Ok, here is the result from OTL, file named OTL.txt (you said OTLListIt.txt but I didn't see one called that - hoping that was a typo?).
OTL logfile created on: 9/14/2011 8:44:26 PM - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\dward\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.53 Gb Available Physical Memory | 40.38% Memory free
7.60 Gb Paging File | 5.15 Gb Available in Paging File | 67.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.56 Gb Total Space | 294.17 Gb Free Space | 63.19% Space Free | Partition Type: NTFS
Computer Name: DWARD | User Name: dward | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\dward\Desktop\LTO.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrobat.exe (Adobe Systems Incorporated)
PRC - C:\Windows\SysWOW64\atashost.exe (Cisco WebEx LLC)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Program Files (x86)\Lenovo\Access Connections\AcDeskBandHlpr.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Access Connections\SvcGuiHlpr.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Lenovo)
PRC - C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Player\hqtray.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
PRC - C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - c:\Program Files (x86)\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\OCS Inventory Agent\OcsService.exe (
http://www.ocsinventory-ng.org)
PRC - C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe (Lenovo Group Limited)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
PRC - C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Adobe\Acrobat 8.0\PDFMaker\Common\AdobePDFMakerX.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\VMware\VMware Player\zlib1.dll ()
MOD - C:\Program Files (x86)\VMware\VMware Player\libxml2.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (ZuneWlanCfgSvc) -- C:\Program Files\Zune\ZuneWlanCfgSvc.exe (Microsoft Corporation)
SRV:
64bit: - (WMZuneComm) -- C:\Program Files\Zune\WMZuneComm.exe (Microsoft Corporation)
SRV:
64bit: - (ZuneNetworkSvc) -- C:\Program Files\Zune\ZuneNss.exe (Microsoft Corporation)
SRV:
64bit: - (LENOVO.TPKNRSVC) -- C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe (Lenovo Group Limited)
SRV:
64bit: - (LENOVO.CAMMUTE) -- C:\Program Files\Lenovo\Communications Utility\CamMute.exe (Lenovo Group Limited)
SRV:
64bit: - (TPHDEXLGSVC) -- C:\Windows\SysNative\TPHDEXLG64.exe (Lenovo.)
SRV:
64bit: - (TPHKSVC) -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe (Lenovo Group Limited)
SRV:
64bit: - (LENOVO.MICMUTE) -- C:\Program Files\Lenovo\HOTKEY\micmute.exe (Lenovo Group Limited)
SRV:
64bit: - (WiMAXAppSrv) -- C:\Program Files\Intel\WiMAX\Bin\AppSrv.exe (Intel® Corporation)
SRV:
64bit: - (DMAgent) -- C:\Program Files\Intel\WiMAX\Bin\DMAgent.exe (Red Bend Ltd.)
SRV:
64bit: - (EvtEng) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:
64bit: - (RegSrvc) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:
64bit: - (IBMPMSVC) -- C:\Windows\SysNative\ibmpmsvc.exe (Lenovo.)
SRV:
64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Sophos AutoUpdate Service) -- C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
SRV - (SAVService) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
SRV - (SAVAdminService) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
SRV - (swi_service) -- C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos Limited)
SRV - (Sophos Message Router) -- C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe (Sophos Limited)
SRV - (Sophos Agent) -- C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos Limited)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (!SASCORE) -- C:\Program Files (x86)\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV - (LMIMaint) -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (atashost) -- C:\Windows\SysWOW64\atashost.exe (Cisco WebEx LLC)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (LogMeIn) -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (AcSvc) -- C:\Program Files (x86)\Lenovo\Access Connections\AcSvc.exe (Lenovo)
SRV - (AcPrfMgrSvc) -- C:\Program Files (x86)\Lenovo\Access Connections\AcPrfMgrSvc.exe (Lenovo)
SRV - (DozeSvc) -- C:\Program Files (x86)\ThinkPad\Utilities\DZSVC64.EXE (Lenovo.)
SRV - (Power Manager DBC Service) -- C:\Program Files (x86)\ThinkPad\Utilities\PWMDBSVC.EXE (Lenovo)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (VMnetDHCP) -- C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMAuthdService) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe (VMware, Inc.)
SRV - (VMware NAT Service) -- C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMUSBArbService) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
SRV - (UNS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (ufad-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vmware-ufad.exe (VMware, Inc.)
SRV - (CVPND) -- C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (npggsvc) -- C:\Windows\SysWow64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SUService) -- c:\Program Files (x86)\Lenovo\System Update\SUService.exe (Lenovo Group Limited)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HsfXAudioService) -- C:\Windows\SysWOW64\XAudio64.dll (Conexant Systems, Inc.)
SRV - (OCS INVENTORY) -- C:\Program Files (x86)\OCS Inventory Agent\ocsservice.exe (
http://www.ocsinventory-ng.org)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (UleadBurningHelper) -- C:\Program Files (x86)\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
SRV - (IviRegMgr) -- C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (InterVideo)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (SAVOnAccess) -- C:\Windows\SysNative\drivers\savonaccess.sys (Sophos Limited)
DRV:
64bit: - (sdcfilter) -- C:\Windows\SysNative\drivers\sdcfilter.sys (Sophos Plc)
DRV:
64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (SophosBootDriver) -- C:\Windows\SysNative\drivers\SophosBootDriver.sys (Sophos Plc)
DRV:
64bit: - (LMIRfsClientNP) -- C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:
64bit: - (AirDisplay) -- C:\Windows\SysNative\drivers\AVVideoCard.sys (Windows ® Win 7 DDK provider)
DRV:
64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:
64bit: - (LMIRfsDriver) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:
64bit: - (lmimirr) -- C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:
64bit: - (WsAudio_DeviceS(5)) WsAudio_DeviceS(5) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys (Wondershare)
DRV:
64bit: - (WsAudio_DeviceS(4)) WsAudio_DeviceS(4) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys (Wondershare)
DRV:
64bit: - (WsAudio_DeviceS(3)) WsAudio_DeviceS(3) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys (Wondershare)
DRV:
64bit: - (WsAudio_DeviceS(2)) WsAudio_DeviceS(2) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys (Wondershare)
DRV:
64bit: - (WsAudio_DeviceS(1)) WsAudio_DeviceS(1) -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys (Wondershare)
DRV:
64bit: - (PCDSRVC{127174DC-C366ED8B-06020000}_0) -- c:\Program Files\PC-Doctor\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:
64bit: - (CnxtHdAudService) -- C:\Windows\SysNative\drivers\CHDRT64.sys (Conexant Systems Inc.)
DRV:
64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (DzHDD64) -- C:\Windows\SysNative\drivers\DZHDD64.SYS (Lenovo.)
DRV:
64bit: - (TPPWRIF) -- C:\Windows\SysNative\drivers\TPPWR64V.SYS ()
DRV:
64bit: - (e1kexpress) Intel® -- C:\Windows\SysNative\drivers\e1k62x64.sys (Intel Corporation)
DRV:
64bit: - (pmxdrv) -- C:\Windows\SysNative\drivers\pmxdrv.sys ()
DRV:
64bit: - (Shockprf) -- C:\Windows\SysNative\drivers\ApsX64.sys (Lenovo.)
DRV:
64bit: - (TPDIGIMN) -- C:\Windows\SysNative\drivers\ApsHM64.sys (Lenovo.)
DRV:
64bit: - (vmci) -- C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:
64bit: - (vmx86) -- C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:
64bit: - (vmkbd) -- C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.)
DRV:
64bit: - (VMnetuserif) -- C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:
64bit: - (hcmon) -- C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:
64bit: - (vmusb) -- C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:
64bit: - (VMnetBridge) -- C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:
64bit: - (VMnetAdapter) -- C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:
64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (dc3d) MS Hardware Device Detection Driver (HID) -- C:\Windows\SysNative\drivers\dc3d.sys (Microsoft Corporation)
DRV:
64bit: - (CVPNDRVA) -- C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:
64bit: - (NETw5s64) Intel® -- C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:
64bit: - (Impcd) -- C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:
64bit: - (bpmp) -- C:\Windows\SysNative\drivers\bpmp.sys (Intel Corporation)
DRV:
64bit: - (bpusb) -- C:\Windows\SysNative\drivers\bpusb.sys (Intel Corporation)
DRV:
64bit: - (bpenum) -- C:\Windows\SysNative\drivers\bpenum.sys (Intel Corporation)
DRV:
64bit: - (CVirtA) -- C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:
64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:
64bit: - (5U877) -- C:\Windows\SysNative\drivers\5U877.sys (Ricoh co.,Ltd.)
DRV:
64bit: - (IntcDAud) Intel® -- C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:
64bit: - (IBMPMDRV) -- C:\Windows\SysNative\drivers\ibmpmdrv.sys (Lenovo.)
DRV:
64bit: - (rimspci) -- C:\Windows\SysNative\drivers\rimspe64.sys (REDC)
DRV:
64bit: - (sdbus) -- C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:
64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:
64bit: - (rixdpcie) -- C:\Windows\SysNative\drivers\rixdpe64.sys (REDC)
DRV:
64bit: - (TVTI2C) -- C:\Windows\SysNative\drivers\tvti2c.sys (Lenovo (United States) Inc.)
DRV:
64bit: - (HECIx64) Intel® -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (VClone) -- C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:
64bit: - (psadd) -- C:\Windows\SysNative\drivers\psadd.sys (Lenovo (United States) Inc.)
DRV:
64bit: - (HSF_DPV) -- C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:
64bit: - (CAXHWAZL) -- C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:
64bit: - (winachsf) -- C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:
64bit: - (SrvHsfV92) -- C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (SrvHsfWinac) -- C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (SrvHsfHDA) -- C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:
64bit: - (netw5v64) Intel® -- C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (XAudio) -- C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:
64bit: - (smihlp) SMI Helper Driver (smihlp) -- C:\Program Files\ThinkVantage Fingerprint Software\smihlp.sys (UPEK Inc.)
DRV:
64bit: - (DNE) -- C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks, Inc.)
DRV:
64bit: - (lenovo.smi) -- C:\Windows\SysNative\drivers\smiifx64.sys (Lenovo Group Limited)
DRV:
64bit: - (mdmxsdk) -- C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (SASDIFSV) -- C:\Program Files (x86)\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files (x86)\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LMIInfo) -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (vstor2-ws60) -- C:\Program Files (x86)\VMware\VMware Player\vstor2-ws60.sys (VMware, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://www.lenovo.com/welcome/thinkpad [binary data]
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/?ocid=OIE9HP
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.0.0.17:80
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.ubcd4win.com/forum/"
FF:
64bit: - HKLM\Software\MozillaPlugins\@curl.com/Curl.RTE: c:\Program Files (x86)\Curl Corporation\Surge\plugins\np-curl-surge64.dll (Curl, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@curl.com/Curl.RTE.7.0: c:\Program Files (x86)\Curl Corporation\Surge\plugins\np-curl-surge64-7-0.dll (Curl, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.3: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@curl.com/Curl.RTE: c:\Program Files (x86)\Curl Corporation\Surge\plugins\np-curl-surge.dll (Curl, Inc.)
FF - HKLM\Software\MozillaPlugins\@curl.com/Curl.RTE.7.0: c:\Program Files (x86)\Curl Corporation\Surge\plugins\np-curl-surge-7-0.dll (Curl, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.3: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files (x86)\Google\Update\1.2.183.13\npGoogleOneClick8.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll (OnLive)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/07/21 23:21:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/08/08 14:26:27 | 000,000,000 | ---D | M]
[2011/04/18 16:20:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/12/28 11:24:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/30 09:35:58 | 000,171,832 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files (x86)\mozilla firefox\plugins\npatgpc.dll
[2010/11/12 19:53:06 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/09/10 23:09:03 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHOX64.dll (Sophos Limited)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Sophos Web Content Scanner) - {39EA7695-B3F2-4C44-A4BC-297ADA8FD235} - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SophosBHO.dll (Sophos Limited)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IePasswordManagerHelper Class) - {BF468356-BB7E-42D7-9F15-4F3B9BCFCED2} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O2 - BHO: (Bing Bar BHO) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (@C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll,-100) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\MSN Toolbar\Platform\6.3.2322.0\npwinext.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:
64bit: - HKU\.DEFAULT\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKU\S-1-5-18\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..\Toolbar\WebBrowser - No CLSID value found.
O3: - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [AcWin7Hlpr] C:\Program Files (x86)\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [Zune Launcher] C:\Program Files\Zune\ZuneLauncher.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMSS] C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe (Intel Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files (x86)\ThinkPad\Utilities\PWMTR64V.DLL (Lenovo Group Limited)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
O4 - HKLM..\Run: [VMware hqtray] C:\Program Files (x86)\VMware\VMware Player\hqtray.exe (VMware, Inc.)
O4 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880..\Run: [Air Display Support] C:\Program Files\Avatron\Air Display\AirDisplay.exe (Avatron Software, Inc)
O4 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880..\Run: [ShoreTel Personal Call Manager] C:\Program Files (x86)\Shoreline Communications\ShoreWare Client\ShoreTel.exe (ShoreTel Inc.)
O4 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10t_ActiveX.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\All Users\!SASCORE [2011/07/23 00:20:19 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Adobe [2011/09/08 05:15:59 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Apple [2011/09/08 05:15:08 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Apple Computer [2011/09/08 05:16:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Application Data [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Blizzard Entertainment [2011/04/04 20:20:43 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Desktop [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Documents [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Favorites [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\FLEXnet [2011/09/08 05:16:01 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\GroupPolicy [2011/08/19 09:44:54 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Insight Software [2010/12/14 21:51:16 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Insight Software Solutions [2010/12/16 20:13:54 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\InstallShield [2010/06/24 17:27:18 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\install_clap [2011/05/31 19:38:45 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Intel [2010/06/17 18:21:16 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\InterVideo [2011/07/02 20:49:05 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Intuit [2011/07/12 07:08:22 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Kaspersky Lab Setup Files [2010/12/28 10:50:33 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Lenovo [2011/04/04 20:21:17 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\LogMeIn [2011/09/09 18:04:35 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Macrovision [2010/06/24 15:29:27 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Malwarebytes [2011/07/24 11:33:02 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Microsoft [2011/09/09 18:12:51 | 000,000,000 | --SD | M]
O4 - Startup: C:\Users\All Users\Microsoft Help [2011/09/02 09:24:16 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\NOS [2011/01/02 01:45:48 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\ntuser.pol ()
O4 - Startup: C:\Users\All Users\NVIDIA [2010/11/19 15:39:27 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\NVIDIA Corporation [2010/11/19 15:28:56 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PC-Doctor for Windows [2010/11/19 15:32:29 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PCDr [2010/11/19 15:40:23 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\PMB Files [2011/03/15 18:18:31 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\RICOH [2011/06/28 09:16:43 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Rosetta Stone [2011/03/14 13:09:16 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\SecuROM [2010/12/10 13:11:54 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Skype [2010/12/07 10:05:05 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Sophos [2011/03/01 21:44:18 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Sophos Web Intelligence [2011/08/30 01:28:32 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Spybot - Search & Destroy [2011/09/08 05:16:06 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Start Menu [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\Sun [2010/12/28 11:24:34 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\SUPERAntiSpyware.com [2011/07/23 00:20:24 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Temp [2011/05/31 19:35:00 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Templates [2009/07/13 23:08:56 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\All Users\TVersity [2010/12/10 23:52:16 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\Ulead Systems [2010/06/17 18:35:36 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\VMware [2011/09/13 23:51:34 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\WebEx [2011/08/30 01:09:24 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\WindSolutions [2011/07/16 19:16:29 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\{93E26451-CD9A-43A5-A2FA-C42392EA4001} [2010/06/24 16:18:17 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\All Users\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6} [2011/02/02 11:06:44 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\cspackman\AppData [2011/09/08 05:16:06 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\cspackman\Contacts [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Desktop [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Documents [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Downloads [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Favorites [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Links [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Music [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\ntuser.dat ()
O4 - Startup: C:\Users\cspackman\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\cspackman\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\cspackman\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\cspackman\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\cspackman\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\cspackman\ntuser.ini ()
O4 - Startup: C:\Users\cspackman\Pictures [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Saved Games [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Searches [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\cspackman\Videos [2011/09/08 05:16:07 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Default\AppData [2011/01/10 11:07:27 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Default\NTUSER.DAT ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG1 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT.LOG2 ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TM.blf ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Default\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\-Course_Evaluation-2010[1].docx ()
O4 - Startup: C:\Users\dward\.inittool [2011/04/20 15:40:57 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\dward\.maptool [2011/04/20 15:50:33 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\dward\AppData [2010/06/24 17:09:01 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\dward\Application Data [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Contacts [2010/12/07 12:19:12 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Cookies [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\defogger_reenable ()
O4 - Startup: C:\Users\dward\Desktop [2011/09/14 20:34:33 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Documents [2011/09/13 23:11:55 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Downloads [2011/09/13 21:43:49 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Dropbox [2011/09/13 23:54:11 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Favorites [2011/08/30 16:39:40 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Links [2011/09/08 06:00:23 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Local Settings [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Music [2011/09/08 12:41:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\My Documents [2010/12/07 12:19:00 | 000,000,000 | RHSD | M]
O4 - Startup: C:\Users\dward\NetHood [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\New folder [2011/09/09 04:37:33 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\dward\ntuser.dat ()
O4 - Startup: C:\Users\dward\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\dward\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\dward\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\dward\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{044784f8-b41a-11e0-a4a5-e705dd4d2cbf}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{044784f8-b41a-11e0-a4a5-e705dd4d2cbf}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{044784f8-b41a-11e0-a4a5-e705dd4d2cbf}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{3ab40dbe-b689-11e0-93a2-f0def1240dfd}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{3ab40dbe-b689-11e0-93a2-f0def1240dfd}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{3ab40dbe-b689-11e0-93a2-f0def1240dfd}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{4ca35fd9-120e-11e0-9c28-005056c00008}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{4ca35fd9-120e-11e0-9c28-005056c00008}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{4ca35fd9-120e-11e0-9c28-005056c00008}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{5634f079-58e8-11e0-861f-8631e6be1b4c}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{5634f079-58e8-11e0-861f-8631e6be1b4c}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{5634f079-58e8-11e0-861f-8631e6be1b4c}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{59fecae7-c305-11e0-ba97-f0def1240dfd}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{59fecae7-c305-11e0-ba97-f0def1240dfd}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{59fecae7-c305-11e0-ba97-f0def1240dfd}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{79a56f6c-1277-11e0-a3cc-a45a77ecadb3}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{79a56f6c-1277-11e0-a3cc-a45a77ecadb3}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{79a56f6c-1277-11e0-a3cc-a45a77ecadb3}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{84382731-13e2-11e0-adf5-005056c00008}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{84382731-13e2-11e0-adf5-005056c00008}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{84382731-13e2-11e0-adf5-005056c00008}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{c5a47917-d933-11e0-b693-f0def1240dfd}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{c5a47917-d933-11e0-b693-f0def1240dfd}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{c5a47917-d933-11e0-b693-f0def1240dfd}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{d2099440-2290-11e0-9925-e952632e0b07}.TM.blf ()
O4 - Startup: C:\Users\dward\ntuser.dat{d2099440-2290-11e0-9925-e952632e0b07}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.dat{d2099440-2290-11e0-9925-e952632e0b07}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\dward\ntuser.ini ()
O4 - Startup: C:\Users\dward\ntuser.pol ()
O4 - Startup: C:\Users\dward\Pictures [2011/09/08 12:05:29 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\PrintHood [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Recent [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\SAM.LOG1 - Shortcut.lnk = File not found
O4 - Startup: C:\Users\dward\Saved Games [2010/12/30 01:54:47 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\Searches [2011/01/01 23:53:20 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\dward\SendTo [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Start Menu [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Templates [2010/12/07 12:19:00 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\dward\Tracing [2011/09/13 23:52:34 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\dward\Videos [2011/07/22 06:56:56 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\AppData [2011/09/10 22:48:26 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\hward\Application Data [2011/09/10 22:48:26 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\hward\Contacts [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Cookies [2011/09/10 22:48:26 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\hward\Desktop [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Documents [2011/09/10 22:49:34 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Downloads [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Favorites [2011/09/10 22:49:03 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Links [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Local Settings [2011/09/10 22:48:26 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\hward\Music [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\NTUSER.DAT ()
O4 - Startup: C:\Users\hward\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\hward\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\hward\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TM.blf ()
O4 - Startup: C:\Users\hward\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\hward\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\hward\ntuser.ini ()
O4 - Startup: C:\Users\hward\Pictures [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Podcasts [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Saved Games [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Searches [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\hward\Videos [2011/09/10 22:49:01 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe\AppData [2011/07/21 17:30:37 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\jdoe\Application Data [2011/07/21 17:30:37 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe\Contacts [2011/07/21 23:21:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe\Cookies [2011/07/21 17:30:37 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe\Documents [2011/07/21 22:19:36 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe\Favorites [2011/07/21 23:21:14 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\jdoe\Links [2011/07/21 23:21:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe\Local Settings [2011/07/21 17:30:37 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe\NTUSER.DAT ()
O4 - Startup: C:\Users\jdoe\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\jdoe\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\jdoe\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TM.blf ()
O4 - Startup: C:\Users\jdoe\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\jdoe\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\jdoe\Saved Games [2011/09/08 19:39:53 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe\Searches [2011/07/21 23:21:14 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\jdoe\Videos [2011/07/21 23:21:14 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe.DWARD\AppData [2011/09/08 09:33:49 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\jdoe.DWARD\Application Data [2011/09/08 09:33:49 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe.DWARD\Contacts [2011/09/08 09:34:04 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe.DWARD\Cookies [2011/09/08 09:33:49 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe.DWARD\Desktop [2011/09/08 09:33:59 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe.DWARD\Favorites [2011/09/08 09:34:00 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\jdoe.DWARD\Local Settings [2011/09/08 09:33:49 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\jdoe.DWARD\NTUSER.DAT ()
O4 - Startup: C:\Users\jdoe.DWARD\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\jdoe.DWARD\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\jdoe.DWARD\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TM.blf ()
O4 - Startup: C:\Users\jdoe.DWARD\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\jdoe.DWARD\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\jdoe.DWARD\ntuser.ini ()
O4 - Startup: C:\Users\Mcx1-DWARD\AppData [2011/09/08 05:16:08 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Contacts [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Desktop [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Documents [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Downloads [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Favorites [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Links [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Music [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.dat{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Mcx1-DWARD\ntuser.ini ()
O4 - Startup: C:\Users\Mcx1-DWARD\Pictures [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Saved Games [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Searches [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Mcx1-DWARD\Videos [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\AppData [2011/01/13 02:59:08 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Desktop [2011/08/30 01:14:16 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Documents [2011/09/10 22:48:56 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Lenovo [2010/12/28 08:53:05 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Libraries [2011/07/21 23:21:45 | 000,000,000 | RH-D | M]
O4 - Startup: C:\Users\Public\Music [2011/07/21 23:21:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Pictures [2011/07/21 23:21:45 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Public\Recorded TV [2010/12/30 01:12:46 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Sony Online Entertainment [2011/07/21 23:20:55 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Public\Videos [2011/09/08 05:16:08 | 000,000,000 | R--D | M]
O4 - Startup: C:\Users\Support\Desktop [2011/09/08 05:16:08 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\Support\ntuser.dat ()
O4 - Startup: C:\Users\Support\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\Support\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\Support\ntuser.dat{d20992fc-2290-11e0-9925-e952632e0b07}.TM.blf ()
O4 - Startup: C:\Users\Support\ntuser.dat{d20992fc-2290-11e0-9925-e952632e0b07}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\Support\ntuser.dat{d20992fc-2290-11e0-9925-e952632e0b07}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\Sysadmin\My Documents [2011/01/26 16:59:42 | 000,000,000 | ---D | M]
O4 - Startup: C:\Users\TEMP\AppData [2011/09/13 23:51:24 | 000,000,000 | -H-D | M]
O4 - Startup: C:\Users\TEMP\Application Data [2011/09/13 23:51:24 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\TEMP\Cookies [2011/09/13 23:51:24 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\TEMP\Local Settings [2011/09/13 23:51:24 | 000,000,000 | -HSD | M]
O4 - Startup: C:\Users\TEMP\NTUSER.DAT ()
O4 - Startup: C:\Users\TEMP\ntuser.dat.LOG1 ()
O4 - Startup: C:\Users\TEMP\ntuser.dat.LOG2 ()
O4 - Startup: C:\Users\TEMP\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TM.blf ()
O4 - Startup: C:\Users\TEMP\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000001.regtrans-ms ()
O4 - Startup: C:\Users\TEMP\NTUSER.DAT{0509cabc-8276-11e0-bf3f-bde5ae9f88c2}.TMContainer00000000000000000002.regtrans-ms ()
O4 - Startup: C:\Users\TEMP\ntuser.ini ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKU\S-1-5-21-3285435944-2673782006-698548661-1006\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8:
64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra 'Tools' menuitem : Lenovo Password Manager... - {F4F55DC8-0B69-4DFE-BA94-CB677B88B2A3} - C:\Program Files (x86)\Lenovo\Client Security Solution\tvtpwm_ie_com.dll (Lenovo Group Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files (x86)\VMware\VMware Player\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\ProgramData\Sophos Web Intelligence\swi_lsp.dll (Sophos Limited)
O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )
O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: careerbuilder.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: download.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: mainman.dcs ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: mastercontrol.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: miniaturemarket.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: openair.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: salesforce.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: sony.com ([]* in Trusted sites)
O15 - HKU\S-1-5-21-2826600035-753975784-1930528410-5880\..Trusted Domains: stewartcoopercoon.com ([]* in Trusted sites)
O16 - DPF: {3AC3D009-2E89-4F1E-9F51-04D4FBD50122}
http://10.0.0.82/ShoreWareResources/ClientInstall/ShoretelClientInstall.ocx (Shoretel SClientInstall)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mainman.dcs
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9BDD7AAE-2865-4F30-9819-017BF9564AA4}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\nvinitx.dll C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured_x64.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20:
64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) -C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll) -C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\sophos_detoured.dll) -C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) -C:\Program Files (x86)\Sophos\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:
64bit: - Winlogon\Notify\psfus: DllName - (C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll) - C:\Program Files\ThinkVantage Fingerprint Software\psqlpwd.dll (UPEK Inc.)
O22:
64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O28:
64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/13 23:46:07 | 000,000,000 | ---D | C] -- C:\Anything15183A
[2011/09/13 23:46:07 | 000,000,000 | ---D | C] -- \Anything15183A
[2011/09/13 23:44:00 | 000,000,000 | ---D | C] -- C:\Anything30629A
[2011/09/13 23:44:00 | 000,000,000 | ---D | C] -- \Anything30629A
[2011/09/13 23:36:37 | 000,000,000 | ---D | C] -- C:\Anything28886A
[2011/09/13 23:36:37 | 000,000,000 | ---D | C] -- \Anything28886A
[2011/09/13 23:22:29 | 000,000,000 | ---D | C] -- C:\Anything
[2011/09/13 23:22:29 | 000,000,000 | ---D | C] -- \Anything
[2011/09/13 23:22:01 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2011/09/13 23:22:01 | 000,000,000 | --SD | C] -- \32788R22FWJFW
[2011/09/10 23:10:45 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/09/10 23:10:45 | 000,000,000 | -HSD | C] -- \$RECYCLE.BIN
[2011/09/09 18:31:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/09/09 18:31:57 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/09/09 18:31:16 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/09/09 18:31:16 | 000,000,000 | ---D | C] -- \ComboFix
[2011/09/02 09:19:38 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/09/02 09:19:38 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/09/02 09:19:37 | 002,303,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/09/02 09:19:37 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/09/02 09:19:37 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/09/02 09:19:37 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/09/02 09:19:37 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/09/02 09:19:37 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/09/02 09:19:36 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/09/01 17:36:27 | 000,199,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\xmllite.dll
[2011/09/01 17:36:22 | 000,319,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbcjt32.dll
[2011/09/01 17:36:22 | 000,212,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbctrac.dll
[2011/09/01 17:36:22 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbctrac.dll
[2011/09/01 17:36:22 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccp32.dll
[2011/09/01 17:36:22 | 000,122,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccp32.dll
[2011/09/01 17:36:22 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccu32.dll
[2011/09/01 17:36:22 | 000,106,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\odbccr32.dll
[2011/09/01 17:36:22 | 000,086,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccu32.dll
[2011/09/01 17:36:22 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\odbccr32.dll
[2011/09/01 17:36:15 | 001,162,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll
[2011/09/01 17:36:15 | 000,422,400 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2011/09/01 17:36:14 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll
[2011/09/01 17:36:14 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe
[2011/09/01 17:36:14 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll
[2011/09/01 17:36:14 | 000,214,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll
[2011/09/01 17:36:14 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe
[2011/09/01 17:36:14 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll
[2011/09/01 17:36:14 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll
[2011/09/01 17:36:14 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll
[2011/09/01 17:36:14 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe
[2011/09/01 17:36:14 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll
[2011/09/01 17:36:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/01 17:36:14 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/01 17:36:13 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/09/01 17:36:13 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/09/01 17:36:13 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/09/01 17:36:13 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/09/01 17:36:13 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/09/01 17:36:12 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/09/01 17:36:12 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/01 17:36:12 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll[2011/09/01 17:36:12 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/01 17:36:12 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/09/01 17:36:12 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/09/01 17:36:12 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/09/01 17:36:12 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe
[2011/09/01 17:36:09 | 005,507,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2011/09/01 17:36:08 | 003,957,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2011/09/01 17:36:08 | 003,902,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2011/08/30 16:35:39 | 000,000,000 | ---D | C] -- C:\Users\dward\New folder
[2011/08/19 11:02:28 | 000,144,160 | ---- | C] (Sophos Limited) -- C:\Windows\SysNative\drivers\savonaccess.sys
[2011/08/19 11:02:28 | 000,026,104 | ---- | C] (Sophos Plc) -- C:\Windows\SysNative\drivers\sdcfilter.sys
[2011/08/19 11:02:24 | 000,183,024 | ---- | C] (Sophos Plc) -- C:\Windows\SysNative\sdccoinstaller.dll
[2011/08/19 10:56:41 | 000,252,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\drvinst.exe
[2011/08/19 10:56:41 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\devrtl.dll
[2011/08/19 09:44:54 | 000,000,000 | ---D | C] -- C:\ProgramData\GroupPolicy
[2011/07/12 15:55:18 | 000,014,928 | ---- | C] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files (x86)\sasdifsv64.sys
[2011/07/12 15:55:18 | 000,012,368 | ---- | C] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files (x86)\saskutil64.sys
[2011/06/30 07:50:13 | 002,988,928 | ---- | C] (SUPERAntiSpyware.com) -- C:\Program Files (x86)\SUPERAntiSpyware.exe
[2011/05/04 11:55:20 | 000,411,008 | ---- | C] (SUPERAntiSpyware.com) -- C:\Program Files (x86)\SSUpdate64.exe
[2011/05/04 11:55:09 | 000,128,384 | ---- | C] (SUPERAntiSpyware.com) -- C:\Program Files (x86)\SASCore64.exe
[2010/06/29 11:48:34 | 001,401,856 | ---- | C] (SuperAntiSpyware.com) -- C:\Program Files (x86)\deupx2964.dll
[2010/01/07 14:12:12 | 000,190,976 | ---- | C] (SUPERAntiSpyware.com) -- C:\Program Files (x86)\SASCTXMN64.DLL
[2004/05/07 16:31:40 | 000,348,160 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\msvcr71.dll
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/14 20:45:00 | 000,000,382 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/09/14 20:20:07 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/14 19:59:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/14 16:46:51 | 000,734,468 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/14 16:46:51 | 000,629,766 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/14 16:46:51 | 000,108,576 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/13 23:59:52 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/13 23:59:52 | 000,020,704 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/13 23:52:18 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/13 23:50:51 | 3060,531,200 | -HS- | M] () -- C:\hiberfil.sys
[2011/09/10 23:09:03 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/09/07 03:25:00 | 000,000,188 | ---- | M] () -- C:\Users\dward\defogger_reenable
[2011/08/28 07:22:11 | 000,001,234 | ---- | M] () -- C:\Users\dward\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.8.lnk
[2011/08/19 11:02:28 | 000,144,160 | ---- | M] (Sophos Limited) -- C:\Windows\SysNative\drivers\savonaccess.sys
[2011/08/19 11:02:28 | 000,026,104 | ---- | M] (Sophos Plc) -- C:\Windows\SysNative\drivers\sdcfilter.sys
[2011/08/19 11:02:25 | 000,037,400 | ---- | M] (Sophos Limited) -- C:\Windows\SysNative\SophosBootTasks.exe
[2011/08/19 11:02:24 | 000,183,024 | ---- | M] (Sophos Plc) -- C:\Windows\SysNative\sdccoinstaller.dll
[2011/08/19 09:44:48 | 000,001,798 | RHS- | M] () -- C:\Users\dward\ntuser.pol
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/09 18:32:03 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/09/09 18:32:01 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/09/09 18:31:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/09/09 18:31:58 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/09/09 18:31:57 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/09/07 03:25:00 | 000,000,188 | ---- | C] () -- C:\Users\dward\defogger_reenable
[2011/08/28 07:22:11 | 000,001,234 | ---- | C] () -- C:\Users\dward\Application Data\Microsoft\Internet Explorer\Quick Launch\FrostWire 4.21.8.lnk
[2011/07/23 00:20:22 | 000,027,648 | ---- | C] () -- C:\Program Files (x86)\Uninstall.dat
[2011/07/22 11:19:07 | 001,403,723 | ---- | C] () -- C:\Program Files (x86)\PROCESSLISTRELATED.DB
[2011/07/22 11:18:34 | 054,671,816 | ---- | C] () -- C:\Program Files (x86)\PROCESSLIST.DB
[2011/07/12 07:08:34 | 000,000,126 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2011/05/04 11:56:10 | 000,027,520 | ---- | C] () -- C:\Program Files (x86)\SASINST.EXE
[2011/03/30 17:41:32 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2011/02/13 22:17:21 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\grcauth2.dll
[2011/02/13 22:17:21 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\grcauth1.dll
[2011/02/13 22:17:21 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\diit7x7.dll
[2011/02/13 22:17:21 | 000,000,204 | ---- | C] () -- C:\Windows\SysWow64\awrmncx.dll
[2011/02/13 22:17:21 | 000,000,100 | ---- | C] () -- C:\Windows\SysWow64\prsgrc.dll
[2011/02/13 22:17:21 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\qmtn7ft.dll
[2011/02/13 22:17:21 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\serauth2.dll
[2011/02/13 22:17:21 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\serauth1.dll
[2011/02/13 22:17:21 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\nsprs.dll
[2011/02/13 22:17:20 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth2.dll
[2011/02/13 22:17:20 | 000,001,025 | ---- | C] () -- C:\Windows\SysWow64\clauth1.dll
[2011/02/13 22:17:20 | 000,000,072 | ---- | C] () -- C:\Windows\SysWow64\ssprs.dll
[2011/02/13 22:17:17 | 000,000,016 | -H-- | C] () -- C:\Windows\SysWow64\jm1ixs2.dll
[2011/02/10 21:40:36 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2011/01/17 15:56:13 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/12/10 10:30:48 | 000,156,072 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2010/12/07 10:12:22 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/12/07 09:36:21 | 000,030,884 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/11/20 06:56:46 | 3060,531,200 | -HS- | C] () -- \hiberfil.sys
[2010/09/13 13:04:24 | 000,300,544 | ---- | C] () -- C:\Program Files (x86)\RUNSAS.EXE
[2010/08/25 20:34:30 | 000,870,560 | ---- | C] () -- C:\Windows\SysWow64\igkrng575.bin
[2010/08/25 20:34:30 | 000,127,868 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng575.bin
[2010/08/25 20:34:30 | 000,104,796 | ---- | C] () -- C:\Windows\SysWow64\igfcg575m.bin
[2010/06/24 15:45:17 | 000,001,024 | ---- | C] () -- \.rnd
[2010/06/24 15:45:12 | 000,751,686 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/06/17 18:15:51 | 000,208,896 | ---- | C] () -- C:\Windows\SysWow64\iglhsip32.dll
[2010/06/17 18:15:51 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\iglhcp32.dll
[2010/01/25 13:58:06 | 000,462,848 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/08/26 16:31:50 | 000,644,096 | ---- | C] () -- \tvtpwm_message_hook.dll
[2009/07/24 11:28:58 | 000,008,192 | RHS- | C] () -- \BOOTSECT.BAK
[2009/07/24 11:28:56 | 000,383,562 | RHS- | C] () -- \bootmgr
[2009/07/13 23:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:59:36 | 000,982,196 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2009/07/13 15:59:36 | 000,139,824 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2009/07/13 15:59:36 | 000,097,448 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
[2009/07/13 15:59:35 | 000,417,344 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2009/07/13 15:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2008/07/28 12:10:52 | 000,411,136 | ---- | C] () -- C:\Program Files (x86)\SASREPAIRS.STG
[2007/11/27 14:12:26 | 001,088,725 | ---- | C] () -- C:\Program Files (x86)\SUPERAntiSpyware.chm
[2006/12/02 00:37:14 | 000,904,704 | ---- | C] () -- \msdia80.dll
[2004/05/20 14:28:44 | 000,002,048 | ---- | C] () -- C:\Program Files (x86)\detect.wav
< End of report >