Thank you so much for your help. I couldn't find help anywhere, even Norton until I stumbled across GTG.
Question 1:
Are you really in Antarctica??????? [I know...you could tell me, but then you'd have to kill me]
Question 2:
I could not find the attached "Scan.txt" file you said to drag into the custom Scans/fixes area.
I ran the scan on the windows folder and here is what I came up with.
Thanks again for your help Agent ST!
OTL logfile created on: 10/11/2011 4:21:07 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
64bit-Windows 7 Professional Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 89.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 98.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = H: | %SystemRoot% = H:\Windows | %ProgramFiles% = H:\Program Files (x86)
Drive C: | 100.00 Mb Total Space | 74.21 Mb Free Space | 74.22% Space Free | Partition Type: NTFS
Drive H: | 465.66 Gb Total Space | 212.75 Gb Free Space | 45.69% Space Free | Partition Type: NTFS
Drive X: | 436.59 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2011/06/21 18:57:42 | 000,341,296 | ---- | M] (Nitro PDF Software) [Auto] -- H:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe -- (NitroReaderDriverReadSpool2)
SRV:
64bit: - [2011/05/04 20:01:07 | 001,431,888 | ---- | M] (Flexera Software, Inc.) [On_Demand] -- H:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe -- (FLEXnet Licensing Service 64)
SRV:
64bit: - [2011/02/05 16:39:26 | 001,012,224 | ---- | M] () [Auto] -- H:\Program Files\Synergy\synergys.exe -- (Synergy Server)
SRV:
64bit: - [2010/10/28 06:14:30 | 000,357,456 | ---- | M] (Logitech, Inc.) [On_Demand] -- H:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:
64bit: - [2010/09/22 18:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled] -- H:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:
64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto] -- H:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand] -- H:\Windows\System32\appmgmts.dll -- (AppMgmt)
SRV - [2011/08/03 07:50:00 | 002,255,464 | ---- | M] (NVIDIA Corporation) [Auto] -- H:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/08/03 03:31:42 | 000,379,496 | ---- | M] (NVIDIA Corporation) [Auto] -- H:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/07/09 12:37:12 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand] -- H:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto] -- H:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/02/28 18:44:14 | 000,183,560 | ---- | M] (Microsoft Corporation.) [On_Demand] -- H:\Program Files (x86)\Microsoft\BingBar\BBSvc.EXE -- (BBSvc)
SRV - [2011/02/16 08:02:40 | 001,034,208 | ---- | M] (PC Tools) [On_Demand] -- H:\Program Files (x86)\PC Tools Utilities\Tools\Repair\DMRepairSrv.exe -- (DMRepairService)
SRV - [2011/02/16 08:02:28 | 001,050,592 | ---- | M] (PC Tools) [On_Demand] -- H:\Program Files (x86)\PC Tools Utilities\Tools\Defrag\DMDefragSrv.exe -- (DMDefragService)
SRV - [2011/02/16 08:02:14 | 000,632,800 | ---- | M] (PC Tools) [Auto] -- H:\Program Files (x86)\Common Files\PC Tools\sMonitor\StartManSvc.exe -- (PCToolsSSDMonitorSvc)
SRV - [2011/02/09 15:56:10 | 000,689,464 | ---- | M] (Radialpoint Inc.) [Auto] -- H:\Program Files (x86)\Windstream\Servicepoint\ServicepointService.exe -- (ServicepointService)
SRV - [2011/02/02 14:08:16 | 000,018,656 | ---- | M] () [Auto] -- H:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe -- (Autodesk Content Service)
SRV - [2010/11/22 11:17:06 | 000,181,312 | ---- | M] () [Auto] -- H:\Program Files (x86)\Photodex\CompuPicPro\scsiaccess.exe -- (ScsiAccess)
SRV - [2010/11/20 08:17:22 | 000,073,216 | ---- | M] () [On_Demand] -- H:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto] -- H:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/10/23 13:31:44 | 000,401,920 | ---- | M] (Amazon.com) [Auto] -- H:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe -- (Amazon Download Agent)
SRV - [2009/10/09 05:45:56 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [Auto] -- H:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled] -- H:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/09/21 20:24:20 | 000,487,672 | ---- | M] (HiWired Inc.) [Auto] -- H:\Program Files (x86)\HiWired\PC Check & Connect\HiWired.Client.Core.exe -- (HiWiredCore)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2011/02/04 19:34:18 | 000,162,328 | ---- | M] (PC Tools) [Kernel | On_Demand] -- H:\Windows\System32\drivers\PCTDMDefrag.sys -- (PCTDMDefrag)
