Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

How do I remove Win32/Heur from my pc. I have Windows 7 pro.


  • Please log in to reply

#1
Ed Jump

Ed Jump

    New Member

  • Member
  • Pip
  • 1 posts
Good morning All. As it will be easy to tell, I am ignorant of pc's and viruses. I currently have Windows 7 pro, with AVG (free edition) as my security. When doing an AVG scan last night, it showed that I have picked up the Win32/Heur virus. Is there any way for me to remove it safely? Thank y'all for any help you can give me, it's greatly appreciated !!!

BTW, I followed your directions, and the entire OTL file is pasted below;

OTL logfile created on: 3/8/2011 9:49:07 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\Ed Jump\Desktop
An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 52.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 221.64 Gb Total Space | 190.41 Gb Free Space | 85.91% Space Free | Partition Type: NTFS
Drive D: | 252.58 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: EDJUMP-PC | User Name: Ed Jump | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/03/08 09:48:09 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ed Jump\Desktop\OTL.exe
PRC - [2011/03/06 15:03:32 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/07 01:22:44 | 001,084,256 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2011/01/07 01:22:12 | 001,052,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2011/01/05 23:19:16 | 002,614,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:56:58 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2009/11/25 18:50:10 | 002,011,205 | ---- | M] (Informer Technologies, Inc.) -- C:\Program Files\Software Informer\softinfo.exe
PRC - [2009/08/17 16:40:54 | 000,079,168 | ---- | M] (Broadcom Corp.) -- C:\Program Files\Broadcom\BPowMon\BPowMon.exe
PRC - [2009/07/13 19:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009/07/13 19:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/03/31 16:01:42 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) -- C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe
PRC - [2007/01/01 15:22:02 | 003,739,648 | ---- | M] (Google) -- C:\Program Files\Google\Google Talk\googletalk.exe
PRC - [2005/06/30 15:28:58 | 000,073,728 | ---- | M] () -- C:\Program Files\EasyOffice\EasyOpen.exe
PRC - [2003/09/01 01:10:00 | 000,425,984 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org1.1.0\program\soffice.exe
PRC - [2003/02/07 14:36:36 | 000,053,248 | ---- | M] () -- C:\Program Files\EasyOffice\EasySpeller.exe


========== Modules (SafeList) ==========

MOD - [2011/03/08 09:48:09 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ed Jump\Desktop\OTL.exe
MOD - [2011/01/05 23:19:14 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - [2011/01/30 01:58:54 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2009/08/17 16:40:54 | 000,079,168 | ---- | M] (Broadcom Corp.) [Auto | Running] -- C:\Program Files\Broadcom\BPowMon\BPowMon.exe -- (BPowMon)
SRV - [2009/07/13 19:16:15 | 000,016,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2009/07/13 19:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 19:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 19:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/31 16:01:42 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\Realtek\Audio\HDA\AERTSrv.exe -- (AERTFilters)


========== Driver Services (SafeList) ==========

DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/13 15:27:54 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/03 15:24:18 | 000,021,072 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/08/03 15:24:16 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/03 15:24:12 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/07/30 17:35:30 | 000,021,744 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Running] -- c:\Program Files\Dell Support Center\pcdsrvc.pkms -- (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2009/08/21 14:50:48 | 000,273,960 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\k57nd60x.sys -- (k57nd60x) Broadcom NetLink ™
DRV - [2009/07/13 19:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009/07/13 19:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009/07/13 19:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009/07/13 17:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009/07/13 17:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbInc1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USSMB/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.getfreefl...com/search.html
IE - HKCU\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbInc1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "MyStart Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.reference.com/"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.8
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {fe0258ab-4f74-43a1-8781-bcdf340f9ee9}:2.6.4
FF - prefs.js..extensions.enabledItems: {f69e22c7-bc50-414a-9269-0f5c344cd94c}:0.7
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.7.2
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:0.2.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.0
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:5.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.2.4
FF - prefs.js..extensions.enabledItems: [email protected]:2.1
FF - prefs.js..extensions.enabledItems: {a27007d0-bec0-4df7-abf8-54ae0b833ce8}:1.2.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:3.9.1.14019
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.06
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.81
FF - prefs.js..extensions.enabledItems: {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}:3.2.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:3.2.5.2
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.1
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.3
FF - prefs.js..extensions.enabledItems: {bee6eb20-01e0-ebd1-da83-080329fb9a3a}:0.1
FF - prefs.js..extensions.enabledItems: [email protected]:4.1.8
FF - prefs.js..extensions.enabledItems: {AFF0F480-EDE7-11DB-8BB2-438255D89593}:1.3.4
FF - prefs.js..extensions.enabledItems: {e8754cd5-4214-41ea-8e28-142af83d76b1}:0.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.2
FF - prefs.js..keyword.URL: "http://mystart.incre...ss_bar&search="
FF - prefs.js..network.proxy.type: 0


FF - HKLM\software\mozilla\Firefox\Extensions\\{22C7F6C6-8D67-4534-92B5-529A0EC09405}: c:\Program Files\Trend Micro\Client Server Security Agent\bho\1009\FirefoxExtension
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/29 14:10:59 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/03/06 15:03:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/03/06 15:03:34 | 000,000,000 | ---D | M]

[2011/01/29 21:50:19 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Extensions
[2011/03/07 21:36:06 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions
[2011/02/02 14:35:57 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/01/30 00:00:29 | 000,000,000 | ---D | M] (AddThis) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2011/02/15 12:30:35 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/01/30 00:00:27 | 000,000,000 | ---D | M] (CookieCuller) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2011/01/30 00:51:24 | 000,000,000 | ---D | M] (Babylon Word Search) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{a27007d0-bec0-4df7-abf8-54ae0b833ce8}
[2011/03/01 07:54:41 | 000,000,000 | ---D | M] ("StumbleUpon") -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2011/02/28 00:22:30 | 000,000,000 | ---D | M] ("WordPress Helper") -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{AFF0F480-EDE7-11DB-8BB2-438255D89593}
[2011/02/12 22:58:58 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/07 14:49:51 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2011/01/30 00:00:30 | 000,000,000 | ---D | M] (Easy Youtube Video Downloader) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}
[2011/01/30 00:00:36 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/02/06 01:02:35 | 000,000,000 | ---D | M] (IncrediMail MediaBar 2 Community Toolbar) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}
[2011/01/30 00:00:39 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/02/09 00:29:45 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/02/16 11:04:18 | 000,000,000 | ---D | M] (Wordpress Toolbar) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{e8754cd5-4214-41ea-8e28-142af83d76b1}
[2011/02/06 01:02:35 | 000,000,000 | ---D | M] (Theme Font Size Changer) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{f69e22c7-bc50-414a-9269-0f5c344cd94c}
[2011/01/30 00:00:41 | 000,000,000 | ---D | M] (Redirect Remover) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\{fe0258ab-4f74-43a1-8781-bcdf340f9ee9}
[2011/02/17 11:16:32 | 000,000,000 | ---D | M] (Adblock Plus Pop-up Addon) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/03 00:29:55 | 000,000,000 | ---D | M] ("AutoPager") -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/06 01:02:36 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/01/30 00:00:27 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/02 14:35:57 | 000,000,000 | ---D | M] (SimilarWeb) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/17 11:16:32 | 000,000,000 | ---D | M] (Autofill) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/03/05 22:25:15 | 000,000,000 | ---D | M] (ImageTools) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/13 22:40:39 | 000,000,000 | ---D | M] (FastestFox) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/02 00:21:28 | 000,000,000 | ---D | M] (Nuclear Games Toolbar) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/02/23 23:08:52 | 000,000,000 | ---D | M] (Zoom Page) -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\extensions\[email protected]
[2011/01/30 00:20:37 | 000,001,449 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\100-search-engines.xml
[2011/01/30 00:19:53 | 000,000,931 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\dictionary.xml
[2011/01/30 00:20:17 | 000,002,404 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\ebookpedianet.xml
[2011/02/04 15:45:53 | 000,002,153 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\MyStart Search.xml
[2011/03/05 19:17:09 | 000,001,981 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\scirus.xml
[2011/01/30 00:24:58 | 000,005,868 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\the-free-dictionary.xml
[2011/01/30 00:22:58 | 000,001,539 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\thesaurus---referencecom.xml
[2011/01/30 00:23:34 | 000,001,180 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\urban-dictionary.xml
[2011/01/30 00:22:38 | 000,000,705 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\webster.xml
[2011/02/16 11:03:05 | 000,001,794 | ---- | M] () -- C:\Users\Ed Jump\AppData\Roaming\Mozilla\Firefox\Profiles\m1jknj8c.default\searchplugins\wp-codex.xml
[2011/02/22 16:41:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/01/30 08:59:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/02/16 12:02:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/01/29 14:10:59 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG10\FIREFOX
[2011/02/02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/10 15:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (no name) - {1CA1377B-DC1D-4A52-9585-6E06050FAC53} - No CLSID value found.
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbInc1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (IncrediMail MediaBar 2 Toolbar) - {d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0} - C:\Program Files\IncrediMail_MediaBar_2\tbInc1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Nuclear Games Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (IncrediMail MediaBar 2 Toolbar) - {D40B90B4-D3B1-4D6B-A5D7-DC041C1B76C0} - C:\Program Files\IncrediMail_MediaBar_2\tbInc1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [EasySpeller] C:\Program Files\EasyOffice\EasySpeller.exe ()
O4 - HKLM..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [EasyOpen] C:\Program Files\EasyOffice\EASYOPEN.EXE ()
O4 - HKCU..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe (IncrediMail, Ltd.)
O4 - HKCU..\Run: [Software Informer] C:\Program Files\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - Startup: C:\Users\Ed Jump\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 1.1.0.lnk = C:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\Program Files\IncrediMail\Bin\resources\WebMenuImg.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\tmpx {0E526CB5-7446-41D1-A403-19BFE95E8C23} - Reg Error: Key error. File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 15:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [1996/09/11 04:36:16 | 000,215,478 | R--- | M] () - D:\AUTORUN.BMP -- [ CDFS ]
O32 - AutoRun File - [1996/09/09 10:51:12 | 000,025,088 | R--- | M] (New World Computing, Inc.) - D:\AUTORUN.EXE -- [ CDFS ]
O32 - AutoRun File - [1996/09/09 10:51:12 | 000,000,029 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O32 - AutoRun File - [1996/09/24 07:20:54 | 000,000,287 | R--- | M] () - D:\AUTORUN.INI -- [ CDFS ]
O33 - MountPoints2\{dd795b2e-1954-11e0-b606-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{dd795b2e-1954-11e0-b606-806e6f6e6963}\Shell\AutoRun\command - "" = D:\AUTORUN.EXE -- [1996/09/09 10:51:12 | 000,025,088 | R--- | M] (New World Computing, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/03/08 09:48:09 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\Ed Jump\Desktop\OTL.exe
[2011/03/06 08:40:10 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\TheGreatPharaoh
[2011/02/27 21:25:59 | 000,000,000 | ---D | C] -- C:\Logs
[2011/02/24 17:21:42 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Local\Apple Computer
[2011/02/24 17:21:17 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Apple Computer
[2011/02/22 19:09:07 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2011/02/22 19:08:55 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
[2011/02/22 19:08:47 | 000,000,000 | ---D | C] -- C:\Program Files\FreeTime
[2011/02/22 19:07:30 | 000,000,000 | ---D | C] -- C:\ProgramData\PY_Software
[2011/02/22 19:07:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PY Software
[2011/02/22 19:07:27 | 000,000,000 | ---D | C] -- C:\Program Files\2D and 3D Animator
[2011/02/22 16:40:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameTop.com
[2011/02/22 16:40:53 | 000,000,000 | ---D | C] -- C:\Program Files\GameTop.com
[2011/02/22 16:38:21 | 000,000,000 | ---D | C] -- C:\Program Files\Search Toolbar
[2011/02/19 23:53:54 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\.gimp-2.6
[2011/02/19 15:29:08 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Yahoo!
[2011/02/19 13:26:08 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\acccore
[2011/02/19 13:26:07 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Local\AIM
[2011/02/19 13:16:54 | 000,000,000 | ---D | C] -- C:\Program Files\Belarc
[2011/02/19 13:10:48 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\GlarySoft
[2011/02/19 10:44:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP
[2011/02/19 10:44:51 | 000,000,000 | ---D | C] -- C:\Program Files\GIMP-2.0
[2011/02/19 10:42:57 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2011/02/19 10:42:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/02/19 10:42:56 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Skype
[2011/02/19 10:42:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2011/02/19 10:38:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
[2011/02/19 10:37:29 | 000,000,000 | ---D | C] -- C:\ProgramData\AIM
[2011/02/19 10:37:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
[2011/02/19 10:37:26 | 000,000,000 | ---D | C] -- C:\Program Files\AIM
[2011/02/19 10:36:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities
[2011/02/19 10:36:24 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Utilities
[2011/02/19 10:35:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
[2011/02/19 10:35:47 | 000,000,000 | ---D | C] -- C:\Program Files\IrfanView
[2011/02/19 10:35:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Talk
[2011/02/19 09:48:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CookBook+Calendar
[2011/02/19 09:48:44 | 000,000,000 | ---D | C] -- C:\Program Files\CookBook+Calendar
[2011/02/17 21:20:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Speech SDK 5.1
[2011/02/17 21:20:25 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Speech SDK 5.1
[2011/02/17 21:09:08 | 000,000,000 | -H-D | C] -- C:\$AVG
[2011/02/17 20:48:22 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Local\Windows Live
[2011/02/16 12:02:23 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/02/13 12:40:37 | 000,000,000 | ---D | C] -- C:\Games
[2011/02/12 23:58:59 | 000,000,000 | ---D | C] -- C:\Program Files\Tower Blaster
[2011/02/12 23:58:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Play Tower Blaster
[2011/02/12 13:19:25 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Land Of Runes
[2011/02/11 23:06:34 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\KewlBoxPrefs
[2011/02/11 21:10:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia
[2011/02/11 21:10:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MostFun.com Games
[2011/02/11 21:10:40 | 000,000,000 | ---D | C] -- C:\Program Files\MostFun
[2011/02/11 20:59:08 | 000,000,000 | ---D | C] -- C:\ProgramData\NeoEdge Networks
[2011/02/10 23:24:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Weather Channel
[2011/02/10 23:23:16 | 000,000,000 | ---D | C] -- C:\Program Files\The Weather Channel FW
[2011/02/10 23:23:02 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Local\The Weather Channel
[2011/02/10 23:15:23 | 000,000,000 | ---D | C] -- C:\Spiele
[2011/02/09 21:43:16 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab
[2011/02/09 21:40:57 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\SystemRequirementsLab
[2011/02/07 18:20:39 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Software Informer
[2011/02/07 18:20:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Software Informer
[2011/02/07 18:20:39 | 000,000,000 | ---D | C] -- C:\Program Files\Software Informer
[2011/02/07 18:17:17 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\AppData\Roaming\Sound Editor Deluxe
[2011/02/07 18:17:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Editor Deluxe
[2011/02/07 18:17:07 | 002,084,864 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioDesign2.dll
[2011/02/07 18:17:07 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\NCTAudioFile2.dll
[2011/02/07 18:17:07 | 001,212,416 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioInformation2.dll
[2011/02/07 18:17:07 | 000,880,640 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioEditor2.dll
[2011/02/07 18:17:07 | 000,835,584 | ---- | C] (NCT) -- C:\Windows\System32\NCTAudioCDGrabber2.dll
[2011/02/07 18:17:07 | 000,602,112 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioTransform2.dll
[2011/02/07 18:17:07 | 000,479,232 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioVisualization2.dll
[2011/02/07 18:17:07 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioRecord2.dll
[2011/02/07 18:17:07 | 000,458,752 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTAudioPlayer2.dll
[2011/02/07 18:17:07 | 000,417,792 | ---- | C] (Online Media Technologies Ltd.) -- C:\Windows\System32\NCTTextToAudio2.dll
[2011/02/07 18:17:07 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\NCTWMAFile2.dll
[2011/02/07 18:17:06 | 000,000,000 | ---D | C] -- C:\Program Files\Sound Editor Deluxe
[2011/02/07 14:10:11 | 000,000,000 | ---D | C] -- C:\Users\Ed Jump\dwhelper
[2011/02/07 12:08:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games - Make money playing video games
[2011/02/07 12:08:20 | 000,000,000 | ---D | C] -- C:\Program Files\Games - Make money playing video games
[2011/02/07 00:02:53 | 000,000,000 | ---D | C] -- C:\Program Files\Super Solitaire
[2011/02/06 23:54:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mini Golf Game
[2011/02/06 23:54:26 | 000,000,000 | ---D | C] -- C:\Program Files\Mini Golf Game
[2011/02/06 15:20:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Merriam-Webster Reference Library
[2011/02/06 15:20:35 | 000,000,000 | ---D | C] -- C:\Program Files\Merriam-Webster Reference Library
[2010/08/25 18:59:08 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll

========== Files - Modified Within 30 Days ==========

[2011/03/08 09:48:09 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ed Jump\Desktop\OTL.exe
[2011/03/08 09:47:00 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/03/08 08:39:05 | 108,043,993 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2011/03/08 08:37:18 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/03/08 00:47:00 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/03/07 11:58:18 | 000,000,422 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/03/07 08:32:39 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/03/07 08:32:39 | 000,014,032 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/03/07 08:25:28 | 000,000,316 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2011/03/07 08:25:09 | 1582,931,968 | -HS- | M] () -- C:\hiberfil.sys
[2011/03/05 08:06:10 | 000,003,584 | ---- | M] () -- C:\Users\Ed Jump\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 19:08:55 | 000,001,162 | ---- | M] () -- C:\Users\Ed Jump\Desktop\Format Factory.lnk
[2011/02/22 00:03:34 | 000,365,991 | ---- | M] () -- C:\Users\Public\Documents\Documents\HTML Cheatsheet - Webmonkey - Wired.com_1298354605319.png
[2011/02/21 15:04:12 | 000,716,203 | ---- | M] () -- C:\Users\Public\Documents\Documents\HERSHEY'S - Chocolate Quicky Sticky Bread_1298322248578.png
[2011/02/21 11:17:48 | 000,535,746 | ---- | M] () -- C:\Users\Public\Documents\Documents\How to Make Invisible Folder and Hide Private Files_1298308662209.png
[2011/02/21 11:14:04 | 000,504,786 | ---- | M] () -- C:\Users\Public\Documents\Documents\How to Hide Important Files inside a Picture_1298308432842.png
[2011/02/20 14:04:36 | 000,113,329 | ---- | M] () -- C:\Users\Public\Documents\Documents\Online Web Tools and Code Generators-Special Character Codes
[2011/02/19 13:18:30 | 000,404,059 | ---- | M] () -- C:\Users\Public\Documents\Documents\Belarc Advisor Current Profile_1298143098818.png
[2011/02/19 13:16:54 | 000,002,021 | ---- | M] () -- C:\Users\Ed Jump\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2011/02/19 13:16:54 | 000,001,997 | ---- | M] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2011/02/19 10:45:00 | 000,001,071 | ---- | M] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011/02/19 10:42:57 | 000,002,503 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/02/19 10:38:56 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2011/02/19 10:37:31 | 000,000,355 | -H-- | M] () -- C:\IPH.PH
[2011/02/19 10:37:29 | 000,001,885 | ---- | M] () -- C:\Users\Ed Jump\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2011/02/19 10:37:29 | 000,001,861 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
[2011/02/19 10:36:25 | 000,001,030 | ---- | M] () -- C:\Users\Public\Desktop\Glary Utilities.lnk
[2011/02/19 10:35:48 | 000,000,974 | ---- | M] () -- C:\Users\Public\Desktop\IrfanView.lnk
[2011/02/19 10:35:12 | 000,001,211 | ---- | M] () -- C:\Users\Public\Desktop\Google Talk.lnk
[2011/02/19 09:48:46 | 000,001,089 | ---- | M] () -- C:\Users\Ed Jump\Desktop\CookBook + Calendar.lnk
[2011/02/19 00:27:32 | 000,265,271 | ---- | M] () -- C:\Users\Public\Documents\Documents\Anatomical Gift Program - Department of Neurobiology and Developmental Sciences - University of Arkansas for Medical Sciences_1298096847071.png
[2011/02/19 00:13:08 | 000,330,371 | ---- | M] () -- C:\Users\Public\Documents\Documents\UT Knoxville - Forensic Anthropology Center - Donation_1298095984178.png
[2011/02/19 00:11:32 | 000,914,911 | ---- | M] () -- C:\Users\Public\Documents\Documents\UT Knoxville - College of Arts & Sciences - Department of Anthropology_1298095884399.png
[2011/02/18 23:42:09 | 000,830,477 | ---- | M] () -- C:\Users\Public\Documents\Documents\The Survival Station - 51 Free Tools to Stay Informed and Invisible on the Internet_1298094121540.png
[2011/02/18 14:08:23 | 000,684,748 | ---- | M] () -- C:\Users\Public\Documents\Documents\Collection Agency Laws.sxd
[2011/02/18 14:05:28 | 000,266,415 | ---- | M] () -- C:\Users\Public\Documents\Documents\603-363-1021 - 6033631021_1297639030370 (320x1650).jpg
[2011/02/18 12:53:14 | 000,411,949 | ---- | M] () -- C:\Users\Public\Documents\Documents\Hotel Soap Opera_1297999114546 (747x1650).jpg
[2011/02/18 09:20:30 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/02/17 20:58:57 | 000,001,322 | ---- | M] () -- C:\Users\Ed Jump\Desktop\Windows Live Photo Gallery.lnk
[2011/02/17 12:22:21 | 003,589,460 | ---- | M] () -- C:\Users\Public\Documents\Documents\JVC Digital Video Camera.pdf
[2011/02/14 15:28:15 | 000,033,768 | ---- | M] () -- C:\Users\Public\Documents\Documents\Sweet Pickled Beaver
[2011/02/14 14:56:19 | 001,241,841 | ---- | M] () -- C:\Users\Public\Documents\Documents\Recipe- New York Cheesecake—Light - Hobby Farms_1297716975161.png
[2011/02/13 17:17:25 | 000,678,337 | ---- | M] () -- C:\Users\Public\Documents\Documents\Debt Collector laws.png
[2011/02/13 14:45:37 | 000,232,554 | ---- | M] () -- C:\Users\Public\Documents\Documents\cuts-of-beef1.jpg
[2011/02/10 23:24:22 | 000,001,221 | ---- | M] () -- C:\Users\Public\Desktop\The Weather Channel Desktop .lnk
[2011/02/10 21:09:03 | 000,001,991 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2011/02/09 21:27:00 | 000,281,944 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/02/07 18:17:09 | 000,001,814 | ---- | M] () -- C:\Users\Ed Jump\Desktop\Sound Editor Deluxe.lnk
[2011/02/07 14:15:47 | 000,278,603 | ---- | M] () -- C:\Users\Public\Documents\Documents\julia nolan chemical engineer - Google Search_1297109728250.png
[2011/02/06 15:20:59 | 000,001,181 | ---- | M] () -- C:\Users\Public\Desktop\Merriam-Webster References.lnk

========== Files Created - No Company Name ==========

[2011/03/05 08:06:09 | 000,003,584 | ---- | C] () -- C:\Users\Ed Jump\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/22 19:08:55 | 000,001,162 | ---- | C] () -- C:\Users\Ed Jump\Desktop\Format Factory.lnk
[2011/02/22 00:03:33 | 000,365,991 | ---- | C] () -- C:\Users\Public\Documents\Documents\HTML Cheatsheet - Webmonkey - Wired.com_1298354605319.png
[2011/02/21 15:04:12 | 000,716,203 | ---- | C] () -- C:\Users\Public\Documents\Documents\HERSHEY'S - Chocolate Quicky Sticky Bread_1298322248578.png
[2011/02/21 11:17:47 | 000,535,746 | ---- | C] () -- C:\Users\Public\Documents\Documents\How to Make Invisible Folder and Hide Private Files_1298308662209.png
[2011/02/21 11:14:03 | 000,504,786 | ---- | C] () -- C:\Users\Public\Documents\Documents\How to Hide Important Files inside a Picture_1298308432842.png
[2011/02/20 14:04:35 | 000,113,329 | ---- | C] () -- C:\Users\Public\Documents\Documents\Online Web Tools and Code Generators-Special Character Codes
[2011/02/19 13:18:29 | 000,404,059 | ---- | C] () -- C:\Users\Public\Documents\Documents\Belarc Advisor Current Profile_1298143098818.png
[2011/02/19 13:16:54 | 000,002,021 | ---- | C] () -- C:\Users\Ed Jump\Application Data\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2011/02/19 13:16:54 | 000,002,009 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2011/02/19 13:16:54 | 000,001,997 | ---- | C] () -- C:\Users\Public\Desktop\Belarc Advisor.lnk
[2011/02/19 10:45:00 | 000,001,071 | ---- | C] () -- C:\Users\Public\Desktop\GIMP 2.lnk
[2011/02/19 10:42:57 | 000,002,503 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2011/02/19 10:38:56 | 000,001,088 | ---- | C] () -- C:\Users\Public\Desktop\Picasa 3.lnk
[2011/02/19 10:37:29 | 000,001,885 | ---- | C] () -- C:\Users\Ed Jump\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2011/02/19 10:37:29 | 000,001,861 | ---- | C] () -- C:\Users\Public\Desktop\AIM.lnk
[2011/02/19 10:37:22 | 000,000,355 | -H-- | C] () -- C:\IPH.PH
[2011/02/19 10:36:25 | 000,001,030 | ---- | C] () -- C:\Users\Public\Desktop\Glary Utilities.lnk
[2011/02/19 10:36:25 | 000,000,316 | ---- | C] () -- C:\Windows\tasks\GlaryInitialize.job
[2011/02/19 10:35:48 | 000,000,974 | ---- | C] () -- C:\Users\Public\Desktop\IrfanView.lnk
[2011/02/19 10:35:16 | 000,001,211 | ---- | C] () -- C:\Users\Public\Desktop\Google Talk.lnk
[2011/02/19 09:48:46 | 000,001,089 | ---- | C] () -- C:\Users\Ed Jump\Desktop\CookBook + Calendar.lnk
[2011/02/19 00:27:32 | 000,265,271 | ---- | C] () -- C:\Users\Public\Documents\Documents\Anatomical Gift Program - Department of Neurobiology and Developmental Sciences - University of Arkansas for Medical Sciences_1298096847071.png
[2011/02/19 00:13:07 | 000,330,371 | ---- | C] () -- C:\Users\Public\Documents\Documents\UT Knoxville - Forensic Anthropology Center - Donation_1298095984178.png
[2011/02/19 00:11:32 | 000,914,911 | ---- | C] () -- C:\Users\Public\Documents\Documents\UT Knoxville - College of Arts & Sciences - Department of Anthropology_1298095884399.png
[2011/02/18 23:42:08 | 000,830,477 | ---- | C] () -- C:\Users\Public\Documents\Documents\The Survival Station - 51 Free Tools to Stay Informed and Invisible on the Internet_1298094121540.png
[2011/02/18 14:08:22 | 000,684,748 | ---- | C] () -- C:\Users\Public\Documents\Documents\Collection Agency Laws.sxd
[2011/02/18 14:05:28 | 000,266,415 | ---- | C] () -- C:\Users\Public\Documents\Documents\603-363-1021 - 6033631021_1297639030370 (320x1650).jpg
[2011/02/18 12:53:13 | 000,411,949 | ---- | C] () -- C:\Users\Public\Documents\Documents\Hotel Soap Opera_1297999114546 (747x1650).jpg
[2011/02/17 20:58:57 | 000,001,322 | ---- | C] () -- C:\Users\Ed Jump\Desktop\Windows Live Photo Gallery.lnk
[2011/02/17 12:22:21 | 003,589,460 | ---- | C] () -- C:\Users\Public\Documents\Documents\JVC Digital Video Camera.pdf
[2011/02/14 15:28:15 | 000,033,768 | ---- | C] () -- C:\Users\Public\Documents\Documents\Sweet Pickled Beaver
[2011/02/14 14:56:18 | 001,241,841 | ---- | C] () -- C:\Users\Public\Documents\Documents\Recipe- New York Cheesecake—Light - Hobby Farms_1297716975161.png
[2011/02/13 17:17:24 | 000,678,337 | ---- | C] () -- C:\Users\Public\Documents\Documents\Debt Collector laws.png
[2011/02/13 14:45:36 | 000,232,554 | ---- | C] () -- C:\Users\Public\Documents\Documents\cuts-of-beef1.jpg
[2011/02/10 23:24:22 | 000,001,221 | ---- | C] () -- C:\Users\Public\Desktop\The Weather Channel Desktop .lnk
[2011/02/07 18:17:09 | 000,001,814 | ---- | C] () -- C:\Users\Ed Jump\Desktop\Sound Editor Deluxe.lnk
[2011/02/07 18:17:07 | 000,113,486 | ---- | C] () -- C:\Windows\System32\NCTWMAProfiles.prx
[2011/02/07 14:15:47 | 000,278,603 | ---- | C] () -- C:\Users\Public\Documents\Documents\julia nolan chemical engineer - Google Search_1297109728250.png
[2011/02/06 15:20:59 | 000,001,181 | ---- | C] () -- C:\Users\Public\Desktop\Merriam-Webster References.lnk
[2011/01/25 23:57:50 | 000,000,083 | ---- | C] () -- C:\Users\Ed Jump\AppData\Roaming\sversion.ini
[2011/01/25 23:51:43 | 000,069,632 | ---- | C] () -- C:\Windows\uinst001.exe
[2011/01/25 23:44:57 | 000,274,432 | ---- | C] () -- C:\Windows\System32\ClassX.dll
[2011/01/25 23:44:57 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dtidb.dll
[2011/01/25 23:44:57 | 000,024,576 | ---- | C] () -- C:\Windows\System32\classxps.dll
[2011/01/25 23:44:27 | 000,121,344 | ---- | C] () -- C:\Windows\System32\Ltpnt13n.dll
[2011/01/25 23:41:34 | 000,049,152 | ---- | C] () -- C:\Windows\System32\EasyBack.exe
[2011/01/25 23:41:34 | 000,024,576 | ---- | C] () -- C:\Windows\System32\EasyZipCmdCN.dll
[2011/01/25 23:41:33 | 000,073,728 | ---- | C] () -- C:\Windows\EasyZipp.exe
[2011/01/25 23:40:57 | 000,338,944 | ---- | C] () -- C:\Windows\System32\lffpx7.dll
[2011/01/25 23:40:57 | 000,118,784 | ---- | C] () -- C:\Windows\System32\lfkodak.dll
[2011/01/25 23:40:46 | 000,040,960 | ---- | C] () -- C:\Windows\EasyBar.exe
[2011/01/05 23:23:53 | 000,146,432 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2011/01/05 23:23:53 | 000,072,704 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2011/01/05 23:11:27 | 000,208,896 | ---- | C] () -- C:\Windows\System32\iglhsip32.dll
[2011/01/05 23:11:27 | 000,143,360 | ---- | C] () -- C:\Windows\System32\iglhcp32.dll
[2011/01/05 23:11:24 | 000,000,151 | ---- | C] () -- C:\Windows\System32\GfxUI.exe.config
[2010/08/25 19:30:02 | 000,439,308 | ---- | C] () -- C:\Windows\System32\igcompkrng500.bin
[2010/08/25 19:30:00 | 000,982,240 | ---- | C] () -- C:\Windows\System32\igkrng500.bin
[2010/08/25 19:30:00 | 000,092,356 | ---- | C] () -- C:\Windows\System32\igfcg500m.bin
[2009/07/13 22:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:33:53 | 000,281,944 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 20:05:48 | 000,634,934 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 20:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 20:05:48 | 000,109,798 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 20:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 20:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 20:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 18:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/13 17:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 17:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[1999/01/12 11:40:22 | 000,029,184 | ---- | C] () -- C:\Windows\rmud.exe

========== LOP Check ==========

[2011/02/19 13:30:20 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\acccore
[2011/01/29 22:28:27 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\Air Bandits
[2011/01/29 14:12:49 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\AVG10
[2011/01/25 23:44:54 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\EasyOffice
[2011/02/19 13:10:48 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\GlarySoft
[2011/02/19 00:42:56 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\KewlBoxPrefs
[2011/02/12 13:25:55 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\Land Of Runes
[2011/01/30 11:09:26 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\PCDr
[2011/03/08 08:40:04 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\Software Informer
[2011/02/07 18:20:10 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\Sound Editor Deluxe
[2011/02/09 21:40:57 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\SystemRequirementsLab
[2011/03/06 08:40:11 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\TheGreatPharaoh
[2011/01/27 13:36:46 | 000,000,000 | ---D | M] -- C:\Users\Ed Jump\AppData\Roaming\Windows Live Writer
[2011/03/07 08:25:28 | 000,000,316 | ---- | M] () -- C:\Windows\Tasks\GlaryInitialize.job
[2011/02/18 09:20:30 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/13 22:53:46 | 000,018,098 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011/03/07 11:58:18 | 000,000,422 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job

========== Purity Check ==========



< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP