Continuation of OTL.txt
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons:
fox@replace.fx:0.13.3
FF - prefs.js..extensions.enabledAddons:
seo4firefox@seobook.com:3.6.5
FF - prefs.js..extensions.enabledAddons:
seotoolbar@seobook.com:1.1.36
FF - prefs.js..extensions.enabledAddons:
sm@submitter.net:1.0
FF - prefs.js..extensions.enabledAddons: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:7.5.0.4
FF - prefs.js..extensions.enabledAddons: {888d99e7-e8b5-46a3-851e-1ec45da1e644}:13.0.0
FF - prefs.js..extensions.enabledAddons: {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}:0.17
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:1.0
FF - prefs.js..extensions.enabledAddons:
autoreload@yz.com:1.13
FF - prefs.js..extensions.enabledItems:
firebug@software.joehewitt.com:1.6.2
FF - prefs.js..extensions.enabledItems: {8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}:0.16
FF - prefs.js..extensions.enabledItems:
seotoolbar@seobook.com:1.1.3
FF - prefs.js..extensions.enabledItems:
seo4firefox@seobook.com:3.4.2
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..network.proxy.backup.ftp: "222.165.130.82"
FF - prefs.js..network.proxy.backup.ftp_port: 80
FF - prefs.js..network.proxy.backup.socks: "222.165.130.82"
FF - prefs.js..network.proxy.backup.socks_port: 80
FF - prefs.js..network.proxy.backup.ssl: "222.165.130.82"
FF - prefs.js..network.proxy.backup.ssl_port: 80
FF - prefs.js..network.proxy.type: 4
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\User\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\User\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\User\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/02/02 21:49:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{203FB6B2-2E1E-4474-863B-4C483ECCE78E}: C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2.0.0.16\coFFNST\ [2012/09/12 10:24:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/09/11 10:10:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/09/10 22:39:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/11 05:10:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/07/16 14:12:52 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{FCF36B88-1BBA-487f-B64B-D2E8980A9293}: C:\Program Files (x86)\Lenovo\Client Security Solution\PWM Firefox Extension [2011/01/28 00:03:39 | 000,000,000 | ---D | M]
[2011/02/02 20:23:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Extensions
[2012/09/05 21:13:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions
[2012/08/02 17:51:27 | 000,000,000 | ---D | M] (iMacros for Firefox) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2011/05/16 13:15:15 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2012/09/05 21:13:11 | 000,023,140 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
autoreload@yz.com.xpi
[2012/09/01 00:27:15 | 001,625,368 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
firebug@software.joehewitt.com.xpi
[2012/08/31 22:26:35 | 000,238,009 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
fox@replace.fx.xpi
[2012/08/08 13:25:45 | 000,087,184 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
seo4firefox@seobook.com.xpi
[2012/08/02 17:51:25 | 000,221,589 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
seotoolbar@seobook.com.xpi
[2011/05/03 19:06:18 | 000,020,044 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\
sm@submitter.net.xpi
[2012/06/04 11:33:36 | 000,030,312 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}.xpi
[2012/08/27 13:42:34 | 000,270,021 | ---- | M] () (No name found) -- C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\1iqfgxhs.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/05/05 12:05:40 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/11 05:10:03 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:08:02 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2010/03/27 19:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npContribute.dll
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/03/08 06:24:04 | 000,103,168 | ---- | M] (Midasplayer Ltd) -- C:\Program Files (x86)\mozilla firefox\plugins\npmidas.dll
[2012/08/31 22:26:32 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/08/31 22:26:32 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\User\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\User\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Contribute CS5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npContribute.dll
CHR - plugin: king.com - Game controller for firefox (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npmidas.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\User\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\User\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\User\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: Click 2 Save = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahllmicjfilnopfmpmokidfabdacfkpi\1.1_0\
CHR - Extension: Angry Birds = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: SiteAdvisor = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho\3.50.146.2_0\
CHR - Extension: PageSpeed Insights (by Google) = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gplegfbjlmmehdoakndmohflojccocli\2.0.2.0_0\
CHR - Extension: Enhance Views Auto-Watch = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipohphkfcbeoiojnnpplnjmajbcnilof\0.7_0\
CHR - Extension: Click 2 Save = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kobefgncomcambiloeiedmmmpgnljeem\1.1_0\
CHR - Extension: RSS Feed Reader = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp\3.3.9_0\
O1 HOSTS File: ([2011/07/16 16:51:20 | 000,001,569 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1
www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com127.0.0.1 localhost
O2:
64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL File not found
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120910195501.dll (McAfee, Inc.)
O2:
64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120910195502.dll (McAfee, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Norton Safe Web Lite BHO) - {F0DA78E9-6B60-42fb-BC26-EF2CFB8C8FF3} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\CoIEPlg.dll (Symantec Corporation)
O3:
64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Norton Safe Web Lite) - {30CEEEA2-3742-40e4-85DD-812BF1CBB83D} - C:\Program Files (x86)\Norton Safe Web Lite\Engine\2.0.0.16\CoIEPlg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [LENOVO.TPKNRRES] C:\Program Files\Lenovo\Communications Utility\TPKNRRES.exe (Lenovo Group Limited)
O4:
64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe ()
O4:
64bit: - HKLM..\Run: [TPHOTKEY] C:\Program Files\Lenovo\HOTKEY\TPOSDSVC.exe (Lenovo Group Limited)
O4:
64bit: - HKLM..\Run: [TpShocks] C:\Windows\SysNative\TpShocks.exe (Lenovo.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe (Ricoh co.,Ltd.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1000..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1002..\Run: [googletalk] C:\Users\User\AppData\Roaming\Google\Google Talk\googletalk.exe (Google)
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1004..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1005..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1000..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1004..\RunOnce: [] File not found
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1004..\RunOnce: [Lenovoautoqdrive] C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe ()
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1004..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1005..\RunOnce: [] File not found
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1005..\RunOnce: [Lenovoautoqdrive] C:\Program Files (x86)\Common Files\Lenovo\LenovoDrive\LenovoAutoRunReg.exe ()
O4 - HKU\S-1-5-21-2599837038-3619574724-1502302346-1005..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 1
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra 'Tools' menuitem : Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2DA885D4-EDF1-4C58-9165-944537E409B2}: DhcpNameServer = 64.71.255.198 64.71.255.253
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D0A41E55-7780-4E83-88F8-FE9928C2292A}: DhcpNameServer = 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F11D77F5-D788-4787-9466-E0E675062D65}: DhcpNameServer = 64.71.255.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F7643DDD-2053-4BEE-B414-755D7DE7257F}: DhcpNameServer = 8.8.8.8 4.2.2.1
O18:
64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\intu-help-qb2 - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\intu-help-qb2 {84D77A00-41B5-4b8b-8ADF-86486D72E749} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:
64bit: - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:
64bit: - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/10 12:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ]
O33 - MountPoints2\{6e8e9b6b-2839-11e1-82f0-95b9fda48f27}\Shell - "" = AutoRun
O33 - MountPoints2\{6e8e9b6b-2839-11e1-82f0-95b9fda48f27}\Shell\AutoRun\command - "" = "D:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{73107598-2a8e-11e0-ba44-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{73107598-2a8e-11e0-ba44-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009/08/10 17:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/12 20:19:11 | 000,600,064 | ---- | C] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2012/09/12 20:02:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/09/12 10:35:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{50BF63E3-8F79-426A-80B9-BB04AF9A04FF}
[2012/09/12 01:31:12 | 000,000,000 | ---D | C] -- C:\FRST
[2012/09/12 00:00:08 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/09/11 23:25:27 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\User\Desktop\aswMBR.exe
[2012/09/11 23:21:39 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\RK_Quarantine
[2012/09/11 22:34:37 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A28219C4-E02E-4767-8D87-8326FB3A1765}
[2012/09/11 18:20:14 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\AV Software
[2012/09/11 15:16:21 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\SEO Tools
[2012/09/11 15:03:46 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\SMOH
[2012/09/11 13:55:29 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Web Projects
[2012/09/11 10:58:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Roaming\Malwarebytes
[2012/09/11 10:57:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/11 10:57:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/11 10:57:45 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/09/11 10:57:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/11 10:55:21 | 000,000,000 | ---D | C] -- C:\Users\User\Desktop\Desktop Backup
[2012/09/11 10:34:04 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{EF12762E-9422-4FE0-8178-EDE853B10593}
[2012/09/11 10:14:37 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{2789CC6C-A461-4D3C-84DA-3A297AA9F2D1}
[2012/09/10 19:47:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SiteAdvisor
[2012/09/10 19:46:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee.com
[2012/09/10 19:45:21 | 000,010,248 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeclnk.sys
[2012/09/10 19:45:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\McAfee
[2012/09/10 19:45:19 | 000,162,224 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\mfevtps.exe
[2012/09/10 19:45:17 | 000,647,208 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfehidk.sys
[2012/09/10 19:45:17 | 000,487,296 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfefirek.sys
[2012/09/10 19:45:17 | 000,289,664 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfewfpk.sys
[2012/09/10 19:45:17 | 000,229,528 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeavfk.sys
[2012/09/10 19:45:17 | 000,160,792 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfeapfk.sys
[2012/09/10 19:45:17 | 000,100,912 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mferkdet.sys
[2012/09/10 19:45:17 | 000,075,936 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\mfenlfk.sys
[2012/09/10 19:45:16 | 000,065,264 | ---- | C] (McAfee, Inc.) -- C:\Windows\SysNative\drivers\cfwids.sys
[2012/09/10 19:45:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\McAfee
[2012/09/10 19:45:01 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee.com
[2012/09/10 19:45:00 | 000,000,000 | ---D | C] -- C:\Program Files\McAfee
[2012/09/10 19:44:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\McAfee
[2012/09/10 19:41:01 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2012/09/07 18:56:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{BE166267-F768-4E66-96D7-210E997A30A4}
[2012/09/07 16:59:28 | 000,000,000 | -HSD | C] -- C:\Windows\SysNative\%APPDATA%
[2012/09/07 14:18:30 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{AD366A27-5559-468C-AF0D-09C9771C56CC}
[2012/09/06 20:19:48 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A13E4F86-B8CB-468F-BFE1-E3D62019926B}
[2012/09/06 12:24:00 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{1EBB6398-F7FE-456D-9555-8C3B9C059F06}
[2012/08/31 22:15:53 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{4087D341-16A9-4BA9-8FB4-9F6FED077FED}
[2012/08/31 12:38:11 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CB3DD80A-5162-476D-9F15-F3E0668F58AE}
[2012/08/30 23:41:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{28AB2F5E-324F-4FCC-BE4B-D6A45FB00BF1}
[2012/08/30 15:47:39 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C859F252-107F-4E35-8985-0983601DFA65}
[2012/08/29 21:52:45 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A7F7B8BE-4357-4370-8CD2-C74DE695EDAF}
[2012/08/29 13:26:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{28005105-3CC1-480E-A104-E58F240CFF39}
[2012/08/28 23:27:11 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{CBB301F5-0914-44B4-8087-CFFAB6148CDF}
[2012/08/27 12:36:56 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{7A1991B9-63B2-4D55-AE57-7FAD051D4D07}
[2012/08/25 17:27:58 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{14821B7F-AB9B-4E05-A59E-2C3D38DDA233}
[2012/08/24 13:28:40 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\User\Desktop\TDSSKiller.exe
[2012/08/23 17:38:52 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{C1E8FDAC-D2FA-4514-87CF-74A710F32024}
[2012/08/23 11:49:51 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{97EF6901-489A-454F-ACD3-2B5D130A8FAE}
[2012/08/22 14:59:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{7B7C1F95-D0EB-4321-A2F6-CCB2BD2456BA}
[2012/08/21 22:14:19 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{0B2475D9-F5E1-4CCD-94E5-65AA8861B4F4}
[2012/08/20 17:00:22 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{9544AA04-8612-417E-BBC6-AE54104630BF}
[2012/08/20 10:22:15 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A77CBF22-9996-43C9-A344-A77A11C12DC6}
[2012/08/19 21:21:44 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{D5686E41-96BC-493A-B27C-EC7544CC58E1}
[2012/08/17 14:17:41 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{A7D89F9B-6D18-42B6-B375-1642DFB3C772}
[2012/08/17 14:17:01 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{FB3B87CB-BAB4-4D6A-90A3-E777E33DF8B5}
[2012/08/17 11:20:17 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{14D0C7C2-A0B3-43FB-B421-3A70D5BF890B}
[2012/08/16 11:09:42 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{827D84DB-0FC3-464C-B034-3A8EBA95225D}
[2012/08/15 16:08:13 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{05AFB277-63AE-41BD-AE57-CD38E91F4300}
[2012/08/15 08:48:21 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{20289C5A-67A0-471A-AE63-F288F3429D44}
[2012/08/14 17:45:57 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{E30AB018-91C7-4237-ABD5-0860066A4441}
[2012/08/14 17:45:27 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{79B93C8E-C619-46A7-81A3-2581FFE853FE}
[2012/08/13 22:10:43 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{9BE38BBF-301C-4846-B8DC-67BDB8B68F01}
[2012/08/13 22:09:57 | 000,000,000 | ---D | C] -- C:\Users\User\AppData\Local\{6F787983-CF1E-4726-89E4-63366F6BAF3F}
[2011/12/15 15:54:32 | 001,386,496 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\msvbvm60.dll
[2011/12/15 15:54:32 | 001,077,336 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\mscomctl.ocx
[2011/12/15 15:54:32 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\oleaut32.dll
[2011/12/15 15:54:32 | 000,545,280 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\hhctrl.ocx
[2011/12/15 15:54:32 | 000,422,848 | ---- | C] (VideoSoft) -- C:\Program Files (x86)\vsflex7l.ocx
[2011/12/15 15:54:32 | 000,353,864 | ---- | C] (Catalyst Development Corporation) -- C:\Program Files (x86)\cswskax6.ocx
[2011/12/15 15:54:32 | 000,140,488 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\comdlg32.ocx
[2011/12/15 15:54:32 | 000,083,456 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\olepro32.dll
[2011/12/15 15:54:32 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\asycfilt.dll
[2011/12/15 15:54:32 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\stdole2.tlb
[2011/12/15 15:54:32 | 000,003,584 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\comcat.dll
========== Files - Modified Within 30 Days ==========
[2012/09/12 20:41:00 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/09/12 20:41:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/09/12 20:21:13 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599837038-3619574724-1502302346-1002UA.job
[2012/09/12 20:19:16 | 000,600,064 | ---- | M] (OldTimer Tools) -- C:\Users\User\Desktop\OTL.exe
[2012/09/12 20:02:16 | 000,001,839 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/09/12 18:42:13 | 000,244,729 | ---- | M] () -- C:\Users\User\Desktop\bb.png
[2012/09/12 16:17:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/12 10:31:11 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/12 10:31:11 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/12 10:23:32 | 3060,535,296 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/12 09:20:12 | 000,000,512 | ---- | M] () -- C:\Users\User\Desktop\MBR.dat
[2012/09/12 00:00:04 | 640,781,351 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/09/11 23:25:46 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\User\Desktop\aswMBR.exe
[2012/09/11 23:14:17 | 001,378,816 | ---- | M] () -- C:\Users\User\Desktop\RogueKiller.exe
[2012/09/11 23:13:11 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\User\Desktop\TDSSKiller.exe
[2012/09/11 22:02:45 | 000,726,270 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/11 22:02:45 | 000,628,874 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/11 22:02:45 | 000,111,026 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/11 15:53:14 | 000,001,456 | ---- | M] () -- C:\Users\User\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/09/11 10:57:58 | 000,001,124 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/11 05:10:11 | 000,002,059 | ---- | M] () -- C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/09/10 21:21:00 | 000,000,872 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2599837038-3619574724-1502302346-1002Core.job
[2012/09/07 17:04:46 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/08/20 21:06:36 | 000,029,530 | ---- | M] () -- C:\Users\User\Desktop\saa.jpg
[2012/08/15 10:07:10 | 000,001,333 | ---- | M] () -- C:\Users\User\Desktop\index.html
[2012/08/15 08:45:46 | 005,014,920 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2012/09/12 18:42:19 | 000,244,729 | ---- | C] () -- C:\Users\User\Desktop\bb.png
[2012/09/12 09:20:12 | 000,000,512 | ---- | C] () -- C:\Users\User\Desktop\MBR.dat
[2012/09/12 00:00:04 | 640,781,351 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/09/11 23:14:15 | 001,378,816 | ---- | C] () -- C:\Users\User\Desktop\RogueKiller.exe
[2012/09/11 10:57:58 | 000,001,124 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/10 22:49:39 | 000,001,839 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Total Protection.lnk
[2012/08/20 21:06:40 | 000,029,530 | ---- | C] () -- C:\Users\User\Desktop\saa.jpg
[2012/03/11 02:53:52 | 000,000,745 | ---- | C] () -- C:\Windows\WinRos.ini
[2011/12/15 15:54:32 | 000,643,072 | ---- | C] () -- C:\Program Files (x86)\ECLActiveX.ocx
[2011/09/28 17:01:09 | 000,000,600 | ---- | C] () -- C:\Users\User\AppData\Local\PUTTY.RND
[2011/08/30 02:39:19 | 000,000,095 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2011/08/20 17:08:44 | 000,000,031 | ---- | C] () -- C:\Users\User\AppData\Roaming\Days5.ini
[2011/07/31 14:40:33 | 000,009,216 | ---- | C] () -- C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/16 18:09:34 | 000,032,608 | ---- | C] () -- C:\Windows\king-uninstall.exe
[2011/04/06 15:09:15 | 000,000,132 | ---- | C] () -- C:\Users\User\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/02/25 13:31:07 | 000,004,997 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
[2011/02/25 13:26:27 | 000,000,045 | ---- | C] () -- C:\Users\User\AppData\Local\machpro.dat
[2011/02/03 15:04:33 | 000,001,456 | ---- | C] () -- C:\Users\User\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/01/27 23:36:25 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2011/01/27 23:36:25 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2011/01/27 23:36:25 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2011/01/27 23:36:25 | 000,104,796 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2011/01/27 23:36:24 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
========== LOP Check ==========
[2011/02/05 13:34:11 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\BMD12345
[2012/07/31 18:23:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Canon
[2011/02/02 21:04:55 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Lite
[2011/02/02 21:34:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DAEMON Tools Pro
[2011/11/14 21:40:27 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\DancinDogg Golf
[2012/07/07 16:59:56 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\FileZilla
[2012/03/11 02:53:18 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Interactive Data
[2012/02/06 15:54:22 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Kayako
[2011/02/03 09:59:34 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Lenovo
[2011/04/17 13:49:01 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Opera
[2011/11/14 21:45:58 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\OptiShot
[2011/07/31 13:50:08 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Research In Motion
[2011/07/03 13:21:20 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\To-Do DeskList
[2012/05/17 01:04:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Ulead Systems
[2011/04/25 15:09:42 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\Update
[2012/09/10 22:38:33 | 000,000,000 | ---D | M] -- C:\Users\User\AppData\Roaming\uTorrent
[2012/09/12 20:41:00 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012/05/27 01:41:44 | 000,032,622 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/09/12 20:41:00 | 000,000,382 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
< End of report >