Help! I downloaded an Excel viewer from CNET and got infected with the Stormfall malware and I don't know how to remove it.
Here is my OTL log:
OTL logfile created on: 6/1/2014 9:39:52 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Tim\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.01 Gb Available Physical Memory | 33.84% Memory free
5.97 Gb Paging File | 2.93 Gb Available in Paging File | 49.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 454.82 Gb Total Space | 75.82 Gb Free Space | 16.67% Space Free | Partition Type: NTFS
Drive Q: | 9.76 Gb Total Space | 3.25 Gb Free Space | 33.32% Space Free | Partition Type: NTFS
Computer Name: THIMKPAD | User Name: Tim | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/06/01 09:38:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Tim\Desktop\OTL.exe
PRC - [2014/05/19 17:45:22 | 033,322,312 | ---- | M] (Dropbox, Inc.) -- C:\Users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2014/05/15 10:31:16 | 001,863,856 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe
PRC - [2014/05/09 12:20:29 | 000,275,568 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2014/04/25 10:03:52 | 022,415,552 | ---- | M] (Google) -- C:\Program Files\Google\Drive\googledrivesync.exe
PRC - [2014/03/30 09:13:57 | 000,054,960 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe
PRC - [2014/03/30 09:13:12 | 001,614,344 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe
PRC - [2014/03/30 09:11:32 | 001,343,472 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe
PRC - [2013/08/01 17:52:57 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2013/06/26 19:23:04 | 000,207,528 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2013/06/26 19:23:00 | 000,523,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2013/04/22 09:43:52 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe
PRC - [2013/04/22 09:40:54 | 005,687,152 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe
PRC - [2013/04/22 09:40:04 | 000,270,192 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2013/01/29 18:13:12 | 001,668,224 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
PRC - [2013/01/29 18:13:12 | 001,093,744 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
PRC - [2013/01/10 14:10:44 | 000,873,248 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2013/01/10 14:10:41 | 001,821,984 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2013/01/10 14:10:11 | 005,918,496 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Control Panel Client\nvcplui.exe
PRC - [2012/11/22 19:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/06/25 17:45:14 | 000,082,824 | ---- | M] (Bitdefender) -- C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe
PRC - [2011/05/05 20:32:30 | 000,132,392 | ---- | M] (Synaptics Incorporated) -- C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
PRC - [2011/04/19 03:52:00 | 000,143,360 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.exe
PRC - [2011/04/19 03:52:00 | 000,062,824 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\ThinkPad\Utilities\SCHTASK.EXE
PRC - [2011/03/08 15:14:34 | 000,303,976 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
PRC - [2011/03/08 13:21:18 | 000,138,168 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\ZOOM\TpScrex.exe
PRC - [2011/02/24 22:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/01/14 15:52:10 | 000,065,896 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
PRC - [2011/01/14 15:52:08 | 000,054,632 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe
PRC - [2011/01/14 15:51:56 | 000,041,320 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe
PRC - [2010/12/14 15:57:20 | 000,136,040 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
PRC - [2010/12/03 10:57:38 | 000,099,328 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\tphkload.exe
PRC - [2010/12/02 12:55:54 | 000,064,440 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
PRC - [2010/11/29 16:32:44 | 000,069,560 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe
PRC - [2010/11/24 16:34:24 | 000,045,496 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\micmute.exe
PRC - [2010/10/29 20:25:12 | 000,142,696 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
PRC - [2010/07/19 18:42:16 | 000,866,576 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2010/07/19 18:23:28 | 000,477,456 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2010/05/02 20:54:36 | 002,533,400 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/05/02 20:54:32 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/05/02 20:54:28 | 001,522,200 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
PRC - [2010/04/06 22:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe
PRC - [2010/03/31 22:50:46 | 000,043,960 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Lenovo\VIRTSCRL\virtscrl.exe
PRC - [2010/03/27 05:01:26 | 014,090,688 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Illustrator.exe
PRC - [2010/02/22 04:57:06 | 000,406,992 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe
PRC - [2009/08/28 15:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe
PRC - [2009/07/13 18:14:17 | 000,008,192 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dinotify.exe
PRC - [2008/10/30 15:23:52 | 000,031,744 | ---- | M] (Ricoh co.,Ltd.) -- C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe
PRC - [2008/01/10 13:13:50 | 000,061,440 | ---- | M] (Ulead Systems, Inc.) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
========== Modules (No Company Name) ==========
MOD - [2014/05/30 16:41:39 | 000,043,008 | ---- | M] () -- c:\Users\Tim\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaul_ch.dll
MOD - [2014/05/30 16:41:28 | 000,027,136 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_multiprocessing.pyd
MOD - [2014/05/30 16:41:27 | 001,159,680 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_ssl.pyd
MOD - [2014/05/30 16:41:27 | 001,062,400 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._controls_.pyd
MOD - [2014/05/30 16:41:27 | 000,811,008 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._windows_.pyd
MOD - [2014/05/30 16:41:27 | 000,805,888 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._gdi_.pyd
MOD - [2014/05/30 16:41:27 | 000,713,216 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_hashlib.pyd
MOD - [2014/05/30 16:41:27 | 000,686,080 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\unicodedata.pyd
MOD - [2014/05/30 16:41:27 | 000,127,488 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\pyexpat.pyd
MOD - [2014/05/30 16:41:27 | 000,110,080 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\PyWinTypes27.dll
MOD - [2014/05/30 16:41:27 | 000,070,656 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._html2.pyd
MOD - [2014/05/30 16:41:27 | 000,038,912 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32inet.pyd
MOD - [2014/05/30 16:41:27 | 000,035,840 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32process.pyd
MOD - [2014/05/30 16:41:27 | 000,025,600 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32pdh.pyd
MOD - [2014/05/30 16:41:27 | 000,024,064 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32pipe.pyd
MOD - [2014/05/30 16:41:27 | 000,018,432 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32event.pyd
MOD - [2014/05/30 16:41:27 | 000,010,240 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\select.pyd
MOD - [2014/05/30 16:41:26 | 000,557,056 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\pysqlite2._sqlite.pyd
MOD - [2014/05/30 16:41:26 | 000,525,640 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\windows._lib_cacheinvalidation.pyd
MOD - [2014/05/30 16:41:26 | 000,320,512 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32com.shell.shell.pyd
MOD - [2014/05/30 16:41:26 | 000,167,936 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32gui.pyd
MOD - [2014/05/30 16:41:26 | 000,128,512 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_elementtree.pyd
MOD - [2014/05/30 16:41:26 | 000,119,808 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32file.pyd
MOD - [2014/05/30 16:41:26 | 000,108,544 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32security.pyd
MOD - [2014/05/30 16:41:26 | 000,098,816 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32api.pyd
MOD - [2014/05/30 16:41:26 | 000,087,552 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_ctypes.pyd
MOD - [2014/05/30 16:41:26 | 000,045,568 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\_socket.pyd
MOD - [2014/05/30 16:41:26 | 000,022,528 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32ts.pyd
MOD - [2014/05/30 16:41:26 | 000,017,408 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32profile.pyd
MOD - [2014/05/30 16:41:25 | 001,175,040 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._core_.pyd
MOD - [2014/05/30 16:41:25 | 000,735,232 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._misc_.pyd
MOD - [2014/05/30 16:41:25 | 000,364,544 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\pythoncom27.dll
MOD - [2014/05/30 16:41:25 | 000,078,336 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._animate.pyd
MOD - [2014/05/30 16:41:24 | 000,122,368 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\wx._wizard.pyd
MOD - [2014/05/30 16:41:24 | 000,011,264 | ---- | M] () -- C:\Users\Tim\AppData\Local\Temp\_MEI48523\win32crypt.pyd
MOD - [2014/05/15 10:31:16 | 016,361,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32_13_0_0_214.dll
MOD - [2014/05/09 12:20:28 | 003,839,088 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2014/03/30 09:14:09 | 000,093,040 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\bdmetrics.dll
MOD - [2014/03/30 09:12:57 | 000,204,280 | ---- | M] () -- C:\Program Files\Bitdefender\Bitdefender 2013\txmlutil.dll
MOD - [2014/02/28 04:02:23 | 000,122,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\78652b7fa68ee058bff6a118c657f565\SMDiagnostics.ni.dll
MOD - [2014/02/28 04:02:22 | 000,806,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\34b53ecafa1d7ccc7ca961d722b5d983\System.ServiceModel.Internals.ni.dll
MOD - [2014/02/28 04:02:20 | 002,825,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\f6d7bb59f318c130d68816a89335d05e\System.Runtime.Serialization.ni.dll
MOD - [2014/02/28 04:02:19 | 007,662,080 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bada32953bb6b16a53d653eae23d78dc\System.Xml.ni.dll
MOD - [2014/02/28 04:02:14 | 000,976,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\bbc48ec4245e502ae19b0601d3799c9e\System.Configuration.ni.dll
MOD - [2014/02/28 04:02:13 | 010,060,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\ff26cc03e6d57d8abd13b990332e67c6\System.ni.dll
MOD - [2014/02/28 04:02:06 | 016,953,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\ce5f61c5754789df97be8dc991c47d07\mscorlib.ni.dll
MOD - [2014/02/13 04:26:29 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\8bc548587e91ecf0552a40e47bbf99cc\System.Windows.Forms.ni.dll
MOD - [2014/02/13 04:26:24 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5c24d3b0041ebf4f48a93615b9fa3de9\System.Drawing.ni.dll
MOD - [2014/02/13 04:26:08 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\217ece46920546d718414291d463bb1c\System.Xml.ni.dll
MOD - [2014/02/13 04:26:05 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\5b6ddf934128d538cd5cd77bf4209b93\System.Configuration.ni.dll
MOD - [2014/02/13 04:26:04 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b3a78269847005365001c33870cd121f\System.ni.dll
MOD - [2014/02/13 04:25:58 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\ede2c6c842840e009f01bcc74fa4c457\mscorlib.ni.dll
MOD - [2014/01/02 18:09:26 | 003,610,624 | ---- | M] () -- C:\Users\Tim\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/08/23 12:01:44 | 025,100,288 | ---- | M] () -- C:\Users\Tim\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2011/05/05 20:32:00 | 000,066,856 | ---- | M] () -- C:\Program Files\Synaptics\SynTP\SynTPEnhPS.dll
MOD - [2011/04/19 03:52:00 | 000,043,520 | ---- | M] () -- C:\Program Files\ThinkPad\Utilities\US\PWMRT32V.DLL
MOD - [2011/03/21 17:30:20 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010/03/27 05:01:30 | 000,058,816 | ---- | M] () -- C:\Program Files\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\SPBasic.dll
MOD - [2010/03/27 05:00:08 | 000,070,592 | ---- | M] () -- C:\Program Files\Adobe\Adobe Illustrator CS5\Support Files\Contents\Windows\Alcid.dll
MOD - [2010/02/22 04:50:20 | 000,060,416 | ---- | M] () -- C:\Program Files\Common Files\Adobe\CS5ServiceManager\zlib1.dll
========== Services (SafeList) ==========
SRV - [2014/05/15 10:31:18 | 000,257,712 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/05/09 12:20:29 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/03/30 09:13:57 | 000,054,960 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\updatesrv.exe -- (UPDATESRV)
SRV - [2014/03/30 09:13:11 | 000,062,688 | ---- | M] (Bitdefender) [Disabled | Stopped] -- C:\Program Files\Bitdefender\Bitdefender 2013\bdparentalservice.exe -- (BdDesktopParental)
SRV - [2014/03/30 09:11:32 | 001,343,472 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\vsserv.exe -- (VSSERV)
SRV - [2014/03/06 00:38:10 | 000,108,032 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/02/21 13:39:52 | 000,024,120 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2013/10/23 09:15:08 | 000,172,192 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2013/06/26 19:23:04 | 000,207,528 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2013/06/26 19:23:00 | 000,523,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2013/05/26 21:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2013/04/22 09:43:52 | 001,042,808 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WDBackupEngine.exe -- (WDBackup)
SRV - [2013/04/22 09:40:04 | 000,270,192 | R--- | M] (Western Digital Technologies, Inc.) [Auto | Running] -- C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2013/01/11 08:11:54 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/25 17:45:14 | 000,082,824 | ---- | M] (Bitdefender) [Auto | Running] -- C:\Program Files\Bitdefender\Bitdefender Safebox\safeboxservice.exe -- (SafeBox)
SRV - [2011/05/27 00:16:34 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/04/19 03:52:00 | 000,292,200 | ---- | M] (Lenovo.) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc)
SRV - [2011/04/19 03:52:00 | 000,143,360 | ---- | M] () [Auto | Running] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc)
SRV - [2011/04/19 03:52:00 | 000,083,304 | ---- | M] (Lenovo) [On_Demand | Stopped] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.exe -- (Power Manager DBC Service)
SRV - [2011/01/14 15:52:10 | 000,065,896 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe -- (LENOVO.TPKNRSVC)
SRV - [2011/01/14 15:51:56 | 000,041,320 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe -- (LENOVO.CAMMUTE)
SRV - [2010/12/03 10:57:38 | 000,099,328 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV - [2010/12/02 12:55:54 | 000,064,440 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2010/11/24 16:34:24 | 000,045,496 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV - [2010/07/19 18:42:16 | 000,866,576 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng)
SRV - [2010/07/19 18:23:28 | 000,477,456 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc)
SRV - [2010/05/02 20:54:36 | 002,533,400 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/05/02 20:54:32 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/04/06 22:37:40 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/09/29 18:25:38 | 000,099,768 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe -- (TurboBoost)
SRV - [2009/08/28 15:09:58 | 001,019,904 | ---- | M] (Lenovo Group Limited) [Auto | Running] -- C:\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe -- (ThinkVantage Registry Monitor Service)
SRV - [2009/07/13 18:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/04/28 19:21:04 | 000,410,624 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\System32\XAudio32.dll -- (HsfXAudioService)
SRV - [2008/01/10 13:13:50 | 000,061,440 | ---- | M] (Ulead Systems, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe -- (UleadBurningHelper)
========== Driver Services (SafeList) ==========
DRV - [2014/03/30 09:15:52 | 000,078,144 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- c:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfndisf6.sys -- (BdfNdisf)
DRV - [2014/03/30 09:14:09 | 000,778,032 | ---- | M] (BitDefender) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avc3.sys -- (avc3)
DRV - [2014/03/30 09:13:43 | 000,066,832 | ---- | M] (BitDefender SRL) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\bdsandbox.sys -- (BDSandBox)
DRV - [2014/03/30 09:13:26 | 000,516,936 | ---- | M] (BitDefender) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\avckf.sys -- (avckf)
DRV - [2013/08/23 12:48:39 | 000,165,744 | ---- | M] (BitDefender LLC) [File_System | Boot | Running] -- C:\Windows\System32\drivers\gzflt.sys -- (gzflt)
DRV - [2013/08/07 12:46:04 | 000,360,376 | ---- | M] (BitDefender S.R.L.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\trufos.sys -- (trufos)
DRV - [2013/07/26 10:53:51 | 000,135,600 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Bitdefender\Bitdefender 2013\bdselfpr.sys -- (bdselfpr)
DRV - [2013/06/26 19:23:04 | 000,020,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftvollh.sys -- (Sftvol)
DRV - [2013/06/26 19:23:00 | 000,197,800 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftplaylh.sys -- (Sftplay)
DRV - [2013/06/26 19:23:00 | 000,024,232 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\Sftredirlh.sys -- (Sftredir)
DRV - [2013/06/26 19:22:58 | 000,583,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Sftfslh.sys -- (Sftfs)
DRV - [2013/02/18 09:22:18 | 000,149,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2013/01/11 08:11:54 | 008,913,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2013/01/11 08:11:54 | 000,025,376 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvpciflt.sys -- (nvpciflt)
DRV - [2012/11/02 13:17:14 | 000,242,504 | ---- | M] (BitDefender) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\avchv.sys -- (avchv)
DRV - [2012/04/17 13:40:22 | 000,072,704 | ---- | M] (BitDefender) [Kernel | System | Running] -- C:\Windows\System32\drivers\bdvedisk.sys -- (BDVEDISK)
DRV - [2011/11/14 19:16:27 | 000,090,704 | ---- | M] (BitDefender LLC) [Kernel | System | Running] -- C:\Program Files\Common Files\Bitdefender\Bitdefender Firewall\bdfwfpf.sys -- (bdfwfpf)
DRV - [2011/04/19 03:52:00 | 000,025,968 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD)
DRV - [2011/04/19 03:52:00 | 000,013,424 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF)
DRV - [2011/01/13 11:18:50 | 000,132,608 | ---- | M] (Ricoh co.,Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\5U877.sys -- (5U877)
DRV - [2010/12/10 12:42:09 | 000,816,792 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pmxdrv.sys -- (pmxdrv)
DRV - [2010/11/20 03:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 02:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/10/15 00:27:18 | 000,269,824 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\IntcDAud.sys -- (IntcDAud)
DRV - [2010/09/07 14:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System | Running] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi)
DRV - [2010/08/25 09:45:56 | 000,486,016 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2010/07/22 09:38:06 | 000,215,208 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\e1k6232.sys -- (e1kexpress)
DRV - [2010/07/14 05:42:24 | 006,814,720 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\NETwNs32.sys -- (NETwNs32)
DRV - [2010/06/16 14:44:38 | 000,120,432 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf)
DRV - [2010/06/16 14:44:38 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN)
DRV - [2010/05/10 14:47:34 | 000,015,416 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio32.sys -- (XAudio)
DRV - [2010/02/26 00:31:22 | 000,132,480 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Impcd.sys -- (Impcd)
DRV - [2010/01/07 04:20:22 | 000,375,808 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL8187.sys -- (RTL8187)
DRV - [2009/10/25 22:39:00 | 000,048,640 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimspe86.sys -- (rimspci)
DRV - [2009/09/29 18:25:42 | 000,013,752 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\TurboB.sys -- (TurboB)
DRV - [2009/09/24 04:58:52 | 000,038,336 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tvti2c.sys -- (TVTI2C)
DRV - [2009/09/16 20:54:14 | 000,041,088 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HECI.sys -- (HECI)
DRV - [2009/07/13 16:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009/07/13 16:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2009/07/13 15:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32)
DRV - [2009/07/01 19:16:16 | 000,033,088 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\psadd.sys -- (psadd)
DRV - [2009/05/10 19:33:48 | 000,088,832 | ---- | M] (Lenovo) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LenovoRd.sys -- (LenovoRd)
DRV - [2008/05/06 17:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2007/04/09 09:50:34 | 000,009,600 | ---- | M] (Waytech Development, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UsbFltr.sys -- (UsbFltr)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\..\SearchScopes,DefaultScope = {E84816C5-83A0-4164-A278-A4F97DC64AD6}
IE - HKLM\..\SearchScopes\{E84816C5-83A0-4164-A278-A4F97DC64AD6}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/us/laptop/?c [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\SearchScopes,DefaultScope = {E84816C5-83A0-4164-A278-A4F97DC64AD6}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://www.kickstar...ch-of-the-ants"
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.8.26
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Tim\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Tim\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Tim\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/05/09 12:20:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\Bitdefender\Bitdefender 2013\bdtbext [2014/03/30 09:06:27 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2014/05/09 12:20:18 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
[2011/05/26 11:58:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tim\AppData\Roaming\Mozilla\Extensions
[2014/05/27 22:24:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\kpwyeb7f.default\extensions
[2014/05/27 22:24:59 | 000,533,329 | ---- | M] () (No name found) -- C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\kpwyeb7f.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2014/05/01 19:36:34 | 000,957,880 | ---- | M] () (No name found) -- C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\kpwyeb7f.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014/05/20 12:30:28 | 000,000,643 | ---- | M] () -- C:\Users\Tim\AppData\Roaming\Mozilla\Firefox\Profiles\kpwyeb7f.default\searchplugins\trovi-search.xml
[2014/05/09 12:20:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/05/09 12:20:31 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2011/05/26 15:35:09 | 000,000,855 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [B2C_AGENT] C:\ProgramData\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe (LG Electronics)
O4 - HKLM..\Run: [Bdagent] C:\Program Files\Bitdefender\Bitdefender 2013\bdagent.exe (Bitdefender)
O4 - HKLM..\Run: [IMSS] C:\Program Files\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4 - HKLM..\Run: [Logitech Download Assistant] C:\Windows\System32\LogiLDA.dll (Logitech, Inc.)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RotateImage] C:\Program Files\Integrated Camera Driver\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files\Western Digital\WD Quick View\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKCU..\Run: [OutfoxTV] C:\Program Files\OutfoxTV\OutfoxTV\DesktopContainer.exe File not found
O4 - Startup: C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Tim\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3BF97CDD-C848-4B09-B498-D198787FCD6C}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CD1CBD65-C01A-492C-B2C0-80C16FCDBBAA}: DhcpNameServer = 75.75.75.75 75.75.76.76
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (c:\windows\system32\nvinit.dll) - C:\Windows\System32\nvinit.dll (NVIDIA Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/06/10 09:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{b1ebc5f6-8793-11e0-941c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b1ebc5f6-8793-11e0-941c-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/10 14:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O33 - MountPoints2\{e26924b1-36b2-11e2-9717-f0def11b37d4}\Shell - "" = AutoRun
O33 - MountPoints2\{e26924b1-36b2-11e2-9717-f0def11b37d4}\Shell\AutoRun\command - "" = "H:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/06/01 09:38:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Tim\Desktop\OTL.exe
[2014/05/31 11:29:55 | 000,000,000 | ---D | C] -- C:\Users\Tim\Desktop\New folder
[2014/05/20 23:09:07 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{407392FA-6FB1-4F05-81C8-0F1DFD1261D2}
[2014/05/20 12:33:14 | 000,000,000 | -HSD | C] -- C:\Users\Tim\AppData\Local\EmieUserList
[2014/05/20 12:33:14 | 000,000,000 | -HSD | C] -- C:\Users\Tim\AppData\Local\EmieSiteList
[2014/05/20 12:21:48 | 000,000,000 | ---D | C] -- C:\Users\Tim\Documents\Optimizer Pro
[2014/05/20 12:17:50 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\IsolatedStorage
[2014/05/20 12:16:28 | 000,000,000 | ---D | C] -- C:\Program Files\webget
[2014/05/20 12:16:15 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Roaming\StormFall
[2014/05/20 12:16:15 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StormFall
[2014/05/20 12:16:05 | 001,705,063 | ---- | C] (AnyProtect.com) -- C:\Users\Tim\AppData\Local\AnyProtectScannerSetup.exe
[2014/05/19 11:05:19 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{2398FCAC-7F1F-42C4-BAAA-BF5CCF60666A}
[2014/05/16 22:53:59 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{3067C60C-2D43-4F27-B967-BBE65A215A66}
[2014/05/15 12:55:35 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{D252AA83-7DC8-4900-B106-2E71B773977A}
[2014/05/14 15:46:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER
[2014/05/14 15:36:52 | 002,724,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/05/13 19:35:42 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Roaming\DropboxMaster
[2014/05/13 18:50:36 | 000,369,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
[2014/05/13 18:50:36 | 000,302,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2014/05/13 18:50:28 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2014/05/13 18:50:28 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2014/05/13 18:50:27 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\objsel.dll
[2014/05/13 18:50:26 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cngprovider.dll
[2014/05/13 18:50:26 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adprovider.dll
[2014/05/13 18:50:26 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\capiprovider.dll
[2014/05/13 18:50:26 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dpapiprovider.dll
[2014/05/13 18:50:26 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dimsroam.dll
[2014/05/13 18:50:25 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wincredprovider.dll
[2014/05/13 18:50:25 | 000,015,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sspisrv.dll
[2014/05/09 22:33:14 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{F35C4FF6-8678-46F0-8C5F-67F8B1E4DFD5}
[2014/05/09 21:57:51 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\GoPro
[2014/05/09 20:34:15 | 000,000,000 | ---D | C] -- C:\Users\Tim\Desktop\Plythrough Video
[2014/05/09 20:28:08 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2014/05/09 20:22:07 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Roaming\GoPro
[2014/05/09 20:21:40 | 000,000,000 | ---D | C] -- C:\Program Files\CineForm
[2014/05/09 12:20:17 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/05/07 12:32:39 | 000,000,000 | ---D | C] -- C:\Users\Tim\AppData\Local\{C64DD0BF-F729-4DAB-B60A-144599DAE914}
[2014/05/05 23:54:34 | 000,000,000 | --SD | C] -- C:\Windows\System32\CompatTel
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/06/01 09:43:01 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/06/01 09:38:58 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Tim\Desktop\OTL.exe
[2014/06/01 09:28:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/06/01 09:26:07 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2014/06/01 09:22:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1518848740-4250292544-4256302612-1002UA.job
[2014/06/01 09:12:28 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/05/31 18:48:18 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1518848740-4250292544-4256302612-1002Core.job
[2014/05/31 18:42:42 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/31 12:05:00 | 000,000,372 | ---- | M] () -- C:\Windows\tasks\PassShow Update.job
[2014/05/31 09:48:58 | 000,001,456 | ---- | M] () -- C:\Users\Tim\AppData\Local\Adobe Save for Web 12.0 Prefs
[2014/05/30 16:48:36 | 000,019,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/30 16:48:36 | 000,019,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/30 16:46:18 | 000,663,102 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2014/05/30 16:46:18 | 000,122,680 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2014/05/30 16:40:05 | 000,000,436 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2014/05/30 16:39:56 | 000,008,192 | ---- | M] () -- C:\Windows\System32\WDPABKP.dat
[2014/05/30 16:39:22 | 2406,223,872 | -HS- | M] () -- C:\hiberfil.sys
[2014/05/26 09:50:40 | 003,716,104 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2014/05/24 10:06:23 | 000,001,059 | ---- | M] () -- C:\Users\Tim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/05/23 19:04:41 | 001,433,591 | ---- | M] () -- C:\Users\Tim\Desktop\IMG_20140523_190441.jpg
[2014/05/23 18:03:30 | 001,249,478 | ---- | M] () -- C:\Users\Tim\Desktop\IMG_20140523_180330.jpg
[2014/05/20 12:22:29 | 000,000,324 | ---- | M] () -- C:\Users\Tim\AppData\Roaming\aps.uninstall.scan.results
[2014/05/20 10:41:44 | 000,009,151 | ---- | M] () -- C:\Users\Tim\Desktop\nvidia shield.jpg
[2014/05/19 12:38:04 | 000,002,903 | ---- | M] () -- C:\Users\Tim\Desktop\Playthrough round 2 part two and round three part 1.wlmp
[2014/05/19 12:33:41 | 000,002,731 | ---- | M] () -- C:\Users\Tim\Desktop\Playthrough round 2 edit 2nd half.wlmp
[2014/05/19 12:29:12 | 000,002,250 | ---- | M] () -- C:\Users\Tim\Desktop\Round 3 Part 2.wlmp
[2014/05/19 07:19:26 | 001,705,063 | ---- | M] (AnyProtect.com) -- C:\Users\Tim\AppData\Local\AnyProtectScannerSetup.exe
[2014/05/15 12:54:32 | 000,743,047 | ---- | M] () -- C:\Users\Tim\Desktop\PDXAGE1EventBook.pdf
[2014/05/15 10:31:16 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2014/05/15 10:31:16 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2014/05/09 21:48:50 | 000,024,304 | ---- | M] () -- C:\Users\Tim\Documents\untitled_AutoSave.gcs
[2014/05/09 15:23:20 | 115,345,816 | ---- | M] () -- C:\Users\Tim\Desktop\GoProStudioPC-2.0.1.319.exe
[2014/05/09 00:06:23 | 000,369,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\aepdu.dll
[2014/05/09 00:04:12 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\aeinv.dll
[2014/05/06 13:32:41 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2014/05/05 20:07:39 | 002,724,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2014/05/05 12:05:28 | 000,069,895 | ---- | M] () -- C:\Users\Tim\Desktop\MagicraftQuote to Tim 2014.4.23 - Quotation.pdf
[2014/05/04 10:56:41 | 000,050,417 | ---- | M] () -- C:\Users\Tim\Desktop\728px-Velvet_Ant.jpg
[2014/05/04 10:54:52 | 000,138,272 | ---- | M] () -- C:\Users\Tim\Desktop\ant in moon.jpg
[2014/05/04 10:40:15 | 000,716,691 | ---- | M] () -- C:\Users\Tim\Desktop\March-of-the-Ants-Rules-Compressed-2014.pdf
[2014/05/04 00:57:31 | 078,448,837 | ---- | M] () -- C:\Users\Tim\Desktop\March of the Ants Rules May 2014.pdf
[2014/05/04 00:56:05 | 001,414,609 | ---- | M] () -- C:\Users\Tim\Desktop\Rule Book 1, Set up, Gameplay.pdf
[2014/05/02 23:00:30 | 000,462,486 | ---- | M] () -- C:\Users\Tim\Desktop\March-of-the-Ants-Rules1.pdf
[3 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/05/23 19:29:11 | 001,249,478 | ---- | C] () -- C:\Users\Tim\Desktop\IMG_20140523_180330.jpg
[2014/05/23 19:28:44 | 001,433,591 | ---- | C] () -- C:\Users\Tim\Desktop\IMG_20140523_190441.jpg
[2014/05/20 12:20:52 | 000,000,324 | ---- | C] () -- C:\Users\Tim\AppData\Roaming\aps.uninstall.scan.results
[2014/05/20 12:15:34 | 000,000,372 | ---- | C] () -- C:\Windows\tasks\PassShow Update.job
[2014/05/20 10:41:43 | 000,009,151 | ---- | C] () -- C:\Users\Tim\Desktop\nvidia shield.jpg
[2014/05/19 12:38:04 | 000,002,903 | ---- | C] () -- C:\Users\Tim\Desktop\Playthrough round 2 part two and round three part 1.wlmp
[2014/05/19 12:33:11 | 000,002,731 | ---- | C] () -- C:\Users\Tim\Desktop\Playthrough round 2 edit 2nd half.wlmp
[2014/05/19 12:29:12 | 000,002,250 | ---- | C] () -- C:\Users\Tim\Desktop\Round 3 Part 2.wlmp
[2014/05/15 12:54:31 | 000,743,047 | ---- | C] () -- C:\Users\Tim\Desktop\PDXAGE1EventBook.pdf
[2014/05/09 22:04:22 | 2154,913,846 | ---- | C] () -- C:\Users\Tim\Desktop\GOPR0156.MP4
[2014/05/09 22:03:59 | 1658,617,182 | ---- | C] () -- C:\Users\Tim\Desktop\GOPR0153.MP4
[2014/05/09 22:03:36 | 3934,786,975 | ---- | C] () -- C:\Users\Tim\Desktop\GOPR0152.MP4
[2014/05/09 22:03:28 | 3430,597,098 | ---- | C] () -- C:\Users\Tim\Desktop\GOPR0151.MP4
[2014/05/09 20:26:38 | 000,024,304 | ---- | C] () -- C:\Users\Tim\Documents\untitled_AutoSave.gcs
[2014/05/09 15:16:16 | 115,345,816 | ---- | C] () -- C:\Users\Tim\Desktop\GoProStudioPC-2.0.1.319.exe
[2014/05/05 12:05:36 | 000,069,895 | ---- | C] () -- C:\Users\Tim\Desktop\MagicraftQuote to Tim 2014.4.23 - Quotation.pdf
[2014/05/04 10:56:41 | 000,050,417 | ---- | C] () -- C:\Users\Tim\Desktop\728px-Velvet_Ant.jpg
[2014/05/04 10:54:52 | 000,138,272 | ---- | C] () -- C:\Users\Tim\Desktop\ant in moon.jpg
[2014/05/04 10:40:19 | 000,716,691 | ---- | C] () -- C:\Users\Tim\Desktop\March-of-the-Ants-Rules-Compressed-2014.pdf
[2014/05/04 00:55:34 | 001,414,609 | ---- | C] () -- C:\Users\Tim\Desktop\Rule Book 1, Set up, Gameplay.pdf
[2014/05/04 00:52:53 | 078,448,837 | ---- | C] () -- C:\Users\Tim\Desktop\March of the Ants Rules May 2014.pdf
[2014/04/26 23:39:46 | 000,000,017 | ---- | C] () -- C:\Windows\System32\shortcut_ex.dat
[2014/03/30 09:08:53 | 000,764,980 | ---- | C] () -- C:\ProgramData\1396195323.bdinstall.bin
[2014/03/29 22:06:10 | 000,007,632 | ---- | C] () -- C:\Users\Tim\AppData\Local\Resmon.ResmonCfg
[2014/03/29 14:28:22 | 000,008,192 | ---- | C] () -- C:\Windows\System32\WDPABKP.dat
[2013/10/21 12:27:47 | 006,699,056 | ---- | C] () -- C:\Users\Tim\leahnic2.bmp
[2013/10/21 12:27:29 | 006,699,056 | ---- | C] () -- C:\Users\Tim\leahnic.bmp
[2013/10/21 11:27:55 | 006,699,056 | ---- | C] () -- C:\Users\Tim\leahnicrelease.bmp
[2013/10/21 11:27:32 | 006,699,056 | ---- | C] () -- C:\Users\Tim\LeahPassport.bmp
[2013/10/21 11:26:52 | 006,699,056 | ---- | C] () -- C:\Users\Tim\leahnicapp.bmp
[2013/09/11 11:22:54 | 000,867,020 | ---- | C] () -- C:\Windows\System32\igkrng575.bin
[2013/09/11 11:22:52 | 000,105,608 | ---- | C] () -- C:\Windows\System32\igfcg575m.bin
[2013/09/11 11:22:52 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2013/09/11 11:22:51 | 000,128,204 | ---- | C] () -- C:\Windows\System32\igcompkrng575.bin
[2013/09/11 11:22:50 | 013,787,648 | ---- | C] () -- C:\Windows\System32\ig4icd32.dll
[2013/09/11 11:22:50 | 000,094,208 | ---- | C] () -- C:\Windows\System32\IccLibDll.dll
[2013/08/12 15:24:57 | 000,000,132 | ---- | C] () -- C:\Users\Tim\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2013/04/16 12:59:36 | 000,000,132 | ---- | C] () -- C:\Users\Tim\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
[2013/03/01 23:14:15 | 000,393,256 | ---- | C] () -- C:\Windows\System32\CNQ2414N.DAT
[2012/07/09 15:59:04 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2012/07/09 15:59:04 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2012/05/15 19:58:25 | 000,000,132 | ---- | C] () -- C:\Users\Tim\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/04/25 14:19:31 | 000,001,456 | ---- | C] () -- C:\Users\Tim\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/06/29 20:26:51 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
========== ZeroAccess Check ==========
[2009/07/13 21:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 19:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 05:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/13 18:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:054203E4
< End of report >
Edited by Tim Eisner, 01 June 2014 - 10:54 AM.