gammo,
Thanks for your help !
OTL logfile created on: 6/4/2012 8:43:34 AM - Run 2
OTL by OldTimer - Version 3.2.46.0 Folder = C:\Users\Patrick\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.98 Gb Total Physical Memory | 6.11 Gb Available Physical Memory | 76.52% Memory free
15.96 Gb Paging File | 13.81 Gb Available in Paging File | 86.54% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1384.23 Gb Total Space | 1328.71 Gb Free Space | 95.99% Space Free | Partition Type: NTFS
Drive D: | 12.94 Gb Total Space | 1.59 Gb Free Space | 12.29% Space Free | Partition Type: NTFS
Drive E: | 4.38 Gb Total Space | 1.50 Gb Free Space | 34.24% Space Free | Partition Type: UDF
Computer Name: PATRICK-HP | User Name: Patrick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/06/04 08:42:49 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Patrick\Desktop\OTL.exe
PRC - [2012/06/02 05:29:23 | 000,351,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/03/27 19:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton 360\Engine\6.2.1.5\ccsvchst.exe
PRC - [2012/03/21 17:35:40 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2012/03/21 17:35:40 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2012/02/22 23:49:58 | 006,591,800 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/10/01 12:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2011/10/01 12:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2011/05/06 17:07:18 | 000,460,144 | ---- | M] () -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe
PRC - [2011/03/28 21:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2010/09/28 12:09:28 | 001,119,768 | ---- | M] (PDF Complete Inc) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe
PRC - [2010/09/11 05:02:22 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/03/18 14:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/10/07 04:47:22 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/01/26 15:31:16 | 002,144,088 | ---- | M] (Safer Networking Limited) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2005/07/15 17:48:33 | 000,479,232 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
========== Modules (No Company Name) ========== MOD - [2012/02/22 23:49:56 | 000,921,600 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2012/02/22 23:49:38 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2012/01/31 17:56:29 | 000,204,288 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2011/11/17 02:33:55 | 000,031,232 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\lsass.exe -- (Netlogon)
SRV:
64bit: - [2010/11/20 09:27:23 | 000,476,160 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\QAGENTRT.DLL -- (napagent)
SRV:
64bit: - [2010/11/20 09:26:50 | 000,084,992 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\Mcx2Svc.dll -- (Mcx2Svc)
SRV:
64bit: - [2010/11/20 09:26:39 | 000,569,344 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\iphlpsvc.dll -- (iphlpsvc)
SRV:
64bit: - [2010/11/20 09:25:49 | 000,080,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\certprop.dll -- (CertPropSvc)
SRV:
64bit: - [2010/09/27 16:10:00 | 000,270,336 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:
64bit: - [2010/08/05 23:51:08 | 000,291,896 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:
64bit: - [2010/08/05 23:47:48 | 000,681,528 | ---- | M] (Hewlett-Packard) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe -- (HPAuto)
SRV:
64bit: - [2009/10/07 04:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:
64bit: - [2009/07/13 21:41:56 | 000,381,952 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\w32time.dll -- (W32Time)
SRV:
64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/13 21:41:27 | 000,097,792 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\mprdim.dll -- (RemoteAccess)
SRV:
64bit: - [2009/07/13 21:41:11 | 000,156,672 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\iscsiexe.dll -- (MSiSCSI)
SRV:
64bit: - [2009/07/13 21:39:41 | 000,014,336 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\snmptrap.exe -- (SNMPTRAP)
SRV:
64bit: - [2009/03/01 13:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2012/06/02 05:29:26 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/03/27 19:14:06 | 000,138,232 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton 360\Engine\6.2.1.5\ccSvcHst.exe -- (N360)
SRV - [2012/03/21 17:35:40 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2012/03/21 17:35:40 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/10/01 12:30:22 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2011/10/01 12:30:18 | 000,508,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2011/09/09 21:10:28 | 000,086,072 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2011/08/18 20:53:38 | 000,625,728 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe -- (RaMediaServer)
SRV - [2011/05/06 17:07:18 | 000,460,144 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2011/03/28 21:07:50 | 000,094,264 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe -- (HPDrvMntSvc.exe)
SRV - [2011/03/22 12:23:58 | 000,241,648 | ---- | M] (CyberLink) [Auto | Stopped] -- C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe -- (CLKMSVC10_C6F09094)
SRV - [2010/10/12 13:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/09/28 12:09:28 | 001,119,768 | ---- | M] (PDF Complete Inc) [Auto | Running] -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe -- (pdfcDispatcher)
SRV - [2010/09/11 05:02:22 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/06/01 19:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/03/18 16:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 14:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/07/13 21:15:41 | 000,075,264 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\mprdim.dll -- (RemoteAccess)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/10 16:39:58 | 000,089,920 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2012/05/02 13:07:28 | 000,175,736 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:
64bit: - [2012/04/12 22:45:04 | 001,860,672 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:
64bit: - [2012/03/29 02:28:38 | 000,405,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\symnets.sys -- (SymNetS)
DRV:
64bit: - [2012/03/29 02:28:30 | 001,092,728 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\symefa64.sys -- (SymEFA)
DRV:
64bit: - [2012/03/29 02:28:25 | 000,451,192 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\symds64.sys -- (SymDS)
DRV:
64bit: - [2012/03/29 02:06:25 | 000,190,072 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\ironx64.sys -- (SymIRON)
DRV:
64bit: - [2012/03/29 02:03:27 | 000,737,912 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\srtsp64.sys -- (SRTSP)
DRV:
64bit: - [2012/03/29 02:03:27 | 000,037,496 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:
64bit: - [2012/03/21 17:35:40 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:
64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012/01/31 17:56:30 | 000,231,440 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2012/01/31 17:56:29 | 010,203,648 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2012/01/31 17:56:29 | 000,310,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2011/11/29 18:44:29 | 000,167,048 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\N360x64\0602010.005\ccsetx64.sys -- (ccSet_N360)
DRV:
64bit: - [2011/10/01 12:30:22 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:
64bit: - [2011/10/01 12:30:18 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:
64bit: - [2011/10/01 12:30:18 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:
64bit: - [2011/10/01 12:30:10 | 000,764,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:
64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/09/27 16:10:00 | 000,517,120 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:
64bit: - [2010/09/13 09:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:
64bit: - [2010/09/03 02:59:26 | 000,349,800 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2010/03/01 16:59:50 | 000,024,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cqcpu.sys -- (cqcpu)
DRV:
64bit: - [2010/03/01 16:59:50 | 000,024,376 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cpqdfw.sys -- (CpqDfw)
DRV:
64bit: - [2009/10/07 04:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:
64bit: - [2009/10/07 04:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:
64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 21:47:48 | 000,024,144 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\crcdisk.sys -- (crcdisk)
DRV:
64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/07/13 20:10:33 | 000,021,504 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\SysNative\drivers\ws2ifsl.sys -- (ws2ifsl)
DRV:
64bit: - [2009/07/13 19:19:47 | 000,092,160 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\cdfs.sys -- (cdfs)
DRV:
64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2008/06/14 14:26:50 | 000,057,312 | ---- | M] (Ray Hinchliffe) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SIVX64.sys -- (SIVDRIVER)
DRV:
64bit: - [2007/02/03 13:30:58 | 000,058,528 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:
64bit: - [2007/02/03 13:25:56 | 000,955,680 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CamDrL64.sys -- (CamDrL64) Logitech QuickCam Pro 3000(PID_08B0)
DRV - [2012/06/03 20:45:10 | 002,068,600 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120603.009\ex64.sys -- (NAVEX15)
DRV - [2012/06/03 20:45:10 | 000,120,440 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\VirusDefs\20120603.009\eng64.sys -- (NAVENG)
DRV - [2012/05/30 22:19:39 | 000,484,512 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2012/05/30 22:19:39 | 000,138,912 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/05/02 18:56:46 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\IPSDefs\20120601.001\IDSviA64.sys -- (IDSVia64)
DRV - [2012/04/03 21:44:36 | 001,160,824 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\Definitions\BASHDefs\20120517.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2010/06/24 18:53:04 | 000,021,504 | ---- | M] (
http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\libusb0.sys -- (libusb0)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPDSK/1IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPDSK/1IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {ec29edf6-ad3c-4e1c-a087-d6cb81400c43}
IE:
64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://search.ask.co...&l=dis&o=HPDTDFIE:
64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" =
http://search.yahoo....psg&type=HPDTDFIE:
64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" =
http://en.wikipedia....h={searchTerms}IE:
64bit: - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" =
http://rover.ebay.co...s}&mfe=DesktopsIE:
64bit: - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" =
http://www.bing.com/...rc=IE-SearchBoxIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPDSK/1IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPDSK/1IE - HKLM\..\SearchScopes,DefaultScope = {ec29edf6-ad3c-4e1c-a087-d6cb81400c43}
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://search.ask.co...&l=dis&o=HPDTDFIE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" =
http://search.yahoo....psg&type=HPDTDFIE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" =
http://en.wikipedia....h={searchTerms}IE - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" =
http://rover.ebay.co...s}&mfe=DesktopsIE - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" =
http://www.bing.com/...rc=IE-SearchBox IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.google.com/IE - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRCIE - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Patrick\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\FireFox Extension [2011/09/08 23:30:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Video Downloader\Plugin_FireFox [2011/09/08 23:31:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\IPSFFPlgn\ [2012/05/03 09:16:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.2.0.9\coFFPlgn\ [2012/06/04 08:41:16 | 000,000,000 | ---D | M]
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
Hosts file not found
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton 360\Engine\6.2.1.5\ips\ipsbho.dll (Symantec Corporation)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\6.2.1.5\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (RAW Thumbnail Viewer) - {F301665A-12F8-4331-804A-5BCBD379668C} - C:\Program Files (x86)\ArcSoft\RAW Thumbnail Viewer\EXIFToolBar.dll (ArcSoft Inc.)
O3:
64bit: - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe (Symantec Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-1520967169-3638953700-3227044673-1000\..Trusted Domains: google.com ([www] https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94}
http://utilities.pcp...ols/pcmatic.cab (PCPitstop Utility)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20614.www2.h...hpdetect118.cab (GMNRev Class)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcp.../pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E7330E27-9A83-4D99-8D7E-8553DE1C3FF0}: DhcpNameServer = 209.18.47.61 209.18.47.62
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/03/19 11:41:35 | 000,000,000 | RH-- | M] () - E:\autorun.wbcat -- [ UDF ]
O32 - AutoRun File - [2012/03/19 11:41:35 | 000,000,130 | ---- | M] () - E:\autorun.inf -- [ UDF ]
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ========== [2012/06/04 06:39:59 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{90301F3C-D128-4C76-8F9A-F9F664DB38E3}
[2012/06/04 06:39:50 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{35E30CA8-D4F6-47BD-87BD-2799D6987874}
[2012/06/03 17:52:55 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4980B347-7733-441F-A026-8E17C2537626}
[2012/06/03 17:52:44 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{EEE6FB20-E828-4E81-AD08-95E5916E3373}
[2012/06/03 13:35:25 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Patrick\Desktop\OTL.exe
[2012/06/03 13:32:38 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/06/03 13:31:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/06/03 13:31:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2012/06/03 05:52:09 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{08E06223-E918-4B51-8FB6-C6DFEA2CEDB6}
[2012/06/03 05:51:59 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{82770856-F509-4BD6-819A-896598BF2C96}
[2012/06/01 18:41:07 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{5F83CCD3-46B0-4ADB-AE03-273AF1E42BE2}
[2012/06/01 18:40:58 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{84BF2289-3FFD-43BF-8B29-114C0311E067}
[2012/06/01 05:28:32 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{2E6F102B-5664-4310-93F5-E1D3628724D9}
[2012/06/01 05:28:23 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{BCDF4F52-21FD-46D2-BA7A-D1ED1B8E5B8F}
[2012/05/31 20:19:54 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Roaming\WildTangent
[2012/05/31 18:58:10 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{95E44782-9466-4482-81DA-524D384D4BA8}
[2012/05/31 16:49:10 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4F36E4E6-64F4-4D6C-B184-10DAD6239BDE}
[2012/05/31 16:49:01 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{ED623CF9-A0A0-4AF5-8BCD-19A66BA0A1D4}
[2012/05/31 06:53:59 | 002,322,184 | ---- | C] (ESET) -- C:\Users\Patrick\Desktop\esetsmartinstaller_enu.exe
[2012/05/30 21:40:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools
[2012/05/30 21:37:16 | 000,251,528 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012/05/30 21:37:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012/05/30 21:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012/05/30 21:37:04 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Roaming\TestApp
[2012/05/30 21:25:09 | 000,000,000 | ---D | C] -- C:\Users\Patrick\Desktop\TECH
[2012/05/30 21:14:38 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{A4EA0614-A4B8-4396-B9BD-F862D4DD0EC3}
[2012/05/30 21:14:28 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{273C4DE4-58BB-40B8-B884-A0A13A7CC48C}
[2012/05/30 21:11:57 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/05/30 21:06:01 | 002,127,960 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Patrick\Desktop\larry.com
[2012/05/30 15:46:49 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Patrick\Desktop\aswMBR.exe
[2012/05/30 06:13:43 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{10EC5C86-1862-4115-A712-CA18817C5057}
[2012/05/30 06:13:33 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{E7616986-8993-4F8B-A27F-52403979019E}
[2012/05/29 18:13:09 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{EFED52D8-6DCB-46BF-BFFC-C15AB56B9DF7}
[2012/05/29 18:12:58 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{F429E500-745C-47FA-B818-CE26BCD0F23F}
[2012/05/29 07:51:21 | 000,000,000 | ---D | C] -- C:\ProgramData\PCPitstop
[2012/05/29 07:51:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PCPitstop
[2012/05/29 07:51:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Pitstop
[2012/05/29 06:11:06 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{048AB9DD-7F07-400A-8AA7-4FB2F8563C6B}
[2012/05/29 06:10:57 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{44EEF7A3-7309-4728-9643-8207A70E09C6}
[2012/05/28 18:18:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/05/28 18:18:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/05/28 17:00:54 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2012/05/28 16:38:57 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/05/28 16:31:17 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Roaming\Malwarebytes
[2012/05/28 16:31:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/28 16:31:08 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/05/28 16:31:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/05/28 16:31:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/05/28 16:14:17 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\Diagnostics
[2012/05/28 06:35:34 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{8A31DC4A-DA08-4693-B73B-2F2625F28562}
[2012/05/28 06:35:24 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{7458C8FD-F8FF-4591-9A47-EFF29181D33B}
[2012/05/27 19:33:25 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{461ABD88-AD43-4929-9BB4-B2BCF96BAC59}
[2012/05/27 19:27:17 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\MediaSmart DVD
[2012/05/27 19:22:47 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{45CA2CC2-7181-48E9-A212-B6E740768FCA}
[2012/05/27 19:22:37 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4E586488-3F83-4C92-8F63-B47D14AAA148}
[2012/05/27 10:44:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Belarc
[2012/05/27 06:04:35 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{6A59AC9C-A37F-4F29-8DE5-F41F5E684438}
[2012/05/27 06:04:26 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{EEAB6E40-C5E6-498B-8E7A-E2E59EB33448}
[2012/05/26 09:00:32 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{AF21497D-6449-4AF0-8773-C693953F8894}
[2012/05/26 09:00:23 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{B54479C6-D28D-471B-B694-1DBF9EAAFE51}
[2012/05/25 22:30:39 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{E8DCDAD3-79D7-4193-82FF-12C788091C04}
[2012/05/25 09:46:24 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{7055921C-CDBF-42F5-9148-5748ED8DCFB6}
[2012/05/25 09:46:15 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{1EB7079F-59E1-457D-9998-3240450B0F5A}
[2012/05/24 17:25:21 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{E2ED6258-05ED-4335-A9B5-992884ABF81D}
[2012/05/24 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{9F62F5B0-BB5D-4F4A-8CED-1E8B3895A6D3}
[2012/05/24 01:45:52 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{C87B2290-B88F-472D-B43D-D771E343AC97}
[2012/05/24 01:45:41 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{685143D3-6E2F-496F-A168-2FD5F769F27E}
[2012/05/23 08:31:37 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{34D055A5-2F16-498B-9232-365C05044DE9}
[2012/05/23 08:31:28 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{F00F29C4-75D7-48ED-89F3-841AFF5222A4}
[2012/05/22 20:07:18 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{476FF0F7-C455-4B43-8F88-A98A85318B24}
[2012/05/22 20:07:09 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{9B7EEDF4-1E32-4290-91E6-2974F995D902}
[2012/05/22 07:42:49 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{D40AD7CB-F825-467F-8D34-6C3D800C983B}
[2012/05/22 07:42:40 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{37CE0D57-EC56-4259-AEAF-4CB187E742A4}
[2012/05/21 13:26:49 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{489BB383-EA32-467F-A0D5-4606B293EB8E}
[2012/05/21 13:26:38 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{33389A6F-EF30-4291-9F2D-E2959661BE49}
[2012/05/21 12:45:53 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{2026CFF6-21D2-446B-9151-D562E9DA9556}
[2012/05/20 22:29:01 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{EB07F3FD-B6B7-44BE-918F-5BAD3CB04396}
[2012/05/20 22:28:51 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{83FE7E2E-F1B1-44C8-963D-BF44BD4F675B}
[2012/05/20 22:28:27 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4263096C-796E-48BA-A128-E15B642EABA1}
[2012/05/20 22:28:16 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{828F3D33-7C28-47FF-9DF0-7C1B926E33C1}
[2012/05/20 09:29:47 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{38B1BD74-F811-4694-BC86-613A5B5A33E5}
[2012/05/20 09:29:38 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{C362092C-850C-4B46-9ADA-352B9FEAB656}
[2012/05/19 13:18:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/05/19 13:17:27 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2012/05/19 13:17:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Silverlight
[2012/05/19 10:07:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Ralink
[2012/05/19 10:07:56 | 000,000,000 | ---D | C] -- C:\Users\Patrick\Documents\Media Share
[2012/05/19 09:53:30 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{51942465-F8BB-4896-9226-C9C29C6C502A}
[2012/05/19 09:53:20 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{1FEF5F26-AA36-4FBB-B8F1-4B1F935148CF}
[2012/05/18 09:04:12 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{F0B7A466-87F1-4699-9B31-23E92C517447}
[2012/05/18 09:04:03 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{9BDE5AB8-928E-44CC-BDE4-51AA26025770}
[2012/05/17 15:13:02 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{DCF9E101-970E-4E6D-B269-54AC3EEA8E45}
[2012/05/17 15:12:50 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{8D73B3AE-E346-463B-9CD1-CF5648C273D1}
[2012/05/17 15:11:37 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{B8246642-9397-4618-A556-1FD6F5A44859}
[2012/05/16 21:52:33 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{2C40C008-D4BE-4FF0-AA35-487372172203}
[2012/05/16 21:52:22 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{6AE1FF45-AEF0-4C5C-827F-F04DE967E7DE}
[2012/05/16 18:11:31 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{867D71BA-8BFC-4CF6-A6DF-4C20F9DA4877}
[2012/05/16 18:11:22 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{60350172-AD23-498F-A90C-5CC38471F89E}
[2012/05/16 04:14:58 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4F9FC4DE-E807-4501-B896-50342D87F587}
[2012/05/16 04:14:47 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{3592DE92-C76E-4D06-9559-3079602AC5C8}
[2012/05/16 00:41:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
[2012/05/16 00:40:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2012/05/16 00:40:57 | 002,403,392 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysNative\RaCertMgr.dll
[2012/05/16 00:40:57 | 001,608,768 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysWow64\RaCertMgr.dll
[2012/05/16 00:40:57 | 001,115,136 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysWow64\RAIHV.dll
[2012/05/16 00:40:57 | 001,115,136 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysNative\RAIHV.dll
[2012/05/16 00:40:57 | 000,127,488 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysWow64\RAEXTUI.dll
[2012/05/16 00:40:57 | 000,127,488 | ---- | C] (Ralink Technology, Corp.) -- C:\Windows\SysNative\RAEXTUI.dll
[2012/05/16 00:40:57 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\RaLanguages
[2012/05/16 00:40:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ralink
[2012/05/16 00:40:20 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Roaming\InstallShield
[2012/05/15 08:29:17 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{38A4DD99-A2AE-4682-AE25-77A4817CCCA7}
[2012/05/15 08:29:05 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{2556FE1D-90C0-489B-B4C3-85EE9617199D}
[2012/05/14 15:36:32 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{BB22988C-2109-456C-8EAC-6BE5309E05EF}
[2012/05/14 15:36:21 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{BF9351D1-EBCC-4053-9356-B5BFC6E540DF}
[2012/05/13 23:12:24 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{F5235961-22C0-45D7-A0AE-83BFBE9A39CD}
[2012/05/13 23:12:13 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{C74F84CA-C2BC-4A0D-BDD8-40F309D2E4AF}
[2012/05/13 22:44:49 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{C2E5DFA3-B26E-4357-83BA-9D771C7B2EA7}
[2012/05/13 09:04:33 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{6853ED66-89FD-4BEA-8AD6-84FB6CAE2DDA}
[2012/05/13 09:04:15 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{608CF39A-1B9C-4D74-8CA8-330FBD577692}
[2012/05/12 08:52:07 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{E3548A8E-DA24-48B0-995E-864CA5D5A72C}
[2012/05/12 08:51:57 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{FC37B3A1-9AA4-4DB4-A646-98D91ED327F1}
[2012/05/11 20:53:39 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{BD475149-E253-4E83-9E3B-2A7E21A5EBF1}
[2012/05/11 02:31:56 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{3C6A9B57-2CAD-421B-91E7-34249AF7307F}
[2012/05/11 02:31:44 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{54240AC6-246C-4528-A8CE-29F2681AAD91}
[2012/05/10 06:39:18 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{C703051C-2ED5-48F6-A900-A5ED0DE42486}
[2012/05/10 06:39:07 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{FC8F6539-B718-4A11-BE68-074BC2C37552}
[2012/05/09 15:40:11 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{3D39A33C-B924-41B7-B6A9-F0DC6786763E}
[2012/05/09 15:40:02 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{3AC315C7-D7D6-40E9-BAFC-0C552CCF6164}
[2012/05/09 02:24:43 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{D3D20B52-03B1-4694-87A4-1D3B3665232A}
[2012/05/09 02:24:30 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{79281A44-4774-4106-BB6B-76BE0CBB80D1}
[2012/05/08 23:49:02 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{6C13A559-787F-4700-852C-A117B06ED43B}
[2012/05/08 22:20:39 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{E9C23E02-C07C-4188-9514-6078D84EB568}
[2012/05/08 08:44:56 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{52D59BDB-8368-4B91-BEB1-C1F8D2CF9FFE}
[2012/05/08 08:44:46 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{BB8A0CFE-7FB9-446D-9851-DF31B37F4015}
[2012/05/07 14:13:51 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{3FAF53FA-90F5-4E8C-87B4-0C9066E0C8E2}
[2012/05/06 21:53:18 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{33C04797-4774-476B-B5FB-E54650222639}
[2012/05/06 21:53:07 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{61542643-7F7E-4124-BFBF-F4A727123546}
[2012/05/06 20:10:26 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{4BFB585C-AB6A-404F-B760-1D12F8428423}
[2012/05/06 20:10:15 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{62271B8F-0A19-41A7-9E4C-6540EEAB31E3}
[2012/05/06 00:20:45 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{85005987-4D53-4E98-8795-7883582996DE}
[2012/05/06 00:20:34 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{281ABF64-34AF-4F7C-AF97-340FD39F96B6}
[2012/05/05 09:07:48 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{F87954D1-A425-468E-B402-E6897645775F}
[2012/05/05 09:07:37 | 000,000,000 | ---D | C] -- C:\Users\Patrick\AppData\Local\{2D2FCE3F-34A0-46AA-9682-37A8A42A834F}
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2012/06/04 08:42:49 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Patrick\Desktop\OTL.exe
[2012/06/04 08:40:17 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/04 08:40:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/04 08:40:06 | 2133,753,855 | -HS- | M] () -- C:\hiberfil.sys
[2012/06/04 08:31:00 | 000,000,328 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/06/04 08:11:00 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/04 07:51:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/04 06:46:43 | 000,016,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/04 06:46:43 | 000,016,112 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/03 15:37:12 | 000,707,369 | ---- | M] () -- C:\Users\Patrick\Desktop\LIFEINSURANCE CASHVALUE.pdf
[2012/06/03 13:31:54 | 000,000,871 | ---- | M] () -- C:\Users\Patrick\Desktop\ERUNT.lnk
[2012/06/03 07:22:50 | 000,727,310 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/03 07:22:50 | 000,624,606 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/06/03 07:22:50 | 000,106,724 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/05/31 20:20:02 | 000,002,526 | ---- | M] () -- C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
[2012/05/31 06:54:22 | 002,322,184 | ---- | M] (ESET) -- C:\Users\Patrick\Desktop\esetsmartinstaller_enu.exe
[2012/05/30 21:37:29 | 001,597,133 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/05/30 21:13:36 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForPATRICK-HP$.job
[2012/05/30 21:06:56 | 002,127,960 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Patrick\Desktop\larry.com
[2012/05/30 15:46:53 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Patrick\Desktop\aswMBR.exe
[2012/05/30 12:56:47 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2012/05/30 12:56:47 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2012/05/29 21:47:24 | 000,000,340 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForPatrick.job
[2012/05/28 17:56:00 | 000,001,252 | ---- | M] () -- C:\Users\Patrick\Desktop\Disk Cleanup.lnk
[2012/05/28 17:00:54 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2012/05/28 16:31:09 | 000,001,075 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/27 17:21:34 | 000,000,017 | ---- | M] () -- C:\Users\Patrick\AppData\Local\resmon.resmoncfg
[2012/05/27 10:44:16 | 000,002,054 | ---- | M] () -- C:\Users\Patrick\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/05/27 10:44:16 | 000,002,030 | ---- | M] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/05/24 20:30:04 | 000,326,376 | ---- | M] () -- C:\Users\Patrick\Desktop\TDBANK MAY.pdf
[2012/05/24 15:06:18 | 001,004,567 | ---- | M] () -- C:\Users\Patrick\Desktop\TD ACCOUNTS2.pdf
[2012/05/19 09:52:35 | 000,002,261 | ---- | M] () -- C:\Users\Public\Desktop\Norton 360.lnk
[2012/05/19 09:52:12 | 001,597,133 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0602010.005\Cat.DB
[2012/05/19 09:52:03 | 000,008,942 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0602010.005\VT20120410.034
[2012/05/13 03:45:26 | 000,000,172 | ---- | M] () -- C:\Windows\SysNative\drivers\N360x64\0602010.005\isolate.ini
[2012/05/11 11:14:26 | 000,251,528 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012/05/11 09:32:56 | 000,285,448 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ========== [2012/06/03 15:37:11 | 000,707,369 | ---- | C] () -- C:\Users\Patrick\Desktop\LIFEINSURANCE CASHVALUE.pdf
[2012/06/03 13:31:54 | 000,000,871 | ---- | C] () -- C:\Users\Patrick\Desktop\ERUNT.lnk
[2012/05/30 21:37:18 | 001,597,133 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012/05/28 17:56:00 | 000,001,252 | ---- | C] () -- C:\Users\Patrick\Desktop\Disk Cleanup.lnk
[2012/05/28 16:31:09 | 000,001,075 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/27 17:21:34 | 000,000,017 | ---- | C] () -- C:\Users\Patrick\AppData\Local\resmon.resmoncfg
[2012/05/27 10:44:16 | 000,002,054 | ---- | C] () -- C:\Users\Patrick\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2012/05/27 10:44:16 | 000,002,042 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2012/05/27 10:44:16 | 000,002,030 | ---- | C] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2012/05/24 20:30:03 | 000,326,376 | ---- | C] () -- C:\Users\Patrick\Desktop\TDBANK MAY.pdf
[2012/05/24 15:06:17 | 001,004,567 | ---- | C] () -- C:\Users\Patrick\Desktop\TD ACCOUNTS2.pdf
[2012/05/16 00:40:57 | 000,000,451 | ---- | C] () -- C:\Windows\SysWow64\DiagFunc.ini
[2012/05/16 00:40:57 | 000,000,451 | ---- | C] () -- C:\Windows\SysNative\DiagFunc.ini
[2012/05/16 00:40:52 | 000,792,416 | ---- | C] () -- C:\Windows\SysNative\DiagFunc.dll
[2012/05/16 00:40:45 | 000,792,416 | ---- | C] () -- C:\Windows\SysWow64\DiagFunc.dll
[2011/12/19 14:56:02 | 000,003,584 | ---- | C] () -- C:\Users\Patrick\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/11/03 12:12:53 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/10/24 05:53:06 | 000,053,760 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/10/09 22:53:31 | 000,000,276 | ---- | C] () -- C:\Windows\_delis32.ini
[2011/10/02 15:57:26 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/10/02 15:57:26 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/09/13 15:18:29 | 000,221,824 | ---- | C] () -- C:\Windows\hpoins19.dat.temp
[2011/09/13 15:18:29 | 000,013,898 | ---- | C] () -- C:\Windows\hpomdl19.dat.temp
[2011/09/07 12:27:06 | 000,743,066 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/19 03:34:49 | 000,014,051 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2011/01/19 03:34:02 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2011/01/19 03:27:12 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/09/21 14:30:44 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
========== LOP Check ========== [2011/09/17 13:25:53 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\Blio
[2011/12/27 10:59:45 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\Flip Video
[2011/10/09 22:54:25 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\FotoWire
[2012/02/19 12:04:15 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\IObit
[2011/10/09 23:17:00 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\Leadertech
[2011/09/07 07:20:07 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\PictureMover
[2012/06/03 17:14:19 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\SoftGrid Client
[2012/05/30 21:37:04 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\TestApp
[2011/09/07 12:27:31 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\TP
[2012/01/02 23:11:00 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\Visan
[2012/05/31 20:19:58 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\WildTangent
[2011/09/15 20:47:17 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\WinBatch
[2011/09/07 08:59:53 | 000,000,000 | ---D | M] -- C:\Users\Patrick\AppData\Roaming\Windows Live Writer
[2012/03/03 17:07:38 | 000,032,570 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >