here is the OTL log
OTL logfile created on: 30/04/2014 20:13:09 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\lesley\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
2.75 Gb Total Physical Memory | 1.16 Gb Available Physical Memory | 42.30% Memory free
5.73 Gb Paging File | 3.94 Gb Available in Paging File | 68.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.98 Gb Total Space | 82.29 Gb Free Space | 59.21% Space Free | Partition Type: NTFS
Drive D: | 10.07 Gb Total Space | 1.75 Gb Free Space | 17.37% Space Free | Partition Type: NTFS
Computer Name: LESLEY-PC | User Name: lesley | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/04/30 20:10:36 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\lesley\Downloads\OTL.exe
PRC - [2014/04/02 02:58:05 | 000,841,032 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Chrome\Application\chrome.exe
PRC - [2014/03/24 12:18:08 | 000,118,264 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe
PRC - [2014/03/24 12:12:26 | 000,740,896 | ---- | M] (McAfee, Inc.) -- c:\Program Files\McAfee\SiteAdvisor\saUI.exe
PRC - [2014/03/19 17:24:00 | 000,383,504 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\SiteAdvisor\McChHost.exe
PRC - [2013/09/08 23:55:33 | 006,827,008 | ---- | M] (Bandoo Media Inc.) -- C:\Users\lesley\AppData\Local\iLivid\iLivid.exe
PRC - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360\Engine\20.4.0.40\ccsvchst.exe
PRC - [2013/05/10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/10/26 07:49:04 | 000,202,752 | ---- | M] () -- C:\Users\lesley\AppData\Local\WebPlayer\Free Mahjong Games\WebPlayer.exe
PRC - [2009/07/16 14:43:04 | 000,241,664 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\AssistantServices.exe
PRC - [2009/07/16 14:42:20 | 000,132,608 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe
PRC - [2009/04/11 07:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/06 17:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files\SMINST\BLService.exe
PRC - [2008/06/13 15:26:54 | 002,498,560 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
PRC - [2008/01/21 03:33:22 | 000,318,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
========== Modules (No Company Name) ==========
MOD - [2014/04/15 20:37:31 | 004,110,808 | ---- | M] () -- c:\Program Files\Optimizer Pro\OptProCrash.dll
MOD - [2014/04/02 02:58:03 | 000,390,472 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppgooglenaclpluginchrome.dll
MOD - [2014/04/02 02:58:02 | 013,691,720 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll
MOD - [2014/04/02 02:57:59 | 004,081,480 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll
MOD - [2014/04/02 02:57:52 | 001,647,432 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll
MOD - [2014/04/02 02:57:49 | 000,065,352 | ---- | M] () -- C:\Program Files\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll
MOD - [2014/02/13 11:58:27 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\c5213af29d521ee19cc55983f8c2037c\System.Management.ni.dll
MOD - [2014/02/13 11:56:53 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e3ab5ab0fbb86c36425e6902e54a547b\System.Runtime.Remoting.ni.dll
MOD - [2014/02/13 11:56:51 | 000,627,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\cbadc7af4484ceeb8092c5f2b1240f0b\System.EnterpriseServices.ni.dll
MOD - [2014/02/13 11:56:51 | 000,280,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\cbadc7af4484ceeb8092c5f2b1240f0b\System.EnterpriseServices.Wrapper.dll
MOD - [2014/02/13 11:56:50 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\24c666e940e61baf4d33315346a03ab6\System.Transactions.ni.dll
MOD - [2014/02/13 11:56:24 | 001,801,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\3cf321fb70231d473d99105a582c23e1\System.Deployment.ni.dll
MOD - [2014/02/13 11:56:17 | 000,978,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\d17ceca243fabda73eefb21d9bd072df\System.Configuration.ni.dll
MOD - [2014/02/13 10:13:46 | 005,462,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f87e71868aedbc6c4e8fe7160d17c4ab\System.Xml.ni.dll
MOD - [2014/02/13 10:13:27 | 012,434,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d2b605fc7deda872727d1ed37710420e\System.Windows.Forms.ni.dll
MOD - [2014/02/13 10:13:15 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\8e6265a54260bddfc05951e764f5bc48\System.Drawing.ni.dll
MOD - [2014/02/13 10:12:43 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\5ee93fdf928109a9dc70ad2c96bb0a92\System.Data.ni.dll
MOD - [2014/02/13 10:12:25 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\71e362b114f878201540696b6d66bf45\PresentationFramework.Aero.ni.dll
MOD - [2014/02/13 10:12:22 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\b46f1c203d1e4bec4597adf684ec1d41\PresentationFramework.ni.dll
MOD - [2014/02/13 10:11:58 | 012,218,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\07d57714fff9db216537473f4a777f22\PresentationCore.ni.dll
MOD - [2014/02/13 10:11:40 | 003,325,440 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d981bccab40fbbdc1d35bf2a58c947b7\WindowsBase.ni.dll
MOD - [2014/02/13 10:11:36 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\957628d9dd7b3bf370a56dca7835a997\System.ni.dll
MOD - [2014/02/13 10:11:24 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\694a37a84dee2cd2609a1dfab27c0433\mscorlib.ni.dll
MOD - [2012/10/26 07:49:04 | 000,202,752 | ---- | M] () -- C:\Users\lesley\AppData\Local\WebPlayer\Free Mahjong Games\WebPlayer.exe
MOD - [2012/05/30 07:51:08 | 000,699,280 | R--- | M] () -- C:\Program Files\Norton 360\Engine\20.4.0.40\wincfi39.dll
MOD - [2012/05/25 04:25:00 | 000,921,600 | ---- | M] () -- C:\Program Files\Yahoo!\Messenger\yui.dll
MOD - [2011/09/27 08:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 08:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/07/16 14:42:20 | 000,132,608 | ---- | M] () -- C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe
MOD - [2009/04/11 07:28:21 | 000,368,640 | ---- | M] () -- C:\Windows\System32\msjetoledb40.dll
MOD - [2009/04/11 03:04:15 | 000,113,664 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
MOD - [2009/03/30 05:42:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/30 05:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2008/10/01 00:56:06 | 000,032,768 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Content.XmlSerializers.dll
MOD - [2008/10/01 00:52:02 | 000,007,168 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll
MOD - [2008/10/01 00:52:00 | 000,057,344 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
MOD - [2008/10/01 00:51:52 | 000,118,784 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\ECLibrary.dll
MOD - [2008/10/01 00:51:52 | 000,010,240 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll
MOD - [2008/10/01 00:51:36 | 000,040,960 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll
MOD - [2008/10/01 00:51:36 | 000,028,672 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll
MOD - [2008/10/01 00:51:36 | 000,005,632 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll
MOD - [2008/06/13 15:26:54 | 002,498,560 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
MOD - [2007/08/14 21:59:54 | 006,365,184 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtGui4.dll
MOD - [2007/07/12 21:55:52 | 000,131,072 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\plugins\imageformats\qjpeg4.dll
MOD - [2007/07/12 21:55:28 | 001,581,056 | ---- | M] () -- C:\Program Files\Common Files\LightScribe\QtCore4.dll
========== Services (SafeList) ==========
SRV - [2014/04/28 21:04:21 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/03/24 12:18:08 | 000,118,264 | ---- | M] (McAfee, Inc.) [Auto | Running] -- c:\Program Files\McAfee\SiteAdvisor\McSACore.exe -- (McAfee SiteAdvisor Service)
SRV - [2013/05/21 05:44:22 | 000,144,368 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360\Engine\20.4.0.40\ccSvcHst.exe -- (N360)
SRV - [2013/05/10 08:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/07/20 18:21:59 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/07/16 14:43:04 | 000,241,664 | ---- | M] () [Auto | Running] -- C:\Program Files\T-Mobile Mobile Broadband Manager\AssistantServices.exe -- (UI Assistant Service)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/06 17:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/02/03 20:00:00 | 000,129,992 | ---- | M] (EasyBits Sofware AS) [Auto | Running] -- C:\Windows\System32\ezsvc7.dll -- (ezSharedSvc)
SRV - [2008/01/21 03:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2014/04/16 19:59:08 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2013/06/19 18:53:05 | 000,142,496 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2013/05/31 17:58:19 | 001,002,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\BASHDefs\20130715.001\BHDrvx86.sys -- (BHDrvx86)
DRV - [2013/05/23 06:25:28 | 000,934,488 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symefa.sys -- (SymEFA)
DRV - [2013/05/22 17:40:20 | 001,611,992 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130810.005\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/05/22 17:40:18 | 000,093,272 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\VirusDefs\20130810.005\NAVENG.SYS -- (NAVENG)
DRV - [2013/05/21 06:02:00 | 000,367,704 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symds.sys -- (SymDS)
DRV - [2013/05/18 12:15:59 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2013/05/17 15:30:54 | 000,386,720 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\Definitions\IPSDefs\20130809.001\IDSvix86.sys -- (IDSVix86)
DRV - [2013/05/16 06:02:14 | 000,603,224 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\N360\1404000.028\srtsp.sys -- (SRTSP)
DRV - [2013/04/25 01:43:56 | 000,352,344 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\symtdiv.sys -- (SYMTDIv)
DRV - [2013/04/16 03:41:14 | 000,134,744 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\ccsetx86.sys -- (ccSet_N360)
DRV - [2013/03/05 02:39:19 | 000,175,264 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\ironx86.sys -- (SymIRON)
DRV - [2013/03/05 02:21:35 | 000,032,344 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\N360\1404000.028\srtspx.sys -- (SRTSPX)
DRV - [2013/01/31 02:00:00 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/08/02 18:38:44 | 000,018,432 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netaapl.sys -- (Netaapl)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2009/09/05 17:55:36 | 001,183,744 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2009/07/24 16:51:38 | 000,101,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/07/23 21:01:00 | 009,791,072 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/07/14 00:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WINUSB)
DRV - [2009/06/22 21:01:02 | 000,112,128 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009/06/22 20:38:24 | 000,102,912 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/05/22 09:08:38 | 000,022,528 | ---- | M] (Bytemobile, Inc.) [Kernel | Boot | Unknown] -- C:\Windows\System32\drivers\BMLoad.sys -- (BMLoad)
DRV - [2009/05/22 09:08:38 | 000,018,816 | ---- | M] (Bytemobile, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\tcpipBM.sys -- (tcpipBM)
DRV - [2009/05/22 09:04:04 | 000,105,344 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV - [2009/05/22 09:04:04 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV - [2009/05/22 09:04:04 | 000,104,960 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV - [2009/05/22 09:04:04 | 000,009,728 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\massfilter.sys -- (massfilter)
DRV - [2008/10/03 04:39:28 | 000,222,208 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008/05/09 20:17:32 | 000,043,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/04/24 23:51:46 | 000,014,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/01/21 03:32:45 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2007/10/18 00:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/06/19 01:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/23 10:50:50 | 000,025,896 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | System | Running] -- C:\Windows\System32\drivers\RtlProt.sys -- (RtlProt)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?ilc=8
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...q={searchTerms}
IE - HKU\.DEFAULT\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache =
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\SearchScopes,DefaultScope = {1BF6ED5B-95B9-40F2-AF93-DE307057F6A6}
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...q={searchTerms}
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\SearchScopes\{1BF6ED5B-95B9-40F2-AF93-DE307057F6A6}: "URL" = http://uk.search.yah...p={SearchTerms}
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" =
IE - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "AutoConfigURL" = file://C:/Users/lesley/AppData/Local/LPT/NewConfig.txt
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: ""
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....ch?fr=ffsp1&p="
FF - prefs.js..browser.search.order.1: ""
FF - prefs.js..extensions.enabledItems: {a763bd81-dd2b-6e49-34ce-c0d80e0a42f3}:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..extensions.enabledItems: [email protected]:4.1.0
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems:
FF - prefs.js..browser.startup.homepage: "http://feed.snapdo.c...gC3tWis13PFaQ,"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..keyword.URL: "http://feed.snapdo.c...ype=A110GB0&p="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_206.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\lesley\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\T-Mobile Mobile Broadband Manager\addon [2010/06/12 15:06:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2014/03/28 20:24:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\coFFPlgn\ [2014/04/30 20:07:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.3.0.36\IPSFFPlgn\ [2013/05/18 16:00:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/05 20:56:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/06/23 17:06:51 | 000,000,000 | ---D | M]
[2009/06/27 13:34:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lesley\AppData\Roaming\Mozilla\Extensions
[2014/04/15 20:34:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions
[2009/09/02 22:19:11 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/03 14:53:15 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2014/04/15 20:34:40 | 000,000,000 | ---D | M] ("Snap.Do ") -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\{a763bd81-dd2b-6e49-34ce-c0d80e0a42f3}
[2014/04/15 20:34:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\extensions\staged
[2014/04/15 20:34:45 | 000,002,377 | ---- | M] () -- C:\Users\lesley\AppData\Roaming\Mozilla\Firefox\Profiles\l0q5u8vk.default\searchplugins\Web Search.xml
[2012/06/26 00:05:37 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/26 00:05:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2010/06/12 15:06:02 | 000,000,000 | ---D | M] (Bytemobile Optimization Client) -- C:\PROGRAM FILES\T-MOBILE MOBILE BROADBAND MANAGER\ADDON
File not found (No name found) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\COFFPLGN
File not found (No name found) -- C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.0.0.136\IPSFFPLGN
File not found (No name found) -- C:\USERS\LESLEY\APPDATA\LOCAL\{337D5158-7284-4835-B7AF-CE4F08F7D7C2}
[2014/04/29 23:29:32 | 000,002,065 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\McSiteAdvisor.xml
========== Chrome ==========
CHR - default_search_provider: McAfee (Enabled)
CHR - default_search_provider: search_url = http://uk.search.yah...p={searchTerms}
CHR - default_search_provider: suggest_url = ,
CHR - homepage: http://feed.snapdo.c...rggC3tWis13PFaQ,
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\34.0.1847.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Java Platform SE 7 U5 (Disabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live™ Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - plugin: Java Deployment Toolkit 7.0.170.2 (Disabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: SiteAdvisor = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.65.135.1_0\
CHR - Extension: Norton Identity Protection = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0\
CHR - Extension: Smiley Bar for Facebook = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocblcnaofikinigmceddfghppkkjbog\1.0.0.0_0\
CHR - Extension: Google Wallet = C:\Users\lesley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
O1 HOSTS File: ([2013/06/22 00:11:44 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\20.4.0.40\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - No CLSID value found.
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\20.4.0.40\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..\Toolbar\WebBrowser: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [UIExec] C:\Program Files\T-Mobile Mobile Broadband Manager\UIExec.exe ()
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000..\Run: [FileHippo.com] C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000..\Run: [Free Mahjong Games] C:\Users\lesley\AppData\Local\WebPlayer\Free Mahjong Games\WebPlayer.exe ()
O4 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000..\Run: [iLivid] C:\Users\lesley\AppData\Local\iLivid\iLivid.exe (Bandoo Media Inc.)
O4 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Software Limited)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html ()
O9 - Extra Button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.3.7.16.dll/206 File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-4095824921-2520398854-2341837645-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D9F1A67-0D74-4F73-8382-A961723E133C}: DhcpNameServer = 172.20.10.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F2B3000-315B-4E23-A67B-FBFDEE106A0D}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE65EEA7-EC85-45B6-A237-D1A115EDD8C8}: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - AppInit_DLLs: (c:\progra~2\wincert\win32c~1.dll) - File not found
O20 - AppInit_DLLs: (c:\progra~1\optimi~1\optpro~2.dll) - c:\Program Files\Optimizer Pro\OptProCrash.dll ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O27 - HKLM IFEO\bitguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bpsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsemngr.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserdefender.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsermngr.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browserprotect.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\browsersafeguard.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\bundlesweetimsetup.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\cltmngsvc.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta babylon.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta tb.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\delta2.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltainstaller.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltasetup.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltatb.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\deltatb_2501-c733154b.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\iminentsetup.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\protectedsearch.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\rjatydimofu.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\searchprotection.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst32.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\stinst64.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\sweetimsetup.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O27 - HKLM IFEO\tbdelta.exetoolbar783881609.exe: Debugger - C:\Windows\System32\tasklist.exe (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\System32\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: x64 - (c:\program files\movies toolbar\datamngr\x64\apcrtldr.dll) - File not found
O36 - AppCertDlls: x86 - (C:\Program Files\Movies Toolbar\Datamngr\apcrtldr.dll) - File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/04/15 20:42:51 | 000,000,000 | ---D | C] -- C:\Users\lesley\Documents\Optimizer Pro
[2014/04/15 20:42:50 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Roaming\Optimizer Pro
[2014/04/15 20:38:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveSupport
[2014/04/15 20:38:48 | 000,000,000 | ---D | C] -- C:\Program Files\LiveSupport
[2014/04/15 20:37:39 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Mahjong Games
[2014/04/15 20:37:31 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Local\WebPlayer
[2014/04/15 20:37:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro v3.2
[2014/04/15 20:37:01 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro
[2014/04/15 20:35:09 | 000,000,000 | ---D | C] -- C:\Program Files\LPT
[2014/04/15 20:33:58 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Local\LPT
[2014/04/15 20:33:56 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Local\Smartbar
[2014/04/15 20:33:03 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FilesFrog Update Checker
[2014/04/15 20:33:03 | 000,000,000 | ---D | C] -- C:\Users\lesley\AppData\Local\FilesFrog Update Checker
[2014/04/06 16:39:53 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
========== Files - Modified Within 30 Days ==========
[2014/04/30 20:05:15 | 000,000,248 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2014/04/30 20:04:47 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/04/30 20:04:29 | 000,048,222 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2014/04/30 20:04:29 | 000,048,222 | ---- | M] () -- C:\ProgramData\nvModes.001
[2014/04/30 20:04:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/04/30 20:03:44 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2014/04/30 20:03:44 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2014/04/30 20:03:10 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/04/29 23:03:31 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/04/21 17:02:21 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2014/04/21 17:02:21 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2014/04/17 00:38:57 | 255,060,460 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2014/04/16 21:22:52 | 000,313,936 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/04/16 19:59:08 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2014/04/15 20:37:39 | 000,002,015 | ---- | M] () -- C:\Users\lesley\Desktop\Free Mahjong Games.lnk
[2014/04/15 20:37:10 | 000,000,859 | ---- | M] () -- C:\Users\lesley\Desktop\Optimizer Pro.lnk
[2014/04/15 20:34:48 | 000,002,327 | ---- | M] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Search.lnk
[2014/04/15 20:34:47 | 000,002,303 | ---- | M] () -- C:\Users\lesley\Desktop\Search.lnk
[2014/04/11 21:21:35 | 000,001,927 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/04/06 15:42:34 | 000,000,845 | ---- | M] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Norton Utilities.lnk
[2014/04/05 13:24:10 | 000,647,880 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/04/05 13:24:10 | 000,124,848 | ---- | M] () -- C:\Windows\System32\perfc009.dat
========== Files Created - No Company Name ==========
[2014/04/21 17:02:21 | 000,000,000 | RHS- | C] () -- C:\MSDOS.SYS
[2014/04/21 17:02:21 | 000,000,000 | RHS- | C] () -- C:\IO.SYS
[2014/04/15 20:37:38 | 000,002,015 | ---- | C] () -- C:\Users\lesley\Desktop\Free Mahjong Games.lnk
[2014/04/15 20:37:08 | 000,000,859 | ---- | C] () -- C:\Users\lesley\Desktop\Optimizer Pro.lnk
[2014/04/15 20:34:48 | 000,002,327 | ---- | C] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Search.lnk
[2014/04/15 20:34:47 | 000,002,333 | ---- | C] () -- C:\Users\lesley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2014/04/15 20:34:46 | 000,002,303 | ---- | C] () -- C:\Users\lesley\Desktop\Search.lnk
[2014/04/06 15:42:34 | 000,000,845 | ---- | C] () -- C:\Users\lesley\Application Data\Microsoft\Internet Explorer\Quick Launch\Norton Utilities.lnk
[2010/08/02 23:32:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uremomix.dll
[2010/08/02 21:30:10 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iqisozidohugi.dll
[2010/08/02 19:28:10 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udulibikixe.dll
[2010/08/01 23:05:19 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\okujecuxiq.dll
[2010/08/01 21:02:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iyekuyepebeham.dll
[2010/08/01 14:29:05 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ocaxobeditexete.dll
[2010/08/01 02:28:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewigobabamisa.dll
[2010/08/01 00:26:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\evejopevogani.dll
[2010/07/31 22:24:58 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eleqocefuwej.dll
[2010/07/31 04:31:02 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udobalepinubesi.dll
[2010/07/30 22:15:30 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ubifuyiw.dll
[2010/07/30 20:13:08 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\udebotax.dll
[2010/07/30 18:11:09 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\owepejid.dll
[2010/07/30 14:42:45 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ilonepoza.dll
[2010/07/30 12:40:45 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\epapozadu.dll
[2010/07/29 23:44:36 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewufayoqevi.dll
[2010/07/29 21:42:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ajuzaxeqetalajo.dll
[2010/07/29 19:40:57 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iqisagubi.dll
[2010/07/29 14:36:49 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ememomixefenoy.dll
[2010/07/29 12:35:07 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\azasanukukub.dll
[2010/07/29 10:32:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ijisozid.dll
[2010/07/28 23:51:13 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ivafiyas.dll
[2010/07/28 21:48:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\otodovuj.dll
[2010/07/28 19:46:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\aqudumok.dll
[2010/07/27 22:52:47 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uvepamep.dll
[2010/07/26 23:39:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ofoguzele.dll
[2010/07/26 23:25:13 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ubetenim.dll
[2010/07/26 21:23:16 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eloyicubucamot.dll
[2010/07/25 23:40:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ekimamerih.dll
[2010/07/25 21:38:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uzeroyowuyazam.dll
[2010/07/25 19:36:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uzoqikuwafonutul.dll
[2010/07/25 17:34:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ojegejopevo.dll
[2010/07/25 14:20:34 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ezegoweli.dll
[2010/07/25 01:07:22 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\icitegixiv.dll
[2010/07/25 00:35:00 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufeyijevula.dll
[2010/07/24 22:33:14 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\acitiwuvubomure.dll
[2010/07/23 23:43:19 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\olabepaguh.dll
[2010/07/23 21:38:04 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iconasowovone.dll
[2010/07/23 19:06:15 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ewovuhox.dll
[2010/07/22 23:52:17 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\apojepope.dll
[2010/07/22 00:23:50 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\uhuyujup.dll
[2010/07/21 22:54:55 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ijepamep.dll
[2010/07/21 21:06:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\adudilak.dll
[2010/07/21 20:54:07 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\eruyewiducena.dll
[2010/07/20 23:10:01 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iwefumak.dll
[2010/07/20 21:08:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\iputaduxotoyeful.dll
[2010/07/19 23:42:56 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\utaxasuxomod.dll
[2010/07/19 21:37:53 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\enaxijokiqovab.dll
[2010/07/19 18:28:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\exitoced.dll
[2010/07/19 00:22:23 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufoyoxajij.dll
[2010/07/18 22:20:22 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\umevumeged.dll
[2010/07/17 21:54:38 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\oquvuwox.dll
[2010/07/17 19:52:41 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ahegokidonotudok.dll
[2010/07/17 17:48:28 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\enomihudu.dll
[2010/07/16 22:37:41 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ilawelijosi.dll
[2010/07/16 20:35:40 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ibopikeb.dll
[2010/07/16 17:16:02 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\ifixoqirac.dll
[2010/07/15 23:55:22 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ebiwukaza.dll
[2010/07/15 21:53:23 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\odorafoxosivolup.dll
[2010/07/14 22:31:55 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ajehoyop.dll
[2010/07/14 22:13:56 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\efidusex.dll
[2010/07/13 22:23:45 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\evohecew.dll
[2010/07/13 20:21:44 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufepulukelikuf.dll
[2010/07/13 18:19:43 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\evuderirif.dll
[2010/07/13 00:56:10 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ohubemojokesiy.dll
[2010/07/12 22:54:09 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ecogugek.dll
[2010/07/12 20:52:09 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ebeberer.dll
[2010/07/11 23:41:04 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ixebuxidetayol.dll
[2010/07/11 21:29:27 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\emiyugup.dll
[2010/07/11 19:27:27 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ufosuxidigibavuk.dll
[2010/07/11 16:00:57 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ezejiyerezuqah.dll
[2010/07/10 23:53:11 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\ohazopes.dll
[2010/07/10 21:51:11 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\uxaxemex.dll
[2010/07/10 19:49:10 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\upukulej.dll
[2010/07/10 12:43:02 | 000,025,623 | ---- | C] () -- C:\Users\lesley\AppData\Local\amorowov.dll
[2010/07/09 17:28:08 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\iresozoq.dll
[2010/07/02 20:20:42 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\aruwuroviqo.dll
[2010/07/02 18:18:41 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\efuyiyukejub.dll
[2010/05/29 19:16:00 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\inojupiliyojo.dll
[2010/05/28 19:52:00 | 000,025,228 | ---- | C] () -- C:\Users\lesley\AppData\Local\ipidobuvogepu.dll
[2010/04/08 23:16:00 | 000,023,090 | ---- | C] () -- C:\Users\lesley\AppData\Local\ipobohid.dll
[2010/04/07 21:07:39 | 000,023,090 | ---- | C] () -- C:\Users\lesley\AppData\Local\ibeciquc.dll
[2010/01/30 22:08:18 | 000,008,484 | ---- | C] () -- C:\Users\lesley\AppData\Local\d3d9caps.dat
[2010/01/15 17:28:53 | 000,000,120 | ---- | C] () -- C:\Users\lesley\AppData\Local\Amaloxubacepexo.dat
[2010/01/15 17:28:53 | 000,000,000 | ---- | C] () -- C:\Users\lesley\AppData\Local\Jnidakusadiyu.bin
[2009/10/12 17:55:41 | 000,008,704 | ---- | C] () -- C:\Users\lesley\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/06/24 20:18:00 | 000,048,222 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/06/24 20:10:48 | 000,048,222 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/04/14 17:49:08 | 000,000,248 | ---- | C] () -- C:\ProgramData\hpqp.ini
========== ZeroAccess Check ==========
[2006/11/02 13:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 18:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 07:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 07:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/06/22 20:13:50 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/01/02 01:16:04 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\EasyChat
[2009/07/28 00:30:04 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\Gaijin Ent
[2010/08/14 01:30:58 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\lowsec
[2013/07/05 01:37:17 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\Memory Resource
[2014/04/15 20:42:50 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\Optimizer Pro
[2013/05/02 18:39:52 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\PlusWinks
[2010/06/26 00:26:13 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\Program Files
[2010/08/01 00:48:11 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\Titanium Gears
[2009/06/24 20:08:29 | 000,000,000 | ---D | M] -- C:\Users\lesley\AppData\Roaming\WildTangent
[2009/06/24 21:22:02 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\EPSON
[2010/07/18 19:56:33 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\passport_photo
[2010/06/12 15:06:33 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\Program Files
[2010/02/09 17:56:55 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\Sports Interactive
[2011/01/06 21:01:14 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\Spotify
[2009/06/28 12:18:57 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\Template
[2009/12/05 10:25:28 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\TigerPlayer
[2010/08/03 19:47:15 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\uTorrent
[2009/06/25 23:03:47 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\WildTangent
[2010/04/18 20:51:14 | 000,000,000 | ---D | M] -- C:\Users\roger\AppData\Roaming\WindSolutions
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:D287FACF
< End of report >
thank you in advance