This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Reopening topic - Random freezing [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, It freezes very at random when on the internet, when not on the internet (like when opening folders in Documents, etc), when trying to shut down (for example: Start button won't respond when I click on it), & it won't respond when clicking on ctrl+alt+delete. I guess it's more than 50% of the time that these things work well. When it does hang or freeze, it continues to do that, so from that point on, it's not random. That's when I shut down my laptop, wait 10 seconds, then start it up again. That can help alot sometimes. This happens frequently: blue circle next to the cursor keeps spinning round & round - also, I see "(not responding)" a lot Saw this 3 times yesterday: "A problem has been detected and windows has been shut down to prevent damage to your computer" Saw this once today: "Desktop Window Manager stopped working and was closed - A problem caused the application to stop working correctly. Windows will notify you if a solution is available." I got good help from Satchfan 2 weeks ago here in the Malware forum. I should've kept going with that, but I got a reply that didn't notify me in my email, so I lost track - plus, at the time, it seemed like my computer was doing better. I should daily check my topic online, not wait for the email notification - & I should check my spam folder. I reopened the topic in the Windows forum - since I had the feeling it was more of a Windows problem than a malware problem - but Ztruker said to finish up my topic in the Malware forum, then come back to the Windows forum if I still have problems.
Hello again nonkly

As far as I was concerned your computer was free of malware but we'll take another look just to be sure so that Ztruker is satisfied.

Download and run OTL
  • download OTL to your desktop.
  • double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • click Scan all users.
  • under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    DRIVES
    CREATERESTOREPOINT

  • click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • when the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • you may need two posts to fit them both in.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Logs to include with next post:

OTL.txt
Extras.txt
aswMBR log


Thanks

Satchfan
Howdy Satchfan,

Searched my computer for Extras.txt - didn't find it - besides the search, I looked in the C drive, Downloads, & Desktop. Here are the other 2 logs, though:


OTL logfile created on: 2/11/2013 3:01:33 PM - Run 4
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jim\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.07 Gb Available Physical Memory | 54.51% Memory free
7.61 Gb Paging File | 5.68 Gb Available in Paging File | 74.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.35 Gb Total Space | 328.43 Gb Free Space | 72.61% Space Free | Partition Type: NTFS
Drive D: | 13.12 Gb Total Space | 2.18 Gb Free Space | 16.65% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2013/02/11 14:58:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jim\Downloads\OTL.exe
PRC - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/11 20:11:44 | 000,085,280 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/12/11 20:10:31 | 000,109,344 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012/12/11 20:10:29 | 000,384,800 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/08/29 13:51:48 | 001,061,960 | R— | M] (Carbonite, Inc.) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2011/03/24 07:11:18 | 000,107,800 | —- | M] (Octoshape ApS) – C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/09/02 22:45:02 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe
PRC - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
PRC - [2009/10/05 23:08:42 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe
PRC - [1999/12/31 16:00:00 | 000,284,480 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [1999/09/30 18:31:38 | 000,869,376 | —- | M] (Fred's Software) – C:\Program Files (x86)\PrintKey2000\Printkey2000.exe


========== Modules (No Company Name) ==========

MOD - [2013/01/08 21:21:08 | 000,489,472 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\8511eac49521cf5fa810ec3367c40cab\IAStorUtil.ni.dll
MOD - [2013/01/08 21:21:08 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5d918739168186b055c86a63123a1a30\IAStorCommon.ni.dll
MOD - [2013/01/08 16:03:36 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll
MOD - [2013/01/08 16:03:33 | 011,833,344 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\0ac577a8ad6528ff03b50db5eeeac8be\System.Web.ni.dll
MOD - [2013/01/08 16:03:20 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/08 16:03:18 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/08 16:03:05 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll
MOD - [2013/01/08 16:02:58 | 001,592,832 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/08 16:02:18 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll
MOD - [2013/01/08 16:02:15 | 007,989,760 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/08 16:02:10 | 011,493,376 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2010/03/11 10:35:14 | 000,126,976 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanProcess.dll
MOD - [2010/03/05 10:51:54 | 000,143,360 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\Scan.dll
MOD - [2010/02/06 05:12:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FilingRes.dll
MOD - [2010/02/02 11:51:00 | 000,077,824 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanRes.dll
MOD - [2010/02/02 11:51:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManagerRes.dll
MOD - [2010/01/14 11:22:06 | 000,094,208 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\PDF.dll
MOD - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
MOD - [2009/12/21 10:41:22 | 000,086,109 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManager.dll
MOD - [2009/12/21 10:41:14 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\AmCommonLib.dll
MOD - [2009/10/05 23:08:38 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2009/08/07 02:47:06 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuRes.dll
MOD - [2009/06/25 07:00:06 | 000,897,024 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\EncryptPdf.dll
MOD - [2008/08/27 14:58:38 | 000,045,056 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFillRsc.dll
MOD - [2008/06/02 08:27:08 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFill.dll
MOD - [2006/05/15 12:24:18 | 000,122,938 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\CommonFunc.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/08/29 13:43:58 | 006,742,088 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe – (CarboniteService)
SRV:64bit: - [2012/07/11 10:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2011/05/13 18:58:10 | 000,030,520 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2010/09/22 14:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [1999/12/31 16:00:00 | 000,314,880 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [1999/12/31 16:00:00 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Program Files\IDT\WDM\AESTSr64.exe – (AESTFilters)
SRV - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/11 20:11:44 | 000,085,280 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/12/11 20:10:31 | 000,109,344 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2012/12/04 10:54:14 | 000,103,472 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe – (McAfee SiteAdvisor Service)
SRV - [2012/11/16 15:10:37 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/13 17:46:26 | 000,147,888 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\ramaint.exe – (LMIMaint)
SRV - [2012/11/12 15:46:10 | 000,375,728 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe – (LMIGuardianSvc)
SRV - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2010/11/08 10:04:18 | 000,407,424 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe – (LogMeIn)
SRV - [2010/09/02 22:45:02 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe – (McComponentHostService)
SRV - [2010/06/14 07:00:48 | 000,270,848 | —- | M] (Novatel Wireless Inc.) [Auto | Running] – C:\Program Files (x86)\Novatel Wireless\Verizon\Drivers\NWHelper_001.exe – (NWVZHelper)
SRV - [2010/03/18 10:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS)
SRV - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS)
SRV - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe – (PDFProFiltSrv)
SRV - [2009/06/10 13:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 16:07:28 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/11 20:12:07 | 000,129,216 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avipbb.sys – (avipbb)
DRV:64bit: - [2012/12/11 20:12:06 | 000,099,912 | —- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/11/14 17:38:20 | 000,040,712 | —- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss6.sys – (taphss6)
DRV:64bit: - [2012/11/13 14:44:32 | 000,015,712 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\SWDUMon.sys – (SWDUMon)
DRV:64bit: - [2012/11/12 15:46:12 | 000,088,008 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\Windows\SysNative\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV:64bit: - [2012/10/19 16:04:09 | 004,747,328 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2012/09/24 08:58:11 | 000,027,800 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/08/01 10:13:40 | 000,038,632 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:64bit: - [2012/05/19 14:10:42 | 000,275,648 | —- | M] (LotSoft, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys – (DigiartyVirtualCDBus)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/22 08:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 13:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/05/13 18:58:16 | 000,030,008 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2011/05/13 18:57:58 | 000,043,320 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 01:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/09/22 20:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/07/08 06:52:32 | 000,256,512 | —- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NWADIenum.sys – (NWADI)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbser2_000.sys – (NWUSBPort2_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbser_000.sys – (NWUSBPort_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbmdm_000.sys – (NWUSBModem_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,025,600 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NwUsbCdFil64.sys – (NWUSBCDFIL64)
DRV:64bit: - [2010/05/27 22:32:56 | 000,320,560 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/01/27 09:22:02 | 000,072,216 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV:64bit: - [2010/01/27 09:21:36 | 000,011,552 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lmimirr.sys – (lmimirr)
DRV:64bit: - [2009/12/07 03:53:26 | 000,117,504 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbmdm.sys – (hwdatacard)
DRV:64bit: - [2009/12/07 03:36:48 | 000,246,224 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbnet.sys – (ewusbnet)
DRV:64bit: - [2009/09/26 07:42:58 | 000,233,984 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64)
DRV:64bit: - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/07/30 19:58:42 | 000,236,544 | —- | M] (Realtek ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/29 10:17:00 | 000,070,656 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\enecir.sys – (enecir)
DRV:64bit: - [2009/06/10 13:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 13:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 13:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 12:35:33 | 000,389,120 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/06/10 12:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV:64bit: - [1999/12/31 16:00:00 | 007,770,048 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [1999/12/31 16:00:00 | 000,568,640 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [1999/12/31 16:00:00 | 000,536,064 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV - [2010/01/27 09:22:02 | 000,015,928 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys – (LMIInfo)
DRV - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/07/13 17:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2008/07/26 22:30:36 | 000,014,544 | —- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\BatteryCare\WinRing0x64.sys – (WinRing0_1_2_0)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\.DEFAULT\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-18\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,defaultscope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}

IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes\{DAE550AF-EBC5-406C-8E30-B524825B0B46}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/11/27 15:49:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/26 13:33:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/12/12 16:55:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/01/25 12:20:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions
[2012/12/03 18:43:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/01/25 12:20:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 10:44:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/23 17:50:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 10:18:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2012/07/14 12:03:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/08/30 23:15:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/10/19 22:01:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/05/10 14:21:18 | 000,002,024 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

========== Chrome ==========

CHR - homepage: http://www.my.yahoo.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.my.yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Zeon Plus (Enabled) = C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Adblock Plus = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFProfessional-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [BatteryCare] C:\Program Files (x86)\BatteryCare\BatteryCare.exe (Filipe Lourenço)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [Octoshape Streaming Services] C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [OpAgent] "OpAgent.exe" /agent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8:64bit: - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O9:64bit: - Extra Button: PDFill PDF Editor - {ED93D107-B43A-490e-AA5C-C5578BAAF479} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{382CECE5-D5A4-432B-83D7-AB14CE7F9FCC}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell - "" = AutoRun
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell - "" = AutoRun
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell - "" = AutoRun
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\VZAccess_Manager.exe /z detect
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/02/05 13:17:00 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/30 15:45:45 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\BatteryCare
[2013/01/28 13:31:43 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/28 13:31:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/28 13:31:02 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Programs
[2013/01/25 11:34:23 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/25 11:34:18 | 000,000,000 | —D | C] – C:\JRT
[2013/01/24 12:43:24 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Burgomeister
[2013/01/15 14:34:04 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Computer stuff & Troubleshooting
[2013/01/14 15:23:31 | 000,000,000 | -HSD | C] – C:\found.000
[2009/05/28 22:47:08 | 001,821,008 | —- | C] (Microsoft Corporation) – C:\Program Files\instmsiw.exe

========== Files - Modified Within 30 Days ==========

[2013/02/11 14:43:00 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000UA.job
[2013/02/11 14:33:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/11 14:19:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 14:19:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/11 14:12:04 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/11 14:11:35 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2013/02/11 14:11:30 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/11 14:11:22 | 3063,046,144 | -HS- | M] () – C:\hiberfil.sys
[2013/02/10 13:10:18 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2013/02/08 12:42:37 | 000,022,197 | —- | M] () – C:\Users\Jim\Desktop\It's night time in the big city.odt
[2013/02/07 00:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000Core.job
[2013/01/30 15:45:41 | 000,001,043 | —- | M] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/30 13:12:13 | 457,681,826 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/28 13:31:44 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/25 15:43:05 | 002,720,770 | —- | M] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/15 16:56:10 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/01/15 16:56:07 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2013/01/15 16:53:05 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/01/15 16:53:01 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/01/15 16:52:55 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/14 15:26:35 | 000,010,120 | —- | M] () – C:\bootsqm.dat

========== Files Created - No Company Name ==========

[2013/01/30 15:45:41 | 000,001,043 | —- | C] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/28 13:31:44 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/25 15:43:04 | 002,720,770 | —- | C] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/14 15:26:35 | 000,010,120 | —- | C] () – C:\bootsqm.dat
[2012/11/06 16:17:14 | 000,870,544 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2012/11/06 16:17:14 | 000,050,028 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2012/06/14 15:38:47 | 000,000,505 | —- | C] () – C:\Windows\cdplayer.ini
[2012/06/14 15:31:58 | 000,001,534 | —- | C] () – C:\ProgramData\ss.ini
[2011/05/25 19:01:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/04/16 17:11:41 | 000,000,032 | —- | C] () – C:\Windows\DICapture.INI
[2011/02/02 12:36:10 | 000,001,854 | —- | C] () – C:\Users\Jim\AppData\Roaming\GhostObjGAFix.xml
[2010/06/16 11:16:05 | 000,000,000 | —- | C] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2010/06/09 10:40:09 | 000,001,026 | —- | C] () – C:\Users\Jim\Pictures - Shortcut.lnk
[2010/05/28 14:30:22 | 000,389,363 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.JPG
[2010/05/28 14:30:21 | 000,391,040 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.0
[2010/05/27 17:04:11 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/05/28 22:47:08 | 000,000,313 | —- | C] () – C:\Program Files\setup.ini

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 04:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< MD5 for: EXPLORER.EXE >
[2009/11/27 14:19:58 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/11/27 14:19:58 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2009/08/02 22:19:07 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/02 21:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/02 21:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2009/11/27 14:19:58 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/02 22:17:37 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2009/11/27 14:19:58 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SysWOW64\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: ST9500420AS
Partitions: 4
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 199.00MB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 452.00GB
Starting Offset: 209715200
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 13.00GB
Starting Offset: 485914312704
Hidden sectors: 0


DeviceID: Disk #0, Partition #3
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 103.00MB
Starting Offset: 499998785536
Hidden sectors: 0


========== Alternate Data Streams ==========

@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:9B013599
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:527B6DAD

< End of report >


__________________________________



aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software
Run date: 2013-02-11 15:40:09
—————————–
15:40:09.720 OS Version: Windows x64 6.1.7601 Service Pack 1
15:40:09.720 Number of processors: 4 586 0x2502
15:40:09.721 ComputerName: JIM-PC UserName: Jim
15:40:15.420 Initialize success
15:40:23.514 AVAST engine download error: 0
15:40:48.497 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
15:40:48.502 Disk 0 Vendor: ST950042 0006 Size: 476940MB BusType: 3
15:40:48.518 Disk 0 MBR read successfully
15:40:48.522 Disk 0 MBR scan
15:40:48.525 Disk 0 unknown MBR code
15:40:48.533 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
15:40:48.544 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 463204 MB offset 409600
15:40:48.579 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 13432 MB offset 949051392
15:40:48.625 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 103 MB offset 976560128
15:40:48.658 Disk 0 scanning C:\Windows\system32\drivers
15:41:01.419 Service scanning
15:41:27.852 Modules scanning
15:41:27.864 Disk 0 trace - called modules:
15:41:28.212 ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys iaStor.sys hal.dll
15:41:28.219 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8006e6e060]
15:41:28.225 3 CLASSPNP.SYS[fffff8800109243f] -> nt!IofCallDriver -> [0xfffffa8004ab6b10]
15:41:28.232 5 hpdskflt.sys[fffff88002776189] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8004952050]
15:41:28.238 Scan finished successfully
15:42:02.142 Disk 0 MBR has been saved successfully to "C:\Users\Jim\Desktop\MBR.dat"
15:42:02.152 The log file has been saved successfully to "C:\Users\Jim\Desktop\aswMBR - 2013 02 11.txt"
OTL Extras log

You didn’t get an Extras log because that is the fourth time you’ve run OTL. :)
  • open OTL again, click on Extra Registry -> Use Safelist
  • then click Run Scan
You should now get an Extras log.

satchfan
Here we go, this is it - the Extras log:



