After seeing this page a few times when opening my browser, I checked my Google Chrome home page setting and sure enough it was still set to Google. I used Trend Micro Titanium Internet Security (TIS) to run a scan, which appeared to get "stuck" at 16%. I then installed Malwarebytes and scanned and it removed 20 something things. I also tried Spybot S&D, and it found some cookies but nothing that seemed like malware. Then I tried scanning with Trend again and it was taking a really long time and wouldn't finish. So I decided to uninstall/reinstall Trend Micro. After uninstalling I rebooted and started to install, at which point I was prompted that TIS conflicted with Malwarebytes and Spybot so I uninstalled them. My Trend is installed, updated, and has successfully completed 2 full scans, each time finding a bunch of items, some are what I think are legitimate Vista AntiMalware removal tools that I have successfully used in the past on someone else's computer.
Recently, I have been getting spontaneous random browser windows opening in Chrome with Facebook page of Will and Kate's wedding. I also have seen some weird pages open with Internet Explorer 9 with pages such as cigarette ads, work at home ads, but luckily no adult stuff. I can only close these by right-clicking on the task bar icon and selecting Close. I no sooner close one and another opens. I uninstalled IE9 (was offered as a Windows Update) and haven't seen any popups in a while...
It seems like when I scan with the TIS software, maybe something gets scanned which triggers it. Today I found the Geeks To Go site, downloaded OTL.exe and here is my first scan results from OTL.txt:
OTL logfile created on: 4/27/2011 9:44:18 PM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Admin\Downloads - Admin
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 6.00 Gb Available Physical Memory | 71.00% Memory free
16.00 Gb Paging File | 13.00 Gb Available in Paging File | 83.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.34 Gb Total Space | 29.73 Gb Free Space | 12.80% Space Free | Partition Type: NTFS
Drive D: | 233.42 Gb Total Space | 43.46 Gb Free Space | 18.62% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 527.23 Gb Free Space | 56.60% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 516.49 Gb Free Space | 55.45% Space Free | Partition Type: NTFS
Computer Name: ZEUS | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/04/27 18:54:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads - Admin\OTL.exe
PRC - [2011/04/27 17:51:48 | 000,474,116 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Admin\AppData\Roaming\local.exe
PRC - [2011/04/27 16:36:08 | 000,474,116 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Admin\AppData\Roaming\Ubdate27,4.exe
PRC - [2011/02/28 16:26:48 | 000,023,840 | ---- | M] (Apache Software Foundation) -- C:\Program Files (x86)\VisualSVN Server\bin\VisualSVNServer.exe
PRC - [2010/12/13 02:32:54 | 003,246,040 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
PRC - [2010/12/06 05:56:42 | 000,390,728 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2010/12/06 05:55:24 | 005,542,168 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2010/11/23 18:46:14 | 000,075,064 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2010/11/16 04:52:28 | 002,536,448 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe
PRC - [2010/10/22 01:36:04 | 005,695,784 | ---- | M] (Bitvise) -- C:\Program Files (x86)\Bitvise WinSSHD\WinSSHD.exe
PRC - [2010/10/22 01:36:04 | 003,291,360 | ---- | M] () -- C:\Program Files (x86)\Bitvise WinSSHD\sshdctrl.exe
PRC - [2010/10/13 23:02:02 | 000,126,976 | ---- | M] () -- C:\Program Files (x86)\Zinio Alert Messenger\Zinio Alert Messenger.exe
PRC - [2010/09/22 18:11:26 | 000,640,440 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2010/06/16 17:42:58 | 000,839,680 | ---- | M] () -- C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
PRC - [2010/05/25 20:53:46 | 002,139,400 | ---- | M] () -- C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe
PRC - [2010/04/13 19:01:58 | 000,094,024 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\TscHelp.exe
PRC - [2010/04/13 19:01:56 | 000,079,688 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\SnagPriv.exe
PRC - [2010/04/13 19:01:52 | 007,384,904 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\SnagitEditor.exe
PRC - [2010/04/13 19:01:52 | 007,046,984 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\Snagit32.exe
PRC - [2010/03/03 20:39:40 | 002,598,760 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Ghost\Agent\VProTray.exe
PRC - [2010/03/03 20:39:38 | 004,590,432 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Ghost\Agent\VProSvc.exe
PRC - [2008/09/15 06:00:50 | 000,624,640 | ---- | M] () -- C:\Program Files (x86)\ASUS\AASP\1.00.76\aaCenter.exe
========== Modules (SafeList) ==========
MOD - [2011/04/27 18:54:58 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Downloads - Admin\OTL.exe
MOD - [2010/11/20 08:21:36 | 000,156,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\winsta.dll
MOD - [2010/11/20 07:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
MOD - [2009/07/13 21:09:00 | 000,002,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\normaliz.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/02/16 20:20:04 | 000,256,336 | ---- | M] (Trend Micro Inc.) [Auto | Running] -- C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe -- (Amsp)
SRV:64bit: - [2010/10/17 18:43:02 | 000,099,048 | ---- | M] (SANDBOXIE L.T.D) [Auto | Running] -- C:\Program Files\Sandboxie\SbieSvc.exe -- (SbieSvc)
SRV:64bit: - [2010/10/15 21:38:16 | 001,436,424 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/01/24 23:26:29 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/12/16 13:33:58 | 000,147,336 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2010/12/16 13:33:48 | 000,407,424 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
SRV - [2010/12/16 13:33:37 | 000,373,640 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/12/13 02:32:54 | 003,246,040 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2010/12/06 05:58:36 | 001,112,240 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010/11/24 16:00:16 | 007,669,760 | ---- | M] () [On_Demand | Stopped] -- c:\wamp\bin\mysql\mysql5.1.53\bin\mysqld.exe -- (wampmysqld)
SRV - [2010/11/23 18:46:14 | 000,075,064 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/10/24 14:34:38 | 000,021,504 | ---- | M] (Apache Software Foundation) [On_Demand | Stopped] -- c:\wamp\bin\apache\apache2.2.17\bin\httpd.exe -- (wampapache)
SRV - [2010/10/22 01:36:04 | 005,695,784 | ---- | M] (Bitvise) [Auto | Running] -- C:\Program Files (x86)\Bitvise WinSSHD\WinSSHD.exe -- (WinSSHD)
SRV - [2010/10/13 13:44:30 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/05/25 20:53:46 | 002,139,400 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Acronis\DiskDirector\OSS\reinstall_svc.exe -- (OS Selector)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 20:39:38 | 004,590,432 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Ghost\Agent\VProSvc.exe -- (Norton Ghost)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/12 08:09:18 | 002,227,216 | ---- | M] (Symantec) [On_Demand | Stopped] -- C:\Program Files (x86)\Norton Ghost\Shared\Drivers\GenericMountHelperx64.exe -- (GenericMount Helper Service)
SRV - [2010/01/27 08:43:06 | 000,049,664 | ---- | M] (The Digital Lifestyle.com) [Auto | Running] -- C:\Program Files (x86)\The Digital Lifestyle.com\mcBackup 3.0\mceBackupService.exe -- (mceBackup Service)
SRV - [2009/09/21 21:19:22 | 002,963,960 | ---- | M] (Symantec) [On_Demand | Running] -- C:\Program Files (x86)\Norton Ghost\Shared\Drivers\SymSnapServicex64.exe -- (SymSnapService)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/04/03 00:12:30 | 000,144,464 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmcomm.sys -- (tmcomm)
DRV:64bit: - [2011/04/03 00:12:30 | 000,105,552 | ---- | M] (Trend Micro Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\tmtdi.sys -- (tmtdi)
DRV:64bit: - [2011/04/03 00:12:30 | 000,090,704 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmactmon.sys -- (tmactmon)
DRV:64bit: - [2011/04/03 00:12:30 | 000,067,664 | ---- | M] (Trend Micro Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\tmevtmgr.sys -- (tmevtmgr)
DRV:64bit: - [2011/01/07 17:03:08 | 000,045,408 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2010/12/16 13:33:38 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:64bit: - [2010/12/13 02:32:57 | 000,285,280 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp)
DRV:64bit: - [2010/12/13 02:32:37 | 001,263,200 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm273.sys -- (tdrpman273) Acronis Try&Decide and Restore Points filter (build 273)
DRV:64bit: - [2010/12/13 02:32:21 | 000,970,336 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2010/12/13 02:31:33 | 000,277,088 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2010/11/20 09:34:02 | 000,360,832 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)
DRV:64bit: - [2010/11/20 09:34:02 | 000,194,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 09:32:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:32:46 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2010/11/20 07:35:32 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)
DRV:64bit: - [2010/11/20 07:35:20 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 07:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/10/17 18:42:58 | 000,145,512 | ---- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] -- C:\Program Files\Sandboxie\SbieDrv.sys -- (SbieDrv)
DRV:64bit: - [2010/10/13 11:57:09 | 000,015,416 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV:64bit: - [2010/10/06 07:12:35 | 000,035,112 | ---- | M] (TeamViewer GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\teamviewervpn.sys -- (teamviewervpn)
DRV:64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)
DRV:64bit: - [2010/08/31 13:32:44 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpdispm.sys -- (RDPDISPM)
DRV:64bit: - [2010/08/12 13:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2010/06/11 11:51:24 | 001,634,176 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hcw89.sys -- (hcw89)
DRV:64bit: - [2010/05/31 11:31:10 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:64bit: - [2010/05/31 11:30:44 | 000,011,552 | ---- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lmimirr.sys -- (lmimirr)
DRV:64bit: - [2010/04/27 16:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010/04/27 16:57:14 | 000,036,936 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmHidLo.sys -- (WmHidLo)
DRV:64bit: - [2010/04/27 16:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010/04/27 14:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010/04/27 14:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2010/04/19 20:47:42 | 000,050,688 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2010/02/12 08:10:12 | 000,066,608 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GenericMount.sys -- (GenericMount)
DRV:64bit: - [2009/12/17 18:25:17 | 000,034,472 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2009/10/01 23:03:40 | 000,154,168 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2009/09/21 21:40:14 | 000,020,528 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vproeventmonitor.sys -- (VProEventMonitor)
DRV:64bit: - [2009/09/21 21:20:42 | 000,170,032 | ---- | M] (StorageCraft) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\symsnap.sys -- (symsnap)
DRV:64bit: - [2009/08/25 00:10:52 | 000,035,840 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS -- (BVRPMPR5a64)
DRV:64bit: - [2009/08/09 17:25:45 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 16:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/03/07 14:03:40 | 000,019,432 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz132_x64.sys -- (cpuz132)
DRV:64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV - [2010/05/31 11:31:10 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 70 18 0F 39 2E F7 CB 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost; 127.0.0.1; <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://danswebspot.c...onsulting.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.5
FF - prefs.js..extensions.enabledItems: [email protected]:4.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.6
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.5.5
FF - prefs.js..extensions.enabledItems: {00084897-021a-4361-8423-083407a033e0}:1.4
FF - prefs.js..extensions.enabledItems: {AB7308B2-C13C-4eba-AC78-2AD55B96EE09}:3.0.0
FF - prefs.js..extensions.enabledItems: {C6128004-4838-4708-9A97-BB172D17767D}:1.6.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems: {4BBDD651-70CF-4821-84F8-2B918CF89CA3}:6.3.3.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.10
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.14.2
FF - prefs.js..extensions.enabledItems: {3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}:0.9.6
FF - prefs.js..extensions.enabledItems: {6e84150a-d526-41f1-a480-a67d3fed910d}:1.4.5.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.608
FF - prefs.js..extensions.enabledItems: {6D0612DB-D5D3-474f-959E-FA754CCA2B1B}:3.0.0
FF - prefs.js..extensions.enabledItems: {3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}:0.8.19
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.5
FF - prefs.js..extensions.enabledItems: {BE2100B3-1D80-48eb-ACCF-D26750644378}:0.4.23
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.8
FF - prefs.js..extensions.enabledItems: {79fcaa13-5f29-4c33-aad7-6c48c175760a}:0.8.1
FF - prefs.js..extensions.enabledItems: [email protected]:2.1.0
FF - prefs.js..extensions.enabledItems: {d5eeb813-935a-435d-b01e-b3a02f2cb408}:0.9.2
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: [email protected]:2
FF - prefs.js..extensions.enabledItems: 5
FF - prefs.js..extensions.enabledItems: 0
FF - prefs.js..extensions.enabledItems: 1
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.72.0
FF - prefs.js..extensions.enabledItems: {22C7F6C6-8D67-4534-92B5-529A0EC09405}:6.5.0.1234
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.1
FF - prefs.js..extensions.enabledItems: {36C13C8F-54F1-412e-8177-2E411719162D}:4.1.1
FF - prefs.js..network.proxy.backup.ftp: "201.59.176.82"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "201.59.176.82"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "201.59.176.82"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "201.59.176.82"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "200.172.79.174"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "200.172.79.174"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "200.172.79.174"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "200.172.79.174"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "200.172.79.174"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - HKLM\software\mozilla\Firefox\extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010/10/14 00:08:18 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: C:\Program Files\Trend Micro\AMSP\Module\20004\1.5.1464\6.6.1079\firefoxextension\ [2011/04/26 00:59:23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/12/22 16:51:55 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/24 21:26:46 | 000,000,000 | ---D | M]
[2010/10/13 21:01:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Extensions
[2011/04/21 12:18:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (CS Lite) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{00084897-021a-4361-8423-083407a033e0}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Qute) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{36C13C8F-54F1-412e-8177-2E411719162D}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Forecastbar Enhanced) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{3CE993BF-A3D9-4fd2-B3B6-768CBBC337F8}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (ShowIP) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{3e9bb2a7-62ca-4efa-a4e6-f6f6168a652d}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2011/04/02 01:15:49 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Page Validator) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{6D0612DB-D5D3-474f-959E-FA754CCA2B1B}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (IE View) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (zoomFox) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{79fcaa13-5f29-4c33-aad7-6c48c175760a}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}(2)
[2010/12/21 15:05:39 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2010/12/08 10:17:23 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (CSS Validator) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{AB7308B2-C13C-4eba-AC78-2AD55B96EE09}
[2011/04/02 01:17:43 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] ("Universal Print") -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{BE2100B3-1D80-48eb-ACCF-D26750644378}
[2010/10/13 21:01:56 | 000,000,000 | ---D | M] ("Universal Print") -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{BE2100B3-1D80-48eb-ACCF-D26750644378}(16999)
[2011/01/21 23:07:56 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] ("Dictionary Tooltip") -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{C6128004-4838-4708-9A97-BB172D17767D}
[2011/04/02 01:15:46 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/04/02 01:17:45 | 000,000,000 | ---D | M] (Aviary) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{d5eeb813-935a-435d-b01e-b3a02f2cb408}
[2011/04/02 01:15:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/11/04 07:37:07 | 000,000,000 | ---D | M] (CLEO) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2011/04/02 01:16:29 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2011/04/02 01:17:33 | 000,000,000 | ---D | M] (CodeBurner for Firebug) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2010/11/18 23:49:32 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2010/10/13 21:01:35 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\foxmarks@kei(16945).com
[2011/04/02 01:17:20 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (Kempelton) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2011/04/02 10:06:43 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] (YSlow) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\[email protected]
[2011/04/02 01:15:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\extensions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions
[2010/09/05 11:11:17 | 000,002,382 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\fohbc6ei.default\searchplugins\aviary.xml
[2011/03/17 09:14:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/03/17 09:14:47 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2010/10/14 00:08:18 | 000,000,000 | ---D | M] (Adobe Contribute Toolbar) -- C:\PROGRAM FILES (X86)\ADOBE\ADOBE CONTRIBUTE CS5\PLUGINS\FIREFOXPLUGIN\{01A8CA0A-4C96-465B-A49B-65C46FAD54F9}
[2011/04/26 00:59:23 | 000,000,000 | ---D | M] (Trend Micro NSC Firefox Extension) -- C:\PROGRAM FILES\TREND MICRO\AMSP\MODULE\20004\1.5.1464\6.6.1079\FIREFOXEXTENSION
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/04/27 19:59:37 | 000,433,443 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 14916 more lines...
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2:64bit: - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1079\TmIEPlg.dll (Trend Micro Inc.)
O2:64bit: - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (TmIEPlugInBHO Class) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1079\TmIEPlg32.dll (Trend Micro Inc.)
O2 - BHO: (FGCatchUrl) - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files (x86)\FlashGet\jccatch.dll (www.flashget.com)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (TmBpIeBHO Class) - {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} - C:\Program Files\Trend Micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
O2 - BHO: (FlashGet GetFlash Class) - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files (x86)\FlashGet\getflash.dll (www.flashget.com)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [Trend Micro Client Framework] C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe (Trend Micro Inc.)
O4:64bit: - HKLM..\Run: [Trend Micro Titanium] C:\Program Files\Trend Micro\Titanium\UIFramework\uiWinMgr.exe (Trend Micro Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [NBKeyScan] File not found
O4 - HKLM..\Run: [Norton Ghost 15.0] C:\Program Files (x86)\Norton Ghost\Agent\VProTray.exe (Symantec Corporation)
O4 - HKLM..\Run: [SAOB Monitor] C:\Program Files (x86)\Acronis\TrueImageHome\OnlineBackupStandalone\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [WinSSHD Activation State Checker] C:\Program Files (x86)\Bitvise WinSSHD\WinsshdActStateCheck.exe (Bitvise)
O4 - HKCU..\Run: [HKCU] C:\Users\Admin\AppData\Local\Temp\31517.exe ()
O4 - HKCU..\Run: [Local] C:\Users\Admin\AppData\Roaming\local.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Microsoft Windows] C:\Users\Admin\AppData\Roaming\Microsoft\JavaUpdate.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [Skype] C:\Users\Admin\AppData\Roaming\svchost.exe (Mozilla Corporation)
O4 - HKCU..\Run: [Windows Defender] C:\Users\Admin\AppData\Roaming\Ubdate27,4.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Zinio Alert Messenger.lnk = C:\Program Files (x86)\Zinio Alert Messenger\Zinio Alert Messenger.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\JC_ALL.HTM ()
O8:64bit: - Extra context menu item: &Download with FlashGet - C:\Program Files (x86)\FlashGet\JC_LINK.HTM ()
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: &Download All with FlashGet - C:\Program Files (x86)\FlashGet\JC_ALL.HTM ()
O8 - Extra context menu item: &Download with FlashGet - C:\Program Files (x86)\FlashGet\JC_LINK.HTM ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
O9 - Extra 'Tools' menuitem : FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files (x86)\FlashGet\flashget.exe (FlashGet.com)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus....ek_sys_ctrl.cab (asusTek_sysctrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logme...ivex/RACtrl.cab (Performance Viewer Activex Control)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcp.../pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe64.dll (Trend Micro Inc.)
O18:64bit: - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1079\TmIEPlg.dll (Trend Micro Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\tmbp {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\6.5.1234\6.5.1234\TmBpIe32.dll (Trend Micro Inc.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - C:\Program Files\Trend Micro\AMSP\module\20004\1.5.1464\6.6.1079\TmIEPlg32.dll (Trend Micro Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{749caee9-d6ea-11df-98ed-00248c0998f8}\Shell - "" = AutoRun
O33 - MountPoints2\{749caee9-d6ea-11df-98ed-00248c0998f8}\Shell\AutoRun\command - "" = H:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/28 07:04:11 | 000,000,000 | --SD | C] -- C:\Users\Admin\Documents\My Shapes
[2011/04/27 21:05:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{44222E2A-778C-454E-BAAA-23120A69D7CB}
[2011/04/27 17:51:47 | 000,474,116 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Admin\AppData\Roaming\local.exe
[2011/04/27 16:36:07 | 000,474,116 | ---- | C] (Adobe Systems Incorporated) -- C:\Users\Admin\AppData\Roaming\Ubdate27,4.exe
[2011/04/27 11:21:16 | 000,560,132 | -H-- | C] (Mozilla Corporation) -- C:\Users\Admin\AppData\Roaming\svchost.exe
[2011/04/27 09:04:44 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{426CFE15-1242-4E60-B139-497496D9BDFC}
[2011/04/26 00:50:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Trend Micro Titanium Internet Security
[2011/04/26 00:50:04 | 000,105,552 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmtdi.sys
[2011/04/26 00:49:53 | 000,144,464 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmcomm.sys
[2011/04/26 00:49:53 | 000,090,704 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmactmon.sys
[2011/04/26 00:49:53 | 000,067,664 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmevtmgr.sys
[2011/04/26 00:39:18 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011/04/26 00:37:42 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7F253EB8-BC8D-4C51-B668-16AADD3C89CA}
[2011/04/25 22:13:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/04/25 22:07:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7F7E047E-8E8B-495C-B06D-7235385FB04B}
[2011/04/25 21:21:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{D6C6A8BA-0E9C-4774-8FF5-765B43F7E542}
[2011/04/25 09:21:15 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{1899E1BC-BFAC-48A3-94D4-F04CBCCD9BD7}
[2011/04/24 21:20:48 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A38E0263-6579-4387-A6C9-19E2F5F47632}
[2011/04/24 00:04:07 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7E1ACB71-2829-4151-8C4E-4D9E1FAA58A4}
[2011/04/23 23:32:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/04/23 23:32:01 | 000,024,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/04/23 17:14:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2011/04/23 12:03:39 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{9F447BE6-ADA1-4F77-B74E-618826056B14}
[2011/04/22 09:00:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/04/22 08:58:20 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/04/22 08:58:19 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/04/22 08:58:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/04/22 08:53:23 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/04/22 08:53:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011/04/21 23:38:18 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{6C02C8DF-94C2-404B-AD19-35BE9237BCE7}
[2011/04/16 23:35:59 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{607AFD77-2960-4DAF-8949-B560078019D3}
[2011/04/15 01:14:03 | 000,000,000 | ---D | C] -- C:\temp
[2011/04/10 10:01:09 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{A9EDEDB8-B794-4A65-A1AD-78FCAA22416B}
[2011/04/09 22:43:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\James Bond 007 - Blood Stone
[2011/04/09 22:19:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Activision
[2011/04/09 22:00:40 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{D5D74060-1B6E-46BF-A9AD-12FDD5B3C380}
[2011/04/08 21:59:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{940C414D-73C3-48E5-B111-2AD7BE3548A7}
[2011/04/08 21:13:19 | 004,199,768 | ---- | C] (Amyuni Technologies
http://www.amyuni.com) -- C:\Windows\SysWow64\cdintf400.dll
[2011/04/08 21:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quicken 2011
[2011/04/04 21:57:55 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{E134CF5A-54B6-4379-A21D-782CE5428FA7}
[2011/04/03 13:37:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Canneverbe Limited
[2011/04/03 13:37:47 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
[2011/04/03 13:37:28 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\OpenCandy
[2011/04/03 13:37:28 | 000,000,000 | ---D | C] -- C:\Program Files\CDBurnerXP
[2011/04/03 09:56:41 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{46F3E77F-8B7A-465E-86E1-45066B346139}
[2011/04/02 21:16:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{66CFB16C-31A0-499E-BC19-CE2AA9490C33}
[2011/04/02 09:15:54 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{7C5AA355-B1D4-4C29-B0E5-4959AA6563A5}
[2011/04/01 21:28:19 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\EA Games
[2011/04/01 21:15:26 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{BAAF4D65-F961-43B7-B33A-1960ABE8CADB}
[2011/04/01 09:14:58 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F7ADC152-3C3E-4918-8375-CD7D46BFD3B9}
[2011/03/31 09:14:20 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\{F0EE4E0A-2303-487F-9FAE-05F5D56C3E9C}
[2011/02/26 12:01:12 | 001,169,224 | ---- | C] (Microsoft Corporation) -- C:\Users\Admin\AppData\Roaming\0Q11SIUAOM.exe
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/04/27 21:22:05 | 000,025,644 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\data.dat
[2011/04/27 21:21:39 | 000,311,246 | RHS- | M] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.dat
[2011/04/27 21:08:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2045766283-185155172-3896411630-1001UA.job
[2011/04/27 19:59:37 | 000,433,443 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/04/27 19:59:37 | 000,433,443 | R--- | M] () -- C:\Users\Admin\Desktop\hosts
[2011/04/27 19:17:36 | 000,001,112 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Zinio Alert Messenger.lnk
[2011/04/27 19:17:12 | 000,004,384 | RHS- | M] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.cfg
[2011/04/27 19:16:06 | 000,000,324 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2011/04/27 19:16:00 | 000,000,632 | RHS- | M] () -- C:\Users\Admin\ntuser.pol
[2011/04/27 19:09:36 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 19:09:36 | 000,014,832 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/04/27 19:00:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/04/27 19:00:00 | 2146,246,655 | -HS- | M] () -- C:\hiberfil.sys
[2011/04/27 18:56:07 | 000,004,096 | -HS- | M] () -- C:\VSNAP.IDX
[2011/04/27 18:43:44 | 000,002,062 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2011/04/26 23:08:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2045766283-185155172-3896411630-1001Core.job
[2011/04/26 00:50:55 | 000,001,444 | ---- | M] () -- C:\Users\Admin\Desktop\Trend Micro Titanium Internet Security.lnk
[2011/04/26 00:49:50 | 000,775,342 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/04/26 00:49:50 | 000,658,310 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/04/26 00:49:50 | 000,118,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/04/23 17:14:15 | 000,001,069 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/23 17:05:11 | 005,635,094 | ---- | M] () -- C:\Users\Admin\Desktop\Sneakers.mp3
[2011/04/22 22:04:51 | 000,000,036 | ---- | M] () -- C:\Users\Admin\AppData\Local\housecall.guid.cache
[2011/04/22 09:00:36 | 000,001,786 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/21 12:30:27 | 000,008,511 | -H-- | M] () -- C:\Users\Admin\AppData\Roaming\Adminlog.dat
[2011/04/20 23:25:48 | 000,538,624 | ---- | M] () -- C:\Users\Admin\AppData\Roaming\chrtmp
[2011/04/19 16:20:01 | 000,208,448 | RHS- | M] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.xtr
[2011/04/15 03:42:26 | 005,054,936 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/04/15 00:49:00 | 000,002,491 | ---- | M] () -- C:\Users\Public\Desktop\Safari.lnk
[2011/04/10 00:04:27 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/04/10 00:04:20 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011/04/09 15:10:57 | 000,001,307 | ---- | M] () -- C:\Users\Admin\Desktop\DPC Latency Tester v1.2.0.lnk
[2011/04/08 21:13:14 | 000,001,805 | ---- | M] () -- C:\Users\Public\Desktop\Quicken Home & Business 2011.lnk
[2011/04/08 21:12:29 | 000,000,171 | ---- | M] () -- C:\Windows\QUICKEN.INI
[2011/04/08 19:24:58 | 000,000,095 | ---- | M] () -- C:\Users\Admin\Desktop\Crysis 2 Patch 1.2 + MP crack (download torrent) - TPB.url
[2011/04/03 02:24:35 | 000,001,024 | ---- | M] () -- C:\Users\Admin\.rnd
[2011/04/03 00:12:30 | 000,144,464 | ---- | M] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmcomm.sys
[2011/04/03 00:12:30 | 000,105,552 | ---- | M] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmtdi.sys
[2011/04/03 00:12:30 | 000,090,704 | ---- | M] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmactmon.sys
[2011/04/03 00:12:30 | 000,067,664 | ---- | M] (Trend Micro Inc.) -- C:\Windows\SysNative\drivers\tmevtmgr.sys
[2011/04/03 00:06:13 | 000,001,489 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2011/04/03 00:02:02 | 000,001,489 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2011/04/01 15:57:02 | 000,000,084 | ---- | M] () -- C:\Users\Admin\Desktop\WinTV-HVR-2250 Support page.url
[2011/04/01 10:35:37 | 000,002,144 | ---- | M] () -- C:\Users\Admin\Desktop\Durlap01171_work_laptop.rdp
[2011/04/01 10:28:55 | 000,002,122 | ---- | M] () -- C:\Users\Admin\Desktop\Apollo.rdp
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[2 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/04/27 19:57:09 | 000,433,443 | R--- | C] () -- C:\Users\Admin\Desktop\hosts
[2011/04/27 19:17:12 | 000,004,384 | RHS- | C] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.cfg
[2011/04/26 00:50:39 | 000,001,444 | ---- | C] () -- C:\Users\Admin\Desktop\Trend Micro Titanium Internet Security.lnk
[2011/04/25 22:07:25 | 000,025,644 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\data.dat
[2011/04/23 17:14:15 | 000,001,069 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2011/04/23 17:05:10 | 005,635,094 | ---- | C] () -- C:\Users\Admin\Desktop\Sneakers.mp3
[2011/04/22 22:00:40 | 000,000,036 | ---- | C] () -- C:\Users\Admin\AppData\Local\housecall.guid.cache
[2011/04/22 09:00:36 | 000,001,786 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/04/20 18:19:04 | 000,538,624 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\chrtmp
[2011/04/19 16:19:52 | 000,208,448 | RHS- | C] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.xtr
[2011/04/19 16:19:24 | 000,311,246 | RHS- | C] () -- C:\Users\Admin\AppData\Roaming\--((Mutex))--.dat
[2011/04/15 00:49:00 | 000,002,491 | ---- | C] () -- C:\Users\Public\Desktop\Safari.lnk
[2011/04/10 00:04:27 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/04/10 00:04:20 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/04/09 15:11:10 | 000,001,307 | ---- | C] () -- C:\Users\Admin\Desktop\DPC Latency Tester v1.2.0.lnk
[2011/04/08 21:13:13 | 000,001,805 | ---- | C] () -- C:\Users\Public\Desktop\Quicken Home & Business 2011.lnk
[2011/04/08 19:24:58 | 000,000,095 | ---- | C] () -- C:\Users\Admin\Desktop\Crysis 2 Patch 1.2 + MP crack (download torrent) - TPB.url
[2011/04/03 13:37:31 | 000,001,695 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
[2011/04/03 02:25:34 | 000,773,120 | ---- | C] () -- C:\Windows\SysWow64\NEROINSTAEC43759.DB
[2011/04/01 15:57:02 | 000,000,084 | ---- | C] () -- C:\Users\Admin\Desktop\WinTV-HVR-2250 Support page.url
[2010/12/25 23:08:03 | 000,002,062 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2010/12/23 18:29:38 | 000,000,000 | ---- | C] () -- C:\Windows\HPMProp.INI
[2010/11/23 18:45:12 | 000,189,480 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010/11/23 18:45:10 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010/11/23 18:45:09 | 003,360,624 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2010/11/11 21:12:32 | 000,007,610 | ---- | C] () -- C:\Users\Admin\AppData\Local\Resmon.ResmonCfg
[2010/11/04 18:58:59 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010/11/04 18:58:59 | 000,014,392 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010/11/04 18:58:04 | 000,026,728 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2010/10/26 22:14:27 | 000,000,163 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\PLGComp.ini
[2010/10/15 21:56:50 | 000,004,608 | ---- | C] () -- C:\Windows\SysWow64\adesk_patcher64.exe
[2010/10/15 08:40:11 | 000,000,171 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2010/10/15 03:07:36 | 000,746,018 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/15 02:02:41 | 000,000,487 | ---- | C] () -- C:\Windows\my.ini
[2010/10/14 02:36:44 | 000,179,263 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/10/13 13:32:27 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\dmcrypto.dll
[2010/10/13 13:31:37 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010/10/13 13:31:37 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/10/13 12:14:45 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010/10/11 00:42:26 | 000,001,456 | ---- | C] () -- C:\Users\Admin\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/03/03 19:48:14 | 000,215,144 | R--- | C] () -- C:\Windows\pw32a.dll
[2010/03/03 19:48:14 | 000,215,144 | R--- | C] () -- C:\Windows\patchw32.dll
[2010/02/08 07:33:04 | 000,359,320 | ---- | C] () -- C:\Windows\SysWow64\vfprintpthelper.dll
[2010/01/25 13:58:06 | 000,462,848 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/03/13 00:38:41 | 000,022,328 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\PnkBstrK.sys
[2009/03/11 19:50:10 | 000,000,105 | ---- | C] () -- C:\Users\Admin\AppData\Roaming\default.pls
[2007/12/28 03:22:02 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2005/08/13 12:42:34 | 000,008,511 | -H-- | C] () -- C:\Users\Admin\AppData\Roaming\Adminlog.dat
========== LOP Check ==========
[2010/10/13 20:59:39 | 000,000,000 | -HSD | M] -- C:\Users\Admin\AppData\Roaming\.#
[2010/10/13 20:59:39 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\1407F3B3-F6F4-42A3-9F71-9B11560DB0BD
[2010/10/13 20:59:39 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Acronis
[2011/04/03 13:44:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\App Launcher Gadget
[2010/11/04 07:34:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Autodesk
[2011/04/03 13:37:47 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Canneverbe Limited
[2010/11/04 07:34:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Canon
[2010/12/18 16:58:57 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/13 21:00:33 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/11/04 07:37:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ContentGuard
[2010/11/20 18:33:22 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FlashGet
[2010/11/04 07:37:06 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GetRightToGo
[2010/11/04 07:34:48 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\GlarySoft
[2011/03/25 08:47:19 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Hive Cluster
[2010/12/31 21:31:18 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ImgBurn
[2010/11/04 07:37:07 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\IrfanView
[2009/04/16 01:03:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\iTSfv
[2010/10/13 21:02:02 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Network Associates
[2011/04/03 13:37:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenCandy
[2010/10/07 02:46:28 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\OpenDNS Updater
[2010/11/04 07:34:53 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Opera
[2010/10/13 22:03:07 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Prish
[2011/03/08 23:59:51 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Rovio
[2010/10/13 21:02:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ScanSoft
[2010/11/20 18:35:45 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\StreamTorrent
[2010/10/07 02:46:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Subversion
[2010/11/04 07:37:09 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\TeamViewer
[2010/12/13 09:02:39 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Thinstall
[2010/10/13 21:02:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Ulead Systems
[2009/04/10 23:05:05 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Uniblue
[2011/04/27 09:55:30 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\uTorrent
[2010/10/13 21:02:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\VSO
[2010/10/13 21:02:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\WinBatch
[2010/10/13 23:02:10 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ZinioAlertMessenger.9310D8F796442B71068C511E15D70529A702D19D.1
[2010/10/13 22:55:04 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\ZinioReader4.9310D8F796442B71068C511E15D70529A702D19D.1
[2011/04/27 19:16:06 | 000,000,324 | ---- | M] () -- C:\Windows\Tasks\GlaryInitialize.job
[2010/12/20 10:16:47 | 000,032,538 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
Any help would be greatly appreciated. I use this PC for web devel work and I am worried about losing data.
Thanks... Dan