So after months and months of ignoring these problems due to being busy with other things, I finally have time to pay attention to it.
What prompted me to look into my computer's problems just happened like an hour ago.
I turn on my computer, I open up Task Manager as I usually do, and I see like 6 wmpnscfg.exe processes open taking up a lot of cpu, and in a couple seconds, they all close.
Hmmmm....
I might have a keylogger running in the background.
Task Manager always shows two csrss.exe and rundll32.exe processes.
I asked someone if it was anything and they said it's a keylogger.
I'm concerned about that because, as badly as I want to buy stuff off Amazon and like shop for stuff on the internet, I'm paranoid to use my credit card now.
I often keep Task Manager running in the background, and every time I use my computer, Task Manager will show that my CPU Usage lingers around like 90 to 100, even when I leave my computer alone for a couple minutes.
When this happens, usually constantly, my CPU fan will blow like crazy.
Also, what's even weirder is that whenever I try to look into the problem, CPU usage drops to normal, shifting from 0 to 40 percent, like it is right now as I'm typing this.
In the past, my internet has dropped out and lagged on me, like even when it's sunny and my internet bill's been paid so maybe it's related to the CPU usage?
Another problem I've been having in the past is that Windows will randomly notify me that "new" people would connect to my home network.
That's a problem.
It could be like neighbors using my internet connection, or it could be something else that's far more dangerous, right?
Explorer.exe sometimes takes up a lot of memory, like pushing 50,000 and more.
Usually this happens when my comp is idle.
That's something I've been worried about.
Things I've used to try and fix these problems include using McAfee Antivirus and scanning, which usually comes up empty with 0 problems to be fixed, which I find hard to believe.
I've used CCleaner just to like empty out my internet cache, cookies, stuff like that, not really messing with the registry, log files and all that.
I downloaded MalwareBytes, had it scan my comp, again nothing popped up.
Basically, my problem is a laggy, sometimes slow computer with some suspect things going on.
When I bought this computer last year, it was a rocket, and it was only 512MB of RAM and running Windows XP.
Around Fall of last year to January of this year, it started to really lag on me, like I couldn't even run anything smoothly, so I had a guy look into it and clean it up, and it helped somewhat, but it was still slow.
Last month, I had my computer upgraded to Windows 7, put 2GB of RAM in my computer, and even though it's faster and things aren't freezing up on me or crashing, I still have these little annoying problems.
I've attached my OTL scan as well as the Extras.txt that came with it.
Some help would be greatly appreciated.
Thanks
OTL logfile created on: 4/14/2012 10:43:27 PM - Run 1
OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Mark\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.40 Gb Available Physical Memory | 70.15% Memory free
3.98 Gb Paging File | 3.02 Gb Available in Paging File | 75.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 35.80 Gb Free Space | 48.04% Space Free | Partition Type: NTFS
Computer Name: COMPAQ | User Name: Mark | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/04/14 22:42:44 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Mark\Downloads\OTL.exe
PRC - [2012/04/14 22:26:31 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Mark\Downloads\HijackThis.exe
PRC - [2012/02/18 07:59:28 | 000,282,648 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\saUI.exe
PRC - [2011/12/06 17:25:42 | 000,150,856 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2011/12/06 17:21:24 | 000,160,608 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2011/12/06 17:21:08 | 000,166,288 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2011/11/22 17:18:26 | 001,318,816 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2011/06/02 16:09:14 | 000,579,584 | ---- | M] (LOUD Technologies, Inc.) -- C:\Program Files\LoudAudio\MackieTaskBar.exe
PRC - [2011/04/08 13:59:50 | 000,419,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MAT\McPvTray.exe
PRC - [2011/02/25 22:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/07 16:42:10 | 000,477,560 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\MSC\McUICnt.exe
PRC - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2010/12/14 07:31:12 | 000,184,552 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\MSM\McSmtFwk.exe
PRC - [2009/07/13 18:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/04/14 07:43:42 | 000,604,704 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\SOUNDMAN.EXE
PRC - [2008/06/24 16:06:06 | 001,840,424 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
========== Modules (No Company Name) ==========
MOD - [2012/04/09 13:28:48 | 000,444,400 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\ppgooglenaclpluginchrome.dll
MOD - [2012/04/09 13:28:46 | 003,915,248 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\pdf.dll
MOD - [2012/04/09 13:27:21 | 000,122,880 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\avutil-51.dll
MOD - [2012/04/09 13:27:20 | 000,220,672 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\avformat-53.dll
MOD - [2012/04/09 13:27:19 | 001,747,456 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\avcodec-53.dll
MOD - [2012/04/09 12:42:11 | 008,743,584 | ---- | M] () -- C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/04/02 23:54:07 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/12/06 17:25:42 | 000,150,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2011/12/06 17:21:24 | 000,160,608 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2011/12/06 17:21:08 | 000,166,288 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2011/10/18 16:59:54 | 000,361,976 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2011/01/28 12:28:50 | 000,203,080 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\McAfee\MSC\McAWFwk.exe -- (McAWFwk)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (MSK80Service)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2011/01/27 18:28:14 | 000,214,904 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 18:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 18:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2003/04/18 16:06:26 | 000,008,192 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hawkes Learning Systems\Hawkes Update Service Manager\srvany.exe -- (HawkesUpdater)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (mfeavfk01)
DRV - [2011/10/15 12:16:16 | 000,464,176 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2011/10/15 12:16:16 | 000,338,176 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2011/10/15 12:16:16 | 000,180,816 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2011/10/15 12:16:16 | 000,165,680 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2011/10/15 12:16:16 | 000,121,256 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2011/10/15 12:16:16 | 000,087,656 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2011/10/15 12:16:16 | 000,064,880 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfenlfk.sys -- (mfenlfk)
DRV - [2011/10/15 12:16:16 | 000,059,456 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2011/10/15 12:16:16 | 000,057,600 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2011/06/02 16:14:46 | 000,063,552 | ---- | M] (LOUD Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MackieUSB.sys -- (MackieUSB)
DRV - [2011/04/11 14:29:16 | 000,064,048 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\McPvDrv.sys -- (McPvDrv)
DRV - [2009/07/13 18:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/13 18:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 18:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/13 16:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/13 16:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 16:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/13 15:02:53 | 000,545,792 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\netr73.sys -- (netr73)
DRV - [2009/07/13 15:02:52 | 000,043,008 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Rtnicxp.sys -- (RTL8023xp)
DRV - [2009/06/18 19:45:02 | 004,172,832 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RTKVAC.SYS -- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 24 80 7C BE 29 15 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mark\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mark\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/04/03 22:38:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/04/14 22:20:11 | 000,000,000 | ---D | M]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Mark\AppData\Local\Google\Chrome\Application\18.0.1025.152\gcswf32.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Mark\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: SiteAdvisor = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.41.123.2_0\
CHR - Extension: Gmail = C:\Users\Mark\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120404013900.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4 - HKLM..\Run: [Loud Taskbar] C:\Program Files\LoudAudio\MackieTaskBar.exe (LOUD Technologies, Inc.)
O4 - HKLM..\Run: [McPvTray_exe] C:\Program Files\McAfee\MAT\McPvTray.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Windows\System32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SoundMan] C:\Windows\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe (Nero AG)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{23FA1743-221B-4F35-89CA-14FE78318388}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2C5E10F7-F8D0-4216-A6AE-89427D7C534A}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/04/14 22:31:45 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Other
[2012/04/07 18:35:27 | 000,000,000 | ---D | C] -- C:\Users\Mark\Desktop\Beats Rough
[2012/04/04 23:25:55 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Hawkes Learning Systems
[2012/04/04 23:13:20 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Malwarebytes
[2012/04/04 23:13:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/04/04 23:13:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/04/04 23:13:11 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/04/04 23:13:11 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/04/03 22:38:34 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/04/02 23:54:08 | 000,000,000 | ---D | C] -- C:\Windows\System32\Wat
[2012/04/02 01:39:35 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2012/04/02 01:39:23 | 000,000,000 | ---D | C] -- C:\a756b714c39790502327d4c32bb8986c
[2012/04/02 01:26:39 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Audacity
[2012/04/01 22:37:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Camel Audio
[2012/04/01 22:37:30 | 000,000,000 | ---D | C] -- C:\Program Files\Camel Audio
[2012/04/01 22:37:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Camel Audio
[2012/04/01 22:08:24 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\BullzipPDFPrinter_7_2_0_1338
[2012/04/01 22:06:45 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\School
[2012/04/01 22:05:17 | 000,000,000 | -H-D | C] -- C:\ProgramData\{93906220-8503-45CF-87CB-5A54C8DE1AB2}
[2012/04/01 21:54:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hawkes Learning Systems
[2012/04/01 21:54:55 | 000,344,064 | ---- | C] (RSP Software - http://rspsoftware.clic3.net) -- C:\Windows\System32\rsp_ogg_player_ocx2.dll
[2012/04/01 21:54:54 | 000,344,064 | ---- | C] (RSP Software - http://rspsoftware.clic3.net) -- C:\Windows\System32\rsp_ogg_player_ocx1.dll
[2012/04/01 21:54:53 | 000,372,736 | ---- | C] (Aivosto Oy) -- C:\Windows\System32\vbwExtender.ocx
[2012/04/01 21:54:53 | 000,205,848 | ---- | C] (Sheridan Software Systems, Inc.) -- C:\Windows\System32\THREED32.OCX
[2012/04/01 21:54:52 | 001,328,824 | ---- | C] (FarPoint Technologies, Inc.) -- C:\Windows\System32\SPR32X60.ocx
[2012/04/01 21:54:51 | 000,159,744 | ---- | C] (RSP Software - http://svansa.tripod.com) -- C:\Windows\System32\rsp_ogg_vorbis_ocx_320reg.ocx
[2012/04/01 21:53:35 | 000,000,000 | ---D | C] -- C:\Program Files\Hawkes Learning Systems
[2012/04/01 21:52:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2012/04/01 21:51:21 | 000,000,000 | -H-D | C] -- C:\ProgramData\{A77F137D-236E-4155-A17D-2DA1AC94D44C}
[2012/04/01 21:50:54 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\PackageAware
[2012/04/01 21:17:53 | 000,064,048 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\McPvDrv.sys
[2012/04/01 21:17:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/04/01 21:17:51 | 000,000,000 | R-SD | C] -- C:\Users\Mark\Documents\McAfee Vaults
[2012/04/01 21:17:51 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\McAfee Anti-Theft
[2012/04/01 21:17:05 | 000,009,608 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeclnk.sys
[2012/04/01 21:15:59 | 000,165,680 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfewfpk.sys
[2012/04/01 21:15:59 | 000,064,880 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfenlfk.sys
[2012/04/01 21:15:58 | 000,464,176 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfehidk.sys
[2012/04/01 21:15:58 | 000,338,176 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfefirek.sys
[2012/04/01 21:15:58 | 000,180,816 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeavfk.sys
[2012/04/01 21:15:58 | 000,121,256 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfeapfk.sys
[2012/04/01 21:15:58 | 000,087,656 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mferkdet.sys
[2012/04/01 21:15:58 | 000,059,456 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\mfebopk.sys
[2012/04/01 21:15:58 | 000,057,600 | ---- | C] (McAfee, Inc.) -- C:\Windows\System32\drivers\cfwids.sys
[2012/04/01 21:15:46 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2012/04/01 21:15:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Mcafee
[2012/04/01 21:15:40 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2012/04/01 21:08:21 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012/04/01 21:01:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/04/01 21:01:45 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/04/01 20:48:02 | 000,225,280 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\rewire.dll
[2012/04/01 20:48:02 | 000,000,000 | ---D | C] -- C:\Program Files\VstPlugins
[2012/04/01 20:48:00 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Image-Line
[2012/04/01 20:47:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2012/04/01 20:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Outsim
[2012/04/01 20:44:15 | 000,000,000 | ---D | C] -- C:\Program Files\Image-Line
[2012/04/01 20:42:18 | 000,000,000 | ---D | C] -- C:\Program Files\Audacity
[2012/04/01 20:26:22 | 000,000,000 | ---D | C] -- C:\Program Files\DIFX
[2012/04/01 20:17:22 | 000,000,000 | ---D | C] -- C:\Program Files\LoudAudio
[2012/04/01 20:15:41 | 000,232,448 | ---- | C] (LOUD Technologies, Inc.) -- C:\Windows\Mackie64.exe
[2012/04/01 20:15:41 | 000,204,800 | ---- | C] (LOUD Technologies, Inc.) -- C:\Windows\Mackie.exe
[2012/04/01 20:15:41 | 000,063,552 | ---- | C] (LOUD Technologies, Inc.) -- C:\Windows\System32\drivers\MackieUSB.sys
[2012/04/01 20:14:02 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\WinRAR
[2012/04/01 20:14:01 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/04/01 20:14:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/04/01 20:13:34 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR
[2012/04/01 20:12:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Macromedia
[2012/04/01 20:12:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Adobe
[2012/04/01 20:09:32 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/04/01 20:07:05 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Google
[2012/04/01 19:39:34 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Diagnostics
[2012/04/01 19:37:11 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\Music
[2012/04/01 18:06:37 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\dvdcss
[2012/04/01 18:04:49 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\vlc
[2012/04/01 18:04:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/04/01 18:04:04 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN
[2012/03/31 22:56:24 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Babylon
[2012/03/31 22:56:22 | 000,000,000 | ---D | C] -- C:\Program Files\FoxTabVideoConverter
[2012/03/31 22:56:18 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Babylon
[2012/03/31 22:56:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Babylon
[2012/03/31 22:19:28 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\CyberLink
[2012/03/31 22:19:11 | 000,000,000 | ---D | C] -- C:\Users\Mark\Documents\CyberLink
[2012/03/31 22:18:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD
[2012/03/31 22:18:02 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2012/03/31 22:17:57 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information
[2012/03/31 22:17:55 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
[2012/03/31 22:11:52 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield
[2012/03/31 21:46:52 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Nero
[2012/03/31 21:42:42 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Ahead
[2012/03/31 21:42:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 8
[2012/03/31 21:39:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Nero
[2012/03/31 21:39:04 | 000,000,000 | ---D | C] -- C:\Program Files\Nero
[2012/03/31 21:39:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero
[2012/03/31 21:12:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
[2012/03/31 21:11:36 | 000,106,496 | ---- | C] (Pegasus Software) -- C:\Windows\System32\TwnLib20.dll
[2012/03/31 21:11:32 | 000,038,912 | ---- | C] (Pegasus Imaging Corp.) -- C:\Windows\System32\picn20.dll
[2012/03/31 21:11:30 | 000,569,344 | ---- | C] (Pegasus Software,LLC) -- C:\Windows\System32\imagr5.dll
[2012/03/31 21:11:30 | 000,544,768 | ---- | C] (Pegasus Software, LLC) -- C:\Windows\System32\imagx5.dll
[2012/03/31 21:11:30 | 000,283,920 | ---- | C] (Pegasus Software, LLC) -- C:\Windows\System32\ImagXpr5.dll
[2012/03/31 21:11:27 | 000,155,648 | ---- | C] (Ahead Software Gmbh) -- C:\Windows\System32\NeroCheck.exe
[2012/03/31 21:11:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Ahead
[2012/03/31 21:11:22 | 000,000,000 | ---D | C] -- C:\Program Files\Ahead
[2012/03/31 20:47:37 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2012/03/31 20:47:22 | 000,000,000 | -HSD | C] -- C:\Boot
[2012/03/31 20:35:15 | 000,000,000 | ---D | C] -- C:\Windows.old
[2012/03/31 20:34:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/03/31 20:34:00 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync
[2012/03/31 20:33:39 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2012/03/31 20:33:24 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012/03/31 20:33:24 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET
[2012/03/31 20:24:28 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/03/31 20:08:56 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Microsoft Help
[2012/03/31 20:08:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/03/31 20:08:44 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2012/03/31 20:02:37 | 000,000,000 | R--D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/03/31 20:02:37 | 000,000,000 | R--D | C] -- C:\Users\Mark\Searches
[2012/03/31 20:02:37 | 000,000,000 | R--D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/03/31 20:02:36 | 000,000,000 | -H-D | C] -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/03/31 20:02:23 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Identities
[2012/03/31 20:02:15 | 000,000,000 | R--D | C] -- C:\Users\Mark\Contacts
[2012/03/31 20:01:53 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\VirtualStore
[2012/03/31 20:01:48 | 000,000,000 | --SD | C] -- C:\Users\Mark\AppData\Roaming\Microsoft
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Videos
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Saved Games
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Pictures
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Music
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Links
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Favorites
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Downloads
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Documents
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\Desktop
[2012/03/31 20:01:48 | 000,000,000 | R--D | C] -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\AppData\Local\Temporary Internet Files
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Templates
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Start Menu
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\SendTo
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Recent
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\PrintHood
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\NetHood
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Documents\My Videos
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Documents\My Pictures
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Documents\My Music
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\My Documents
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Local Settings
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\AppData\Local\History
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Cookies
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\Application Data
[2012/03/31 20:01:48 | 000,000,000 | -HSD | C] -- C:\Users\Mark\AppData\Local\Application Data
[2012/03/31 20:01:48 | 000,000,000 | -H-D | C] -- C:\Users\Mark\AppData
[2012/03/31 20:01:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Temp
[2012/03/31 20:01:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Local\Microsoft
[2012/03/31 20:01:48 | 000,000,000 | ---D | C] -- C:\Users\Mark\AppData\Roaming\Media Center Programs
[2012/03/31 20:01:29 | 000,000,000 | -HSD | C] -- C:\Recovery
[2012/03/31 19:52:15 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2012/03/31 19:49:02 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
========== Files - Modified Within 30 Days ==========
[2012/04/14 22:24:37 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/14 22:24:37 | 000,014,224 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/14 22:23:17 | 000,623,940 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/04/14 22:23:17 | 000,106,316 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/04/14 22:21:24 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/04/14 22:15:58 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/04/14 22:15:52 | 1603,969,024 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/14 00:12:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-406179606-2168368824-3621562350-1000UA.job
[2012/04/13 20:12:02 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-406179606-2168368824-3621562350-1000Core.job
[2012/04/09 19:20:55 | 000,002,354 | ---- | M] () -- C:\Users\Mark\Desktop\Google Chrome.lnk
[2012/04/03 10:21:45 | 000,001,407 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/04/03 10:19:28 | 000,359,352 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/04/03 00:02:02 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/04/01 23:49:40 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/04/01 21:54:59 | 000,001,275 | ---- | M] () -- C:\Users\Public\Desktop\Intermediate Algebra.lnk
[2012/04/01 21:01:46 | 000,000,965 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/04/01 20:48:02 | 000,001,104 | ---- | M] () -- C:\Users\Mark\Desktop\FL Studio 10.lnk
[2012/04/01 20:42:40 | 000,000,965 | ---- | M] () -- C:\Users\Mark\Desktop\Audacity.lnk
[2012/04/01 19:41:13 | 000,000,000 | -H-- | M] () -- C:\Users\Mark\Documents\Default.rdp
[2012/04/01 18:04:41 | 000,001,024 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/03/31 22:30:09 | 000,000,042 | ---- | M] () -- C:\Users\Mark\AppData\Roaming\default.pls
[2012/03/31 21:42:04 | 000,002,703 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk
[2012/03/31 21:42:04 | 000,002,679 | ---- | M] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/03/31 21:42:04 | 000,002,605 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home Essentials SE.lnk
[2012/03/31 21:42:04 | 000,002,581 | ---- | M] () -- C:\Users\Public\Desktop\Nero Home Essentials SE.lnk
[2012/03/31 21:41:13 | 000,001,024 | ---- | M] () -- C:\Users\Mark\.rnd
[2012/03/31 21:12:40 | 000,001,568 | ---- | M] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2012/03/31 20:47:25 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2012/03/31 20:47:23 | 000,000,355 | RHS- | M] () -- C:\Boot.ini.saved
[2012/03/31 20:47:08 | 000,001,345 | ---- | M] () -- C:\Users\Mark\Desktop\Media Center.lnk
[2012/03/31 20:46:59 | 000,001,326 | ---- | M] () -- C:\Users\Mark\Desktop\Windows DVD Maker.lnk
[2012/03/31 20:46:52 | 000,002,645 | ---- | M] () -- C:\Users\Mark\Desktop\Microsoft Office PowerPoint 2003.lnk
[2012/03/31 20:46:45 | 000,002,693 | ---- | M] () -- C:\Users\Mark\Desktop\Microsoft Office Outlook 2003.lnk
[2012/03/31 20:46:39 | 000,002,675 | ---- | M] () -- C:\Users\Mark\Desktop\Microsoft Office Word 2003.lnk
[2012/03/31 20:35:39 | 000,000,376 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/03/31 20:04:49 | 000,000,003 | RHS- | M] () -- C:\win7ldr
[2012/03/31 20:04:49 | 000,000,003 | ---- | M] () -- C:\Windows\7Loader.TAG
[2012/03/31 20:04:06 | 000,203,316 | RHS- | M] () -- C:\grldr
[2012/03/31 19:53:18 | 000,042,045 | ---- | M] () -- C:\Windows\System32\license.rtf
[2012/03/31 19:51:07 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
========== Files Created - No Company Name ==========
[2012/04/03 10:21:45 | 000,001,413 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/04/03 00:02:02 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/04/01 23:49:40 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/04/01 21:54:59 | 000,001,275 | ---- | C] () -- C:\Users\Public\Desktop\Intermediate Algebra.lnk
[2012/04/01 21:20:06 | 000,001,828 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/04/01 21:01:46 | 000,000,965 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/04/01 20:48:02 | 000,001,104 | ---- | C] () -- C:\Users\Mark\Desktop\FL Studio 10.lnk
[2012/04/01 20:42:40 | 000,000,977 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012/04/01 20:42:40 | 000,000,965 | ---- | C] () -- C:\Users\Mark\Desktop\Audacity.lnk
[2012/04/01 20:15:41 | 000,193,088 | ---- | C] () -- C:\Windows\System32\LoudAudioProp.dll
[2012/04/01 20:15:41 | 000,122,944 | ---- | C] () -- C:\Windows\System32\MackieAsio.dll
[2012/04/01 20:09:36 | 000,002,354 | ---- | C] () -- C:\Users\Mark\Desktop\Google Chrome.lnk
[2012/04/01 20:07:10 | 000,000,904 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-406179606-2168368824-3621562350-1000UA.job
[2012/04/01 20:07:05 | 000,000,852 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-406179606-2168368824-3621562350-1000Core.job
[2012/04/01 19:41:13 | 000,000,000 | -H-- | C] () -- C:\Users\Mark\Documents\Default.rdp
[2012/04/01 18:04:41 | 000,001,024 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/03/31 22:30:09 | 000,000,042 | ---- | C] () -- C:\Users\Mark\AppData\Roaming\default.pls
[2012/03/31 21:42:04 | 000,002,703 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart Essentials.lnk
[2012/03/31 21:42:04 | 000,002,679 | ---- | C] () -- C:\Users\Public\Desktop\Nero StartSmart Essentials.lnk
[2012/03/31 21:42:04 | 000,002,605 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero Home Essentials SE.lnk
[2012/03/31 21:42:04 | 000,002,581 | ---- | C] () -- C:\Users\Public\Desktop\Nero Home Essentials SE.lnk
[2012/03/31 21:41:12 | 000,001,024 | ---- | C] () -- C:\Users\Mark\.rnd
[2012/03/31 21:12:40 | 000,001,568 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Nero StartSmart.lnk
[2012/03/31 20:47:25 | 000,008,192 | RHS- | C] () -- C:\BOOTSECT.BAK
[2012/03/31 20:47:23 | 000,383,562 | RHS- | C] () -- C:\bootmgr
[2012/03/31 20:47:23 | 000,000,211 | -H-- | C] () -- C:\Boot.BAK
[2012/03/31 20:47:08 | 000,001,345 | ---- | C] () -- C:\Users\Mark\Desktop\Media Center.lnk
[2012/03/31 20:46:59 | 000,001,326 | ---- | C] () -- C:\Users\Mark\Desktop\Windows DVD Maker.lnk
[2012/03/31 20:46:52 | 000,002,645 | ---- | C] () -- C:\Users\Mark\Desktop\Microsoft Office PowerPoint 2003.lnk
[2012/03/31 20:46:45 | 000,002,693 | ---- | C] () -- C:\Users\Mark\Desktop\Microsoft Office Outlook 2003.lnk
[2012/03/31 20:46:39 | 000,002,675 | ---- | C] () -- C:\Users\Mark\Desktop\Microsoft Office Word 2003.lnk
[2012/03/31 20:35:39 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/03/31 20:23:26 | 000,001,407 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/03/31 20:04:49 | 000,203,316 | RHS- | C] () -- C:\grldr
[2012/03/31 20:04:49 | 000,000,003 | RHS- | C] () -- C:\win7ldr
[2012/03/31 20:04:49 | 000,000,003 | ---- | C] () -- C:\Windows\7Loader.TAG
[2012/03/31 20:01:48 | 000,000,290 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/03/31 20:01:48 | 000,000,272 | ---- | C] () -- C:\Users\Mark\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/03/31 19:53:03 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012/03/31 19:52:55 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012/03/31 19:51:07 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2012/03/31 19:48:32 | 1603,969,024 | -HS- | C] () -- C:\hiberfil.sys
========== LOP Check ==========
[2012/04/10 23:59:53 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Audacity
[2012/03/31 22:56:18 | 000,000,000 | ---D | M] -- C:\Users\Mark\AppData\Roaming\Babylon
[2009/07/13 21:53:46 | 000,011,582 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >