Background: Just got a new machine after the old laptop got junked out (warranty replacement). I had a copy of Photoshop CS2 on my last computer (probably not legit, but never had any issues), and the friend who did that told me he'd load CS3 for me. Apparently, it was a cracked version (I know, I know) and I've had issues since. By issues, I mean McAfee (trial version that came w/ system) found and blocked a few trojans, but was unable to remove one. I've also had issues with log-ins and clicking (after I click the mouse, it is often unresponsive or too responsive).
I just ran MBAM, which found, quarantined and removed 4 trojan.bho infections, and 1 rootkit.agent infection. Performance already seems to be improved, but I know how sneaky these things can be. OTL log follows- thanks in advance for assistance!
OTL logfile created on: 6/6/2011 12:26:27 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\Erin\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.75 Gb Total Physical Memory | 1.65 Gb Available Physical Memory | 60.19% Memory free
5.49 Gb Paging File | 3.94 Gb Available in Paging File | 71.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254.14 Gb Total Space | 216.48 Gb Free Space | 85.18% Space Free | Partition Type: NTFS
Drive D: | 29.00 Gb Total Space | 20.20 Gb Free Space | 69.66% Space Free | Partition Type: NTFS
Computer Name: ERIN-PC | User Name: Erin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/06 12:25:41 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Erin\Downloads\OTL.exe
PRC - [2011/04/14 11:25:41 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/03/24 16:25:38 | 003,122,528 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2010/03/02 17:37:40 | 000,171,104 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe
PRC - [2010/01/19 12:48:52 | 000,323,280 | ---- | M] (Napster) -- C:\Program Files (x86)\Napster\napster.exe
PRC - [2009/12/18 21:52:48 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2008/10/17 16:52:16 | 000,099,632 | ---- | M] (brother) -- C:\Program Files (x86)\Brownie\brpjp04a.exe
========== Modules (SafeList) ==========
MOD - [2011/06/06 12:25:41 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Erin\Downloads\OTL.exe
MOD - [2011/04/08 16:56:28 | 000,018,176 | ---- | M] (McAfee, Inc.) -- c:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
MOD - [2011/03/24 06:57:57 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/04/14 14:01:38 | 000,245,352 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe -- (mfefire)
SRV:64bit: - [2011/04/14 14:01:38 | 000,200,056 | ---- | M] () [Unknown | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2011/04/14 14:01:38 | 000,149,032 | ---- | M] (McAfee, Inc.) [Unknown | Running] -- C:\Program Files\Common Files\mcafee\systemcore\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2010/10/07 20:34:28 | 000,509,416 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2010/09/22 13:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/07/19 13:19:32 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2010/03/10 10:14:44 | 000,355,440 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2009/09/22 13:16:32 | 000,579,400 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\Lenovo\ReadyComm\ConnSvc.exe -- (Lenovo ReadyComm ConnSvc)
SRV:64bit: - [2009/08/14 09:22:48 | 000,509,192 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files\Lenovo\ReadyComm\AppSvc.exe -- (Lenovo ReadyComm AppSvc)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/05/17 20:27:52 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/14 09:27:26 | 000,038,152 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe -- (IGRS)
SRV - [2009/07/13 20:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\windows\SysWow64\IgrsSvcs.exe -- (ReadyComm.DirectRouter)
SRV - [2009/07/13 20:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\windows\SysWow64\IgrsSvcs.exe -- (PS_MDP)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/04/14 14:01:38 | 000,530,304 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,441,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2011/04/14 14:01:38 | 000,283,744 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,190,520 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,121,376 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,094,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mferkdet.sys -- (mferkdet)
DRV:64bit: - [2011/04/14 14:01:38 | 000,075,160 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2011/04/14 14:01:38 | 000,063,056 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/03/24 07:20:00 | 000,107,912 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/24 07:20:00 | 000,027,016 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/08/07 03:07:16 | 001,326,928 | ---- | M] (Bison Electronics. Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BisonC07.sys -- (Cam5607)
DRV:64bit: - [2010/07/19 13:45:56 | 007,448,576 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2010/07/19 12:39:40 | 000,268,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/07/15 07:47:42 | 000,116,240 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/06/17 04:15:36 | 000,016,440 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\AtiPcie64.sys -- (AtiPcie) AMD PCI Express (3GIO)
DRV:64bit: - [2010/03/11 22:23:16 | 000,242,720 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2010/02/22 05:03:44 | 000,075,304 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010/01/15 13:08:34 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2010/01/07 07:46:20 | 000,302,128 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2009/12/14 07:46:56 | 001,573,888 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\athrx.sys -- (athr)
DRV:64bit: - [2009/10/18 19:40:50 | 000,028,176 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2009/07/21 09:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/16 06:55:34 | 000,011,280 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDMirror.sys -- (wdmirror)
DRV:64bit: - [2009/07/15 22:38:20 | 000,079,376 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WDBridge.sys -- (Bridge0)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand | Running] -- C:\Windows\SysNative\wbem\ntfs.mof -- (Ntfs)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 15:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:64bit: - [2009/06/10 15:34:36 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\k57nd60a.sys -- (k57nd60a) Broadcom NetLink ™
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/08/06 07:32:16 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV:64bit: - [2007/07/26 03:00:00 | 000,053,488 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Search The Web"
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/05/26 11:12:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/05/29 12:09:12 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/05/29 12:09:12 | 000,000,000 | ---D | M]
[2011/05/13 21:11:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Erin\AppData\Roaming\Mozilla\Extensions
[2011/05/17 22:29:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Erin\AppData\Roaming\Mozilla\Firefox\Profiles\vq3n5tq0.default\extensions
[2011/05/13 21:11:25 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
File not found (No name found) --
[2011/05/26 11:12:12 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2011/04/14 11:26:02 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\components\Scriptff.dll
[2010/01/19 12:48:52 | 000,106,192 | ---- | M] ( ) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npstrlnk.dll
[2010/01/01 03:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
[2010/12/08 16:21:24 | 000,002,224 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\webblog.xml
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20110513212927.dll (McAfee, Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20110513212927.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [BrStsWnd] C:\Program Files (x86)\Brownie\BrstsW64.exe (brother)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NapsterShell] C:\Program Files (x86)\Napster\napster.exe (Napster)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UCam_Menu] C:\Program Files (x86)\Lenovo\YouCam\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [YouCam Mirror Tray icon] C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe (CyberLink Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{58de1b06-80ef-11e0-8fb1-b870f4001843}\Shell - "" = AutoRun
O33 - MountPoints2\{58de1b06-80ef-11e0-8fb1-b870f4001843}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/06/06 12:21:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/06/06 12:11:05 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Malwarebytes
[2011/06/06 12:11:01 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/06/06 12:11:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/06 12:11:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/06 12:10:57 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011/06/06 12:10:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/05/29 12:25:06 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Roxio
[2011/05/29 12:09:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Napster
[2011/05/29 12:08:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Roxio Shared
[2011/05/29 12:08:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PX Storage Engine
[2011/05/29 12:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Sonic Shared
[2011/05/29 12:08:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Napster Shared
[2011/05/29 12:07:09 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\InstallShield
[2011/05/29 12:03:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Napster
[2011/05/29 12:02:42 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Napster
[2011/05/29 12:02:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Napster
[2011/05/26 11:07:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2011/05/26 11:07:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2011/05/26 11:06:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2011/05/26 11:06:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2011/05/26 11:05:30 | 000,000,000 | ---D | C] -- C:\windows\PCHEALTH
[2011/05/26 11:05:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2011/05/26 11:03:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2011/05/26 11:03:12 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2011/05/26 11:02:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2011/05/26 11:02:13 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Microsoft Help
[2011/05/26 11:01:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2011/05/26 11:01:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2011/05/26 11:01:07 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2011/05/25 21:37:28 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\U3
[2011/05/20 06:16:03 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtualizedApplications
[2011/05/19 22:31:12 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\SoftGrid Client
[2011/05/19 22:31:11 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\SoftGrid Client
[2011/05/19 22:29:49 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\TP
[2011/05/18 23:02:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2011/05/17 22:21:32 | 000,000,000 | ---D | C] -- C:\Users\Erin\Documents\Adobe Scripts
[2011/05/17 21:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Object
[2011/05/17 21:50:42 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\MediaGet2
[2011/05/17 21:36:55 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\uTorrent
[2011/05/17 20:39:52 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2011/05/17 20:33:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011/05/17 20:31:35 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Microsoft Games
[2011/05/17 20:31:00 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\spool
[2011/05/17 20:27:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Macrovision Shared
[2011/05/17 20:24:00 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\WinRAR
[2011/05/17 20:24:00 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/17 20:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/17 20:23:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2011/05/17 06:26:29 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2011/05/17 06:26:28 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2011/05/16 11:58:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/16 11:58:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/05/16 11:58:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/05/16 11:57:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011/05/16 11:57:04 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Apple
[2011/05/16 11:57:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/05/16 11:57:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/05/16 11:32:36 | 000,086,016 | ---- | C] (MindVision Software) -- C:\windows\unvise32.exe
[2011/05/16 11:31:50 | 000,000,000 | ---D | C] -- C:\ProgramData\QuickTime
[2011/05/16 11:30:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Rosetta Stone
[2011/05/16 11:30:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Rosetta Stone
[2011/05/14 21:33:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother HL-2140
[2011/05/14 21:33:37 | 000,077,824 | ---- | C] (Brother Industries, Ltd.) -- C:\windows\SysWow64\brlmw03a.dll
[2011/05/14 21:33:35 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Brownie
[2011/05/14 21:31:56 | 000,176,128 | ---- | C] (Brother Industries, Ltd.) -- C:\windows\SysWow64\BROSNMP.DLL
[2011/05/14 21:31:56 | 000,111,928 | ---- | C] (Brother Industries Ltd) -- C:\windows\SysWow64\BRRBTOOL.EXE
[2011/05/14 21:31:55 | 000,200,704 | ---- | C] (brother) -- C:\windows\SysWow64\Pdrvinst.dll
[2011/05/14 21:31:55 | 000,024,223 | ---- | C] (Brother Industries, Ltd) -- C:\windows\SysWow64\BRLM03A.DLL
[2011/05/14 21:31:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Brother
[2011/05/14 21:26:42 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Adobe
[2011/05/13 21:11:33 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Mozilla
[2011/05/13 21:11:33 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Mozilla
[2011/05/13 21:11:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/05/13 21:09:16 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Best Buy pc app
[2011/05/13 21:06:37 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Macromedia
[2011/05/13 21:06:35 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Adobe
[2011/05/13 21:06:28 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Diagnostics
[2011/05/13 20:22:56 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011/05/13 20:18:33 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Best Buy
[2011/05/13 20:18:20 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\ATI
[2011/05/13 20:18:20 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\ATI
[2011/05/13 20:18:16 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Apps
[2011/05/13 20:18:15 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Deployment
[2011/05/13 20:17:09 | 000,000,000 | R--D | C] -- C:\Users\Erin\Searches
[2011/05/13 20:17:09 | 000,000,000 | R--D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/05/13 20:17:09 | 000,000,000 | -H-D | C] -- C:\Users\Erin\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2011/05/13 20:16:42 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Identities
[2011/05/13 20:16:39 | 000,000,000 | R--D | C] -- C:\Users\Erin\Contacts
[2011/05/13 20:16:38 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/05/13 20:16:38 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\VirtualStore
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\AppData\Local\Temporary Internet Files
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Templates
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Start Menu
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\SendTo
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Recent
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\PrintHood
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\NetHood
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Documents\My Videos
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Documents\My Pictures
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Documents\My Music
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\My Documents
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Local Settings
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\AppData\Local\History
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Cookies
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\Application Data
[2011/05/13 20:16:20 | 000,000,000 | -HSD | C] -- C:\Users\Erin\AppData\Local\Application Data
[2011/05/13 20:16:19 | 000,000,000 | --SD | C] -- C:\Users\Erin\AppData\Roaming\Microsoft
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Videos
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Saved Games
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Pictures
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Music
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Links
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Favorites
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Downloads
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\My Documents
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\Desktop
[2011/05/13 20:16:19 | 000,000,000 | R--D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/05/13 20:16:19 | 000,000,000 | -H-D | C] -- C:\Users\Erin\AppData
[2011/05/13 20:16:19 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Temp
[2011/05/13 20:16:19 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Local\Microsoft
[2011/05/13 20:16:19 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Media Center Programs
[2011/05/13 20:16:19 | 000,000,000 | ---D | C] -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
[2011/05/13 20:16:01 | 000,000,000 | -HSD | C] -- C:\Recovery
[2011/05/13 04:11:53 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2011/06/06 12:26:41 | 000,013,632 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 12:26:41 | 000,013,632 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/06 12:21:31 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2011/06/06 12:19:53 | 000,000,339 | ---- | M] () -- C:\windows\Brownie.ini
[2011/06/06 12:19:03 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2011/06/06 12:18:54 | 2210,578,432 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/06 12:11:01 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/06 12:02:10 | 002,354,040 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2011/06/01 14:42:36 | 000,327,777 | ---- | M] () -- C:\Users\Erin\Documents\Praxis Score Report 4-30-11.pdf
[2011/06/01 06:44:54 | 000,726,316 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2011/06/01 06:44:54 | 000,624,178 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2011/06/01 06:44:54 | 000,106,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2011/05/29 12:09:12 | 000,001,881 | ---- | M] () -- C:\Users\Public\Desktop\Napster.lnk
[2011/05/29 12:02:42 | 000,003,069 | ---- | M] () -- C:\Users\Erin\Desktop\Napster Download Manager.lnk
[2011/05/29 11:54:13 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/29 09:39:23 | 002,691,832 | ---- | M] () -- C:\Users\Erin\Documents\Understanding by Design 2005
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysWow64\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,025,912 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2011/05/26 13:43:31 | 000,003,584 | ---- | M] () -- C:\Users\Erin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/26 06:33:24 | 000,743,534 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/05/25 20:49:06 | 024,829,973 | ---- | M] () -- C:\Users\Erin\Documents\My Blue Room.mov
[2011/05/24 21:06:57 | 000,808,567 | ---- | M] () -- C:\Users\Erin\Documents\NTP Teaching for Results facilitator's manual.pdf
[2011/05/24 21:06:10 | 000,592,069 | ---- | M] () -- C:\Users\Erin\Documents\NTP Facilitator Orientation Manual.pdf
[2011/05/16 11:58:56 | 000,001,845 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/16 11:31:48 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\QuickTime.qtp
[2011/05/16 11:30:55 | 000,002,169 | ---- | M] () -- C:\Users\Erin\Desktop\The Rosetta Stone.lnk
[2011/05/15 18:30:11 | 000,007,680 | ---- | M] () -- C:\CurrentFileterGrp.grf
[2011/05/14 21:33:44 | 000,000,034 | ---- | M] () -- C:\windows\SysWow64\BD2140.DAT
[2011/05/14 21:33:38 | 000,009,868 | ---- | M] () -- C:\windows\HL-2140.INI
[2011/05/14 21:33:38 | 000,000,151 | ---- | M] () -- C:\windows\BRVIDEO.INI
[2011/05/14 21:33:38 | 000,000,000 | ---- | M] () -- C:\windows\brmx2001.ini
[2011/05/14 21:32:03 | 000,000,410 | ---- | M] () -- C:\windows\BRWMARK.INI
[2011/05/13 21:11:28 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/13 21:05:23 | 000,001,437 | ---- | M] () -- C:\Users\Erin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/13 20:22:48 | 000,002,239 | ---- | M] () -- C:\Users\Erin\Desktop\OneKey Recovery.lnk
[2011/05/13 20:22:14 | 000,000,088 | ---- | M] () -- C:\ProgramData\profile.xml
[2011/05/13 20:18:33 | 000,000,398 | ---- | M] () -- C:\Users\Erin\Desktop\pc app.appref-ms
[2011/05/13 20:18:20 | 000,001,118 | ---- | M] () -- C:\Users\Erin\Desktop\Cyberlink Power2Go.lnk
[2011/05/13 20:18:17 | 000,002,425 | ---- | M] () -- C:\Users\Erin\Desktop\CyberLink YouCam.lnk
[2011/05/13 20:17:58 | 000,000,432 | ---- | M] () -- C:\Users\Erin\Desktop\Desktop.lnk
[2011/05/13 04:15:31 | 000,039,252 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2011/05/13 04:15:31 | 000,039,252 | ---- | M] () -- C:\windows\SysNative\license.rtf
========== Files Created - No Company Name ==========
[2011/06/06 12:11:01 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/01 14:42:35 | 000,327,777 | ---- | C] () -- C:\Users\Erin\Documents\Praxis Score Report 4-30-11.pdf
[2011/05/29 12:09:12 | 000,001,881 | ---- | C] () -- C:\Users\Public\Desktop\Napster.lnk
[2011/05/29 12:02:42 | 000,003,069 | ---- | C] () -- C:\Users\Erin\Desktop\Napster Download Manager.lnk
[2011/05/29 11:54:13 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2011/05/29 09:39:12 | 002,691,832 | ---- | C] () -- C:\Users\Erin\Documents\Understanding by Design 2005
[2011/05/26 13:43:31 | 000,003,584 | ---- | C] () -- C:\Users\Erin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/26 12:51:48 | 024,829,973 | ---- | C] () -- C:\Users\Erin\Documents\My Blue Room.mov
[2011/05/24 21:06:57 | 000,808,567 | ---- | C] () -- C:\Users\Erin\Documents\NTP Teaching for Results facilitator's manual.pdf
[2011/05/24 21:06:10 | 000,592,069 | ---- | C] () -- C:\Users\Erin\Documents\NTP Facilitator Orientation Manual.pdf
[2011/05/19 22:30:31 | 000,743,534 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2011/05/17 20:35:08 | 000,001,137 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS3.lnk
[2011/05/17 20:33:23 | 000,001,223 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Stock Photos CS3.lnk
[2011/05/17 20:32:33 | 000,001,403 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit 2.lnk
[2011/05/17 20:32:22 | 000,001,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS3.lnk
[2011/05/17 20:30:31 | 000,001,099 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS3.lnk
[2011/05/16 11:58:56 | 000,001,845 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/16 11:57:03 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/16 11:31:48 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\QuickTime.qtp
[2011/05/16 11:30:55 | 000,002,169 | ---- | C] () -- C:\Users\Erin\Desktop\The Rosetta Stone.lnk
[2011/05/15 18:30:11 | 000,007,680 | ---- | C] () -- C:\CurrentFileterGrp.grf
[2011/05/14 21:33:38 | 000,000,151 | ---- | C] () -- C:\windows\BRVIDEO.INI
[2011/05/14 21:33:38 | 000,000,000 | ---- | C] () -- C:\windows\brmx2001.ini
[2011/05/14 21:33:37 | 000,000,114 | ---- | C] () -- C:\windows\SysWow64\brlmw03a.ini
[2011/05/14 21:33:35 | 000,009,868 | ---- | C] () -- C:\windows\HL-2140.INI
[2011/05/14 21:32:03 | 000,000,410 | ---- | C] () -- C:\windows\BRWMARK.INI
[2011/05/14 21:32:03 | 000,000,034 | ---- | C] () -- C:\windows\SysWow64\BD2140.DAT
[2011/05/14 21:31:35 | 000,000,339 | ---- | C] () -- C:\windows\Brownie.ini
[2011/05/13 21:11:28 | 000,001,150 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/05/13 21:11:28 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/05/13 21:05:23 | 000,001,437 | ---- | C] () -- C:\Users\Erin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/05/13 20:22:14 | 000,000,088 | ---- | C] () -- C:\ProgramData\profile.xml
[2011/05/13 20:18:33 | 000,000,398 | ---- | C] () -- C:\Users\Erin\Desktop\pc app.appref-ms
[2011/05/13 20:18:00 | 000,001,409 | ---- | C] () -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2011/05/13 20:17:51 | 000,001,443 | ---- | C] () -- C:\Users\Erin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/05/13 20:17:10 | 000,000,432 | ---- | C] () -- C:\Users\Erin\Desktop\Desktop.lnk
[2011/05/13 20:16:19 | 000,002,425 | ---- | C] () -- C:\Users\Erin\Desktop\CyberLink YouCam.lnk
[2011/05/13 20:16:19 | 000,002,239 | ---- | C] () -- C:\Users\Erin\Desktop\OneKey Recovery.lnk
[2011/05/13 20:16:19 | 000,001,118 | ---- | C] () -- C:\Users\Erin\Desktop\Cyberlink Power2Go.lnk
[2011/05/13 20:16:19 | 000,000,290 | ---- | C] () -- C:\Users\Erin\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2011/05/13 20:16:19 | 000,000,272 | ---- | C] () -- C:\Users\Erin\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2011/05/13 04:11:48 | 2210,578,432 | -HS- | C] () -- C:\hiberfil.sys
[2011/03/24 16:47:28 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011/03/24 16:47:28 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011/03/24 16:38:33 | 000,016,648 | R--- | C] () -- C:\windows\SysWow64\LogAPI.dll
[2011/03/24 16:25:41 | 002,110,816 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/03/24 16:25:41 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/03/24 16:25:34 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/03/24 16:09:19 | 000,015,190 | ---- | C] () -- C:\windows\M3000Twn.ini
[2011/03/24 15:52:43 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011/03/24 15:45:38 | 000,002,857 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2009/07/14 00:38:36 | 000,067,584 | ---- | C] () -- C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:59:36 | 000,982,196 | ---- | C] () -- C:\windows\SysWow64\igkrng500.bin
[2009/07/13 16:59:36 | 000,139,824 | ---- | C] () -- C:\windows\SysWow64\igfcg500.bin
[2009/07/13 16:59:36 | 000,097,448 | ---- | C] () -- C:\windows\SysWow64\igfcg500m.bin
[2009/07/13 16:59:35 | 000,417,344 | ---- | C] () -- C:\windows\SysWow64\igcompkrng500.bin
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/05/26 08:59:05 | 000,000,000 | ---D | M] -- C:\Users\Erin\AppData\Roaming\SoftGrid Client
[2011/05/19 22:31:21 | 000,000,000 | ---D | M] -- C:\Users\Erin\AppData\Roaming\TP
[2011/05/17 22:26:05 | 000,000,000 | ---D | M] -- C:\Users\Erin\AppData\Roaming\uTorrent
[2009/07/14 00:08:49 | 000,005,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >