For your reference and time saving, I ran updated, dds, aswMBR, TDSS killer, HJT, MalwareByte's quick scan, AdwCleaner, mcafee stinger, scanners in just about this order if memory serves right, in addition to OTL at last, for which I have just provided you the log. They were all clean to my best knowledge (none mentioned w32/small.ca). My final problem is McAfee Antivirus having an exclamation mark notifying me that Real-Time scanning is off for quite a few months now and I can't seem to get it to behave properly so I am thinking of re-installing momentarily after this small.ca issue however, right now W32/small.ca is my focus. I run tdsskiller meticulously and still find it odd it happened to begin with, the w32/small.ca notification is 1 day old (Mcafee Real-time scanning feature flaw has been ongoing for about 5 months at least, I tend to get windows' 'Action Center' alerting me to enable Windows or McAfee firewall and things like the update service.)
OTL logfile created on: 3/27/2013 1:58:30 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\J\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
15.60 Gb Total Physical Memory | 13.09 Gb Available Physical Memory | 83.88% Memory free
16.11 Gb Paging File | 13.37 Gb Available in Paging File | 83.03% Paging File free
Paging file location(s): c:\pagefile.sys 4300 16000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254.14 Gb Total Space | 2.88 Gb Free Space | 1.14% Space Free | Partition Type: NTFS
Drive D: | 29.00 Gb Total Space | 20.96 Gb Free Space | 72.29% Space Free | Partition Type: NTFS
Drive E: | 1862.98 Gb Total Space | 1592.54 Gb Free Space | 85.48% Space Free | Partition Type: NTFS
Drive F: | 29.81 Gb Total Space | 2.82 Gb Free Space | 9.48% Space Free | Partition Type: FAT32
Drive G: | 231.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: J-PC | User Name: J | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/27 13:56:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
PRC - [2013/03/17 04:00:55 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2013/03/17 03:22:07 | 001,822,424 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe
PRC - [2013/03/07 22:40:55 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/03/06 02:21:52 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/02/09 12:16:19 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/01/10 14:50:56 | 000,009,216 | ---- | M] (Ellora Assets Corp.) -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
PRC - [2012/12/18 12:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/12/05 01:39:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
========== Modules (No Company Name) ==========
MOD - [2013/03/17 03:22:05 | 014,717,144 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013/03/07 22:40:53 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
========== Services (SafeList) ==========
SRV:64bit: - [2013/01/30 00:40:44 | 008,894,864 | ---- | M] (DisplayLink Corp.) [On_Demand | Stopped] -- C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe -- (DisplayLinkService)
SRV:64bit: - [2012/11/22 05:42:06 | 000,378,952 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2012/11/09 07:37:30 | 000,177,680 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/11/09 07:34:50 | 000,218,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (mcpltsvc)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (HomeNetSvc)
SRV:64bit: - [2012/10/06 08:28:16 | 001,007,288 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe -- (mfecore)
SRV:64bit: - [2012/09/06 14:22:54 | 000,018,944 | ---- | M] (Hercules®) [Auto | Running] -- C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE -- (HerculesDJControlMP3)
SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2011/08/09 22:59:20 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2011/08/09 14:46:16 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/01/28 12:28:54 | 000,225,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\McAfee\MSC\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/11/05 00:50:02 | 000,068,760 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2013/03/07 22:40:53 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/03/06 02:21:52 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/02/09 12:16:19 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013/01/10 14:50:56 | 000,009,216 | ---- | M] (Ellora Assets Corp.) [Auto | Running] -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe -- (FreemakeVideoCapture)
SRV - [2012/12/18 12:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/09 01:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2011/11/13 08:53:40 | 000,946,032 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToMyPC\g2svc.exe -- (GoToMyPC)
SRV - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/03/01 16:43:52 | 000,076,448 | ---- | M] (Atheros Commnucations) [On_Demand | Stopped] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010/11/05 01:15:28 | 000,579,488 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\ConnSvc.exe -- (Lenovo ReadyComm ConnSvc)
SRV - [2009/08/13 22:22:48 | 000,509,192 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\AppSvc.exe -- (Lenovo ReadyComm AppSvc)
SRV - [2009/07/16 18:12:42 | 000,276,296 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll -- (PS_MDP)
SRV - [2009/07/15 05:27:26 | 000,038,152 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe -- (IGRS)
SRV - [2009/07/15 05:27:20 | 000,103,688 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll -- (ReadyComm.DirectRouter)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/03/17 03:50:34 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2013/03/17 03:50:33 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2013/02/25 11:12:04 | 002,426,672 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2012/11/09 07:40:24 | 000,069,672 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2012/11/09 07:37:42 | 000,339,776 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/11/09 07:35:50 | 000,771,096 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/11/09 07:34:58 | 000,515,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/11/09 07:34:18 | 000,309,400 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/11/09 07:33:58 | 000,178,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/11/02 02:46:50 | 000,328,976 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfencbdc.sys -- (mfencbdc)
DRV:64bit: - [2012/11/02 02:46:50 | 000,097,208 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfencrk.sys -- (mfencrk)
DRV:64bit: - [2012/10/30 14:49:34 | 000,306,032 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJAsioK.sys -- (HDJAsioK)
DRV:64bit: - [2012/10/30 14:49:32 | 000,238,960 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJBulk.sys -- (Bulk)
DRV:64bit: - [2012/10/30 14:49:30 | 000,271,216 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJMidi.sys -- (HDJMidi)
DRV:64bit: - [2012/08/23 07:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 07:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 07:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/05/28 11:28:18 | 000,197,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/10/18 13:31:24 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011/10/18 13:31:12 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011/10/18 04:20:20 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/10/18 04:20:20 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/08/09 15:33:32 | 009,360,896 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/08/09 14:08:50 | 000,309,760 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/03/01 16:44:08 | 000,280,224 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2011/03/01 16:44:06 | 000,298,656 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2011/03/01 16:44:06 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2011/03/01 16:44:06 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2011/03/01 16:44:04 | 000,051,872 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2011/02/16 18:53:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2011/02/11 14:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2010/12/05 01:39:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/28 13:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/21 03:05:22 | 000,228,224 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm331avs.sys -- (vm331avs)
DRV:64bit: - [2010/09/30 16:45:22 | 000,299,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/09/02 22:46:48 | 001,392,688 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/08/16 02:28:50 | 000,008,320 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmuvcflt.sys -- (vmuvcflt)
DRV:64bit: - [2010/06/24 19:33:36 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010/06/24 14:46:14 | 000,033,888 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\appliand.sys -- (appliandMP)
DRV:64bit: - [2010/05/14 15:04:16 | 000,073,856 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010/05/14 15:04:16 | 000,028,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010/02/18 02:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/11/23 18:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 18:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/10/07 08:49:28 | 006,379,288 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2009/10/07 08:47:46 | 000,327,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2009/08/07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\WNt500x64\sandra.sys -- (SANDRA)
DRV:64bit: - [2009/07/21 14:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/15 19:55:36 | 000,011,280 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDMirror.sys -- (wdmirror)
DRV:64bit: - [2009/07/15 11:38:22 | 000,079,376 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WDBridge.sys -- (Bridge0)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 13:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=LENN&bmod=LENN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7LENN_enUS459
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7BFF2FA6A4-B3B1-11DD-B910-6C9A55D89593%7D:0.46
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013/01/31 17:46:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]\ [2013/01/22 14:33:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]\ [2013/01/22 14:33:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/17 04:05:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2013/03/17 04:13:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:40:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:40:58 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/10/18 04:10:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\J\AppData\Roaming\Mozilla\Extensions
[2013/02/03 18:11:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\J\AppData\Roaming\Mozilla\Firefox\Profiles\xulj7ht6.default\extensions
[2013/01/22 17:37:54 | 000,000,000 | ---D | M] (Bazzacuda Image Saver Plus) -- C:\Users\J\AppData\Roaming\Mozilla\Firefox\Profiles\xulj7ht6.default\extensions\{FF2FA6A4-B3B1-11DD-B910-6C9A55D89593}
[2013/03/07 22:40:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 22:40:56 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/02/15 17:35:09 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/15 17:35:09 | 000,002,086 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: RealNetworks RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - Extension: Freemake Video Downloader = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0\
CHR - Extension: Freemake Youtube Download Button = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0\
CHR - Extension: SiteAdvisor = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\
CHR - Extension: RealDownloader = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.1_0\
CHR - Extension: Freemake Video Converter = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
O1 HOSTS File: ([2011/12/18 03:58:38 | 000,000,871 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Dolby Tuning and Profile Creator] C:\Program Files\Dolby Tuning and Profile Creator\pcee4.exe (Dolby Laboratories Inc.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Hercules DJ Series] C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®)
O4 - HKLM..\Run: [mcpltui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F5907B3-1AA0-4E1C-A4FB-4E0728463A40}: DhcpNameServer = 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F5907B3-1AA0-4E1C-A4FB-4E0728463A40}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A7DD4D4-2D89-4F90-9DA4-8B91D5D0D69E}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/28 08:29:54 | 000,000,050 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{43b2d2ad-f9c1-11e0-ad43-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{43b2d2ad-f9c1-11e0-ad43-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2008/02/27 10:50:06 | 000,099,624 | R--- | M] (Guillemot Corporation S.A.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/27 13:56:04 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
[2013/03/27 13:50:10 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\RK_Quarantine
[2013/03/27 13:17:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/03/27 05:21:56 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\cocktails
[2013/03/27 01:00:49 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine
[2013/03/27 01:00:33 | 000,000,000 | ---D | C] -- C:\Program Files\stinger
[2013/03/26 21:22:32 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
[2013/03/26 21:22:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ
[2013/03/26 19:10:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hercules
[2013/03/26 19:10:17 | 000,336,896 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJSeries.cpl
[2013/03/26 19:07:05 | 000,078,336 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAsiou.dll
[2013/03/26 19:07:04 | 000,278,528 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAsioCpl.dll
[2013/03/26 19:07:02 | 000,271,216 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJMidi.sys
[2013/03/26 19:07:02 | 000,078,848 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\windows\SysNative\HerculesDJDevices.dll
[2013/03/26 19:07:01 | 000,238,960 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJBulk.sys
[2013/03/26 19:07:01 | 000,037,744 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJCtrl.sys
[2013/03/26 19:07:00 | 000,369,664 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJAsioCpl.dll
[2013/03/26 19:07:00 | 000,306,032 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJAsioK.sys
[2013/03/26 19:07:00 | 000,091,136 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJAsiou.dll
[2013/03/26 19:05:59 | 000,000,000 | ---D | C] -- C:\Program Files\Hercules
[2013/03/26 18:37:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual DJ
[2013/03/26 18:25:36 | 000,103,936 | ---- | C] (Hercules®) -- C:\windows\SysNative\hrfdongle.dll
[2013/03/26 18:25:35 | 000,610,816 | ---- | C] (Hercules®) -- C:\windows\SysNative\hdjapi.dll
[2013/03/26 18:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\Guillemot
[2013/03/26 18:21:16 | 000,088,064 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HRFDongle.dll
[2013/03/26 18:21:16 | 000,073,728 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJSAPI.dll
[2013/03/26 18:21:15 | 000,613,888 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAPI.dll
[2013/03/26 17:37:50 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\Logs
[2013/03/26 17:25:26 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\J\Desktop\dds.com
[2013/03/26 17:25:09 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\J\Desktop\aswMBR.exe
[2013/03/26 16:11:17 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/03/26 16:11:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2013/03/26 16:00:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ZHPDiag
[2013/03/26 16:00:07 | 000,000,000 | ---D | C] -- C:\ZHP
[2013/03/26 15:01:31 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\MP
[2013/03/26 11:41:18 | 000,000,000 | R--D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2013/03/25 13:10:14 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\defari-the_lost_tapes_of_ruby_d-(dubcnn)
[2013/03/19 19:02:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2013/03/19 19:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2013/03/17 04:59:42 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Shark007
[2013/03/17 04:59:30 | 001,551,200 | ---- | C] (MPC-HC Team) -- C:\windows\SysNative\VSFilter.dll
[2013/03/17 04:59:30 | 000,000,000 | ---D | C] -- C:\Program Files\Shark007
[2013/03/17 04:45:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
[2013/03/17 04:44:45 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Win7codecs
[2013/03/17 04:38:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
[2013/03/17 04:25:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\aTube Catcher 2.0
[2013/03/17 04:05:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RealNetworks
[2013/03/17 04:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks
[2013/03/17 04:02:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2013/03/17 04:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/03/17 04:01:02 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\windows\SysWow64\pncrt.dll
[2013/03/17 03:27:29 | 000,000,000 | ---D | C] -- C:\Program Files\DisplayLink Graphics
[2013/03/17 03:25:19 | 000,000,000 | ---D | C] -- C:\Program Files\DisplayLink Core Software
[2013/03/17 03:21:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/17 03:21:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2013/03/16 00:47:41 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\DonationCoder
[2013/03/16 00:47:40 | 000,000,000 | ---D | C] -- C:\Users\J\Documents\DonationCoder
[2013/03/16 00:47:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URLSnooper2
[2013/03/16 00:47:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DonationCoder
[2013/03/16 00:47:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\URLSnooper2
[2013/03/13 16:03:36 | 001,297,248 | ---- | C] (MPC-HC Team) -- C:\windows\SysWow64\VSFilter.dll
[2013/03/07 22:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/03/07 11:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\CitrixLogs
[2013/03/07 11:34:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix
[2013/03/07 11:34:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Citrix
[2013/03/06 13:34:47 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\PMS
[2013/03/06 12:26:30 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\Jay
[2013/03/05 14:20:32 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/27 13:56:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
[2013/03/27 13:47:02 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/27 13:20:09 | 000,028,928 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/27 13:20:09 | 000,028,928 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/27 13:16:05 | 000,663,102 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013/03/27 13:16:05 | 000,122,680 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013/03/27 13:16:04 | 000,783,400 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013/03/27 13:10:04 | 000,453,605 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2013/03/27 13:09:38 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/27 13:08:44 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2013/03/27 13:07:59 | 3976,384,510 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/27 05:21:38 | 000,016,182 | ---- | M] () -- C:\Users\J\Documents\Clueless.rtf
[2013/03/26 21:22:33 | 000,001,042 | ---- | M] () -- C:\Users\J\Desktop\VirtualDJ Home FREE.lnk
[2013/03/26 19:15:32 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJAsioK_01009.Wdf
[2013/03/26 19:14:55 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJBulk_01009.Wdf
[2013/03/26 18:40:58 | 000,285,224 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013/03/26 17:33:09 | 000,000,512 | ---- | M] () -- C:\Users\J\Desktop\MBR.dat
[2013/03/26 17:27:28 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\J\Desktop\aswMBR.exe
[2013/03/26 17:25:42 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\J\Desktop\dds.com
[2013/03/26 16:11:17 | 000,002,955 | ---- | M] () -- C:\Users\J\Desktop\HiJackThis.lnk
[2013/03/26 16:00:42 | 000,000,994 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/03/26 16:00:39 | 000,001,983 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/03/26 16:00:39 | 000,001,856 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/03/26 14:40:33 | 000,012,142 | ---- | M] () -- C:\Users\J\Desktop\Thunderdome XX - Playlist.m3u
[2013/03/26 11:41:05 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2013/03/25 17:14:42 | 000,389,514 | ---- | M] () -- C:\Users\J\Desktop\kjenspool.png
[2013/03/24 20:56:15 | 000,010,566 | ---- | M] () -- C:\Users\J\Documents\diggy.rtf
[2013/03/24 00:17:44 | 000,021,396 | ---- | M] () -- C:\Users\J\Documents\twit phrases 2.rtf
[2013/03/23 05:22:29 | 000,000,335 | ---- | M] () -- C:\Users\J\Documents\REP - Curls.rtf
[2013/03/23 02:35:57 | 000,706,981 | ---- | M] () -- C:\Users\J\Desktop\Img_130323022310-2.png
[2013/03/21 01:03:40 | 000,006,834 | ---- | M] () -- C:\Users\J\Documents\twits phrases.rtf
[2013/03/20 06:03:00 | 000,000,290 | ---- | M] () -- C:\windows\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-867398653-3465891867-48189854-1001.job
[2013/03/19 19:05:21 | 000,077,296 | ---- | M] () -- C:\Users\J\Desktop\J-PC - CPUZ BEFORE
[2013/03/19 19:02:29 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/03/19 17:57:42 | 000,000,334 | ---- | M] () -- C:\Users\J\Documents\dat fag.rtf
[2013/03/19 17:57:28 | 000,003,965 | ---- | M] () -- C:\Users\J\Documents\testudo 1.rtf
[2013/03/19 09:17:51 | 000,003,731 | ---- | M] () -- C:\Users\J\Documents\jakeinpeoria blasts 909.rtf
[2013/03/19 05:30:54 | 000,044,326 | ---- | M] () -- C:\Users\J\Documents\##bit ly - station links##.rtf
[2013/03/18 11:23:42 | 000,002,544 | ---- | M] () -- C:\Users\J\Documents\drama 3.rtf
[2013/03/18 10:59:06 | 000,010,796 | ---- | M] () -- C:\Users\J\Documents\clone drama 2.rtf
[2013/03/18 09:14:20 | 000,000,042 | ---- | M] () -- C:\Users\J\Desktop\Radio Greenbier 1 - FM Top 40.m3u
[2013/03/18 08:37:03 | 000,000,039 | ---- | M] () -- C:\Users\J\Desktop\ESPN 1280.m3u
[2013/03/18 08:00:37 | 000,004,800 | ---- | M] () -- C:\Users\J\Documents\clone drama.rtf
[2013/03/17 18:48:56 | 000,049,106 | ---- | M] () -- C:\Users\J\Documents\#bum smack#.rtf
[2013/03/17 04:39:06 | 000,002,121 | ---- | M] () -- C:\Users\Public\Desktop\Video Search.lnk
[2013/03/17 04:39:01 | 000,001,203 | ---- | M] () -- C:\Users\Public\Desktop\aTube.lnk
[2013/03/17 04:14:12 | 000,001,316 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013/03/17 04:06:40 | 000,001,260 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/03/17 04:01:02 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\windows\SysWow64\pncrt.dll
[2013/03/17 03:50:38 | 000,002,079 | ---- | M] () -- C:\Users\Public\Desktop\Lenovo EE Boot Optimizer.lnk
[2013/03/17 03:50:34 | 000,203,000 | ---- | M] () -- C:\windows\SysNative\LsDefrag.bmp
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd10.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd10.dll
[2013/03/17 01:08:45 | 000,025,185 | ---- | M] () -- C:\windows\SysWow64\ieuinit.inf
[2013/03/17 01:08:44 | 000,025,185 | ---- | M] () -- C:\windows\SysNative\ieuinit.inf
[2013/03/16 00:58:19 | 000,000,046 | ---- | M] () -- C:\Users\J\Desktop\1230Wausau-The Voice-Phil.m3u
[2013/03/16 00:47:41 | 000,000,046 | ---- | M] () -- C:\windows\SysWow64\DonationCoder_urlsnooper_InstallInfo.dat
[2013/03/15 13:20:53 | 000,025,159 | ---- | M] () -- C:\Users\J\Documents\espn comment - kobe ankle injury.rtf
[2013/03/14 21:37:24 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Internet Browser.lnk
[2013/03/13 16:06:38 | 001,551,200 | ---- | M] (MPC-HC Team) -- C:\windows\SysNative\VSFilter.dll
[2013/03/13 16:03:36 | 001,297,248 | ---- | M] (MPC-HC Team) -- C:\windows\SysWow64\VSFilter.dll
[2013/03/13 06:02:14 | 000,000,478 | ---- | M] () -- C:\Users\J\Documents\new drachtens March ---.rtf
[2013/03/13 04:49:17 | 000,001,082 | ---- | M] () -- C:\Users\J\Documents\espn comment clippers - dunk -.rtf
[2013/03/12 21:16:31 | 000,011,699 | ---- | M] () -- C:\Users\J\Documents\espn la - comments dwight howard returns.rtf
[2013/03/12 17:13:49 | 000,001,762 | ---- | M] () -- C:\Users\J\Documents\stucknut-mentino.rtf
[2013/03/12 04:43:42 | 000,004,054 | ---- | M] () -- C:\Users\J\Documents\stucknut- rant on college sports and 24-7 network.rtf
[2013/03/12 02:55:15 | 000,000,291 | ---- | M] () -- C:\Users\J\Documents\j from com.rtf
[2013/03/11 07:03:55 | 000,001,065 | ---- | M] () -- C:\windows\winamp.ini
[2013/03/11 05:58:47 | 001,064,411 | ---- | M] () -- C:\Users\J\Documents\hottass girl code.rtf
[2013/03/09 02:35:35 | 008,145,705 | ---- | M] () -- C:\Users\J\Documents\opicate- espn - kobe doing 40-12-6.rtf
[2013/03/08 23:09:19 | 000,004,394 | ---- | M] () -- C:\Users\J\Documents\s-nut- rant.rtf
[2013/03/08 15:02:34 | 000,003,813 | ---- | M] () -- C:\Users\J\Documents\trenddd.rtf
[2013/03/05 20:06:21 | 000,002,275 | ---- | M] () -- C:\Users\J\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/05 14:25:32 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/02/27 08:57:04 | 004,283,392 | ---- | M] () -- C:\windows\SysWow64\x264vfw.dll
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/26 21:22:33 | 000,001,042 | ---- | C] () -- C:\Users\J\Desktop\VirtualDJ Home FREE.lnk
[2013/03/26 19:15:32 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJAsioK_01009.Wdf
[2013/03/26 19:14:55 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJBulk_01009.Wdf
[2013/03/26 17:33:09 | 000,000,512 | ---- | C] () -- C:\Users\J\Desktop\MBR.dat
[2013/03/26 16:11:17 | 000,002,955 | ---- | C] () -- C:\Users\J\Desktop\HiJackThis.lnk
[2013/03/26 16:00:42 | 000,000,994 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/03/26 16:00:39 | 000,001,983 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/03/26 16:00:39 | 000,001,856 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/03/26 14:40:33 | 000,012,142 | ---- | C] () -- C:\Users\J\Desktop\Thunderdome XX - Playlist.m3u
[2013/03/25 17:14:37 | 000,389,514 | ---- | C] () -- C:\Users\J\Desktop\kjenspool.png
[2013/03/24 08:44:31 | 000,010,566 | ---- | C] () -- C:\Users\J\Documents\diggy.rtf
[2013/03/24 04:57:20 | 000,016,182 | ---- | C] () -- C:\Users\J\Documents\Clueless.rtf
[2013/03/23 05:22:28 | 000,000,335 | ---- | C] () -- C:\Users\J\Documents\REP - Curls.rtf
[2013/03/23 02:35:56 | 000,706,981 | ---- | C] () -- C:\Users\J\Desktop\Img_130323022310-2.png
[2013/03/22 10:51:13 | 3976,384,510 | -HS- | C] () -- C:\hiberfil.sys
[2013/03/20 18:22:55 | 000,021,396 | ---- | C] () -- C:\Users\J\Documents\twit phrases 2.rtf
[2013/03/20 06:03:00 | 000,000,290 | ---- | C] () -- C:\windows\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-867398653-3465891867-48189854-1001.job
[2013/03/19 19:05:19 | 000,077,296 | ---- | C] () -- C:\Users\J\Desktop\J-PC - CPUZ BEFORE
[2013/03/19 19:02:29 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/03/19 17:57:41 | 000,000,334 | ---- | C] () -- C:\Users\J\Documents\dat fag.rtf
[2013/03/19 17:57:27 | 000,003,965 | ---- | C] () -- C:\Users\J\Documents\testudo 1.rtf
[2013/03/19 09:16:14 | 000,003,731 | ---- | C] () -- C:\Users\J\Documents\jakeinpeoria blasts 909.rtf
[2013/03/18 11:23:42 | 000,002,544 | ---- | C] () -- C:\Users\J\Documents\drama 3.rtf
[2013/03/18 10:08:40 | 000,010,796 | ---- | C] () -- C:\Users\J\Documents\clone drama 2.rtf
[2013/03/18 09:14:20 | 000,000,042 | ---- | C] () -- C:\Users\J\Desktop\Radio Greenbier 1 - FM Top 40.m3u
[2013/03/18 08:37:02 | 000,000,039 | ---- | C] () -- C:\Users\J\Desktop\ESPN 1280.m3u
[2013/03/18 08:00:36 | 000,004,800 | ---- | C] () -- C:\Users\J\Documents\clone drama.rtf
[2013/03/17 04:59:31 | 000,580,096 | ---- | C] () -- C:\windows\SysNative\ac3filter.acm
[2013/03/17 04:59:31 | 000,206,336 | ---- | C] () -- C:\windows\SysNative\unrar64.dll
[2013/03/17 04:39:01 | 000,001,203 | ---- | C] () -- C:\Users\Public\Desktop\aTube.lnk
[2013/03/17 04:28:06 | 000,002,121 | ---- | C] () -- C:\Users\Public\Desktop\Video Search.lnk
[2013/03/17 04:14:10 | 000,001,316 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013/03/17 04:06:40 | 000,001,260 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/03/17 03:50:41 | 000,453,605 | ---- | C] () -- C:\windows\SysNative\fastboot.set
[2013/03/17 03:50:41 | 000,203,000 | ---- | C] () -- C:\windows\SysNative\LsDefrag.bmp
[2013/03/17 03:50:38 | 000,002,079 | ---- | C] () -- C:\Users\Public\Desktop\Lenovo EE Boot Optimizer.lnk
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd10.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd10.dll
[2013/03/17 01:08:45 | 000,025,185 | ---- | C] () -- C:\windows\SysWow64\ieuinit.inf
[2013/03/17 01:08:44 | 000,025,185 | ---- | C] () -- C:\windows\SysNative\ieuinit.inf
[2013/03/16 00:58:19 | 000,000,046 | ---- | C] () -- C:\Users\J\Desktop\1230Wausau-The Voice-Phil.m3u
[2013/03/16 00:47:41 | 000,000,046 | ---- | C] () -- C:\windows\SysWow64\DonationCoder_urlsnooper_InstallInfo.dat
[2013/03/15 12:16:48 | 000,025,159 | ---- | C] () -- C:\Users\J\Documents\espn comment - kobe ankle injury.rtf
[2013/03/13 04:49:16 | 000,001,082 | ---- | C] () -- C:\Users\J\Documents\espn comment clippers - dunk -.rtf
[2013/03/13 04:47:47 | 000,000,478 | ---- | C] () -- C:\Users\J\Documents\new drachtens March ---.rtf
[2013/03/12 20:54:54 | 000,011,699 | ---- | C] () -- C:\Users\J\Documents\espn la - comments dwight howard returns.rtf
[2013/03/12 19:36:01 | 000,006,834 | ---- | C] () -- C:\Users\J\Documents\twits phrases.rtf
[2013/03/12 17:13:48 | 000,001,762 | ---- | C] () -- C:\Users\J\Documents\stucknut-mentino.rtf
[2013/03/12 04:43:41 | 000,004,054 | ---- | C] () -- C:\Users\J\Documents\stucknut- rant on college sports and 24-7 network.rtf
[2013/03/12 02:55:13 | 000,000,291 | ---- | C] () -- C:\Users\J\Documents\j from com.rtf
[2013/03/11 05:58:47 | 001,064,411 | ---- | C] () -- C:\Users\J\Documents\hottass girl code.rtf
[2013/03/11 03:16:28 | 000,044,326 | ---- | C] () -- C:\Users\J\Documents\##bit ly - station links##.rtf
[2013/03/09 00:53:07 | 008,145,705 | ---- | C] () -- C:\Users\J\Documents\opicate- espn - kobe doing 40-12-6.rtf
[2013/03/08 23:07:53 | 000,004,394 | ---- | C] () -- C:\Users\J\Documents\s-nut- rant.rtf
[2013/03/08 14:21:46 | 000,003,813 | ---- | C] () -- C:\Users\J\Documents\trenddd.rtf
[2013/02/27 08:57:04 | 004,283,392 | ---- | C] () -- C:\windows\SysWow64\x264vfw.dll
[2013/02/09 12:16:30 | 000,234,768 | ---- | C] () -- C:\windows\SysWow64\PnkBstrB.exe
[2013/02/09 12:16:19 | 000,075,136 | ---- | C] () -- C:\windows\SysWow64\PnkBstrA.exe
[2013/01/12 10:33:36 | 000,237,568 | ---- | C] () -- C:\windows\SysWow64\rmc_rtspdl.dll
[2012/12/28 21:07:05 | 000,001,065 | ---- | C] () -- C:\windows\winamp.ini
[2012/12/23 04:26:00 | 000,776,014 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/11/07 05:52:44 | 012,865,536 | ---- | C] () -- C:\Users\J\AppData\Roaming\Sandra.mdb
[2012/07/17 15:22:04 | 000,179,200 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2012/07/03 03:28:06 | 000,112,640 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2012/05/22 01:28:58 | 000,155,648 | ---- | C] () -- C:\windows\SysWow64\mlc.dll
[2012/05/02 17:12:46 | 000,001,422 | ---- | C] () -- C:\ProgramData\profile.xml
[2012/05/02 17:07:47 | 000,016,648 | ---- | C] () -- C:\windows\SysWow64\LogAPI.dll
[2012/05/02 16:04:05 | 000,001,652 | ---- | C] () -- C:\windows\vm331Rmv.ini
[2012/05/02 16:04:05 | 000,001,652 | ---- | C] () -- C:\windows\SysWow64\vm331Rmv.ini
[2011/12/08 06:32:24 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll
[2011/10/18 13:37:28 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011/10/18 13:37:28 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011/10/18 13:17:19 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/10/18 13:17:19 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/10/18 13:17:06 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/10/18 12:42:27 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011/10/18 12:38:27 | 000,003,929 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2011/08/09 22:56:20 | 000,059,904 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 22:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 21:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/06/03 21:14:48 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\AC3Filter
[2012/11/01 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Amazon
[2012/05/02 17:28:40 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\ArcSyncConfig
[2012/03/16 17:18:49 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Auslogics
[2013/03/16 00:47:41 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\DonationCoder
[2013/01/25 13:35:19 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\FreemakeVideoDownloader
[2012/04/21 04:32:51 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\GlarySoft
[2012/10/31 20:55:17 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\ImgBurn
[2012/06/16 04:52:18 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Leadertech
[2012/05/02 17:08:06 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Lenovo
[2012/05/02 14:59:48 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\LSC
[2013/01/28 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Replay Media Catcher 4
[2013/01/27 18:34:41 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Replay Media Catcher 4.bak
[2012/12/13 15:24:57 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\rockbox.org
[2013/03/17 05:00:37 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Shark007
[2013/03/19 11:04:38 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\SoftGrid Client
[2012/05/30 08:13:22 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Synaptics
[2012/12/23 04:28:14 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\TP
[2013/03/17 04:47:25 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Win7codecs
[2013/02/20 04:21:44 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
< End of report >
OTL logfile created on: 3/27/2013 1:58:30 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\J\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16521)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
15.60 Gb Total Physical Memory | 13.09 Gb Available Physical Memory | 83.88% Memory free
16.11 Gb Paging File | 13.37 Gb Available in Paging File | 83.03% Paging File free
Paging file location(s): c:\pagefile.sys 4300 16000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 254.14 Gb Total Space | 2.88 Gb Free Space | 1.14% Space Free | Partition Type: NTFS
Drive D: | 29.00 Gb Total Space | 20.96 Gb Free Space | 72.29% Space Free | Partition Type: NTFS
Drive E: | 1862.98 Gb Total Space | 1592.54 Gb Free Space | 85.48% Space Free | Partition Type: NTFS
Drive F: | 29.81 Gb Total Space | 2.82 Gb Free Space | 9.48% Space Free | Partition Type: FAT32
Drive G: | 231.41 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: J-PC | User Name: J | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/27 13:56:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
PRC - [2013/03/17 04:00:55 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
PRC - [2013/03/17 03:22:07 | 001,822,424 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe
PRC - [2013/03/07 22:40:55 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/03/06 02:21:52 | 000,039,056 | ---- | M] () -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/02/09 12:16:19 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2013/01/10 14:50:56 | 000,009,216 | ---- | M] (Ellora Assets Corp.) -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe
PRC - [2012/12/18 12:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/12/05 01:39:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
========== Modules (No Company Name) ==========
MOD - [2013/03/17 03:22:05 | 014,717,144 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013/03/07 22:40:53 | 003,069,848 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
========== Services (SafeList) ==========
SRV:64bit: - [2013/01/30 00:40:44 | 008,894,864 | ---- | M] (DisplayLink Corp.) [On_Demand | Stopped] -- C:\Program Files\DisplayLink Core Software\DisplayLinkManager.exe -- (DisplayLinkService)
SRV:64bit: - [2012/11/22 05:42:06 | 000,378,952 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV:64bit: - [2012/11/09 07:37:30 | 000,177,680 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/11/09 07:34:50 | 000,218,320 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (mcpltsvc)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2012/10/07 04:13:42 | 000,220,856 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe -- (HomeNetSvc)
SRV:64bit: - [2012/10/06 08:28:16 | 001,007,288 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe -- (mfecore)
SRV:64bit: - [2012/09/06 14:22:54 | 000,018,944 | ---- | M] (Hercules®) [Auto | Running] -- C:\Program Files\Hercules\Audio\DJ Console Series\drivers\amd64\HerculesDJControlMP3.EXE -- (HerculesDJControlMP3)
SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2012/08/31 13:20:06 | 000,201,304 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2011/08/09 22:59:20 | 000,365,568 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV:64bit: - [2011/08/09 14:46:16 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/01/28 12:28:54 | 000,225,216 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\McAfee\MSC\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2010/09/22 11:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2008/11/05 00:50:02 | 000,068,760 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV - [2013/03/07 22:40:53 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/03/06 02:21:52 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2013/02/09 12:16:19 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2013/01/10 14:50:56 | 000,009,216 | ---- | M] (Ellora Assets Corp.) [Auto | Running] -- C:\Program Files (x86)\Freemake\CaptureLib\CaptureLibService.exe -- (FreemakeVideoCapture)
SRV - [2012/12/18 12:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/09 01:40:10 | 000,104,912 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2011/11/13 08:53:40 | 000,946,032 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToMyPC\g2svc.exe -- (GoToMyPC)
SRV - [2011/10/01 09:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 09:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/03/01 16:43:52 | 000,076,448 | ---- | M] (Atheros Commnucations) [On_Demand | Stopped] -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe -- (AtherosSvc)
SRV - [2010/11/05 01:15:28 | 000,579,488 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\ConnSvc.exe -- (Lenovo ReadyComm ConnSvc)
SRV - [2009/08/13 22:22:48 | 000,509,192 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\AppSvc.exe -- (Lenovo ReadyComm AppSvc)
SRV - [2009/07/16 18:12:42 | 000,276,296 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\PS_MDP.dll -- (PS_MDP)
SRV - [2009/07/15 05:27:26 | 000,038,152 | ---- | M] (Lenovo Group Limited) [On_Demand | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\IGRS.exe -- (IGRS)
SRV - [2009/07/15 05:27:20 | 000,103,688 | ---- | M] (Lenovo Group Limited) [Auto | Stopped] -- C:\Program Files (x86)\Lenovo\ReadyComm\common\router.dll -- (ReadyComm.DirectRouter)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/03/17 03:50:34 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2013/03/17 03:50:33 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2013/02/25 11:12:04 | 002,426,672 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2012/11/09 07:40:24 | 000,069,672 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2012/11/09 07:37:42 | 000,339,776 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/11/09 07:35:50 | 000,771,096 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/11/09 07:34:58 | 000,515,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/11/09 07:34:18 | 000,309,400 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/11/09 07:33:58 | 000,178,840 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/11/02 02:46:50 | 000,328,976 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfencbdc.sys -- (mfencbdc)
DRV:64bit: - [2012/11/02 02:46:50 | 000,097,208 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mfencrk.sys -- (mfencrk)
DRV:64bit: - [2012/10/30 14:49:34 | 000,306,032 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJAsioK.sys -- (HDJAsioK)
DRV:64bit: - [2012/10/30 14:49:32 | 000,238,960 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJBulk.sys -- (Bulk)
DRV:64bit: - [2012/10/30 14:49:30 | 000,271,216 | ---- | M] (© Guillemot R&D, 2012. All rights reserved.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HDJMidi.sys -- (HDJMidi)
DRV:64bit: - [2012/08/23 07:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 07:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/23 07:07:35 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2012/05/28 11:28:18 | 000,197,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HipShieldK.sys -- (HipShieldK)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/10/18 13:31:24 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011/10/18 13:31:12 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011/10/18 04:20:20 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/10/18 04:20:20 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/10/01 09:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2011/10/01 09:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2011/10/01 09:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2011/10/01 09:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2011/08/09 15:33:32 | 009,360,896 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/08/09 14:08:50 | 000,309,760 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/03/01 16:44:08 | 000,280,224 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btfilter.sys -- (BtFilter)
DRV:64bit: - [2011/03/01 16:44:06 | 000,298,656 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_a2dp.sys -- (BTATH_A2DP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,201,376 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_hcrp.sys -- (BTATH_HCRP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,154,272 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_rcp.sys -- (BTATH_RCP)
DRV:64bit: - [2011/03/01 16:44:06 | 000,055,456 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_lwflt.sys -- (BTATH_LWFLT)
DRV:64bit: - [2011/03/01 16:44:06 | 000,036,000 | ---- | M] (Atheros) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btath_flt.sys -- (AthBTPort)
DRV:64bit: - [2011/03/01 16:44:06 | 000,028,832 | ---- | M] (Atheros) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btath_bus.sys -- (BTATH_BUS)
DRV:64bit: - [2011/03/01 16:44:04 | 000,051,872 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AthDfu.sys -- (ATHDFU)
DRV:64bit: - [2011/02/16 18:53:00 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)
DRV:64bit: - [2011/02/11 14:23:34 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (npf)
DRV:64bit: - [2010/12/05 01:39:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/28 13:50:38 | 000,044,672 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\usbfilter.sys -- (usbfilter)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/21 03:05:22 | 000,228,224 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vm331avs.sys -- (vm331avs)
DRV:64bit: - [2010/09/30 16:45:22 | 000,299,520 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/09/02 22:46:48 | 001,392,688 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/08/16 02:28:50 | 000,008,320 | ---- | M] (Vimicro Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmuvcflt.sys -- (vmuvcflt)
DRV:64bit: - [2010/06/24 19:33:36 | 000,076,912 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C62x64.sys -- (L1C)
DRV:64bit: - [2010/06/24 14:46:14 | 000,033,888 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\appliand.sys -- (appliandMP)
DRV:64bit: - [2010/05/14 15:04:16 | 000,073,856 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_sata.sys -- (amd_sata)
DRV:64bit: - [2010/05/14 15:04:16 | 000,028,800 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amd_xata.sys -- (amd_xata)
DRV:64bit: - [2010/02/18 02:18:24 | 000,046,136 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\amdiox64.sys -- (amdiox64)
DRV:64bit: - [2009/11/23 18:38:00 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2009/11/23 18:37:50 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2009/10/07 08:49:28 | 006,379,288 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64)
DRV:64bit: - [2009/10/07 08:47:46 | 000,327,704 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2009/08/07 23:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\WNt500x64\sandra.sys -- (SANDRA)
DRV:64bit: - [2009/07/21 14:20:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/15 19:55:36 | 000,011,280 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WDMirror.sys -- (wdmirror)
DRV:64bit: - [2009/07/15 11:38:22 | 000,079,376 | ---- | M] (Lenovo) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WDBridge.sys -- (Bridge0)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 13:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=LENN&bmod=LENN
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7LENN_enUS459
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7BFF2FA6A4-B3B1-11DD-B910-6C9A55D89593%7D:0.46
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2013/01/31 17:46:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]\ [2013/01/22 14:33:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Downloader\BrowserPlugin\Firefox\[email protected]\ [2013/01/22 14:33:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/17 04:05:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Freemake\Freemake Video Converter\BrowserPlugin\Firefox\ [2013/03/17 04:13:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:40:58 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/07 22:40:58 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/10/18 04:10:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\J\AppData\Roaming\Mozilla\Extensions
[2013/02/03 18:11:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\J\AppData\Roaming\Mozilla\Firefox\Profiles\xulj7ht6.default\extensions
[2013/01/22 17:37:54 | 000,000,000 | ---D | M] (Bazzacuda Image Saver Plus) -- C:\Users\J\AppData\Roaming\Mozilla\Firefox\Profiles\xulj7ht6.default\extensions\{FF2FA6A4-B3B1-11DD-B910-6C9A55D89593}
[2013/03/07 22:40:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 22:40:56 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/02/15 17:35:09 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/15 17:35:09 | 000,002,086 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin101752.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpplugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: RealNetworks RealDownloader Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll
CHR - plugin: RealNetworks RealDownloader HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll
CHR - plugin: RealNetworks RealDownloader PepperFlashVideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll
CHR - plugin: RealDownloader Plugin (Enabled) = C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - Extension: Freemake Video Downloader = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf\1.0.0_0\
CHR - Extension: Freemake Youtube Download Button = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh\1.0.0_0\
CHR - Extension: SiteAdvisor = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.60.126.1_0\
CHR - Extension: RealDownloader = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.1_0\
CHR - Extension: Freemake Video Converter = C:\Users\J\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbolfgndggfhhpbnkgnpjkfhinclbigj\1.0.0_0\
O1 HOSTS File: ([2011/12/18 03:58:38 | 000,000,871 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Dolby Tuning and Profile Creator] C:\Program Files\Dolby Tuning and Profile Creator\pcee4.exe (Dolby Laboratories Inc.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Hercules DJ Series] C:\Program Files\Hercules\Audio\DJ Console Series\HDJSeriesCPL.exe (Hercules®)
O4 - HKLM..\Run: [mcpltui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F5907B3-1AA0-4E1C-A4FB-4E0728463A40}: DhcpNameServer = 192.168.1.1 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0F5907B3-1AA0-4E1C-A4FB-4E0728463A40}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7A7DD4D4-2D89-4F90-9DA4-8B91D5D0D69E}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/28 08:29:54 | 000,000,050 | R--- | M] () - G:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{43b2d2ad-f9c1-11e0-ad43-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{43b2d2ad-f9c1-11e0-ad43-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Setup.exe -- [2008/02/27 10:50:06 | 000,099,624 | R--- | M] (Guillemot Corporation S.A.)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/27 13:56:04 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
[2013/03/27 13:50:10 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\RK_Quarantine
[2013/03/27 13:17:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/03/27 05:21:56 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\cocktails
[2013/03/27 01:00:49 | 000,000,000 | ---D | C] -- C:\Stinger_Quarantine
[2013/03/27 01:00:33 | 000,000,000 | ---D | C] -- C:\Program Files\stinger
[2013/03/26 21:22:32 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
[2013/03/26 21:22:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VirtualDJ
[2013/03/26 19:10:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hercules
[2013/03/26 19:10:17 | 000,336,896 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJSeries.cpl
[2013/03/26 19:07:05 | 000,078,336 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAsiou.dll
[2013/03/26 19:07:04 | 000,278,528 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAsioCpl.dll
[2013/03/26 19:07:02 | 000,271,216 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJMidi.sys
[2013/03/26 19:07:02 | 000,078,848 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\windows\SysNative\HerculesDJDevices.dll
[2013/03/26 19:07:01 | 000,238,960 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJBulk.sys
[2013/03/26 19:07:01 | 000,037,744 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJCtrl.sys
[2013/03/26 19:07:00 | 000,369,664 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJAsioCpl.dll
[2013/03/26 19:07:00 | 000,306,032 | ---- | C] (© Guillemot R&D, 2012. All rights reserved.) -- C:\windows\SysNative\drivers\HDJAsioK.sys
[2013/03/26 19:07:00 | 000,091,136 | ---- | C] (Hercules®) -- C:\windows\SysNative\HDJAsiou.dll
[2013/03/26 19:05:59 | 000,000,000 | ---D | C] -- C:\Program Files\Hercules
[2013/03/26 18:37:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virtual DJ
[2013/03/26 18:25:36 | 000,103,936 | ---- | C] (Hercules®) -- C:\windows\SysNative\hrfdongle.dll
[2013/03/26 18:25:35 | 000,610,816 | ---- | C] (Hercules®) -- C:\windows\SysNative\hdjapi.dll
[2013/03/26 18:21:55 | 000,000,000 | ---D | C] -- C:\Program Files\Guillemot
[2013/03/26 18:21:16 | 000,088,064 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HRFDongle.dll
[2013/03/26 18:21:16 | 000,073,728 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJSAPI.dll
[2013/03/26 18:21:15 | 000,613,888 | ---- | C] (Hercules®) -- C:\windows\SysWow64\HDJAPI.dll
[2013/03/26 17:37:50 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\Logs
[2013/03/26 17:25:26 | 000,688,992 | R--- | C] (Swearware) -- C:\Users\J\Desktop\dds.com
[2013/03/26 17:25:09 | 004,745,728 | ---- | C] (AVAST Software) -- C:\Users\J\Desktop\aswMBR.exe
[2013/03/26 16:11:17 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/03/26 16:11:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2013/03/26 16:00:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ZHPDiag
[2013/03/26 16:00:07 | 000,000,000 | ---D | C] -- C:\ZHP
[2013/03/26 15:01:31 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\MP
[2013/03/26 11:41:18 | 000,000,000 | R--D | C] -- C:\Users\J\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices
[2013/03/25 13:10:14 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\defari-the_lost_tapes_of_ruby_d-(dubcnn)
[2013/03/19 19:02:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
[2013/03/19 19:02:24 | 000,000,000 | ---D | C] -- C:\Program Files\CPUID
[2013/03/17 04:59:42 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Shark007
[2013/03/17 04:59:30 | 001,551,200 | ---- | C] (MPC-HC Team) -- C:\windows\SysNative\VSFilter.dll
[2013/03/17 04:59:30 | 000,000,000 | ---D | C] -- C:\Program Files\Shark007
[2013/03/17 04:45:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shark007 Codecs
[2013/03/17 04:44:45 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\Win7codecs
[2013/03/17 04:38:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\aTube Catcher
[2013/03/17 04:25:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\aTube Catcher 2.0
[2013/03/17 04:05:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\RealNetworks
[2013/03/17 04:04:31 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks
[2013/03/17 04:02:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\xing shared
[2013/03/17 04:01:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2013/03/17 04:01:02 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\windows\SysWow64\pncrt.dll
[2013/03/17 03:27:29 | 000,000,000 | ---D | C] -- C:\Program Files\DisplayLink Graphics
[2013/03/17 03:25:19 | 000,000,000 | ---D | C] -- C:\Program Files\DisplayLink Core Software
[2013/03/17 03:21:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/03/17 03:21:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2013/03/16 00:47:41 | 000,000,000 | ---D | C] -- C:\Users\J\AppData\Roaming\DonationCoder
[2013/03/16 00:47:40 | 000,000,000 | ---D | C] -- C:\Users\J\Documents\DonationCoder
[2013/03/16 00:47:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URLSnooper2
[2013/03/16 00:47:04 | 000,000,000 | ---D | C] -- C:\ProgramData\DonationCoder
[2013/03/16 00:47:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\URLSnooper2
[2013/03/13 16:03:36 | 001,297,248 | ---- | C] (MPC-HC Team) -- C:\windows\SysWow64\VSFilter.dll
[2013/03/07 22:40:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/03/07 11:34:42 | 000,000,000 | ---D | C] -- C:\ProgramData\CitrixLogs
[2013/03/07 11:34:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Citrix
[2013/03/07 11:34:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Citrix
[2013/03/06 13:34:47 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\PMS
[2013/03/06 12:26:30 | 000,000,000 | ---D | C] -- C:\Users\J\Desktop\Jay
[2013/03/05 14:20:32 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/27 13:56:22 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\J\Desktop\OTL.exe
[2013/03/27 13:47:02 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/27 13:20:09 | 000,028,928 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/27 13:20:09 | 000,028,928 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/27 13:16:05 | 000,663,102 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2013/03/27 13:16:05 | 000,122,680 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2013/03/27 13:16:04 | 000,783,400 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2013/03/27 13:10:04 | 000,453,605 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2013/03/27 13:09:38 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/27 13:08:44 | 000,067,584 | ---- | M] () -- C:\windows\bootstat.dat
[2013/03/27 13:07:59 | 3976,384,510 | -HS- | M] () -- C:\hiberfil.sys
[2013/03/27 05:21:38 | 000,016,182 | ---- | M] () -- C:\Users\J\Documents\Clueless.rtf
[2013/03/26 21:22:33 | 000,001,042 | ---- | M] () -- C:\Users\J\Desktop\VirtualDJ Home FREE.lnk
[2013/03/26 19:15:32 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJAsioK_01009.Wdf
[2013/03/26 19:14:55 | 000,000,000 | -H-- | M] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJBulk_01009.Wdf
[2013/03/26 18:40:58 | 000,285,224 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2013/03/26 17:33:09 | 000,000,512 | ---- | M] () -- C:\Users\J\Desktop\MBR.dat
[2013/03/26 17:27:28 | 004,745,728 | ---- | M] (AVAST Software) -- C:\Users\J\Desktop\aswMBR.exe
[2013/03/26 17:25:42 | 000,688,992 | R--- | M] (Swearware) -- C:\Users\J\Desktop\dds.com
[2013/03/26 16:11:17 | 000,002,955 | ---- | M] () -- C:\Users\J\Desktop\HiJackThis.lnk
[2013/03/26 16:00:42 | 000,000,994 | ---- | M] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/03/26 16:00:39 | 000,001,983 | ---- | M] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/03/26 16:00:39 | 000,001,856 | ---- | M] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/03/26 14:40:33 | 000,012,142 | ---- | M] () -- C:\Users\J\Desktop\Thunderdome XX - Playlist.m3u
[2013/03/26 11:41:05 | 000,000,035 | ---- | M] () -- C:\Users\Public\Documents\AtherosServiceConfig.ini
[2013/03/25 17:14:42 | 000,389,514 | ---- | M] () -- C:\Users\J\Desktop\kjenspool.png
[2013/03/24 20:56:15 | 000,010,566 | ---- | M] () -- C:\Users\J\Documents\diggy.rtf
[2013/03/24 00:17:44 | 000,021,396 | ---- | M] () -- C:\Users\J\Documents\twit phrases 2.rtf
[2013/03/23 05:22:29 | 000,000,335 | ---- | M] () -- C:\Users\J\Documents\REP - Curls.rtf
[2013/03/23 02:35:57 | 000,706,981 | ---- | M] () -- C:\Users\J\Desktop\Img_130323022310-2.png
[2013/03/21 01:03:40 | 000,006,834 | ---- | M] () -- C:\Users\J\Documents\twits phrases.rtf
[2013/03/20 06:03:00 | 000,000,290 | ---- | M] () -- C:\windows\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-867398653-3465891867-48189854-1001.job
[2013/03/19 19:05:21 | 000,077,296 | ---- | M] () -- C:\Users\J\Desktop\J-PC - CPUZ BEFORE
[2013/03/19 19:02:29 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/03/19 17:57:42 | 000,000,334 | ---- | M] () -- C:\Users\J\Documents\dat fag.rtf
[2013/03/19 17:57:28 | 000,003,965 | ---- | M] () -- C:\Users\J\Documents\testudo 1.rtf
[2013/03/19 09:17:51 | 000,003,731 | ---- | M] () -- C:\Users\J\Documents\jakeinpeoria blasts 909.rtf
[2013/03/19 05:30:54 | 000,044,326 | ---- | M] () -- C:\Users\J\Documents\##bit ly - station links##.rtf
[2013/03/18 11:23:42 | 000,002,544 | ---- | M] () -- C:\Users\J\Documents\drama 3.rtf
[2013/03/18 10:59:06 | 000,010,796 | ---- | M] () -- C:\Users\J\Documents\clone drama 2.rtf
[2013/03/18 09:14:20 | 000,000,042 | ---- | M] () -- C:\Users\J\Desktop\Radio Greenbier 1 - FM Top 40.m3u
[2013/03/18 08:37:03 | 000,000,039 | ---- | M] () -- C:\Users\J\Desktop\ESPN 1280.m3u
[2013/03/18 08:00:37 | 000,004,800 | ---- | M] () -- C:\Users\J\Documents\clone drama.rtf
[2013/03/17 18:48:56 | 000,049,106 | ---- | M] () -- C:\Users\J\Documents\#bum smack#.rtf
[2013/03/17 04:39:06 | 000,002,121 | ---- | M] () -- C:\Users\Public\Desktop\Video Search.lnk
[2013/03/17 04:39:01 | 000,001,203 | ---- | M] () -- C:\Users\Public\Desktop\aTube.lnk
[2013/03/17 04:14:12 | 000,001,316 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013/03/17 04:06:40 | 000,001,260 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/03/17 04:01:02 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\windows\SysWow64\pncrt.dll
[2013/03/17 03:50:38 | 000,002,079 | ---- | M] () -- C:\Users\Public\Desktop\Lenovo EE Boot Optimizer.lnk
[2013/03/17 03:50:34 | 000,203,000 | ---- | M] () -- C:\windows\SysNative\LsDefrag.bmp
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysWow64\dlumd10.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | M] () -- C:\windows\SysNative\dlumd10.dll
[2013/03/17 01:08:45 | 000,025,185 | ---- | M] () -- C:\windows\SysWow64\ieuinit.inf
[2013/03/17 01:08:44 | 000,025,185 | ---- | M] () -- C:\windows\SysNative\ieuinit.inf
[2013/03/16 00:58:19 | 000,000,046 | ---- | M] () -- C:\Users\J\Desktop\1230Wausau-The Voice-Phil.m3u
[2013/03/16 00:47:41 | 000,000,046 | ---- | M] () -- C:\windows\SysWow64\DonationCoder_urlsnooper_InstallInfo.dat
[2013/03/15 13:20:53 | 000,025,159 | ---- | M] () -- C:\Users\J\Documents\espn comment - kobe ankle injury.rtf
[2013/03/14 21:37:24 | 000,002,183 | ---- | M] () -- C:\Users\Public\Desktop\Internet Browser.lnk
[2013/03/13 16:06:38 | 001,551,200 | ---- | M] (MPC-HC Team) -- C:\windows\SysNative\VSFilter.dll
[2013/03/13 16:03:36 | 001,297,248 | ---- | M] (MPC-HC Team) -- C:\windows\SysWow64\VSFilter.dll
[2013/03/13 06:02:14 | 000,000,478 | ---- | M] () -- C:\Users\J\Documents\new drachtens March ---.rtf
[2013/03/13 04:49:17 | 000,001,082 | ---- | M] () -- C:\Users\J\Documents\espn comment clippers - dunk -.rtf
[2013/03/12 21:16:31 | 000,011,699 | ---- | M] () -- C:\Users\J\Documents\espn la - comments dwight howard returns.rtf
[2013/03/12 17:13:49 | 000,001,762 | ---- | M] () -- C:\Users\J\Documents\stucknut-mentino.rtf
[2013/03/12 04:43:42 | 000,004,054 | ---- | M] () -- C:\Users\J\Documents\stucknut- rant on college sports and 24-7 network.rtf
[2013/03/12 02:55:15 | 000,000,291 | ---- | M] () -- C:\Users\J\Documents\j from com.rtf
[2013/03/11 07:03:55 | 000,001,065 | ---- | M] () -- C:\windows\winamp.ini
[2013/03/11 05:58:47 | 001,064,411 | ---- | M] () -- C:\Users\J\Documents\hottass girl code.rtf
[2013/03/09 02:35:35 | 008,145,705 | ---- | M] () -- C:\Users\J\Documents\opicate- espn - kobe doing 40-12-6.rtf
[2013/03/08 23:09:19 | 000,004,394 | ---- | M] () -- C:\Users\J\Documents\s-nut- rant.rtf
[2013/03/08 15:02:34 | 000,003,813 | ---- | M] () -- C:\Users\J\Documents\trenddd.rtf
[2013/03/05 20:06:21 | 000,002,275 | ---- | M] () -- C:\Users\J\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/05 14:25:32 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/02/27 08:57:04 | 004,283,392 | ---- | M] () -- C:\windows\SysWow64\x264vfw.dll
[2 C:\windows\SysWow64\*.tmp files -> C:\windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/26 21:22:33 | 000,001,042 | ---- | C] () -- C:\Users\J\Desktop\VirtualDJ Home FREE.lnk
[2013/03/26 19:15:32 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJAsioK_01009.Wdf
[2013/03/26 19:14:55 | 000,000,000 | -H-- | C] () -- C:\windows\SysNative\drivers\Msft_Kernel_HDJBulk_01009.Wdf
[2013/03/26 17:33:09 | 000,000,512 | ---- | C] () -- C:\Users\J\Desktop\MBR.dat
[2013/03/26 16:11:17 | 000,002,955 | ---- | C] () -- C:\Users\J\Desktop\HiJackThis.lnk
[2013/03/26 16:00:42 | 000,000,994 | ---- | C] () -- C:\Users\Public\Desktop\MBRCheck.lnk
[2013/03/26 16:00:39 | 000,001,983 | ---- | C] () -- C:\Users\Public\Desktop\ZHPFix.lnk
[2013/03/26 16:00:39 | 000,001,856 | ---- | C] () -- C:\Users\Public\Desktop\ZHPDiag.lnk
[2013/03/26 14:40:33 | 000,012,142 | ---- | C] () -- C:\Users\J\Desktop\Thunderdome XX - Playlist.m3u
[2013/03/25 17:14:37 | 000,389,514 | ---- | C] () -- C:\Users\J\Desktop\kjenspool.png
[2013/03/24 08:44:31 | 000,010,566 | ---- | C] () -- C:\Users\J\Documents\diggy.rtf
[2013/03/24 04:57:20 | 000,016,182 | ---- | C] () -- C:\Users\J\Documents\Clueless.rtf
[2013/03/23 05:22:28 | 000,000,335 | ---- | C] () -- C:\Users\J\Documents\REP - Curls.rtf
[2013/03/23 02:35:56 | 000,706,981 | ---- | C] () -- C:\Users\J\Desktop\Img_130323022310-2.png
[2013/03/22 10:51:13 | 3976,384,510 | -HS- | C] () -- C:\hiberfil.sys
[2013/03/20 18:22:55 | 000,021,396 | ---- | C] () -- C:\Users\J\Documents\twit phrases 2.rtf
[2013/03/20 06:03:00 | 000,000,290 | ---- | C] () -- C:\windows\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-867398653-3465891867-48189854-1001.job
[2013/03/19 19:05:19 | 000,077,296 | ---- | C] () -- C:\Users\J\Desktop\J-PC - CPUZ BEFORE
[2013/03/19 19:02:29 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CPUID CPU-Z.lnk
[2013/03/19 17:57:41 | 000,000,334 | ---- | C] () -- C:\Users\J\Documents\dat fag.rtf
[2013/03/19 17:57:27 | 000,003,965 | ---- | C] () -- C:\Users\J\Documents\testudo 1.rtf
[2013/03/19 09:16:14 | 000,003,731 | ---- | C] () -- C:\Users\J\Documents\jakeinpeoria blasts 909.rtf
[2013/03/18 11:23:42 | 000,002,544 | ---- | C] () -- C:\Users\J\Documents\drama 3.rtf
[2013/03/18 10:08:40 | 000,010,796 | ---- | C] () -- C:\Users\J\Documents\clone drama 2.rtf
[2013/03/18 09:14:20 | 000,000,042 | ---- | C] () -- C:\Users\J\Desktop\Radio Greenbier 1 - FM Top 40.m3u
[2013/03/18 08:37:02 | 000,000,039 | ---- | C] () -- C:\Users\J\Desktop\ESPN 1280.m3u
[2013/03/18 08:00:36 | 000,004,800 | ---- | C] () -- C:\Users\J\Documents\clone drama.rtf
[2013/03/17 04:59:31 | 000,580,096 | ---- | C] () -- C:\windows\SysNative\ac3filter.acm
[2013/03/17 04:59:31 | 000,206,336 | ---- | C] () -- C:\windows\SysNative\unrar64.dll
[2013/03/17 04:39:01 | 000,001,203 | ---- | C] () -- C:\Users\Public\Desktop\aTube.lnk
[2013/03/17 04:28:06 | 000,002,121 | ---- | C] () -- C:\Users\Public\Desktop\Video Search.lnk
[2013/03/17 04:14:10 | 000,001,316 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2013/03/17 04:06:40 | 000,001,260 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/03/17 03:50:41 | 000,453,605 | ---- | C] () -- C:\windows\SysNative\fastboot.set
[2013/03/17 03:50:41 | 000,203,000 | ---- | C] () -- C:\windows\SysNative\LsDefrag.bmp
[2013/03/17 03:50:38 | 000,002,079 | ---- | C] () -- C:\Users\Public\Desktop\Lenovo EE Boot Optimizer.lnk
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd9.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd11.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysWow64\dlumd10.dll
[2013/03/17 03:23:58 | 000,000,000 | ---- | C] () -- C:\windows\SysNative\dlumd10.dll
[2013/03/17 01:08:45 | 000,025,185 | ---- | C] () -- C:\windows\SysWow64\ieuinit.inf
[2013/03/17 01:08:44 | 000,025,185 | ---- | C] () -- C:\windows\SysNative\ieuinit.inf
[2013/03/16 00:58:19 | 000,000,046 | ---- | C] () -- C:\Users\J\Desktop\1230Wausau-The Voice-Phil.m3u
[2013/03/16 00:47:41 | 000,000,046 | ---- | C] () -- C:\windows\SysWow64\DonationCoder_urlsnooper_InstallInfo.dat
[2013/03/15 12:16:48 | 000,025,159 | ---- | C] () -- C:\Users\J\Documents\espn comment - kobe ankle injury.rtf
[2013/03/13 04:49:16 | 000,001,082 | ---- | C] () -- C:\Users\J\Documents\espn comment clippers - dunk -.rtf
[2013/03/13 04:47:47 | 000,000,478 | ---- | C] () -- C:\Users\J\Documents\new drachtens March ---.rtf
[2013/03/12 20:54:54 | 000,011,699 | ---- | C] () -- C:\Users\J\Documents\espn la - comments dwight howard returns.rtf
[2013/03/12 19:36:01 | 000,006,834 | ---- | C] () -- C:\Users\J\Documents\twits phrases.rtf
[2013/03/12 17:13:48 | 000,001,762 | ---- | C] () -- C:\Users\J\Documents\stucknut-mentino.rtf
[2013/03/12 04:43:41 | 000,004,054 | ---- | C] () -- C:\Users\J\Documents\stucknut- rant on college sports and 24-7 network.rtf
[2013/03/12 02:55:13 | 000,000,291 | ---- | C] () -- C:\Users\J\Documents\j from com.rtf
[2013/03/11 05:58:47 | 001,064,411 | ---- | C] () -- C:\Users\J\Documents\hottass girl code.rtf
[2013/03/11 03:16:28 | 000,044,326 | ---- | C] () -- C:\Users\J\Documents\##bit ly - station links##.rtf
[2013/03/09 00:53:07 | 008,145,705 | ---- | C] () -- C:\Users\J\Documents\opicate- espn - kobe doing 40-12-6.rtf
[2013/03/08 23:07:53 | 000,004,394 | ---- | C] () -- C:\Users\J\Documents\s-nut- rant.rtf
[2013/03/08 14:21:46 | 000,003,813 | ---- | C] () -- C:\Users\J\Documents\trenddd.rtf
[2013/02/27 08:57:04 | 004,283,392 | ---- | C] () -- C:\windows\SysWow64\x264vfw.dll
[2013/02/09 12:16:30 | 000,234,768 | ---- | C] () -- C:\windows\SysWow64\PnkBstrB.exe
[2013/02/09 12:16:19 | 000,075,136 | ---- | C] () -- C:\windows\SysWow64\PnkBstrA.exe
[2013/01/12 10:33:36 | 000,237,568 | ---- | C] () -- C:\windows\SysWow64\rmc_rtspdl.dll
[2012/12/28 21:07:05 | 000,001,065 | ---- | C] () -- C:\windows\winamp.ini
[2012/12/23 04:26:00 | 000,776,014 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/11/07 05:52:44 | 012,865,536 | ---- | C] () -- C:\Users\J\AppData\Roaming\Sandra.mdb
[2012/07/17 15:22:04 | 000,179,200 | ---- | C] () -- C:\windows\SysWow64\unrar.dll
[2012/07/03 03:28:06 | 000,112,640 | ---- | C] () -- C:\windows\SysWow64\ff_vfw.dll
[2012/05/22 01:28:58 | 000,155,648 | ---- | C] () -- C:\windows\SysWow64\mlc.dll
[2012/05/02 17:12:46 | 000,001,422 | ---- | C] () -- C:\ProgramData\profile.xml
[2012/05/02 17:07:47 | 000,016,648 | ---- | C] () -- C:\windows\SysWow64\LogAPI.dll
[2012/05/02 16:04:05 | 000,001,652 | ---- | C] () -- C:\windows\vm331Rmv.ini
[2012/05/02 16:04:05 | 000,001,652 | ---- | C] () -- C:\windows\SysWow64\vm331Rmv.ini
[2011/12/08 06:32:24 | 000,216,064 | ---- | C] ( ) -- C:\windows\SysWow64\lagarith.dll
[2011/10/18 13:37:28 | 000,000,512 | ---- | C] () -- C:\windows\previous.bin
[2011/10/18 13:37:28 | 000,000,512 | ---- | C] () -- C:\windows\current.bin
[2011/10/18 13:17:19 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/10/18 13:17:19 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/10/18 13:17:06 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/10/18 12:42:27 | 000,000,000 | ---- | C] () -- C:\windows\ativpsrm.bin
[2011/10/18 12:38:27 | 000,003,929 | ---- | C] () -- C:\windows\SysWow64\atipblag.dat
[2011/08/09 22:56:20 | 000,059,904 | ---- | C] () -- C:\windows\SysWow64\OVDecode.dll
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 22:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 21:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/06/03 21:14:48 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\AC3Filter
[2012/11/01 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Amazon
[2012/05/02 17:28:40 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\ArcSyncConfig
[2012/03/16 17:18:49 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Auslogics
[2013/03/16 00:47:41 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\DonationCoder
[2013/01/25 13:35:19 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\FreemakeVideoDownloader
[2012/04/21 04:32:51 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\GlarySoft
[2012/10/31 20:55:17 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\ImgBurn
[2012/06/16 04:52:18 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Leadertech
[2012/05/02 17:08:06 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Lenovo
[2012/05/02 14:59:48 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\LSC
[2013/01/28 18:29:15 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Replay Media Catcher 4
[2013/01/27 18:34:41 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Replay Media Catcher 4.bak
[2012/12/13 15:24:57 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\rockbox.org
[2013/03/17 05:00:37 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Shark007
[2013/03/19 11:04:38 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\SoftGrid Client
[2012/05/30 08:13:22 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Synaptics
[2012/12/23 04:28:14 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\TP
[2013/03/17 04:47:25 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Win7codecs
[2013/02/20 04:21:44 | 000,000,000 | ---D | M] -- C:\Users\J\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
< End of report >
Edited by sisp53, 27 March 2013 - 04:09 PM.