I downloaded a program and it installed all kinds of junkware, and corupted my system file. I was able to get my system to turn back on and boot, but I still beleive there might be some more issues. The malware had deleted all my restore files and had deleted my hosts file as well as many other files.
The time of the software install that caused all this was 9/27/2014 about 5:00pm
Currently on my 2nd hard disk it is showing a System Volume Information folder even though I have the DO not show hidden and the hide system protected files checked. Also my main system drive C: is now appears to have more files since the available space has drastily reduced.
here is a copy of the OLT report:
er OTL logfile created on: 9/28/2014 11:47:33 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Users\Pickett_Kevin\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17239)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
15.90 Gb Total Physical Memory | 13.29 Gb Available Physical Memory | 83.59% Memory free
31.80 Gb Paging File | 28.90 Gb Available in Paging File | 90.89% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 111.69 Gb Total Space | 50.96 Gb Free Space | 45.63% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 693.57 Gb Free Space | 74.46% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 342.63 Gb Free Space | 73.56% Space Free | Partition Type: NTFS
Drive G: | 465.76 Gb Total Space | 55.21 Gb Free Space | 11.85% Space Free | Partition Type: NTFS
Computer Name: ASUS_I7 | User Name: Pickett_Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Users\Pickett_Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - D:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\EC Simulator.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe ()
PRC - C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe ()
PRC - C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (ASUSTek Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\AI Suite II.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\AsRoutineController.exe (ASUSTeK Computer Inc.)
PRC - D:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe (Schneider Electric)
PRC - D:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe (Schneider Electric)
PRC - D:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe (Schneider Electric)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\AlertHelper.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\TurboVHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\DIGI+ VRM\VRMHelp.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pnSvc.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files (x86)\ASUS\AI Suite II\EPU\EPUHelp.exe (ASUSTeK Computer Inc.)
========== Modules (No Company Name) ==========
MOD - D:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\HookKey32.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\CpuFreq.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\aaHMLib.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AssistFunc.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsMultiLang.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzUpdt.exe ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EzULIB.dll ()
MOD - C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMLib.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\EasyUpdt.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor Graph\SensorGraph.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\Sensor.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\BarGadget\BarGadget.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TabGadget\TabGadget.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\AI Charger+\AIChargerPlus.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Settings\Settings.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Splitter\Splitter.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\AssistFunc.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Bluetooth Go!\BluetoothGO.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Probe_II\ProbeII.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\MyLogo\MyLogo.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\aaHMLib.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\ImageHelper.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\iPhone Simulator\AsNetlib.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\ImageHelper.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\EasyUpdate\ImageHelper.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\Sensor\AlertHelper\pngio.dll ()
MOD - C:\Program Files (x86)\ASUS\AI Suite II\TurboV EVO\pngio.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (Intel® -- C:\Windows\SysNative\IPROSetMonitor.exe (Intel Corporation)
SRV:64bit: - (NisSrv) -- C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (VsEtwService120) -- C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (rpcapd) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV:64bit: - (DTSAudioService) -- C:\Program Files\Realtek\Audio\HDA\DTSAudioService64.exe (DTS)
SRV:64bit: - (c2wts) -- C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (simptcp) -- C:\Windows\SysNative\TCPSVCS.EXE (Microsoft Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (TeamViewer9) -- C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (BlueIris) -- D:\Program Files (x86)\Blue Iris 3\BlueIrisService.exe ()
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) -- C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (cphs) -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software LLC)
SRV - (LightShow Pro Service) -- D:\Program Files\Minleon\LightShowPro\LightShowProService.exe (Minleon International Ltd.)
SRV - (Garmin Core Update Service) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Garmin Ltd or its subsidiaries)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Te.Service) -- C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe (Microsoft Corporation)
SRV - (fussvc) -- C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe (Microsoft Corporation)
SRV - (Macromedia Licensing Service) -- C:\Program Files (x86)\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe ()
SRV - (asComSvc) -- C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe ()
SRV - (AsSysCtrlService) -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.13\AsSysCtrlService.exe (ASUSTeK Computer Inc.)
SRV - (RealNetworks Downloader Resolver Service) -- C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (asHmComSvc) -- C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe (ASUSTeK Computer Inc.)
SRV - (NAUpdate) -- C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (ICCS) -- C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe (Intel Corporation)
SRV - (APC Data Service) -- D:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe (Schneider Electric)
SRV - (APC UPS Service) -- D:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe (Schneider Electric)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (AtherosSvc) -- C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (WAS) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (W3SVC) -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (x10nets) -- C:\Program Files (x86)\Common Files\X10\Common\X10nets.exe (X10)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (HPSLPSVC) -- D:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard Co.)
SRV - (simptcp) -- C:\Windows\SysWOW64\TCPSVCS.EXE (Microsoft Corporation)
SRV - (Microsoft Office Groove Audit Service) -- D:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (rpcapd) -- C:\Program Files (x86)\WinPcap\rpcapd.exe ()
========== Driver Services (SafeList) ==========
DRV:64bit: - (SMUpdd) -- C:\Program Files\Common Files\Goobzo\GBUpdate\smw.sys File not found
DRV:64bit: - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV:64bit: - (voxaldriver) -- C:\Windows\SysNative\drivers\voxaldriverx64.sys ()
DRV:64bit: - (MBAMWebAccessControl) -- C:\Windows\SysNative\drivers\mwac.sys (Malwarebytes Corporation)
DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (e1cexpress) -- C:\Windows\SysNative\drivers\e1c62x64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (ScreamBAudioSvc) -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC)
DRV:64bit: - (FTSER2K) -- C:\Windows\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (Ser2pl) -- C:\Windows\SysNative\drivers\ser2pl64.sys (Prolific Technology Inc.)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (FTDIBUS) -- C:\Windows\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (ICCWDT) -- C:\Windows\SysNative\drivers\ICCWDT.sys (Intel Corporation)
DRV:64bit: - (teamviewervpn) -- C:\Windows\SysNative\drivers\teamviewervpn.sys (TeamViewer GmbH)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (DFX11_1) -- C:\Windows\SysNative\drivers\dfx11_1x64.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (terminpt) -- C:\Windows\SysNative\drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) -- C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (NPF) -- C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Rovi Corporation)
DRV:64bit: - (asmtxhci) -- C:\Windows\SysNative\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV:64bit: - (asmthub3) -- C:\Windows\SysNative\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BtFilter) -- C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) -- C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) -- C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) -- C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) -- C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (ATHDFU) -- C:\Windows\SysNative\drivers\AthDfu.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AthBTPort) -- C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_BUS) -- C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (tsusbhub) -- C:\Windows\SysNative\drivers\tsusbhub.sys (Microsoft Corporation)
DRV:64bit: - (Synth3dVsc) -- C:\Windows\SysNative\drivers\Synth3dVsc.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) -- C:\Windows\SysNative\drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (AiChargerPlus) -- C:\Windows\SysNative\drivers\AiChargerPlus.sys (ASUSTek Computer Inc.)
DRV:64bit: - (MEIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (nm3) -- C:\Windows\SysNative\drivers\nm3.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (61883) -- C:\Windows\SysNative\drivers\61883.sys (Microsoft Corporation)
DRV:64bit: - (Avc) -- C:\Windows\SysNative\drivers\avc.sys (Microsoft Corporation)
DRV:64bit: - (MSDV) -- C:\Windows\SysNative\drivers\msdv.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (X10Hid) -- C:\Windows\SysNative\drivers\x10hid.sys (X10 Wireless Technology, Inc.)
DRV - (AFS) -- C:\Windows\SysWow64\drivers\AFS.SYS (Oak Technology Inc.)
DRV - (AiChargerPlus) -- C:\Windows\SysWOW64\drivers\AiChargerPlus.sys (ASUSTek Computer Inc.)
DRV - (cpudrv64) -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPF) -- C:\Windows\SysWOW64\drivers\npf.sys (Politecnico di Torino)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = DB BF 96 AA 9F D2 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "yahoo.com"
FF - prefs.js..extensions.enabledAddons: web2pdfextension%40web2pdf.adobedotcom:2.0
FF - prefs.js..extensions.enabledAddons: NoiaScrollbars%40ArisT2_Noia4dev:1.2.1
FF - prefs.js..extensions.enabledAddons: Noia4Options%40ArisT2:2.0.0
FF - prefs.js..extensions.enabledAddons: %7Bfaf13420-5e24-11e0-80e3-0800200c9a66%7D:2.0.0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_152.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.40.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: D:\Program Files\AdobeCS6\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1213153.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@IPCWebComponents: C:\Program Files (x86)\IPCWebComponents\npIPCReg.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.67.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3508.0205: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: D:\Program Files (x86)\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: D:\Program Files (x86)\RealPlayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeExManDetect: D:\Program Files\AdobeCS6\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll (Adobe Systems)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/07/30 16:09:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/07/30 16:09:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2014/07/16 11:15:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 24.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/09/16 16:04:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Components: D:\Program Files (x86)\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 32.0.3\extensions\\Plugins: D:\Program Files (x86)\Mozilla Firefox\plugins [2014/09/25 14:53:49 | 000,000,000 | ---D | M]
[2013/06/15 17:01:11 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\Extensions
[2014/09/17 11:28:23 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\Firefox\Profiles\axnvanjm.default-1410973686164.backup\extensions
[2014/09/22 18:29:42 | 000,000,000 | ---D | M] (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\Firefox\Profiles\j9cpfgrv.Kevin\extensions
[2014/09/17 11:48:00 | 000,000,000 | ---D | M] (Garmin Communicator) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\Firefox\Profiles\j9cpfgrv.Kevin\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2014/09/17 11:48:00 | 000,000,000 | ---D | M] (DownloadHelper) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\Firefox\Profiles\j9cpfgrv.Kevin\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2014/09/17 11:26:01 | 000,088,730 | R--- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\axnvanjm.default-1410973686164.backup\extensions\[email protected]
[2014/09/17 11:26:38 | 000,084,390 | ---- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\axnvanjm.default-1410973686164.backup\extensions\NoiaButtons@ArisT2_Noia4dev.xpi
[2014/09/17 11:28:23 | 000,095,335 | ---- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\axnvanjm.default-1410973686164.backup\extensions\NoiaScrollbars@ArisT2_Noia4dev.xpi
[2014/09/17 11:26:01 | 001,493,384 | R--- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\axnvanjm.default-1410973686164.backup\extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi
[2014/06/05 14:23:23 | 000,024,427 | ---- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\j9cpfgrv.Kevin\extensions\[email protected]
[2013/09/12 14:20:33 | 000,066,667 | ---- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\j9cpfgrv.Kevin\extensions\[email protected]
[2014/06/05 14:23:03 | 000,088,730 | R--- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\j9cpfgrv.Kevin\extensions\[email protected]
[2014/06/05 14:23:52 | 000,095,335 | ---- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\j9cpfgrv.Kevin\extensions\NoiaScrollbars@ArisT2_Noia4dev.xpi
[2014/06/05 14:23:03 | 001,493,384 | R--- | M] () (No name found) -- D:\Users\Pickett_Kevin\AppData\Roaming\mozilla\firefox\profiles\j9cpfgrv.Kevin\extensions\{faf13420-5e24-11e0-80e3-0800200c9a66}.xpi
[2013/09/19 09:46:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/09/19 09:46:55 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014/07/16 11:15:26 | 000,000,000 | ---D | M] (Adobe Acrobat - Create PDF) -- C:\PROGRAM FILES (X86)\ADOBE\ACROBAT 11.0\ACROBAT\BROWSER\WCFIREFOXEXTN
File not found (No name found) -- D:\USERS\PICKETT_KEVIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AXNVANJM.DEFAULT-1410973686164\EXTENSIONS\[email protected]
File not found (No name found) -- D:\USERS\PICKETT_KEVIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AXNVANJM.DEFAULT-1410973686164\EXTENSIONS\NOIASCROLLBARS@ARIST2_NOIA4DEV.XPI
========== Chrome ==========
CHR - default_search_provider: (Enabled)
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
CHR - plugin: Error reading preferences file
CHR - Extension: Google Docs = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.7_0\
CHR - Extension: Google Drive = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Google Voice Search Hotword (Beta) = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5023_0\
CHR - Extension: YouTube = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Adobe Acrobat - Create PDF = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj\11.0.6.70_0\
CHR - Extension: RealDownloader = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0\
CHR - Extension: Google Wallet = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Gmail = D:\Users\Pickett_Kevin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2014/09/28 11:21:21 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2:64bit: - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Microsoft Web Test Recorder 12.0 Helper) - {432dd630-7e03-4c97-9d62-b99f52df4fc2} - D:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe Acrobat Create PDF Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Adobe Acrobat Create PDF from Selection) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe Acrobat Create PDF Toolbar) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Classic Start Menu] C:\Program Files\Classic Shell\ClassicStartMenu.exe (IvoSoft)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RtHDVBg_DTS] C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ASUS AiChargerPlus Execute] C:\Program Files (x86)\InstallShield Installation Information\{E6931688-DA2B-4E16-8539-3D323D69C677}\AiChargerPlus.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUS ShellProcess Execute] C:\Program Files (x86)\ASUS\AI Suite II\ASUS Mobilink\Simulator\AsShellProcess.exe (ASUSTeK Computer Inc.)
O4 - HKLM..\Run: [Display] D:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe (Schneider Electric)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{AFC8591B-E7F1-4BD8-A1DC-865FF0C3EF2C}: NameServer = 10.0.0.1,8.8.8.8
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/09/28 11:45:55 | 000,602,112 | ---- | C] (OldTimer Tools) -- D:\Users\Pickett_Kevin\Desktop\OTL.exe
[2014/09/28 11:21:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2014/09/28 11:06:51 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/09/28 10:29:28 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RegZooka
[2014/09/27 19:37:45 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Branding
[2014/09/27 19:17:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\globalUpdate
[2014/09/27 17:02:12 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Documents\ProPCCleaner
[2014/09/27 13:16:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Blue Iris ActiveX Control
[2014/09/25 19:18:24 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Local\Moonware_Studios
[2014/09/25 19:17:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2014/09/25 19:17:46 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.2013-06.com.moonware
[2014/09/25 07:06:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Deskshare
[2014/09/22 18:33:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IPCWebComponents
[2014/09/22 18:33:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IPCWebComponents
[2014/09/22 11:55:05 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Desktop\Foscam Utilities
[2014/09/18 14:14:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Screaming Bee
[2014/09/17 11:06:08 | 000,000,000 | -HSD | C] -- D:\Users\Pickett_Kevin\AppData\Local\EmieUserList
[2014/09/17 11:06:08 | 000,000,000 | -HSD | C] -- D:\Users\Pickett_Kevin\AppData\Local\EmieSiteList
[2014/09/17 10:44:48 | 002,050,560 | ---- | C] (xy-VSFilter Team) -- C:\Windows\SysNative\VSFilter.dll.bak
[2014/09/17 10:44:29 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Roaming\Shark007
[2014/09/17 10:44:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Shark007
[2014/09/17 10:44:27 | 003,502,080 | ---- | C] (x264vfw project) -- C:\Windows\SysNative\x264vfw.dll
[2014/09/17 10:44:27 | 000,180,736 | ---- | C] (fccHandler) -- C:\Windows\SysNative\ac3acm.acm
[2014/09/17 10:44:26 | 001,712,512 | ---- | C] (MPC-BE Team) -- C:\Windows\SysNative\VSFilter.dll
[2014/09/17 10:44:26 | 000,361,472 | ---- | C] (fccHandler) -- C:\Windows\SysNative\aacacm.acm
[2014/09/17 10:44:26 | 000,124,909 | ---- | C] (Open Source Software community project) -- C:\Windows\SysNative\pthreadGC2.dll
[2014/09/17 10:44:07 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Roaming\Advanced
[2014/09/17 10:42:39 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Local\Installer
[2014/09/17 10:16:41 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Desktop\GOPRO
[2014/09/17 09:59:54 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Desktop\VLC
[2014/09/16 16:36:02 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2014/09/16 16:35:45 | 002,162,992 | ---- | C] (Yamaha Corporation) -- C:\Windows\SysNative\YamahaAE.dll
[2014/09/16 16:35:43 | 002,101,848 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\WavesGUILib64.dll
[2014/09/16 16:35:42 | 001,048,824 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\slcnt64.dll
[2014/09/16 16:35:42 | 000,724,728 | ---- | C] (DTS, Inc.) -- C:\Windows\SysNative\sltech64.dll
[2014/09/16 16:35:42 | 000,518,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSX64.dll
[2014/09/16 16:35:42 | 000,246,008 | ---- | C] (TODO: <Company name>) -- C:\Windows\SysNative\slprp64.dll
[2014/09/16 16:35:42 | 000,211,184 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSTSH64.dll
[2014/09/16 16:35:42 | 000,198,896 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSHP64.dll
[2014/09/16 16:35:42 | 000,155,888 | ---- | C] (SRS Labs, Inc.) -- C:\Windows\SysNative\SRSWOW64.dll
[2014/09/16 16:35:41 | 000,889,592 | ---- | C] (DTS, Inc.) -- C:\Windows\SysNative\sl3apo64.dll
[2014/09/16 16:35:41 | 000,221,024 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFNHK64.dll
[2014/09/16 16:35:41 | 000,081,248 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFCOM64.dll
[2014/09/16 16:35:41 | 000,078,688 | ---- | C] (Synopsys, Inc.) -- C:\Windows\SysNative\SFAPO64.dll
[2014/09/16 16:35:41 | 000,074,064 | ---- | C] (Virage Logic Corporation / Sonic Focus) -- C:\Windows\SysWow64\SFCOM.dll
[2014/09/16 16:35:40 | 000,375,128 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEP64A.dll
[2014/09/16 16:35:40 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DHT64.dll
[2014/09/16 16:35:40 | 000,310,104 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RP3DAA64.dll
[2014/09/16 16:35:40 | 000,204,120 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEED64A.dll
[2014/09/16 16:35:40 | 000,101,208 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEL64A.dll
[2014/09/16 16:35:40 | 000,078,680 | ---- | C] (Dolby Laboratories, Inc.) -- C:\Windows\SysNative\RTEEG64A.dll
[2014/09/16 16:35:39 | 007,164,176 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEP64A.dll
[2014/09/16 16:35:39 | 000,942,384 | ---- | C] (Nahimic Inc) -- C:\Windows\SysNative\NAHIMICAPOSettingsIPC.dll
[2014/09/16 16:35:39 | 000,434,960 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EED64A.dll
[2014/09/16 16:35:39 | 000,141,584 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEL64A.dll
[2014/09/16 16:35:39 | 000,124,176 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEA64A.dll
[2014/09/16 16:35:39 | 000,075,024 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\R4EEG64A.dll
[2014/09/16 16:35:38 | 012,894,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVoiceAPO3064.dll
[2014/09/16 16:35:38 | 005,751,048 | ---- | C] (Nahimic Inc) -- C:\Windows\SysNative\NAHIMICAPOlfx.dll
[2014/09/16 16:35:38 | 003,959,384 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioVnN64.dll
[2014/09/16 16:35:38 | 001,313,904 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxSpeechAPO64.dll
[2014/09/16 16:35:38 | 000,956,504 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVoiceAPO2064.dll
[2014/09/16 16:35:38 | 000,662,784 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxVolumeSDAPO.dll
[2014/09/16 16:35:37 | 028,343,384 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioVnA64.dll
[2014/09/16 16:35:37 | 014,863,448 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek64.dll
[2014/09/16 16:35:37 | 002,041,432 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioEQ64.dll
[2014/09/16 16:35:37 | 001,934,424 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioRealtek264.dll
[2014/09/16 16:35:37 | 001,317,976 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO6064.dll
[2014/09/16 16:35:37 | 001,168,472 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO5064.dll
[2014/09/16 16:35:37 | 001,136,728 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO4064.dll
[2014/09/16 16:35:37 | 001,063,512 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPOShell64.dll
[2014/09/16 16:35:37 | 000,900,696 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysWow64\MaxxAudioAPOShell.dll
[2014/09/16 16:35:37 | 000,663,296 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO30.dll
[2014/09/16 16:35:37 | 000,318,808 | ---- | C] (Waves Audio Ltd.) -- C:\Windows\SysNative\MaxxAudioAPO20.dll
[2014/09/16 16:35:36 | 002,770,976 | ---- | C] (Fortemedia Corporation) -- C:\Windows\SysNative\FMAPO64.dll
[2014/09/16 16:35:36 | 001,756,264 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2SpeakerDLL64.dll
[2014/09/16 16:35:36 | 001,568,360 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSS2HeadphoneDLL64.dll
[2014/09/16 16:35:36 | 000,712,296 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSSymmetryDLL64.dll
[2014/09/16 16:35:36 | 000,693,352 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSVoiceClarityDLL64.dll
[2014/09/16 16:35:36 | 000,603,984 | ---- | C] (Knowles Acoustics ) -- C:\Windows\SysNative\KAAPORT64.dll
[2014/09/16 16:35:36 | 000,501,184 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PLFX64.dll
[2014/09/16 16:35:36 | 000,487,360 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PGFX64.dll
[2014/09/16 16:35:36 | 000,415,680 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSU2PREC64.dll
[2014/09/16 16:35:36 | 000,291,488 | ---- | C] (ICEpower a/s) -- C:\Windows\SysNative\ICEsoundAPO64.dll
[2014/09/16 16:35:35 | 006,218,072 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\DDPP64A.dll
[2014/09/16 16:35:35 | 001,939,800 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\DDPD64A.dll
[2014/09/16 16:35:35 | 001,486,952 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBoostDLL64.dll
[2014/09/16 16:35:35 | 000,728,680 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSBassEnhancementDLL64.dll
[2014/09/16 16:35:35 | 000,491,112 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSNeoPCDLL64.dll
[2014/09/16 16:35:35 | 000,432,744 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLimiterDLL64.dll
[2014/09/16 16:35:35 | 000,428,648 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGainCompensatorDLL64.dll
[2014/09/16 16:35:35 | 000,315,736 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\DDPO64A.dll
[2014/09/16 16:35:35 | 000,261,464 | ---- | C] (Dolby Laboratories) -- C:\Windows\SysNative\DDPA64.dll
[2014/09/16 16:35:35 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSLFXAPO64.dll
[2014/09/16 16:35:35 | 000,242,792 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPO64.dll
[2014/09/16 16:35:35 | 000,241,768 | ---- | C] (DTS) -- C:\Windows\SysNative\DTSGFXAPONS64.dll
[2014/09/16 16:35:35 | 000,113,576 | ---- | C] (Real Sound Lab SIA) -- C:\Windows\SysNative\CONEQMSAPOGUILibrary.dll
[2014/09/16 16:25:15 | 000,000,000 | ---D | C] -- C:\Program Files\Intel
[2014/09/16 16:16:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SystemRequirementsLab
[2014/09/14 14:43:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2014/09/14 14:43:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
[2014/09/14 14:43:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2014/09/11 12:29:04 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\AppData\Roaming\JVSG
[2014/09/10 18:06:09 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Documents\Security Monitor Pro
[2014/09/10 18:02:40 | 025,784,672 | ---- | C] (DeskShare Inc. ) -- D:\Users\Pickett_Kevin\Desktop\SecurityMonitorPro.exe
[2014/09/01 15:16:09 | 000,000,000 | ---D | C] -- D:\Users\Pickett_Kevin\Speech Software
[2014/08/29 14:54:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014/08/29 13:38:21 | 000,460,800 | ---- | C] (RedfernPlace) -- D:\Users\Pickett_Kevin\Desktop\PathEditor.exe
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/09/28 11:45:55 | 000,602,112 | ---- | M] (OldTimer Tools) -- D:\Users\Pickett_Kevin\Desktop\OTL.exe
[2014/09/28 11:41:18 | 000,042,563 | ---- | M] () -- D:\Users\Pickett_Kevin\IP_Log_Data.js
[2014/09/28 11:41:18 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/09/28 11:41:11 | 000,122,584 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/09/28 11:40:58 | 4214,075,390 | -HS- | M] () -- C:\hiberfil.sys
[2014/09/28 11:40:06 | 000,000,028 | ---- | M] () -- D:\Users\Pickett_Kevin\AppData\Roaming\Network Meter_Usage.ini
[2014/09/28 11:39:04 | 001,373,475 | ---- | M] () -- D:\Users\Pickett_Kevin\Desktop\adwcleaner_3.310.exe
[2014/09/28 11:36:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/09/28 11:29:18 | 000,000,881 | ---- | M] () -- D:\Users\Pickett_Kevin\Desktop\Temp File Cleaner.lnk
[2014/09/28 11:21:21 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2014/09/28 10:29:29 | 000,000,859 | ---- | M] () -- D:\Users\Pickett_Kevin\Desktop\RegZooka.lnk
[2014/09/27 23:20:25 | 000,001,184 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/27 23:20:25 | 000,001,184 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/27 19:01:04 | 006,273,640 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/09/27 17:01:02 | 000,000,418 | ---- | M] () -- D:\Users\Pickett_Kevin\AppData\Roaming\WinInstallFlashLog.ini
[2014/09/18 13:35:46 | 000,034,512 | ---- | M] () -- C:\Windows\SysNative\drivers\voxaldriverx64.sys
[2014/09/16 16:36:11 | 000,000,000 | -H-- | M] () -- C:\ProgramData\DP45977C.lfl
[2014/09/16 16:30:06 | 000,020,754 | ---- | M] () -- C:\Windows\SysNative\results.xml
[2014/09/16 15:22:23 | 000,001,769 | ---- | M] () -- C:\Windows\Language_trs.ini
[2014/09/16 15:10:12 | 004,044,528 | ---- | M] () -- C:\Windows\PE_Rom.dll
[2014/09/14 17:14:45 | 000,221,184 | ---- | M] () -- D:\Users\Pickett_Kevin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/09/14 15:07:08 | 000,001,044 | ---- | M] () -- D:\Users\Pickett_Kevin\Desktop\Dropbox.lnk
[2014/09/13 12:01:36 | 000,008,324 | ---- | M] () -- D:\Users\Pickett_Kevin\Documents\security view.jvsg
[2014/09/13 10:35:08 | 025,784,672 | ---- | M] (DeskShare Inc. ) -- D:\Users\Pickett_Kevin\Desktop\SecurityMonitorPro.exe
[2014/09/01 22:37:52 | 001,712,512 | ---- | M] (MPC-BE Team) -- C:\Windows\SysNative\VSFilter.dll
[2014/08/29 14:53:52 | 000,002,155 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/08/29 12:41:17 | 000,001,852 | ---- | M] () -- D:\Users\Pickett_Kevin\Desktop\LOR Route Add.lnk
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/09/28 11:39:04 | 001,373,475 | ---- | C] () -- D:\Users\Pickett_Kevin\Desktop\adwcleaner_3.310.exe
[2014/09/28 10:29:29 | 000,000,859 | ---- | C] () -- D:\Users\Pickett_Kevin\Desktop\RegZooka.lnk
[2014/09/27 19:00:54 | 006,273,640 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/09/27 17:38:51 | 000,001,184 | -H-- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/09/27 17:38:51 | 000,001,184 | -H-- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/09/27 17:35:49 | 000,000,028 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\Network Meter_Usage.ini
[2014/09/27 17:01:00 | 000,000,418 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\WinInstallFlashLog.ini
[2014/09/24 15:54:37 | 000,001,646 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Iris 3.lnk
[2014/09/18 13:35:46 | 000,034,512 | ---- | C] () -- C:\Windows\SysNative\drivers\voxaldriverx64.sys
[2014/09/17 10:44:27 | 000,148,992 | ---- | C] ( ) -- C:\Windows\SysNative\lagarith.dll
[2014/09/17 10:44:26 | 002,231,296 | ---- | C] () -- C:\Windows\SysNative\ac3filter.acm.new
[2014/09/17 10:44:26 | 002,231,296 | ---- | C] () -- C:\Windows\SysNative\ac3filter.acm
[2014/09/17 10:44:26 | 000,580,096 | ---- | C] () -- C:\Windows\SysNative\ac3filter.acm.old
[2014/09/17 10:44:26 | 000,206,336 | ---- | C] () -- C:\Windows\SysNative\unrar64.dll
[2014/09/17 10:44:19 | 001,679,360 | ---- | C] () -- C:\Windows\SysWow64\ac3filter.acm.new
[2014/09/16 16:36:11 | 000,000,000 | -H-- | C] () -- C:\ProgramData\DP45977C.lfl
[2014/09/16 16:35:42 | 002,117,424 | ---- | C] () -- C:\Windows\SysNative\SStudio.dll
[2014/09/16 16:35:41 | 005,804,772 | ---- | C] () -- C:\Windows\SysNative\drivers\rtvienna.dat
[2014/09/16 16:35:40 | 001,099,203 | ---- | C] () -- C:\Windows\SysNative\drivers\RTAIODAT.DAT
[2014/09/16 16:35:35 | 000,109,848 | ---- | C] () -- C:\Windows\SysNative\AcpiServiceVnA64.dll
[2014/09/16 16:35:35 | 000,033,592 | ---- | C] () -- C:\Windows\SysNative\audioLibVc.dll
[2014/09/13 11:58:47 | 000,008,324 | ---- | C] () -- D:\Users\Pickett_Kevin\Documents\security view.jvsg
[2014/08/20 15:53:21 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2014/08/20 15:53:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2014/08/20 15:53:21 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2014/08/20 15:53:21 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2014/08/20 15:53:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2014/08/07 16:10:36 | 000,000,351 | ---- | C] () -- C:\Windows\editor.INI
[2014/08/07 15:56:02 | 000,003,316 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\DosPanel.ini
[2014/07/10 08:53:59 | 000,000,039 | ---- | C] () -- C:\Windows\nap.ini
[2014/05/06 10:35:04 | 000,026,955 | ---- | C] () -- D:\Users\Pickett_Kevin\Chi.jpg
[2014/03/29 11:43:49 | 004,583,074 | ---- | C] () -- D:\Users\Pickett_Kevin\e8319_ME302C_em.pdf
[2014/03/20 08:40:40 | 000,078,848 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014/03/19 10:56:23 | 000,001,456 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Local\Adobe Save for Web 13.0 Prefs
[2014/02/25 17:56:42 | 000,000,360 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\com.iliumsoft.ewallet.plist
[2014/02/13 12:07:22 | 000,737,484 | ---- | C] () -- D:\Users\Pickett_Kevin\ResEdit-x64.zip
[2014/02/13 12:05:15 | 005,546,433 | ---- | C] () -- D:\Users\Pickett_Kevin\ResourceEditor20110910.zip
[2014/02/12 15:49:02 | 000,036,738 | ---- | C] () -- D:\Users\Pickett_Kevin\Pickett_Lan IPs to Mac.xml
[2014/01/29 17:43:46 | 000,221,184 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/01/28 18:17:57 | 000,002,353 | ---- | C] () -- D:\Users\Pickett_Kevin\mkvreg.reg
[2014/01/28 11:59:12 | 000,000,104 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.64.bc
[2014/01/27 14:52:32 | 000,000,298 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2013/12/06 15:13:08 | 000,042,563 | ---- | C] () -- D:\Users\Pickett_Kevin\IP_Log_Data.js
[2013/12/05 11:32:31 | 000,000,132 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2013/11/29 20:51:49 | 000,000,132 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\Adobe BMP Format CS6 Prefs
[2013/10/30 09:48:32 | 000,010,443 | ---- | C] () -- C:\ProgramData\regid.2009-06.com.flexerasoftware_E8544335-72A1-47D2-B281-75B66D03EF81.swidtag
[2013/10/28 12:17:59 | 000,000,232 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
[2013/10/15 15:50:35 | 000,002,099 | ---- | C] () -- D:\Users\Pickett_Kevin\.xmlcopyeditor
[2013/10/04 18:27:03 | 000,002,376 | -H-- | C] () -- C:\Windows\SysWow64\oeiwsc27.dll
[2013/10/02 13:07:45 | 000,000,600 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\winscp.rnd
[2013/10/02 12:55:54 | 000,000,600 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Local\PUTTY.RND
[2013/09/29 16:12:06 | 004,175,360 | ---- | C] () -- C:\Windows\SysWow64\LS3Renderer.dll
[2013/09/06 15:58:58 | 000,007,619 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Local\Resmon.ResmonCfg
[2013/07/22 12:23:33 | 000,000,504 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2013/07/18 13:47:47 | 000,000,634 | ---- | C] () -- C:\Program Files (x86)\CsdIIMatrixSign.mdl
[2013/06/27 18:19:59 | 000,149,504 | ---- | C] () -- C:\Windows\unwise32_setup.exe
[2013/06/22 14:33:24 | 000,776,536 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2013/06/17 14:36:18 | 000,127,184 | ---- | C] () -- C:\Windows\Unwise.exe
[2013/06/17 12:46:20 | 000,205,028 | ---- | C] () -- C:\Windows\hpwins26.dat
[2013/06/17 12:46:20 | 000,000,370 | ---- | C] () -- C:\Windows\hpwmdl26.dat
[2013/06/17 10:55:48 | 000,001,271 | ---- | C] () -- D:\Users\Pickett_Kevin\AppData\Roaming\Network Meter_Settings.ini
[2013/06/16 13:51:28 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2013/06/16 11:03:29 | 000,000,162 | ---- | C] () -- C:\Windows\ODBC.INI
[2013/06/15 13:49:59 | 004,044,528 | ---- | C] () -- C:\Windows\PE_Rom.dll
[2013/06/15 13:20:08 | 000,014,464 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsUpIO.sys
[2013/06/15 13:16:31 | 000,015,232 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2013/06/15 13:16:31 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2013/06/15 13:16:31 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2013/06/15 13:16:28 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2013/06/15 12:45:30 | 000,828,772 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/15 12:22:11 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013/06/14 10:50:24 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\MPMapTrace.dll
[2013/06/14 10:10:42 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\mpPathan.dll
[2013/03/28 20:13:14 | 000,798,734 | ---- | C] () -- C:\Windows\SysWow64\amdocl_ld32.exe
[2013/03/28 20:13:12 | 000,995,342 | ---- | C] () -- C:\Windows\SysWow64\amdocl_as32.exe
[2013/03/28 19:38:08 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2013/03/28 19:38:08 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2013/01/16 16:03:42 | 000,019,294 | ---- | C] () -- D:\Users\Pickett_Kevin\Invoice for GE Lights.pdf
[2012/12/14 02:42:30 | 000,963,452 | ---- | C] () -- C:\Windows\SysWow64\igcodeckrng600.bin
[2012/12/14 02:42:28 | 000,272,928 | ---- | C] () -- C:\Windows\SysWow64\igvpkrng600.bin
[2012/11/27 01:18:46 | 000,038,912 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 20:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 20:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll -- [2010/11/20 21:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/06/17 15:39:24 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\addpcs
[2014/09/17 10:44:59 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Advanced
[2013/12/20 11:00:09 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\ArKaos LEDMapper2
[2014/03/27 12:08:33 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\ArKaos MediaMaster
[2014/08/29 13:16:57 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Audacity
[2014/07/10 09:37:28 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Audio Visual Devices
[2014/03/25 12:31:56 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\AxTools
[2013/11/04 15:14:42 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\CDXReader
[2013/10/22 15:06:26 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\chc
[2013/06/17 09:25:54 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2014/09/28 11:02:49 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\ClassicShell
[2013/06/17 09:25:54 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2013/09/29 14:41:42 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\com.adobe.WidgetBrowser
[2013/08/08 13:05:02 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\com.comcast.callerid
[2013/08/08 13:03:17 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\com.comcast.callerid.13A1FA90F0FC9DC009FB0956ADD0F13F8608561B.1
[2013/09/26 16:39:55 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Digiarty
[2014/07/30 13:51:22 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\DLA
[2014/01/29 12:19:42 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Doena Soft
[2014/09/14 15:07:17 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Dropbox
[2014/03/19 19:56:28 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\FalconHardwareUtility
[2014/09/14 15:04:52 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\FileZilla
[2014/01/01 12:39:33 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Garmin
[2014/05/11 11:24:39 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\GoPro
[2013/06/17 09:25:54 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Ilium Software
[2014/09/16 13:17:11 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Jovian
[2014/09/11 12:29:04 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\JVSG
[2013/11/04 15:14:43 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\LavFilters
[2013/11/18 20:32:10 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\LightFactory
[2014/08/25 16:49:56 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\LOROC
[2014/03/17 15:43:44 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Mael
[2014/07/30 14:37:40 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Microchip
[2013/09/17 12:38:43 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\MOVAVI
[2014/09/27 18:20:40 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Notepad++
[2014/03/06 15:01:39 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\NuGet
[2013/10/05 11:21:02 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Oracle
[2013/06/17 09:25:55 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\PACE Anti-Piracy
[2014/02/09 18:43:34 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\PowerISO
[2013/10/24 18:11:44 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Publish Providers
[2013/10/28 12:43:08 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Reasonable Software House Ltd
[2013/09/29 16:10:41 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Red Giant Link
[2013/09/29 13:14:50 | 000,000,000 | -H-D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\RWBYTE
[2014/09/17 10:44:36 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Shark007
[2014/08/15 11:43:43 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\SolidDocuments
[2013/10/29 11:07:26 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Sony
[2013/09/17 16:39:41 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2013/10/15 15:33:22 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Stylus Studio
[2013/07/30 16:21:28 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Syncios
[2013/07/18 13:43:56 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Tape_Worm
[2014/09/27 17:23:12 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\TeamViewer
[2014/09/18 15:58:17 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\uTorrent
[2014/03/27 12:13:53 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Video Mapper
[2013/12/19 15:23:15 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Vixen
[2013/10/09 15:53:45 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\Wireshark
[2014/03/19 11:41:32 | 000,000,000 | ---D | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\wyUpdate
[2014/03/19 11:41:07 | 000,000,000 | -HSD | M] -- D:\Users\Pickett_Kevin\AppData\Roaming\wyUpdate AU
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 1365 bytes -> C:\ProgramData\Microsoft:samtzRLIBVKz7rdE75K7cU9INCI5
@Alternate Data Stream - 1313 bytes -> C:\ProgramData\Microsoft:5RuzemZJUnDfIYE0mNXI
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:054203E4
@Alternate Data Stream - 1192 bytes -> C:\ProgramData\Microsoft:aarOOjjTtyI2F13dwmqha
@Alternate Data Stream - 1188 bytes -> C:\ProgramData\Microsoft:klccog60WQXGKv8gv4QzeoD
< End of report >
Thank you
Kevin
Edited by pickett, 28 September 2014 - 12:03 PM.