OTL logfile created on: 2/12/2013 4:29:50 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jim\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.01 Gb Available Physical Memory | 52.82% Memory free
7.61 Gb Paging File | 5.41 Gb Available in Paging File | 71.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.35 Gb Total Space | 327.90 Gb Free Space | 72.49% Space Free | Partition Type: NTFS
Drive D: | 13.12 Gb Total Space | 2.18 Gb Free Space | 16.65% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2013/02/11 14:58:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jim\Downloads\OTL.exe
PRC - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/12/11 20:11:44 | 000,085,280 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/12/11 20:10:31 | 000,109,344 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2012/12/11 20:10:29 | 000,384,800 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/08/29 13:51:48 | 001,061,960 | R— | M] (Carbonite, Inc.) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2012/08/13 09:57:02 | 010,376,704 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
PRC - [2012/08/13 09:57:02 | 010,368,512 | —- | M] (OpenOffice.org) – C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
PRC - [2011/03/24 07:11:18 | 000,107,800 | —- | M] (Octoshape ApS) – C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/09/02 22:45:02 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe
PRC - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
PRC - [2009/10/05 23:08:42 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe
PRC - [1999/12/31 16:00:00 | 000,284,480 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [1999/09/30 18:31:38 | 000,869,376 | —- | M] (Fred's Software) – C:\Program Files (x86)\PrintKey2000\Printkey2000.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/06 15:10:57 | 012,459,888 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\User Data\PepperFlash\11.5.31.139\pepflashplayer.dll
MOD - [2013/01/25 18:35:06 | 000,460,240 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppgooglenaclpluginchrome.dll
MOD - [2013/01/25 18:35:04 | 004,012,496 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
MOD - [2013/01/25 18:34:19 | 000,597,968 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\libglesv2.dll
MOD - [2013/01/25 18:34:18 | 000,124,368 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\libegl.dll
MOD - [2013/01/25 18:34:16 | 001,552,848 | —- | M] () – C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\ffmpegsumo.dll
MOD - [2013/01/08 21:21:08 | 000,489,472 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\8511eac49521cf5fa810ec3367c40cab\IAStorUtil.ni.dll
MOD - [2013/01/08 21:21:08 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5d918739168186b055c86a63123a1a30\IAStorCommon.ni.dll
MOD - [2013/01/08 16:03:36 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll
MOD - [2013/01/08 16:03:20 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/08 16:03:18 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/08 16:03:05 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\865d2bf19a7af7fab8660a42d92550fe\System.Windows.Forms.ni.dll
MOD - [2013/01/08 16:02:58 | 001,592,832 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/08 16:02:18 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll
MOD - [2013/01/08 16:02:15 | 007,989,760 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/08 16:02:10 | 011,493,376 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012/08/10 15:51:32 | 000,985,088 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll
MOD - [2012/08/10 15:50:56 | 000,170,496 | —- | M] () – C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll
MOD - [2010/03/11 10:35:14 | 000,126,976 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanProcess.dll
MOD - [2010/03/05 10:51:54 | 000,143,360 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\Scan.dll
MOD - [2010/02/06 05:12:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FilingRes.dll
MOD - [2010/02/02 11:51:00 | 000,077,824 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanRes.dll
MOD - [2010/02/02 11:51:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManagerRes.dll
MOD - [2010/01/14 11:22:06 | 000,094,208 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\PDF.dll
MOD - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
MOD - [2009/12/21 10:41:22 | 000,086,109 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManager.dll
MOD - [2009/12/21 10:41:14 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\AmCommonLib.dll
MOD - [2009/10/05 23:08:38 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2009/08/07 02:47:06 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuRes.dll
MOD - [2009/06/25 07:00:06 | 000,897,024 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\EncryptPdf.dll
MOD - [2008/08/27 14:58:38 | 000,045,056 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFillRsc.dll
MOD - [2008/06/02 08:27:08 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFill.dll
MOD - [2006/05/15 12:24:18 | 000,122,938 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\CommonFunc.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/08/29 13:43:58 | 006,742,088 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe – (CarboniteService)
SRV:64bit: - [2012/07/11 10:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2011/05/13 18:58:10 | 000,030,520 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2010/09/22 14:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [1999/12/31 16:00:00 | 000,314,880 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [1999/12/31 16:00:00 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Program Files\IDT\WDM\AESTSr64.exe – (AESTFilters)
SRV - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/11 20:11:44 | 000,085,280 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/12/11 20:10:31 | 000,109,344 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2012/12/04 10:54:14 | 000,103,472 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe – (McAfee SiteAdvisor Service)
SRV - [2012/11/16 15:10:37 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/13 17:46:26 | 000,147,888 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\ramaint.exe – (LMIMaint)
SRV - [2012/11/12 15:46:10 | 000,375,728 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe – (LMIGuardianSvc)
SRV - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2010/11/08 10:04:18 | 000,407,424 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe – (LogMeIn)
SRV - [2010/09/02 22:45:02 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe – (McComponentHostService)
SRV - [2010/06/14 07:00:48 | 000,270,848 | —- | M] (Novatel Wireless Inc.) [Auto | Running] – C:\Program Files (x86)\Novatel Wireless\Verizon\Drivers\NWHelper_001.exe – (NWVZHelper)
SRV - [2010/03/18 10:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS)
SRV - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS)
SRV - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe – (PDFProFiltSrv)
SRV - [2009/06/10 13:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 16:07:28 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/11 20:12:07 | 000,129,216 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avipbb.sys – (avipbb)
DRV:64bit: - [2012/12/11 20:12:06 | 000,099,912 | —- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/11/14 17:38:20 | 000,040,712 | —- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss6.sys – (taphss6)
DRV:64bit: - [2012/11/13 14:44:32 | 000,015,712 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\SWDUMon.sys – (SWDUMon)
DRV:64bit: - [2012/11/12 15:46:12 | 000,088,008 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\Windows\SysNative\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV:64bit: - [2012/10/19 16:04:09 | 004,747,328 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2012/09/24 08:58:11 | 000,027,800 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/08/01 10:13:40 | 000,038,632 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:64bit: - [2012/05/19 14:10:42 | 000,275,648 | —- | M] (LotSoft, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys – (DigiartyVirtualCDBus)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/22 08:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 13:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/05/13 18:58:16 | 000,030,008 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2011/05/13 18:57:58 | 000,043,320 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 01:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/09/22 20:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/07/08 06:52:32 | 000,256,512 | —- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NWADIenum.sys – (NWADI)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nwusbser2_000.sys – (NWUSBPort2_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nwusbser_000.sys – (NWUSBPort_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\nwusbmdm_000.sys – (NWUSBModem_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,025,600 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NwUsbCdFil64.sys – (NWUSBCDFIL64)
DRV:64bit: - [2010/05/27 22:32:56 | 000,320,560 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/01/27 09:22:02 | 000,072,216 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV:64bit: - [2010/01/27 09:21:36 | 000,011,552 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lmimirr.sys – (lmimirr)
DRV:64bit: - [2009/12/07 03:53:26 | 000,117,504 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbmdm.sys – (hwdatacard)
DRV:64bit: - [2009/12/07 03:36:48 | 000,246,224 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbnet.sys – (ewusbnet)
DRV:64bit: - [2009/09/26 07:42:58 | 000,233,984 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64)
DRV:64bit: - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/07/30 19:58:42 | 000,236,544 | —- | M] (Realtek ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/29 10:17:00 | 000,070,656 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\enecir.sys – (enecir)
DRV:64bit: - [2009/06/10 13:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 13:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 13:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 12:35:33 | 000,389,120 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/06/10 12:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV:64bit: - [1999/12/31 16:00:00 | 007,770,048 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [1999/12/31 16:00:00 | 000,568,640 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [1999/12/31 16:00:00 | 000,536,064 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV - [2010/01/27 09:22:02 | 000,015,928 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys – (LMIInfo)
DRV - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/07/13 17:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2008/07/26 22:30:36 | 000,014,544 | —- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\BatteryCare\WinRing0x64.sys – (WinRing0_1_2_0)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searcisor\mcieplg.dll
IE - HKCU\..\SearchScopes\{DAE550AF-EBC5-406C-8E30-B524825B0B46}: "URL" = http://search.yahoo.com/search?fr=mcafee&p;={SearchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/11/27 15:49:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/26 13:33:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/12/12 16:55:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/01/25 12:20:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions
[2012/12/03 18:43:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/01/25 12:20:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 10:44:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/23 17:50:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 10:18:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2012/07/14 12:03:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/08/30 23:15:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/10/19 22:01:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/05/10 14:21:18 | 000,002,024 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

========== Chrome ==========

CHR - homepage: http://www.my.yahoo.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.my.yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Zeon Plus (Enabled) = C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Adblock Plus = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFProfessional-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKCU..\Run: [BatteryCare] C:\Program Files (x86)\BatteryCare\BatteryCare.exe (Filipe Lourenço)
O4 - HKCU..\Run: [Octoshape Streaming Services] C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKCU..\Run: [OpAgent] "OpAgent.exe" /agent File not found
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8:64bit: - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O9:64bit: - Extra Button: PDFill PDF Editor - {ED93D107-B43A-490e-AA5C-C5578BAAF479} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{382CECE5-D5A4-432B-83D7-AB14CE7F9FCC}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{61855E5F-84D8-4B3C-95A8-13CA19ABEE04}: NameServer = 198.224.173.135 198.224.174.135
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell - "" = AutoRun
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell - "" = AutoRun
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell - "" = AutoRun
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\VZAccess_Manager.exe /z detect
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/05 13:17:00 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/30 15:45:45 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\BatteryCare
[2013/01/28 13:31:43 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/28 13:31:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/28 13:31:02 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Programs
[2013/01/25 11:34:23 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/25 11:34:18 | 000,000,000 | —D | C] – C:\JRT
[2013/01/24 12:43:24 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Burgomeister
[2013/01/15 14:34:04 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Computer stuff & Troubleshooting
[2013/01/14 15:23:31 | 000,000,000 | -HSD | C] – C:\found.000
[2009/05/28 22:47:08 | 001,821,008 | —- | C] (Microsoft Corporation) – C:\Program Files\instmsiw.exe

========== Files - Modified Within 30 Days ==========

[2013/02/12 16:33:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/12 15:43:01 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000UA.job
[2013/02/12 14:52:28 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/12 14:52:28 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/12 14:45:19 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/12 14:44:55 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2013/02/12 14:44:50 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/12 14:44:43 | 3063,046,144 | -HS- | M] () – C:\hiberfil.sys
[2013/02/11 15:42:02 | 000,000,512 | —- | M] () – C:\Users\Jim\Desktop\MBR.dat
[2013/02/10 13:10:18 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2013/02/08 12:42:37 | 000,022,197 | —- | M] () – C:\Users\Jim\Desktop\It's night time in the big city.odt
[2013/02/07 00:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000Core.job
[2013/01/30 15:45:41 | 000,001,043 | —- | M] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/30 13:12:13 | 457,681,826 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/28 13:31:44 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/25 15:43:05 | 002,720,770 | —- | M] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/15 16:56:10 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/01/15 16:56:07 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2013/01/15 16:53:05 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/01/15 16:53:01 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/01/15 16:52:55 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/14 15:26:35 | 000,010,120 | —- | M] () – C:\bootsqm.dat

========== Files Created - No Company Name ==========

[2013/02/11 15:42:02 | 000,000,512 | —- | C] () – C:\Users\Jim\Desktop\MBR.dat
[2013/01/30 15:45:41 | 000,001,043 | —- | C] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/28 13:31:44 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/25 15:43:04 | 002,720,770 | —- | C] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/14 15:26:35 | 000,010,120 | —- | C] () – C:\bootsqm.dat
[2012/11/06 16:17:14 | 000,870,544 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2012/11/06 16:17:14 | 000,050,028 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2012/06/14 15:38:47 | 000,000,505 | —- | C] () – C:\Windows\cdplayer.ini
[2012/06/14 15:31:58 | 000,001,534 | —- | C] () – C:\ProgramData\ss.ini
[2011/05/25 19:01:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/04/16 17:11:41 | 000,000,032 | —- | C] () – C:\Windows\DICapture.INI
[2011/02/02 12:36:10 | 000,001,854 | —- | C] () – C:\Users\Jim\AppData\Roaming\GhostObjGAFix.xml
[2010/06/16 11:16:05 | 000,000,000 | —- | C] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2010/06/09 10:40:09 | 000,001,026 | —- | C] () – C:\Users\Jim\Pictures - Shortcut.lnk
[2010/05/28 14:30:22 | 000,389,363 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.JPG
[2010/05/28 14:30:21 | 000,391,040 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.0
[2010/05/27 17:04:11 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/05/28 22:47:08 | 000,000,313 | —- | C] () – C:\Program Files\setup.ini

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:9B013599
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:527B6DAD

< End of report >
So that log I just sent you wasn't really the Extras log? It was the OTL log?
Well, hopefully I got it right this time, & here is the actual Extras log:



OTL Extras logfile created on: 2/12/2013 4:29:50 PM - Run 5
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jim\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.01 Gb Available Physical Memory | 52.82% Memory free
7.61 Gb Paging File | 5.41 Gb Available in Paging File | 71.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.35 Gb Total Space | 327.90 Gb Free Space | 72.49% Space Free | Partition Type: NTFS
Drive D: | 13.12 Gb Total Space | 2.18 Gb Free Space | 16.65% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.reg [@ = Regedit.Document] – c:\Winnt\Regedit.exe %1

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.reg [@ = Regedit.Document] – c:\Winnt\Regedit.exe %1

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0213738B-F1D9-4817-9090-FA788724F5B4}" = lport=2869 | protocol=6 | dir=in | app=system |
"{0D5D52D9-8F36-403C-BCBD-3B37BE88FEA6}" = rport=138 | protocol=17 | dir=out | app=system |
"{111A807A-9D6A-4043-A4BA-018FBBE52115}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{28149F58-B651-4AED-B602-C36DB405A461}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{2B469322-64C7-4030-B2A0-3761D3A767D4}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{42F80BF8-4498-42C5-B56B-AAF5559C8F0E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{4D2013EB-2AEC-4A2C-B9D7-9BC3475CC3AD}" = rport=137 | protocol=17 | dir=out | app=system |
"{58344D84-838E-438D-9DF5-075C1D5ED0A6}" = rport=445 | protocol=6 | dir=out | app=system |
"{6531368C-12FF-4022-8693-5C68F53AD6D3}" = lport=139 | protocol=6 | dir=in | app=system |
"{65C1C547-0583-4E70-A79A-CA83C2E3CC90}" = lport=445 | protocol=6 | dir=in | app=system |
"{70B0D51F-1B91-47C5-9443-657C95FEAB0E}" = lport=137 | protocol=17 | dir=in | app=system |
"{835DAB16-6FFD-4717-9282-DF3719C314E6}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9D577D26-49D7-4F8E-B308-AAD64512C7EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{9FE7642F-529C-4478-91CA-431F2121C60A}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{B81531CF-3771-46E3-B1CC-52AB469791EB}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{FA2AA4B0-503E-467C-9FE7-1AD848BCDE53}" = lport=138 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{032DE89F-3D30-4931-8557-D9AF0E976E9A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{041378EF-5F4F-4F4D-8686-3D287EBE790B}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe |
"{0DAAFA40-2D78-4AAE-AB26-8706A65BA8C6}" = protocol=17 | dir=in | app=c:\program files (x86)\verizon wireless\vzaccess manager\vzaccess manager.exe |
"{12DA9B41-62EF-4CC9-8823-B37794C673E5}" = protocol=17 | dir=in | app=c:\program files (x86)\verizon wireless\firmware updates\novatel\duu_verizon_usb760_fw167.029.exe |
"{2A8FAB7B-0EFE-4BC3-9E6F-22C7A307914B}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{2B0C1B9B-EB10-4341-B6E2-F98656CA2285}" = protocol=17 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{3BC2456C-7D46-4E5C-BB99-272502F58CF2}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\kernel\clml\clmlsvc.exe |
"{3BD98A76-A539-4730-8E86-935C8463A972}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo! mail download multiple emails to text files software\yahoo! mail download multiple emails to text files software.exe |
"{4E52999B-7425-4CC3-A4D6-EA7954129615}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe |
"{54F581FE-B4DE-4110-9037-1C1F0A9DEDC0}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{5BB38C44-D16F-4427-B0B5-32F5CB81CC25}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartmusic.exe |
"{63AA1A9B-20E0-4E43-9D0A-C742BEDC02EB}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{706EE022-656F-4150-9A81-5953C7450567}" = protocol=6 | dir=in | app=c:\program files (x86)\verizon wireless\vzaccess manager\vzaccess manager.exe |
"{70B8C24F-AC57-4388-8FE9-6BEFCB5A91DA}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\live tv\qp.exe |
"{7AA07C30-B6D4-4529-B033-8F3330703CBE}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe |
"{97203400-121B-4F87-9A13-FE2048E20E5E}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{982D8F78-E21C-4148-A9FB-F9FC0C36160F}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A0E3C074-6F6B-4601-AB67-964F77D310D9}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\live tv\qpservice.exe |
"{B74BA44B-840D-4567-97A2-5621A32C6855}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B77541B3-E2F9-4C84-9F07-C82844B9FDD9}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{B78A2161-2459-4FF3-AD75-92BF95A22E14}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartphoto.exe |
"{C2086898-715B-4377-ADF3-6D1B284D8A1C}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe |
"{C72846FF-1E03-4FFE-8063-E064E860D3F4}" = protocol=6 | dir=in | app=c:\program files (x86)\verizon wireless\firmware updates\novatel\duu_verizon_usb760_fw167.029.exe |
"{C973A4CE-4112-484F-A3FE-A0BA800AA189}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\tsmagent.exe |
"{D631DC01-B62B-4513-9693-FC3E05D4C071}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hptouchsmartvideo.exe |
"{DE000386-50AD-462A-B142-AE786F655F5A}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe |
"{E6EE8CEB-9B7F-4E63-9AAD-6AFD2AE630BB}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo! mail download multiple emails to text files software\yahoo! mail download multiple emails to text files software.exe |
"{FCAD7EB0-2241-468E-9B9A-321050DAA530}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{FCB5D852-E36D-47F2-86AB-660D3AB3A3FF}" = protocol=6 | dir=in | app=c:\program files (x86)\windows ilivid toolbar\datamngr\toolbar\dtuser.exe |
"{FD59BA48-5D34-4D1F-9EEE-8E893AE85BF9}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"TCP Query User{30F495B8-0C6B-469F-9A13-951766D3933C}C:\users\jim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=6 | dir=in | app=c:\users\jim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |
"TCP Query User{40330D42-BEB9-45CB-8F7A-67C4B1DFA3EE}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"TCP Query User{4AE0CBC9-366D-408F-A8E8-91C2A61725B0}C:\program files (x86)\1clickdownload\1clickdownload.exe" = protocol=6 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownload.exe |
"TCP Query User{91D891EA-B75E-4924-8055-83E6D7E4CAC3}C:\users\jim\appdata\local\google\chrome\application\chrome.exe" = protocol=6 | dir=in | app=c:\users\jim\appdata\local\google\chrome\application\chrome.exe |
"UDP Query User{0A3D3400-4318-4B00-8C5F-5E78F7AE35AA}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"UDP Query User{18819ED3-FB48-400C-917B-6A72A363DD47}C:\program files (x86)\1clickdownload\1clickdownload.exe" = protocol=17 | dir=in | app=c:\program files (x86)\1clickdownload\1clickdownload.exe |
"UDP Query User{45399FC9-A01D-47EE-94FD-1366FCD24809}C:\users\jim\appdata\local\google\chrome\application\chrome.exe" = protocol=17 | dir=in | app=c:\users\jim\appdata\local\google\chrome\application\chrome.exe |
"UDP Query User{CC1D65ED-B9A0-48E0-A0BE-945B95C1501A}C:\users\jim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe" = protocol=17 | dir=in | app=c:\users\jim\appdata\roaming\octoshape\octoshape streaming services\octoshapeclient.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{713D2C50-6D57-4107-BD41-2F553D9A50BB}" = Nuance PDF Professional 6
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{88E60521-1E4E-4785-B9F1-1798A4BD0C30}" = HP MediaSmart SmartMenu
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{D1399216-81B2-457C-A0F7-73B9A2EF6902}" = PDFill PDF Editor with FREE Writer and FREE Tools
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"E3F691F05CED909CB0C875FCB3045BE22A677287" = Windows Driver Package - Plustek Image (05/02/2007 2.0.0.0)
"FFE7D41DF3C645075BB149E21988B63996C34187" = ENE CIR Receiver Driver
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}" = Scansoft PDF Professional
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{14D08502-FEE4-40E5-90D3-8A967A1D8BA2}" = Readiris Pro 10 Corporate Edition
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{1747DF05-6890-440B-B094-2146F5DC50E0}" = HP MediaSmart SlingPlayer
"{17B4760F-334B-475D-829F-1A3E94A6A4E6}" = HP Setup
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2070AC73-FC3D-4391-AB3B-A1229DFA2761}" = Nuance OmniPage 17
"{22443966-38F8-8A4D-AA16-0FBFA246881F}" = Acrobat.com
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 39
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{34F93E31-E1A0-421C-8E86-BCF7C4193A91}" = LogMeIn
"{35021DFB-F9CA-402A-89A2-47F91E506465}" = HP MediaSmart/TouchSmart Netflix
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40378052-5E6C-4C45-83EC-A56D085CB256}" = Plustek OpticBook 4600
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{4475560E-9418-4908-A158-472D873AE139}" = LogMeIn
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{47D7C9B8-BD44-4D2E-9040-E946477B2F9A}" = Microsoft Live Search Toolbar
"{49A143E9-4A6A-43E7-86B1-388194C79248}" = HP Smart Web Printing
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{501451DE-5808-4599-B544-8BD0915B6B24}_is1" = FreeRIP3 3.70
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{54CC7901-804D-4155-B353-21F0CC9112AB}" = HP Wireless Assistant
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{780F9A1C-6BFE-4691-83A9-095D859E3052}" = VZAccess Manager
"{783033B0-D8E6-11D5-9293-0050BA073EEC}" = Presto! ImageFolio 4
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7A21C722-F259-4976-B7AA-6658E5FDEDAF}" = Google Drive
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{82A213BD-B6AA-4281-A2D3-59D51893CC56}" = HP MediaSmart Software Notebook Demo
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9945E868-8992-4776-905E-C4B2B43FCA4F}" = Zimbra Desktop
"{99D5EF59-CF6F-4030-901B-4DDDB7F99403}" = Presto! PageManager 7.10
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.5)
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B51605BF-6326-4553-AE96-6D7F1813D5F5}" = HP User Guides 0154
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6A6036D-FBD0-4324-BEAA-C0845257160C}_is1" = BatteryCare 0.9.12.1
"{CAC2CF93-B532-4A88-81FE-110750C3E4BA}" = Verizon Wireless USB760 Firmware Updates
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C3}" = WinZip 15.5
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D07205E7-F6D3-4333-AFCC-782A07685B72}" = OverDrive Media Console
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D46D081B-F60E-467E-A7C4-117B70D76731}" = HP Update
"{D8DFA46A-39F7-4368-810D-18AFCFDDAEAF}" = Adobe Shockwave Player
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF802C05-4660-418c-970C-B988ADB1D316}" = Microsoft Live Search Toolbar
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E503B4BF-F7BB-3D5F-8BC8-F694B1CFF942}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022.218
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"{E92D47A1-D27D-430A-8368-0BAFD956507D}" = HP Support Assistant
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F19553C5-F843-4C27-BF9F-9DE4D901B895}" = Verizon Mobile Broadband Drivers
"{F1D7AC58-554A-4A58-B784-B61558B1449A}" = QLBCASL
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 4.57
"Acer 3G Connection Manager" = Acer 3G Connection Manager
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"BN_DesktopReader" = NOOK for PC
"Carbonite Backup" = Carbonite
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Digital Editions" = Adobe Digital Editions
"ffdshow_is1" = ffdshow [rev 2527] [2008-12-19]
"HandBrake" = HandBrake 0.9.6
"HP Smart Web Printing" = HP Smart Web Printing
"HUAWEI DataCard Driver" = HUAWEI DataCard Driver 3.10.00.00
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{67626E09-5366-4480-8F1E-93FADF50CA15}" = HP MediaSmart Live TV
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{E553760D-D7F7-48BF-BD8B-C7E23BA04CB5}" = HP MediaSmart Internet TV
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"McAfee Security Scan" = McAfee Security Scan Plus
"Mozilla Thunderbird 17.0 (x86 en-GB)" = Mozilla Thunderbird 17.0 (x86 en-GB)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Picasa 3" = Picasa 3
"PrintKey2000" = PrintKey2000
"QuickLink Mobile" = QuickLink Mobile
"SimpleOCR 3.1" = SimpleOCR 3.1
"Vivitar Experience Image Manager" = Vivitar Experience Image Manager
"VLC media player" = VLC media player 2.0.4
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Mail Download Multiple Emails To Text Fil~56A3D419_is1" = Yahoo! Mail Download Multiple Emails To Text Files Software

