Here is the OTLPE log:
OTL logfile created on: 2/24/2011 6:10:06 PM - Run
OTLPE by OldTimer - Version 3.1.44.3 Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional (Version = 6.1.7600) - Type = System
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 214.29 Gb Total Space | 95.65 Gb Free Space | 44.63% Space Free | Partition Type: NTFS
Drive E: | 8.65 Gb Total Space | 3.25 Gb Free Space | 37.58% Space Free | Partition Type: NTFS
Drive X: | 436.55 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2010/07/13 16:26:12 | 000,719,216 | ---- | M] (Wacom Technology, Corp.) [Auto] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV:
64bit: - [2010/07/13 16:26:08 | 007,329,648 | ---- | M] (Wacom Technology, Corp.) [Auto] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:
64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/16 00:40:40 | 000,037,664 | ---- | M] (Apple Inc.) [Auto] -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/10/10 16:33:10 | 000,120,712 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe -- (LMIMaint)
SRV - [2010/09/27 13:52:18 | 000,373,640 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/10/29 01:02:00 | 003,407,292 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand] -- C:\Windows\SysWow64\GameMon.des -- (npggsvc)
SRV - [2009/09/23 15:37:30 | 000,051,168 | ---- | M] (NOS Microsystems Ltd.) [On_Demand] -- C:\Program Files (x86)\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) @C:\Program Files (x86)
SRV - [2009/07/16 16:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/08/11 11:40:58 | 000,057,920 | ---- | M] (LogMeIn, Inc.) [Auto] -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe -- (LogMeIn)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2010/10/10 16:32:59 | 000,087,456 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV:
64bit: - [2010/09/28 15:44:52 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\igdkmd64.sys -- (igfx)
DRV:
64bit: - [2010/05/19 16:52:38 | 000,018,288 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:
64bit: - [2010/01/13 15:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETw5s64.sys -- (NETw5s64) Intel(R)
DRV:
64bit: - [2009/09/29 21:46:11 | 000,871,408 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV:
64bit: - [2009/09/21 18:29:22 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wacomvhid.sys -- (wacomvhid)
DRV:
64bit: - [2009/07/13 20:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\amdsata.sys -- (amdsata)
DRV:
64bit: - [2009/07/13 20:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot] -- C:\Windows\System32\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 16:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand] -- C:\Windows\System32\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2009/06/10 15:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- C:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:
64bit: - [2009/06/10 15:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand] -- C:\Windows\System32\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2009/06/10 15:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\netw5v64.sys -- (netw5v64) Intel(R)
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand] -- C:\Windows\system32\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV:
64bit: - [2008/08/11 11:40:58 | 000,072,216 | ---- | M] (LogMeIn, Inc.) [File_System | Auto] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV:
64bit: - [2007/11/09 04:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:
64bit: - [2007/05/14 16:06:18 | 000,027,520 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand] -- C:\Windows\System32\drivers\RimUsb_AMD64.sys -- (RimUsb)
DRV:
64bit: - [2007/02/16 14:12:36 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand] -- C:\Windows\System32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2009/02/24 17:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand] -- C:\Windows\SysWOW64\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/08/11 11:41:00 | 000,015,928 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto] -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys -- (LMIInfo)
DRV - [2005/01/01 04:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Administrator_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Bowen_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://ca.msn.com/?lang=en-ca&OCID=iehp
IE - HKU\Bowen_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKU\Bowen_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 5E 7A 86 EF 6D D4 CA 01 [binary data]
IE - HKU\Bowen_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\Bowen_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.1
[2011/01/26 19:58:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\Mozilla\Extensions
[2011/01/26 19:58:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\22nxrdcq.default\extensions
[2011/02/13 12:54:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\s7fsd9h1.default\extensions
[2011/02/16 17:40:51 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/07/19 22:45:03 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011/01/27 13:05:00 | 000,000,000 | ---D | M] (RealPlayer Browser Record Plugin) -- C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2010/11/12 18:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/12/21 11:51:44 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/12/21 11:51:44 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/12/21 11:51:44 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/12/21 11:51:44 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/04/30 14:56:09 | 000,001,798 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1
www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BambooCore] C:\Program Files (x86)\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\Bowen_ON_C..\Run: [Bamboo Dock] C:\Program Files (x86)\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe ()
O4 - HKU\Bowen_ON_C..\Run: [LCR] File not found
O4 - HKU\Bowen_ON_C..\Run: [RESTART_STICKY_NOTES] File not found
O4 - HKU\LocalService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [GrpConv] C:\Windows\SysWow64\grpconv.exe (Microsoft Corporation)
O4 - HKU\Administrator_ON_C..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_Plugin.exe (Adobe Systems, Inc.)
O4 - HKU\Bowen_ON_C..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10h_Plugin.exe (Adobe Systems, Inc.)
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Bowen_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13:
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501}
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565}
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/MessengerGamesContent/GameContent/Default/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 206.248.154.22 206.248.154.170
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:
64bit: - AppInit_DLLs: (avgrssta.dll) - File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 06:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/02/17 16:54:33 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2011/02/17 16:14:14 | 006,022,408 | ---- | C] (OPSWAT, Inc.) -- C:\Users\Bowen\Desktop\AppRemover.exe
[2011/02/13 13:30:25 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\WinRAR
[2011/02/06 15:40:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/02/06 15:35:40 | 000,472,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysWow64\deployJava1.dll
[2011/02/06 15:35:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Java
[2011/01/26 20:26:13 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Scanned Documents
[2011/01/26 20:26:13 | 000,000,000 | ---D | C] -- C:\Users\Administrator\Documents\Fax
[2011/01/26 19:57:58 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Mozilla
[2011/01/26 19:57:58 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Local\Mozilla
[2011/01/26 19:44:17 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Apple Computer
[2011/01/26 19:44:12 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Real
[2011/01/26 19:40:46 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\Wacom
[2011/01/26 19:40:38 | 000,000,000 | ---D | C] -- C:\Users\Administrator\AppData\Roaming\WTablet
========== Files - Modified Within 30 Days ==========
[2011/02/17 19:01:30 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/02/17 19:01:20 | 328,335,685 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/02/17 19:01:15 | 3117,412,352 | -HS- | M] () -- C:\hiberfil.sys
[2011/02/17 16:25:05 | 000,721,199 | ---- | M] () -- C:\Users\Bowen\Desktop\rkill.exe
[2011/02/17 16:14:31 | 006,022,408 | ---- | M] (OPSWAT, Inc.) -- C:\Users\Bowen\Desktop\AppRemover.exe
[2011/02/17 16:13:56 | 004,270,552 | ---- | M] () -- C:\Users\Bowen\Desktop\ComboFix.exe
[2011/02/17 11:19:53 | 000,000,298 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3541986981-812281285-174318126-1000.job
[2011/02/15 00:43:21 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2011/02/15 00:43:21 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2011/02/13 22:59:44 | 000,000,600 | ---- | M] () -- C:\Users\Bowen\AppData\Roaming\winscp.rnd
[2011/02/13 13:31:07 | 002,657,282 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/02/13 13:31:07 | 001,126,288 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/02/13 13:25:35 | 000,000,314 | ---- | M] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3541986981-812281285-174318126-500.job
[2011/02/13 12:54:59 | 000,001,444 | ---- | M] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/13 12:54:16 | 000,000,000 | ---- | M] () -- C:\Windows\nsreg.dat
[2011/02/13 12:46:54 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/02/11 13:12:28 | 000,010,819 | ---- | M] () -- C:\Users\Bowen\Desktop\whywaterloo.docx
[2011/02/07 10:54:45 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3541986981-812281285-174318126-1000UA.job
[2011/02/07 10:54:45 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/02/07 02:47:18 | 000,009,940 | ---- | M] () -- C:\Users\Bowen\Documents\mredauto.1
[2011/02/07 00:04:58 | 000,002,409 | ---- | M] () -- C:\Users\Bowen\Desktop\Google Chrome.lnk
[2011/02/06 17:57:16 | 000,000,000 | ---- | M] () -- C:\Users\Bowen\AppData\Local\prvlcl.dat
[2011/02/06 17:06:59 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/02/06 17:06:59 | 000,013,472 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/02/01 18:20:40 | 015,693,798 | ---- | M] () -- C:\Users\Bowen\Desktop\2B.rar
[2011/01/27 06:59:42 | 000,000,162 | -H-- | M] () -- C:\Users\Administrator\Desktop\~$b_report_1_template.docx
========== Files Created - No Company Name ==========
[2011/02/17 16:25:05 | 000,721,199 | ---- | C] () -- C:\Users\Bowen\Desktop\rkill.exe
[2011/02/17 16:13:55 | 004,270,552 | ---- | C] () -- C:\Users\Bowen\Desktop\ComboFix.exe
[2011/02/15 00:25:16 | 000,001,908 | ---- | C] () -- C:\Windows\diagwrn.xml
[2011/02/15 00:25:16 | 000,001,908 | ---- | C] () -- C:\Windows\diagerr.xml
[2011/02/13 22:59:44 | 000,000,600 | ---- | C] () -- C:\Users\Bowen\AppData\Roaming\winscp.rnd
[2011/02/13 13:25:35 | 000,000,314 | ---- | C] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3541986981-812281285-174318126-500.job
[2011/02/13 12:54:59 | 000,001,444 | ---- | C] () -- C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/02/13 12:54:16 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/11 13:12:28 | 000,010,819 | ---- | C] () -- C:\Users\Bowen\Desktop\whywaterloo.docx
[2011/02/07 11:36:49 | 000,000,298 | ---- | C] () -- C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3541986981-812281285-174318126-1000.job
[2011/02/07 02:47:18 | 000,009,940 | ---- | C] () -- C:\Users\Bowen\Documents\mredauto.1
[2011/02/01 18:20:35 | 015,693,798 | ---- | C] () -- C:\Users\Bowen\Desktop\2B.rar
[2011/01/27 06:59:42 | 000,000,162 | -H-- | C] () -- C:\Users\Administrator\Desktop\~$b_report_1_template.docx
[2010/09/22 19:58:08 | 000,815,104 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/09/22 19:58:08 | 000,180,224 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/09/04 12:21:45 | 000,000,614 | ---- | C] () -- C:\Program Files (x86)\RejoinCommandLine.txt
[2010/08/25 18:52:00 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 18:52:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/06/02 15:33:28 | 000,018,760 | ---- | C] () -- C:\Windows\SysWow64\QQVistaHelper.dll
[2010/05/27 19:09:00 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2010/05/05 17:28:24 | 000,000,000 | ---- | C] () -- C:\Users\Bowen\AppData\Local\prvlcl.dat
[2009/11/19 18:26:26 | 000,006,392 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/09/30 15:46:46 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2009/07/13 19:02:54 | 000,245,248 | ---- | C] () -- C:\Windows\SysWow64\DShowRdpFilter.dll
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:25:04 | 000,197,632 | ---- | C] () -- C:\Windows\SysWow64\ir32_32.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
========== LOP Check ==========
[2011/01/26 19:40:46 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Wacom
[2010/08/23 18:32:39 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Audacity
[2009/09/29 21:49:52 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\DAEMON Tools Lite
[2010/05/01 03:33:10 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Dev-Cpp
[2010/01/02 16:44:25 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\ImgBurn
[2009/12/13 12:50:17 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\iWin
[2010/05/25 01:46:19 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\LolClient
[2009/12/23 22:22:18 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\NeopleLauncherDFO
[2009/10/06 16:47:47 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\PLT Scheme
[2011/02/07 15:08:31 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Racket
[2010/12/26 01:58:50 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/06/02 15:37:33 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Tencent
[2010/06/06 03:39:55 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Tunngle
[2011/01/01 03:08:09 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\uTorrent
[2010/12/22 21:36:51 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\Wacom
[2010/12/22 21:36:54 | 000,000,000 | ---D | M] -- C:\Users\Bowen\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2011/02/06 15:29:50 | 000,032,592 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2011/02/13 20:52:41 | 000,292,352 | ---- | M] ()(C:\Users\Bowen\Desktop\_????Preface(edited).doc) -- C:\Users\Bowen\Desktop\_需审阅的Preface(edited).doc
[2011/02/13 20:52:40 | 000,292,352 | ---- | C] ()(C:\Users\Bowen\Desktop\_????Preface(edited).doc) -- C:\Users\Bowen\Desktop\_需审阅的Preface(edited).doc
< End of report >
here is also the mbr checker log:
MBRCheck, version 1.2.3
(c) 2010, AD
Command-line:
Windows Version: Windows 7 Professional
Windows Information: (build 7600), 64-bit
Base Board Manufacturer: TOSHIBA
BIOS Manufacturer: INSYDE
System Manufacturer: TOSHIBA
System Product Name: Satellite L300
Logical Drives Mask: 0x000000bc
Kernel Drivers (total 134):
0x0205B000 \SystemRoot\system32\ntoskrnl.exe
0x02012000 \SystemRoot\system32\hal.dll
0x00BA7000 \SystemRoot\system32\kdcom.dll
0x00CA8000 \SystemRoot\system32\mcupdate_GenuineIntel.dll
0x00CEC000 \SystemRoot\system32\PSHED.dll
0x00D00000 \SystemRoot\system32\CLFS.SYS
0x00E81000 \SystemRoot\system32\CI.dll
0x00F41000 \SystemRoot\system32\drivers\Wdf01000.sys
0x00FE5000 \SystemRoot\system32\drivers\WDFLDR.SYS
0x01070000 \SystemRoot\System32\Drivers\spii.sys
0x011A4000 \SystemRoot\System32\Drivers\WMILIB.SYS
0x011AD000 \SystemRoot\System32\Drivers\SCSIPORT.SYS
0x01000000 \SystemRoot\system32\DRIVERS\ACPI.sys
0x01057000 \SystemRoot\system32\DRIVERS\msisadrv.sys
0x01061000 \SystemRoot\system32\DRIVERS\vdrvroot.sys
0x00E00000 \SystemRoot\system32\DRIVERS\pci.sys
0x011DC000 \SystemRoot\System32\drivers\partmgr.sys
0x011F1000 \SystemRoot\system32\DRIVERS\compbatt.sys
0x00E33000 \SystemRoot\system32\DRIVERS\BATTC.SYS
0x00E3F000 \SystemRoot\system32\DRIVERS\volmgr.sys
0x00D5E000 \SystemRoot\System32\drivers\volmgrx.sys
0x00E54000 \SystemRoot\System32\drivers\mountmgr.sys
0x00E6E000 \SystemRoot\system32\DRIVERS\atapi.sys
0x00DBA000 \SystemRoot\system32\DRIVERS\ataport.SYS
0x00FF4000 \SystemRoot\system32\DRIVERS\msahci.sys
0x00DE4000 \SystemRoot\system32\DRIVERS\PCIIDEX.SYS
0x00DF4000 \SystemRoot\system32\DRIVERS\amdxata.sys
0x00C00000 \SystemRoot\system32\drivers\fltmgr.sys
0x00C4C000 \SystemRoot\system32\drivers\fileinfo.sys
0x01246000 \SystemRoot\System32\Drivers\Ntfs.sys
0x014AC000 \SystemRoot\System32\Drivers\msrpc.sys
0x0150A000 \SystemRoot\System32\Drivers\ksecdd.sys
0x01524000 \SystemRoot\System32\Drivers\cng.sys
0x01597000 \SystemRoot\System32\drivers\pcw.sys
0x015A8000 \SystemRoot\System32\Drivers\Fs_Rec.sys
0x016FF000 \SystemRoot\system32\drivers\ndis.sys
0x01600000 \SystemRoot\system32\drivers\NETIO.SYS
0x01660000 \SystemRoot\System32\Drivers\ksecpkg.sys
0x01803000 \SystemRoot\System32\drivers\tcpip.sys
0x0168B000 \SystemRoot\System32\drivers\fwpkclnt.sys
0x016D5000 \SystemRoot\system32\DRIVERS\vmstorfl.sys
0x015B2000 \SystemRoot\system32\DRIVERS\volsnap.sys
0x016E5000 \SystemRoot\system32\DRIVERS\TVALZ_O.SYS
0x01400000 \SystemRoot\System32\drivers\rdyboost.sys
0x0143A000 \SystemRoot\System32\Drivers\mup.sys
0x016F2000 \SystemRoot\System32\drivers\hwpolicy.sys
0x0144C000 \SystemRoot\System32\DRIVERS\fvevol.sys
0x01486000 \SystemRoot\system32\DRIVERS\disk.sys
0x01200000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS
0x0123B000 \SystemRoot\System32\Drivers\Null.SYS
0x016EA000 \SystemRoot\System32\Drivers\Beep.SYS
0x00C60000 \SystemRoot\System32\drivers\vga.sys
0x00C6E000 \SystemRoot\System32\drivers\VIDEOPRT.SYS
0x00C93000 \SystemRoot\System32\drivers\watchdog.sys
0x00E77000 \SystemRoot\system32\drivers\rdpencdd.sys
0x02265000 \SystemRoot\System32\Drivers\Msfs.SYS
0x02270000 \SystemRoot\System32\Drivers\Npfs.SYS
0x02281000 \SystemRoot\system32\DRIVERS\tdx.sys
0x0229F000 \SystemRoot\system32\DRIVERS\TDI.SYS
0x022AC000 \SystemRoot\System32\Drivers\avgtdia.sys
0x022FD000 \SystemRoot\System32\DRIVERS\netbt.sys
0x02342000 \SystemRoot\system32\drivers\afd.sys
0x023CC000 \SystemRoot\system32\DRIVERS\wfplwf.sys
0x023D5000 \SystemRoot\system32\DRIVERS\pacer.sys
0x02200000 \SystemRoot\system32\DRIVERS\vwififlt.sys
0x02216000 \SystemRoot\system32\DRIVERS\netbios.sys
0x028F0000 \SystemRoot\system32\DRIVERS\rdbss.sys
0x02941000 \SystemRoot\system32\drivers\nsiproxy.sys
0x0294D000 \SystemRoot\system32\drivers\csc.sys
0x029D0000 \SystemRoot\System32\Drivers\dfsc.sys
0x02800000 \SystemRoot\system32\DRIVERS\tunnel.sys
0x02826000 \SystemRoot\system32\DRIVERS\usbuhci.sys
0x02833000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0x02889000 \SystemRoot\system32\DRIVERS\usbehci.sys
0x0289A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0x028BE000 \SystemRoot\system32\DRIVERS\Rt64win7.sys
0x02AA1000 \SystemRoot\system32\DRIVERS\NETw5s64.sys
0x02A00000 \SystemRoot\system32\DRIVERS\vwifibus.sys
0x02A0D000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0x02A2B000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0x02A3A000 \SystemRoot\system32\DRIVERS\mouclass.sys
0x02A49000 \SystemRoot\system32\DRIVERS\cdrom.sys
0x02A73000 \SystemRoot\system32\DRIVERS\GEARAspiWDM.sys
0x02A80000 \SystemRoot\system32\DRIVERS\blbdrive.sys
0x02A91000 \SystemRoot\system32\DRIVERS\CompositeBus.sys
0x029EE000 \SystemRoot\system32\DRIVERS\wacomvhid.sys
0x02225000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS
0x029F1000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS
0x0223E000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0x02249000 \SystemRoot\system32\DRIVERS\AgileVpn.sys
0x03296000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0x032BA000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0x032C6000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0x032F5000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0x03310000 \SystemRoot\system32\DRIVERS\raspptp.sys
0x03331000 \SystemRoot\system32\DRIVERS\rassstp.sys
0x0334B000 \SystemRoot\system32\DRIVERS\rdpbus.sys
0x03356000 \SystemRoot\system32\DRIVERS\termdd.sys
0x0336A000 \SystemRoot\system32\DRIVERS\mcdbus.sys
0x033A7000 \SystemRoot\system32\DRIVERS\swenum.sys
0x033A9000 \SystemRoot\system32\DRIVERS\ks.sys
0x033EC000 \SystemRoot\system32\DRIVERS\umbus.sys
0x03200000 \SystemRoot\system32\DRIVERS\usbhub.sys
0x0325A000 \SystemRoot\system32\DRIVERS\mouhid.sys
0x03267000 \SystemRoot\system32\DRIVERS\wacommousefilter.sys
0x0326F000 \SystemRoot\System32\Drivers\NDProxy.SYS
0x03284000 \SystemRoot\System32\Drivers\crashdmp.sys
0x017F1000 \SystemRoot\System32\Drivers\dump_dumpata.sys
0x0149C000 \SystemRoot\System32\Drivers\dump_msahci.sys
0x013E9000 \SystemRoot\System32\Drivers\dump_dumpfve.sys
0x04EF1000 \SystemRoot\system32\DRIVERS\usbccgp.sys
0x04F0E000 \SystemRoot\system32\DRIVERS\USBD.SYS
0x04F10000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS
0x000B0000 \SystemRoot\System32\win32k.sys
0x04F2B000 \SystemRoot\System32\drivers\Dxapi.sys
0x005B0000 \SystemRoot\System32\drivers\dxg.sys
0x006B0000 \SystemRoot\System32\TSDDD.dll
0x00900000 \SystemRoot\System32\framebuf.dll
0x00B70000 \SystemRoot\System32\ATMFD.DLL
0x04F37000 \SystemRoot\system32\drivers\WudfPf.sys
0x04F58000 \SystemRoot\system32\DRIVERS\nwifi.sys
0x04FAB000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0x04FBE000 \SystemRoot\system32\DRIVERS\bowser.sys
0x04FDC000 \SystemRoot\System32\drivers\mpsdrv.sys
0x04E00000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0x04E2D000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys
0x04E7B000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys
0x77100000 \Windows\System32\ntdll.dll
0x47E20000 \Windows\System32\smss.exe
0xFF420000 \Windows\System32\apisetschema.dll
0xFF130000 \Windows\System32\autochk.exe
0xFE680000 \Windows\System32\shell32.dll
0xFE550000 \Windows\System32\wininet.dll
0x76FE0000 \Windows\System32\kernel32.dll
Processes (total 29):
0 System Idle Process
4 System
260 C:\Windows\System32\smss.exe
344 csrss.exe
380 csrss.exe
388 C:\Windows\System32\wininit.exe
416 C:\Windows\System32\winlogon.exe
488 C:\Windows\System32\services.exe
496 C:\Windows\System32\lsass.exe
504 C:\Windows\System32\lsm.exe
616 C:\Windows\System32\svchost.exe
696 C:\Windows\System32\svchost.exe
780 C:\Windows\System32\svchost.exe
828 C:\Windows\System32\svchost.exe
892 C:\Windows\System32\svchost.exe
948 C:\Windows\System32\svchost.exe
980 C:\Windows\System32\wisptis.exe
108 C:\Windows\System32\svchost.exe
640 C:\Windows\System32\svchost.exe
1136 C:\Windows\System32\svchost.exe
1292 C:\Windows\System32\wisptis.exe
1336 C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
1436 C:\Windows\explorer.exe
1536 C:\Windows\System32\ctfmon.exe
1564 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
1000 C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
1208 C:\Program Files (x86)\Mozilla Firefox\firefox.exe
808 C:\Users\Bowen\Downloads\MBRCheck.exe
1084 C:\Windows\System32\conhost.exe
\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`5dd00000 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000035`f0300000 (NTFS)
PhysicalDrive0 Model Number: WDCWD2500BEVS-26VAT0, Rev: 11.01A11
Size Device Name MBR Status
--------------------------------------------
232 GB \\.\PhysicalDrive0 MBR Code Faked!
SHA1: A7CEF36363F5C16CC311122770D0B9723F5430D3
Found non-standard or infected MBR.
Enter 'Y' and hit ENTER for more options, or 'N' to exit:
Done!