otl
OTL logfile created on: 1/5/2012 8:08:34 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows Vista (TM) Home Premium Service Pack 1 (Version = 6.0.6001) - Type = System
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 91.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 146.18 Gb Free Space | 52.31% Space Free | Partition Type: NTFS
Drive D: | 465.83 Gb Total Space | 211.20 Gb Free Space | 45.34% Space Free | Partition Type: NTFS
Drive E: | 963.48 Mb Total Space | 717.67 Mb Free Space | 74.49% Space Free | Partition Type: FAT32
Drive F: | 409.17 Gb Total Space | 194.21 Gb Free Space | 47.46% Space Free | Partition Type: NTFS
Drive G: | 465.68 Gb Total Space | 44.39 Gb Free Space | 9.53% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2011/06/17 02:34:18 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:
64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/10/15 03:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/15 01:54:40 | 000,381,248 | ---- | M] (NVIDIA Corporation) [Auto] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/07/07 19:31:08 | 000,195,336 | ---- | M] (Microsoft Corporation.) [On_Demand] -- C:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/06/15 17:33:20 | 000,249,648 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE -- (BBUpdate)
SRV - [2010/01/15 07:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand] -- C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2009/08/19 22:55:40 | 000,196,608 | ---- | M] (ASUSTeK Computer Inc.) [Auto] -- C:\Windows\SysWOW64\AsHookDevice.exe -- (Device Handle Service)
SRV - [2008/07/27 13:03:13 | 000,069,632 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2011/08/02 17:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011/07/07 18:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2011/04/30 06:59:22 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:
64bit: - [2011/04/30 06:59:22 | 000,060,184 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:
64bit: - [2010/12/01 14:06:31 | 000,125,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\AnyDVD.sys -- (AnyDVD)
DRV:
64bit: - [2010/06/23 10:21:34 | 000,318,568 | ---- | M] (Realtek ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009/11/11 15:11:42 | 000,232,480 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:
64bit: - [2009/02/24 19:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV:
64bit: - [2009/02/17 07:18:00 | 000,069,192 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftdibus.sys -- (FTDIBUS)
DRV:
64bit: - [2009/02/17 07:17:00 | 000,084,808 | ---- | M] (FTDI Ltd.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ftser2k.sys -- (FTSER2K)
DRV:
64bit: - [2009/01/19 17:41:48 | 000,609,280 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\netr28x.sys -- (netr28x)
DRV:
64bit: - [2008/01/20 21:47:28 | 000,046,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\WpdUsb.sys -- (WpdUsb)
DRV:
64bit: - [2006/10/31 18:23:42 | 000,015,680 | ---- | M] () [Kernel | On_Demand] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
DRV:
64bit: - [2006/10/18 21:09:19 | 001,930,176 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (ialm)
DRV:
64bit: - [2006/09/18 16:36:24 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV - [2010/12/01 14:06:31 | 000,125,512 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand] -- C:\Windows\SysWOW64\drivers\AnyDVD.sys -- (AnyDVD)
DRV - [2009/02/24 19:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Deshra_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.asus.com [binary data]
IE - HKU\Deshra_ON_C\Software\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKU\Deshra_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Deshra_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "search"
FF - prefs.js..browser.startup.homepage: "http://go.microsoft.com/fwlink/?LinkId=69157|http://www.asus.com/"
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/10 22:10:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/11 10:30:49 | 000,000,000 | ---D | M]
[2011/02/23 10:17:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deshra\AppData\Roaming\Mozilla\Extensions
[2012/01/04 19:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deshra\AppData\Roaming\Mozilla\Firefox\Profiles\u8syq1tr.default\extensions
[2012/01/04 19:48:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Deshra\AppData\Roaming\Mozilla\Firefox\Profiles\u8syq1tr.default\extensions\staged
[2011/12/06 04:27:03 | 000,001,210 | ---- | M] () -- C:\Users\Deshra\AppData\Roaming\Mozilla\Firefox\Profiles\u8syq1tr.default\searchplugins\search.xml
[2011/11/11 10:30:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/11/11 10:30:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\DESHRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\U8SYQ1TR.DEFAULT\EXTENSIONS\{BAEBEF65-9289-47C5-8524-C345CC5D860D}.XPI
[2011/12/13 21:44:32 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/11/10 22:10:00 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/11/11 10:30:36 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/11/10 22:09:57 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/10 22:09:57 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/11/10 01:42:05 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files (x86)\Save Flash\SaveFlash.dll (PilotGroup LLC)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\Deshra_ON_C\..\Toolbar\WebBrowser: (&Save Flash) - {4064EA35-578D-4073-A834-C96D82CBCF40} - C:\Program Files (x86)\Save Flash\SaveFlash.dll (PilotGroup LLC)
O4:
64bit: - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [AgentMonitor] C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [RunAIShell] C:\Program Files (x86)\ASUS\AI Manager\AsShellApplication.exe (ASUSTeK Computer Inc.)
O4 - HKU\Deshra_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKU\Deshra_ON_C..\Run: [WMPNSCFG] File not found
O4 - HKU\Deshra_ON_C..\Run: [yBlqxAdBNPjQ.exe] C:\ProgramData\yBlqxAdBNPjQ.exe ()
O4 - HKU\UpdatusUser_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser_ON_C..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Deshra_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\Deshra_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\LocalService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\NetworkService_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\systemprofile_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\UpdatusUser_ON_C\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O8 - Extra context menu item: Sothink SWF Catcher - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files (x86)\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9}
http://support.asus.com/select/asusTek_sys_ctrl3.cab (asusTek_sysctrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.10.1
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/05 14:25:42 | 000,000,000 | ---D | C] -- C:\Users\Deshra\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Check
[2011/12/22 02:17:52 | 000,000,000 | ---D | C] -- C:\Users\Deshra\AppData\Roaming\redsn0w
[2011/12/16 23:33:57 | 000,000,000 | ---D | C] -- C:\Users\Deshra\AppData\Local\TempDIR
[2011/12/13 21:53:46 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\WindowsPowerShell
[2011/12/13 21:53:46 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011/12/13 21:45:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011/12/13 21:43:50 | 001,942,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dfshim.dll
[2011/12/13 21:43:50 | 001,130,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dfshim.dll
[2011/12/13 21:43:50 | 000,320,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHost.exe
[2011/12/13 21:43:50 | 000,295,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHost.exe
[2011/12/13 21:43:50 | 000,109,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\PresentationHostProxy.dll
[2011/12/13 21:43:50 | 000,099,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\PresentationHostProxy.dll
[2011/12/13 21:43:50 | 000,049,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\netfxperf.dll
[2011/12/13 21:43:50 | 000,048,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\netfxperf.dll
[2011/12/13 21:42:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrsmgr.dll
[2011/12/13 21:42:57 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrsmgr.dll
[2011/12/13 21:42:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmplpxy.dll
[2011/12/13 21:42:56 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrssrv.dll
[2011/12/13 21:42:50 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmplpxy.dll
[2011/12/13 21:42:50 | 000,010,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrssrv.dll
[2011/12/13 21:42:48 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\pwrshplugin.dll
[2011/12/13 21:42:48 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrs.exe
[2011/12/13 21:42:48 | 000,041,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pwrshplugin.dll
[2011/12/13 21:42:48 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrshost.exe
[2011/12/13 21:42:48 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wsmprovhost.exe
[2011/12/13 21:42:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmRes.dll
[2011/12/13 21:42:47 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmRes.dll
[2011/12/13 21:42:46 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wevtfwd.dll
[2011/12/13 21:42:46 | 000,113,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecutil.exe
[2011/12/13 21:42:46 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wecapi.dll
[2011/12/13 21:42:46 | 000,081,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wevtfwd.dll
[2011/12/13 21:42:46 | 000,079,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wecutil.exe
[2011/12/13 21:42:46 | 000,056,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wecapi.dll
[2011/12/13 21:42:46 | 000,040,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrs.exe
[2011/12/13 21:42:46 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrshost.exe
[2011/12/13 21:42:46 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wsmprovhost.exe
[2011/12/13 21:42:43 | 000,310,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmWmiPl.dll
[2011/12/13 21:42:43 | 000,180,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WsmAuto.dll
[2011/12/13 21:42:43 | 000,145,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmAuto.dll
[2011/12/13 21:42:42 | 000,370,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winrscmd.dll
[2011/12/13 21:42:42 | 000,352,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManMigrationPlugin.dll
[2011/12/13 21:42:42 | 000,348,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WSManHTTPConfig.exe
[2011/12/13 21:42:42 | 000,252,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManMigrationPlugin.dll
[2011/12/13 21:42:42 | 000,246,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WSManHTTPConfig.exe
[2011/12/13 21:42:42 | 000,241,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\winrscmd.dll
[2011/12/13 21:42:42 | 000,214,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WsmWmiPl.dll
[2011/12/13 21:26:15 | 000,847,872 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\oleaut32.dll
[2011/12/13 21:26:04 | 001,398,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42.dll
[2011/12/13 21:26:04 | 001,360,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mfc42u.dll
[2011/12/13 21:26:04 | 001,161,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42u.dll
[2011/12/13 21:26:04 | 001,136,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfc42.dll
[2011/12/13 21:26:03 | 001,075,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.efi
[2011/12/13 21:26:03 | 001,062,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winload.exe
[2011/12/13 21:26:03 | 000,990,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.efi
[2011/12/13 21:26:03 | 000,979,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winresume.exe
[2011/12/13 21:26:02 | 000,020,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kdusb.dll
[2011/12/13 21:26:02 | 000,018,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kd1394.dll
[2011/12/13 21:26:02 | 000,018,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\kdcom.dll
[2011/12/13 21:26:01 | 000,367,616 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\atmfd.dll
[2011/12/13 21:26:01 | 000,292,864 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\atmfd.dll
[2011/12/13 21:26:01 | 000,048,128 | ---- | C] (Adobe Systems) -- C:\Windows\System32\atmlib.dll
[2011/12/13 21:26:00 | 000,034,304 | ---- | C] (Adobe Systems) -- C:\Windows\SysWow64\atmlib.dll
[2011/12/13 21:25:58 | 000,560,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/12/13 21:25:57 | 000,429,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\EncDec.dll
[2011/12/13 21:25:57 | 000,416,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbe.dll
[2011/12/13 21:25:57 | 000,323,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbe.dll
[2011/12/13 21:25:57 | 000,226,816 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mpg2splt.ax
[2011/12/13 21:25:57 | 000,210,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sbeio.dll
[2011/12/13 21:25:57 | 000,177,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mpg2splt.ax
[2011/12/13 21:25:57 | 000,153,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\sbeio.dll
[2011/12/13 21:25:55 | 002,424,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstscax.dll
[2011/12/13 21:25:55 | 002,067,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2011/12/13 21:25:55 | 000,730,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstsc.exe
[2011/12/13 21:25:55 | 000,677,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2011/12/13 21:25:51 | 000,753,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript.dll
[2011/12/13 21:25:51 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\vbscript.dll
[2011/12/13 21:25:51 | 000,512,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/12/13 21:25:48 | 000,450,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2011/12/13 21:25:48 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011/12/13 21:22:14 | 000,221,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnsapi.dll
[2011/12/13 21:22:14 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\dnscacheugc.exe
[2011/12/13 21:22:14 | 000,025,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dnscacheugc.exe
[2011/12/08 01:20:17 | 000,000,000 | ---D | C] -- C:\Users\Deshra\AppData\Local\cache
[2011/12/08 01:19:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
[2011/12/08 01:19:29 | 000,000,000 | -H-D | C] -- C:\ProgramData\VTech
[2011/12/08 01:19:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VTech
========== Files - Modified Within 30 Days ==========
[2012/01/05 14:37:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/05 14:25:46 | 000,000,272 | -H-- | M] () -- C:\ProgramData\~vcAvNjbO90gt57
[2012/01/05 14:25:46 | 000,000,160 | -H-- | M] () -- C:\ProgramData\~vcAvNjbO90gt57r
[2012/01/05 14:25:42 | 000,000,637 | ---- | M] () -- C:\Users\Deshra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/05 14:25:42 | 000,000,613 | ---- | M] () -- C:\Users\Deshra\Desktop\System Check.lnk
[2012/01/05 14:25:37 | 000,000,336 | -H-- | M] () -- C:\ProgramData\vcAvNjbO90gt57
[2012/01/05 14:24:48 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/05 14:24:48 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/05 14:21:38 | 000,358,178 | -H-- | M] () -- C:\ProgramData\vcAvNjbO90gt57.exe
[2012/01/05 14:20:48 | 000,075,776 | ---- | M] () -- C:\Users\Deshra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/05 14:15:34 | 000,444,194 | -H-- | M] () -- C:\ProgramData\yBlqxAdBNPjQ.exe
[2011/12/28 10:53:28 | 000,595,446 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/28 10:53:28 | 000,101,144 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/13 21:55:37 | 000,229,160 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/13 21:53:46 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2011/12/13 21:53:46 | 000,000,000 | R--D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
[2011/12/13 21:50:51 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/12/09 09:32:30 | 000,000,680 | ---- | M] () -- C:\Users\Deshra\AppData\Local\d3d9caps.dat
[2011/12/09 02:36:47 | 782,323,034 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/12/08 01:37:53 | 000,000,581 | ---- | M] () -- C:\Users\Deshra\AppData\Local\cookies.ini
[2011/12/08 01:19:43 | 000,001,044 | ---- | M] () -- C:\Users\Deshra\Desktop\Learning Lodge Navigator.lnk
[2011/12/08 01:19:43 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VTech
========== Files Created - No Company Name ==========
[2012/01/05 14:25:46 | 000,000,272 | -H-- | C] () -- C:\ProgramData\~vcAvNjbO90gt57
[2012/01/05 14:25:46 | 000,000,160 | -H-- | C] () -- C:\ProgramData\~vcAvNjbO90gt57r
[2012/01/05 14:25:42 | 000,000,637 | ---- | C] () -- C:\Users\Deshra\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/05 14:25:42 | 000,000,613 | ---- | C] () -- C:\Users\Deshra\Desktop\System Check.lnk
[2012/01/05 14:25:37 | 000,000,336 | -H-- | C] () -- C:\ProgramData\vcAvNjbO90gt57
[2012/01/05 14:21:38 | 000,358,178 | -H-- | C] () -- C:\ProgramData\vcAvNjbO90gt57.exe
[2012/01/05 14:18:41 | 000,444,194 | -H-- | C] () -- C:\ProgramData\yBlqxAdBNPjQ.exe
[2011/12/13 21:42:43 | 000,201,184 | ---- | C] () -- C:\Windows\SysWow64\winrm.vbs
[2011/12/13 21:42:43 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2011/12/13 21:42:43 | 000,004,675 | ---- | C] () -- C:\Windows\SysWow64\wsmanconfig_schema.xml
[2011/12/13 21:42:43 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2011/12/13 21:42:43 | 000,002,426 | ---- | C] () -- C:\Windows\SysWow64\WsmTxt.xsl
[2011/12/13 21:42:43 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2011/12/09 09:32:30 | 000,000,680 | ---- | C] () -- C:\Users\Deshra\AppData\Local\d3d9caps.dat
[2011/12/08 01:20:23 | 000,000,581 | ---- | C] () -- C:\Users\Deshra\AppData\Local\cookies.ini
[2011/12/08 01:19:43 | 000,001,044 | ---- | C] () -- C:\Users\Deshra\Desktop\Learning Lodge Navigator.lnk
[2011/12/06 04:27:02 | 000,421,376 | ---- | C] () -- C:\Users\Deshra\AppData\Roaming\ScanDisc.exe
[2011/12/06 04:27:02 | 000,000,288 | ---- | C] () -- C:\Users\Deshra\AppData\Roaming\376EBE68.reg
[2011/12/06 04:26:19 | 000,003,776 | -HS- | C] () -- C:\Users\Deshra\AppData\Local\x0ym23x1be4ukx
[2011/12/06 04:26:19 | 000,003,776 | -HS- | C] () -- C:\ProgramData\x0ym23x1be4ukx
[2011/12/05 05:44:51 | 000,010,570 | -HS- | C] () -- C:\Users\Deshra\AppData\Local\6a55ol2s67a224
[2011/12/05 05:44:51 | 000,010,570 | -HS- | C] () -- C:\ProgramData\6a55ol2s67a224
[2011/11/10 01:33:09 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/11/10 01:33:09 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/11/10 01:33:09 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/11/10 01:33:09 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/11/10 01:33:09 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/11/06 08:43:13 | 000,045,151 | ---- | C] () -- C:\Users\Deshra\AppData\Roaming\UserTile.png
[2011/10/15 01:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/07/13 07:27:11 | 000,008,380 | -HS- | C] () -- C:\Users\Deshra\AppData\Local\b6bo46lu10ri1w645385mo7j0w0
[2011/07/13 07:27:11 | 000,008,380 | -HS- | C] () -- C:\ProgramData\b6bo46lu10ri1w645385mo7j0w0
[2011/03/06 21:50:55 | 000,000,342 | ---- | C] () -- C:\Windows\SIERRA.INI
[2011/03/06 21:01:43 | 000,839,680 | ---- | C] () -- C:\Windows\SysWow64\FDRpage.dll
[2011/03/06 21:01:43 | 000,007,548 | ---- | C] () -- C:\Windows\SysWow64\drivers\Samhid.sys
[2011/03/06 20:59:20 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\CreateDir.exe
[2011/03/06 12:41:10 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011/02/23 04:36:34 | 000,075,776 | ---- | C] () -- C:\Users\Deshra\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 12:24:16 | 000,106,605 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2011/02/22 12:24:16 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2011/02/22 10:53:06 | 000,000,732 | ---- | C] () -- C:\Users\Deshra\AppData\Local\d3d9caps64.dat
[2011/02/22 10:32:24 | 000,221,184 | ---- | C] () -- C:\Windows\SysWow64\drivers\ServiceHelp.dll
[2011/02/22 10:31:37 | 000,024,576 | R--- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011/02/22 10:31:37 | 000,014,392 | R--- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011/02/22 10:31:35 | 000,011,832 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2011/02/22 10:31:35 | 000,010,216 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2011/02/22 10:27:59 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/02/22 10:24:51 | 000,014,713 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2011/02/22 10:08:36 | 000,023,388 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2011/02/22 10:08:26 | 000,018,322 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2008/01/20 21:49:49 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2007/12/28 10:22:02 | 000,010,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
[2006/11/02 10:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 10:02:31 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll
[2006/11/02 07:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2011/05/06 01:32:20 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\AnvSoft
[2011/10/12 22:41:36 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\BAC7E
[2011/10/12 18:56:49 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\BD9BA
[2011/02/23 14:12:37 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\Eltima Software
[2011/10/09 16:19:53 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\h99ggTZZqjYw
[2011/10/09 22:08:23 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\j11iibD33o
[2011/02/23 10:38:27 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\Leadertech
[2011/04/01 11:53:56 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\Masque
[2011/12/22 02:31:24 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\redsn0w
[2011/05/19 20:34:15 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\ReelDealVampireAdventure
[2011/05/06 08:18:31 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\Sony
[2011/07/19 09:43:02 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\spotmau
[2011/10/09 16:20:00 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\TEEEK88fRZ9h
[2011/12/28 03:17:45 | 000,000,000 | ---D | M] -- C:\Users\Deshra\AppData\Roaming\uTorrent
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2011/08/15 10:37:08 | 000,000,000 | -H-D | M] -- C:\ProgramData\CanonBJ
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2011/03/27 03:10:55 | 000,000,000 | -H-D | M] -- C:\ProgramData\Masque
[2011/03/02 15:38:28 | 000,000,000 | -H-D | M] -- C:\ProgramData\SlySoft
[2011/05/06 08:18:31 | 000,000,000 | -H-D | M] -- C:\ProgramData\Sony
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/09/27 08:47:18 | 000,000,000 | -H-D | M] -- C:\ProgramData\TEMP
[2006/11/02 10:42:17 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/12/08 01:19:29 | 000,000,000 | -H-D | M] -- C:\ProgramData\VTech
[2011/02/22 10:36:57 | 000,000,000 | -H-D | M] -- C:\ProgramData\WinZip
[2011/02/22 10:24:51 | 000,000,000 | -H-D | M] -- C:\ProgramData\Wireless LAN Card
[2011/11/04 12:31:56 | 000,000,000 | ---D | M] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/01/05 14:23:57 | 000,024,940 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 160 bytes -> C:\ProgramData\TEMP:FB1B13D8
< End of report >
I believe the the interloper that started it is the second to last entry located in C:\programdata
fortunately as a pc and console modder and repairer I have dealt with stuff like this so I have an idea but sheesh this one is nasty.