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
"Octoshape Streaming Services" = Octoshape Streaming Services

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 2/10/2013 12:34:21 AM | Computer Name = Jim-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Host Process for Windows Services because of this error. Program:
Host Process for Windows Services File: The error value is listed in the Additional
Data section. User Action 1. Open the file again. This situation might be a temporary
problem that corrects itself when the program runs again. 2. If the file still cannot
be accessed and - It is on the network, your network administrator should verify
that there is not a problem with the network and that the server can be contacted.
-
It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the
disk is fully inserted into the computer. 3. Check and repair the file system by
running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click
OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem
persists, restore the file from a backup copy. 5. Determine whether other files
on the same disk can be opened. If not, the disk might be damaged. If it is a hard
disk, contact your administrator or computer hardware vendor for further assistance.

Additional
Data Error value: C00000B5 Disk type: 0

Error - 2/10/2013 5:54:14 PM | Computer Name = Jim-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Dwm.exe, version: 6.1.7600.16385, time
stamp: 0x4a5bc541 Faulting module name: dwmcore.dll, version: 6.1.7601.17514, time
stamp: 0x4ce7c62d Exception code: 0xc0000006 Fault offset: 0x000000000009a9a0 Faulting
process id: 0x974 Faulting application start time: 0x01ce07d300c4194a Faulting application
path: C:\Windows\system32\Dwm.exe Faulting module path: C:\Windows\system32\dwmcore.dll
Report
Id: 687058c8-73cc-11e2-a3e7-f0b3c3c9eddb

Error - 2/10/2013 5:54:14 PM | Computer Name = Jim-PC | Source = Application Error | ID = 1000
Description = Faulting application name: svchost.exe_WinDefend, version: 6.1.7600.16385,
time stamp: 0x4a5bc3c1 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000006 Fault offset: 0x00000000000253c9
Faulting
process id: 0x139c Faulting application start time: 0x01ce07d36e73c7fb Faulting application
path: C:\Windows\System32\svchost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 687317f2-73cc-11e2-a3e7-f0b3c3c9eddb

Error - 2/10/2013 5:54:14 PM | Computer Name = Jim-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Host Process for Windows Services because of this error. Program:
Host Process for Windows Services File: The error value is listed in the Additional
Data section. User Action 1. Open the file again. This situation might be a temporary
problem that corrects itself when the program runs again. 2. If the file still cannot
be accessed and - It is on the network, your network administrator should verify
that there is not a problem with the network and that the server can be contacted.
-
It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the
disk is fully inserted into the computer. 3. Check and repair the file system by
running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click
OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem
persists, restore the file from a backup copy. 5. Determine whether other files
on the same disk can be opened. If not, the disk might be damaged. If it is a hard
disk, contact your administrator or computer hardware vendor for further assistance.

Additional
Data Error value: C00000B5 Disk type: 0

Error - 2/10/2013 5:54:14 PM | Computer Name = Jim-PC | Source = Application Error | ID = 1005
Description = Windows cannot access the file C:\Windows\System32\dwmcore.dll for
one of the following reasons: there is a problem with the network connection, the
disk that the file is stored on, or the storage drivers installed on this computer;
or the disk is missing. Windows closed the program Desktop Window Manager because
of this error. Program: Desktop Window Manager File: C:\Windows\System32\dwmcore.dll

The
error value is listed in the Additional Data section. User Action 1. Open the file
again. This situation might be a temporary problem that corrects itself when the
program runs again. 2. If the file still cannot be accessed and - It is on the network,
your
network administrator should verify that there is not a problem with the network
and that the server can be contacted. - It is on a removable disk, for example,
a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3.
Check and repair the file system by running CHKDSK. To run CHKDSK, click Start,
click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F,
and then press ENTER. 4. If the problem persists, restore the file from a backup
copy. 5. Determine whether other files on the same disk can be opened. If not, the
disk might be damaged. If it is a hard disk, contact your administrator or computer
hardware vendor for further assistance. Additional Data Error value: C00000B5 Disk
type: 3

Error - 2/10/2013 6:52:45 PM | Computer Name = Jim-PC | Source = RasClient | ID = 20227
Description =

Error - 2/10/2013 6:52:57 PM | Computer Name = Jim-PC | Source = RasClient | ID = 20227
Description =

Error - 2/11/2013 9:18:46 PM | Computer Name = Jim-PC | Source = ESENT | ID = 604
Description = svchost (964) Locale ID 0x00000409 (English (United States) English)
is either invalid or not installed on this machine.

Error - 2/11/2013 11:13:43 PM | Computer Name = Jim-PC | Source = LogMeIn Guardian | ID = 131176
Description = LogMeIn Guardian has detected a problem with the LogMeIn software
installed on this machine. The problem is locally identified by the following reference
ID: 'ec2058620851efb9bb0604765c9491e9'.

Error - 2/12/2013 6:10:15 PM | Computer Name = Jim-PC | Source = RasClient | ID = 20227
Description =

[ Hewlett-Packard Events ]
Error - 3/21/2012 6:38:24 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\031221033806.xml
File not created by asset agent

Error - 5/2/2012 4:34:37 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\051202013432.xml
File not created by asset agent

Error - 5/16/2012 4:20:21 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\051216012018.xml
File not created by asset agent

Error - 5/16/2012 4:22:33 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\051216012231.xml
File not created by asset agent

Error - 5/30/2012 5:45:26 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\051230024523.xml
File not created by asset agent

Error - 6/20/2012 5:48:01 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061220024755.xml
File not created by asset agent

Error - 7/4/2012 6:21:36 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\071204032132.xml
File not created by asset agent

Error - 9/5/2012 5:16:10 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091205021606.xml
File not created by asset agent

Error - 9/12/2012 5:28:51 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091212022848.xml
File not created by asset agent

Error - 9/19/2012 5:14:50 PM | Computer Name = Jim-PC | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091219021447.xml
File not created by asset agent

[ System Events ]
Error - 2/12/2013 6:45:06 PM | Computer Name = Jim-PC | Source = Microsoft-Windows-Kernel-General | ID = 5
Description =

Error - 2/12/2013 7:09:32 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:33 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:34 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:35 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:36 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:37 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:38 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:39 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.

Error - 2/12/2013 7:09:40 PM | Computer Name = Jim-PC | Source = iaStor | ID = 262153
Description = The device, \Device\Ide\iaStor0, did not respond within the timeout
period.


< End of report >
Still nothing bad showing up but a few unwanted entries.

Note: If you have MalwareBytes Anti-Malware 1.6 or higher installed and are using the Pro version or trial version, please temporarily disable it for the duration of this fix as it may interfere with the successfully execution of the script below.

Run OTL
  • double click on the icon to run it.
  • copy/paste ALL the following text written inside the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :OTL
    IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes\{DAE550AF-EBC5-406C-8E30-B524825B0B46}: "URL" = http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
    @Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:9B013599
    @Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:527B6DAD
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
    "{2B0C1B9B-EB10-4341-B6E2-F98656CA2285}" =-
    "{FCB5D852-E36D-47F2-86AB-660D3AB3A3FF}" =- 
    
    :Files
    ipconfig /flushdns /c
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]

  • click the Run Fix button at the top
  • let the program run unhindered, reboot when it is done
  • please post a new OTL log and the OTL fix log
===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
Logs to include in the next post:

OTL fix log
New OTL log
AdwCleaner


Can you tell me the remaining problem(s)

Satchfan
I did the OTL fix, but when I clicked on reboot, it rebooted, & then the Welcome screen stayed on for around 5 minutes, then the screen went dark - had to turn off the computer. Turned on the computer & it went to the Welcome screen for 5 minutes, then went dark again, so I turned it off. Do I need to be guided on how to use Safe Mode to turn on my computer at this point? Am using an internet computer at the library to send this to you.
False alarm. When I got back to my laptop, after using the library internet computer, there was a 'box' in the middle of the dark screen - it was asking me if I want to run OTL, so I clicked yes, & then the OTL Fix log came up, & my computer was back on. So all is well. Now I'm going to get to the other 2 logs, & send all 3 to you.
All the random freezing that has been happening for weeks, happened last night, so it was still present, as of last night. I'm going to see what today & tomorrow bring.

Here are the 3 logs in the order that I did them:

OTL fix log
AdwClean log
OTL log



All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-1396301682-2749084838-641560585-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DAE550AF-EBC5-406C-8E30-B524825B0B46}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DAE550AF-EBC5-406C-8E30-B524825B0B46}\ not found.
ADS C:\ProgramData\Temp:9B013599 deleted successfully.
ADS C:\ProgramData\Temp:527B6DAD deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2B0C1B9B-EB10-4341-B6E2-F98656CA2285} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2B0C1B9B-EB10-4341-B6E2-F98656CA2285}\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FCB5D852-E36D-47F2-86AB-660D3AB3A3FF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FCB5D852-E36D-47F2-86AB-660D3AB3A3FF}\ not found.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Jim\Downloads\cmd.bat deleted successfully.
C:\Users\Jim\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!

[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Flash cache emptied: 0 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Jim
->Flash cache emptied: 62 bytes

User: Public

User: TEMP

User: TEMP.Jim-PC
->Flash cache emptied: 0 bytes

User: TEMP.Jim-PC.000

User: TEMP.Jim-PC.001

User: TEMP.Jim-PC.002

User: TEMP.Jim-PC.003

Total Flash Files Cleaned = 0.00 mb


[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Jim
->Temp folder emptied: 1514751 bytes
->Temporary Internet Files folder emptied: 15287611 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 8641475 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: TEMP
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: TEMP.Jim-PC
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: TEMP.Jim-PC.000

User: TEMP.Jim-PC.001

User: TEMP.Jim-PC.002

User: TEMP.Jim-PC.003

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 33750624 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 32902 bytes
%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
RecycleBin emptied: 11767220 bytes

Total Files Cleaned = 68.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 02132013_130846

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Jim\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


________________________________________________________________________________
____________



# AdwCleaner v2.112 - Logfile created 02/13/2013 at 13:58:33
# Updated 10/02/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Jim - JIM-PC
# Boot Mode : Normal
# Running from : C:\Users\Jim\Downloads\adwcleaner0.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\Jim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FreeRIP3

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\TBSB08970
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1301A8A5-3DFB-4731-A162-B357D00C9644}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{EA28B360-05E0-4F93-8150-02891F1D8D3C}
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetupv1.exe
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{6A4BCABA-C437-4C76-A54E-AF31B8A76CB9}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{8F5F1CB6-EA9E-40AF-A5CA-C7FD63CC1971}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apntoolbarinstaller_RASMANCS
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{7CD74AFF-3433-4E34-92E2-D98DFDB30754}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{97720195-206A-42AE-8E65-260B9BA5589F}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B18788A4-92BD-440E-A4D1-380C36531119}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC1AC828-BB47-4361-AFB5-96EEE259DD87}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{06DE5702-44CF-4B79-B4EF-3DDF653358F5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1B730ACF-26A3-447B-9994-14AEE0EB72CC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{477F210A-2A86-4666-9C4B-1189634D2C84}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FF871E51-2655-4D06-AED5-745962A96B32}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{424624F4-C5DD-4E1D-BDD0-1E9C9B7799CC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7F000001-DB8E-F89C-2FEC-49BF726F8C12}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9C8A3CA5-889E-4554-BEEC-EC0876E4E96A}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F9189560-573A-4FDE-B055-AE7B0F4CF080}
Key Deleted : HKLM\SOFTWARE\Tarma Installer

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16464

[OK] Registry is clean.

-\\ Google Chrome v24.0.1312.57

File : C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

-\\ Opera v [Unable to get version]

File : C:\Users\Jim\AppData\Roaming\Opera\Opera\operaprefs.ini

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [5749 octets] - [13/02/2013 13:54:25]
AdwCleaner[S1].txt - [5810 octets] - [13/02/2013 13:58:33]

########## EOF - C:\AdwCleaner[S1].txt - [5870 octets] ##########


________________________________________________________________________________
_______________________



OTL logfile created on: 2/13/2013 2:09:01 PM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jim\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 2.40 Gb Available Physical Memory | 63.05% Memory free
7.61 Gb Paging File | 6.03 Gb Available in Paging File | 79.35% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 452.35 Gb Total Space | 329.01 Gb Free Space | 72.73% Space Free | Partition Type: NTFS
Drive D: | 13.12 Gb Total Space | 2.18 Gb Free Space | 16.65% Space Free | Partition Type: NTFS
Drive E: | 99.02 Mb Total Space | 95.10 Mb Free Space | 96.04% Space Free | Partition Type: FAT32

Computer Name: JIM-PC | User Name: Jim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found –
PRC - [2013/02/12 20:08:34 | 000,086,752 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2013/02/12 20:07:18 | 000,385,248 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2013/02/12 20:07:18 | 000,110,816 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2013/02/11 14:58:40 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jim\Downloads\OTL.exe
PRC - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/08/29 13:51:48 | 001,061,960 | R— | M] (Carbonite, Inc.) – C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2011/03/24 07:11:18 | 000,107,800 | —- | M] (Octoshape ApS) – C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe
PRC - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/09/02 22:45:02 | 000,255,536 | —- | M] (McAfee, Inc.) – C:\Program Files (x86)\McAfee Security Scan\2.1.121\SSScheduler.exe
PRC - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
PRC - [2009/10/05 23:08:42 | 000,210,216 | —- | M] (CyberLink) – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
PRC - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe
PRC - [1999/12/31 16:00:00 | 000,284,480 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [1999/09/30 18:31:38 | 000,869,376 | —- | M] (Fred's Software) – C:\Program Files (x86)\PrintKey2000\Printkey2000.exe


========== Modules (No Company Name) ==========

MOD - [2013/02/12 21:25:47 | 012,436,480 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll
MOD - [2013/01/08 21:21:08 | 000,489,472 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\8511eac49521cf5fa810ec3367c40cab\IAStorUtil.ni.dll
MOD - [2013/01/08 21:21:08 | 000,014,336 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5d918739168186b055c86a63123a1a30\IAStorCommon.ni.dll
MOD - [2013/01/08 16:03:36 | 000,771,584 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll
MOD - [2013/01/08 16:03:20 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/08 16:03:18 | 005,453,312 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/08 16:02:58 | 001,592,832 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/08 16:02:18 | 003,347,968 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cf827fe7bc99d9bcf0ba3621054ef527\WindowsBase.ni.dll
MOD - [2013/01/08 16:02:15 | 007,989,760 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/08 16:02:10 | 011,493,376 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2010/03/11 10:35:14 | 000,126,976 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanProcess.dll
MOD - [2010/03/05 10:51:54 | 000,143,360 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\Scan.dll
MOD - [2010/02/06 05:12:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FilingRes.dll
MOD - [2010/02/02 11:51:00 | 000,077,824 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\ScanRes.dll
MOD - [2010/02/02 11:51:00 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManagerRes.dll
MOD - [2010/01/14 11:22:06 | 000,094,208 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\PDF.dll
MOD - [2009/12/21 10:41:42 | 000,131,072 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuAction.exe
MOD - [2009/12/21 10:41:22 | 000,086,109 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\FormatManager.dll
MOD - [2009/12/21 10:41:14 | 000,036,864 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\AmCommonLib.dll
MOD - [2009/10/05 23:08:38 | 000,931,112 | —- | M] () – c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll
MOD - [2009/08/07 02:47:06 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\DocuRes.dll
MOD - [2009/06/25 07:00:06 | 000,897,024 | —- | M] () – C:\Program Files (x86)\Plustek\Plustek OpticBook 4600\EncryptPdf.dll
MOD - [2008/08/27 14:58:38 | 000,045,056 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFillRsc.dll
MOD - [2008/06/02 08:27:08 | 000,061,440 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\EdgeFill.dll
MOD - [2006/05/15 12:24:18 | 000,122,938 | —- | M] () – C:\Program Files (x86)\Common Files\iMpacct\CommonFunc.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/08/29 13:43:58 | 006,742,088 | R— | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] – C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe – (CarboniteService)
SRV:64bit: - [2012/07/11 10:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2011/05/13 18:58:10 | 000,030,520 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Windows\SysNative\hpservice.exe – (hpsrv)
SRV:64bit: - [2010/09/22 14:10:10 | 000,057,184 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe – (wlcrasvc)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV:64bit: - [1999/12/31 16:00:00 | 000,314,880 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [1999/12/31 16:00:00 | 000,089,600 | —- | M] (Andrea Electronics Corporation) [Auto | Running] – C:\Program Files\IDT\WDM\AESTSr64.exe – (AESTFilters)
SRV - [2013/02/12 20:08:34 | 000,086,752 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2013/02/12 20:07:18 | 000,110,816 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2012/12/18 06:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/12/04 10:54:14 | 000,103,472 | —- | M] (McAfee, Inc.) [Auto | Running] – c:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe – (McAfee SiteAdvisor Service)
SRV - [2012/11/16 15:10:37 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/13 17:46:26 | 000,147,888 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\ramaint.exe – (LMIMaint)
SRV - [2012/11/12 15:46:10 | 000,375,728 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe – (LMIGuardianSvc)
SRV - [2011/01/25 13:40:22 | 000,092,216 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2010/11/08 10:04:18 | 000,407,424 | —- | M] (LogMeIn, Inc.) [Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe – (LogMeIn)
SRV - [2010/09/02 22:45:02 | 000,227,232 | —- | M] (McAfee, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\McAfee Security Scan\2.1.121\McCHSvc.exe – (McComponentHostService)
SRV - [2010/06/14 07:00:48 | 000,270,848 | —- | M] (Novatel Wireless Inc.) [Auto | Running] – C:\Program Files (x86)\Novatel Wireless\Verizon\Drivers\NWHelper_001.exe – (NWVZHelper)
SRV - [2010/03/18 10:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/09/30 20:01:32 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS)
SRV - [2009/09/30 20:01:30 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS)
SRV - [2009/06/30 13:49:06 | 000,134,944 | —- | M] (Nuance Communications, Inc.) [Auto | Running] – C:\Program Files (x86)\Nuance\PDF Professional 6\PDFProFiltSrv.exe – (PDFProFiltSrv)
SRV - [2009/06/10 13:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 16:07:28 | 000,250,616 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe – (GameConsoleService)
SRV - [1999/12/31 16:00:00 | 000,013,632 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/12/11 20:12:07 | 000,129,216 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avipbb.sys – (avipbb)
DRV:64bit: - [2012/12/11 20:12:06 | 000,099,912 | —- | M] (Avira Operations GmbH & Co. KG) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/11/14 17:38:20 | 000,040,712 | —- | M] (Anchorfree Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss6.sys – (taphss6)
DRV:64bit: - [2012/11/13 14:44:32 | 000,015,712 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\SWDUMon.sys – (SWDUMon)
DRV:64bit: - [2012/11/12 15:46:12 | 000,088,008 | —- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] – C:\Windows\SysNative\LMIRfsClientNP.dll – (LMIRfsClientNP)
DRV:64bit: - [2012/10/19 16:04:09 | 004,747,328 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2012/09/24 08:58:11 | 000,027,800 | —- | M] (Avira Operations GmbH & Co. KG) [Kernel | System | Running] – C:\Windows\SysNative\drivers\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/08/01 10:13:40 | 000,038,632 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:64bit: - [2012/05/19 14:10:42 | 000,275,648 | —- | M] (LotSoft, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\DigiartyVirtualCDBus.sys – (DigiartyVirtualCDBus)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/07/22 08:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/12 13:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/05/13 18:58:16 | 000,030,008 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\hpdskflt.sys – (hpdskflt)
DRV:64bit: - [2011/05/13 18:57:58 | 000,043,320 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Accelerometer.sys – (Accelerometer)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 01:37:42 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/09/22 20:36:48 | 000,048,488 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\fssfltr.sys – (fssfltr)
DRV:64bit: - [2010/07/08 06:52:32 | 000,256,512 | —- | M] (Novatel Wireless Inc) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\NWADIenum.sys – (NWADI)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbser2_000.sys – (NWUSBPort2_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbser_000.sys – (NWUSBPort_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,217,728 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nwusbmdm_000.sys – (NWUSBModem_000)
DRV:64bit: - [2010/07/08 06:52:32 | 000,025,600 | —- | M] (Novatel Wireless Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\NwUsbCdFil64.sys – (NWUSBCDFIL64)
DRV:64bit: - [2010/05/27 22:32:56 | 000,320,560 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2010/01/27 09:22:02 | 000,072,216 | —- | M] (LogMeIn, Inc.) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\LMIRfsDriver.sys – (LMIRfsDriver)
DRV:64bit: - [2010/01/27 09:21:36 | 000,011,552 | —- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\lmimirr.sys – (lmimirr)
DRV:64bit: - [2009/12/07 03:53:26 | 000,117,504 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbmdm.sys – (hwdatacard)
DRV:64bit: - [2009/12/07 03:36:48 | 000,246,224 | —- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ewusbnet.sys – (ewusbnet)
DRV:64bit: - [2009/09/26 07:42:58 | 000,233,984 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud)
DRV:64bit: - [2009/09/17 12:54:54 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64)
DRV:64bit: - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV:64bit: - [2009/07/30 19:58:42 | 000,236,544 | —- | M] (Realtek ) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/06/29 10:17:00 | 000,070,656 | —- | M] (ENE TECHNOLOGY INC.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\enecir.sys – (enecir)
DRV:64bit: - [2009/06/10 13:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 13:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 13:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 12:35:33 | 000,389,120 | —- | M] (Marvell) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:64bit: - [2009/06/10 12:35:28 | 005,434,368 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\netw5v64.sys – (netw5v64)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2009/04/29 08:48:32 | 000,018,432 | —- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HpqKbFiltr.sys – (HpqKbFiltr)
DRV:64bit: - [1999/12/31 16:00:00 | 007,770,048 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:64bit: - [1999/12/31 16:00:00 | 000,568,640 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:64bit: - [1999/12/31 16:00:00 | 000,536,064 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV - [2010/01/27 09:22:02 | 000,015,928 | —- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys – (LMIInfo)
DRV - [2009/09/02 09:58:08 | 000,225,280 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - [2009/07/13 17:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
DRV - [2008/07/26 22:30:36 | 000,014,544 | —- | M] (OpenLibSys.org) [Kernel | On_Demand | Stopped] – C:\Program Files (x86)\BatteryCare\WinRing0x64.sys – (WinRing0_1_2_0)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope =


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\.DEFAULT\..\SearchScopes,defaultscope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-18\..\SearchScopes,defaultscope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,defaultscope =

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,defaultscope =

IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\ZEON/PDF,version=2.0: C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll (Zeon Corporation)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@octoshape.com/Octoshape Streaming Services,version=1.0: C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll (Octoshape ApS)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jim\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2009/11/27 15:49:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/12/26 13:33:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/12/12 16:55:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 17.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

[2013/01/25 12:20:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions
[2012/12/03 18:43:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Jim\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/01/25 12:20:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/08 10:44:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/23 17:50:20 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/17 10:18:34 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2012/07/14 12:03:42 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/08/30 23:15:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/10/19 22:01:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/05/10 14:21:18 | 000,002,024 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml

========== Chrome ==========

CHR - homepage: http://www.my.yahoo.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter},
CHR - homepage: http://www.my.yahoo.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\McChPlg.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Mozilla\plugins\npoctoshape.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Zeon Plus (Enabled) = C:\Program Files (x86)\Nuance\PDF Professional 6\bin\nppdf.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Jim\AppData\Local\HuluDesktop\instances\0.9.14.1\npHDPlg.dll
CHR - plugin: Octoshape Streaming Services (Enabled) = C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1103234-0-npoctoshape.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Adblock Plus = C:\Users\Jim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (PlusIEEventHelper Class) - {551A852F-39A6-44A7-9C13-AFBEC9185A9D} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\PlusIEContextMenu.dll (Zeon Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0566.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDF Professional 6\bin\ZeonIEFavClient.dll (Zeon Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4:64bit: - HKLM..\Run: [WrtMon.exe] C:\Windows\SysNative\spool\drivers\x64\3\WrtMon.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4 - HKLM..\Run: [Nuance PDF Professional 6-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PDFProfessional-reminder] C:\Program Files (x86)\Nuance\PDF Professional 6\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [BatteryCare] C:\Program Files (x86)\BatteryCare\BatteryCare.exe (Filipe Lourenço)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [Octoshape Streaming Services] C:\Users\Jim\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS)
O4 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000..\Run: [OpAgent] "OpAgent.exe" /agent File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8:64bit: - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8:64bit: - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with Nuance PDF Converter 6.0 - C:\Program Files (x86)\Nuance\PDF Professional 6\cnvres_eng.dll ()
O8 - Extra context menu item: Open with PDF Professional 6 - C:\Program Files (x86)\Nuance\PDF Professional 6\Bin\PlusIEContextMenu.dll (Zeon Corporation)
O9:64bit: - Extra Button: PDFill PDF Editor - {ED93D107-B43A-490e-AA5C-C5578BAAF479} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O9 - Extra Button: PDFill PDF Editor - {FB858B22-55E2-413f-87F5-30ADC5552151} - C:\Program Files (x86)\PlotSoft\PDFill\DownloadPDF.exe (PlotSoft LLC)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKU\S-1-5-21-1396301682-2749084838-641560585-1000\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{382CECE5-D5A4-432B-83D7-AB14CE7F9FCC}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\gopher - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{01f9633b-2ad2-11df-b708-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell - "" = AutoRun
O33 - MountPoints2\{0810774d-6219-11e0-9499-9ae8e1b4e3e3}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30c5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell - "" = AutoRun
O33 - MountPoints2\{1dfe30d5-2a45-11df-9fcc-f8ded1558afd}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{4917f135-38eb-11df-8c9f-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f143352-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell - "" = AutoRun
O33 - MountPoints2\{4f14335b-343f-11df-911c-00a0c6000000}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{58130b4a-374e-11df-987a-c417fe11427b}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell - "" = AutoRun
O33 - MountPoints2\{6b793421-655d-11e0-af4f-a307948c1efa}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c67-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell - "" = AutoRun
O33 - MountPoints2\{9d538c72-2cc2-11df-853c-f70ecc9545ff}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{ad1c6da2-afbb-11e0-a23f-c417fe11427b}\Shell\AutoRun\command - "" = G:\VZAccess_Manager.exe /z detect
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell - "" = AutoRun
O33 - MountPoints2\{c7ed975b-2b8d-11df-acb8-c417fe11427b}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{dd584e7d-63a0-11e0-9b65-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44e4-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell - "" = AutoRun
O33 - MountPoints2\{e5ef44f2-2bf1-11df-8926-cce13fede1f4}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell - "" = AutoRun
O33 - MountPoints2\{f716fdd4-6194-11e0-badb-b3c93bc1d3e5}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\H\Shell - "" = AutoRun
O33 - MountPoints2\H\Shell\AutoRun\command - "" = H:\VZAccess_Manager.exe /z detect
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/02/13 13:08:46 | 000,000,000 | —D | C] – C:\_OTL
[2013/02/12 21:00:04 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/02/12 21:00:04 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/02/12 21:00:03 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/02/12 21:00:03 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/02/12 21:00:03 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/02/12 21:00:03 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/02/12 21:00:02 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/02/12 21:00:02 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/02/12 21:00:02 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/02/12 21:00:01 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/02/12 21:00:01 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/02/12 21:00:01 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/02/12 20:59:59 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/02/12 20:59:59 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/02/12 20:59:59 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/02/12 20:54:50 | 005,553,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/02/12 20:54:49 | 003,967,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2013/02/12 20:54:48 | 003,913,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2013/02/12 20:54:45 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2013/02/12 20:54:44 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/02/12 20:54:44 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/02/12 20:54:43 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/02/12 20:54:43 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/02/12 20:54:42 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/02/12 20:54:37 | 000,288,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\FWPKCLNT.SYS
[2013/02/05 13:17:00 | 000,158,128 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/02/05 13:17:00 | 000,149,936 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/30 15:45:45 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Roaming\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BatteryCare
[2013/01/30 15:45:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\BatteryCare
[2013/01/28 13:31:02 | 000,000,000 | —D | C] – C:\Users\Jim\AppData\Local\Programs
[2013/01/25 11:34:23 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/01/25 11:34:18 | 000,000,000 | —D | C] – C:\JRT
[2013/01/24 12:43:24 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Burgomeister
[2013/01/15 14:34:04 | 000,000,000 | —D | C] – C:\Users\Jim\Desktop\Computer stuff & Troubleshooting
[2013/01/14 15:23:31 | 000,000,000 | -HSD | C] – C:\found.000
[2009/05/28 22:47:08 | 001,821,008 | —- | C] (Microsoft Corporation) – C:\Program Files\instmsiw.exe

========== Files - Modified Within 30 Days ==========

[2013/02/13 14:13:40 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 14:13:40 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/13 14:05:45 | 000,000,888 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/13 14:05:20 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2013/02/13 14:05:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/02/13 14:05:08 | 3063,046,144 | -HS- | M] () – C:\hiberfil.sys
[2013/02/13 13:43:01 | 000,000,900 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000UA.job
[2013/02/13 13:33:11 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/12 22:15:05 | 000,000,258 | RHS- | M] () – C:\ProgramData\ntuser.pol
[2013/02/12 21:21:35 | 000,391,384 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/02/12 21:03:48 | 000,758,210 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/02/12 21:03:48 | 000,637,044 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/02/12 21:03:48 | 000,111,160 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/02/11 15:42:02 | 000,000,512 | —- | M] () – C:\Users\Jim\Desktop\MBR.dat
[2013/02/08 12:42:37 | 000,022,197 | —- | M] () – C:\Users\Jim\Desktop\It's night time in the big city.odt
[2013/02/07 00:43:00 | 000,000,848 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1396301682-2749084838-641560585-1000Core.job
[2013/01/30 15:45:41 | 000,001,043 | —- | M] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/30 13:12:13 | 457,681,826 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/01/25 15:43:05 | 002,720,770 | —- | M] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/15 16:56:10 | 000,477,616 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\npdeployJava1.dll
[2013/01/15 16:56:07 | 000,473,520 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\deployJava1.dll
[2013/01/15 16:53:05 | 000,158,128 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2013/01/15 16:53:01 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2013/01/15 16:52:55 | 000,149,936 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2013/01/14 15:26:35 | 000,010,120 | —- | M] () – C:\bootsqm.dat

========== Files Created - No Company Name ==========

[2013/02/11 15:42:02 | 000,000,512 | —- | C] () – C:\Users\Jim\Desktop\MBR.dat
[2013/01/30 15:45:41 | 000,001,043 | —- | C] () – C:\Users\Public\Desktop\BatteryCare.lnk
[2013/01/25 15:43:04 | 002,720,770 | —- | C] () – C:\Users\Jim\Desktop\bookmarks_1_25_13.html
[2013/01/14 15:26:35 | 000,010,120 | —- | C] () – C:\bootsqm.dat
[2012/11/06 16:17:14 | 000,870,544 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2012/11/06 16:17:14 | 000,050,028 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2012/06/14 15:38:47 | 000,000,505 | —- | C] () – C:\Windows\cdplayer.ini
[2012/06/14 15:31:58 | 000,001,534 | —- | C] () – C:\ProgramData\ss.ini
[2011/05/25 19:01:32 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2011/04/16 17:11:41 | 000,000,032 | —- | C] () – C:\Windows\DICapture.INI
[2011/02/02 12:36:10 | 000,001,854 | —- | C] () – C:\Users\Jim\AppData\Roaming\GhostObjGAFix.xml
[2010/06/16 11:16:05 | 000,000,000 | —- | C] () – C:\Users\Jim\AppData\Roaming\wklnhst.dat
[2010/06/09 10:40:09 | 000,001,026 | —- | C] () – C:\Users\Jim\Pictures - Shortcut.lnk
[2010/05/28 14:30:22 | 000,389,363 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.JPG
[2010/05/28 14:30:21 | 000,391,040 | —- | C] () – C:\Users\Jim\AppData\Local\tmpJIM GROSS-BILL.0
[2010/05/27 17:04:11 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/05/28 22:47:08 | 000,000,313 | —- | C] () – C:\Program Files\setup.ini

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

< End of report >
nonkly, there is still nothing that I can see as malware causing these problems. We've checked all of the ways known to search for the presence of malware and there is still no evidence of it. I suggest you return to Ztruker and ask for further analysis/help. Let me know what you decide Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI