O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Java Plug-in 1.6.0_16)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab (Reg Error: Key error.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.1.cab (DLM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2D6B2DAD-6A3D-4D3B-BE1D-C8117EE66090}: DhcpNameServer = 208.59.247.45 208.59.247.46 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41095C22-33CE-46D2-896E-7C6B845BF651}: DhcpNameServer = 152.3.182.5 152.3.182.3 152.3.189.18
O18:
64bit: - Protocol\Handler\cf - No CLSID value found
O18:
64bit: - Protocol\Handler\gcf - No CLSID value found
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\cf - No CLSID value found
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\21.0.1180.89\npchrome_frame.dll (Google Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\ATFUS: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/03 21:06:24 | 000,599,040 | ---- | C] (OldTimer Tools) -- C:\Users\Vivek\Desktop\OTL.exe
[2012/09/03 20:37:47 | 000,000,000 | ---D | C] -- C:\Users\Vivek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/09/02 23:42:56 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/09/01 00:10:59 | 000,000,000 | ---D | C] -- C:\Users\Vivek\AppData\Local\Macromedia
[2012/08/31 23:54:52 | 000,000,000 | ---D | C] -- C:\Users\Vivek\Desktop\RK_Quarantine
[2012/08/31 19:43:19 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Vivek\Desktop\dds.com
[2012/08/31 19:01:13 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/31 19:01:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/31 19:00:53 | 010,652,120 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Vivek\Desktop\mbam-setup-1.62.0.1300.exe
[2012/08/31 17:12:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/22 20:33:51 | 038,685,384 | ---- | C] (VMware, Inc.) -- C:\Users\Vivek\Desktop\VMware-viewclient-x86_64-5.1.0-704644.exe
[2012/08/16 10:09:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/03 21:06:28 | 000,599,040 | ---- | M] (OldTimer Tools) -- C:\Users\Vivek\Desktop\OTL.exe
[2012/09/03 21:05:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-816525379-3359804378-3665389369-1003UA.job
[2012/09/03 20:37:49 | 000,002,377 | ---- | M] () -- C:\Users\Vivek\Desktop\Google Chrome.lnk
[2012/09/03 20:31:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/03 20:20:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/03 20:17:30 | 000,077,520 | ---- | M] () -- C:\Users\Vivek\Desktop\bookmarks_9_3_12.html
[2012/09/03 18:30:21 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/03 18:30:21 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/03 18:26:11 | 000,792,128 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/03 18:26:11 | 000,671,120 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/03 18:26:11 | 000,124,278 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/03 18:21:13 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/03 18:20:33 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-816525379-3359804378-3665389369-1003Core.job
[2012/09/03 18:20:33 | 000,000,466 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/09/03 18:20:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/03 18:20:20 | 3139,444,736 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/02 23:42:48 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/09/02 00:04:37 | 000,000,512 | ---- | M] () -- C:\Users\Vivek\Desktop\MBR.dat
[2012/09/01 01:09:36 | 880,245,280 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/08/31 19:43:17 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Vivek\Desktop\dds.com
[2012/08/31 19:11:07 | 000,302,592 | ---- | M] () -- C:\Users\Vivek\Desktop\9grlctx0.exe
[2012/08/31 19:00:51 | 010,652,120 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Vivek\Desktop\mbam-setup-1.62.0.1300.exe
[2012/08/31 18:36:04 | 000,000,328 | ---- | M] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2012/08/31 17:18:50 | 000,000,600 | ---- | M] () -- C:\Users\Vivek\AppData\Roaming\winscp.rnd
[2012/08/29 09:32:18 | 000,647,413 | ---- | M] () -- C:\Users\Vivek\Desktop\Docusign_Lease_50_Cherry_St_1_Somervillepd.zip
[2012/08/27 21:51:00 | 000,000,600 | ---- | M] () -- C:\Users\Vivek\AppData\Local\PUTTY.RND
[2012/08/22 20:34:14 | 038,685,384 | ---- | M] (VMware, Inc.) -- C:\Users\Vivek\Desktop\VMware-viewclient-x86_64-5.1.0-704644.exe
[2012/08/22 12:46:18 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/08/22 12:38:03 | 008,864,168 | ---- | M] (SurfRight B.V.) -- C:\Users\Vivek\Desktop\HitmanPro36_x64.exe
[2012/08/21 00:30:00 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/08/16 10:10:12 | 000,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/08/16 03:29:21 | 000,497,584 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/12 00:52:06 | 000,075,864 | ---- | M] () -- C:\Users\Vivek\Desktop\checks.pdf
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/03 20:37:49 | 000,002,377 | ---- | C] () -- C:\Users\Vivek\Desktop\Google Chrome.lnk
[2012/09/03 20:17:30 | 000,077,520 | ---- | C] () -- C:\Users\Vivek\Desktop\bookmarks_9_3_12.html
[2012/09/01 01:09:36 | 880,245,280 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/09/01 00:40:46 | 000,000,512 | ---- | C] () -- C:\Users\Vivek\Desktop\MBR.dat
[2012/08/31 19:11:08 | 000,302,592 | ---- | C] () -- C:\Users\Vivek\Desktop\9grlctx0.exe
[2012/08/31 18:36:04 | 000,000,328 | ---- | C] () -- C:\Windows\SysNative\drivers\kgpcpy.cfg
[2012/08/29 09:32:19 | 000,647,413 | ---- | C] () -- C:\Users\Vivek\Desktop\Docusign_Lease_50_Cherry_St_1_Somervillepd.zip
[2012/08/22 12:53:36 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/21 00:00:18 | 000,000,528 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/08/16 10:09:36 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2012/08/16 10:09:36 | 000,002,025 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2012/08/12 00:52:06 | 000,075,864 | ---- | C] () -- C:\Users\Vivek\Desktop\checks.pdf
[2011/12/18 14:32:40 | 000,010,486 | -HS- | C] () -- C:\Users\Vivek\AppData\Local\774335p0e210t008t785a0hmt7c3
[2011/11/17 17:59:33 | 000,000,222 | ---- | C] () -- C:\Users\Vivek\contestapplet.conf.bak
[2011/11/17 17:59:33 | 000,000,222 | ---- | C] () -- C:\Users\Vivek\contestapplet.conf
[2011/09/29 20:51:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/09/29 20:51:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/09/29 20:51:41 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/09/29 20:51:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/09/29 20:51:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/09/05 15:56:06 | 000,000,401 | ---- | C] () -- C:\Windows\crackpdf.INI
[2011/05/18 12:59:58 | 000,000,011 | ---- | C] () -- C:\Windows\OSA.INI
[2011/03/26 17:36:48 | 000,007,611 | ---- | C] () -- C:\Users\Vivek\AppData\Local\Resmon.ResmonCfg
[2010/11/08 21:31:00 | 000,001,006 | ---- | C] () -- C:\Users\Vivek\.zir.cfg
[2010/10/11 11:29:27 | 000,002,108 | ---- | C] () -- C:\Users\Vivek\.root_hist
[2010/02/13 22:44:12 | 000,011,287 | ---- | C] () -- C:\Users\Vivek\gsview64.ini
[2010/01/20 10:24:10 | 000,000,600 | ---- | C] () -- C:\Users\Vivek\AppData\Local\PUTTY.RND
[2010/01/06 17:30:33 | 000,000,600 | ---- | C] () -- C:\Users\Vivek\AppData\Roaming\winscp.rnd
========== LOP Check ==========
[2011/11/17 19:38:44 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\3D3D9
[2010/06/11 18:11:14 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\avidemux
[2012/02/18 21:58:44 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\B403D
[2010/03/09 15:11:27 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\CachedFiles
[2011/11/13 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\d88ffR9hTXqj
[2011/11/13 18:08:58 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\DeeelIIBrzNyxuS
[2012/09/03 18:22:18 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Dropbox
[2010/01/06 16:08:47 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Echo Software
[2010/08/23 12:35:24 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Foxit Software
[2011/11/13 18:40:58 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\fpnG4aQH6W7E9Tq
[2011/11/13 18:45:24 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\G1uvS2obFpGaJ
[2011/11/13 18:45:22 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\gYXwkUVelBz
[2010/06/24 11:26:42 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\InterVideo
[2010/08/23 17:56:10 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\IrfanView
[2011/11/13 18:09:00 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\kS2iDp4HsKf9TqY
[2011/07/04 19:35:34 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Leadertech
[2011/11/13 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\OdEK8gRZ9YwUeIt
[2011/11/13 18:41:00 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\OYCwkIVrlNx0c
[2010/11/17 16:31:01 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\ParaView
[2011/05/26 10:58:43 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\PCDr
[2011/04/24 22:47:16 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\PDF Writer
[2011/11/13 18:09:07 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\PWJJJdEE8RZqhXk
[2010/10/14 12:29:27 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\StarNet
[2010/02/20 12:31:22 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Subversion
[2011/05/05 15:04:36 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\Update
[2012/08/22 12:44:31 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\uTorrent
[2011/11/13 18:45:29 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\VjekIBrzOyA2b3n
[2011/11/13 18:45:29 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\X5aQH6dWKfLgXjC
[2011/11/13 18:45:18 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\yD2onF4pm5Q7E8R
[2011/11/13 18:09:08 | 000,000,000 | ---D | M] -- C:\Users\Vivek\AppData\Roaming\ZVVVellOBz0cAiv
[2012/08/21 00:30:00 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask-Delay.job
[2012/08/22 12:46:18 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2011/11/23 14:59:18 | 000,032,574 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/09/03 18:20:33 | 000,000,466 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
< End of report >