OTL logfile created on: 5/8/2013 5:05:08 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Simpson\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 46.79% Memory free
6.18 Gb Paging File | 4.47 Gb Available in Paging File | 72.36% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 184.84 Gb Total Space | 107.27 Gb Free Space | 58.03% Space Free | Partition Type: NTFS
Computer Name: SIMPSON-PC | User Name: Simpson | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Simpson\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\SlimDrivers\SlimDrivers.exe (SlimWare Utilities, Inc.)
PRC - C:\Program Files\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\TOSHIBA\IVP\ISM\pinger.exe ()
PRC - C:\Windows\System32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
MOD - C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\TWarnMsg\TWarnMsg.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll ()
MOD - C:\Windows\System32\igfxTMM.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtGui4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files\Common Files\LightScribe\QtCore4.dll ()
MOD - C:\Program Files\TOSHIBA\TBS\NotifyTBS.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ()
========== Services (SafeList) ==========
SRV - (McComponentHostService) – C:\Program Files\McAfee Security Scan\3.0.318\McCHSvc.exe (McAfee, Inc.)
SRV - (GameConsoleService) – C:\Program Files\TOSHIBA Games\TOSHIBA Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (LiveUpdate Notice Service) – C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
SRV - (TNaviSrv) – C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
SRV - (TOSHIBA SMART Log Service) – C:\Program Files\TOSHIBA\SMARTLogService\TosIPCSrv.exe (TOSHIBA Corporation)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (Swupdtmr) – c:\TOSHIBA\IVP\swupdate\swupdtmr.exe ()
SRV - (LiveUpdate) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE (Symantec Corporation)
SRV - (pinger) – C:\TOSHIBA\IVP\ISM\pinger.exe ()
SRV - (AgereModemAudio) – C:\Windows\System32\agrsmsvc.exe (Agere Systems)
SRV - (UleadBurningHelper) – C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Driver Services (SafeList) ==========
DRV - (SVRPEDRV) – C:\Windows\System32\sysprep\UP_date\PEDrv.sys File not found
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (Lbd) – system32\DRIVERS\Lbd.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (IO_Memory) – C:\WINDOWS\SYSTEM32\SYSPREP\Drivers\ioport.sys File not found
DRV - (Cdralw2k) – File not found
DRV - (Cdr4_xp) – File not found
DRV - (catchme) – C:\Users\Simpson\AppData\Local\Temp\catchme.sys File not found
DRV - (SWDUMon) – C:\Windows\System32\drivers\SWDUMon.sys ()
DRV - (ctxusbm) – C:\Windows\System32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (WDC_SAM) – C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (NETw3v32) – C:\Windows\System32\drivers\NETw3v32.sys (Intel Corporation)
DRV - (UVCFTR) – C:\Windows\System32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (NETw4v32) – C:\Windows\System32\drivers\NETw4v32.sys (Intel Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (Agere Systems)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (KR10I) – C:\Windows\System32\drivers\KR10I.sys (TOSHIBA CORPORATION)
DRV - (KR10N) – C:\Windows\System32\drivers\KR10N.sys (TOSHIBA CORPORATION)
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (NETwLv32) – C:\Windows\System32\drivers\NETwLv32.sys (Intel Corporation)
DRV - (RTL8169) – C:\Windows\System32\drivers\Rtlh86.sys (Realtek )
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}: "URL" =
http://www.google.com/search?q={searchTerm…ge={startPage};
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Internet Explorer\SearchURL\y, =
http://yandex.ru/yandsearch?win=29&cli…511&text=%s
IE - HKCU\..\SearchScopes,DefaultScope = {9D4555DE-9E0B-475D-BCE5-5021BF27458B}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{9D4555DE-9E0B-475D-BCE5-5021BF27458B}: "URL" =
http://yandex.ru/yandsearch?win=29&cli…t={searchTerms}
IE - HKCU\..\SearchScopes\{E5F5D888-2587-E012-A817-7038F5690F26}: "URL" =
http://www.brotherstart.com/s/?q={searchTe…g=2-199-0-1tmBC
IE - HKCU\..\SearchScopes\yandex.ru-124739: "URL" =
http://www.google.com/search?q={searchTerm…;rlz=1I7GGLL_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "ЯндекÑ"
FF - prefs.js..browser.search.selectedEngine: "ЯндекÑ"
FF - prefs.js..browser.search.suggest.enabled: true
FF - prefs.js..browser.search.useDBForOrder: false
FF - prefs.js..keyword.enabled: true
FF - prefs.js..keyword.URL: "http://yandex.ru/yandsearch?win=29&clid=1855511&text="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/McAfeeMssPlugin: C:\Program Files\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Simpson\AppData\Roaming\Move Networks\plugins\npqmp071505000010.dll (Move Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/03 18:22:06 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Simpson\AppData\Roaming\Move Networks [2009/10/10 18:58:23 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{D450C550-6059-4C56-8765-776ACDB0F77B}: C:\Users\Simpson\AppData\Local\{D450C550-6059-4C56-8765-776ACDB0F77B}
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/01/03 18:22:06 | 000,000,000 | —D | M]
[2012/09/17 19:52:48 | 000,000,000 | —D | M] (No name found) – C:\Users\Simpson\AppData\Roaming\mozilla\Firefox\Profiles\nahd6ha2.default\extensions
[2012/09/17 19:52:54 | 000,000,000 | —D | M] (Search Assistant) – C:\Users\Simpson\AppData\Roaming\mozilla\Firefox\Profiles\nahd6ha2.default\extensions\{B3834E60-12A8-11E0-A289-939FDFD72085}
[2012/07/21 12:47:40 | 000,007,859 | —- | M] () – C:\Users\Simpson\AppData\Roaming\mozilla\firefox\profiles\nahd6ha2.default\searchplugins\yandex.ru-124740.xml
========== Chrome ==========
CHR - homepage: 21843,distribution:{create_all_shortcuts:true,do_not_launch_chrome:true,import_h
istory:false,import_search_engine:false,make_chrome_default:true,show_welcome_pag
e:true,skip_first_run_ui:true,verbose_logging:false},download:{directory_upgrade:
true,extensions_to_open:},extensions:{autoupdate:{next_check:12922471879315600},c
hrome_url_overrides:{bookmarks:[chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html]}},homepage:http://www.google.com/,homepage_is_newtabpage:false,ntp:{pref_version:1,shown_sections:64,tips_cache:{
current_tip:0,tips:[Did you know that there are over 450 browser themes in the Chrome extensions gallery? These include new
http://chrome.google.com/extensions/featured/worldcup\>World Cup themes.,The
https://chrome.google.com/extensions/\>Chrome extensions gallery has over 5,000 extensions! Explore extensions in different categories, such as blogging, shopping, web development, and more.,Parlez-vous français ? Google Chrome's built-in translation bar helps you read more of the Web.
http://www.google.com/support/chrome/bin/answer.py?answer=173424&ctx=tip\>Learn more,Add extra features and functionality to your browser with extensions. Visit the
https://chrome.google.com/extensions\ target=\_blank\>Chrome extensions gallery or
http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=154007&ctx=tip\ target=\_blank\>learn more.\n,Click and hold down the back button to see your browsing history.,Customize Google Chrome with themes! Check out designs at the
https://tools.google.com/chrome/intl/en/themes/index.html\ target=\_blank\>Themes Gallery.,When you use the find bar, yellow markers on the scrollbar help you quickly locate matches on the page.
http://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\>Learn more,Search your bookmarks and browsing history from the address bar.
http://www.google.com/support/chrome/bin/answer.py?answer=95440&ctx=tip\>Learn more,Have your tabs arranged your way. Click a tab and drag it to a new position along the top of the browser window.
http://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\>Learn more,Quickly resize a tab by dragging it to a docking position on your monitor or browser window.
http://www.google.com/support/chrome/bin/answer.py?answer=95622#resize&ctx=tip\>Learn more,Drag a link to the tab strip at the top of your browser window to open it in a new tab.,Press
Ctrl+T to open a new tab. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
Ctrl+N to open a new browser window. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,To search a site, start typing the site's web address in the address bar and press
Tab when prompted. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\>search tricks.,Create address bar keywords for search engines you frequently use.
http://www.google.com/support/chrome/bin/answer.py?hl=en&answer=95653&ctx=tips\>Learn how,Press
Ctrl and + to enlarge a page;
Ctrl and - to make the page smaller; and
Ctrl and
0 to return the page to its normal size. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
Ctrl+F to search the page you're viewing. Learn more about
http://www.google.com/support/chrome/bin/answer.py?answer=95635&ctx=tip\>using the find bar.\n,Press
Ctrl+S to save your current webpage. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
Ctrl+P to print your current webpage. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
Ctrl+J to see a list of files you've downloaded. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
Ctrl+H to see your browsing history. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Click a tab and drag it out of the tab strip to open it in a new window.
http://www.google.com/support/chrome/bin/answer.py?answer=95622&ctx=tips\>Learn more\n,Press
Ctrl+Shift+N to open a new window in incognito mode. Pages you visit while in incognito mode aren't stored in your browsing history.
http://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\>Learn more,Press
Ctrl+O to open a file in the browser. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Press
F11 to go full screen. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Click the star next to the address bar to bookmark the page you're viewing. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.\n,Place shortcuts for your favorite sites on your computer desktop.
http://www.google.com/support/chrome/bin/answer.py?answer=95710&ctx=tip\>Learn more,Want to hide thumbnails on the New Tab page? Use the controls at the top of the page.
http://www.google.com/support/chrome/bin/answer.py?answer=95451&ctx=tip\>Learn more,Drag the star to the bookmarks bar to create a bookmark for the page? Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.,Drag a link to the bookmarks bar to create an instant bookmark. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95739&ctx=tip\>bookmarking tricks.,Press
Ctrl+Shift+T repeatedly to reopen the last 10 tabs you closed. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Don't want to leave traces of your browsing history? Browse in incognito mode.
http://www.google.com/support/chrome/bin/answer.py?answer=95464&ctx=tip\>Learn more,Accidentally closed a window full of tabs? Find it again in the
Recently closed section of the New Tab page.,Add a home button next to the address bar.
http://www.google.com/support/chrome/bin/answer.py?answer=95314&ctx=tip\>Learn how,Search directly from the address bar. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95655&ctx=tip\>search tips.\n,Press
F6 to quickly place your cursor in the address bar. Learn more
http://www.google.com/support/chrome/bin/answer.py?answer=95743&ctx=tip\>keyboard shortcuts.,Switching between computers? Keep your Google Chrome settings, bookmarks, and themes in sync across computers.
http://www.google.com/support/chrome/bin/answer.py?answer=165138&ctx=tip\>Learn how],topic_id:24013},tips_cache_update:1277936445.9828,tips_server:https://clients2.google.com/tools/service/npredir?r=chrometips_win&hl=en-US,shown_page:1024},profile:{content_settings:{pref_version:1},exited_cleanly:tr
ue},sync_promo:{user_skipped:true},bookmark_bar:{show_on_all_tabs:true}
O1 HOSTS File: ([2013/05/05 17:56:59 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [HSON] C:\Program Files\TOSHIBA\TBS\HSON.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [NDSTray.exe] NDSTray.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [Symantec PIF AlertEng] C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe (Symantec Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll (Sun Microsystems, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: wellmont.org ([citrix-gw] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://atitesting.webex.com/client/T27LD/nbr/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1A6FA18D-A133-4F0D-A48E-F7827E031C06}: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Simpson\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Simpson\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
System Restore Service not available.
========== Files/Folders - Created Within 30 Days ==========
[2013/05/08 16:59:10 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Simpson\Desktop\aswMBR.exe
[2013/05/08 16:58:31 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Simpson\Desktop\OTL.exe
[2013/05/07 19:30:01 | 000,000,000 | —D | C] – C:\Users\Simpson\Desktop\RK_Quarantine
[2013/05/07 19:01:58 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/05/07 19:01:43 | 000,000,000 | —D | C] – C:\JRT
[2013/05/07 18:54:36 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\System32\Wdfres.dll
[2013/05/07 18:54:30 | 000,172,032 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFPlatform.dll
[2013/05/07 18:54:30 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winusb.dll
[2013/05/07 18:54:29 | 000,613,888 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFx.dll
[2013/05/07 18:54:29 | 000,047,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\WdfLdr.sys
[2013/05/07 18:54:29 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\WUDFCoinstaller.dll
[2013/05/07 18:50:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2013/05/07 18:45:24 | 000,545,954 | —- | C] (Oleg N. Scherbakov) – C:\Users\Simpson\Desktop\JRT.exe
[2013/05/05 18:00:03 | 000,000,000 | —D | C] – C:\Windows\temp
[2013/05/05 18:00:03 | 000,000,000 | —D | C] – C:\Users\Simpson\AppData\Local\temp
[2013/05/05 17:59:26 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/05/05 17:42:18 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2013/05/05 17:42:18 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2013/05/05 17:42:18 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2013/05/05 17:40:18 | 000,000,000 | —D | C] – C:\Qoobox
[2013/05/05 17:38:33 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2013/04/22 16:46:03 | 000,000,000 | —D | C] – C:\FRST
[2013/04/18 16:19:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/04/18 16:17:08 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2013/04/18 16:16:04 | 006,637,056 | —- | C] (Intel Corporation) – C:\Windows\System32\drivers\NETwLv32.sys
[2013/04/18 16:16:04 | 002,756,608 | —- | C] (Intel Corporation) – C:\Windows\System32\NETwLr32.dll
[2013/04/18 16:16:04 | 000,675,840 | —- | C] (Intel Corporation) – C:\Windows\System32\NETwLc32.dll
[2013/04/18 16:14:49 | 000,363,112 | —- | C] (Realtek ) – C:\Windows\System32\drivers\Rtlh86.sys
[2013/04/18 16:14:49 | 000,080,488 | —- | C] (Realtek Semiconductor Corporation) – C:\Windows\System32\RtNicProp32.dll
[2013/04/18 16:14:15 | 000,000,000 | —D | C] – C:\Intel
[2013/04/18 16:13:02 | 000,000,000 | —D | C] – C:\Users\Simpson\AppData\Local\SlimWare Utilities Inc
[2013/04/18 16:12:58 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
[2013/04/18 16:12:57 | 000,000,000 | —D | C] – C:\Program Files\SlimDrivers
[2013/04/18 16:12:50 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Downloaded Installers
[2012/07/13 18:09:33 | 003,463,560 | —- | C] (Microsoft Corporation) – C:\Users\Simpson\AppData\Local\PackSetup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/05/08 17:00:37 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Simpson\Desktop\aswMBR.exe
[2013/05/08 16:58:32 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Simpson\Desktop\OTL.exe
[2013/05/08 16:33:17 | 000,000,390 | —- | M] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/05/08 16:33:13 | 000,000,374 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2013/05/08 16:33:10 | 000,013,464 | —- | M] () – C:\Windows\System32\drivers\SWDUMon.sys
[2013/05/08 16:32:57 | 000,000,882 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/08 16:32:42 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 16:32:42 | 000,003,744 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 16:32:42 | 000,000,380 | —- | M] () – C:\Windows\tasks\update-sys.job
[2013/05/08 16:32:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/08 16:32:05 | 3210,694,656 | -HS- | M] () – C:\hiberfil.sys
[2013/05/08 03:01:16 | 000,000,886 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/08 03:01:00 | 000,000,380 | —- | M] () – C:\Windows\tasks\update-S-1-5-21-2732826977-1390623016-2335831479-1000.job
[2013/05/07 19:31:43 | 248,224,405 | —- | M] () – C:\Windows\MEMORY.DMP
[2013/05/07 19:29:54 | 000,816,128 | —- | M] () – C:\Users\Simpson\Desktop\RogueKiller.exe
[2013/05/07 19:18:22 | 000,628,743 | —- | M] () – C:\Users\Simpson\Desktop\adwcleaner.exe
[2013/05/07 19:03:09 | 000,000,129 | —- | M] () – C:\Windows\System32\MRT.INI
[2013/05/07 18:51:40 | 000,604,752 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/05/07 18:51:40 | 000,104,420 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/05/07 18:50:50 | 000,001,878 | —- | M] () – C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2013/05/07 18:50:50 | 000,001,878 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk
[2013/05/07 18:45:24 | 000,545,954 | —- | M] (Oleg N. Scherbakov) – C:\Users\Simpson\Desktop\JRT.exe
[2013/05/07 18:41:22 | 000,890,825 | —- | M] () – C:\Users\Simpson\Desktop\SecurityCheck.exe
[2013/05/05 18:02:36 | 000,001,356 | —- | M] () – C:\Users\Simpson\AppData\Local\d3d9caps.dat
[2013/05/05 17:56:59 | 000,000,027 | —- | M] () – C:\Windows\System32\drivers\etc\hosts
[2013/05/05 17:41:52 | 000,000,049 | —- | M] () – C:\Windows\NeroDigital.ini
[2013/05/02 02:06:08 | 000,238,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2013/04/18 16:19:37 | 000,002,040 | —- | M] () – C:\Users\Public\Desktop\Google Earth.lnk
[2013/04/18 16:12:58 | 000,001,854 | —- | M] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/05/07 19:29:48 | 000,816,128 | —- | C] () – C:\Users\Simpson\Desktop\RogueKiller.exe
[2013/05/07 19:18:21 | 000,628,743 | —- | C] () – C:\Users\Simpson\Desktop\adwcleaner.exe
[2013/05/07 19:03:09 | 000,000,129 | —- | C] () – C:\Windows\System32\MRT.INI
[2013/05/07 18:54:40 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2013/05/07 18:54:40 | 000,000,003 | —- | C] () – C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2013/05/07 18:50:50 | 000,001,878 | —- | C] () – C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
[2013/05/07 18:41:13 | 000,890,825 | —- | C] () – C:\Users\Simpson\Desktop\SecurityCheck.exe
[2013/05/05 18:04:02 | 3210,694,656 | -HS- | C] () – C:\hiberfil.sys
[2013/05/05 17:42:18 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/05/05 17:42:18 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/05/05 17:42:18 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/05/05 17:42:18 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/05/05 17:42:18 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2013/04/18 16:13:05 | 000,000,390 | —- | C] () – C:\Windows\tasks\SlimDrivers Startup.job
[2013/04/18 16:13:03 | 000,013,464 | —- | C] () – C:\Windows\System32\drivers\SWDUMon.sys
[2013/04/18 16:12:58 | 000,001,854 | —- | C] () – C:\Users\Public\Desktop\SlimDrivers.lnk
[2011/10/29 18:42:46 | 000,000,049 | —- | C] () – C:\Windows\NeroDigital.ini
[2011/10/11 18:46:56 | 000,000,000 | —- | C] () – C:\Windows\ToDisc.INI
[2010/10/26 18:56:33 | 000,000,120 | —- | C] () – C:\Users\Simpson\AppData\Local\Yzikahurozececi.dat
[2010/10/26 18:56:33 | 000,000,000 | —- | C] () – C:\Users\Simpson\AppData\Local\Ofumakuladole.bin
[2010/07/20 19:59:13 | 000,000,056 | —- | C] () – C:\ProgramData\ezsidmv.dat
[2010/07/18 18:08:54 | 000,001,923 | —- | C] () – C:\Users\Simpson\AppData\Local\UserProducts.xml
[2010/06/30 18:24:05 | 000,001,356 | —- | C] () – C:\Users\Simpson\AppData\Local\d3d9caps.dat
[2009/07/25 21:51:17 | 000,024,358 | —- | C] () – C:\Users\Simpson\AppData\Roaming\UserTile.png
[2008/05/25 15:32:09 | 000,003,029 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2008/04/17 15:36:50 | 000,034,816 | —- | C] () – C:\Users\Simpson\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 08:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 02:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/10/10 16:06:12 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\BitTorrent
[2011/08/13 16:56:13 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Dropbox
[2009/08/14 14:23:16 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\GARMIN
[2011/02/08 17:48:21 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\ICAClient
[2010/09/21 19:51:05 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Maternal-Newborn Nursing
[2009/09/02 18:12:12 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\nutritrac
[2012/07/21 12:47:40 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Opera
[2009/07/25 21:51:16 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\PeerNetworking
[2008/11/12 17:13:59 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\SecondLife
[2008/06/20 20:35:13 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\TOSHIBA
[2008/04/19 17:59:57 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Ulead Systems
[2011/06/18 17:18:49 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\W Photo Studio
[2011/06/18 17:16:20 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\W Photo Studio Viewer
[2011/06/18 17:17:57 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\Walgreens
[2008/04/17 15:30:35 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\WildTangent
[2008/04/17 17:01:18 | 000,000,000 | —D | M] – C:\Users\Simpson\AppData\Roaming\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\erdnt\cache\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 22:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: SERVICES.EXE >
[2008/01/20 22:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\erdnt\cache\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
< MD5 for: SVCHOST.EXE >
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\erdnt\cache\svchost.exe
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\svchost.exe
[2008/01/20 22:23:43 | 000,021,504 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\erdnt\cache\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\System32\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\erdnt\cache\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /rp /s >
< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >
========== Drive Information ==========
Physical Drives
—————
Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type:
Media Type: Fixed hard disk media
Model:
Partitions: 2
Status: OK
Status Info: 0
Partitions
—————
DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 1.00GB
Starting Offset: 1048576
Hidden sectors: 0
DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 185.00GB
Starting Offset: 1573912576
Hidden sectors: 0
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
< End of report >