Yes i wish to continue, sorry very busy the last few days havent had time to work on it.
Heres the OTmoveit log
All processes killed
========== FILES ==========
C:\Program Files\DAEMON Tools Lite\uninst.exe moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 328041 bytes
->Flash cache emptied: 593 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: josh
->Temp folder emptied: 9373293 bytes
->Temporary Internet Files folder emptied: 210888334 bytes
->Java cache emptied: 112268 bytes
->FireFox cache emptied: 55068533 bytes
->Flash cache emptied: 105531 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1264 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 48603 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 13167062 bytes
RecycleBin emptied: 1035943 bytes
Total Files Cleaned = 277.00 mb
OTM by OldTimer - Version 3.1.18.0 log created on 06102011_172031
Files moved on Reboot...
Registry entries deleted on Reboot...
----------------------
here is the OTL log
=============
OTL logfile created on: 6/10/2011 5:30:09 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Users\josh\Desktop
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19048)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.50 Gb Total Physical Memory | 2.30 Gb Available Physical Memory | 65.76% Memory free
7.18 Gb Paging File | 6.08 Gb Available in Paging File | 84.80% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 220.29 Gb Total Space | 18.36 Gb Free Space | 8.34% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 5.04 Gb Free Space | 50.44% Space Free | Partition Type: NTFS
Drive E: | 3.14 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: JOSH-PC | User Name: josh | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\josh\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\LogMeIn\x86\ramaint.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
PRC - C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
PRC - C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
PRC - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - \\?\C:\Windows\System32\wbem\WMIADAP.EXE ()
PRC - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
PRC - C:\Windows\System32\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\System32\WTablet\Wacom_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Windows\System32\PSIService.exe ()
PRC - C:\Program Files\Fingerprint Reader Suite\upeksvr.exe (UPEK Inc.)
PRC - C:\Program Files\Fingerprint Reader Suite\psqltray.exe (UPEK Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
========== Modules (SafeList) ==========
MOD - C:\Users\josh\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (Akamai) -- c:\Program Files\Common Files\Akamai\netsession_win_8675ab0.dll ()
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (LMIMaint) -- C:\Program Files\LogMeIn\x86\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (LogMeIn) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe (LogMeIn, Inc.)
SRV - (ZuneWlanCfgSvc) -- C:\Windows\System32\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV - (WMZuneComm) -- c:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV - (ZuneNetworkSvc) -- c:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (StarWindServiceAE) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (DockLoginService) -- C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (STacSV) -- C:\Windows\System32\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (TabletServiceWacom) -- C:\Windows\System32\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV - (ProtexisLicensing) -- C:\Windows\System32\PSIService.exe ()
SRV - (IAANTMON) Intel(R) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
========== Driver Services (SafeList) ==========
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (LMIRfsClientNP) -- C:\Windows\System32\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (LMIRfsDriver) -- C:\Windows\System32\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV - (LMIInfo) -- C:\Program Files\LogMeIn\x86\rainfo.sys (LogMeIn, Inc.)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (mfehidk) -- C:\Windows\System32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- C:\Windows\System32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) -- C:\Windows\System32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- C:\Windows\System32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- C:\Windows\System32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (sfdrv01) StarForce Protection Environment Driver (version 1.x) -- C:\Windows\System32\drivers\sfdrv01.sys (Protection Technology (StarForce))
DRV - (BCM42RLY) -- C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (WDC_SAM) -- C:\Windows\System32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (OEM02Vfx) -- C:\Windows\System32\drivers\OEM02Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (OEM02Dev) -- C:\Windows\System32\drivers\OEM02Dev.sys (Creative Technology Ltd.)
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Filetrace) -- C:\Windows\System32\drivers\filetrace.sys ()
DRV - (WinUSB) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (irsir) -- C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (e1express) Intel(R) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (WSDPrintDevice) -- C:\Windows\System32\drivers\WSDPrint.sys (Microsoft Corporation)
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (iaNvStor) Intel(R) -- C:\Windows\system32\drivers\ianvstor.sys (Intel Corporation)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (Ph3xIB32) -- C:\Windows\System32\drivers\Ph3xIB32.sys (Philips Semiconductors GmbH)
DRV - (wacommousefilter) -- C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) -- C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (WacomVKHid) -- C:\Windows\System32\drivers\WacomVKHid.sys (Wacom Technology)
DRV - (TPkd) -- C:\Windows\System32\drivers\TPkd.sys (PACE Anti-Piracy, Inc.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (sfsync02) StarForce Protection Synchronization Driver (version 2.x) -- C:\Windows\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfhlp02) StarForce Protection Helper Driver (version 2.x) -- C:\Windows\System32\drivers\sfhlp02.sys (Protection Technology (StarForce))
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {ecdee021-0d17-467f-a1ff-c7a115230949} - Reg Error: Key error. File not found
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaultthis.engineName: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "free-downloads.net Customized Web Search"
FF - prefs.js..browser.startup.homepage: "google.com"
FF - prefs.js..extensions.enabledItems:
piclens@cooliris.com:1.12.2.44026
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.2
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT1098640&q="
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/03 02:35:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/31 15:24:26 | 000,000,000 | ---D | M]
[2010/02/04 09:04:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\josh\AppData\Roaming\mozilla\Extensions
[2010/02/04 09:04:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\josh\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org
[2011/05/25 18:37:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions
[2011/03/20 21:21:33 | 000,000,000 | ---D | M] (Forecastfox Weather) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011/03/20 21:21:39 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/03/20 21:21:44 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/04/13 01:26:50 | 000,000,000 | ---D | M] (free-downloads.net Community Toolbar) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\{ecdee021-0d17-467f-a1ff-c7a115230949}
[2011/04/13 01:26:47 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\engine@conduit.com
[2011/03/25 01:55:25 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\josh\AppData\Roaming\mozilla\Firefox\Profiles\1zivtgyd.default\extensions\piclens@cooliris.com
[2011/03/21 16:07:24 | 000,000,939 | ---- | M] () -- C:\Users\josh\AppData\Roaming\Mozilla\Firefox\Profiles\1zivtgyd.default\searchplugins\conduit.xml
[2011/05/31 15:24:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/05/31 15:24:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\JOSH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\1ZIVTGYD.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
[2011/05/03 02:35:03 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2011/05/31 15:24:16 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/03 17:16:05 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PSQLLauncher] C:\Program Files\Fingerprint Reader Suite\launcher.exe (UPEK Inc.)
O4 - HKLM..\Run: [Zune Launcher] c:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - Startup: C:\Users\josh\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Program Files\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos-beta/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O16 - DPF: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_25-windows-i586.cab (Java Plug-in 1.6.0_25)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (vrlogon.dll) - C:\Windows\System32\vrlogon.dll (UPEK Inc.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\psfus: DllName - C:\Windows\system32\psqlpwd.dll - C:\Windows\System32\psqlpwd.dll (UPEK Inc.)
O24 - Desktop WallPaper: C:\Users\josh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\josh\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O27 - HKLM IFEO\ehshell.exe: Debugger - "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" -MceShellRedirect (LogMeIn, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2005/09/02 15:21:51 | 000,000,051 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/10 17:27:52 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\josh\Desktop\OTL.exe
[2011/06/10 17:20:31 | 000,000,000 | ---D | C] -- C:\_OTM
[2011/06/10 17:19:10 | 000,522,752 | ---- | C] (OldTimer Tools) -- C:\Users\josh\Desktop\OTM.exe
[2011/06/03 17:17:58 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/06/03 17:17:55 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/06/03 17:17:55 | 000,000,000 | ---D | C] -- C:\Users\josh\AppData\Local\temp
[2011/06/03 17:07:30 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/05/31 23:42:08 | 004,111,831 | R--- | C] (Swearware) -- C:\Users\josh\Desktop\ComboFix.exe
[2011/05/31 16:39:09 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2011/05/31 15:25:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/05/31 15:25:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/05/29 15:21:14 | 000,000,000 | ---D | C] -- C:\Users\josh\Desktop\fixing stuff
[2011/05/28 23:14:42 | 000,000,000 | ---D | C] -- C:\Users\josh\AppData\Local\LogMeIn
[2011/05/28 23:14:38 | 000,029,568 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2011/05/28 23:14:37 | 000,083,360 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2011/05/28 23:14:37 | 000,047,640 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\drivers\LMIRfsDriver.sys
[2011/05/28 23:14:34 | 000,087,424 | ---- | C] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2011/05/28 23:14:29 | 000,000,000 | ---D | C] -- C:\ProgramData\LogMeIn
[2011/05/28 23:14:13 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn
[2011/05/28 21:03:11 | 000,000,000 | ---D | C] -- C:\Users\josh\AppData\Roaming\Avira
[2011/05/28 21:01:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/05/28 21:01:25 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/05/28 21:01:24 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/05/28 21:01:24 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/05/28 21:01:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/05/28 21:01:23 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/05/27 14:10:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2
[2011/05/23 15:40:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2011/05/23 15:38:36 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/05/23 15:35:14 | 000,000,000 | ---D | C] -- C:\Program Files\NVIDIA Corporation
[2011/05/23 15:34:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2011/05/23 15:34:20 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Silverlight
[2011/05/22 11:04:21 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/05/22 11:04:21 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/05/22 11:04:21 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/05/22 11:04:13 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/05/22 11:04:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/05/12 17:55:00 | 000,000,000 | ---D | C] -- C:\Users\josh\Desktop\Other
========== Files - Modified Within 30 Days ==========
[2011/06/10 17:32:05 | 000,621,554 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/10 17:32:05 | 000,112,084 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/10 17:27:54 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\josh\Desktop\OTL.exe
[2011/06/10 17:24:20 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/10 17:24:20 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/10 17:24:17 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/10 17:24:15 | 3756,064,768 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/10 17:19:12 | 000,522,752 | ---- | M] (OldTimer Tools) -- C:\Users\josh\Desktop\OTM.exe
[2011/06/10 03:15:38 | 000,007,916 | ---- | M] () -- C:\Users\josh\AppData\Local\d3d9caps.dat
[2011/06/05 23:36:57 | 000,002,230 | ---- | M] () -- C:\Users\Public\Desktop\Movie Magic Screenwriter 6.lnk
[2011/06/03 17:16:05 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/06/03 17:06:34 | 004,111,831 | R--- | M] (Swearware) -- C:\Users\josh\Desktop\ComboFix.exe
[2011/05/31 23:41:29 | 000,102,957 | ---- | M] () -- C:\Users\josh\Desktop\1.jpg
[2011/05/30 18:47:21 | 381,386,495 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/05/29 13:02:03 | 000,000,116 | ---- | M] () -- C:\Users\josh\Adobe Encore_AME.pref
[2011/05/28 23:14:31 | 000,001,024 | ---- | M] () -- C:\.rnd
[2011/05/27 14:00:25 | 000,000,701 | ---- | M] () -- C:\Users\josh\Documents\cast and crew in progress.lnk
[2011/05/23 15:05:48 | 000,027,744 | ---- | M] () -- C:\ProgramData\nvModes.001
[2011/05/22 10:59:59 | 000,003,008 | -HS- | M] () -- C:\Users\josh\AppData\Local\q627c3m4061358n50t62
[2011/05/22 10:59:59 | 000,003,008 | -HS- | M] () -- C:\ProgramData\q627c3m4061358n50t62
[2011/05/14 16:21:45 | 000,027,744 | ---- | M] () -- C:\ProgramData\nvModes.dat
========== Files Created - No Company Name ==========
[2011/06/03 13:10:47 | 000,002,230 | ---- | C] () -- C:\Users\Public\Desktop\Movie Magic Screenwriter 6.lnk
[2011/05/31 23:41:29 | 000,102,957 | ---- | C] () -- C:\Users\josh\Desktop\1.jpg
[2011/05/28 23:14:30 | 000,001,024 | ---- | C] () -- C:\.rnd
[2011/05/28 23:14:18 | 000,000,867 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011/05/27 12:11:53 | 3756,064,768 | -HS- | C] () -- C:\hiberfil.sys
[2011/05/22 11:04:21 | 000,256,512 | ---- | C] () -- C:\Windows\PEV.exe
[2011/05/22 11:04:21 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/05/22 11:04:21 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/05/22 11:04:21 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/05/22 11:04:21 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/05/17 10:00:43 | 000,003,008 | -HS- | C] () -- C:\Users\josh\AppData\Local\q627c3m4061358n50t62
[2011/05/17 10:00:43 | 000,003,008 | -HS- | C] () -- C:\ProgramData\q627c3m4061358n50t62
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2010/11/29 13:00:38 | 000,000,092 | ---- | C] () -- C:\Users\josh\AppData\Local\fusioncache.dat
[2010/02/11 08:51:52 | 000,023,580 | ---- | C] () -- C:\Users\josh\AppData\Roaming\UserTile.png
[2009/11/16 15:14:14 | 000,524,288 | ---- | C] () -- C:\Windows\System32\RegisterDialog.dll
[2009/10/27 08:58:46 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/07/21 21:50:00 | 000,000,000 | ---- | C] () -- C:\Windows\OPPRIN~1.INI
[2009/06/06 18:59:53 | 000,007,916 | ---- | C] () -- C:\Users\josh\AppData\Local\d3d9caps.dat
[2008/12/02 00:41:36 | 000,027,744 | ---- | C] () -- C:\ProgramData\nvModes.001
[2008/12/01 11:58:03 | 000,027,744 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008/10/20 03:04:37 | 000,106,605 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2008/10/20 03:04:37 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/10/17 13:42:31 | 000,164,352 | ---- | C] () -- C:\Users\josh\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/10/17 13:22:50 | 002,463,976 | ---- | C] () -- C:\Windows\System32\NPSWF32.dll
[2008/10/17 12:16:03 | 000,059,392 | ---- | C] () -- C:\Windows\System32\Win32Printer.dll
[2008/10/07 13:49:14 | 000,167,936 | ---- | C] () -- C:\Windows\System32\nvccoin.dll
[2008/10/07 13:49:13 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/10/07 11:18:14 | 000,055,808 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/10/07 11:18:13 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008/10/07 11:11:46 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2008/08/05 18:02:12 | 003,596,288 | ---- | C] () -- C:\Windows\System32\qt-dx331.dll
[2008/08/05 17:58:14 | 000,012,288 | ---- | C] () -- C:\Windows\System32\DivXWMPExtType.dll
[2008/02/08 17:13:44 | 000,319,488 | ---- | C] () -- C:\Windows\System32\LS3Renderer.dll
[2008/02/03 19:11:25 | 000,000,000 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008/01/20 22:24:21 | 000,027,648 | ---- | C] () -- C:\Windows\System32\drivers\filetrace.sys
[2008/01/20 22:24:18 | 000,014,336 | ---- | C] () -- C:\Windows\System32\cmstplua.dll
[2008/01/20 22:23:54 | 000,076,288 | ---- | C] () -- C:\Windows\System32\adsmsext.dll
[2007/06/05 14:20:32 | 000,177,704 | ---- | C] () -- C:\Windows\System32\PSIService.exe
[2006/11/02 08:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:47:37 | 002,501,344 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll
[2006/11/02 06:33:01 | 000,621,554 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,112,084 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:43:43 | 000,013,824 | ---- | C] () -- C:\Windows\System32\cmdkey.exe
[2006/11/02 04:32:08 | 000,015,360 | ---- | C] () -- C:\Windows\System32\doskey.exe
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2003/04/18 16:29:26 | 000,082,432 | ---- | C] () -- C:\Windows\System32\msxml4r.dll
========== LOP Check ==========
[2010/06/27 12:12:22 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Amazon
[2010/12/30 20:15:15 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Beat Hazard
[2010/01/27 23:40:32 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\DAEMON Tools
[2009/09/10 21:00:32 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\gtk-2.0
[2008/11/14 14:38:04 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Inkscape
[2009/09/05 17:45:40 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Lost Marble
[2008/10/17 11:52:34 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Movie Magic Screenwriter
[2009/03/23 16:04:27 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\ourTunes
[2008/12/02 01:39:38 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\PACE Anti-Piracy
[2010/02/11 08:51:52 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\PeerNetworking
[2010/01/28 01:52:57 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Poser Pro
[2010/01/24 00:15:07 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Publish Providers
[2010/01/26 15:12:36 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\Sony
[2009/07/17 09:43:31 | 000,000,000 | ---D | M] -- C:\Users\josh\AppData\Roaming\SoundSpectrum
[2011/06/10 17:22:04 | 000,032,576 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\ERDNT\cache\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SoftwareDistribution\Download.bak\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\SoftwareDistribution\Download.bak\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 22:24:24 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: USERINIT.EXE >
[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\ERDNT\cache\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/20 22:24:49 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
< MD5 for: WINLOGON.EXE >
[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download.bak\cd2b15b1a90e884578188440a1660b12\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\SoftwareDistribution\Download.bak\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\ERDNT\cache\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\System32\winlogon.exe
[2008/01/20 22:24:49 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< %systemroot%\*. /mp /s >
========== Alternate Data Streams ==========
@Alternate Data Stream - 1385 bytes -> C:\ProgramData\Microsoft:vlmDufhypW8pYUHwUTmLtlsN
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A2947BEA
@Alternate Data Stream - 1212 bytes -> C:\ProgramData\Microsoft:ja7CkiHfxPKrVZzL9bHoLtIp
< End of report >