OTL logfile created on: 8/13/2014 9:00:45 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\theroufamily\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17207)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.91 Gb Total Physical Memory | 6.21 Gb Available Physical Memory | 78.51% Memory free
15.81 Gb Paging File | 13.98 Gb Available in Paging File | 88.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1862.92 Gb Total Space | 1806.29 Gb Free Space | 96.96% Space Free | Partition Type: NTFS
Computer Name: THEROUFAMILY-PC | User Name: theroufamily | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/08/13 09:00:05 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\theroufamily\Downloads\OTL (1).exe
PRC - [2012/06/15 19:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccsvchst.exe
PRC - [2012/02/06 17:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2012/02/03 20:55:59 | 000,050,544 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\symerr.exe
PRC - [2011/08/10 20:58:26 | 000,627,304 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
PRC - [2011/05/29 19:54:14 | 000,036,456 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
PRC - [2011/05/20 09:44:32 | 000,986,208 | ---- | M] (CyberLink) -- C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
PRC - [2011/03/29 15:33:08 | 000,598,312 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2011/01/31 22:24:42 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/01/31 22:24:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/05 23:54:22 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/02/03 00:08:56 | 000,087,336 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
========== Modules (No Company Name) ==========
MOD - [2011/08/10 20:58:26 | 000,627,304 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
MOD - [2011/08/10 20:57:22 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyHook.dll
========== Services (SafeList) ==========
SRV:64bit: - [2014/08/03 13:55:20 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/26 22:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/02/06 17:54:04 | 000,255,376 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe -- (Live Updater Service)
SRV:64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2012/06/15 19:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ccSvcHst.exe -- (NIS)
SRV - [2011/05/29 19:54:14 | 000,036,456 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe -- (GREGService)
SRV - [2011/03/29 15:33:08 | 000,598,312 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/01/31 22:24:42 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/01/31 22:24:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/11/05 23:54:22 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2010/10/12 10:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/06/01 15:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2009/06/10 14:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2014/08/03 22:40:44 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2014/07/16 09:42:28 | 000,057,528 | ---- | M] (Corsica) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\webinstr.sys -- (webinstr)
DRV:64bit: - [2012/07/05 19:17:58 | 000,037,536 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012/07/05 19:17:57 | 000,737,952 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2012/06/06 21:43:38 | 000,167,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\ccsetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2012/05/21 18:37:12 | 001,129,120 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symefa64.sys -- (SymEFA)
DRV:64bit: - [2012/04/17 19:13:32 | 000,405,624 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symnets.sys -- (SymNetS)
DRV:64bit: - [2012/04/17 18:42:14 | 000,190,072 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\ironx64.sys -- (SymIRON)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/07/13 22:35:47 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/07/13 22:35:47 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/06/29 23:03:04 | 000,054,784 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronHub3.sys -- (EtronHub3)
DRV:64bit: - [2011/06/29 23:03:02 | 000,077,696 | ---- | M] (Etron Technology Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EtronXHCI.sys -- (EtronXHCI)
DRV:64bit: - [2011/05/16 13:03:26 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\symds64.sys -- (SymDS)
DRV:64bit: - [2011/05/16 07:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/18 20:32:50 | 001,488,448 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2011/04/04 20:10:14 | 012,262,624 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/11/20 20:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 20:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/11/05 23:45:48 | 000,438,808 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/10/19 01:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/15 01:28:17 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2014/08/03 13:03:53 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20140812.023\ex64.sys -- (NAVEX15)
DRV - [2014/08/03 13:03:53 | 000,486,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2014/08/03 13:03:53 | 000,142,128 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2014/08/03 13:03:53 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\VirusDefs\20140812.023\eng64.sys -- (NAVENG)
DRV - [2014/07/31 17:19:14 | 000,525,016 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\IPSDefs\20140812.002\IDSviA64.sys -- (IDSVia64)
DRV - [2014/07/18 02:02:10 | 001,530,160 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\Definitions\BASHDefs\20140801.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2009/07/13 18:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...&q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com/?pc=MAGW
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snapdo.c...&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snapdo.c...&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snapdo.c...NNTU1kHbckxf_jw,,
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snapdo.c...&q={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snapdo.c...&q={searchTerms}
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\IPSFF [2014/08/03 16:29:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.0.0.128\coFFPlgn\ [2014/08/13 08:41:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{50633747-68D0-F14A-F015-11857E5A5AFB}: C:\Program Files (x86)\ver5Re-markit\176.xpi [2014/08/12 00:22:49 | 000,012,876 | ---- | M] ()
O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\ips\ipsbho.dll (Symantec Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\19.9.1.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\SearchScopes present
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.67.222.123 208.67.220.123 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C3969AAA-33F2-4E49-A372-AC3945CC00E1}: DhcpNameServer = 208.67.222.123 208.67.220.123 192.168.1.254
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/08/12 00:23:42 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\24230
[2014/08/12 00:22:50 | 000,057,528 | ---- | C] (Corsica) -- C:\Windows\SysNative\drivers\webinstr.sys
[2014/08/12 00:22:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ver5Re-markit
[2014/08/12 00:20:22 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\SearchProtect
[2014/08/10 19:13:43 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\StormAlerts
[2014/08/06 22:33:16 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\CrashDumps
[2014/08/05 08:52:02 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\Adobe
[2014/08/04 08:41:21 | 000,000,000 | ---D | C] -- C:\Program Files\Google
[2014/08/04 08:41:16 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\Google
[2014/08/04 08:41:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2014/08/04 08:41:11 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2014/08/03 20:25:17 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\CrashRpt
[2014/08/03 18:59:47 | 000,000,000 | ---D | C] -- C:\ProgramData\GFACE
[2014/08/03 18:59:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\wf-launcher
[2014/08/03 18:59:32 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warface Launcher
[2014/08/03 18:59:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Crytek
[2014/08/03 17:10:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2014/08/03 17:10:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2014/08/03 17:10:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2014/08/03 17:10:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014/08/03 17:10:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2014/08/03 17:08:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2014/08/03 17:08:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2014/08/03 17:07:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2014/08/03 17:07:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\Microsoft Help
[2014/08/03 17:07:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2014/08/03 17:07:28 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2014/08/03 16:28:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Symantec Shared
[2014/08/03 16:04:02 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\AppData\Local\EmieUserList
[2014/08/03 16:04:02 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\AppData\Local\EmieSiteList
[2014/08/03 15:59:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2014/08/03 15:59:31 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2014/08/03 15:59:31 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2014/08/03 15:21:09 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\CompatTel
[2014/08/03 14:04:57 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/08/03 13:28:22 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\MRT
[2014/08/03 12:36:19 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\OEM
[2014/08/03 12:36:08 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2014/08/03 12:36:08 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Searches
[2014/08/03 12:36:08 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2014/08/03 12:36:08 | 000,000,000 | -H-D | C] -- C:\Users\theroufamily\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2014/08/03 12:36:01 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\Identities
[2014/08/03 12:35:59 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Contacts
[2014/08/03 12:33:35 | 000,000,000 | ---D | C] -- C:\ProgramData\OEM_E471269A730D
[2014/08/03 12:32:43 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\VirtualStore
[2014/08/03 12:32:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Times Reader
[2014/08/03 12:31:56 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\Adobe
[2014/08/03 12:31:40 | 000,000,000 | --SD | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Videos
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Saved Games
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Pictures
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Music
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Links
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Favorites
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Downloads
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Documents
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\Desktop
[2014/08/03 12:31:40 | 000,000,000 | R--D | C] -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\AppData\Local\Temporary Internet Files
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Templates
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Start Menu
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\SendTo
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Recent
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\PrintHood
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\NetHood
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Documents\My Videos
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Documents\My Pictures
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Documents\My Music
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\My Documents
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Local Settings
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\AppData\Local\History
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Cookies
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\Application Data
[2014/08/03 12:31:40 | 000,000,000 | -HSD | C] -- C:\Users\theroufamily\AppData\Local\Application Data
[2014/08/03 12:31:40 | 000,000,000 | -H-D | C] -- C:\Users\theroufamily\AppData
[2014/08/03 12:31:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\Temp
[2014/08/03 12:31:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Local\Microsoft
[2014/08/03 12:31:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\Media Center Programs
[2014/08/03 12:31:40 | 000,000,000 | ---D | C] -- C:\Users\theroufamily\AppData\Roaming\Macromedia
[2014/08/03 12:31:30 | 000,000,000 | -HSD | C] -- C:\Recovery
[2014/08/03 11:56:55 | 000,000,000 | ---D | C] -- C:\Windows\NAPP_Dism_Log
[2014/08/03 11:32:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Barnes & Noble
[2014/08/03 11:32:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Barnes & Noble
[2014/08/03 11:31:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Fooz Kids
[2014/08/03 11:31:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2014/08/03 11:30:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fooz Kids
[2014/08/03 11:29:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2014/08/03 11:29:31 | 000,000,000 | ---D | C] -- C:\Program Files\Preload
[2014/08/03 11:29:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AUPEO!
[2014/08/03 11:28:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2014/08/03 11:28:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Evernote
[2014/08/03 11:28:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Evernote
[2014/08/03 11:28:10 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD 10
[2014/08/03 11:28:10 | 000,000,000 | ---D | C] -- C:\ProgramData\CLSK
[2014/08/03 11:27:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft
[2014/08/03 11:24:13 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\RTCOM
[2014/08/03 11:24:07 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014/08/03 11:24:06 | 002,578,576 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib.dll
[2014/08/03 11:24:06 | 002,197,264 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ.dll
[2014/08/03 11:24:06 | 001,868,944 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek.dll
[2014/08/03 11:24:06 | 001,718,616 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64A.dll
[2014/08/03 11:24:06 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2014/08/03 11:24:06 | 000,421,720 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64A.dll
[2014/08/03 11:24:06 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2014/08/03 11:24:06 | 000,341,336 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2014/08/03 11:24:06 | 000,334,680 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2014/08/03 11:24:06 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2014/08/03 11:24:06 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2014/08/03 11:24:06 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2014/08/03 11:24:06 | 000,220,496 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFNHK64.dll
[2014/08/03 11:24:06 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2014/08/03 11:24:06 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2014/08/03 11:24:06 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2014/08/03 11:24:06 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2014/08/03 11:24:06 | 000,127,832 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64A.dll
[2014/08/03 11:24:06 | 000,108,888 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64A.dll
[2014/08/03 11:24:06 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2014/08/03 11:24:06 | 000,081,232 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFCOM64.dll
[2014/08/03 11:24:06 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2014/08/03 11:24:06 | 000,078,160 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysNative\SFAPO64.dll
[2014/08/03 11:24:06 | 000,074,584 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64A.dll
[2014/08/03 11:24:06 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
[2014/08/03 11:24:05 | 001,937,312 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2014/08/03 11:24:05 | 001,327,208 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2014/08/03 11:24:05 | 001,179,752 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2014/08/03 11:24:05 | 001,111,656 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2014/08/03 11:24:05 | 000,504,936 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2014/08/03 11:24:05 | 000,491,112 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2014/08/03 11:24:05 | 000,475,752 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2014/08/03 11:24:05 | 000,317,032 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2014/08/03 11:24:05 | 000,269,928 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2014/08/03 11:24:05 | 000,266,856 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2014/08/03 11:24:05 | 000,126,056 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2014/08/03 11:24:05 | 000,125,544 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2014/08/03 11:24:05 | 000,125,032 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2014/08/03 11:24:05 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Temp
[2014/08/03 11:24:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\InstallShield
[2014/08/03 11:22:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\postureAgent
[2014/08/03 11:21:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Etron Technology
[2014/08/03 11:19:18 | 000,533,096 | ---- | C] (Realtek ) -- C:\Windows\SysNative\drivers\Rt64win7.sys
[2014/08/03 11:19:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Realtek
[2014/08/03 11:15:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gateway Documentation
[2014/08/03 11:15:28 | 000,000,000 | -H-D | C] -- C:\book
[2014/08/03 11:15:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2014/08/03 11:11:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2014/08/03 11:11:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Intel
[2014/08/03 11:10:28 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2014/08/03 11:08:04 | 000,000,000 | -HSD | C] -- C:\System Volume Information
========== Files - Modified Within 30 Days ==========
[2014/08/13 09:00:00 | 000,000,412 | ---- | M] () -- C:\Windows\tasks\Gateway Registration - Reminder Recall task.job
[2014/08/13 08:48:03 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/08/13 08:48:03 | 000,016,752 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/08/13 08:45:11 | 000,785,302 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/08/13 08:45:11 | 000,664,560 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/08/13 08:45:11 | 000,122,368 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/08/13 08:40:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/08/13 08:40:56 | 2072,203,263 | -HS- | M] () -- C:\hiberfil.sys
[2014/08/12 10:02:31 | 000,000,456 | ---- | M] () -- C:\Windows\wininit.ini
[2014/08/12 00:22:53 | 000,000,000 | ---- | M] () -- C:\Windows\tasks\Re-markit Update.job
[2014/08/12 00:22:51 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014/08/12 00:22:50 | 000,000,000 | ---- | M] () -- C:\Windows\tasks\Re-markit_wd.job
[2014/08/12 00:20:22 | 000,000,000 | ---- | M] () -- C:\END
[2014/08/12 00:20:16 | 000,012,288 | ---- | M] () -- C:\Windows\SysWow64\net_freamwork.dll
[2014/08/11 07:37:48 | 000,798,048 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/08/10 16:06:30 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014/08/08 20:39:56 | 000,002,508 | ---- | M] () -- C:\Users\Public\Desktop\Norton Internet Security.lnk
[2014/08/08 20:39:46 | 001,883,545 | ---- | M] () -- C:\Windows\SysNative\drivers\NISx64\1309010.00E\Cat.DB
[2014/08/05 08:53:07 | 000,082,340 | ---- | M] () -- C:\Users\theroufamily\Documents\rentalagreement.pdf
[2014/08/03 22:40:44 | 000,175,736 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS
[2014/08/03 22:40:44 | 000,007,488 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.CAT
[2014/08/03 22:40:44 | 000,000,855 | ---- | M] () -- C:\Windows\SysNative\drivers\SYMEVENT64x86.INF
[2014/08/03 20:28:38 | 000,416,712 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/08/03 18:59:32 | 000,001,926 | ---- | M] () -- C:\Users\theroufamily\Desktop\Warface Launcher.lnk
[2014/08/03 16:03:52 | 000,001,418 | ---- | M] () -- C:\Users\theroufamily\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/08/03 13:55:21 | 000,016,284 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2014/08/03 13:55:20 | 000,016,284 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2014/08/03 12:33:35 | 000,001,967 | ---- | M] () -- C:\Users\Public\Desktop\Netflix.lnk
[2014/08/03 12:29:55 | 000,108,227 | ---- | M] () -- C:\Windows\SysWow64\license.rtf
[2014/08/03 12:29:55 | 000,108,227 | ---- | M] () -- C:\Windows\SysNative\license.rtf
[2014/08/03 11:56:55 | 000,011,453 | ---- | M] () -- C:\Windows\ChangeLang_Done.tag
[2014/08/03 11:32:12 | 000,001,215 | ---- | M] () -- C:\Users\Public\Desktop\NOOK for PC.lnk
[2014/08/03 11:15:21 | 000,019,100 | ---- | M] () -- C:\Windows\SysNative\results.xml
[2014/07/16 09:42:28 | 000,057,528 | ---- | M] (Corsica) -- C:\Windows\SysNative\drivers\webinstr.sys
========== Files Created - No Company Name ==========
[2014/08/12 10:02:24 | 000,000,456 | ---- | C] () -- C:\Windows\wininit.ini
[2014/08/12 00:24:19 | 000,002,669 | ---- | C] () -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Search.lnk
[2014/08/12 00:22:53 | 000,000,000 | ---- | C] () -- C:\Windows\tasks\Re-markit Update.job
[2014/08/12 00:22:51 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_webinstr_01009.Wdf
[2014/08/12 00:22:50 | 000,000,000 | ---- | C] () -- C:\Windows\tasks\Re-markit_wd.job
[2014/08/12 00:20:22 | 000,000,000 | ---- | C] () -- C:\END
[2014/08/12 00:20:16 | 000,012,288 | ---- | C] () -- C:\Windows\SysWow64\net_freamwork.dll
[2014/08/10 16:06:30 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2014/08/05 08:53:07 | 000,082,340 | ---- | C] () -- C:\Users\theroufamily\Documents\rentalagreement.pdf
[2014/08/03 18:59:32 | 000,001,926 | ---- | C] () -- C:\Users\theroufamily\Desktop\Warface Launcher.lnk
[2014/08/03 16:03:52 | 000,001,418 | ---- | C] () -- C:\Users\theroufamily\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2014/08/03 16:03:06 | 000,000,412 | ---- | C] () -- C:\Windows\tasks\Gateway Registration - Reminder Recall task.job
[2014/08/03 14:05:38 | 000,798,048 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/08/03 13:55:21 | 000,016,284 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2014/08/03 13:55:20 | 000,016,284 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2014/08/03 13:06:11 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2014/08/03 12:52:06 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2014/08/03 12:36:12 | 000,001,424 | ---- | C] () -- C:\Users\theroufamily\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2014/08/03 12:33:35 | 000,001,967 | ---- | C] () -- C:\Users\Public\Desktop\Netflix.lnk
[2014/08/03 12:32:14 | 000,000,930 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Times Reader.lnk
[2014/08/03 12:31:40 | 000,000,290 | ---- | C] () -- C:\Users\theroufamily\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2014/08/03 12:31:40 | 000,000,272 | ---- | C] () -- C:\Users\theroufamily\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2014/08/03 11:57:43 | 000,011,453 | ---- | C] () -- C:\Windows\ChangeLang_Done.tag
[2014/08/03 11:32:34 | 000,002,493 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2014/08/03 11:32:12 | 000,001,215 | ---- | C] () -- C:\Users\Public\Desktop\NOOK for PC.lnk
[2014/08/03 11:31:01 | 000,001,874 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
[2014/08/03 11:29:54 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2014/08/03 11:23:01 | 000,008,192 | ---- | C] () -- C:\Windows\SysNative\drivers\IntelMEFWVer.dll
[2014/08/03 11:19:18 | 000,074,272 | ---- | C] () -- C:\Windows\SysNative\RtNicProp64.dll
[2014/08/03 11:15:28 | 000,001,344 | ---- | C] () -- C:\Users\Public\Desktop\User's Guide.lnk
[2014/08/03 11:15:21 | 000,019,100 | ---- | C] () -- C:\Windows\SysNative\results.xml
[2014/08/03 11:08:04 | 2072,203,263 | -HS- | C] () -- C:\hiberfil.sys
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 19:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 19:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 18:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 20:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 18:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2014/08/03 12:36:19 | 000,000,000 | ---D | M] -- C:\Users\theroufamily\AppData\Roaming\OEM
========== Purity Check ==========
< End of report >