Here's the OTL.txt:
OTL logfile created on: 10/9/2012 8:21:19 PM - Run 2
OTL by OldTimer - Version 3.2.70.2 Folder = C:\Users\Admin\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.89 Gb Available Physical Memory | 44.42% Memory free
4.23 Gb Paging File | 2.49 Gb Available in Paging File | 58.94% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 222.78 Gb Total Space | 70.73 Gb Free Space | 31.75% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.15 Gb Free Space | 61.54% Space Free | Partition Type: NTFS
Drive G: | 442.98 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive H: | 930.86 Gb Total Space | 788.33 Gb Free Space | 84.69% Space Free | Partition Type: NTFS
Computer Name: HOME-PC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/10/04 19:31:48 | 000,601,088 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
PRC - [2012/08/21 04:12:26 | 004,282,728 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/08/02 12:43:22 | 004,528,528 | —- | M] (Mozy, Inc.) – C:\Program Files\MozyHome\mozystat.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 07:40:36 | 000,296,056 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2012/06/23 10:49:02 | 000,865,792 | —- | M] (Highresolution Enterprises) – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonControl.exe
PRC - [2012/06/23 10:48:50 | 000,073,216 | —- | M] (Highresolution Enterprises) – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe
PRC - [2012/06/06 04:39:34 | 000,843,264 | —- | M] () – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcgrid_gfam_vina_prod_x86.exe.6.12
PRC - [2012/06/06 04:39:32 | 000,507,904 | —- | M] () – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcgrid_gfam_vina_6.12_windows_intelx86
PRC - [2011/12/13 23:09:20 | 001,215,816 | —- | M] (PC-Doctor, Inc.) – C:\Program Files\Dell Support Center\pcdrcui.exe
PRC - [2011/12/13 20:36:04 | 000,158,208 | —- | M] (PC-Doctor, Inc.) – C:\Program Files\Dell Support Center\pcdrsysinfosoftware.p5x
PRC - [2011/09/09 16:01:16 | 001,804,648 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe
PRC - [2011/09/09 15:49:30 | 000,643,944 | —- | M] (Hewlett-Packard Co.) – C:\Program Files\HP\HP Officejet 6700\Bin\HPNetworkCommunicator.exe
PRC - [2011/07/14 12:43:42 | 002,875,461 | —- | M] (Informer Technologies, Inc.) – C:\Program Files\Software Informer\softinfo.exe
PRC - [2011/04/22 07:21:10 | 000,247,728 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
PRC - [2011/04/22 07:21:10 | 000,092,592 | —- | M] (TomTom) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
PRC - [2011/03/04 13:36:13 | 001,253,376 | —- | M] (The Scripps Research Institute and IBM Corporation) – C:\Boinc\Data\projects\www.worldcommunitygrid.org\wcg_hfcc_autodock_6.40_windows_intelx86
PRC - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) – C:\Program Files\Secunia\PSI\psia.exe
PRC - [2010/09/23 19:59:44 | 004,543,232 | —- | M] (World Community Grid) – C:\Boinc\boincmgr.exe
PRC - [2010/09/23 19:59:42 | 000,058,112 | —- | M] (Space Sciences Laboratory) – C:\Boinc\boinctray.exe
PRC - [2010/09/23 19:59:40 | 000,537,344 | —- | M] (World Community Grid) – C:\Boinc\boinc.exe
PRC - [2010/08/10 08:37:22 | 000,217,088 | R— | M] () – C:\Program Files\ASUS\Printer Utilities\UsbService.exe
PRC - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft LifeCam\MSCamS32.exe
PRC - [2010/01/29 01:04:26 | 000,764,784 | —- | M] (Microsoft Corporation
) – C:\Windows\vVX6000.exe
PRC - [2010/01/21 17:24:08 | 000,110,592 | —- | M] (WDC) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009/06/16 09:58:08 | 000,020,480 | —- | M] (Memeo) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2008/07/14 05:42:22 | 000,409,600 | R— | M] () – C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
PRC - [2008/06/06 11:41:22 | 000,352,256 | R— | M] (AVerMedia) – C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
PRC - [2008/01/17 07:22:20 | 004,907,008 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) – C:\Windows\System32\AERTSrv.exe
PRC - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/03/15 11:09:36 | 000,460,784 | —- | M] (Gteko Ltd.) – C:\Program Files\DellSupport\DSAgnt.exe
PRC - [2007/03/12 18:30:14 | 000,517,768 | —- | M] (Symantec Corporation) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
PRC - [2006/11/23 15:13:38 | 000,126,976 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\pmxmiced.exe
PRC - [2006/11/08 14:01:54 | 000,049,152 | —- | M] (Primax Electronics Ltd.) – C:\Windows\System32\ico.exe
PRC - [2006/11/02 07:35:35 | 000,176,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\wpcumi.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/14 04:06:31 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 04:06:20 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 04:06:02 | 014,329,856 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 04:05:29 | 012,219,392 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/05/12 04:43:36 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/12 04:41:36 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/12 04:36:18 | 002,295,296 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/12 04:36:08 | 000,368,128 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/12 04:35:23 | 003,325,952 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/12 04:35:18 | 007,953,408 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/12 04:35:08 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2011/12/13 20:36:04 | 000,483,328 | —- | M] () – C:\Program Files\Dell Support Center\libAsapiCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,098,304 | —- | M] () – C:\Program Files\Dell Support Center\libCSharpCommonCS.dll
MOD - [2011/12/13 20:36:04 | 000,086,016 | —- | M] () – C:\Program Files\Dell Support Center\libTonopahClientCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,040,960 | —- | M] () – C:\Program Files\Dell Support Center\libDataStoreCSharp.dll
MOD - [2011/12/13 20:36:04 | 000,019,456 | —- | M] () – C:\Program Files\Dell Support Center\pcdcsharpcommon.dll
MOD - [2011/12/13 20:36:04 | 000,012,800 | —- | M] () – C:\Program Files\Dell Support Center\libGapiCSharp.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | —- | M] () – C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/04/08 14:56:03 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\4804ced5-915b-48a3-a465-b8a5e02714bf.dll
MOD - [2011/04/08 13:27:10 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\378deb7f-049e-4a5e-83b2-5381dcd9e928.dll
MOD - [2011/04/08 13:12:56 | 000,026,704 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\62d1f0b0-bc9a-4f6c-bad7-93b19a91276a.dll
MOD - [2011/04/08 12:57:00 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\934f6059-2d35-4bd9-a130-a17cb5563507.dll
MOD - [2011/04/08 12:28:00 | 000,026,704 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\173c4dd2-e93c-4725-b006-db1d8f465192.dll
MOD - [2011/04/08 11:59:03 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\739db3eb-d3cd-4c86-a6ea-01a49984fa3b.dll
MOD - [2011/04/06 19:24:19 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\ddb9fe5d-525c-4d5d-ac37-0bd10f2864f8.dll
MOD - [2011/04/06 19:09:39 | 000,026,192 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\7bd83798-7a02-4f50-83a2-b91cabcbd1f9.dll
MOD - [2011/03/24 12:41:34 | 000,719,440 | —- | M] () – C:\ProgramData\PCDr\5907\Downloads\a61f44a8-21a3-4c4a-a04b-993dfb73bf96.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2006/10/26 16:21:22 | 000,056,056 | —- | M] () – C:\Windows\System32\DLAAPI_W.DLL
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] – C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter – (sprtsvc_dellsupportcenter)
SRV - [2012/10/08 12:53:30 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/05 20:26:40 | 000,114,144 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/08/21 04:12:25 | 000,044,808 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe – (avast! Antivirus)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/06/23 10:48:50 | 000,073,216 | —- | M] (Highresolution Enterprises) [Auto | Running] – C:\Program Files\Highresolution Enterprises\X-Mouse Button Control\XMouseButtonSvc.exe – (XMouseButton Launcher)
SRV - [2011/06/12 11:15:00 | 031,125,880 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Microsoft Office\Office14\GROOVE.EXE – (Microsoft SharePoint Workspace Audit Service)
SRV - [2011/04/22 07:21:10 | 000,092,592 | —- | M] (TomTom) [Auto | Running] – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe – (TomTomHOMEService)
SRV - [2010/12/21 07:04:30 | 000,987,704 | —- | M] (Secunia) [Auto | Running] – C:\Program Files\Secunia\PSI\psia.exe – (Secunia PSI Agent)
SRV - [2010/09/23 19:59:40 | 000,537,344 | —- | M] (World Community Grid) [Auto | Running] – C:\Boinc\boinc.exe – (BOINC)
SRV - [2010/08/10 08:37:22 | 000,217,088 | R— | M] () [Auto | Running] – C:\Program Files\ASUS\Printer Utilities\UsbService.exe – (UsbService)
SRV - [2010/05/20 15:27:24 | 000,139,632 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft LifeCam\MSCamS32.exe – (MSCamSvc)
SRV - [2010/01/21 17:24:08 | 000,110,592 | —- | M] (WDC) [Auto | Running] – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe – (WDDMService)
SRV - [2009/06/16 09:58:08 | 000,020,480 | —- | M] (Memeo) [Auto | Running] – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe – (WDSmartWareBackgroundService)
SRV - [2008/07/14 05:42:22 | 000,409,600 | R— | M] () [Auto | Running] – C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe – (AVerScheduleService)
SRV - [2008/06/06 11:41:22 | 000,352,256 | R— | M] (AVerMedia) [Auto | Running] – C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe – (AVerRemote)
SRV - [2008/01/19 02:38:24 | 000,272,952 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/12/05 06:17:24 | 000,077,824 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Windows\System32\AERTSrv.exe – (AERTFilters)
SRV - [2007/09/12 18:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/03/19 11:44:44 | 000,070,656 | —- | M] () [On_Demand | Stopped] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/03/12 18:30:14 | 000,517,768 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe – (LiveUpdate Notice Service)
SRV - [2005/02/09 12:59:00 | 000,014,165 | —- | M] (Pinnacle Systems GmbH) [Auto | Stopped] – C:\Windows\System32\drivers\Pclepci.sys – (PCLEPCI)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\ZDPSp60.sys – (ZDPSp60)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Windows\system32\ZDPNDIS4.SYS – (ZDPNDIS4)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\emOEM.sys – (USB28xxOEM)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\emBDA.sys – (USB28xxBGA)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkfwd.sys – (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\nwlnkflt.sys – (NwlnkFlt)
DRV - File not found [Kernel | Unavailable | Unknown] – system32\DRIVERS\msfwhlpr.sys – (MSFWHLPR)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\ipinip.sys – (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\Admin\AppData\Local\Temp\catchme.sys – (catchme)
DRV - File not found [Kernel | Auto | Stopped] – System32\Drivers\Ca1528av.sys – (Ca1528av)
DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\Bulk1528.sys – (Bulk1528)
DRV - File not found [Kernel | Disabled | Stopped] – C:\Windows\system32\drivers\blbdrive.sys – (blbdrive)
DRV - [2012/08/21 04:13:15 | 000,729,752 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\System32\drivers\aswSnx.sys – (aswSnx)
DRV - [2012/08/21 04:13:15 | 000,355,632 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswSP.sys – (aswSP)
DRV - [2012/08/21 04:13:15 | 000,054,232 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswTdi.sys – (aswTdi)
DRV - [2012/08/21 04:13:14 | 000,058,680 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\System32\drivers\aswMonFlt.sys – (aswMonFlt)
DRV - [2012/08/21 04:13:14 | 000,035,928 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\System32\drivers\aswRdr.sys – (aswRdr)
DRV - [2012/08/21 04:13:13 | 000,021,256 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\System32\drivers\aswFsBlk.sys – (aswFsBlk)
DRV - [2011/12/13 20:36:04 | 000,021,744 | —- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Running] – c:\Program Files\Dell Support Center\pcdsrvc.pkms – (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2010/09/01 03:30:58 | 000,015,544 | —- | M] (Secunia) [File_System | On_Demand | Stopped] – C:\Windows\System32\drivers\psi_mf.sys – (PSI)
DRV - [2010/03/24 05:23:16 | 011,614,760 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvlddmkm.sys – (nvlddmkm)
DRV - [2010/03/10 09:17:26 | 000,024,216 | —- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ivusb.sys – (ivusb)
DRV - [2010/01/29 01:04:28 | 002,074,480 | —- | M] (Microsoft Corporation
) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\VX6000Xp.sys – (VX6000)
DRV - [2009/12/08 08:37:02 | 000,437,888 | —- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AVerFx2hbtv.sys – (AVerFx2hbtv)
DRV - [2009/03/02 14:12:10 | 000,038,400 | —- | M] (Samsung Electronics Co., Ltd.) [Kernel | Auto | Stopped] – C:\Windows\System32\drivers\DgivEcp.sys – (DgiVecp)
DRV - [2009/03/02 14:12:10 | 000,005,120 | —- | M] (Samsung Electronics) [Kernel | Auto | Running] – C:\Windows\System32\drivers\SSPORT.sys – (SSPORT)
DRV - [2009/02/13 12:02:52 | 000,011,520 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\wdcsam.sys – (WDC_SAM)
DRV - [2007/12/16 21:25:04 | 000,066,432 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vuhub.sys – (vuhub)
DRV - [2007/08/09 18:12:30 | 000,110,624 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\nvstor32.sys – (nvstor32)
DRV - [2007/06/29 12:25:14 | 000,045,344 | —- | M] (FotoNation Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CoachVid.sys – (CoachVid)
DRV - [2007/06/29 12:25:14 | 000,010,752 | —- | M] (FotoNation Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\CoachAud.sys – (CoachAud)
DRV - [2007/05/09 09:37:54 | 000,434,176 | —- | M] (Pinnacle a division of Avid Technology, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\MarvinAVS.sys – (PinnacleMarvinAVS)
DRV - [2007/03/23 06:09:16 | 000,129,832 | —- | M] (NVIDIA Corporation) [Kernel | Disabled | Stopped] – C:\Windows\System32\drivers\nvrd32.sys – (nvrd32)
DRV - [2007/03/15 08:57:30 | 001,059,112 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\nvmfdx32.sys – (NVENETFD)
DRV - [2007/02/25 11:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\dsunidrv.sys – (dsunidrv)
DRV - [2007/02/08 20:05:30 | 000,028,120 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLARTL_M.SYS – (DLARTL_M)
DRV - [2007/02/08 20:05:30 | 000,012,856 | —- | M] (Roxio) [File_System | System | Running] – C:\Windows\System32\drivers\DLACDBHM.SYS – (DLACDBHM)
DRV - [2007/01/23 10:11:38 | 000,441,472 | —- | M] (Pinnacle Systems) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\MarvinUsb.sys – (PinnacleMarvinUsb)
DRV - [2007/01/04 10:07:00 | 000,171,520 | —- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\MarvinBus.sys – (MarvinBus)
DRV - [2006/11/02 02:36:43 | 002,028,032 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\atikmdag.sys – (R300)
DRV - [2006/11/02 02:30:55 | 000,200,704 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\e1e6032.sys – (e1express)
DRV - [2006/10/26 16:22:02 | 000,009,400 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLADResM.SYS – (DLADResM)
DRV - [2006/10/26 16:21:34 | 000,094,648 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDFAM.SYS – (DLAUDFAM)
DRV - [2006/10/26 16:21:34 | 000,035,096 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABMFSM.SYS – (DLABMFSM)
DRV - [2006/10/26 16:21:32 | 000,097,848 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAUDF_M.SYS – (DLAUDF_M)
DRV - [2006/10/26 16:21:30 | 000,026,296 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAOPIOM.SYS – (DLAOPIOM)
DRV - [2006/10/26 16:21:28 | 000,032,472 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLABOIOM.SYS – (DLABOIOM)
DRV - [2006/10/26 16:21:26 | 000,014,520 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAPoolM.SYS – (DLAPoolM)
DRV - [2006/10/26 16:21:24 | 000,104,536 | —- | M] (Roxio) [File_System | Auto | Running] – C:\Windows\System32\DLA\DLAIFS_M.SYS – (DLAIFS_M)
DRV - [2006/10/19 16:29:32 | 000,019,008 | —- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pmxusblf.sys – (pmxusblf)
DRV - [2006/10/19 16:27:56 | 000,023,232 | —- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\pmxmouse.sys – (pmxmouse)
DRV - [2006/10/18 13:08:18 | 000,258,048 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\HSXHWBS2.sys – (HSXHWBS2)
DRV - [2006/10/05 16:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand | Running] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2006/08/04 19:39:10 | 000,008,192 | —- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] – C:\Windows\System32\drivers\XAudio.sys – (XAudio)
DRV - [2006/03/01 10:24:16 | 000,290,816 | —- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZD1211U.sys – (ZD1211U(ZyDAS)
DRV - [2004/10/25 13:40:58 | 000,017,664 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\ZDPSp50.sys – (ZDPSp50)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = Reg Error: Variant error.
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://qwest.live.com
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…amp;rlz=1I7DKUS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKCU\..\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7}: "URL" =
http://www.google-feed.net/results.php?q={…D=2&PID=STV
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = ;*.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "GoogleFeed.net"
FF - prefs.js..browser.search.selectedEngine: "GoogleFeed.net"
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: [removed]:6.0
FF - prefs.js..extensions.enabledAddons: [removed]:2012.07.08.17
FF - prefs.js..extensions.enabledAddons: {97E22097-9A2F-45b1-8DAF-36AD648C7EF4}:15.0.4
FF - prefs.js..extensions.enabledAddons: [removed]:7.0.1466
FF - prefs.js..extensions.enabledAddons: [removed]:2.0.0
FF - prefs.js..extensions.enabledAddons: [removed]:4.1.3
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.73.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/07/17 07:45:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/06 20:06:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/27 21:30:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/09/27 21:08:45 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2012/09/27 21:53:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/05/31 15:00:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2010/05/31 15:00:25 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/02/19 19:26:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/01 20:52:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions
[2010/04/30 20:44:22 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/07/16 20:44:35 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/10/01 20:52:48 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/09/27 21:51:07 | 000,000,000 | —D | M] (LastPass) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2012/10/01 20:52:02 | 000,000,000 | —D | M] (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\trash
[2012/07/16 21:10:20 | 000,163,080 | —- | M] () (No name found) – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\extensions\[removed]
[2009/11/14 09:11:09 | 000,000,003 | —- | M] () – C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\2u5n2yy2.default\searchplugins\GoogleFeed.xml
[2012/10/07 19:50:26 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/09/06 20:06:46 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2012/07/17 07:45:20 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2012/09/05 20:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/07/17 07:42:08 | 000,129,144 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2012/09/05 20:26:22 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/05 20:26:22 | 000,002,253 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/10/05 19:25:39 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {0A87E45F-537A-40B4-B812-E2544C21A09F} - No CLSID value found.
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (LastPass Vault) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll ()
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [boincmgr] C:\Boinc\boincmgr.exe (World Community Grid)
O4 - HKLM..\Run: [boinctray] C:\Boinc\boinctray.exe (Space Sciences Laboratory)
O4 - HKLM..\Run: [LifeCam] C:\Program Files\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [USB2Check] C:\Windows\System32\PCLECoInst.dll (Pinnacle Systems)
O4 - HKLM..\Run: [USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKLM..\Run: [VX6000] C:\Windows\vVX6000.exe (Microsoft Corporation
)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [HP Officejet 6700 (NET)] C:\Program Files\HP\HP Officejet 6700\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKCU..\Run: [LaunchList] C:\Program Files\Pinnacle\Studio 11\LaunchList2.exe (Pinnacle Systems)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: LastPass - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=lastpass File not found
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Admin\AppData\LocalLow\LastPass\context.html?cmd=fillforms File not found
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll ()
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll ()
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/vers…vex-2.2.4.5.cab (Reg Error: Unable to open value key)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Unable to open value key)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Unable to open value key)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7653E6A1-5749-4CF5-B9C8-C5C67D00E752}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8C2D2A42-495E-4352-B6FC-4B86185E4601}: DhcpNameServer = 192.168.2.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2DF5B9D-D397-4D17-9055-0D155FF548A8}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\inspiron_DT_1152x864_03.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\inspiron_DT_1152x864_03.jpg
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/25 12:19:29 | 000,000,121 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010/01/28 15:00:27 | 000,000,088 | —- | M] () - G:\autorun.inf – [ UDF ]
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2012/10/07 20:07:55 | 000,000,000 | -HSD | C] – C:\found.000
[2012/10/07 19:58:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2012/10/05 19:30:43 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/10/05 19:30:35 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/10/05 19:30:35 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Local\temp
[2012/10/05 19:05:59 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/10/05 19:05:59 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/10/05 19:05:59 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/10/05 19:05:44 | 000,000,000 | —D | C] – C:\Qoobox
[2012/10/05 19:04:54 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/10/05 18:52:53 | 004,762,471 | R— | C] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2012/10/04 19:31:21 | 004,731,392 | —- | C] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2012/10/04 19:30:53 | 000,601,088 | —- | C] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2012/10/02 21:51:50 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Admin\Desktop\HiJackThis.exe
[2012/09/27 22:04:54 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/09/27 21:30:17 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/09/27 21:30:16 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Maintenance Service
[2012/09/27 19:15:10 | 000,000,000 | —D | C] – C:\Users\Admin\Desktop\Kati ja Anna
[2012/09/17 20:21:23 | 000,000,000 | —D | C] – C:\Users\Admin\AppData\Roaming\PictureMover
[2012/09/17 19:25:14 | 002,212,440 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Admin\Desktop\TDSSKiller.exe
[2011/01/01 14:07:15 | 010,974,280 | —- | C] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2010/01/31 21:36:39 | 008,653,312 | —- | C] (Dell, Inc. ) – C:\Users\Admin\AppData\Roaming\DataSafeDotNet.exe
[2007/07/20 18:56:57 | 011,718,184 | —- | C] (World Community Grid ) – C:\Users\Admin\wcg_boinc_5.8.15_windows_intelx86.exe
[3 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/09 20:20:30 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2012/10/09 20:14:48 | 000,071,218 | —- | M] () – C:\ProgramData\nvModes.001
[2012/10/09 20:12:46 | 000,071,221 | —- | M] () – C:\ProgramData\nvModes.dat
[2012/10/09 19:36:02 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/10/09 19:26:05 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/09 19:26:04 | 000,003,696 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/09 19:22:26 | 000,005,484 | —- | M] () – C:\Windows\mozy.blk
[2012/10/09 19:22:26 | 000,002,416 | —- | M] () – C:\Windows\mozy.flt
[2012/10/07 23:24:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/10/07 23:24:25 | 187,627,764 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/10/06 13:36:35 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/10/06 13:31:39 | 000,513,501 | —- | M] () – C:\Users\Admin\Desktop\AdwCleaner.exe
[2012/10/05 19:25:39 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/10/05 18:54:54 | 002,212,440 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Admin\Desktop\TDSSKiller.exe
[2012/10/05 18:53:41 | 004,762,471 | R— | M] (Swearware) – C:\Users\Admin\Desktop\ComboFix.exe
[2012/10/05 18:52:35 | 002,193,278 | —- | M] () – C:\Users\Admin\Desktop\tdsskiller.zip
[2012/10/04 20:12:06 | 000,000,120 | —- | M] () – C:\Users\Admin\Desktop\MBR.zip
[2012/10/04 20:11:29 | 000,000,512 | —- | M] () – C:\Users\Admin\Desktop\MBR.dat
[2012/10/04 19:31:54 | 004,731,392 | —- | M] (AVAST Software) – C:\Users\Admin\Desktop\aswMBR.exe
[2012/10/04 19:31:48 | 000,601,088 | —- | M] (OldTimer Tools) – C:\Users\Admin\Desktop\OTL.exe
[2012/10/03 18:28:11 | 000,640,408 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/10/03 18:28:11 | 000,118,660 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/10/02 21:51:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Admin\Desktop\HiJackThis.exe
[2012/09/27 21:51:17 | 010,974,280 | —- | M] (LastPass) – C:\Program Files\Common Files\lpuninstall.exe
[2012/09/27 21:30:33 | 000,000,872 | —- | M] () – C:\Users\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/23 07:32:53 | 000,536,056 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[3 C:\*.tmp files -> C:\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/07 23:24:25 | 187,627,764 | —- | C] () – C:\Windows\MEMORY.DMP
[2012/10/06 13:31:32 | 000,513,501 | —- | C] () – C:\Users\Admin\Desktop\AdwCleaner.exe
[2012/10/05 19:05:59 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/10/05 19:05:59 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/10/05 19:05:59 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/10/05 19:05:59 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/10/05 19:05:59 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/10/05 18:52:08 | 002,193,278 | —- | C] () – C:\Users\Admin\Desktop\tdsskiller.zip
[2012/10/04 20:12:06 | 000,000,120 | —- | C] () – C:\Users\Admin\Desktop\MBR.zip
[2012/10/04 20:11:29 | 000,000,512 | —- | C] () – C:\Users\Admin\Desktop\MBR.dat
[2012/07/16 20:47:11 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/06/27 21:39:03 | 000,014,115 | —- | C] () – C:\Windows\twspmm.ini
[2012/04/14 21:32:47 | 000,000,931 | —- | C] () – C:\Users\Admin\AppData\Roaming\ofx2csv.ini
[2012/01/21 17:39:08 | 000,000,064 | —- | C] () – C:\Windows\qwimp.ini
[2012/01/21 17:22:08 | 000,000,372 | —- | C] () – C:\Windows\intuprof.ini
[2011/07/19 19:52:00 | 000,022,723 | —- | C] () – C:\Windows\System32\SSGR3l3.dll
[2011/05/28 17:39:51 | 000,066,432 | —- | C] () – C:\Windows\System32\drivers\vuhub.sys
[2011/02/09 23:03:48 | 000,000,314 | —- | C] () – C:\Windows\primopdf.ini
[2011/01/01 14:34:37 | 000,000,611 | —- | C] () – C:\Windows\eReg.dat
[2010/11/13 10:31:25 | 000,000,675 | —- | C] () – C:\Windows\EReg072.dat
[2010/04/13 19:34:24 | 000,071,218 | —- | C] () – C:\ProgramData\nvModes.001
[2010/04/13 18:51:05 | 000,071,221 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/12/22 11:52:37 | 000,000,040 | —- | C] () – C:\Users\Admin\AppData\Roaming\cdr.ini
[2009/11/27 17:39:23 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/03/09 19:58:29 | 000,695,642 | —- | C] () – C:\Users\Admin\AppData\Roaming\unins000.exe
[2009/03/09 19:58:29 | 000,001,870 | —- | C] () – C:\Users\Admin\AppData\Roaming\unins000.dat
[2008/06/25 06:56:47 | 000,001,356 | —- | C] () – C:\Users\Admin\AppData\Local\d3d9caps.dat
[2008/05/20 07:24:32 | 000,734,762 | —- | C] () – C:\Users\Admin\AppData\Roaming\datasafeupdate.msi
[2007/09/01 14:02:56 | 000,004,933 | —- | C] () – C:\Users\Admin\AppData\Roaming\SmarThruOptions.xml
[2007/07/31 19:29:47 | 000,000,000 | —- | C] () – C:\Users\Admin\AppData\Roaming\wklnhst.dat
[2007/07/20 14:47:48 | 000,008,362 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/07/14 14:28:38 | 000,000,632 | RHS- | C] () – C:\Users\Admin\ntuser.pol
[2007/07/14 12:58:11 | 000,032,256 | —- | C] () – C:\Users\Admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2008/06/10 21:08:58 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ACAMPREF
[2010/04/14 21:02:42 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\ChessBase
[2007/10/19 21:17:18 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\DataSafeOnline
[2007/07/14 13:04:04 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Earthlink
[2011/10/26 18:08:57 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Highresolution Enterprises
[2010/02/01 22:07:13 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\IObit
[2007/08/18 19:05:33 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PC Magazine Utilities
[2011/07/19 09:10:59 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PCDr
[2012/09/17 20:21:53 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\PictureMover
[2012/10/09 20:18:34 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Software Informer
[2007/07/31 19:29:47 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Template
[2008/05/19 21:21:48 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Tenebril
[2010/05/31 15:00:21 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Thunderbird
[2010/02/19 19:26:13 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\TomTom
[2010/01/30 18:03:05 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Ulead Systems
[2010/11/27 18:38:46 | 000,000,000 | —D | M] – C:\Users\Admin\AppData\Roaming\Western Digital
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/10/29 01:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 01:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 22:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2007/11/13 23:52:33 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2007/11/13 23:52:32 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\erdnt\cache\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 21:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 04:45:07 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 02:33:10 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SVCHOST.EXE >
[2006/11/02 04:45:47 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\erdnt\cache\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\System32\svchost.exe
[2008/01/19 02:33:32 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\erdnt\cache\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/19 02:33:33 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 04:45:50 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe
< MD5 for: WINLOGON.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\erdnt\cache\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 04:45:57 | 000,308,224 | —- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 02:33:37 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: WDC WD25 00JS-75NCB3 SCSI Disk Device
Partitions: 3
Status: OK
Status Info: 0
Drive: \\\\.\\PHYSICALDRIVE1 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: WD My Book 1111 USB Device
Partitions: 1
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 55.00MB
Starting Offset: 32256
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 10.00GB
Starting Offset: 57671680
Hidden sectors: 0
DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 223.00GB
Starting Offset: 10795089920
Hidden sectors: 0
DeviceID: Disk #1, Partition #0
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 1048576
Hidden sectors: 0
< End of report >
It did not open an Extras.Txt