Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Can't download anything. [Solved]


  • This topic is locked This topic is locked

#1
covphoenix

covphoenix

    Member

  • Member
  • PipPip
  • 78 posts
Hi,

Recently i have not been able to download anything. Everytime the download process is complete, it says the file had a virus and was removed. Can you help please.

Thanks
  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi I will need you to download and run a programme for me

Are you able to download to another computer and then transfer via a USB ?

Download OTL to your Desktop
Secondary link
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

    Posted Image
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    c:\program files (x86)\Google\Desktop /s
    c:\program files\Google\Desktop /s
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#3
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
OTL Extras logfile created on: 06/08/2013 16:43:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.62 Gb Available Physical Memory | 31.08% Memory free
4.23 Gb Paging File | 2.74 Gb Available in Paging File | 64.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.27 Gb Total Space | 23.74 Gb Free Space | 10.63% Space Free | Partition Type: NTFS
Drive D: | 9.61 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: RYAN-PC | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"UacDisableNotify" = 0
"InternetSettingsDisableNotify" = 0
"AutoUpdateDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{082702D5-5DD8-4600-BCE5-48B15174687F}" = HP Doc Viewer
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{11BB336F-0E58-4977-B866-F24FA334616B}" = HP Active Support Library
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 4.0
"{1BDC9633-895B-4842-BCB6-8FA1EC2A3C5A}" = Adobe Shockwave Player
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{247C5DDA-FFD7-44E0-8BF7-79BC80A0BF87}" = Windows Live Family Safety
"{250E9609-E830-43EB-B379-DAB7546A2422}" = muvee autoProducer 6.1
"{254C37AA-6B72-4300-84F6-98A82419187E}" = Hewlett-Packard Active Check
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2D6E3D97-1FDF-4993-AC75-72F59EC445C5}" = Windows Live Family Safety
"{2D87E961-577B-492B-AD54-1368680FB9A7}" = Virtual Earth 3D (Beta)
"{31216452-5540-4C96-B754-94890A63D5AB}" = HP Help and Support
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34D2AB40-150D-475D-AE32-BD23FB5EE355}" = HP Quick Launch Buttons 6.30 E1
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3D3E663D-4E7E-4577-A560-7ECDDD45548A}" = PVSonyDll
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{45D707E9-F3C4-11D9-A373-0050BAE317E1}" = HP QuickPlay 3.6
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{546A0B92-34FF-4796-A39A-4842FAF0B70E}" = ESU for Microsoft Vista
"{548F12A2-BD2E-4B5A-9B62-BBC0AA8EB3DD}" = Everio MediaBrowser 3
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.52.02
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{612F4E20-3661-4D44-AD79-823F1B613FB3}" = HP Update
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = Hewlett-Packard Asset Agent for Health Check
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{77F8A71E-3515-4832-B8B2-2F1EDBD2E0F1}" = Bing Bar
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7DC4A410-9986-4329-9E5D-687B2C42CA39}" = HP QuickTouch 1.00 C4
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91170409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office FrontPage 2003
"{91FD46D2-4FB7-4A51-8637-556E1BE1DB7C}" = iTunes
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{96AD3B61-EAE2-11E2-9E72-B8AC6F98CCE3}" = Google Earth
"{9885A11E-60E4-417C-B58B-8B31B21C0B8A}" = HP Easy Setup - Frontend
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Touch Pad Driver
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-A83000000003}" = Adobe Reader 8.3.1
"{AEBBFC67-7A03-4DF3-9E71-BA5C9EB4FBEF}" = MobileMe Control Panel
"{AF844339-2F8A-4593-81B3-9F4C54038C4E}" = Windows Live MIME IFilter
"{b02df929-29a7-4fd2-9a70-81a644b635f7}" = HP Total Care Advisor
"{B2544A03-10D0-4E5E-BA69-0362FFC20D18}" = OGA Notifier 2.0.0048.0
"{B53620C0-3A83-4F50-A7AB-175DB64C1CE3}" = HP User Guides 0090
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{BD0E2B92-3814-46F0-893B-4612EA010C7E}" = HP Customer Experience Enhancements
"{C45B1500-7B63-47C2-AB25-C28CB46AFDEE}" = OD2 Music Manager
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C950420B-4182-49EA-850A-A6A2ABF06C6B}" = Marvell Miniport Driver
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CBAE4F50-9FC9-4557-AB36-9826DF3C103C}" = HP Wireless Assistant
"{CC4A73BF-938E-4C19-A553-853C035C9BA1}" = LightScribe System Software 1.10.13.1
"{CCA357C1-4637-492E-81DF-B6F4E9F47DDE}" = HP Wireless Mouse Suite 2.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6A0DD73-6EF2-9A8D-6F60-4F338F922B37}" = BBC iPlayer Desktop
"{DBA4DB9D-EE51-4944-A419-98AB1F1249C8}" = LiveUpdate Notice (Symantec Corporation)
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E14ADE0E-75F3-4A46-87E5-26692DD626EC}" = Apple Mobile Device Support
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"{F7F3B252-E772-48AA-93EB-7964BC326067}" = MSCU for Microsoft Vista
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_6" = AIM 6
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1" = BBC iPlayer Desktop
"CCleaner" = CCleaner
"CdaC13Ba" = Cda Product Service - shared component
"Celtx (2.9.1)" = Celtx (2.9.1)
"CNXT_AUDIO_HDA" = Conexant HD Audio
"CNXT_MODEM_HDAUDIO_HERMOSA_HSF" = HDAUDIO Soft Data Fax Modem with SmartCP
"DivX Setup" = DivX Setup
"DTD Poker" = DTD Poker
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"ETTA Table Tennis Manager6.0" = ETTA Table Tennis Manager
"Free DVD Decrypter_is1" = Free DVD Decrypter version 1.5.6.602
"Google Updater" = Google Updater
"Hauppauge MCE2005 Software Encoder" = Hauppauge MCE XP/Vista Software Encoder (2.0.25149)
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"iLivid" = iLivid
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{F5577101-33CC-4711-8235-3A95BCD49DB0}" = EA Link
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 4.8.0
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"LiveUpdate" = LiveUpdate 3.2 (Symantec Corporation)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NIS" = Norton Internet Security
"NVIDIA Drivers" = NVIDIA Drivers
"PokerStars" = PokerStars
"RealPlayer 16.0" = RealPlayer
"SlingMedia.QPSlingPlayer_is1" = QuickPlay SlingPlayer 0.4.4
"SP6" = Logitech SetPoint 6.32
"SS_MeerkatManor01" = SS_MeerkatManor01 Screen Saver
"ViewpointMediaPlayer" = Viewpoint Media Player
"vShare" = vShare Plugin
"WildTangent hp Master Uninstall" = My HP Games
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"YInstHelper" = Yahoo! Install Manager

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"Google Chrome" = Google Chrome

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 19/07/2013 13:28:51 | Computer Name = Ryan-PC | Source = ESENT | ID = 489
Description = Windows (3304) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log"
for read only access failed with system error 5 (0x00000005): "Access is denied.
". The open file operation will fail with error -1032 (0xfffffbf8).

Error - 19/07/2013 13:28:51 | Computer Name = Ryan-PC | Source = ESENT | ID = 455
Description = Windows (3304) Windows: Error -1032 (0xfffffbf8) occurred while opening
logfile C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log.

Error - 19/07/2013 13:28:51 | Computer Name = Ryan-PC | Source = Windows Search Service | ID = 9000
Description =

Error - 19/07/2013 13:28:51 | Computer Name = Ryan-PC | Source = Windows Search Service | ID = 1006
Description =

Error - 23/07/2013 13:37:13 | Computer Name = Ryan-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

Error - 29/07/2013 10:01:02 | Computer Name = Ryan-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 29/07/2013 10:01:03 | Computer Name = Ryan-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 29/07/2013 10:20:56 | Computer Name = Ryan-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 06/08/2013 11:42:33 | Computer Name = Ryan-PC | Source = Application Hang | ID = 1002
Description = The program OTL.exe version 3.2.69.0 stopped interacting with Windows
and was closed. To see if more information about the problem is available, check
the problem history in the Problem Reports and Solutions control panel. Process
ID: 7e0 Start Time: 01ce92bb3f024631 Termination Time: 47

Error - 06/08/2013 11:46:03 | Computer Name = Ryan-PC | Source = Microsoft-Windows-CAPI2 | ID = 131585
Description =

[ OSession Events ]
Error - 10/02/2011 09:53:00 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

Error - 26/03/2011 14:22:23 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6550.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 208
seconds with 0 seconds of active time. This session ended with a crash.

Error - 16/05/2011 20:40:18 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 2
seconds with 0 seconds of active time. This session ended with a crash.

Error - 20/05/2011 06:35:56 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

Error - 23/05/2011 07:45:55 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 17
seconds with 0 seconds of active time. This session ended with a crash.

Error - 24/05/2011 09:38:58 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.

Error - 07/06/2011 09:04:24 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6550.5004, Microsoft Office Version: 12.0.6425.1000. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 19/10/2011 14:35:20 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 11
seconds with 0 seconds of active time. This session ended with a crash.

Error - 17/12/2011 10:56:13 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6654.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 17
seconds with 0 seconds of active time. This session ended with a crash.

Error - 16/01/2012 09:03:03 | Computer Name = Ryan-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6562.5003, Microsoft Office Version: 12.0.6425.1000. This session lasted 21
seconds with 0 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 05/08/2013 10:36:43 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7024
Description =

Error - 05/08/2013 10:36:43 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06/08/2013 05:39:02 | Computer Name = Ryan-PC | Source = Ntfs | ID = 262281
Description = The default transaction resource manager on volume D: encountered
a non-retryable error and could not start. The data contains the error code.

Error - 06/08/2013 05:40:19 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 06/08/2013 05:40:19 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7024
Description =

Error - 06/08/2013 05:40:19 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 06/08/2013 10:58:16 | Computer Name = Ryan-PC | Source = Ntfs | ID = 262281
Description = The default transaction resource manager on volume D: encountered
a non-retryable error and could not start. The data contains the error code.

Error - 06/08/2013 10:59:14 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 06/08/2013 10:59:14 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7024
Description =

Error - 06/08/2013 10:59:14 | Computer Name = Ryan-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
  • 0

#4
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
OTL logfile created on: 06/08/2013 16:43:07 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.62 Gb Available Physical Memory | 31.08% Memory free
4.23 Gb Paging File | 2.74 Gb Available in Paging File | 64.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.27 Gb Total Space | 23.74 Gb Free Space | 10.63% Space Free | Partition Type: NTFS
Drive D: | 9.61 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: RYAN-PC | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
PRC - [2013/07/17 17:17:12 | 000,814,984 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
PRC - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
PRC - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/10/07 10:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe
PRC - [2011/09/27 20:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
PRC - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelLinkS.exe
PRC - [2010/11/19 09:52:04 | 000,153,496 | ---- | M] (Primax Electronics Ltd.) -- C:\ProgramData\HP Link5 Config\PelLink5.exe
PRC - [2010/11/19 09:51:14 | 000,335,768 | ---- | M] ( ) -- C:\ProgramData\HP Link5 Config\Link5HID.exe
PRC - [2010/11/19 09:50:42 | 000,101,784 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe
PRC - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) -- C:\Windows\System32\drivers\CDAC11BA.EXE
PRC - [2009/04/11 07:28:11 | 000,217,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\WerFault.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/14 19:16:46 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\e3cc2cbffd5fb21da64e93d9b6c27c7c\System.ni.dll
MOD - [2013/07/14 19:16:37 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll
MOD - [2012/11/30 03:07:48 | 000,100,248 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2012/05/30 15:51:08 | 000,699,280 | R--- | M] () -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll
MOD - [2011/10/07 10:41:16 | 000,879,896 | ---- | M] () -- C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
MOD - [2010/11/04 11:17:14 | 000,047,104 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelDrv.dll
MOD - [2010/10/21 15:45:56 | 000,104,960 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelUtil.dll
MOD - [2010/10/12 10:02:04 | 000,079,360 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelComm.dll
MOD - [2010/09/17 11:48:08 | 000,028,672 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelMagnf.dll
MOD - [2010/06/21 14:57:02 | 000,459,264 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelHooks.dll
MOD - [2007/10/01 03:34:52 | 000,345,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007/10/01 03:34:42 | 000,255,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007/10/01 03:34:42 | 000,120,208 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007/10/01 03:34:42 | 000,038,184 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007/10/01 03:33:32 | 000,066,856 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Services (SafeList) ==========

SRV - [2013/07/17 17:17:13 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe -- (NIS)
SRV - [2011/09/27 20:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011/02/28 19:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () [Auto | Running] -- C:\ProgramData\HP Link5 Config\PelLinkS.exe -- (PelLinkS)
SRV - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) [Auto | Running] -- C:\Windows\System32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/05 18:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ryan\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013/07/11 15:28:32 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130804.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/07/10 01:00:00 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/07/10 01:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/07/10 01:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/07/10 01:00:00 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVENG.SYS -- (NAVENG)
DRV - [2013/05/23 06:25:28 | 000,934,488 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymEFA.sys -- (SymEFA)
DRV - [2013/05/21 06:02:00 | 000,367,704 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymDS.sys -- (SymDS)
DRV - [2013/05/21 05:41:34 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2013/05/16 06:02:14 | 000,603,224 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys -- (SRTSP)
DRV - [2013/04/25 01:43:56 | 000,352,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\symtdiv.sys -- (SYMTDIv)
DRV - [2013/04/16 03:41:14 | 000,134,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\ccSetx86.sys -- (ccSet_NIS)
DRV - [2013/03/05 02:39:19 | 000,175,264 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\Ironx86.sys -- (SymIRON)
DRV - [2013/03/05 02:21:35 | 000,032,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys -- (SRTSPX)
DRV - [2011/09/02 07:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2011/09/02 07:31:28 | 000,030,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2011/09/02 07:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2010/11/04 11:14:28 | 000,014,848 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPubA407.sys -- (HPubA407)
DRV - [2010/10/25 14:07:42 | 000,020,992 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPMoA407.sys -- (HPMoA407)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/04/24 22:00:21 | 000,008,864 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/10/18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/01 16:35:52 | 000,183,352 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/09/26 13:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007/08/09 04:42:08 | 000,045,568 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/07/30 19:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 18:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/07/11 18:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/24 09:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007/04/24 09:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007/04/24 09:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125bus.sys -- (s125bus)
DRV - [2007/04/18 13:03:26 | 000,141,312 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/01/09 09:22:28 | 000,006,144 | ---- | M] (Chic) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.h...ilion&pf=laptop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.h...ilion&pf=laptop
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE - HKLM\..\SearchScopes\{09EE41A6-BE54-4155-9689-9B5A9BEE2399}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage

IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com/?fr=fp-yie9
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes,DefaultScope = {755720C4-7AFD-4DE1-A29D-C57ABE040140}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolba...Terms}&srch=dsp
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{0E38A417-0210-4A24-B84A-5255D8948A89}: "URL" = http://uk.search.yah...f-8&fr=chr-yie8
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{60584C85-3606-4C12-ABE4-705744FED08C}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{755720C4-7AFD-4DE1-A29D-C57ABE040140}: "URL" = http://www.google.co...Encoding?}&rlz=
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{8728F7AB-8FBB-4346-9CB4-3CDC9FE75BD7}: "URL" = http://uk.search.yah...p={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{B05BCB51-AA42-4222-B174-526F938DEB6C}: "URL" = http://www.flickr.co...q={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=3.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\IPSFFPlgn\ [2013/07/11 14:01:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\coFFPlgn\ [2013/08/06 16:01:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/31 18:07:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/03 16:28:23 | 000,000,000 | ---D | M]

[2013/04/08 17:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions
[2013/04/08 17:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions\[email protected]
[2012/10/19 02:34:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://www.searchnu.com/406
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.searchnu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\

O1 HOSTS File: ([2006/09/18 22:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EPSON Stylus DX4800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [HPMonitor] C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MediaBarFileManager] C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PelBrain] C:\ProgramData\HP Link5 Config\PelLink5.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe ()
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} http://download.micr...tualEarth3D.cab (SentinelProxy Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{38D8A92F-D4C1-45EF-9A15-EB4E0821656C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4575122C-3310-43AC-892F-1972B3B04756}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - AppInit_DLLs: (c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/06 16:40:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/03 01:23:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/20 12:24:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2013/07/14 16:57:42 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/07/14 16:57:41 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/07/14 16:57:40 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/07/14 16:57:40 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/07/14 16:57:40 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/07/14 16:57:38 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/07/14 16:57:38 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/07/14 16:57:36 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/07/14 16:32:08 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013/07/14 16:32:08 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013/07/14 16:32:08 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013/07/14 16:32:08 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013/07/14 16:32:08 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013/07/14 16:32:08 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013/07/14 16:32:08 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013/07/14 16:32:08 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013/07/14 16:32:05 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2013/07/14 16:31:55 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/07/14 16:31:27 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2013/07/11 13:57:43 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2013/07/11 13:53:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/07/11 13:52:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/07/11 13:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/07/11 13:43:28 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/08/06 16:42:14 | 000,613,784 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/08/06 16:42:14 | 000,111,062 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/08/06 16:34:14 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/06 16:15:00 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/06 15:59:36 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013/08/06 15:59:15 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013/08/06 15:59:15 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2013/08/06 15:58:53 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/06 15:58:30 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 15:58:30 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 15:58:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/08/06 15:58:20 | 2145,771,520 | -HS- | M] () -- C:\hiberfil.sys
[2013/08/06 11:08:19 | 000,002,140 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013/08/06 10:54:03 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000UA.job
[2013/08/04 14:59:49 | 000,002,039 | ---- | M] () -- C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/04 14:59:48 | 000,002,037 | ---- | M] () -- C:\Users\Ryan\Desktop\Google Chrome.lnk
[2013/08/03 01:23:08 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/08/01 11:54:54 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000Core.job
[2013/07/17 17:17:12 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/07/17 17:17:12 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/07/14 19:13:32 | 000,401,568 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/07/14 19:11:34 | 002,543,771 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1404000.028\Cat.DB
[2013/07/11 13:57:49 | 000,002,213 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/07/11 13:31:32 | 000,007,611 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/07/11 13:31:32 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/08/03 01:23:08 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/01/05 13:53:40 | 000,001,940 | ---- | C] () -- C:\Users\Ryan\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/03/29 13:20:17 | 000,005,184 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2010/02/10 16:32:43 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/02/10 16:32:21 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/09/18 11:49:34 | 000,000,082 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2009/08/21 10:51:57 | 000,058,772 | ---- | C] () -- C:\Users\Ryan\HISTORY.WK3
[2009/08/21 10:51:57 | 000,039,178 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.WK3
[2009/08/21 10:51:57 | 000,024,001 | ---- | C] () -- C:\Users\Ryan\HISTORY.FM3
[2009/08/21 10:51:57 | 000,014,435 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.FM3
[2009/08/21 10:51:57 | 000,007,262 | ---- | C] () -- C:\Users\Ryan\COVMAP.FM3
[2009/08/21 10:51:57 | 000,006,930 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.FM3
[2009/08/21 10:51:57 | 000,004,173 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.WK3
[2009/08/21 10:51:57 | 000,002,425 | ---- | C] () -- C:\Users\Ryan\COVMAP.WK3
[2008/10/07 14:17:41 | 000,007,808 | ---- | C] () -- C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2008/09/17 22:28:20 | 001,323,093 | ---- | C] () -- C:\Users\Ryan\imm-077.jpg
[2008/09/17 22:28:20 | 001,288,835 | ---- | C] () -- C:\Users\Ryan\imm-078.jpg
[2008/09/17 22:28:20 | 001,279,222 | ---- | C] () -- C:\Users\Ryan\imm-053.jpg
[2008/09/17 22:28:20 | 001,273,747 | ---- | C] () -- C:\Users\Ryan\imm-059.jpg
[2008/09/17 22:28:20 | 001,204,402 | ---- | C] () -- C:\Users\Ryan\imm-075.jpg
[2008/09/17 22:28:20 | 001,194,039 | ---- | C] () -- C:\Users\Ryan\imm-060.jpg
[2008/09/17 22:28:20 | 001,171,748 | ---- | C] () -- C:\Users\Ryan\imm-094.jpg
[2008/09/17 22:28:20 | 001,169,184 | ---- | C] () -- C:\Users\Ryan\imm-070.jpg
[2008/09/17 22:28:20 | 001,167,660 | ---- | C] () -- C:\Users\Ryan\imm-099.jpg
[2008/09/17 22:28:20 | 001,166,353 | ---- | C] () -- C:\Users\Ryan\imm-071.jpg
[2008/09/17 22:28:20 | 001,158,289 | ---- | C] () -- C:\Users\Ryan\imm-055.jpg
[2008/09/17 22:28:20 | 001,154,139 | ---- | C] () -- C:\Users\Ryan\imm-056.jpg
[2008/09/17 22:28:20 | 001,143,112 | ---- | C] () -- C:\Users\Ryan\imm-080.jpg
[2008/09/17 22:28:20 | 001,135,379 | ---- | C] () -- C:\Users\Ryan\imm-063.jpg
[2008/09/17 22:28:20 | 001,118,906 | ---- | C] () -- C:\Users\Ryan\imm-098.jpg
[2008/09/17 22:28:20 | 001,112,388 | ---- | C] () -- C:\Users\Ryan\imm-072.jpg
[2008/09/17 22:28:20 | 001,103,321 | ---- | C] () -- C:\Users\Ryan\imm-100.jpg
[2008/09/17 22:28:20 | 001,102,895 | ---- | C] () -- C:\Users\Ryan\imm-079.jpg
[2008/09/17 22:28:20 | 001,093,115 | ---- | C] () -- C:\Users\Ryan\imm-081.jpg
[2008/09/17 22:28:20 | 001,090,605 | ---- | C] () -- C:\Users\Ryan\imm-073.jpg
[2008/09/17 22:28:20 | 001,084,980 | ---- | C] () -- C:\Users\Ryan\imm-076.jpg
[2008/09/17 22:28:20 | 001,084,712 | ---- | C] () -- C:\Users\Ryan\imm-091.jpg
[2008/09/17 22:28:20 | 001,083,644 | ---- | C] () -- C:\Users\Ryan\imm-085.jpg
[2008/09/17 22:28:20 | 001,082,950 | ---- | C] () -- C:\Users\Ryan\imm-058.jpg
[2008/09/17 22:28:20 | 001,079,103 | ---- | C] () -- C:\Users\Ryan\imm-054.jpg
[2008/09/17 22:28:20 | 001,066,356 | ---- | C] () -- C:\Users\Ryan\imm-062.jpg
[2008/09/17 22:28:20 | 001,043,880 | ---- | C] () -- C:\Users\Ryan\imm-057.jpg
[2008/09/17 22:28:20 | 001,038,598 | ---- | C] () -- C:\Users\Ryan\imm-061.jpg
[2008/09/17 22:28:20 | 001,036,315 | ---- | C] () -- C:\Users\Ryan\imm-074.jpg
[2008/09/17 22:28:20 | 001,018,160 | ---- | C] () -- C:\Users\Ryan\imm-084.jpg
[2008/09/17 22:28:20 | 001,017,943 | ---- | C] () -- C:\Users\Ryan\imm-065.jpg
[2008/09/17 22:28:20 | 001,006,591 | ---- | C] () -- C:\Users\Ryan\imm-088.jpg
[2008/09/17 22:28:20 | 000,997,553 | ---- | C] () -- C:\Users\Ryan\imm-083.jpg
[2008/09/17 22:28:20 | 000,996,794 | ---- | C] () -- C:\Users\Ryan\imm-082.jpg
[2008/09/17 22:28:20 | 000,990,053 | ---- | C] () -- C:\Users\Ryan\imm-086.jpg
[2008/09/17 22:28:20 | 000,974,827 | ---- | C] () -- C:\Users\Ryan\imm-090.jpg
[2008/09/17 22:28:20 | 000,974,231 | ---- | C] () -- C:\Users\Ryan\imm-095.jpg
[2008/09/17 22:28:20 | 000,971,338 | ---- | C] () -- C:\Users\Ryan\imm-096.jpg
[2008/09/17 22:28:20 | 000,960,482 | ---- | C] () -- C:\Users\Ryan\imm-087.jpg
[2008/09/17 22:28:20 | 000,928,194 | ---- | C] () -- C:\Users\Ryan\imm-093.jpg
[2008/09/17 22:28:20 | 000,915,889 | ---- | C] () -- C:\Users\Ryan\imm-092.jpg
[2008/09/17 22:28:20 | 000,897,569 | ---- | C] () -- C:\Users\Ryan\imm-067.jpg
[2008/09/17 22:28:20 | 000,895,767 | ---- | C] () -- C:\Users\Ryan\imm-064.jpg
[2008/09/17 22:28:20 | 000,883,008 | ---- | C] () -- C:\Users\Ryan\imm-066.jpg
[2008/09/17 22:28:20 | 000,875,773 | ---- | C] () -- C:\Users\Ryan\imm-097.jpg
[2008/09/17 22:28:20 | 000,861,143 | ---- | C] () -- C:\Users\Ryan\imm-089.jpg
[2008/09/17 22:28:20 | 000,814,830 | ---- | C] () -- C:\Users\Ryan\imm-069.jpg
[2008/09/17 22:28:20 | 000,710,128 | ---- | C] () -- C:\Users\Ryan\imm-068.jpg
[2008/09/17 22:28:19 | 001,483,088 | ---- | C] () -- C:\Users\Ryan\imm-031.jpg
[2008/09/17 22:28:19 | 001,358,383 | ---- | C] () -- C:\Users\Ryan\imm-043.jpg
[2008/09/17 22:28:19 | 001,355,074 | ---- | C] () -- C:\Users\Ryan\imm-001.jpg
[2008/09/17 22:28:19 | 001,310,940 | ---- | C] () -- C:\Users\Ryan\imm-030.jpg
[2008/09/17 22:28:19 | 001,281,914 | ---- | C] () -- C:\Users\Ryan\imm-050.jpg
[2008/09/17 22:28:19 | 001,272,139 | ---- | C] () -- C:\Users\Ryan\imm-022.jpg
[2008/09/17 22:28:19 | 001,272,091 | ---- | C] () -- C:\Users\Ryan\imm-009.jpg
[2008/09/17 22:28:19 | 001,270,420 | ---- | C] () -- C:\Users\Ryan\imm-049.jpg
[2008/09/17 22:28:19 | 001,261,265 | ---- | C] () -- C:\Users\Ryan\imm-037.jpg
[2008/09/17 22:28:19 | 001,261,141 | ---- | C] () -- C:\Users\Ryan\imm-025.jpg
[2008/09/17 22:28:19 | 001,238,272 | ---- | C] () -- C:\Users\Ryan\imm-032.jpg
[2008/09/17 22:28:19 | 001,230,416 | ---- | C] () -- C:\Users\Ryan\imm-007.jpg
[2008/09/17 22:28:19 | 001,229,027 | ---- | C] () -- C:\Users\Ryan\imm-034.jpg
[2008/09/17 22:28:19 | 001,227,774 | ---- | C] () -- C:\Users\Ryan\imm-013.jpg
[2008/09/17 22:28:19 | 001,223,206 | ---- | C] () -- C:\Users\Ryan\imm-033.jpg
[2008/09/17 22:28:19 | 001,215,341 | ---- | C] () -- C:\Users\Ryan\imm-017.jpg
[2008/09/17 22:28:19 | 001,203,805 | ---- | C] () -- C:\Users\Ryan\imm-021.jpg
[2008/09/17 22:28:19 | 001,198,472 | ---- | C] () -- C:\Users\Ryan\imm-018.jpg
[2008/09/17 22:28:19 | 001,192,908 | ---- | C] () -- C:\Users\Ryan\imm-045.jpg
[2008/09/17 22:28:19 | 001,192,006 | ---- | C] () -- C:\Users\Ryan\imm-004.jpg
[2008/09/17 22:28:19 | 001,182,455 | ---- | C] () -- C:\Users\Ryan\imm-005.jpg
[2008/09/17 22:28:19 | 001,178,485 | ---- | C] () -- C:\Users\Ryan\imm-002.jpg
[2008/09/17 22:28:19 | 001,177,730 | ---- | C] () -- C:\Users\Ryan\imm-044.jpg
[2008/09/17 22:28:19 | 001,172,603 | ---- | C] () -- C:\Users\Ryan\imm-046.jpg
[2008/09/17 22:28:19 | 001,159,981 | ---- | C] () -- C:\Users\Ryan\imm-024.jpg
[2008/09/17 22:28:19 | 001,157,125 | ---- | C] () -- C:\Users\Ryan\imm-035.jpg
[2008/09/17 22:28:19 | 001,153,980 | ---- | C] () -- C:\Users\Ryan\imm-029.jpg
[2008/09/17 22:28:19 | 001,153,669 | ---- | C] () -- C:\Users\Ryan\imm-048.jpg
[2008/09/17 22:28:19 | 001,152,221 | ---- | C] () -- C:\Users\Ryan\imm-016.jpg
[2008/09/17 22:28:19 | 001,128,909 | ---- | C] () -- C:\Users\Ryan\imm-026.jpg
[2008/09/17 22:28:19 | 001,128,761 | ---- | C] () -- C:\Users\Ryan\imm-003.jpg
[2008/09/17 22:28:19 | 001,118,740 | ---- | C] () -- C:\Users\Ryan\imm-011.jpg
[2008/09/17 22:28:19 | 001,117,617 | ---- | C] () -- C:\Users\Ryan\imm-023.jpg
[2008/09/17 22:28:19 | 001,107,993 | ---- | C] () -- C:\Users\Ryan\imm-051.jpg
[2008/09/17 22:28:19 | 001,107,740 | ---- | C] () -- C:\Users\Ryan\imm-036.jpg
[2008/09/17 22:28:19 | 001,100,749 | ---- | C] () -- C:\Users\Ryan\imm-027.jpg
[2008/09/17 22:28:19 | 001,099,588 | ---- | C] () -- C:\Users\Ryan\imm-028.jpg
[2008/09/17 22:28:19 | 001,073,902 | ---- | C] () -- C:\Users\Ryan\imm-047.jpg
[2008/09/17 22:28:19 | 001,073,031 | ---- | C] () -- C:\Users\Ryan\imm-006.jpg
[2008/09/17 22:28:19 | 001,059,025 | ---- | C] () -- C:\Users\Ryan\imm-020.jpg
[2008/09/17 22:28:19 | 001,057,751 | ---- | C] () -- C:\Users\Ryan\imm-008.jpg
[2008/09/17 22:28:19 | 001,046,622 | ---- | C] () -- C:\Users\Ryan\imm-015.jpg
[2008/09/17 22:28:19 | 001,039,467 | ---- | C] () -- C:\Users\Ryan\imm-019.jpg
[2008/09/17 22:28:19 | 001,037,883 | ---- | C] () -- C:\Users\Ryan\imm-012.jpg
[2008/09/17 22:28:19 | 001,029,406 | ---- | C] () -- C:\Users\Ryan\imm-039.jpg
[2008/09/17 22:28:19 | 001,027,183 | ---- | C] () -- C:\Users\Ryan\imm-040.jpg
[2008/09/17 22:28:19 | 001,027,055 | ---- | C] () -- C:\Users\Ryan\imm-052.jpg
[2008/09/17 22:28:19 | 001,022,940 | ---- | C] () -- C:\Users\Ryan\imm-014.jpg
[2008/09/17 22:28:19 | 001,008,391 | ---- | C] () -- C:\Users\Ryan\imm-038.jpg
[2008/09/17 22:28:19 | 000,991,196 | ---- | C] () -- C:\Users\Ryan\imm-041.jpg
[2008/09/17 22:28:19 | 000,924,138 | ---- | C] () -- C:\Users\Ryan\imm-042.jpg
[2008/09/17 22:28:19 | 000,920,326 | ---- | C] () -- C:\Users\Ryan\imm-010.jpg
[2008/06/29 21:00:01 | 000,024,576 | ---- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/29 12:36:42 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.001
[2008/06/29 12:17:39 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.dat

========== ZeroAccess Check ==========

[2013/07/20 11:55:03 | 000,002,048 | -HS- | M] () -- C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\@
[2013/02/27 16:03:44 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\L
[2013/02/27 16:03:44 | 000,000,000 | -HSD | M] -- C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\U
[2006/11/02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\$Recycle.Bin\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\n.
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/03/07 21:37:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Audacity
[2013/04/02 16:31:03 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\avidemux
[2012/10/19 02:34:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Babylon
[2012/07/25 17:12:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/11/23 11:25:32 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\CoreFTP
[2011/10/29 18:11:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\DVDVideoSoft
[2012/10/18 16:30:04 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Freecorder 6 Video
[2010/10/27 22:41:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\GetRightToGo
[2013/04/08 17:49:24 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Greyfirst
[2011/10/26 17:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Leadertech
[2011/04/18 11:31:50 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Systweak
[2009/09/18 11:49:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Template
[2010/02/15 16:43:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Windows Live Writer
[2012/10/19 02:31:09 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\YourFileDownloader

========== Purity Check ==========



========== Custom Scans ==========

========== Base Services ==========
SRV - [2006/11/02 10:46:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2008/01/19 08:33:43 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2008/01/19 08:33:01 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2009/04/11 07:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2009/04/11 07:28:18 | 000,334,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/04/11 07:28:19 | 000,268,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2008/01/19 08:33:49 | 000,081,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2013/04/24 05:00:30 | 000,133,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2009/04/11 07:28:18 | 000,204,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcsvc.dll -- (Dhcp)
SRV - [2011/03/02 16:44:27 | 000,086,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2008/01/19 08:34:08 | 000,057,344 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/04/11 07:28:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2008/01/19 08:34:34 | 000,288,256 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2009/04/11 07:28:20 | 000,364,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/04/11 07:28:24 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2008/01/19 08:34:49 | 000,045,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2008/01/19 08:35:36 | 000,274,432 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2008/01/19 08:35:36 | 000,237,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2008/01/19 08:35:38 | 000,168,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2008/01/19 08:35:57 | 000,018,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2009/04/11 07:28:25 | 000,222,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2010/08/17 15:11:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
SRV - [2009/04/11 07:28:19 | 000,564,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\emdmgmt.dll -- (EMDMgmt)
SRV - [2008/01/19 08:36:15 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2009/04/11 07:28:24 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2008/01/19 08:36:20 | 000,019,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009/04/11 07:28:26 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/09/06 17:20:29 | 000,125,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/04/11 07:27:49 | 003,408,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SLsvc.exe -- (slsvc)
SRV - [2010/11/04 19:55:12 | 000,601,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2009/04/11 07:28:24 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (Themes)
SRV - [2009/04/11 07:28:23 | 000,153,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2009/04/11 07:28:10 | 001,055,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2008/01/19 08:36:20 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/04/11 07:28:25 | 001,017,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (Eventlog)
SRV - [2009/04/11 07:28:20 | 000,407,552 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2009/04/11 07:28:25 | 000,453,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (stisvc)
SRV - [2009/04/11 07:27:45 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/04/11 07:28:25 | 000,162,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/02 23:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2009/04/11 07:28:18 | 000,175,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009/07/11 20:01:42 | 000,513,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2009/06/10 12:42:23 | 000,160,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/07/01 17:53:28 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2008/07/01 17:53:27 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SERVICES >
[2006/09/18 22:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\System32\drivers\etc\services
[2006/09/18 22:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.CNF >
[2009/07/02 16:36:19 | 000,000,003 | ---- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 -- C:\Users\Ryan\Documents\My Web Sites\_vti_pvt\services.cnf

< MD5 for: SERVICES.EXE >
[2008/01/19 08:33:28 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 10:45:40 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/11 07:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\System32\services.exe
[2009/04/11 07:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 13:40:53 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 13:40:53 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/07/07 14:45:34 | 000,001,688 | ---- | M] () MD5=BD64D178636C32068A36B4E05DF7D85E -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/07/07 14:45:34 | 000,001,688 | ---- | M] () MD5=BD64D178636C32068A36B4E05DF7D85E -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 13:41:29 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2006/11/02 13:41:29 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SVCHOST.EXE >
[2006/11/02 10:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< c:\program files (x86)\Google\Desktop /s >
[2006/11/02 14:01:49 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2006/11/02 14:01:49 | 000,032,646 | ---- | C] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009/10/26 10:33:19 | 000,000,878 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2009/10/26 10:33:20 | 000,000,882 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
[2011/01/09 22:08:03 | 000,000,820 | ---- | C] () -- C:\Windows\Tasks\Google Software Updater.job
[2011/08/14 23:43:04 | 000,000,852 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000Core.job
[2011/08/14 23:43:04 | 000,000,904 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000UA.job
[2012/04/21 17:39:11 | 000,000,830 | ---- | C] () -- C:\Windows\Tasks\Adobe Flash Player Updater.job

< c:\program files\Google\Desktop /s >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 647E-22EE
Directory of C:\
02/11/2006 14:02 <JUNCTION> Documents and Settings [c:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files\Windows Defender
02/11/2006 13:42 <SYMLINKD> en-US [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpClient.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpCmdRun.exe [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MpEvMsg.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpOAV.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtMon.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtPlug.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSigDwn.dll [c:\windows\system32\config]
11/04/2009 07:27 <SYMLINK> MpSoftEx.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSvc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MSASCui.exe [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MsMpCom.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [c:\windows\system32\config]
14 File(s) 4,344,192 bytes
Directory of C:\ProgramData
02/11/2006 14:02 <JUNCTION> Application Data [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Desktop [c:\Users\Public\Desktop]
02/11/2006 14:02 <JUNCTION> Documents [c:\Users\Public\Documents]
02/11/2006 14:02 <JUNCTION> Favorites [c:\Users\Public\Favorites]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
02/11/2006 14:02 <SYMLINKD> All Users [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Default User [c:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
02/11/2006 14:02 <JUNCTION> Application Data [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Desktop [c:\Users\Public\Desktop]
02/11/2006 14:02 <JUNCTION> Documents [c:\Users\Public\Documents]
02/11/2006 14:02 <JUNCTION> Favorites [c:\Users\Public\Favorites]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
02/11/2006 14:02 <JUNCTION> Application Data [c:\Users\Default\AppData\Roaming]
02/11/2006 14:02 <JUNCTION> Cookies [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
02/11/2006 14:02 <JUNCTION> Local Settings [c:\Users\Default\AppData\Local]
02/11/2006 14:02 <JUNCTION> My Documents [c:\Users\Default\Documents]
02/11/2006 14:02 <JUNCTION> NetHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
02/11/2006 14:02 <JUNCTION> PrintHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
02/11/2006 14:02 <JUNCTION> Recent [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
02/11/2006 14:02 <JUNCTION> SendTo [c:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
02/11/2006 14:02 <JUNCTION> Application Data [c:\Users\Default\AppData\Local]
02/11/2006 14:02 <JUNCTION> History [c:\Users\Default\AppData\Local\Microsoft\Windows\History]
02/11/2006 14:02 <JUNCTION> Temporary Internet Files [c:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
02/11/2006 14:02 <JUNCTION> My Music [c:\Users\Default\Music]
02/11/2006 14:02 <JUNCTION> My Pictures [c:\Users\Default\Pictures]
02/11/2006 14:02 <JUNCTION> My Videos [c:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
02/11/2006 14:02 <JUNCTION> My Music [c:\Users\Public\Music]
02/11/2006 14:02 <JUNCTION> My Pictures [c:\Users\Public\Pictures]
02/11/2006 14:02 <JUNCTION> My Videos [c:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Ryan
26/06/2008 07:41 <JUNCTION> Application Data [C:\Users\Ryan\AppData\Roaming]
26/06/2008 07:41 <JUNCTION> Cookies [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies]
26/06/2008 07:41 <JUNCTION> Local Settings [C:\Users\Ryan\AppData\Local]
26/06/2008 07:41 <JUNCTION> My Documents [C:\Users\Ryan\Documents]
26/06/2008 07:41 <JUNCTION> NetHood [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
26/06/2008 07:41 <JUNCTION> PrintHood [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
26/06/2008 07:41 <JUNCTION> Recent [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Recent]
26/06/2008 07:41 <JUNCTION> SendTo [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\SendTo]
26/06/2008 07:41 <JUNCTION> Start Menu [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu]
26/06/2008 07:41 <JUNCTION> Templates [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Ryan\AppData\Local
26/06/2008 07:41 <JUNCTION> Application Data [C:\Users\Ryan\AppData\Local]
26/06/2008 07:41 <JUNCTION> History [C:\Users\Ryan\AppData\Local\Microsoft\Windows\History]
26/06/2008 07:41 <JUNCTION> Temporary Internet Files [C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Ryan\Documents
26/06/2008 07:41 <JUNCTION> My Music [C:\Users\Ryan\Music]
26/06/2008 07:41 <JUNCTION> My Pictures [C:\Users\Ryan\Pictures]
26/06/2008 07:41 <JUNCTION> My Videos [C:\Users\Ryan\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender-events_31bf3856ad364e35_6.0.6000.16386_none_b3613e39beae266f
02/11/2006 13:34 <SYMLINK> MpEvMsg.dll [c:\windows\system32\config]
1 File(s) 65,640 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6000.16386_none_5585eece5b4407f1
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [c:\windows\system32\config]
3 File(s) 681,784 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6001.18000_none_57bcb0ca582f18c5
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpClient.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpCmdRun.exe [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpOAV.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtMon.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtPlug.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSigDwn.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSvc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MSASCui.exe [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MsMpCom.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [c:\windows\system32\config]
12 File(s) 3,765,552 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6002.18005_none_59a829d65550e411
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpClient.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpCmdRun.exe [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpOAV.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtMon.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpRtPlug.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSigDwn.dll [c:\windows\system32\config]
11/04/2009 07:27 <SYMLINK> MpSoftEx.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MpSvc.dll [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MSASCui.exe [c:\windows\system32\config]
19/01/2008 08:38 <SYMLINK> MsMpCom.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [c:\windows\system32\config]
13 File(s) 4,278,552 bytes
Total Files Listed:
43 File(s) 13,135,720 bytes
51 Dir(s) 25,238,478,848 bytes free

< End of report >
  • 0

#5
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
On completion of this run you should be able to download programmes. During the OTL fix a black box will open this is normal

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image
:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolba...Terms}&srch=dsp
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
[2013/04/08 17:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions\[email protected]
O2 - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - AppInit_DLLs: (c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found
[2012/10/19 02:34:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Babylon

:Reg
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll 

:Files
C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce
c:\progra~2\browse~1
C:\Program Files\vShare
fsutil reparsepoint delete "C:\Program Files\Windows Defender\en-US" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpAsDesc.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpClient.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpCmdRun.exe" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpEvMsg.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpOAV.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRTP.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MSASCui.exe" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpCom.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows DefenderMsMpLics.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpRes.dll" /c 
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtMon.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtPlug.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSigDwn.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSoftEx.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

THEN

Please download Junkware Removal Tool to your desktop.
  • Right-mouse click JRT.exe and select "Run as Administrator" the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • post the contents of JRT.txt into your next message.

FINALLY

Run OTL once more

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

    Posted Image
  • Select All Users
  • Under the Custom Scan box paste this in

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won't take long.
  • When the scan completes, it will open one notepad window this time .
  • Post all logs

  • 0

#6
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
I did the first part with otl but when it rebooted i got the following. It wont let me download the junkware removal tool. Should i download it on usb and transfer it or has the first part not worked correctly?

All processes killed
Error: Unable to interpret <:Commands[CREATERESTOREPOINT]:OTLIE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...{searchTerms}IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolba...rms}&srch=dspIE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}[2013/04/08 17:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions\[email protected] - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()O3 - HKLM\..\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()O4 - HKLM.> in the current context!
Error: Unable to interpret <.\Run: [] File not foundO16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()O20 - AppInit_DLLs: (c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found[2012/10/19 02:34:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Babylon :Reg[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]"" = %systemroot%\system32\wbem\fastprox.dll :FilesC:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143cec:\progra~2\browse~1C:\Program Files\vSharefsutil reparsepoint delete "C:\Program Files\Windows Defender\en-US" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpAsDesc.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpClient> in the current context!
Error: Unable to interpret <.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpCmdRun.exe" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpEvMsg.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpOAV.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRTP.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MSASCui.exe" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpCom.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows DefenderMsMpLics.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpRes.dll" /c fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtMon.dll" /cfsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtPlug.dll" /cfsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSigDwn.dll" /cfsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSoftEx.dll" /cfsutil > in the current context!
Error: Unable to interpret <reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c:Commands[resethosts][emptytemp][Reboot]> in the current context!

OTL by OldTimer - Version 3.2.69.0 log created on 08062013_182954

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#7
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Could you run OTL again please

Ensuring that you press the run fix button

:Commands
[CREATERESTOREPOINT]

:OTL
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}: "URL" = http://vshare.toolba...Terms}&srch=dsp
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-re...q={searchTerms}
[2013/04/08 17:49:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions\[email protected]
O2 - BHO: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKLM\..\Toolbar: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (vShare Toolbar) - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files\vShare\vshare_toolbar.dll ()
O4 - HKLM..\Run: [] File not found
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O18 - Protocol\Handler\vsharechrome {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files\vShare\vshare_toolbar.dll ()
O20 - AppInit_DLLs: (c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll) - File not found
[2012/10/19 02:34:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Babylon

:Reg
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll

:Files
C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce
c:\progra~2\browse~1
C:\Program Files\vShare
fsutil reparsepoint delete "C:\Program Files\Windows Defender\en-US" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpAsDesc.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpClient.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpCmdRun.exe" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpEvMsg.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpOAV.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRTP.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MSASCui.exe" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpCom.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows DefenderMsMpLics.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpRes.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtMon.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtPlug.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSigDwn.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSoftEx.dll" /c
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c

:Commands
[resethosts]
[emptytemp]
[Reboot]


  • 0

#8
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
Registry key HKEY_USERS\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Internet Explorer\SearchScopes\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}\ not found.
C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions\[email protected] folder moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found.
C:\Program Files\vShare\vshare_toolbar.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found.
File C:\Program Files\vShare\vshare_toolbar.dll not found.
Registry value HKEY_USERS\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{043C5167-00BB-4324-AF7E-62013FAEDACF} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{043C5167-00BB-4324-AF7E-62013FAEDACF}\ not found.
File C:\Program Files\vShare\vshare_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\ not found.
File C:\Program Files\vShare\vshare_toolbar.dll not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\vsharechrome\ deleted successfully.
File C:\Program Files\vShare\vshare_toolbar.dll not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:c:\progra~2\browse~1\23796~1.11\{16cdf~1\browse~1.dll deleted successfully.
C:\Users\Ryan\AppData\Roaming\Babylon folder moved successfully.
========== REGISTRY ==========
HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32\\"" | %systemroot%\system32\wbem\fastprox.dll /E : value set successfully!
========== FILES ==========
C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\U folder moved successfully.
C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce\L folder moved successfully.
C:\$RECYCLE.BIN\S-1-5-18\$12734cba2aa44fe2bfadca60983143ce folder moved successfully.
File\Folder c:\progra~2\browse~1 not found.
C:\Program Files\vShare\skin folder moved successfully.
C:\Program Files\vShare\radio folder moved successfully.
C:\Program Files\vShare folder moved successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\en-US" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpAsDesc.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpClient.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpCmdRun.exe" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpEvMsg.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpOAV.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRTP.dll" /c >
Error: The system cannot find the file specified.
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MSASCui.exe" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpCom.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows DefenderMsMpLics.dll" /c >
Error: The system cannot find the file specified.
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpRes.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtMon.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpRtPlug.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSigDwn.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSoftEx.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MpSvc.dll" /c >
Error: The file or directory is not a reparse point.
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56478 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Ryan
->Temp folder emptied: 53901 bytes
->Temporary Internet Files folder emptied: 14245532 bytes
->Java cache emptied: 4699896 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 15265397 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 33.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 08062013_195002

Files\Folders moved on Reboot...
C:\Users\Ryan\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.
C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#9
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.3.4 (08.06.2013:1)
OS: Windows Vista ™ Home Premium x86
Ran by Ryan on 06/08/2013 at 20:02:01.44
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr
Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr_toolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\ilivid
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\vshare
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yahoopartnertoolbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\yourfiledownloader
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon
Failed to delete: [Registry Key] HKEY_LOCAL_MACHINE\Software\datamngr
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\tarma installer
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\yourfiledownloader
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\applications\ilividsetupv1.exe
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctl.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\axmetastream.metastreamctlsecondary.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\ilivid
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\s
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.imedixprotocol
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.imedixprotocol.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.pugiobj
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.pugiobj.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.scripthelpers
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\vshare.scripthelpers.1
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{09EE41A6-BE54-4155-9689-9B5A9BEE2399}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{09EE41A6-BE54-4155-9689-9B5A9BEE2399}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Successfully deleted: [Registry Key] "hkey_current_user\software\apn pip"
Successfully deleted: [Registry Key] "hkey_current_user\software\pip"
Successfully deleted: [Registry Key] "hkey_local_machine\software\pip"



~~~ Files

Successfully deleted [File] C:\Windows\system32\Tasks\CreateChoiceProcessTask
Successfully deleted: [File] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ebay.lnk"
Successfully deleted: [File] "C:\Windows\system32\roboot.exe"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\babylon"
Successfully deleted: [Folder] "C:\ProgramData\boost_interprocess"
Successfully deleted: [Folder] "C:\ProgramData\tarma installer"
Successfully deleted: [Folder] "C:\ProgramData\viewpoint"
Successfully deleted: [Folder] "C:\ProgramData\ytd video downloader"
Successfully deleted: [Folder] "C:\Users\Ryan\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\Ryan\AppData\Roaming\yourfiledownloader"
Successfully deleted: [Folder] "C:\Users\Ryan\appdata\local\ilivid"
Successfully deleted: [Folder] "C:\Users\Ryan\appdata\local\ilivid player"
Successfully deleted: [Folder] "C:\Users\Ryan\appdata\locallow\babylontoolbar"
Successfully deleted: [Folder] "C:\Users\Ryan\appdata\locallow\boost_interprocess"
Successfully deleted: [Folder] "C:\Users\Ryan\appdata\locallow\vshare"
Successfully deleted: [Folder] "C:\Program Files\ilivid"
Successfully deleted: [Folder] "C:\Program Files\viewpoint"
Successfully deleted: [Folder] "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ytd video downloader"
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{0A1E5B2E-EF44-4431-9284-A17ADB1E23C7}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{1563759D-F4C9-411C-80F3-FD31B77CC744}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{1AEC0E4C-D8A5-47EA-8D85-339E8A5A10E6}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{23B5089E-53D6-4829-BC84-2B19BAA84A60}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{2629AAE0-EEF4-405A-9DDE-EB327635B799}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{3DD9C6D5-62CC-4B46-86DF-13E0CEA09F77}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{4FE6604A-8BDB-4B0E-A553-695A1D5B300C}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{51356CE9-F170-47AE-802C-5305E1BF4A46}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{553FA93F-59E1-4803-B717-045ADBFB65E4}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{5A1A73DC-509B-4554-BBE3-DC8B0681E248}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{5D0DE66C-CDE8-48F5-8054-94CE908F8137}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{60DAA1A6-4450-484F-8A09-55881AE9D0ED}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{6185B3ED-9489-4C9B-8D43-4426DFAE884E}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{6CB82589-77AE-463E-BEAF-9C4DEBB8C6A4}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{6E58C9C3-D66E-4C81-BFF3-9EDC5CBCB597}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{70318BF4-8C5F-4247-A3E5-4019FC3FFDAF}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{7BEB34EC-55A9-4D28-AFEA-1981A013CB2E}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{7C9A78E9-0113-41BB-A370-22B82172CE32}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{894294B3-7376-4EC1-8A35-2BEEBBC9BF73}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{A1C619B7-A0F9-494F-B787-EEDAA9188865}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{BC75A206-C40F-4D01-A515-38A17A0D3CC7}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{D5228E7B-250E-4344-ABEB-EB3F8BB489B8}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{D7D39E67-02FC-4512-9BC0-D0F499F92CE3}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{EA3DC242-0E4B-4A2F-9AF0-308456656B88}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{EC049589-8E98-4086-8391-0E43407248F2}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{F22455AB-86B5-4A80-B5E5-731B33785F76}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{F31D43FA-5BB4-467B-8766-8777BBCD6E75}
Successfully deleted: [Empty Folder] C:\Users\Ryan\appdata\local\{FC999DE8-EF63-4139-8961-D7652C15BEF6}



~~~ Chrome

Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\pgafcinpmmpklohkojmllohdhomoefph



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 06/08/2013 at 20:05:40.72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#10
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
OTL logfile created on: 06/08/2013 20:11:45 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.87 Gb Available Physical Memory | 43.41% Memory free
4.23 Gb Paging File | 2.94 Gb Available in Paging File | 69.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.27 Gb Total Space | 20.00 Gb Free Space | 8.96% Space Free | Partition Type: NTFS
Drive D: | 9.61 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: RYAN-PC | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
PRC - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
PRC - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/10/07 10:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe
PRC - [2011/09/27 20:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
PRC - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelLinkS.exe
PRC - [2010/11/19 09:52:04 | 000,153,496 | ---- | M] (Primax Electronics Ltd.) -- C:\ProgramData\HP Link5 Config\PelLink5.exe
PRC - [2010/11/19 09:51:14 | 000,335,768 | ---- | M] ( ) -- C:\ProgramData\HP Link5 Config\Link5HID.exe
PRC - [2010/11/19 09:50:42 | 000,101,784 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe
PRC - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) -- C:\Windows\System32\drivers\CDAC11BA.EXE
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/01/19 08:33:04 | 000,318,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
PRC - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/14 19:16:46 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\e3cc2cbffd5fb21da64e93d9b6c27c7c\System.ni.dll
MOD - [2013/07/14 19:16:37 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll
MOD - [2012/11/30 03:07:48 | 000,100,248 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2012/05/30 15:51:08 | 000,699,280 | R--- | M] () -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll
MOD - [2011/10/07 10:41:16 | 000,879,896 | ---- | M] () -- C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
MOD - [2010/11/04 11:17:14 | 000,047,104 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelDrv.dll
MOD - [2010/10/21 15:45:56 | 000,104,960 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelUtil.dll
MOD - [2010/10/12 10:02:04 | 000,079,360 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelComm.dll
MOD - [2010/09/17 11:48:08 | 000,028,672 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelMagnf.dll
MOD - [2010/06/21 14:57:02 | 000,459,264 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelHooks.dll
MOD - [2007/10/01 03:34:52 | 000,345,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007/10/01 03:34:42 | 000,255,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007/10/01 03:34:42 | 000,120,208 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007/10/01 03:34:42 | 000,038,184 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007/10/01 03:33:32 | 000,066,856 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Services (SafeList) ==========

SRV - [2013/07/17 17:17:13 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe -- (NIS)
SRV - [2011/09/27 20:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011/02/28 19:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () [Auto | Running] -- C:\ProgramData\HP Link5 Config\PelLinkS.exe -- (PelLinkS)
SRV - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) [Auto | Running] -- C:\Windows\System32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/05 18:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ryan\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013/07/11 15:28:32 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130804.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/07/10 01:00:00 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/07/10 01:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/07/10 01:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/07/10 01:00:00 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVENG.SYS -- (NAVENG)
DRV - [2013/05/23 06:25:28 | 000,934,488 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymEFA.sys -- (SymEFA)
DRV - [2013/05/21 06:02:00 | 000,367,704 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymDS.sys -- (SymDS)
DRV - [2013/05/21 05:41:34 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2013/05/16 06:02:14 | 000,603,224 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys -- (SRTSP)
DRV - [2013/04/25 01:43:56 | 000,352,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\symtdiv.sys -- (SYMTDIv)
DRV - [2013/04/16 03:41:14 | 000,134,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\ccSetx86.sys -- (ccSet_NIS)
DRV - [2013/03/05 02:39:19 | 000,175,264 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\Ironx86.sys -- (SymIRON)
DRV - [2013/03/05 02:21:35 | 000,032,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys -- (SRTSPX)
DRV - [2011/09/02 07:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2011/09/02 07:31:28 | 000,030,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2011/09/02 07:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2010/11/04 11:14:28 | 000,014,848 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPubA407.sys -- (HPubA407)
DRV - [2010/10/25 14:07:42 | 000,020,992 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPMoA407.sys -- (HPMoA407)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/04/24 22:00:21 | 000,008,864 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/10/18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/01 16:35:52 | 000,183,352 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/09/26 13:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007/08/09 04:42:08 | 000,045,568 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/07/30 19:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 18:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/07/11 18:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/24 09:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007/04/24 09:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007/04/24 09:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125bus.sys -- (s125bus)
DRV - [2007/04/18 13:03:26 | 000,141,312 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/01/09 09:22:28 | 000,006,144 | ---- | M] (Chic) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://securityrespo...er/fix_homepage

IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com/?fr=fp-yie9
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes,DefaultScope = {755720C4-7AFD-4DE1-A29D-C57ABE040140}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{0E38A417-0210-4A24-B84A-5255D8948A89}: "URL" = http://uk.search.yah...f-8&fr=chr-yie8
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{60584C85-3606-4C12-ABE4-705744FED08C}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{755720C4-7AFD-4DE1-A29D-C57ABE040140}: "URL" = http://www.google.co...Encoding?}&rlz=
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{8728F7AB-8FBB-4346-9CB4-3CDC9FE75BD7}: "URL" = http://uk.search.yah...p={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\SearchScopes\{B05BCB51-AA42-4222-B174-526F938DEB6C}: "URL" = http://www.flickr.co...q={searchTerms}
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=3.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\IPSFFPlgn\ [2013/07/11 14:01:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\coFFPlgn\ [2013/08/06 19:57:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/31 18:07:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/03 16:28:23 | 000,000,000 | ---D | M]

[2013/08/06 19:50:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions
[2012/10/19 02:34:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://www.searchnu.com/406
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.searchnu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\

O1 HOSTS File: ([2013/08/06 19:50:47 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EPSON Stylus DX4800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [HPMonitor] C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MediaBarFileManager] C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PelBrain] C:\ProgramData\HP Link5 Config\PelLink5.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} http://download.micr...tualEarth3D.cab (SentinelProxy Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{38D8A92F-D4C1-45EF-9A15-EB4E0821656C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4575122C-3310-43AC-892F-1972B3B04756}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/08/06 20:00:55 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/08/06 18:29:54 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/08/06 16:40:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/03 01:23:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/20 12:24:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2013/07/14 16:57:42 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2013/07/14 16:57:41 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2013/07/14 16:57:40 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2013/07/14 16:57:40 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2013/07/14 16:57:40 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2013/07/14 16:57:38 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2013/07/14 16:57:38 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2013/07/14 16:57:36 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2013/07/14 16:32:08 | 001,172,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10warp.dll
[2013/07/14 16:32:08 | 001,069,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\DWrite.dll
[2013/07/14 16:32:08 | 001,029,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10.dll
[2013/07/14 16:32:08 | 000,683,008 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d2d1.dll
[2013/07/14 16:32:08 | 000,486,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10level9.dll
[2013/07/14 16:32:08 | 000,219,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1core.dll
[2013/07/14 16:32:08 | 000,189,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10core.dll
[2013/07/14 16:32:08 | 000,160,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\d3d10_1.dll
[2013/07/14 16:32:05 | 001,548,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WMVDECOD.DLL
[2013/07/14 16:31:55 | 002,049,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2013/07/14 16:31:27 | 000,505,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\qedit.dll
[2013/07/11 13:57:43 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2013/07/11 13:53:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/07/11 13:52:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/07/11 13:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/07/11 13:43:28 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime

========== Files - Modified Within 30 Days ==========

[2013/08/06 20:15:08 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/06 19:55:16 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013/08/06 19:54:47 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2013/08/06 19:54:25 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013/08/06 19:54:24 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/06 19:54:04 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 19:54:04 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 19:54:03 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000UA.job
[2013/08/06 19:53:56 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/08/06 19:53:52 | 2143,698,944 | -HS- | M] () -- C:\hiberfil.sys
[2013/08/06 19:52:21 | 000,002,140 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013/08/06 19:50:47 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2013/08/06 19:34:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/06 16:42:14 | 000,613,784 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/08/06 16:42:14 | 000,111,062 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/04 14:59:49 | 000,002,039 | ---- | M] () -- C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/04 14:59:48 | 000,002,037 | ---- | M] () -- C:\Users\Ryan\Desktop\Google Chrome.lnk
[2013/08/03 01:23:08 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/08/01 11:54:54 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000Core.job
[2013/07/17 17:17:12 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/07/17 17:17:12 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/07/14 19:13:32 | 000,401,568 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/07/14 19:11:34 | 002,543,771 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1404000.028\Cat.DB
[2013/07/11 13:57:49 | 000,002,213 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/07/11 13:31:32 | 000,007,611 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/07/11 13:31:32 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF

========== Files Created - No Company Name ==========

[2013/08/03 01:23:08 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/01/05 13:53:40 | 000,001,940 | ---- | C] () -- C:\Users\Ryan\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/03/29 13:20:17 | 000,005,184 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2010/02/10 16:32:43 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/02/10 16:32:21 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/09/18 11:49:34 | 000,000,082 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2009/08/21 10:51:57 | 000,058,772 | ---- | C] () -- C:\Users\Ryan\HISTORY.WK3
[2009/08/21 10:51:57 | 000,039,178 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.WK3
[2009/08/21 10:51:57 | 000,024,001 | ---- | C] () -- C:\Users\Ryan\HISTORY.FM3
[2009/08/21 10:51:57 | 000,014,435 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.FM3
[2009/08/21 10:51:57 | 000,007,262 | ---- | C] () -- C:\Users\Ryan\COVMAP.FM3
[2009/08/21 10:51:57 | 000,006,930 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.FM3
[2009/08/21 10:51:57 | 000,004,173 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.WK3
[2009/08/21 10:51:57 | 000,002,425 | ---- | C] () -- C:\Users\Ryan\COVMAP.WK3
[2008/10/07 14:17:41 | 000,007,808 | ---- | C] () -- C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2008/09/17 22:28:20 | 001,323,093 | ---- | C] () -- C:\Users\Ryan\imm-077.jpg
[2008/09/17 22:28:20 | 001,288,835 | ---- | C] () -- C:\Users\Ryan\imm-078.jpg
[2008/09/17 22:28:20 | 001,279,222 | ---- | C] () -- C:\Users\Ryan\imm-053.jpg
[2008/09/17 22:28:20 | 001,273,747 | ---- | C] () -- C:\Users\Ryan\imm-059.jpg
[2008/09/17 22:28:20 | 001,204,402 | ---- | C] () -- C:\Users\Ryan\imm-075.jpg
[2008/09/17 22:28:20 | 001,194,039 | ---- | C] () -- C:\Users\Ryan\imm-060.jpg
[2008/09/17 22:28:20 | 001,171,748 | ---- | C] () -- C:\Users\Ryan\imm-094.jpg
[2008/09/17 22:28:20 | 001,169,184 | ---- | C] () -- C:\Users\Ryan\imm-070.jpg
[2008/09/17 22:28:20 | 001,167,660 | ---- | C] () -- C:\Users\Ryan\imm-099.jpg
[2008/09/17 22:28:20 | 001,166,353 | ---- | C] () -- C:\Users\Ryan\imm-071.jpg
[2008/09/17 22:28:20 | 001,158,289 | ---- | C] () -- C:\Users\Ryan\imm-055.jpg
[2008/09/17 22:28:20 | 001,154,139 | ---- | C] () -- C:\Users\Ryan\imm-056.jpg
[2008/09/17 22:28:20 | 001,143,112 | ---- | C] () -- C:\Users\Ryan\imm-080.jpg
[2008/09/17 22:28:20 | 001,135,379 | ---- | C] () -- C:\Users\Ryan\imm-063.jpg
[2008/09/17 22:28:20 | 001,118,906 | ---- | C] () -- C:\Users\Ryan\imm-098.jpg
[2008/09/17 22:28:20 | 001,112,388 | ---- | C] () -- C:\Users\Ryan\imm-072.jpg
[2008/09/17 22:28:20 | 001,103,321 | ---- | C] () -- C:\Users\Ryan\imm-100.jpg
[2008/09/17 22:28:20 | 001,102,895 | ---- | C] () -- C:\Users\Ryan\imm-079.jpg
[2008/09/17 22:28:20 | 001,093,115 | ---- | C] () -- C:\Users\Ryan\imm-081.jpg
[2008/09/17 22:28:20 | 001,090,605 | ---- | C] () -- C:\Users\Ryan\imm-073.jpg
[2008/09/17 22:28:20 | 001,084,980 | ---- | C] () -- C:\Users\Ryan\imm-076.jpg
[2008/09/17 22:28:20 | 001,084,712 | ---- | C] () -- C:\Users\Ryan\imm-091.jpg
[2008/09/17 22:28:20 | 001,083,644 | ---- | C] () -- C:\Users\Ryan\imm-085.jpg
[2008/09/17 22:28:20 | 001,082,950 | ---- | C] () -- C:\Users\Ryan\imm-058.jpg
[2008/09/17 22:28:20 | 001,079,103 | ---- | C] () -- C:\Users\Ryan\imm-054.jpg
[2008/09/17 22:28:20 | 001,066,356 | ---- | C] () -- C:\Users\Ryan\imm-062.jpg
[2008/09/17 22:28:20 | 001,043,880 | ---- | C] () -- C:\Users\Ryan\imm-057.jpg
[2008/09/17 22:28:20 | 001,038,598 | ---- | C] () -- C:\Users\Ryan\imm-061.jpg
[2008/09/17 22:28:20 | 001,036,315 | ---- | C] () -- C:\Users\Ryan\imm-074.jpg
[2008/09/17 22:28:20 | 001,018,160 | ---- | C] () -- C:\Users\Ryan\imm-084.jpg
[2008/09/17 22:28:20 | 001,017,943 | ---- | C] () -- C:\Users\Ryan\imm-065.jpg
[2008/09/17 22:28:20 | 001,006,591 | ---- | C] () -- C:\Users\Ryan\imm-088.jpg
[2008/09/17 22:28:20 | 000,997,553 | ---- | C] () -- C:\Users\Ryan\imm-083.jpg
[2008/09/17 22:28:20 | 000,996,794 | ---- | C] () -- C:\Users\Ryan\imm-082.jpg
[2008/09/17 22:28:20 | 000,990,053 | ---- | C] () -- C:\Users\Ryan\imm-086.jpg
[2008/09/17 22:28:20 | 000,974,827 | ---- | C] () -- C:\Users\Ryan\imm-090.jpg
[2008/09/17 22:28:20 | 000,974,231 | ---- | C] () -- C:\Users\Ryan\imm-095.jpg
[2008/09/17 22:28:20 | 000,971,338 | ---- | C] () -- C:\Users\Ryan\imm-096.jpg
[2008/09/17 22:28:20 | 000,960,482 | ---- | C] () -- C:\Users\Ryan\imm-087.jpg
[2008/09/17 22:28:20 | 000,928,194 | ---- | C] () -- C:\Users\Ryan\imm-093.jpg
[2008/09/17 22:28:20 | 000,915,889 | ---- | C] () -- C:\Users\Ryan\imm-092.jpg
[2008/09/17 22:28:20 | 000,897,569 | ---- | C] () -- C:\Users\Ryan\imm-067.jpg
[2008/09/17 22:28:20 | 000,895,767 | ---- | C] () -- C:\Users\Ryan\imm-064.jpg
[2008/09/17 22:28:20 | 000,883,008 | ---- | C] () -- C:\Users\Ryan\imm-066.jpg
[2008/09/17 22:28:20 | 000,875,773 | ---- | C] () -- C:\Users\Ryan\imm-097.jpg
[2008/09/17 22:28:20 | 000,861,143 | ---- | C] () -- C:\Users\Ryan\imm-089.jpg
[2008/09/17 22:28:20 | 000,814,830 | ---- | C] () -- C:\Users\Ryan\imm-069.jpg
[2008/09/17 22:28:20 | 000,710,128 | ---- | C] () -- C:\Users\Ryan\imm-068.jpg
[2008/09/17 22:28:19 | 001,483,088 | ---- | C] () -- C:\Users\Ryan\imm-031.jpg
[2008/09/17 22:28:19 | 001,358,383 | ---- | C] () -- C:\Users\Ryan\imm-043.jpg
[2008/09/17 22:28:19 | 001,355,074 | ---- | C] () -- C:\Users\Ryan\imm-001.jpg
[2008/09/17 22:28:19 | 001,310,940 | ---- | C] () -- C:\Users\Ryan\imm-030.jpg
[2008/09/17 22:28:19 | 001,281,914 | ---- | C] () -- C:\Users\Ryan\imm-050.jpg
[2008/09/17 22:28:19 | 001,272,139 | ---- | C] () -- C:\Users\Ryan\imm-022.jpg
[2008/09/17 22:28:19 | 001,272,091 | ---- | C] () -- C:\Users\Ryan\imm-009.jpg
[2008/09/17 22:28:19 | 001,270,420 | ---- | C] () -- C:\Users\Ryan\imm-049.jpg
[2008/09/17 22:28:19 | 001,261,265 | ---- | C] () -- C:\Users\Ryan\imm-037.jpg
[2008/09/17 22:28:19 | 001,261,141 | ---- | C] () -- C:\Users\Ryan\imm-025.jpg
[2008/09/17 22:28:19 | 001,238,272 | ---- | C] () -- C:\Users\Ryan\imm-032.jpg
[2008/09/17 22:28:19 | 001,230,416 | ---- | C] () -- C:\Users\Ryan\imm-007.jpg
[2008/09/17 22:28:19 | 001,229,027 | ---- | C] () -- C:\Users\Ryan\imm-034.jpg
[2008/09/17 22:28:19 | 001,227,774 | ---- | C] () -- C:\Users\Ryan\imm-013.jpg
[2008/09/17 22:28:19 | 001,223,206 | ---- | C] () -- C:\Users\Ryan\imm-033.jpg
[2008/09/17 22:28:19 | 001,215,341 | ---- | C] () -- C:\Users\Ryan\imm-017.jpg
[2008/09/17 22:28:19 | 001,203,805 | ---- | C] () -- C:\Users\Ryan\imm-021.jpg
[2008/09/17 22:28:19 | 001,198,472 | ---- | C] () -- C:\Users\Ryan\imm-018.jpg
[2008/09/17 22:28:19 | 001,192,908 | ---- | C] () -- C:\Users\Ryan\imm-045.jpg
[2008/09/17 22:28:19 | 001,192,006 | ---- | C] () -- C:\Users\Ryan\imm-004.jpg
[2008/09/17 22:28:19 | 001,182,455 | ---- | C] () -- C:\Users\Ryan\imm-005.jpg
[2008/09/17 22:28:19 | 001,178,485 | ---- | C] () -- C:\Users\Ryan\imm-002.jpg
[2008/09/17 22:28:19 | 001,177,730 | ---- | C] () -- C:\Users\Ryan\imm-044.jpg
[2008/09/17 22:28:19 | 001,172,603 | ---- | C] () -- C:\Users\Ryan\imm-046.jpg
[2008/09/17 22:28:19 | 001,159,981 | ---- | C] () -- C:\Users\Ryan\imm-024.jpg
[2008/09/17 22:28:19 | 001,157,125 | ---- | C] () -- C:\Users\Ryan\imm-035.jpg
[2008/09/17 22:28:19 | 001,153,980 | ---- | C] () -- C:\Users\Ryan\imm-029.jpg
[2008/09/17 22:28:19 | 001,153,669 | ---- | C] () -- C:\Users\Ryan\imm-048.jpg
[2008/09/17 22:28:19 | 001,152,221 | ---- | C] () -- C:\Users\Ryan\imm-016.jpg
[2008/09/17 22:28:19 | 001,128,909 | ---- | C] () -- C:\Users\Ryan\imm-026.jpg
[2008/09/17 22:28:19 | 001,128,761 | ---- | C] () -- C:\Users\Ryan\imm-003.jpg
[2008/09/17 22:28:19 | 001,118,740 | ---- | C] () -- C:\Users\Ryan\imm-011.jpg
[2008/09/17 22:28:19 | 001,117,617 | ---- | C] () -- C:\Users\Ryan\imm-023.jpg
[2008/09/17 22:28:19 | 001,107,993 | ---- | C] () -- C:\Users\Ryan\imm-051.jpg
[2008/09/17 22:28:19 | 001,107,740 | ---- | C] () -- C:\Users\Ryan\imm-036.jpg
[2008/09/17 22:28:19 | 001,100,749 | ---- | C] () -- C:\Users\Ryan\imm-027.jpg
[2008/09/17 22:28:19 | 001,099,588 | ---- | C] () -- C:\Users\Ryan\imm-028.jpg
[2008/09/17 22:28:19 | 001,073,902 | ---- | C] () -- C:\Users\Ryan\imm-047.jpg
[2008/09/17 22:28:19 | 001,073,031 | ---- | C] () -- C:\Users\Ryan\imm-006.jpg
[2008/09/17 22:28:19 | 001,059,025 | ---- | C] () -- C:\Users\Ryan\imm-020.jpg
[2008/09/17 22:28:19 | 001,057,751 | ---- | C] () -- C:\Users\Ryan\imm-008.jpg
[2008/09/17 22:28:19 | 001,046,622 | ---- | C] () -- C:\Users\Ryan\imm-015.jpg
[2008/09/17 22:28:19 | 001,039,467 | ---- | C] () -- C:\Users\Ryan\imm-019.jpg
[2008/09/17 22:28:19 | 001,037,883 | ---- | C] () -- C:\Users\Ryan\imm-012.jpg
[2008/09/17 22:28:19 | 001,029,406 | ---- | C] () -- C:\Users\Ryan\imm-039.jpg
[2008/09/17 22:28:19 | 001,027,183 | ---- | C] () -- C:\Users\Ryan\imm-040.jpg
[2008/09/17 22:28:19 | 001,027,055 | ---- | C] () -- C:\Users\Ryan\imm-052.jpg
[2008/09/17 22:28:19 | 001,022,940 | ---- | C] () -- C:\Users\Ryan\imm-014.jpg
[2008/09/17 22:28:19 | 001,008,391 | ---- | C] () -- C:\Users\Ryan\imm-038.jpg
[2008/09/17 22:28:19 | 000,991,196 | ---- | C] () -- C:\Users\Ryan\imm-041.jpg
[2008/09/17 22:28:19 | 000,924,138 | ---- | C] () -- C:\Users\Ryan\imm-042.jpg
[2008/09/17 22:28:19 | 000,920,326 | ---- | C] () -- C:\Users\Ryan\imm-010.jpg
[2008/06/29 21:00:01 | 000,024,576 | ---- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/29 12:36:42 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.001
[2008/06/29 12:17:39 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.dat

========== ZeroAccess Check ==========

[2006/11/02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/03/07 21:37:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Audacity
[2013/04/02 16:31:03 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\avidemux
[2012/07/25 17:12:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/11/23 11:25:32 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\CoreFTP
[2011/10/29 18:11:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\DVDVideoSoft
[2012/10/18 16:30:04 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Freecorder 6 Video
[2010/10/27 22:41:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\GetRightToGo
[2013/04/08 17:49:24 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Greyfirst
[2011/10/26 17:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Leadertech
[2009/09/18 11:49:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Template
[2010/02/15 16:43:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

========== Base Services ==========
SRV - [2006/11/02 10:46:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2008/01/19 08:33:43 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2008/01/19 08:33:01 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2009/04/11 07:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2009/04/11 07:28:18 | 000,334,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/04/11 07:28:19 | 000,268,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2008/01/19 08:33:49 | 000,081,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2013/04/24 05:00:30 | 000,133,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2009/04/11 07:28:18 | 000,204,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcsvc.dll -- (Dhcp)
SRV - [2011/03/02 16:44:27 | 000,086,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2008/01/19 08:34:08 | 000,057,344 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/04/11 07:28:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2008/01/19 08:34:34 | 000,288,256 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2009/04/11 07:28:20 | 000,364,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/04/11 07:28:24 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2008/01/19 08:34:49 | 000,045,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2008/01/19 08:35:36 | 000,274,432 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2008/01/19 08:35:36 | 000,237,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2008/01/19 08:35:38 | 000,168,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2008/01/19 08:35:57 | 000,018,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2009/04/11 07:28:25 | 000,222,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2010/08/17 15:11:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
SRV - [2009/04/11 07:28:19 | 000,564,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\emdmgmt.dll -- (EMDMgmt)
SRV - [2008/01/19 08:36:15 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2009/04/11 07:28:24 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2009/04/11 07:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2008/01/19 08:36:20 | 000,019,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/16 15:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009/04/11 07:28:26 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/09/06 17:20:29 | 000,125,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/04/11 07:27:49 | 003,408,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SLsvc.exe -- (slsvc)
SRV - [2010/11/04 19:55:12 | 000,601,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2009/04/11 07:28:24 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/10 12:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (Themes)
SRV - [2009/04/11 07:28:23 | 000,153,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2009/04/11 07:28:10 | 001,055,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2009/04/11 07:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2008/01/19 08:36:20 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/04/11 07:28:25 | 001,017,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (Eventlog)
SRV - [2009/04/11 07:28:20 | 000,407,552 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2009/04/11 07:28:25 | 000,453,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (stisvc)
SRV - [2009/04/11 07:27:45 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/04/11 07:28:25 | 000,162,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/02 23:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2009/04/11 07:28:18 | 000,175,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2009/07/11 20:01:42 | 000,513,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2009/06/10 12:42:23 | 000,160,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 07:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 07:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/30 04:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2008/07/01 17:53:28 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2008/07/01 17:53:27 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/28 03:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 10:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/19 08:33:10 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: SERVICES >
[2006/09/18 22:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\System32\drivers\etc\services
[2006/09/18 22:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.CNF >
[2009/07/02 16:36:19 | 000,000,003 | ---- | M] () MD5=864E46AD77EBE7A312EB11241A5114B6 -- C:\Users\Ryan\Documents\My Web Sites\_vti_pvt\services.cnf

< MD5 for: SERVICES.DAT >
[2013/07/29 08:23:09 | 000,002,235 | ---- | M] () MD5=3F56F15AB110188F78E3DCE876FC707E -- C:\Users\Ryan\AppData\Local\Temp\jrt\services.dat

< MD5 for: SERVICES.EXE >
[2008/01/19 08:33:28 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 10:45:40 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/11 07:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\System32\services.exe
[2009/04/11 07:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 13:40:53 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 13:40:53 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.LNK >
[2008/07/07 14:45:34 | 000,001,688 | ---- | M] () MD5=BD64D178636C32068A36B4E05DF7D85E -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/07/07 14:45:34 | 000,001,688 | ---- | M] () MD5=BD64D178636C32068A36B4E05DF7D85E -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 22:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 13:41:29 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2006/11/02 13:41:29 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2006/09/18 22:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SVCHOST.EXE >
[2006/11/02 10:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/19 08:33:32 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/19 08:33:33 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 10:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 07:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 10:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/19 08:33:37 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 647E-22EE
Directory of C:\
02/11/2006 14:02 <JUNCTION> Documents and Settings [c:\Users]
0 File(s) 0 bytes
Directory of C:\Program Files\Windows Defender
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
1 File(s) 11,368 bytes
Directory of C:\ProgramData
02/11/2006 14:02 <JUNCTION> Application Data [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Desktop [c:\Users\Public\Desktop]
02/11/2006 14:02 <JUNCTION> Documents [c:\Users\Public\Documents]
02/11/2006 14:02 <JUNCTION> Favorites [c:\Users\Public\Favorites]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
02/11/2006 14:02 <SYMLINKD> All Users [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Default User [c:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
02/11/2006 14:02 <JUNCTION> Application Data [c:\ProgramData]
02/11/2006 14:02 <JUNCTION> Desktop [c:\Users\Public\Desktop]
02/11/2006 14:02 <JUNCTION> Documents [c:\Users\Public\Documents]
02/11/2006 14:02 <JUNCTION> Favorites [c:\Users\Public\Favorites]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\ProgramData\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
02/11/2006 14:02 <JUNCTION> Application Data [c:\Users\Default\AppData\Roaming]
02/11/2006 14:02 <JUNCTION> Cookies [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
02/11/2006 14:02 <JUNCTION> Local Settings [c:\Users\Default\AppData\Local]
02/11/2006 14:02 <JUNCTION> My Documents [c:\Users\Default\Documents]
02/11/2006 14:02 <JUNCTION> NetHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
02/11/2006 14:02 <JUNCTION> PrintHood [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
02/11/2006 14:02 <JUNCTION> Recent [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
02/11/2006 14:02 <JUNCTION> SendTo [c:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
02/11/2006 14:02 <JUNCTION> Start Menu [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
02/11/2006 14:02 <JUNCTION> Templates [c:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
02/11/2006 14:02 <JUNCTION> Application Data [c:\Users\Default\AppData\Local]
02/11/2006 14:02 <JUNCTION> History [c:\Users\Default\AppData\Local\Microsoft\Windows\History]
02/11/2006 14:02 <JUNCTION> Temporary Internet Files [c:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
02/11/2006 14:02 <JUNCTION> My Music [c:\Users\Default\Music]
02/11/2006 14:02 <JUNCTION> My Pictures [c:\Users\Default\Pictures]
02/11/2006 14:02 <JUNCTION> My Videos [c:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
02/11/2006 14:02 <JUNCTION> My Music [c:\Users\Public\Music]
02/11/2006 14:02 <JUNCTION> My Pictures [c:\Users\Public\Pictures]
02/11/2006 14:02 <JUNCTION> My Videos [c:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Ryan
26/06/2008 07:41 <JUNCTION> Application Data [C:\Users\Ryan\AppData\Roaming]
26/06/2008 07:41 <JUNCTION> Cookies [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Cookies]
26/06/2008 07:41 <JUNCTION> Local Settings [C:\Users\Ryan\AppData\Local]
26/06/2008 07:41 <JUNCTION> My Documents [C:\Users\Ryan\Documents]
26/06/2008 07:41 <JUNCTION> NetHood [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
26/06/2008 07:41 <JUNCTION> PrintHood [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
26/06/2008 07:41 <JUNCTION> Recent [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Recent]
26/06/2008 07:41 <JUNCTION> SendTo [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\SendTo]
26/06/2008 07:41 <JUNCTION> Start Menu [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Start Menu]
26/06/2008 07:41 <JUNCTION> Templates [C:\Users\Ryan\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Ryan\AppData\Local
26/06/2008 07:41 <JUNCTION> Application Data [C:\Users\Ryan\AppData\Local]
26/06/2008 07:41 <JUNCTION> History [C:\Users\Ryan\AppData\Local\Microsoft\Windows\History]
26/06/2008 07:41 <JUNCTION> Temporary Internet Files [C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Ryan\Documents
26/06/2008 07:41 <JUNCTION> My Music [C:\Users\Ryan\Music]
26/06/2008 07:41 <JUNCTION> My Pictures [C:\Users\Ryan\Pictures]
26/06/2008 07:41 <JUNCTION> My Videos [C:\Users\Ryan\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender-events_31bf3856ad364e35_6.0.6000.16386_none_b3613e39beae266f
02/11/2006 13:34 <SYMLINK> MpEvMsg.dll [...]
1 File(s) 65,640 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6000.16386_none_5585eece5b4407f1
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [...]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [...]
3 File(s) 681,784 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6001.18000_none_57bcb0ca582f18c5
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [...]
19/01/2008 08:38 <SYMLINK> MpClient.dll [...]
19/01/2008 08:38 <SYMLINK> MpCmdRun.exe [...]
19/01/2008 08:38 <SYMLINK> MpOAV.dll [...]
19/01/2008 08:38 <SYMLINK> MpRtMon.dll [...]
19/01/2008 08:38 <SYMLINK> MpRtPlug.dll [...]
19/01/2008 08:38 <SYMLINK> MpSigDwn.dll [...]
19/01/2008 08:38 <SYMLINK> MpSvc.dll [...]
19/01/2008 08:38 <SYMLINK> MSASCui.exe [...]
19/01/2008 08:38 <SYMLINK> MsMpCom.dll [...]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [...]
12 File(s) 3,765,552 bytes
Directory of C:\Windows\winsxs\x86_security-malware-windows-defender_31bf3856ad364e35_6.0.6002.18005_none_59a829d65550e411
02/11/2006 13:34 <SYMLINK> MpAsDesc.dll [...]
19/01/2008 08:38 <SYMLINK> MpClient.dll [...]
19/01/2008 08:38 <SYMLINK> MpCmdRun.exe [...]
19/01/2008 08:38 <SYMLINK> MpOAV.dll [...]
19/01/2008 08:38 <SYMLINK> MpRtMon.dll [...]
19/01/2008 08:38 <SYMLINK> MpRtPlug.dll [...]
19/01/2008 08:38 <SYMLINK> MpSigDwn.dll [...]
11/04/2009 07:27 <SYMLINK> MpSoftEx.dll [...]
19/01/2008 08:38 <SYMLINK> MpSvc.dll [...]
19/01/2008 08:38 <SYMLINK> MSASCui.exe [...]
19/01/2008 08:38 <SYMLINK> MsMpCom.dll [...]
02/11/2006 13:34 <SYMLINK> MsMpLics.dll [c:\windows\system32\config]
02/11/2006 13:34 <SYMLINK> MsMpRes.dll [...]
13 File(s) 4,278,552 bytes
Total Files Listed:
30 File(s) 8,802,896 bytes
50 Dir(s) 21,066,199,040 bytes free

< End of report >
  • 0

Advertisements


#11
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Darn I missed one, how is the computer behaving now ?

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image
:Commands
[CREATERESTOREPOINT]

:OTL
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-3003987317-153915931-1492068423-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.

:Files
fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpLics.dll" /c 

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

#12
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Ive been able to download a couple of files via my e-mail so its looking good. Here are the two logs from the scans

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3003987317-153915931-1492068423-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{21FA44EF-376D-4D53-9B0F-8A89D3229068} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21FA44EF-376D-4D53-9B0F-8A89D3229068}\ not found.
========== FILES ==========
< fsutil reparsepoint delete "C:\Program Files\Windows Defender\MsMpLics.dll" /c >
C:\Users\Ryan\Desktop\cmd.bat deleted successfully.
C:\Users\Ryan\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: Ryan
->Temp folder emptied: 1382668 bytes
->Temporary Internet Files folder emptied: 23507369 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 602 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 24.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 08062013_211905

Files\Folders moved on Reboot...
C:\Users\Ryan\AppData\Local\Temp\ehmsas.txt moved successfully.
C:\Users\Ryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\ED8654D5-B9F0-4DD9-B3E8-F8F560086FDF.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#13
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
OTL logfile created on: 06/08/2013 21:31:24 - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Ryan\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 0.85 Gb Available Physical Memory | 42.65% Memory free
4.23 Gb Paging File | 2.89 Gb Available in Paging File | 68.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 223.27 Gb Total Space | 17.93 Gb Free Space | 8.03% Space Free | Partition Type: NTFS
Drive D: | 9.61 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: NTFS

Computer Name: RYAN-PC | User Name: Ryan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
PRC - [2013/07/17 17:17:12 | 000,814,984 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_8_800_94_ActiveX.exe
PRC - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe
PRC - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/10/07 10:40:42 | 001,387,288 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPointP\SetPoint.exe
PRC - [2011/09/27 20:05:24 | 000,149,784 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
PRC - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE
PRC - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
PRC - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelLinkS.exe
PRC - [2010/11/19 09:52:04 | 000,153,496 | ---- | M] (Primax Electronics Ltd.) -- C:\ProgramData\HP Link5 Config\PelLink5.exe
PRC - [2010/11/19 09:51:14 | 000,335,768 | ---- | M] ( ) -- C:\ProgramData\HP Link5 Config\Link5HID.exe
PRC - [2010/11/19 09:50:42 | 000,101,784 | ---- | M] (Hewlett-Packard) -- C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe
PRC - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) -- C:\Windows\System32\drivers\CDAC11BA.EXE
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2007/07/25 08:02:42 | 000,174,616 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Modules (No Company Name) ==========

MOD - [2013/07/14 19:16:46 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\e3cc2cbffd5fb21da64e93d9b6c27c7c\System.ni.dll
MOD - [2013/07/14 19:16:37 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll
MOD - [2012/11/30 03:07:48 | 000,100,248 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012/11/30 03:06:58 | 001,263,512 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
MOD - [2012/05/30 15:51:08 | 000,699,280 | R--- | M] () -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\wincfi39.dll
MOD - [2011/10/07 10:41:16 | 000,879,896 | ---- | M] () -- C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/11/19 09:52:28 | 000,294,808 | ---- | M] () -- C:\ProgramData\HP Link5 Config\VolOSD.exe
MOD - [2010/11/04 11:17:14 | 000,047,104 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelDrv.dll
MOD - [2010/10/21 15:45:56 | 000,104,960 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelUtil.dll
MOD - [2010/10/12 10:02:04 | 000,079,360 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelComm.dll
MOD - [2010/09/17 11:48:08 | 000,028,672 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelMagnf.dll
MOD - [2010/06/21 14:57:02 | 000,459,264 | ---- | M] () -- C:\ProgramData\HP Link5 Config\PelHooks.dll
MOD - [2007/10/01 03:34:52 | 000,345,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLTinyDB.dll
MOD - [2007/10/01 03:34:42 | 000,255,384 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapEngine.dll
MOD - [2007/10/01 03:34:42 | 000,120,208 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLSchMgr.dll
MOD - [2007/10/01 03:34:42 | 000,038,184 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\TV\CLCapSvcps.dll
MOD - [2007/10/01 03:33:32 | 000,066,856 | ---- | M] () -- C:\Program Files\Hp\QuickPlay\Kernel\common\MCEMediaStatus.dll
MOD - [2007/06/25 11:55:12 | 000,030,024 | ---- | M] () -- C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe


========== Services (SafeList) ==========

SRV - [2013/07/17 17:17:13 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe -- (NIS)
SRV - [2011/09/27 20:03:28 | 000,295,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2011/02/28 19:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand | Stopped] -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/25 11:46:22 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE -- (SeaPort)
SRV - [2010/11/19 09:52:18 | 000,178,072 | ---- | M] () [Auto | Running] -- C:\ProgramData\HP Link5 Config\PelLinkS.exe -- (PelLinkS)
SRV - [2009/04/24 22:00:31 | 000,039,936 | ---- | M] (C-Dilla Ltd) [Auto | Running] -- C:\Windows\System32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/01/19 08:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/03/05 18:30:06 | 000,110,592 | ---- | M] (Hewlett-Packard Development Company, L.P.) [On_Demand | Stopped] -- C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe -- (Com4Qlb)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ryan\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2013/07/11 15:28:32 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\IPSDefs\20130804.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/07/10 01:00:00 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/07/10 01:00:00 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/07/10 01:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/07/10 01:00:00 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\VirusDefs\20130806.002\NAVENG.SYS -- (NAVENG)
DRV - [2013/05/23 06:25:28 | 000,934,488 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymEFA.sys -- (SymEFA)
DRV - [2013/05/21 06:02:00 | 000,367,704 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\SymDS.sys -- (SymDS)
DRV - [2013/05/21 05:41:34 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\Definitions\BASHDefs\20130715.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2013/05/16 06:02:14 | 000,603,224 | R--- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtsp.sys -- (SRTSP)
DRV - [2013/04/25 01:43:56 | 000,352,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\symtdiv.sys -- (SYMTDIv)
DRV - [2013/04/16 03:41:14 | 000,134,744 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\ccSetx86.sys -- (ccSet_NIS)
DRV - [2013/03/05 02:39:19 | 000,175,264 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\Ironx86.sys -- (SymIRON)
DRV - [2013/03/05 02:21:35 | 000,032,344 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\NIS\1404000.028\srtspx.sys -- (SRTSPX)
DRV - [2011/09/02 07:31:28 | 000,039,192 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2011/09/02 07:31:28 | 000,030,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2011/09/02 07:31:20 | 000,041,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2010/11/04 11:14:28 | 000,014,848 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPubA407.sys -- (HPubA407)
DRV - [2010/10/25 14:07:42 | 000,020,992 | ---- | M] (TPMX Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HPMoA407.sys -- (HPMoA407)
DRV - [2009/10/03 06:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/04/24 22:00:21 | 000,008,864 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2008/11/17 15:40:22 | 003,668,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETw5v32.sys -- (NETw5v32)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/10/18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/10/01 16:35:52 | 000,183,352 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CHDART.sys -- (HdAudAddService)
DRV - [2007/09/26 13:12:22 | 002,251,776 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw4v32.sys -- (NETw4v32)
DRV - [2007/08/09 04:42:08 | 000,045,568 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/07/30 19:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 18:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/07/11 18:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/24 09:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007/04/24 09:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007/04/24 09:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\s125bus.sys -- (s125bus)
DRV - [2007/04/18 13:03:26 | 000,141,312 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2007/01/09 09:22:28 | 000,006,144 | ---- | M] (Chic) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\moufiltr.sys -- (moufiltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
IE - HKCU\..\SearchScopes,bProtectorDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {755720C4-7AFD-4DE1-A29D-C57ABE040140}
IE - HKCU\..\SearchScopes\{0E38A417-0210-4A24-B84A-5255D8948A89}: "URL" = http://uk.search.yah...f-8&fr=chr-yie8
IE - HKCU\..\SearchScopes\{60584C85-3606-4C12-ABE4-705744FED08C}: "URL" = http://rover.ebay.co...e={searchTerms}
IE - HKCU\..\SearchScopes\{755720C4-7AFD-4DE1-A29D-C57ABE040140}: "URL" = http://www.google.co...Encoding?}&rlz=
IE - HKCU\..\SearchScopes\{8728F7AB-8FBB-4346-9CB4-3CDC9FE75BD7}: "URL" = http://uk.search.yah...p={searchTerms}
IE - HKCU\..\SearchScopes\{B05BCB51-AA42-4222-B174-526F938DEB6C}: "URL" = http://www.flickr.co...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=3.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2009/05/21 13:17:39 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\IPSFFPlgn\ [2013/07/11 14:01:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.4.0.40\coFFPlgn\ [2013/08/06 21:25:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/05/31 18:07:52 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/08/03 16:28:23 | 000,000,000 | ---D | M]

[2013/08/06 19:50:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions
[2012/10/19 02:34:29 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://www.searchnu.com/406
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - homepage: http://www.searchnu.com/406
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan\AppData\Local\Google\Chrome\Application\24.0.1312.57\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks™ Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer™ HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Download Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpplugin.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Ryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\

O1 HOSTS File: ([2013/08/06 21:19:41 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.dll (Symantec Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\20.4.0.40\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [EPSON Stylus DX4800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADE.EXE (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe File not found
O4 - HKLM..\Run: [HPMonitor] C:\Program Files\Hewlett-Packard\HP Link5 Monitor\hpMonitor21.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MediaBarFileManager] C:\Program Files\On Demand Distribution\OD2 Music Manager\OD2MediaBar_VistaFileManager.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [PelBrain] C:\ProgramData\HP Link5 Config\PelLink5.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\Yinsthelper.dll (Installation Support)
O16 - DPF: {3BB1D69B-A780-4BE1-876E-F3D488877135} http://download.micr...tualEarth3D.cab (SentinelProxy Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://download.divx...owserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{38D8A92F-D4C1-45EF-9A15-EB4E0821656C}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4575122C-3310-43AC-892F-1972B3B04756}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/09/11 16:18:54 | 000,000,340 | -HS- | M] () - D:\AUTOMODE -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/08/06 20:00:55 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/08/06 18:29:54 | 000,000,000 | ---D | C] -- C:\_OTL
[2013/08/06 16:40:00 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/03 01:23:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/07/20 12:24:38 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2013/07/11 13:57:43 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security
[2013/07/11 13:53:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/07/11 13:52:23 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2013/07/11 13:52:22 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2013/07/11 13:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2013/07/11 13:43:28 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime

========== Files - Modified Within 30 Days ==========

[2013/08/06 21:34:16 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/08/06 21:24:34 | 000,000,163 | ---- | M] () -- C:\Users\Public\Documents\hpqp.ini
[2013/08/06 21:23:46 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.001
[2013/08/06 21:23:26 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 21:23:25 | 000,003,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/06 21:23:20 | 000,000,878 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/08/06 21:23:05 | 000,241,294 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2013/08/06 21:23:02 | 000,401,568 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/08/06 21:22:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/08/06 21:22:13 | 2145,771,520 | -HS- | M] () -- C:\hiberfil.sys
[2013/08/06 21:20:43 | 000,002,140 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013/08/06 21:19:41 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2013/08/06 21:15:01 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/08/06 20:54:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000UA.job
[2013/08/06 16:42:14 | 000,613,784 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/08/06 16:42:14 | 000,111,062 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/08/06 16:26:32 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan\Desktop\OTL.exe
[2013/08/04 14:59:49 | 000,002,039 | ---- | M] () -- C:\Users\Ryan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/08/04 14:59:48 | 000,002,037 | ---- | M] () -- C:\Users\Ryan\Desktop\Google Chrome.lnk
[2013/08/03 01:23:08 | 000,002,073 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/08/01 11:54:54 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3003987317-153915931-1492068423-1000Core.job
[2013/07/14 19:11:34 | 002,543,771 | ---- | M] () -- C:\Windows\System32\drivers\NIS\1404000.028\Cat.DB
[2013/07/11 13:57:49 | 000,002,213 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2013/07/11 13:31:32 | 000,142,496 | ---- | M] (Symantec Corporation) -- C:\Windows\System32\drivers\SYMEVENT.SYS
[2013/07/11 13:31:32 | 000,007,611 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.CAT
[2013/07/11 13:31:32 | 000,000,805 | ---- | M] () -- C:\Windows\System32\drivers\SYMEVENT.INF

========== Files Created - No Company Name ==========

[2013/08/03 01:23:08 | 000,002,073 | ---- | C] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2013/07/11 13:53:09 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/01/05 13:53:40 | 000,001,940 | ---- | C] () -- C:\Users\Ryan\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/03/29 13:20:17 | 000,005,184 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2010/02/10 16:32:43 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.001
[2010/02/10 16:32:21 | 000,241,294 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/09/18 11:49:34 | 000,000,082 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2009/08/21 10:51:57 | 000,058,772 | ---- | C] () -- C:\Users\Ryan\HISTORY.WK3
[2009/08/21 10:51:57 | 000,039,178 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.WK3
[2009/08/21 10:51:57 | 000,024,001 | ---- | C] () -- C:\Users\Ryan\HISTORY.FM3
[2009/08/21 10:51:57 | 000,014,435 | ---- | C] () -- C:\Users\Ryan\DEV_PLAN.FM3
[2009/08/21 10:51:57 | 000,007,262 | ---- | C] () -- C:\Users\Ryan\COVMAP.FM3
[2009/08/21 10:51:57 | 000,006,930 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.FM3
[2009/08/21 10:51:57 | 000,004,173 | ---- | C] () -- C:\Users\Ryan\CLUBTEAM.WK3
[2009/08/21 10:51:57 | 000,002,425 | ---- | C] () -- C:\Users\Ryan\COVMAP.WK3
[2008/10/07 14:17:41 | 000,007,808 | ---- | C] () -- C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2008/09/17 22:28:20 | 001,323,093 | ---- | C] () -- C:\Users\Ryan\imm-077.jpg
[2008/09/17 22:28:20 | 001,288,835 | ---- | C] () -- C:\Users\Ryan\imm-078.jpg
[2008/09/17 22:28:20 | 001,279,222 | ---- | C] () -- C:\Users\Ryan\imm-053.jpg
[2008/09/17 22:28:20 | 001,273,747 | ---- | C] () -- C:\Users\Ryan\imm-059.jpg
[2008/09/17 22:28:20 | 001,204,402 | ---- | C] () -- C:\Users\Ryan\imm-075.jpg
[2008/09/17 22:28:20 | 001,194,039 | ---- | C] () -- C:\Users\Ryan\imm-060.jpg
[2008/09/17 22:28:20 | 001,171,748 | ---- | C] () -- C:\Users\Ryan\imm-094.jpg
[2008/09/17 22:28:20 | 001,169,184 | ---- | C] () -- C:\Users\Ryan\imm-070.jpg
[2008/09/17 22:28:20 | 001,167,660 | ---- | C] () -- C:\Users\Ryan\imm-099.jpg
[2008/09/17 22:28:20 | 001,166,353 | ---- | C] () -- C:\Users\Ryan\imm-071.jpg
[2008/09/17 22:28:20 | 001,158,289 | ---- | C] () -- C:\Users\Ryan\imm-055.jpg
[2008/09/17 22:28:20 | 001,154,139 | ---- | C] () -- C:\Users\Ryan\imm-056.jpg
[2008/09/17 22:28:20 | 001,143,112 | ---- | C] () -- C:\Users\Ryan\imm-080.jpg
[2008/09/17 22:28:20 | 001,135,379 | ---- | C] () -- C:\Users\Ryan\imm-063.jpg
[2008/09/17 22:28:20 | 001,118,906 | ---- | C] () -- C:\Users\Ryan\imm-098.jpg
[2008/09/17 22:28:20 | 001,112,388 | ---- | C] () -- C:\Users\Ryan\imm-072.jpg
[2008/09/17 22:28:20 | 001,103,321 | ---- | C] () -- C:\Users\Ryan\imm-100.jpg
[2008/09/17 22:28:20 | 001,102,895 | ---- | C] () -- C:\Users\Ryan\imm-079.jpg
[2008/09/17 22:28:20 | 001,093,115 | ---- | C] () -- C:\Users\Ryan\imm-081.jpg
[2008/09/17 22:28:20 | 001,090,605 | ---- | C] () -- C:\Users\Ryan\imm-073.jpg
[2008/09/17 22:28:20 | 001,084,980 | ---- | C] () -- C:\Users\Ryan\imm-076.jpg
[2008/09/17 22:28:20 | 001,084,712 | ---- | C] () -- C:\Users\Ryan\imm-091.jpg
[2008/09/17 22:28:20 | 001,083,644 | ---- | C] () -- C:\Users\Ryan\imm-085.jpg
[2008/09/17 22:28:20 | 001,082,950 | ---- | C] () -- C:\Users\Ryan\imm-058.jpg
[2008/09/17 22:28:20 | 001,079,103 | ---- | C] () -- C:\Users\Ryan\imm-054.jpg
[2008/09/17 22:28:20 | 001,066,356 | ---- | C] () -- C:\Users\Ryan\imm-062.jpg
[2008/09/17 22:28:20 | 001,043,880 | ---- | C] () -- C:\Users\Ryan\imm-057.jpg
[2008/09/17 22:28:20 | 001,038,598 | ---- | C] () -- C:\Users\Ryan\imm-061.jpg
[2008/09/17 22:28:20 | 001,036,315 | ---- | C] () -- C:\Users\Ryan\imm-074.jpg
[2008/09/17 22:28:20 | 001,018,160 | ---- | C] () -- C:\Users\Ryan\imm-084.jpg
[2008/09/17 22:28:20 | 001,017,943 | ---- | C] () -- C:\Users\Ryan\imm-065.jpg
[2008/09/17 22:28:20 | 001,006,591 | ---- | C] () -- C:\Users\Ryan\imm-088.jpg
[2008/09/17 22:28:20 | 000,997,553 | ---- | C] () -- C:\Users\Ryan\imm-083.jpg
[2008/09/17 22:28:20 | 000,996,794 | ---- | C] () -- C:\Users\Ryan\imm-082.jpg
[2008/09/17 22:28:20 | 000,990,053 | ---- | C] () -- C:\Users\Ryan\imm-086.jpg
[2008/09/17 22:28:20 | 000,974,827 | ---- | C] () -- C:\Users\Ryan\imm-090.jpg
[2008/09/17 22:28:20 | 000,974,231 | ---- | C] () -- C:\Users\Ryan\imm-095.jpg
[2008/09/17 22:28:20 | 000,971,338 | ---- | C] () -- C:\Users\Ryan\imm-096.jpg
[2008/09/17 22:28:20 | 000,960,482 | ---- | C] () -- C:\Users\Ryan\imm-087.jpg
[2008/09/17 22:28:20 | 000,928,194 | ---- | C] () -- C:\Users\Ryan\imm-093.jpg
[2008/09/17 22:28:20 | 000,915,889 | ---- | C] () -- C:\Users\Ryan\imm-092.jpg
[2008/09/17 22:28:20 | 000,897,569 | ---- | C] () -- C:\Users\Ryan\imm-067.jpg
[2008/09/17 22:28:20 | 000,895,767 | ---- | C] () -- C:\Users\Ryan\imm-064.jpg
[2008/09/17 22:28:20 | 000,883,008 | ---- | C] () -- C:\Users\Ryan\imm-066.jpg
[2008/09/17 22:28:20 | 000,875,773 | ---- | C] () -- C:\Users\Ryan\imm-097.jpg
[2008/09/17 22:28:20 | 000,861,143 | ---- | C] () -- C:\Users\Ryan\imm-089.jpg
[2008/09/17 22:28:20 | 000,814,830 | ---- | C] () -- C:\Users\Ryan\imm-069.jpg
[2008/09/17 22:28:20 | 000,710,128 | ---- | C] () -- C:\Users\Ryan\imm-068.jpg
[2008/09/17 22:28:19 | 001,483,088 | ---- | C] () -- C:\Users\Ryan\imm-031.jpg
[2008/09/17 22:28:19 | 001,358,383 | ---- | C] () -- C:\Users\Ryan\imm-043.jpg
[2008/09/17 22:28:19 | 001,355,074 | ---- | C] () -- C:\Users\Ryan\imm-001.jpg
[2008/09/17 22:28:19 | 001,310,940 | ---- | C] () -- C:\Users\Ryan\imm-030.jpg
[2008/09/17 22:28:19 | 001,281,914 | ---- | C] () -- C:\Users\Ryan\imm-050.jpg
[2008/09/17 22:28:19 | 001,272,139 | ---- | C] () -- C:\Users\Ryan\imm-022.jpg
[2008/09/17 22:28:19 | 001,272,091 | ---- | C] () -- C:\Users\Ryan\imm-009.jpg
[2008/09/17 22:28:19 | 001,270,420 | ---- | C] () -- C:\Users\Ryan\imm-049.jpg
[2008/09/17 22:28:19 | 001,261,265 | ---- | C] () -- C:\Users\Ryan\imm-037.jpg
[2008/09/17 22:28:19 | 001,261,141 | ---- | C] () -- C:\Users\Ryan\imm-025.jpg
[2008/09/17 22:28:19 | 001,238,272 | ---- | C] () -- C:\Users\Ryan\imm-032.jpg
[2008/09/17 22:28:19 | 001,230,416 | ---- | C] () -- C:\Users\Ryan\imm-007.jpg
[2008/09/17 22:28:19 | 001,229,027 | ---- | C] () -- C:\Users\Ryan\imm-034.jpg
[2008/09/17 22:28:19 | 001,227,774 | ---- | C] () -- C:\Users\Ryan\imm-013.jpg
[2008/09/17 22:28:19 | 001,223,206 | ---- | C] () -- C:\Users\Ryan\imm-033.jpg
[2008/09/17 22:28:19 | 001,215,341 | ---- | C] () -- C:\Users\Ryan\imm-017.jpg
[2008/09/17 22:28:19 | 001,203,805 | ---- | C] () -- C:\Users\Ryan\imm-021.jpg
[2008/09/17 22:28:19 | 001,198,472 | ---- | C] () -- C:\Users\Ryan\imm-018.jpg
[2008/09/17 22:28:19 | 001,192,908 | ---- | C] () -- C:\Users\Ryan\imm-045.jpg
[2008/09/17 22:28:19 | 001,192,006 | ---- | C] () -- C:\Users\Ryan\imm-004.jpg
[2008/09/17 22:28:19 | 001,182,455 | ---- | C] () -- C:\Users\Ryan\imm-005.jpg
[2008/09/17 22:28:19 | 001,178,485 | ---- | C] () -- C:\Users\Ryan\imm-002.jpg
[2008/09/17 22:28:19 | 001,177,730 | ---- | C] () -- C:\Users\Ryan\imm-044.jpg
[2008/09/17 22:28:19 | 001,172,603 | ---- | C] () -- C:\Users\Ryan\imm-046.jpg
[2008/09/17 22:28:19 | 001,159,981 | ---- | C] () -- C:\Users\Ryan\imm-024.jpg
[2008/09/17 22:28:19 | 001,157,125 | ---- | C] () -- C:\Users\Ryan\imm-035.jpg
[2008/09/17 22:28:19 | 001,153,980 | ---- | C] () -- C:\Users\Ryan\imm-029.jpg
[2008/09/17 22:28:19 | 001,153,669 | ---- | C] () -- C:\Users\Ryan\imm-048.jpg
[2008/09/17 22:28:19 | 001,152,221 | ---- | C] () -- C:\Users\Ryan\imm-016.jpg
[2008/09/17 22:28:19 | 001,128,909 | ---- | C] () -- C:\Users\Ryan\imm-026.jpg
[2008/09/17 22:28:19 | 001,128,761 | ---- | C] () -- C:\Users\Ryan\imm-003.jpg
[2008/09/17 22:28:19 | 001,118,740 | ---- | C] () -- C:\Users\Ryan\imm-011.jpg
[2008/09/17 22:28:19 | 001,117,617 | ---- | C] () -- C:\Users\Ryan\imm-023.jpg
[2008/09/17 22:28:19 | 001,107,993 | ---- | C] () -- C:\Users\Ryan\imm-051.jpg
[2008/09/17 22:28:19 | 001,107,740 | ---- | C] () -- C:\Users\Ryan\imm-036.jpg
[2008/09/17 22:28:19 | 001,100,749 | ---- | C] () -- C:\Users\Ryan\imm-027.jpg
[2008/09/17 22:28:19 | 001,099,588 | ---- | C] () -- C:\Users\Ryan\imm-028.jpg
[2008/09/17 22:28:19 | 001,073,902 | ---- | C] () -- C:\Users\Ryan\imm-047.jpg
[2008/09/17 22:28:19 | 001,073,031 | ---- | C] () -- C:\Users\Ryan\imm-006.jpg
[2008/09/17 22:28:19 | 001,059,025 | ---- | C] () -- C:\Users\Ryan\imm-020.jpg
[2008/09/17 22:28:19 | 001,057,751 | ---- | C] () -- C:\Users\Ryan\imm-008.jpg
[2008/09/17 22:28:19 | 001,046,622 | ---- | C] () -- C:\Users\Ryan\imm-015.jpg
[2008/09/17 22:28:19 | 001,039,467 | ---- | C] () -- C:\Users\Ryan\imm-019.jpg
[2008/09/17 22:28:19 | 001,037,883 | ---- | C] () -- C:\Users\Ryan\imm-012.jpg
[2008/09/17 22:28:19 | 001,029,406 | ---- | C] () -- C:\Users\Ryan\imm-039.jpg
[2008/09/17 22:28:19 | 001,027,183 | ---- | C] () -- C:\Users\Ryan\imm-040.jpg
[2008/09/17 22:28:19 | 001,027,055 | ---- | C] () -- C:\Users\Ryan\imm-052.jpg
[2008/09/17 22:28:19 | 001,022,940 | ---- | C] () -- C:\Users\Ryan\imm-014.jpg
[2008/09/17 22:28:19 | 001,008,391 | ---- | C] () -- C:\Users\Ryan\imm-038.jpg
[2008/09/17 22:28:19 | 000,991,196 | ---- | C] () -- C:\Users\Ryan\imm-041.jpg
[2008/09/17 22:28:19 | 000,924,138 | ---- | C] () -- C:\Users\Ryan\imm-042.jpg
[2008/09/17 22:28:19 | 000,920,326 | ---- | C] () -- C:\Users\Ryan\imm-010.jpg
[2008/06/29 21:00:01 | 000,024,576 | ---- | C] () -- C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/29 12:36:42 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.001
[2008/06/29 12:17:39 | 000,027,240 | ---- | C] () -- C:\Users\Ryan\AppData\Roaming\nvModes.dat

========== ZeroAccess Check ==========

[2006/11/02 13:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2013/03/07 21:37:15 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Audacity
[2013/04/02 16:31:03 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\avidemux
[2012/07/25 17:12:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2009/11/23 11:25:32 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\CoreFTP
[2011/10/29 18:11:19 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\DVDVideoSoft
[2012/10/18 16:30:04 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Freecorder 6 Video
[2010/10/27 22:41:39 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\GetRightToGo
[2013/04/08 17:49:24 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Greyfirst
[2011/10/26 17:13:25 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Leadertech
[2009/09/18 11:49:34 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Template
[2010/02/15 16:43:49 | 000,000,000 | ---D | M] -- C:\Users\Ryan\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



< End of report >
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
A quick check for any orphans now I feel, how is the computer behaving ?

Please download Malwarebytes Anti-Malware to your desktop.

  • Right-click and Run as Administrator mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    Posted Image
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.


The log can also be found here:

Windows 2000 & Windows XP:
C:\Documents and Settings\<USERNAME>\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs

Windows Vista & Win7:
C:\Users\<USERNAME>\AppData\Roaming\Malwarebytes\Malwarebytes' Anti-Malware\Logs
----------
  • 0

#15
covphoenix

covphoenix

    Member

  • Topic Starter
  • Member
  • PipPip
  • 78 posts
Hi, the computer seems to be running ok. Here is the log

Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Database version: v2013.08.07.03

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Ryan :: RYAN-PC [administrator]

07/08/2013 10:45:59
mbam-log-2013-08-07 (10-45-59).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 218776
Time elapsed: 10 minute(s), 12 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 3
HKCR\CLSID\{99079a25-328f-4bd4-be04-00955acaa0a7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7} (PUP.Optional.SearchQu) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP