Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Slow computer, start up, and start up on programs? [Closed]


  • This topic is locked This topic is locked

#1
Aerostalgic

Aerostalgic

    New Member

  • Member
  • Pip
  • 2 posts
Hello reader, this is my issue with my laptop.
So, this laptop is a Toshiba, and its a little over 2 months old(got it in mid august). And it was working fine until now.
Everything is slow on start up, fire fox keeps giving me the (not responding) and i am not sure if its going to do the same on other browsers.Also, when windows starts up, it takes a abnormal amount of time for it to get past the "Starting/Resuming Windows" screen.
Now, its not as if it just got progressively worse, it just randomly started to happen around Saturday or Friday, and i believe there is a virus causing the massive slow down.

[1.] I've tried simple solutions such as using the system back up, worked well for a while, then re-continued.
[2.] I went on the Microsoft site and tried some options there, i apparently can't run sfc on the command prompt because its unable to run.
[3.] I used some spyware/Malware removers but i don't think it fount anything.

And now with no other clue what to do, i turn to you, whom has more of an idea on what the heck i can do next.

Thank you.

OTL LOG

OTL logfile created on: 10/2/2012 1:15:22 PM - Run 1
OTL by OldTimer - Version 3.2.70.1 Folder = C:\Users\Soap\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 2.33 Gb Available Physical Memory | 67.28% Memory free
6.94 Gb Paging File | 5.58 Gb Available in Paging File | 80.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.97 Gb Total Space | 386.72 Gb Free Space | 85.75% Space Free | Partition Type: NTFS

Computer Name: SOAP-PC | User Name: Soap | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/02 13:15:05 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\Soap\Downloads\OTL.exe
PRC - [2012/10/02 00:22:26 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
PRC - [2012/09/06 19:04:30 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2012/08/26 22:29:05 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/08/21 16:41:03 | 001,807,560 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_4_402_265.exe
PRC - [2012/08/21 13:33:48 | 000,123,320 | ---- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe
PRC - [2012/05/29 11:45:18 | 001,300,376 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
PRC - [2012/05/29 11:44:58 | 002,693,008 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.97\deploy\LoLLauncher.exe
PRC - [2011/11/30 20:17:01 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe
PRC - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/02 00:22:26 | 003,093,624 | ---- | M] () -- C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
MOD - [2012/09/06 19:04:30 | 002,244,064 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/08/21 16:41:03 | 009,813,704 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2012/05/29 11:45:18 | 001,300,376 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
MOD - [2012/05/29 11:44:58 | 002,693,008 | ---- | M] () -- C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.97\deploy\LoLLauncher.exe
MOD - [2012/04/30 03:55:48 | 000,026,112 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\swresample-0.dll
MOD - [2012/04/30 03:55:45 | 008,358,400 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avcodec-54.dll
MOD - [2012/04/30 03:55:45 | 001,152,512 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avformat-54.dll
MOD - [2012/04/30 03:55:45 | 000,333,824 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\swscale-2.dll
MOD - [2012/04/30 03:55:45 | 000,151,040 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avutil-51.dll


========== Services (SafeList) ==========

SRV:64bit: - [2012/02/24 17:36:24 | 000,138,152 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2012/02/13 19:38:18 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012/02/09 22:28:32 | 000,295,360 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:64bit: - [2012/02/02 18:33:46 | 000,580,608 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2011/12/14 18:11:38 | 000,833,976 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\Toshiba\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:64bit: - [2010/10/20 17:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Running] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/10/16 16:06:40 | 001,039,360 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\lxducoms.exe -- (lxdu_device)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/09/10 16:19:45 | 004,537,664 | ---- | M] () [Auto | Running] -- c:\program files (x86)\common files\akamai/netsession_win_5891ae0.dll -- (Akamai)
SRV - [2012/09/06 19:04:30 | 000,114,144 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/08/26 22:29:05 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/08/21 13:33:48 | 000,123,320 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe -- (Norton PC Checkup Application Launcher)
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011/11/30 20:17:01 | 000,126,392 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe -- (PCCUJobMgr)
SRV - [2011/10/01 08:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 08:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/09/13 12:15:37 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/07/11 20:16:06 | 000,057,216 | ---- | M] (TOSHIBA Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2011/06/17 13:33:04 | 000,237,008 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\McAfee Security Scan\3.0.207\McCHSvc.exe -- (McComponentHostService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/13 20:09:14 | 010,826,240 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/02/13 18:36:26 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/02/01 14:54:56 | 000,031,872 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
DRV:64bit: - [2012/01/16 18:49:14 | 000,103,536 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2012/01/14 07:05:54 | 000,056,448 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2012/01/04 15:24:18 | 000,220,288 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdxhc.sys -- (amdxhc)
DRV:64bit: - [2012/01/04 15:24:18 | 000,103,552 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdhub30.sys -- (amdhub30)
DRV:64bit: - [2011/12/22 22:22:12 | 000,412,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/12/05 17:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/10/01 08:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 08:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 08:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 08:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/07/28 17:33:50 | 000,313,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2011/07/18 19:11:10 | 001,145,448 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/08 22:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2010/11/26 18:02:18 | 000,017,720 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2009/07/30 23:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009/07/14 18:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/07 12:51:42 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV:64bit: - [2009/06/19 22:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2010/11/01 06:08:46 | 000,014,544 | ---- | M] (OpenLibSys.org) [File_System | On_Demand | Stopped] -- C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys -- (WinRing0_1_2_0)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}
IE:64bit: - HKLM\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNP
IE - HKLM\..\SearchScopes,DefaultScope = {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}
IE - HKLM\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNP
IE - HKLM\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://fastestwebsea...q={searchterms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.toshiba.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT3225826
IE - HKCU\..\URLSearchHook: {b6ac5e3c-5ceb-4e72-b451-f0e1ba983c14} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {F7CB2E9E-1800-4307-9F4B-9012C32C5842}
IE - HKCU\..\SearchScopes\{{67A2568C-7A0A-4EED-AECC-B5405DE63B64}}: "URL" = http://www.google.co...ng}&rlz=1I7TSNP
IE - HKCU\..\SearchScopes\{614F75A9-A517-41B7-8194-9C806DB3E534}: "URL" = http://search.condui...&ctid=CT3225826
IE - HKCU\..\SearchScopes\{E627DC4B-8C04-4234-A2D4-1D634EE01C41}: "URL" = http://fastestwebsea...q={searchterms}
IE - HKCU\..\SearchScopes\{F7CB2E9E-1800-4307-9F4B-9012C32C5842}: "URL" = http://www.google.co...1I7TSNP_enUS498
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Fastest"
FF - prefs.js..browser.search.defaulturl: "http://fastestwebsea...={searchTerms}"
FF - prefs.js..browser.search.order.1: "http://fastestwebsea...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://search.condui...earchSource=13"
FF - prefs.js..keyword.URL: "http://search.condui...rchSource=2&q="
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Users\Soap\AppData\Local\Roblox\Versions\version-470c28140c5148c2\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/24 05:31:04 | 000,000,000 | ---D | M]

[2012/10/01 17:49:56 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Soap\AppData\Roaming\Mozilla\Extensions
[2012/09/06 19:04:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/06 19:04:30 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/29 04:40:16 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/07/25 17:09:20 | 000,005,859 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fastestwebsearch.xml
[2012/08/29 04:40:15 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (AP Suggestor) - {D0984FD4-FA9A-46ee-9072-70B0735FF852} - C:\Program Files (x86)\AP Suggestor\APSuggestor.dll (APSolo LTD UK)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {B6AC5E3C-5CEB-4E72-B451-F0E1BA983C14} - No CLSID value found.
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\Toshiba\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe (Toshiba)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9 - Extra Button: AP Suggestor - {02E2473F-766B-4ce2-8FD0-C4E8071EF1C4} - C:\Program Files (x86)\AP Suggestor\APSuggestor.dll (APSolo LTD UK)
O9 - Extra 'Tools' menuitem : AP Suggestor options - {02E2473F-766B-4ce2-8FD0-C4E8071EF1C4} - C:\Program Files (x86)\AP Suggestor\APSuggestor.dll (APSolo LTD UK)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A7CFBE5D-006B-4166-B9C1-1E708BBCBB72}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/02 03:33:48 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\ElevatedDiagnostics
[2012/10/02 03:33:47 | 000,000,000 | ---D | C] -- C:\windows\pss
[2012/10/02 02:53:01 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\LolClient
[2012/10/02 01:50:58 | 000,000,000 | ---D | C] -- C:\Riot Games
[2012/10/02 01:50:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2012/10/02 00:22:42 | 000,000,000 | ---D | C] -- C:\Users\Soap\Desktop\League of legends
[2012/10/02 00:22:32 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\PMB Files
[2012/10/02 00:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2012/10/01 22:42:16 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\CrashDumps
[2012/10/01 18:12:02 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\Macromedia
[2012/10/01 17:50:06 | 000,000,000 | ---D | C] -- C:\Mozilla
[2012/10/01 17:47:39 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\Toshiba
[2012/10/01 17:46:55 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\Apple Computer
[2012/10/01 17:46:29 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\ATI
[2012/10/01 17:46:29 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\ATI
[2012/10/01 17:46:27 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\BitTorrent
[2012/10/01 17:46:18 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\TOSHIBA
[2012/10/01 16:04:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2012/10/01 15:22:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/10/01 15:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/10/01 15:22:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/09/25 23:39:54 | 000,000,000 | ---D | C] -- C:\Users\Soap\Documents\My Games
[2012/09/24 06:48:09 | 000,000,000 | ---D | C] -- C:\ProgramData\lx_Cats
[2012/09/24 06:47:50 | 000,000,000 | ---D | C] -- C:\Program Files\Lexmark 5600-6600 Series
[2012/09/24 05:30:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2012/09/24 05:30:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2012/09/24 05:30:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2012/09/24 05:29:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2012/09/24 05:29:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2012/09/24 05:29:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2012/09/23 18:05:38 | 000,000,000 | ---D | C] -- C:\5c4b85423b8a1ae1800da0cdf0
[2012/09/23 16:49:45 | 000,000,000 | ---D | C] -- C:\Users\Soap\Desktop\Borderlands 2 PC full game ^^nosTEAM^^
[2012/09/23 15:54:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\R.G. World Games
[2012/09/22 18:23:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wild Tangent - Fate
[2012/09/22 16:29:41 | 000,000,000 | ---D | C] -- C:\Users\Soap\Desktop\FATE2_-_Undiscovered_Realms_[tfile.ru]
[2012/09/22 16:26:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Conduit
[2012/09/22 16:26:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BitTorrent
[2012/09/21 12:36:19 | 000,000,000 | ---D | C] -- C:\ProgramData\VirtualizedApplications
[2012/09/21 07:44:47 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/09/21 07:39:39 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\SoftGrid Client
[2012/09/21 07:39:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[2012/09/21 07:38:04 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/09/21 07:38:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/09/21 07:38:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Application Virtualization Client
[2012/09/16 23:03:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Celestia Luna Online Alpha
[2012/09/16 13:59:06 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Local\Module
[2012/09/16 04:15:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Perfect World Entertainment
[2012/09/16 04:06:56 | 000,000,000 | ---D | C] -- C:\Perfect World Entertainment
[2012/09/16 02:48:46 | 000,000,000 | ---D | C] -- C:\Users\Soap\Desktop\FW_EN_Installer_0.245.0
[2012/09/15 22:49:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Algodoo Phun Edition
[2012/09/08 20:53:34 | 000,000,000 | ---D | C] -- C:\Users\Soap\AppData\Roaming\.minecraft
[2012/09/07 19:49:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
[2012/09/07 19:49:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SplitMediaLabs
[2012/09/07 19:24:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\agwak3
[2012/09/07 19:22:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AP Suggestor
[2012/09/06 19:04:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/02 13:05:16 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/02 13:05:05 | 000,000,386 | ---- | M] () -- C:\windows\tasks\update-sys.job
[2012/10/02 13:05:05 | 000,000,386 | ---- | M] () -- C:\windows\tasks\update-S-1-5-21-304364499-1681903878-315236120-1000.job
[2012/10/02 13:04:59 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/10/02 04:22:35 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/02 04:22:35 | 000,024,608 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/02 04:11:39 | 000,779,724 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/10/02 04:11:39 | 000,660,770 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/10/02 04:11:39 | 000,121,408 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/10/02 04:00:35 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/02 03:59:06 | 2794,450,944 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/02 02:07:05 | 000,001,725 | ---- | M] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/10/01 20:38:13 | 000,000,630 | ---- | M] () -- C:\Users\Soap\Desktop\troll face.lnk
[2012/10/01 20:29:17 | 000,010,261 | ---- | M] () -- C:\Users\Soap\Documents\troll face.jpg
[2012/10/01 19:16:34 | 000,000,175 | ---- | M] () -- C:\Users\Public\Desktop\DragonNest.url
[2012/10/01 17:48:24 | 000,056,681 | ---- | M] () -- C:\windows\SysNative\tmp.xml
[2012/10/01 17:45:44 | 000,274,320 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/10/01 16:04:25 | 000,001,794 | ---- | M] () -- C:\Users\Public\Desktop\Opera.lnk
[2012/09/25 23:36:22 | 000,000,274 | ---- | M] () -- C:\Users\Public\Documents\neople_uninstaller1.bat
[2012/09/24 06:48:09 | 000,000,154 | ---- | M] () -- C:\windows\SysNative\LexFiles.ulf
[2012/09/24 05:30:52 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/09/23 13:50:27 | 000,002,032 | ---- | M] () -- C:\Users\Soap\Desktop\Play Minecraft!.lnk
[2012/09/23 03:03:51 | 000,796,420 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/09/22 16:26:18 | 000,000,928 | ---- | M] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2012/09/16 04:23:52 | 000,000,942 | ---- | M] () -- C:\Users\Soap\Desktop\Forsaken World.lnk
[2012/09/10 16:30:41 | 000,000,274 | ---- | M] () -- C:\Users\Public\Documents\neople_uninstaller0.bat
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/02 02:07:05 | 000,001,725 | ---- | C] () -- C:\Users\Public\Desktop\Play League of Legends.lnk
[2012/10/01 20:29:17 | 000,010,261 | ---- | C] () -- C:\Users\Soap\Documents\troll face.jpg
[2012/10/01 20:29:17 | 000,000,630 | ---- | C] () -- C:\Users\Soap\Desktop\troll face.lnk
[2012/10/01 19:16:34 | 000,000,175 | ---- | C] () -- C:\Users\Public\Desktop\DragonNest.url
[2012/10/01 17:45:34 | 000,274,320 | ---- | C] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/10/01 16:04:25 | 000,001,794 | ---- | C] () -- C:\Users\Public\Desktop\Opera.lnk
[2012/09/25 23:36:22 | 000,000,274 | ---- | C] () -- C:\Users\Public\Documents\neople_uninstaller1.bat
[2012/09/24 06:48:09 | 000,000,154 | ---- | C] () -- C:\windows\SysNative\LexFiles.ulf
[2012/09/24 06:47:05 | 000,300,032 | ---- | C] () -- C:\windows\SysNative\lxdugrd.dll
[2012/09/24 06:46:41 | 000,521,216 | ---- | C] ( ) -- C:\windows\SysNative\lxduih.exe
[2012/09/24 06:46:41 | 000,109,056 | ---- | C] () -- C:\windows\SysNative\lxduvs.dll
[2012/09/24 06:46:40 | 001,661,952 | ---- | C] ( ) -- C:\windows\SysNative\lxduserv.dll
[2012/09/24 06:46:40 | 001,338,368 | ---- | C] ( ) -- C:\windows\SysNative\lxduusb1.dll
[2012/09/24 06:46:40 | 001,291,264 | ---- | C] ( ) -- C:\windows\SysNative\lxducomc.dll
[2012/09/24 06:46:40 | 001,091,584 | ---- | C] ( ) -- C:\windows\SysNative\lxduhbn3.dll
[2012/09/24 06:46:40 | 001,039,360 | ---- | C] ( ) -- C:\windows\SysNative\lxducoms.exe
[2012/09/24 06:46:40 | 000,987,648 | ---- | C] ( ) -- C:\windows\SysNative\lxdupmui.dll
[2012/09/24 06:46:40 | 000,897,024 | ---- | C] ( ) -- C:\windows\SysNative\lxdulmpm.dll
[2012/09/24 06:46:40 | 000,580,608 | ---- | C] ( ) -- C:\windows\SysNative\lxducomm.dll
[2012/09/24 06:46:40 | 000,548,352 | ---- | C] ( ) -- C:\windows\SysNative\lxduinpa.dll
[2012/09/24 06:46:40 | 000,513,024 | ---- | C] ( ) -- C:\windows\SysNative\lxduiesc.dll
[2012/09/24 06:46:39 | 000,610,304 | ---- | C] ( ) -- C:\windows\SysNative\lxducfg.exe
[2012/09/24 06:45:59 | 001,400,320 | ---- | C] () -- C:\windows\SysNative\lxdudrs64.dll
[2012/09/24 06:45:59 | 001,036,288 | ---- | C] () -- C:\windows\SysWow64\lxdudrs.dll
[2012/09/24 06:45:59 | 000,081,920 | ---- | C] () -- C:\windows\SysWow64\lxducaps.dll
[2012/09/24 06:45:59 | 000,069,632 | ---- | C] () -- C:\windows\SysWow64\lxducnv4.dll
[2012/09/24 06:45:59 | 000,054,784 | ---- | C] () -- C:\windows\SysNative\lxducnv464.dll
[2012/09/24 06:45:59 | 000,025,600 | ---- | C] () -- C:\windows\SysNative\lxducaps64.dll
[2012/09/24 05:30:52 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2012/09/24 05:29:29 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012/09/23 13:50:27 | 000,002,032 | ---- | C] () -- C:\Users\Soap\Desktop\Play Minecraft!.lnk
[2012/09/22 16:26:17 | 000,000,928 | ---- | C] () -- C:\Users\Public\Desktop\BitTorrent.lnk
[2012/09/16 04:23:51 | 000,000,942 | ---- | C] () -- C:\Users\Soap\Desktop\Forsaken World.lnk
[2012/09/10 16:30:41 | 000,000,274 | ---- | C] () -- C:\Users\Public\Documents\neople_uninstaller0.bat
[2012/08/26 22:29:07 | 000,281,288 | ---- | C] () -- C:\windows\SysWow64\PnkBstrB.exe
[2012/08/26 22:29:05 | 000,076,888 | ---- | C] () -- C:\windows\SysWow64\PnkBstrA.exe
[2012/07/13 01:01:27 | 000,796,420 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/07/13 00:03:19 | 000,451,072 | ---- | C] () -- C:\windows\SysWow64\ISSRemoveSP.exe
[2012/07/12 23:35:05 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2012/07/12 23:30:12 | 000,204,960 | ---- | C] () -- C:\windows\SysWow64\ativvsvl.dat
[2012/07/12 23:30:12 | 000,157,152 | ---- | C] () -- C:\windows\SysWow64\ativvsva.dat
[2012/07/12 23:30:12 | 000,003,917 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2012/02/13 19:31:50 | 000,054,784 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
[2012/02/09 16:42:58 | 000,023,040 | ---- | C] () -- C:\windows\SysWow64\kdbsdk32.dll
[2011/05/31 02:39:50 | 000,058,368 | ---- | C] () -- C:\windows\SysWow64\bdmpegv.dll
[2011/05/31 02:38:18 | 000,015,360 | ---- | C] () -- C:\windows\SysWow64\bdmjpeg.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/10/01 17:44:39 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\.minecraft
[2012/10/01 18:52:25 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\BitTorrent
[2012/10/01 17:44:39 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\BlueSprig
[2012/10/01 17:44:39 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\IObit
[2012/10/02 02:53:01 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\LolClient
[2012/10/01 17:44:40 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\SoftGrid Client
[2012/10/01 17:47:39 | 000,000,000 | ---D | M] -- C:\Users\Soap\AppData\Roaming\Toshiba

========== Purity Check ==========



< End of report >

[Edit] After doing a system reboot its still slow, but the problem continues, here a new otl log just incase.

OTL logfile created on: 10/6/2012 7:37:26 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Soapy\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.47 Gb Total Physical Memory | 2.53 Gb Available Physical Memory | 72.92% Memory free
6.94 Gb Paging File | 6.02 Gb Available in Paging File | 86.83% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 450.97 Gb Total Space | 427.32 Gb Free Space | 94.76% Space Free | Partition Type: NTFS

Computer Name: SOAPY-PC | User Name: Soapy | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/10/06 19:37:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Soapy\Desktop\OTL.exe
PRC - [2012/10/06 19:06:30 | 000,874,896 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe
PRC - [2012/09/07 17:04:44 | 000,981,656 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/07/27 19:57:30 | 004,837,248 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASC.exe
PRC - [2012/05/28 15:56:36 | 000,288,128 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe


========== Modules (No Company Name) ==========

MOD - [2012/10/06 19:06:50 | 000,316,928 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2012/10/06 19:06:50 | 000,276,480 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2012/10/06 19:06:50 | 000,168,448 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012/10/06 19:06:50 | 000,099,840 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012/10/06 19:06:50 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2012/10/06 19:06:50 | 000,076,800 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2012/10/06 19:06:50 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2012/10/06 19:06:50 | 000,064,000 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2012/10/06 19:06:50 | 000,046,592 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2012/10/06 19:06:50 | 000,045,568 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gsttypefindfunctions.dll
MOD - [2012/10/06 19:06:48 | 000,783,360 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll
MOD - [2012/10/06 19:06:48 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2012/10/06 19:06:48 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012/10/06 17:53:49 | 009,813,424 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll
MOD - [2012/05/24 10:46:52 | 000,599,936 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\DiskMap.dll
MOD - [2012/05/24 10:46:44 | 008,902,016 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\WebUI.dll
MOD - [2012/05/24 10:46:34 | 000,564,752 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\sqlite3.dll
MOD - [2012/05/24 10:46:12 | 000,058,752 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\NtfsData.dll
MOD - [2011/04/21 16:54:40 | 000,347,024 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\madexcept_.bpl
MOD - [2011/04/21 16:54:40 | 000,179,088 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\madbasic_.bpl
MOD - [2011/04/21 16:54:40 | 000,046,480 | ---- | M] () -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\maddisAsm_.bpl


========== Services (SafeList) ==========

SRV:64bit: - [2012/02/24 17:36:24 | 000,138,152 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe -- (TOSHIBA HDD SSD Alert Service)
SRV:64bit: - [2012/02/13 19:38:18 | 000,235,520 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2012/02/09 22:28:32 | 000,295,360 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\TECO\TecoService.exe -- (TOSHIBA eco Utility Service)
SRV:64bit: - [2012/02/02 18:33:46 | 000,580,608 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe -- (TosCoSrv)
SRV:64bit: - [2011/12/14 18:11:38 | 000,833,976 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files\Toshiba\TPHM\TPCHSrv.exe -- (TPCHSrv)
SRV:64bit: - [2010/10/20 17:41:00 | 000,138,656 | ---- | M] (TOSHIBA Corporation) [Auto | Stopped] -- C:\Windows\SysNative\TODDSrv.exe -- (TODDSrv)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/10/06 17:53:54 | 000,250,288 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/09/07 17:04:46 | 000,676,936 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/09/07 17:04:46 | 000,399,432 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/05/26 12:04:52 | 000,913,792 | ---- | M] (IObit) [Auto | Stopped] -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe -- (AdvancedSystemCareService5)
SRV - [2011/11/30 20:17:01 | 000,126,392 | R--- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe -- (PCCUJobMgr)
SRV - [2011/11/30 20:15:45 | 000,135,608 | R--- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe -- (Norton PC Checkup Application Launcher)
SRV - [2011/11/29 23:17:50 | 000,138,248 | R--- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Norton Anti-Theft\Engine\1.2.0.29\ccSvcHst.exe -- (NAT)
SRV - [2011/11/06 13:14:12 | 002,191,240 | ---- | M] (Toshiba America Information Systems.) [Auto | Stopped] -- C:\Program Files (x86)\Toshiba\ToshibaRegistration\TaisRegistPinger.exe -- (taisregispinger)
SRV - [2011/08/10 08:52:54 | 000,138,760 | R--- | M] (Symantec Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\ccSvcHst.exe -- (NIS)
SRV - [2011/07/11 20:16:06 | 000,057,216 | ---- | M] (TOSHIBA Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe -- (TMachInfo)
SRV - [2010/11/20 23:24:08 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010/03/18 16:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/10/05 08:14:38 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/02/13 20:09:14 | 010,826,240 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/02/13 18:36:26 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/02/01 14:54:56 | 000,031,872 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdkmpfd.sys -- (amdkmpfd)
DRV:64bit: - [2012/01/16 18:49:14 | 000,103,536 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2012/01/14 07:05:54 | 000,056,448 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2012/01/04 15:24:18 | 000,220,288 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdxhc.sys -- (amdxhc)
DRV:64bit: - [2012/01/04 15:24:18 | 000,103,552 | ---- | M] (Advanced Micro Devices, INC.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdhub30.sys -- (amdhub30)
DRV:64bit: - [2011/12/22 22:22:12 | 000,412,432 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2011/12/05 17:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/11/04 19:59:30 | 000,167,048 | R--- | M] (Symantec Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\NATx64\0102000.01D\ccSetx64.sys -- (ccSet_NAT)
DRV:64bit: - [2011/08/08 11:38:06 | 000,167,048 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\ccSetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2011/08/02 14:22:10 | 000,729,720 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2011/08/02 14:22:10 | 000,037,496 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2011/07/28 17:33:50 | 000,313,448 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2011/07/28 15:20:02 | 001,084,536 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2011/07/25 14:18:40 | 000,401,016 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\symnets.sys -- (SymNetS)
DRV:64bit: - [2011/07/25 14:18:36 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\SymDS64.sys -- (SymDS)
DRV:64bit: - [2011/07/25 14:15:52 | 000,189,560 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NISx64\1301000.01C\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2011/07/18 19:11:10 | 001,145,448 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtl8192ce.sys -- (RTL8192Ce)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/08 22:07:00 | 000,038,096 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PGEffect.sys -- (PGEffect)
DRV:64bit: - [2010/11/20 23:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 23:23:47 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:64bit: - [2010/11/20 23:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 23:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2009/07/30 23:22:04 | 000,027,784 | ---- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tdcmdpst.sys -- (tdcmdpst)
DRV:64bit: - [2009/07/14 18:31:18 | 000,026,840 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/07 12:51:42 | 000,009,216 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV:64bit: - [2009/06/19 22:15:22 | 000,014,472 | ---- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\TVALZFL.sys -- (TVALZFL)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2011/08/09 21:00:00 | 002,048,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\EX64.SYS -- (NAVEX15)
DRV - [2011/08/09 21:00:00 | 000,117,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20110810.019\ENG64.SYS -- (NAVENG)
DRV - [2011/07/25 14:15:12 | 001,151,096 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20110723.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2011/07/20 13:43:24 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20110726.001\IDSviA64.sys -- (IDSVia64)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes,DefaultScope = {7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{7CC94BCA-8E5E-4FAD-ACE5-798C208642BC}: "URL" = http://www.google.co...age={startPage}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.toshiba.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.toshiba.com
IE - HKCU\..\SearchScopes,DefaultScope = {5AFD939A-3182-4976-BCCF-CCFEB9B0D8DA}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{5AFD939A-3182-4976-BCCF-CCFEB9B0D8DA}: "URL" = http://www.google.co...1I7TSNP_enUS504
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.57\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012/10/05 20:37:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012/10/06 17:03:59 | 000,000,000 | ---D | M]


O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (TOSHIBA Media Controller Plug-in) - {F3C88694-EFFA-4d78-B409-54B7B2535B14} - C:\Program Files (x86)\Toshiba\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll (<TOSHIBA>)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.1.0.28\CoIEPlg.dll (Symantec Corporation)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\Toshiba\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosNC] C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosReelTimeMonitor] C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\Toshiba\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\Toshiba\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\Toshiba\Power Saver\TPwrMain.exe ()
O4 - HKLM..\Run: [NortonOnlineBackupReminder] C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe (Toshiba)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 5] C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCTray.exe (IObit)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll (Google Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.75.75 75.75.76.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BD64EE2-E669-43DF-BE32-4648D1DD8C81}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/10/06 19:37:08 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Soapy\Desktop\OTL.exe
[2012/10/06 19:24:25 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\BlueSprig
[2012/10/06 19:24:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JetClean
[2012/10/06 19:24:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BlueSprig
[2012/10/06 19:18:56 | 001,147,392 | ---- | C] (J.C. Kessels) -- C:\windows\SysNative\MyDefragScreenSaver_v4.3.1.exe
[2012/10/06 19:18:55 | 000,485,376 | ---- | C] (J.C. Kessels) -- C:\windows\SysNative\MyDefragScreenSaver_v4.3.1.scr
[2012/10/06 19:18:53 | 000,000,000 | ---D | C] -- C:\Program Files\MyDefrag v4.3.1
[2012/10/06 19:10:57 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2012/10/06 19:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced SystemCare 5
[2012/10/06 19:10:27 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\IObit
[2012/10/06 19:09:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2012/10/06 19:07:41 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Malwarebytes
[2012/10/06 19:07:33 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Opera
[2012/10/06 19:07:33 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\Opera
[2012/10/06 19:07:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/10/06 19:07:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/10/06 19:07:04 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/10/06 19:07:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/10/06 19:06:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Opera
[2012/10/06 18:42:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/10/06 18:42:10 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/10/06 18:37:17 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\ParetoLogic
[2012/10/06 18:37:17 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\DriverCure
[2012/10/06 18:37:11 | 000,000,000 | ---D | C] -- C:\ProgramData\ParetoLogic
[2012/10/06 17:51:47 | 000,998,536 | ---- | C] (Solid State Networks) -- C:\Users\Soapy\Documents\install_flashplayer11x32_chrd_aih.exe
[2012/10/05 22:29:46 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\CrashDumps
[2012/10/05 22:05:10 | 000,000,000 | ---D | C] -- C:\Users\Soapy\Desktop\League of legends
[2012/10/05 22:04:18 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\PMB Files
[2012/10/05 22:04:13 | 000,000,000 | ---D | C] -- C:\ProgramData\PMB Files
[2012/10/05 22:03:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pando Networks
[2012/10/05 22:02:40 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Adobe
[2012/10/05 22:02:03 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Google
[2012/10/05 22:02:01 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\Google
[2012/10/05 20:57:49 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Toshiba
[2012/10/05 20:55:41 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\ATI
[2012/10/05 20:55:41 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\ATI
[2012/10/05 20:53:50 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\TOSHIBA
[2012/10/05 20:52:14 | 000,000,000 | R--D | C] -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/10/05 20:52:14 | 000,000,000 | R--D | C] -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/10/05 20:52:13 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Searches
[2012/10/05 20:52:13 | 000,000,000 | -H-D | C] -- C:\Users\Soapy\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/10/05 20:51:04 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Identities
[2012/10/05 20:50:35 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Contacts
[2012/10/05 20:50:28 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\VirtualStore
[2012/10/05 20:47:49 | 000,000,000 | ---D | C] -- C:\windows\Minidump
[2012/10/05 20:37:42 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\WinBatch
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\AppData\Local\Temporary Internet Files
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Templates
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Start Menu
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\SendTo
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Recent
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\PrintHood
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\NetHood
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Documents\My Videos
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Documents\My Pictures
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Documents\My Music
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Local Settings
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\AppData\Local\History
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Cookies
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\Application Data
[2012/10/05 20:36:24 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\AppData\Local\Application Data
[2012/10/05 20:36:23 | 000,000,000 | --SD | C] -- C:\Users\Soapy\AppData\Roaming\Microsoft
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Videos
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Saved Games
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Pictures
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Music
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Links
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Favorites
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Downloads
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Documents
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\Desktop
[2012/10/05 20:36:23 | 000,000,000 | R--D | C] -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/10/05 20:36:23 | 000,000,000 | -HSD | C] -- C:\Users\Soapy\My Documents
[2012/10/05 20:36:23 | 000,000,000 | -H-D | C] -- C:\Users\Soapy\AppData
[2012/10/05 20:36:23 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\Temp
[2012/10/05 20:36:23 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Local\Microsoft
[2012/10/05 20:36:23 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Media Center Programs
[2012/10/05 20:36:23 | 000,000,000 | ---D | C] -- C:\Users\Soapy\AppData\Roaming\Macromedia
[2012/10/05 08:52:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Toshiba Online Backup
[2012/10/05 08:50:31 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NortonPCCheckupx64
[2012/10/05 08:50:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton PC Checkup
[2012/10/05 08:50:31 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NortonPCCheckupx64\0200110.026
[2012/10/05 08:47:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PlayReady
[2012/10/05 08:14:38 | 000,174,200 | ---- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/10/05 08:14:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2012/10/05 08:14:38 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2012/10/05 08:01:05 | 001,084,536 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymEFA64.sys
[2012/10/05 08:01:05 | 000,729,720 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtsp64.sys
[2012/10/05 08:01:05 | 000,451,192 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymDS64.sys
[2012/10/05 08:01:05 | 000,401,016 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\symnets.sys
[2012/10/05 08:01:05 | 000,189,560 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\Ironx64.sys
[2012/10/05 08:01:05 | 000,167,048 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\ccSetx64.sys
[2012/10/05 08:01:05 | 000,037,496 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtspx64.sys
[2012/10/05 08:00:03 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NISx64
[2012/10/05 08:00:03 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NISx64\1301000.01C
[2012/10/05 07:59:58 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2012/10/05 07:59:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Internet Security
[2012/10/05 07:44:58 | 000,167,048 | R--- | C] (Symantec Corporation) -- C:\windows\SysNative\drivers\NATx64\0102000.01D\ccSetx64.sys
[2012/10/05 07:44:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton™ Anti-Theft
[2012/10/05 07:44:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Anti-Theft
[2012/10/05 07:44:57 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NATx64
[2012/10/05 07:44:57 | 000,000,000 | ---D | C] -- C:\windows\SysNative\drivers\NATx64\0102000.01D
[2012/10/05 07:44:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetZero
[2012/10/05 07:09:06 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2012/10/05 07:06:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2012/10/05 07:04:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2012/10/05 07:00:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com
[2012/10/05 06:59:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TOSHIBA Corporation
[2012/10/05 01:31:07 | 000,000,000 | ---D | C] -- C:\089d138f944c1c4b23
[2012/10/05 01:26:35 | 000,000,000 | ---D | C] -- C:\windows\SysNative\tr
[2012/10/05 01:26:35 | 000,000,000 | ---D | C] -- C:\windows\SysNative\sv
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\sk
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\ru
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\pl
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\no
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\nl
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\it
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\hu
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\fr
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\fi
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\es
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\el
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\de
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\da
[2012/10/05 01:26:34 | 000,000,000 | ---D | C] -- C:\windows\SysNative\cs
[2012/10/04 21:48:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek WLAN Driver
[2012/10/04 21:00:26 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Atheros_L1e
[2012/10/04 20:58:56 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\sda
[2012/10/04 20:57:47 | 000,000,000 | ---D | C] -- C:\Program Files\Synaptics
[2012/10/04 20:46:51 | 000,000,000 | ---D | C] -- C:\windows\SysNative\DRVSTORE
[2012/10/04 12:35:53 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012/10/04 12:35:52 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\RTCOM
[2012/10/04 12:31:08 | 002,605,400 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\WavesGUILib.dll
[2012/10/04 12:31:08 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSX64.dll
[2012/10/04 12:31:08 | 000,221,024 | ---- | C] (Synopsys, Inc.) -- C:\windows\SysNative\SFNHK64.dll
[2012/10/04 12:31:08 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSTSH64.dll
[2012/10/04 12:31:08 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSHP64.dll
[2012/10/04 12:31:08 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\windows\SysNative\SRSWOW64.dll
[2012/10/04 12:31:08 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\windows\SysNative\SFCOM64.dll
[2012/10/04 12:31:04 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEP64A.dll
[2012/10/04 12:31:04 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DHT64.dll
[2012/10/04 12:31:04 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RP3DAA64.dll
[2012/10/04 12:31:04 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEED64A.dll
[2012/10/04 12:31:04 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEL64A.dll
[2012/10/04 12:31:04 | 000,078,688 | ---- | C] (Synopsys, Inc.) -- C:\windows\SysNative\SFAPO64.dll
[2012/10/04 12:31:04 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\windows\SysNative\RTEEG64A.dll
[2012/10/04 12:31:04 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\windows\SysWow64\SFCOM.dll
[2012/10/04 12:31:01 | 008,363,864 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioRealtek.dll
[2012/10/04 12:31:01 | 007,163,744 | ---- | C] (Dolby Laboratories) -- C:\windows\SysNative\R4EEP64A.dll
[2012/10/04 12:31:01 | 002,131,288 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioEQ.dll
[2012/10/04 12:31:01 | 001,247,576 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioRealtek264.dll
[2012/10/04 12:31:01 | 000,433,504 | ---- | C] (Dolby Laboratories) -- C:\windows\SysNative\R4EED64A.dll
[2012/10/04 12:31:01 | 000,396,632 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxVolumeSDAPO.dll
[2012/10/04 12:31:01 | 000,137,056 | ---- | C] (Dolby Laboratories) -- C:\windows\SysNative\R4EEL64A.dll
[2012/10/04 12:31:01 | 000,120,160 | ---- | C] (Dolby Laboratories) -- C:\windows\SysNative\R4EEA64A.dll
[2012/10/04 12:31:01 | 000,075,104 | ---- | C] (Dolby Laboratories) -- C:\windows\SysNative\R4EEG64A.dll
[2012/10/04 12:31:00 | 000,978,776 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPOShell64.dll
[2012/10/04 12:31:00 | 000,341,336 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO30.dll
[2012/10/04 12:31:00 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\windows\SysNative\MaxxAudioAPO20.dll
[2012/10/04 12:30:59 | 000,603,984 | ---- | C] (Knowles Acoustics ) -- C:\windows\SysNative\KAAPORT64.dll
[2012/10/04 12:30:44 | 002,528,832 | ---- | C] (Fortemedia Corporation) -- C:\windows\SysNative\FMAPO64.dll
[2012/10/04 12:30:44 | 000,693,352 | ---- | C] (DTS) -- C:\windows\SysNative\DTSVoiceClarityDLL64.dll
[2012/10/04 12:30:44 | 000,537,456 | ---- | C] (DTS) -- C:\windows\SysNative\DTSU2PLFX64.dll
[2012/10/04 12:30:44 | 000,524,656 | ---- | C] (DTS) -- C:\windows\SysNative\DTSU2PGFX64.dll
[2012/10/04 12:30:44 | 000,449,392 | ---- | C] (DTS) -- C:\windows\SysNative\DTSU2PREC64.dll
[2012/10/04 12:30:42 | 001,756,264 | ---- | C] (DTS) -- C:\windows\SysNative\DTSS2SpeakerDLL64.dll
[2012/10/04 12:30:42 | 001,568,360 | ---- | C] (DTS) -- C:\windows\SysNative\DTSS2HeadphoneDLL64.dll
[2012/10/04 12:30:42 | 001,486,952 | ---- | C] (DTS) -- C:\windows\SysNative\DTSBoostDLL64.dll
[2012/10/04 12:30:42 | 000,728,680 | ---- | C] (DTS) -- C:\windows\SysNative\DTSBassEnhancementDLL64.dll
[2012/10/04 12:30:42 | 000,712,296 | ---- | C] (DTS) -- C:\windows\SysNative\DTSSymmetryDLL64.dll
[2012/10/04 12:30:42 | 000,491,112 | ---- | C] (DTS) -- C:\windows\SysNative\DTSNeoPCDLL64.dll
[2012/10/04 12:30:42 | 000,432,744 | ---- | C] (DTS) -- C:\windows\SysNative\DTSLimiterDLL64.dll
[2012/10/04 12:30:42 | 000,428,648 | ---- | C] (DTS) -- C:\windows\SysNative\DTSGainCompensatorDLL64.dll
[2012/10/04 12:30:42 | 000,242,792 | ---- | C] (DTS) -- C:\windows\SysNative\DTSLFXAPO64.dll
[2012/10/04 12:30:42 | 000,242,792 | ---- | C] (DTS) -- C:\windows\SysNative\DTSGFXAPO64.dll
[2012/10/04 12:30:42 | 000,241,768 | ---- | C] (DTS) -- C:\windows\SysNative\DTSGFXAPONS64.dll
[2012/10/04 12:30:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2012/10/04 12:30:35 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2012/10/04 11:19:22 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/10/04 10:59:03 | 000,000,000 | ---D | C] -- C:\windows\kdb
[2012/10/04 10:58:29 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2012/10/04 10:58:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD
[2012/10/04 10:57:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/10/04 10:57:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012/10/04 10:57:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ATI Technologies
[2012/10/04 10:56:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
[2012/10/04 10:53:36 | 000,000,000 | ---D | C] -- C:\Program Files\ATI
[2012/10/04 10:53:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ATI Technologies
[2012/10/04 10:53:10 | 000,494,592 | ---- | C] (AMD) -- C:\windows\SysNative\atieclxx.exe
[2012/10/04 10:53:10 | 000,235,520 | ---- | C] (AMD) -- C:\windows\SysNative\atiesrxx.exe
[2012/10/04 10:53:10 | 000,120,320 | ---- | C] (AMD) -- C:\windows\SysNative\atitmm64.dll
[2012/10/04 10:53:10 | 000,058,880 | ---- | C] (AMD) -- C:\windows\SysNative\coinst.dll
[2012/10/04 10:53:10 | 000,021,504 | ---- | C] (AMD) -- C:\windows\SysNative\atimuixx.dll
[2012/10/04 10:49:11 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/10/04 09:57:45 | 000,000,000 | ---D | C] -- C:\windows\SoftwareDistribution
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/10/06 19:54:12 | 000,024,400 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/06 19:54:12 | 000,024,400 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/06 19:45:32 | 000,274,320 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/10/06 19:37:08 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Soapy\Desktop\OTL.exe
[2012/10/06 19:10:30 | 000,001,279 | ---- | M] () -- C:\Users\Public\Desktop\Uninstaller.lnk
[2012/10/06 19:10:30 | 000,001,228 | ---- | M] () -- C:\Users\Public\Desktop\Advanced SystemCare 5.lnk
[2012/10/06 19:08:47 | 000,050,798 | ---- | M] () -- C:\Users\Soapy\Documents\cc_20121006_160831.reg
[2012/10/06 19:07:13 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/06 19:06:51 | 000,001,836 | ---- | M] () -- C:\Users\Soapy\Documents\Opera.lnk
[2012/10/06 18:57:05 | 000,778,150 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/10/06 18:57:05 | 000,659,818 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/10/06 18:57:05 | 000,120,714 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/10/06 18:52:00 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/10/06 18:51:00 | 2794,450,944 | -HS- | M] () -- C:\hiberfil.sys
[2012/10/06 18:42:10 | 000,000,833 | ---- | M] () -- C:\Users\Soapy\Documents\CCleaner.lnk
[2012/10/06 18:11:46 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/06 17:53:58 | 000,000,830 | ---- | M] () -- C:\windows\tasks\Adobe Flash Player Updater.job
[2012/10/06 17:51:47 | 000,998,536 | ---- | M] (Solid State Networks) -- C:\Users\Soapy\Documents\install_flashplayer11x32_chrd_aih.exe
[2012/10/06 17:25:24 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/06 17:10:03 | 002,353,512 | ---- | M] () -- C:\Users\Soapy\Desktop\LeagueofLegends (1).exe
[2012/10/05 22:04:10 | 001,443,572 | ---- | M] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\Cat.DB
[2012/10/05 21:59:49 | 000,001,444 | ---- | M] () -- C:\Users\Soapy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/05 20:28:20 | 000,108,227 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2012/10/05 20:28:20 | 000,108,227 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2012/10/05 08:47:44 | 000,002,085 | ---- | M] () -- C:\Users\Soapy\Documents\Toshiba Book Place.lnk
[2012/10/05 08:45:33 | 000,772,430 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/10/05 08:14:38 | 000,174,200 | ---- | M] (Symantec Corporation) -- C:\windows\SysNative\drivers\SYMEVENT64x86.SYS
[2012/10/05 08:14:38 | 000,007,530 | ---- | M] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/10/05 08:14:38 | 000,000,855 | ---- | M] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/10/05 05:54:36 | 000,001,711 | ---- | M] () -- C:\Users\Soapy\Documents\TOSHIBA Media Controller.lnk
[2012/10/04 20:58:22 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/10/04 11:06:13 | 000,000,000 | ---- | M] () -- C:\windows\ativpsrm.bin
[2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/10/06 19:44:54 | 000,274,320 | ---- | C] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/10/06 19:10:30 | 000,001,279 | ---- | C] () -- C:\Users\Public\Desktop\Uninstaller.lnk
[2012/10/06 19:10:30 | 000,001,228 | ---- | C] () -- C:\Users\Public\Desktop\Advanced SystemCare 5.lnk
[2012/10/06 19:08:43 | 000,050,798 | ---- | C] () -- C:\Users\Soapy\Documents\cc_20121006_160831.reg
[2012/10/06 19:07:13 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/10/06 19:06:51 | 000,001,848 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012/10/06 19:06:51 | 000,001,836 | ---- | C] () -- C:\Users\Soapy\Documents\Opera.lnk
[2012/10/06 18:42:10 | 000,000,833 | ---- | C] () -- C:\Users\Soapy\Documents\CCleaner.lnk
[2012/10/06 17:10:01 | 002,353,512 | ---- | C] () -- C:\Users\Soapy\Desktop\LeagueofLegends (1).exe
[2012/10/05 21:59:49 | 000,001,444 | ---- | C] () -- C:\Users\Soapy\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/10/05 20:52:53 | 000,001,450 | ---- | C] () -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/10/05 20:52:51 | 000,001,416 | ---- | C] () -- C:\Users\Soapy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/10/05 20:36:23 | 000,000,290 | ---- | C] () -- C:\Users\Soapy\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/10/05 20:36:23 | 000,000,272 | ---- | C] () -- C:\Users\Soapy\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/10/05 20:35:54 | 001,443,572 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\Cat.DB
[2012/10/05 08:50:31 | 000,000,172 | ---- | C] () -- C:\windows\SysNative\drivers\NortonPCCheckupx64\0200110.026\isolate.ini
[2012/10/05 08:47:44 | 000,002,085 | ---- | C] () -- C:\Users\Soapy\Documents\Toshiba Book Place.lnk
[2012/10/05 08:45:30 | 000,772,430 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/10/05 08:14:38 | 000,007,530 | ---- | C] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.CAT
[2012/10/05 08:14:38 | 000,000,855 | ---- | C] () -- C:\windows\SysNative\drivers\SYMEVENT64x86.INF
[2012/10/05 08:00:35 | 000,001,440 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymNet.inf
[2012/10/05 08:00:33 | 000,003,433 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymEFA.inf
[2012/10/05 08:00:33 | 000,002,852 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymDS.inf
[2012/10/05 08:00:33 | 000,001,438 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtsp64.inf
[2012/10/05 08:00:33 | 000,001,420 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtspx64.inf
[2012/10/05 08:00:33 | 000,000,854 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\ccSetx64.inf
[2012/10/05 08:00:33 | 000,000,772 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\Iron.inf
[2012/10/05 08:00:10 | 000,002,801 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymVTcer.dat
[2012/10/05 08:00:05 | 000,007,458 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\symnet64.cat
[2012/10/05 08:00:04 | 000,007,504 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtspx64.cat
[2012/10/05 08:00:04 | 000,007,502 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymEFA64.cat
[2012/10/05 08:00:04 | 000,007,500 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\srtsp64.cat
[2012/10/05 08:00:04 | 000,007,496 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\SymDS64.cat
[2012/10/05 08:00:04 | 000,007,492 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\iron.cat
[2012/10/05 08:00:03 | 000,007,510 | R--- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\ccSetx64.cat
[2012/10/05 08:00:03 | 000,000,172 | ---- | C] () -- C:\windows\SysNative\drivers\NISx64\1301000.01C\isolate.ini
[2012/10/05 07:44:57 | 000,007,468 | R--- | C] () -- C:\windows\SysNative\drivers\NATx64\0102000.01D\ccSetx64.cat
[2012/10/05 07:44:57 | 000,000,853 | R--- | C] () -- C:\windows\SysNative\drivers\NATx64\0102000.01D\ccSetx64.inf
[2012/10/05 07:44:57 | 000,000,172 | ---- | C] () -- C:\windows\SysNative\drivers\NATx64\0102000.01D\isolate.ini
[2012/10/05 07:05:12 | 000,000,912 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/10/05 07:05:04 | 000,000,908 | ---- | C] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/10/05 07:00:51 | 000,001,722 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon.com - Shopping.lnk
[2012/10/05 05:54:36 | 000,001,711 | ---- | C] () -- C:\Users\Soapy\Documents\TOSHIBA Media Controller.lnk
[2012/10/04 21:48:17 | 000,451,072 | ---- | C] () -- C:\windows\SysWow64\ISSRemoveSP.exe
[2012/10/04 20:58:22 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_SynTP_01009.Wdf
[2012/10/04 12:31:04 | 000,238,744 | ---- | C] () -- C:\windows\SysNative\drivers\RTAIODAT.DAT
[2012/10/04 11:06:13 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2012/10/04 10:53:10 | 002,557,568 | ---- | C] () -- C:\windows\SysWow64\atiumdva.cap
[2012/10/04 10:53:10 | 002,555,840 | ---- | C] () -- C:\windows\SysNative\atiumd6a.cap
[2012/10/04 10:53:10 | 000,600,880 | ---- | C] () -- C:\windows\SysNative\atiicdxx.dat
[2012/10/04 10:53:10 | 000,226,456 | ---- | C] () -- C:\windows\SysWow64\atiapfxx.blb
[2012/10/04 10:53:10 | 000,226,456 | ---- | C] () -- C:\windows\SysNative\atiapfxx.blb
[2012/10/04 10:53:10 | 000,204,960 | ---- | C] () -- C:\windows\SysWow64\ativvsvl.dat
[2012/10/04 10:53:10 | 000,204,960 | ---- | C] () -- C:\windows\SysNative\ativvsvl.dat
[2012/10/04 10:53:10 | 000,157,152 | ---- | C] () -- C:\windows\SysWow64\ativvsva.dat
[2012/10/04 10:53:10 | 000,157,152 | ---- | C] () -- C:\windows\SysNative\ativvsva.dat
[2012/10/04 10:53:10 | 000,037,141 | ---- | C] () -- C:\windows\atiogl.xml
[2012/10/04 10:53:10 | 000,003,917 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2012/10/04 10:53:10 | 000,003,917 | ---- | C] () -- C:\windows\SysNative\atipblag.dat
[2012/10/04 09:50:38 | 2794,450,944 | -HS- | C] () -- C:\hiberfil.sys
[2012/04/17 09:33:06 | 000,270,311 | ---- | C] () -- C:\windows\IEDel.exe
[2012/04/17 09:33:06 | 000,006,044 | ---- | C] () -- C:\windows\LANGVARS-es.INI
[2012/04/17 09:33:06 | 000,005,706 | ---- | C] () -- C:\windows\LANGVARS-en.INI
[2012/04/17 09:33:05 | 001,356,832 | ---- | C] () -- C:\windows\ROnce.exe
[2012/04/17 09:33:05 | 000,005,706 | ---- | C] () -- C:\windows\LANGVARS.INI
[2012/02/13 19:31:50 | 000,054,784 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
[2012/02/09 16:42:58 | 000,023,040 | ---- | C] () -- C:\windows\SysWow64\kdbsdk32.dll

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/01/04 06:44:25 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/01/04 04:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/10/06 19:24:25 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\BlueSprig
[2012/10/06 18:37:17 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\DriverCure
[2012/10/06 19:10:27 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\IObit
[2012/10/06 19:07:33 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\Opera
[2012/10/06 18:37:17 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\ParetoLogic
[2012/10/05 20:57:49 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\Toshiba
[2012/10/05 20:37:42 | 000,000,000 | ---D | M] -- C:\Users\Soapy\AppData\Roaming\WinBatch

========== Purity Check ==========



< End of report >

Edited by Aerostalgic, 06 October 2012 - 05:45 PM.

  • 0

Advertisements


#2
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts

Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post the appropriate logs in the Malware Removal forum and wait for help.

Hi and welcome to Geeks to Go. :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:

  • I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine!
  • The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Refrain from running self fixes as this will hinder the malware removal process.
  • It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
  • Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Before we start:

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Next:

Have you got a copy of the Windows 7 64 Bit installation DVD ? If not follow this tutorial:-

How to create a Windows 7 Startup Repair Disk

And create the above...Even though in theory you should be able to enter the System Recovery Options from the Advanced Boot Options, it can prove to be useful to have such a disk regardless.

Also please inform me what exact make & modal is your Toshiba machine.

Scan with DDS:

Please download DDS and save it to your Desktop from here.

Alternate downloads are here or here.

  • Disable any script blocker, and then double click on DDS to run the tool.
  • When done, DDS will open two logs:
  • DDS.txt <-- Will be opened
  • Attach.txt <-- Will be minimized
  • Save both reports to your desktop.
  • Please post the contents of these two Notepad files in your next reply.
When completed the above, please post back the following in the order asked for:

  • How is you computer performing now, any further symptoms and or problems encountered?
  • Answers to my few queries etc.
  • Both DDS logs. <-- Post them individually please, IE: one Log per post/reply.

  • 0

#3
Dakeyras

Dakeyras

    Anti-Malware Mammoth

  • Expert
  • 9,772 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP