OTL logfile created on: 1/16/2014 11:09:23 AM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Users\\Felicia\\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.97 Gb Total Physical Memory | 1.16 Gb Available Physical Memory | 29.28% Memory free
7.93 Gb Paging File | 3.74 Gb Available in Paging File | 47.16% Paging File free
Paging file location(s): ?:\\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 517.33 Gb Free Space | 88.97% Space Free | Partition Type: NTFS
Computer Name: FELICIA-PC | User Name: Felicia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/01/16 11:08:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
PRC - [2013/12/21 00:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe
PRC - [2013/08/06 22:14:57 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\\Program Files (x86)\\Real\\RealPlayer\\Update\\realsched.exe
PRC - [2013/07/02 09:16:32 | 000,507,264 | ---- | M] (Oracle Corporation) -- C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe
PRC - [2013/04/16 02:07:08 | 000,039,056 | ---- | M] () -- C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\rndlresolversvc.exe
PRC - [2009/08/14 19:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe
PRC - [2009/08/14 19:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnat.exe
PRC - [2009/08/14 19:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe
PRC - [2009/07/20 03:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
PRC - [2009/06/09 08:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe
PRC - [2009/06/04 18:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAAnotif.exe
PRC - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe
PRC - [2007/07/19 16:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe
========== Modules (No Company Name) ==========
MOD - [2009/07/20 03:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
========== Services (SafeList) ==========
SRV:64bit: - [2013/11/26 03:18:09 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\SysNative\\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/10/23 17:14:22 | 000,348,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\\Program Files\\Microsoft Security Client\\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2013/10/23 17:14:22 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\\Program Files\\Microsoft Security Client\\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/20 11:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Logishrd\\Bluetooth\\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009/06/09 08:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe -- (DockLoginService)
SRV - [2013/12/21 19:09:25 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/12/21 00:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe -- (AdobeARMservice)
SRV - [2013/12/10 20:57:31 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/07/19 05:01:38 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\\Users\\Felicia\\AppData\\Local\\Temp\\7zS7294\\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2013/04/16 02:07:08 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2011/01/13 13:37:02 | 000,705,856 | ---- | M] (SoftThinks SAS) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell DataSafe Local Backup\\SftService.exe -- (SftService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/08/14 19:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009/08/14 19:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnat.exe -- (VMware NAT Service)
SRV - [2009/08/14 19:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe -- (VMAuthdService)
SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe -- (IAANTMON)
SRV - [2008/12/01 10:49:02 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-ufad.exe -- (ufad-ws60)
SRV - [2007/07/19 16:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe -- (APC UPS Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/09/27 09:53:06 | 000,134,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 07:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 05:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/08/14 19:20:54 | 000,038,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\hcmon.sys -- (hcmon)
DRV:64bit: - [2009/08/14 19:20:48 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2009/08/14 19:20:44 | 000,065,072 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmci.sys -- (vmci)
DRV:64bit: - [2009/08/14 19:20:44 | 000,029,744 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2009/08/14 19:14:28 | 000,076,336 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmx86.sys -- (vmx86)
DRV:64bit: - [2009/08/14 12:40:04 | 000,038,960 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2009/08/14 12:40:04 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2009/07/30 21:58:42 | 000,236,544 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 18:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/07/09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/17 10:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009/06/17 10:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 10:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/17 10:54:14 | 000,013,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2009/06/17 10:54:06 | 000,074,256 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 20:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/05/26 06:13:10 | 000,138,752 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2006/11/01 10:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WimFltr.sys -- (WimFltr)
DRV - [2010/02/17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASENUM.SYS -- (SASENUM)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
DRV - [2008/12/01 10:46:58 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vstor2-ws60.sys -- (vstor2-ws60)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope =
IE:64bit: - HKLM\\..\\SearchScopes\\{5AAEB2D7-D0EB-47E4-94BF-54BC862E9E8F}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE:64bit: - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\..\\SearchScopes\\{A136A9CC-255C-4131-AAB3-7407C8B4C1E5}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://att.my.yahoo.com/\'>http://att.my.yahoo.com/
IE - HKCU\\..\\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files (x86)\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
IE - HKCU\\..\\SearchScopes,DefaultScope = {6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}
IE - HKCU\\..\\SearchScopes\\{03B0EE02-7915-4D0C-BAE9-17A3827F4713}: \"URL\" = http://search.yahoo.com/search?fr=mcafee&p=%7BSearchTerms\'>http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKCU\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7ADSA_en\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADSA_en
IE - HKCU\\..\\SearchScopes\\{6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}: \"URL\" = http://search.yahoo.com/search?fr=chr-atty&p=%7BsearchTerms\'>http://search.yahoo.com/search?fr=chr-atty&p={searchTerms}
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: support%40tubedimmerapp.com:2.6.43
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - user.js - File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_9_900_170.dll File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_9_900_170.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/ShockwavePlayer: C:\\Windows\\SysWOW64\\Adobe\\Director\\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@mcafee.com/MVT: C:\\Program Files (x86)\\McAfee\\Supportability\\MVT\\NPMVTPlugin.dll File not found
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3502.0922: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3508.1109: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3555.0308: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@real.com/nppl3260;version=16.0.2.32: C:\\Program Files (x86)\\Real\\RealPlayer\\Netscape6\\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\MozillaPlugins\\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\MozillaPlugins\\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\MozillaPlugins\\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@real.com/nprpplugin;version=16.0.2.32: C:\\Program Files (x86)\\Real\\RealPlayer\\Netscape6\\nprpplugin.dll (RealPlayer)
FF - HKLM\\Software\\MozillaPlugins\\@realnetworks.com/npdlplugin;version=1: C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\npdlplugin.dll (RealDownloader)
FF - HKLM\\Software\\MozillaPlugins\\Adobe Reader: C:\\Program Files (x86)\\Adobe\\Reader 11.0\\Reader\\AIR\\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Firefox\\Extensions\\\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\Firefox\\Ext\\ [2013/08/06 22:15:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 26.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2013/12/21 19:09:01 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\\software\\mozilla\\Mozilla Firefox 26.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins [2014/01/16 10:08:45 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\\software\\mozilla\\Mozilla Firefox 26.0\\extensions\\\\Components: C:\\Program Files (x86)\\Mozilla Firefox\\components [2013/12/21 19:09:01 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\\software\\mozilla\\Mozilla Firefox 26.0\\extensions\\\\Plugins: C:\\Program Files (x86)\\Mozilla Firefox\\plugins [2014/01/16 10:08:45 | 000,000,000 | ---D | M]
[2013/08/06 20:33:46 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Felicia\\AppData\\Roaming\\Mozilla\\Extensions
[2013/12/12 21:52:19 | 000,000,000 | ---D | M] (No name found) -- C:\\Users\\Felicia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\vy0vsd08.default\\extensions
[2013/12/12 21:52:19 | 000,000,000 | ---D | M] (KeyBar 1.
-- C:\\Users\\Felicia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\vy0vsd08.default\\extensions\\{9ed31f84-c8b3-4926-b950-dff74047ff79}
[2013/10/24 18:50:03 | 000,000,000 | ---D | M] (Tube Dimmer) -- C:\\Users\\Felicia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\vy0vsd08.default\\extensions\\[email protected]
[2013/10/24 18:38:10 | 000,000,997 | ---- | M] () -- C:\\Users\\Felicia\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\vy0vsd08.default\\searchplugins\\conduit.xml
[2013/12/21 19:09:01 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\extensions
[2013/12/21 19:09:00 | 000,000,000 | ---D | M] (No name found) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions
[2013/12/21 19:09:29 | 000,000,000 | ---D | M] (Default) -- C:\\Program Files (x86)\\Mozilla Firefox\\browser\\extensions\\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/08/06 22:15:04 | 000,124,504 | ---- | M] (RealPlayer) -- C:\\Program Files (x86)\\mozilla firefox\\plugins\\nprpplugin.dll
[2011/03/24 09:07:32 | 000,002,024 | ---- | M] () -- C:\\Program Files (x86)\\mozilla firefox\\searchplugins\\McSiteAdvisor.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.msn.com/?pc=UP21&ocid=UP21DHP&dt=022313\'>http://www.msn.com/?pc=UP21&ocid=UP21DHP&dt=022313
CHR - Extension: Google Docs = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\aohghmighlieiainnegkcijnfilokake\\0.5_0\\
CHR - Extension: Google Drive = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\apdfllckaahabafndbhieahigkjlhalf\\6.3_0\\
CHR - Extension: YouTube = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\blpcfgokakmgnkcojhhkbfbldkacnbeo\\4.2.6_0\\
CHR - Extension: Google Search = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\coobgpohoikkiipiblmjeljniedjpjpf\\0.0.0.20_0\\
CHR - Extension: SiteAdvisor = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\fheoggkfdfchfphceeifdbepaooicaho\\3.6.3.1271_0\\
CHR - Extension: RealDownloader = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\idhngdhcfkoamngbedgpaokgjbnpdiji\\1.3.2_0\\
CHR - Extension: Google Wallet = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\nmmhkkegccagdldgiimedpiccmgmieda\\0.0.6.0_1\\
CHR - Extension: Gmail = C:\\Users\\Felicia\\AppData\\Local\\Google\\Chrome\\User Data\\Default\\Extensions\\pjkljhegncpnkpknbcohdijeoejaedia\\7_0\\
O1 HOSTS File: ([2013/07/02 16:42:43 | 000,000,027 | ---- | M]) - C:\\Windows\\SysNative\\drivers\\etc\\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\\Program Files (x86)\\Epson Software\\Easy Photo Print\\EPTBL.dll File not found
O2:64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\\Program Files (x86)\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\\ProgramData\\RealNetworks\\RealDownloader\\BrowserPlugins\\IE\\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\\Program Files (x86)\\Java\\jre7\\bin\\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre7\\bin\\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\\Program Files (x86)\\Yahoo!\\Companion\\Installs\\cpn\\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\\..\\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\\Program Files (x86)\\Epson Software\\Easy Photo Print\\EPTBL.dll File not found
O3 - HKLM\\..\\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files (x86)\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
O3 - HKLM\\..\\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\\..\\Toolbar\\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O4:64bit: - HKLM..\\Run: [IAAnotif] C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [IgfxTray] C:\\Windows\\SysNative\\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [Kernel and Hardware Abstraction Layer] C:\\Windows\\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\\Run: [Logitech Download Assistant] C:\\Windows\\SysNative\\LogiLDA.dll (Logitech, Inc.)
O4:64bit: - HKLM..\\Run: [MSC] c:\\Program Files\\Microsoft Security Client\\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\\Run: [Persistence] C:\\Windows\\SysNative\\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\\Run: [RtHDVCpl] C:\\Program Files\\Realtek\\Audio\\HDA\\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\\Run: [APSDaemon] C:\\Program Files (x86)\\Common Files\\Apple\\Apple Application Support\\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\\Run: [TkBellExe] C:\\Program Files (x86)\\Real\\RealPlayer\\Update\\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\\Run: [CmTray] C:\\Users\\Felicia\\AppData\\Roaming\\Content Manager\\launchCM.exe ()
O4 - HKLM..\\RunOnce: [\"C:\\Program Files (x86)\\Dell DataSafe Local Backup\\Components\\DSUpdate\\DSUpdate.exe\"] C:\\Program Files (x86)\\Dell DataSafe Local Backup\\Components\\DSUpdate\\DSUpdate.exe (Dell)
O4 - Startup: C:\\Users\\Felicia\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\Dell Dock.lnk = File not found
O6 - HKLM\\Software\\Policies\\Microsoft\\Internet Explorer\\Restrictions present
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDrives = 0
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\\Software\\Policies\\Microsoft\\Internet Explorer\\Control Panel present
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDriveTypeAutoRun = 157
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\Explorer: NoDrives = 0
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: LogonHoursAction = 2
O7 - HKCU\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\policies\\System: DontDisplayLogonHoursWarnings = 1
O10:64bit: - Protocol_Catalog9\\Catalog_Entries64\\000000000011 - C:\\Program Files (x86)\\VMware\\VMware Player\\x64\\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\\Catalog_Entries64\\000000000012 - C:\\Program Files (x86)\\VMware\\VMware Player\\x64\\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000011 - C:\\Program Files (x86)\\VMware\\VMware Player\\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\\Catalog_Entries\\000000000012 - C:\\Program Files (x86)\\VMware\\VMware Player\\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\\..Trusted Domains: alpineaccess.com ([]* in Trusted sites)
O15 - HKCU\\..Trusted Domains: alpineaccess.net ([]* in Trusted sites)
O15 - HKCU\\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKCU\\..Trusted Ranges: Range2 ([http] in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab\'>http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab\'>http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} http://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID=%7B896A23A1-5821-4609-A6C6-6D5536C585C9\'>http://webiq005.webiqonline.com/WebIQ/DataServer/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9} (WebIQ Engine Application Object)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77} http://i.dell.com/images/global/js/scanner/SysProExe.cab\'>http://i.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} http://support.dell.com/systemprofiler/SysProExe.CAB\'>http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1274551454442\'>http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1274551454442 (MUCatalogWebControl Class)
O16 - DPF: {66F7F252-3FE1-4650-B1E5-94B2A38271C5} http://treehouse.no-ip.biz/ActiveView.cab\'>http://treehouse.no-ip.biz/ActiveView.cab (ActiveView Control)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB\'>http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} http://games.att.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab\'>http://games.att.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cab (Oberon Flash Game Host)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab\'>http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{28C31212-6713-4A47-8872-34C779D8B726}: NameServer = 10.124.6.3,10.124.3.2
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{471273CC-2F13-4283-A8E4-077C3C484F05}: DhcpNameServer = 192.168.1.254
O17 - HKLM\\System\\CCS\\Services\\Tcpip\\Parameters\\Interfaces\\{47AF739C-9211-470F-8886-1F12156AA75E}: NameServer = 10.124.6.3,10.124.3.2
O18:64bit: - Protocol\\Handler\\ms-help - No CLSID value found
O18:64bit: - Protocol\\Handler\\ms-itss - No CLSID value found
O18:64bit: - Protocol\\Handler\\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\\Handler\\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\\Windows\\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysNative\\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\\Windows\\SysWow64\\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\\Windows\\system32\\userinit.exe) - C:\\Windows\\SysWOW64\\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\\Notify\\GoToAssist: DllName - (C:\\Program Files (x86)\\Citrix\\GoToAssist\\514\\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\\Notify\\igfxcui: DllName - (igfxdev.dll) - C:\\Windows\\SysNative\\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\\Notify\\LBTWlgn: DllName - (c:\\program files\\common files\\logishrd\\bluetooth\\LBTWlgn.dll) - c:\\Program Files\\Common Files\\Logishrd\\Bluetooth\\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\\Notify\\!SASWinLogon: DllName - (C:\\Program Files (x86)\\SUPERAntiSpyware\\SASWINLO.dll) - C:\\Program Files (x86)\\SUPERAntiSpyware\\SASWINLO.dll (SUPERAntiSpyware.com)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\\Program Files (x86)\\SUPERAntiSpyware\\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\\..comfile [open] -- \"%1\" %*
O35:64bit: - HKLM\\..exefile [open] -- \"%1\" %*
O35 - HKLM\\..comfile [open] -- \"%1\" %*
O35 - HKLM\\..exefile [open] -- \"%1\" %*
O37:64bit: - HKLM\\...com [@ = ComFile] -- \"%1\" %*
O37:64bit: - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O37 - HKLM\\...com [@ = ComFile] -- \"%1\" %*
O37 - HKLM\\...exe [@ = exefile] -- \"%1\" %*
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2014/01/16 11:08:40 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
[2014/01/16 09:17:41 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\McAfee Security Scan Plus
[2014/01/16 09:17:38 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\McAfee Security Scan
[2014/01/16 00:57:50 | 000,000,000 | ---D | C] -- C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\McAfee
[2014/01/14 22:22:27 | 000,000,000 | ---D | C] -- C:\\Program Files\\McAfee.com
[2014/01/14 22:22:27 | 000,000,000 | ---D | C] -- C:\\Program Files\\McAfee
[2014/01/14 22:22:22 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\McAfee
[2014/01/14 21:29:20 | 000,000,000 | ---D | C] -- C:\\Program Files\\Common Files\\McAfee
[2014/01/12 16:44:31 | 000,000,000 | ---D | C] -- C:\\ProgramData\\HPSSUPPLY
[2014/01/11 22:58:16 | 000,000,000 | ---D | C] -- C:\\Program Files\\Microsoft Silverlight
[2014/01/11 22:58:16 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Microsoft Silverlight
[2013/12/30 21:43:03 | 000,000,000 | ---D | C] -- C:\\Users\\Felicia\\AppData\\Roaming\\PCHC
[2013/12/24 21:43:17 | 000,000,000 | ---D | C] -- C:\\Users\\Felicia\\AppData\\Local\\{59D4B796-5903-43EA-8562-2DD263B4CA6A}
[2013/12/21 19:09:00 | 000,000,000 | ---D | C] -- C:\\Program Files (x86)\\Mozilla Firefox
[2 C:\\Users\\Felicia\\AppData\\Local\\*.tmp files -> C:\\Users\\Felicia\\AppData\\Local\\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2014/01/16 11:08:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
[2014/01/16 10:57:00 | 000,000,830 | ---- | M] () -- C:\\Windows\\tasks\\Adobe Flash Player Updater.job
[2014/01/16 10:12:29 | 000,022,464 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/01/16 10:12:29 | 000,022,464 | -H-- | M] () -- C:\\Windows\\SysNative\\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/01/16 10:04:39 | 000,067,584 | --S- | M] () -- C:\\Windows\\bootstat.dat
[2014/01/16 10:04:28 | 3193,688,064 | -HS- | M] () -- C:\\hiberfil.sys
[2014/01/16 10:03:05 | 000,000,000 | -H-- | M] () -- C:\\Windows\\SysNative\\drivers\\Msft_Kernel_LUsbFilt_01005.Wdf
[2 C:\\Users\\Felicia\\AppData\\Local\\*.tmp files -> C:\\Users\\Felicia\\AppData\\Local\\*.tmp -> ]
========== Files Created - No Company Name ==========
[2014/01/16 10:03:05 | 000,000,000 | -H-- | C] () -- C:\\Windows\\SysNative\\drivers\\Msft_Kernel_LUsbFilt_01005.Wdf
[2013/08/29 23:42:10 | 000,203,703 | ---- | C] () -- C:\\Windows\\hpwins26.dat.temp
[2013/08/29 23:42:10 | 000,000,370 | ---- | C] () -- C:\\Windows\\hpwmdl26.dat.temp
[2013/08/29 22:45:56 | 000,204,350 | ---- | C] () -- C:\\Windows\\hpwins26.dat
[2013/08/29 22:45:55 | 000,000,370 | ---- | C] () -- C:\\Windows\\hpwmdl26.dat
[2013/07/02 16:34:16 | 000,256,000 | ---- | C] () -- C:\\Windows\\PEV.exe
[2013/07/02 16:34:16 | 000,208,896 | ---- | C] () -- C:\\Windows\\MBR.exe
[2013/07/02 16:34:16 | 000,098,816 | ---- | C] () -- C:\\Windows\\sed.exe
[2013/07/02 16:34:16 | 000,080,412 | ---- | C] () -- C:\\Windows\\grep.exe
[2013/07/02 16:34:16 | 000,068,096 | ---- | C] () -- C:\\Windows\\zip.exe
[2013/06/27 21:34:47 | 000,000,151 | ---- | C] () -- C:\\Windows\\Reimage.ini
[2011/06/17 00:34:30 | 000,001,246 | -HS- | C] () -- C:\\ProgramData\\2jfc8wwm7ycpfm031iq1747w633v26o7v3ik
[2011/05/14 21:48:19 | 000,000,032 | RH-- | C] () -- C:\\ProgramData\\hash.dat
[2011/04/13 20:33:50 | 000,000,632 | RHS- | C] () -- C:\\Users\\Felicia\\ntuser.pol
[2010/04/11 12:44:39 | 000,001,578 | -H-- | C] () -- C:\\Users\\Felicia\\AppData\\Roaming\\wklnhst.dat
[2010/04/07 12:01:49 | 000,004,608 | ---- | C] () -- C:\\Users\\Felicia\\AppData\\Local\\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/03 11:33:17 | 000,000,056 | -H-- | C] () -- C:\\ProgramData\\ezsidmv.dat
========== ZeroAccess Check ==========
[2009/07/13 22:55:00 | 000,000,227 | RHS- | M] () -- C:\\Windows\\assembly\\Desktop.ini
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64
[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
[HKEY_CURRENT_USER\\Software\\Classes\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32] /64
[HKEY_CURRENT_USER\\Software\\Classes\\Wow6432node\\clsid\\{fbeb8a05-beee-4442-804e-409d6c4515e9}\\InProcServer32]
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\shell32.dll -- [2013/07/25 20:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Apartment
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{42aedc87-2188-41fd-b9a3-0c966feabec1}\\InProcServer32]
\"\" = %SystemRoot%\\system32\\shell32.dll -- [2013/07/25 19:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Apartment
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\wbem\\fastprox.dll -- [2009/07/13 19:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Free
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\\InProcServer32]
\"\" = %systemroot%\\system32\\wbem\\fastprox.dll -- [2010/11/20 06:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Free
[HKEY_LOCAL_MACHINE\\Software\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32] /64
\"\" = C:\\Windows\\SysNative\\wbem\\wbemess.dll -- [2009/07/13 19:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
\"ThreadingModel\" = Both
[HKEY_LOCAL_MACHINE\\Software\\Wow6432Node\\Classes\\clsid\\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\\ProgramData\\TEMP:DFC5A2B2
@Alternate Data Stream - 123 bytes -> C:\\ProgramData\\TEMP:C46995DA
@Alternate Data Stream - 109 bytes -> C:\\ProgramData\\TEMP:A8ADE5D8
< End of report >
OTL logfile created on: 1/16/2014 11:09:23 AM - Run 6
OTL by OldTimer - Version 3.2.69.0 Folder = C:\\Users\\Felicia\\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16428)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.97 Gb Total Physical Memory | 1.16 Gb Available Physical Memory | 29.28% Memory free
7.93 Gb Paging File | 3.74 Gb Available in Paging File | 47.16% Paging File free
Paging file location(s): ?:\\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\\Windows | %ProgramFiles% = C:\\Program Files (x86)
Drive C: | 581.48 Gb Total Space | 517.33 Gb Free Space | 88.97% Space Free | Partition Type: NTFS
Computer Name: FELICIA-PC | User Name: Felicia | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/01/16 11:08:40 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\\Users\\Felicia\\Desktop\\OTL.exe
PRC - [2013/12/21 00:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe
PRC - [2013/08/06 22:14:57 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\\Program Files (x86)\\Real\\RealPlayer\\Update\\realsched.exe
PRC - [2013/07/02 09:16:32 | 000,507,264 | ---- | M] (Oracle Corporation) -- C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jucheck.exe
PRC - [2013/04/16 02:07:08 | 000,039,056 | ---- | M] () -- C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\rndlresolversvc.exe
PRC - [2009/08/14 19:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe
PRC - [2009/08/14 19:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) -- C:\\Windows\\SysWOW64\\vmnat.exe
PRC - [2009/08/14 19:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe
PRC - [2009/07/20 03:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
PRC - [2009/06/09 08:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe
PRC - [2009/06/04 18:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAAnotif.exe
PRC - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe
PRC - [2007/07/19 16:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe
========== Modules (No Company Name) ==========
MOD - [2009/07/20 03:00:00 | 000,077,824 | ---- | M] () -- C:\\Program Files\\Logitech\\SetPoint\\x86\\SetPoint32.exe
========== Services (SafeList) ==========
SRV:64bit: - [2013/11/26 03:18:09 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Windows\\SysNative\\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/10/23 17:14:22 | 000,348,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\\Program Files\\Microsoft Security Client\\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2013/10/23 17:14:22 | 000,023,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\\Program Files\\Microsoft Security Client\\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2013/05/26 23:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\\Program Files\\Windows Defender\\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/20 11:36:14 | 000,160,784 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\\Program Files\\Common Files\\Logishrd\\Bluetooth\\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2009/06/09 08:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\\Program Files\\Dell\\DellDock\\DockLogin.exe -- (DockLoginService)
SRV - [2013/12/21 19:09:25 | 000,119,408 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\\Program Files (x86)\\Mozilla Maintenance Service\\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/12/21 00:04:16 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\\Program Files (x86)\\Common Files\\Adobe\\ARM\\1.0\\armsvc.exe -- (AdobeARMservice)
SRV - [2013/12/10 20:57:31 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/07/19 05:01:38 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\\Users\\Felicia\\AppData\\Local\\Temp\\7zS7294\\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2013/04/16 02:07:08 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\\Program Files (x86)\\RealNetworks\\RealDownloader\\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2011/01/13 13:37:02 | 000,705,856 | ---- | M] (SoftThinks SAS) [Disabled | Stopped] -- C:\\Program Files (x86)\\Dell DataSafe Local Backup\\SftService.exe -- (SftService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v4.0.30319\\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/08/14 19:19:44 | 000,326,192 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2009/08/14 19:19:30 | 000,399,920 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Windows\\SysWOW64\\vmnat.exe -- (VMware NAT Service)
SRV - [2009/08/14 19:19:24 | 000,113,200 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-authd.exe -- (VMAuthdService)
SRV - [2009/06/10 15:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/04 18:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\\Program Files (x86)\\Intel\\Intel Matrix Storage Manager\\IAANTmon.exe -- (IAANTMON)
SRV - [2008/12/01 10:49:02 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vmware-ufad.exe -- (ufad-ws60)
SRV - [2007/07/19 16:54:48 | 000,689,408 | ---- | M] (American Power Conversion Corporation) [Auto | Running] -- C:\\Program Files (x86)\\APC\\APC PowerChute Personal Edition\\mainserv.exe -- (APC UPS Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2013/09/27 09:53:06 | 000,134,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 00:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\\Windows\\SysNative\\drivers\\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/11 00:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 07:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 05:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/08/14 19:20:54 | 000,038,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\hcmon.sys -- (hcmon)
DRV:64bit: - [2009/08/14 19:20:48 | 000,030,256 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetuserif.sys -- (VMnetuserif)
DRV:64bit: - [2009/08/14 19:20:44 | 000,065,072 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmci.sys -- (vmci)
DRV:64bit: - [2009/08/14 19:20:44 | 000,029,744 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\VMkbd.sys -- (vmkbd)
DRV:64bit: - [2009/08/14 19:14:28 | 000,076,336 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmx86.sys -- (vmx86)
DRV:64bit: - [2009/08/14 12:40:04 | 000,038,960 | R--- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetbridge.sys -- (VMnetBridge)
DRV:64bit: - [2009/08/14 12:40:04 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\vmnetadapter.sys -- (VMnetAdapter)
DRV:64bit: - [2009/07/30 21:58:42 | 000,236,544 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/13 19:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 19:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 18:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 18:35:37 | 000,025,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WSDScan.sys -- (WSDScan)
DRV:64bit: - [2009/07/09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/17 10:54:46 | 000,040,976 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LUsbFilt.sys -- (LUsbFilt)
DRV:64bit: - [2009/06/17 10:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2009/06/17 10:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2009/06/17 10:54:14 | 000,013,328 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2009/06/17 10:54:06 | 000,074,256 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2009/06/10 14:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 14:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 14:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 14:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 20:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\\Windows\\SysNative\\drivers\\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/05/26 06:13:10 | 000,138,752 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\\Windows\\SysNative\\drivers\\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2006/11/01 10:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysNative\\drivers\\WimFltr.sys -- (WimFltr)
DRV - [2010/02/17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\sasdifsv.sys -- (SASDIFSV)
DRV - [2010/02/17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/02/17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\\Program Files (x86)\\SUPERAntiSpyware\\SASENUM.SYS -- (SASENUM)
DRV - [2009/07/13 19:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\\Windows\\SysWOW64\\drivers\\wimmount.sys -- (WIMMount)
DRV - [2008/12/01 10:46:58 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\\Program Files (x86)\\VMware\\VMware Player\\vstor2-ws60.sys -- (vstor2-ws60)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\\..\\SearchScopes,DefaultScope =
IE:64bit: - HKLM\\..\\SearchScopes\\{5AAEB2D7-D0EB-47E4-94BF-54BC862E9E8F}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE:64bit: - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
IE - HKLM\\..\\SearchScopes,DefaultScope =
IE - HKLM\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKLM\\..\\SearchScopes\\{A136A9CC-255C-4131-AAB3-7407C8B4C1E5}: \"URL\" = http://www.bing.com/search?q=%7BsearchTerms%7D&form=DLCDF8&pc=MDDC&src=IE-SearchBox\'>http://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
IE - HKCU\\SOFTWARE\\Microsoft\\Internet Explorer\\Main,Start Page = http://att.my.yahoo.com/\'>http://att.my.yahoo.com/
IE - HKCU\\..\\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\Program Files (x86)\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll (Yahoo! Inc.)
IE - HKCU\\..\\SearchScopes,DefaultScope = {6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}
IE - HKCU\\..\\SearchScopes\\{03B0EE02-7915-4D0C-BAE9-17A3827F4713}: \"URL\" = http://search.yahoo.com/search?fr=mcafee&p=%7BSearchTerms\'>http://search.yahoo.com/search?fr=mcafee&p={SearchTerms}
IE - HKCU\\..\\SearchScopes\\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: \"URL\" = http://www.google.com/search?q=%7BsearchTerms%7D&rls=com.microsoft:%7Blanguage%7D:%7Breferrer:source?%7D&ie=%7BinputEncoding%7D&oe=%7BoutputEncoding%7D&sourceid=ie7&rlz=1I7ADSA_en\'>http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7ADSA_en
IE - HKCU\\..\\SearchScopes\\{6A50FBDC-5DF4-4c9c-9B3B-2749F6FF4D24}: \"URL\" = http://search.yahoo.com/search?fr=chr-atty&p=%7BsearchTerms\'>http://search.yahoo.com/search?fr=chr-atty&p={searchTerms}
IE - HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings: \"ProxyEnable\" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: support%40tubedimmerapp.com:2.6.43
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:26.0
FF - user.js - File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\system32\\Macromed\\Flash\\NPSWF64_11_9_900_170.dll File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~1\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/FlashPlayer: C:\\Windows\\SysWOW64\\Macromed\\Flash\\NPSWF32_11_9_900_170.dll ()
FF - HKLM\\Software\\MozillaPlugins\\@adobe.com/ShockwavePlayer: C:\\Windows\\SysWOW64\\Adobe\\Director\\np32dsw_1205146.dll (Adobe Systems, Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/DTPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\dtplugin\\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@java.com/JavaPlugin,version=10.45.2: C:\\Program Files (x86)\\Java\\jre7\\bin\\plugin2\\npjp2.dll (Oracle Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@mcafee.com/MVT: C:\\Program Files (x86)\\McAfee\\Supportability\\MVT\\NPMVTPlugin.dll File not found
FF - HKLM\\Software\\MozillaPlugins\\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\\Program Files (x86)\\Yahoo!\\Shared\\npYState.dll (Yahoo! Inc.)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/OfficeAuthz,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/SharePoint,version=14.0: C:\\PROGRA~2\\MICROS~2\\Office14\\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3502.0922: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3508.1109: C:\\Program Files (x86)\\Windows Live\\Photo Gallery\\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\\Software\\MozillaPlugins\\@microsoft.com/WLPG,version=15.4.3555.0308: C:\\Program Files (x86)\\