/07/13 18:15:06 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=50BA656134F78AF64E4DD3C8B6FEFD7E – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_e83a414890e8132b\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\erdnt\cache64\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\SysNative\cngaudit.dll
[2009/07/13 18:40:20 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=86FE1B1F8FD42CD0DB641AB1CDB13093 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.1.7600.16385_none_4458dccc49458461\cngaudit.dll
< MD5 for: IASTOR.SYS >
[2007/04/26 03:41:38 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\Drivers\storage\R154092\iastor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Drivers\storage\R284354\x64\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\drivers\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\DriverStore\FileRepository\iaahci.inf_amd64_neutral_2b0c50dc63f09dae\iaStor.sys
[2010/09/14 05:24:26 | 000,437,272 | —- | M] (Intel Corporation) MD5=F7CE9BE72EDAC499B713ECA6DAE5D26F – C:\Windows\SysNative\DriverStore\FileRepository\iastor.inf_amd64_neutral_5b314ccea0aa569d\iaStor.sys
< MD5 for: IASTORV.SYS >
[2010/11/20 20:23:47 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_668286aa35d55928\iaStorV.sys
[2010/11/20 20:23:47 | 000,410,496 | —- | M] (Intel Corporation) MD5=3DF4395A7CF8B7A72A5F4606366B8C2D – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17514_none_0d3757e79e6784d0\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=5B3DE7208E5000D5B451B9D290D2579C – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.21680_none_0d714416b7c182d5\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\drivers\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\SysNative\DriverStore\FileRepository\iastorv.inf_amd64_neutral_0bcee2057afcc090\iaStorV.sys
[2011/11/08 14:49:54 | 000,410,496 | —- | M] (Intel Corporation) MD5=AAAF44DB3BD0B9D1FB6969B23ECC8366 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.1.7601.17577_none_0cf9793d9e95787b\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\erdnt\cache64\netlogon.dll
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\SysNative\netlogon.dll
[2010/11/20 20:24:01 | 000,695,808 | —- | M] (Microsoft Corporation) MD5=AA339DD8BB128EF66660DFBBB59043D3 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_5bddbcb24e997298\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\erdnt\cache86\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\SysWOW64\netlogon.dll
[2010/11/20 20:24:09 | 000,563,712 | —- | M] (Microsoft Corporation) MD5=C1809B9907ADEDAF16F50C894100883B – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.1.7601.17514_none_6632670482fa3493\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=D23C7E8566DA2B8A7C0DBBB761D54888 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.21680_none_983ab4c5eef82cad\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\drivers\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_0276fc3b3ea60d41\nvstor.sys
[2011/11/08 14:49:54 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=DAB0E87525C10052BF65F06152F37E4A – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17577_none_97c2e9ecd5cc2253\nvstor.sys
[2010/11/20 20:23:47 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\SysNative\DriverStore\FileRepository\nvraid.inf_amd64_neutral_dd659ed032d28a14\nvstor.sys
[2010/11/20 20:23:47 | 000,166,272 | —- | M] (NVIDIA Corporation) MD5=F7CD50FE7139F07E77DA8AC8033D1832 – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.1.7601.17514_none_9800c896d59e2ea8\nvstor.sys
< MD5 for: SCECLI.DLL >
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\erdnt\cache86\scecli.dll
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\SysWOW64\scecli.dll
[2010/11/20 20:23:54 | 000,175,616 | —- | M] (Microsoft Corporation) MD5=8124944EC89D6A1815E4E53F5B96AAF4 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_a088921d241bbb4e\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\erdnt\cache64\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\SysNative\scecli.dll
[2010/11/20 20:24:32 | 000,232,960 | —- | M] (Microsoft Corporation) MD5=ED78427259134C63ED69804D2132B86C – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.1.7601.17514_none_9633e7caefbaf953\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
< >
[2009/07/13 22:08:49 | 000,000,006 | -H– | C] () – C:\Windows\Tasks\SA.DAT
[2009/07/13 22:08:49 | 000,032,542 | —- | C] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/08 10:58:15 | 000,000,830 | —- | C] () – C:\Windows\Tasks\Adobe Flash Player Updater.job
[2012/09/20 20:37:05 | 000,000,884 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001Core.job
[2012/09/20 20:37:05 | 000,000,936 | —- | C] () – C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3398785354-3721342185-2269831038-1001UA.job
< End of report >