DRV:
64bit: - [2011/02/04 19:34:08 | 000,189,880 | ---- | M] (PC Tools) [Kernel | On_Demand] -- H:\Windows\System32\drivers\PCTDSMon.sys -- (PCTDSMon)
DRV:
64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- H:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- H:\Windows\System32\drivers\fssfltr.sys -- (fssfltr)
DRV:
64bit: - [2010/08/24 13:29:32 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:
64bit: - [2010/08/24 13:29:10 | 000,063,568 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:
64bit: - [2009/10/09 02:41:02 | 001,394,176 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\athrx.sys -- (athr)
DRV:
64bit: - [2009/06/10 17:01:11 | 001,485,312 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\VSTDPV6.SYS -- (VST64_DPV)
DRV:
64bit: - [2009/06/10 17:01:11 | 000,740,864 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\VSTCNXT6.SYS -- (winachsf)
DRV:
64bit: - [2009/06/10 17:01:11 | 000,411,136 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand] -- H:\Windows\System32\drivers\VSTBS26.SYS -- (VST64HWBS2)
DRV:
64bit: - [2009/06/10 16:38:56 | 000,000,308 | ---- | M] () [File_System | On_Demand] -- H:\Windows\System32\wbem\ntfs.mof -- (Ntfs)
DRV:
64bit: - [2009/06/10 16:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- H:\Windows\System32\drivers\e1e6032e.sys -- (e1express) Intel®
DRV:
64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- H:\Windows\system32\DRIVERS\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- H:\Windows\system32\DRIVERS\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand] -- H:\Windows\System32\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/03/05 00:57:34 | 000,075,088 | ---- | M] (PC Dynamics, Inc.) [Kernel | System] -- H:\Windows\System32\drivers\SAFDSKNT.SYS -- (SafDskNT)
DRV:
64bit: - [2008/06/16 03:00:00 | 000,055,024 | ---- | M] (Sonic Solutions) [Kernel | Boot] -- H:\Windows\System32\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:
64bit: - [2007/02/06 14:30:06 | 000,227,328 | ---- | M] (Hauppauge Computer Works, Inc.) [23|25|26]xxx) [Kernel | On_Demand] -- H:\Windows\System32\drivers\hcwPP2.sys -- (hcwPP2)
DRV - [2011/02/04 19:32:00 | 000,108,056 | ---- | M] (PC Tools) [Kernel | On_Demand] -- H:\Windows\SysWOW64\drivers\PCTDMDefrag.sys -- (PCTDMDefrag)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKU\admin_ON_H\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\admin_ON_H\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
========== FireFox ========== FF - prefs.js..extensions.enabledItems:
[email protected]:1.12.3.49167
FF - prefs.js..extensions.enabledItems:
[email protected]:0.7.2.6
FF - prefs.js..extensions.enabledItems:
[email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:3.0.1
FF - prefs.js..extensions.enabledItems: {21e48e29-f574-4619-b65d-0f00eea92e5b}:1.87
FF - prefs.js..extensions.enabledItems: {28FAD68E-4001-48d5-B994-68069F7CFB1D}:0.4.9
FF - prefs.js..extensions.enabledItems: {6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}:1.4.14
FF - prefs.js..extensions.enabledItems: {81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}:7.3.0.0
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.7
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}:3.4
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.6
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems:
[email protected]:1.23.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {d47a9f51-8281-43fa-f450-f28ef8735e9a}:2.1.1
FF - prefs.js..extensions.enabledItems: {cb84136f-9c44-433a-9048-c5cd9df1dc16}:3.0.0.314
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: H:\Program Files (x86)\Windstream\Servicepoint\nprpspa.dll (Windstream)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer: H:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: H:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin: H:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE: File not found
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: H:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: H:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: H:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision: H:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming: H:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@radialpoint.com/SPA,version=1: H:\Program Files (x86)\Windstream\Servicepoint\nprpspa.dll (Windstream)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.4:
FF - HKLM\Software\Wow6432Node\MozillaPlugins\Adobe Reader: H:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\Wow6432Node\MozillaPlugins\NitroPDF: H:\Program Files (x86)\Nitro PDF\Reader\npnitromozilla.dll ( )
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/04 13:42:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/04 13:42:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/10/04 13:50:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\wow6432node\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2010/11/22 06:40:30 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Extensions
[2010/11/22 06:40:30 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions
[2010/11/22 08:51:56 | 000,000,000 | ---D | M] (Screengrab) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/11/22 08:51:56 | 000,000,000 | ---D | M] ("Garmin Communicator") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/11/22 08:51:58 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/22 08:51:58 | 000,000,000 | ---D | M] ("GoogleEnhancer") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{21e48e29-f574-4619-b65d-0f00eea92e5b}
[2010/11/22 08:51:58 | 000,000,000 | ---D | M] (MouseZoom) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (Fire.fm) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (iMacros for Firefox) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (Firefox Showcase) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (DownloadHelper) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] ("CoolPreviews") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (Adblock Plus) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/11/22 08:51:59 | 000,000,000 | ---D | M] (DownThemAll!) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2010/11/22 08:51:56 | 000,000,000 | ---D | M] (Cooliris) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\
[email protected][2010/11/22 08:51:56 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\
[email protected][2010/11/22 08:51:56 | 000,000,000 | ---D | M] ("AmazonAssist") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\
[email protected][2010/11/22 08:51:56 | 000,000,000 | ---D | M] (Smart Bookmarks Bar) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\extensions\
[email protected][2011/10/04 14:31:40 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions
[2010/11/22 08:54:01 | 000,000,000 | ---D | M] (Screengrab) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/08/29 16:09:43 | 000,000,000 | ---D | M] (Garmin Communicator) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/11/22 08:54:01 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/04/17 00:41:08 | 000,000,000 | ---D | M] ("GoogleEnhancer") -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{21e48e29-f574-4619-b65d-0f00eea92e5b}
[2011/06/17 11:44:19 | 000,000,000 | ---D | M] (MouseZoom) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2011/03/20 18:45:27 | 000,000,000 | ---D | M] (Fire.fm) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{6F0976E6-26F3-4AFE-BBEC-9E99E27E4DF3}
[2011/10/04 14:31:37 | 000,000,000 | ---D | M] (iMacros for Firefox) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}
[2011/09/10 13:45:05 | 000,000,000 | ---D | M] (Showcase) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2011/08/22 14:15:54 | 000,000,000 | ---D | M] (DownloadHelper) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/06/27 16:59:21 | 000,000,000 | ---D | M] (Pixlr Grabber) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{d47a9f51-8281-43fa-f450-f28ef8735e9a}
[2011/05/23 11:55:17 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2011/06/17 11:44:16 | 000,000,000 | ---D | M] (DownThemAll!) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2011/08/10 13:10:31 | 000,000,000 | ---D | M] (Разпознаване на устройство Logitech) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\
[email protected][2011/10/04 13:44:42 | 000,000,000 | ---D | M] (Cooliris) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\
[email protected][2010/11/22 08:54:01 | 000,000,000 | ---D | M] (Smart Bookmarks Bar) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\
[email protected][2011/05/23 11:55:17 | 000,000,000 | ---D | M] (No name found) -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\extensions\{dc572301-7619-498c-a57d-39143191b318}\modules\extensions
[2009/09/16 20:55:58 | 000,000,945 | ---- | M] () -- H:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\t5vxif08.default\searchplugins\youtube-video-search.xml
[2011/10/04 13:42:09 | 000,000,000 | ---D | M] (No name found) -- H:\Program Files (x86)\Mozilla Firefox\extensions
[2010/12/17 23:49:52 | 000,000,000 | ---D | M] (Java Console) -- H:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/06/27 12:46:19 | 000,000,000 | ---D | M] (Java Console) -- H:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- H:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\T5VXIF08.DEFAULT\EXTENSIONS\{CE6E6E3B-84DD-4CAC-9F63-8D2AE4F30A4B}.XPI
() (No name found) -- H:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\T5VXIF08.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- H:\USERS\ADMIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\T5VXIF08.DEFAULT\EXTENSIONS\
[email protected][2011/09/29 03:10:22 | 000,134,104 | ---- | M] (Mozilla Foundation) -- H:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- H:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 21:16:42 | 000,002,252 | ---- | M] () -- H:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | ---- | M]) - H:\Windows\System32\drivers\etc\hosts
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - H:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKU\admin_ON_H\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\admin_ON_H\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [EvtMgr6] H:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [AmazonGSDownloaderTray] H:\Program Files (x86)\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe (Amazon.com)
O4 - HKLM..\Run: [SSDMonitor] H:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKU\admin_ON_H..\Run: [HD] H:\Program Files (x86)\U-Clean\Hd.cmd ()
O4 - HKU\admin_ON_H..\Run: [Jing] H:\Program Files (x86)\TechSmith\Jing\Jing.exe (TechSmith Corporation)
O4 - HKU\admin_ON_H..\Run: [RocketDock] H:\Program Files (x86)\RocketDock\RocketDock.exe ()
O4 - HKU\LocalService_ON_H..\Run: [Sidebar] H:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_H..\Run: [Sidebar] H:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\UpdatusUser.PDS-22_ON_H..\Run: [Sidebar] H:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\LocalService_ON_H..\RunOnce: [mctadmin] File not found
O4 - HKU\NetworkService_ON_H..\RunOnce: [mctadmin] File not found
O4 - HKU\UpdatusUser.PDS-22_ON_H..\RunOnce: [mctadmin] File not found
O4 - Startup: H:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ()
O4 - Startup: H:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk ()
O4 - Startup: H:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Synergy.lnk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O8:
64bit: - Extra context menu item: Add to Evernote 4.0 - H:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Evernote 4.0 - H:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - Reg Error: Value error. File not found
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - H:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - H:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O13:
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:
64bit: - admin_ON_H\..Trusted Domains: millenniumchem.com ([remote] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F}
https://juniper.net/...SetupClient.cab (JuniperSetupClientControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O18:
64bit: - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:
64bit: - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Filter\text/xml {807553E5-5146-11D5-A672-00B0D022E945} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - H:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - H:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - H:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - H:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R--- | M] () - X:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found
64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2011/10/04 20:26:23 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Belarc
[2011/10/04 18:15:38 | 000,000,000 | ---D | C] -- H:\Users\admin\Desktop\Tools
[2011/10/04 18:14:48 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safer Networking
[2011/10/04 18:14:47 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Safer Networking
[2011/10/04 18:06:11 | 000,000,000 | ---D | C] -- H:\Windows\ERDNT
[2011/10/04 18:05:36 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/10/04 18:05:36 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\ERUNT
[2011/10/04 16:21:07 | 000,000,000 | ---D | C] -- H:\ProgramData\Spybot - Search & Destroy
[2011/10/04 16:21:07 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/10/04 16:21:06 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Spybot - Search & Destroy
[2011/10/04 15:23:12 | 000,000,000 | ---D | C] -- H:\d4f14e97366c60bd3caabb9ca8
[2011/10/04 14:44:18 | 000,000,000 | ---D | C] -- H:\2607f8a13b7c9fa9aa66e8ab31632f
[2011/10/04 13:24:18 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/10/04 13:23:45 | 000,000,000 | ---D | C] -- H:\ProgramData\NVIDIA
[2011/10/04 13:23:40 | 006,136,936 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvcpl.dll
[2011/10/04 13:23:40 | 003,021,416 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvsvc64.dll
[2011/10/04 13:23:40 | 000,836,200 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\easyupdatusapiu64.dll
[2011/10/04 13:23:40 | 000,117,864 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvmctray.dll
[2011/10/04 13:23:40 | 000,061,544 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvshext.dll
[2011/10/04 13:23:33 | 000,000,000 | ---D | C] -- H:\ProgramData\NVIDIA Corporation
[2011/10/04 13:23:00 | 006,613,096 | ---- | C] (NVIDIA Corporation) -- H:\Windows\SysWow64\nvwgf2um.dll
[2011/10/04 13:23:00 | 001,519,720 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvdispco64.dll
[2011/10/04 13:23:00 | 001,453,160 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvgenco64.dll
[2011/10/04 12:50:56 | 000,506,400 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\nvudisp.exe
[2011/10/04 12:50:03 | 000,506,400 | ---- | C] (NVIDIA Corporation) -- H:\Windows\System32\NVUNINST.EXE
[2011/10/03 20:59:27 | 000,000,000 | -HSD | C] -- H:\found.005
[2011/10/03 19:40:54 | 001,182,680 | ---- | C] (PC Tools) -- H:\Windows\is-CAMTS.exe
[2011/10/03 13:33:13 | 000,000,000 | -HSD | C] -- H:\found.004
[2011/10/01 21:46:10 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Registry Mechanic
[2011/10/01 20:59:35 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\PC Tools Performance Toolkit
[2011/10/01 20:38:17 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Utilities
[2011/10/01 20:38:16 | 000,044,544 | ---- | C] (Microsoft Corporation) -- H:\Windows\SysWow64\msxml4a.dll
[2011/10/01 20:38:15 | 000,189,880 | ---- | C] (PC Tools) -- H:\Windows\System32\drivers\PCTDSMon.sys
[2011/10/01 20:38:15 | 000,162,328 | ---- | C] (PC Tools) -- H:\Windows\System32\drivers\PCTDMDefrag.sys
[2011/10/01 20:38:15 | 000,108,056 | ---- | C] (PC Tools) -- H:\Windows\SysWow64\drivers\PCTDMDefrag.sys
[2011/10/01 20:38:13 | 001,101,824 | ---- | C] (Woodbury Associates Limited) -- H:\Windows\SysWow64\UniBox210.ocx
[2011/10/01 20:38:13 | 000,880,640 | ---- | C] (Woodbury Associates Limited) -- H:\Windows\SysWow64\UniBox10.ocx
[2011/10/01 20:38:13 | 000,658,432 | ---- | C] (Microsoft Corporation) -- H:\Windows\SysWow64\MSCOMCT2.OCX
[2011/10/01 20:38:13 | 000,506,368 | ---- | C] (Microsoft Corporation) -- H:\Windows\SysWow64\msxml.dll
[2011/10/01 20:38:13 | 000,212,992 | ---- | C] (Woodbury Associates Limited) -- H:\Windows\SysWow64\UniBoxVB12.ocx
[2011/10/01 20:38:09 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\PC Tools Utilities
[2011/10/01 20:38:09 | 000,000,000 | ---D | C] -- H:\docs\File Recover
[2011/10/01 14:09:29 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\PCToolsFirewallPlus
[2011/10/01 14:09:28 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Spam Monitor
[2011/10/01 11:39:03 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Local\Threat Expert
[2011/09/30 17:51:26 | 002,189,264 | ---- | C] (Threat Expert Ltd.) -- H:\Windows\PCTBDCore.dll1052.old
[2011/09/30 17:51:26 | 002,189,264 | ---- | C] (Threat Expert Ltd.) -- H:\Windows\PCTBDCore.dll1027.old
[2011/09/30 17:51:26 | 001,640,400 | ---- | C] (Threat Expert Ltd.) -- H:\Windows\PCTBDCore.dll1000.old
[2011/09/30 17:51:26 | 000,149,456 | ---- | C] (PC Tools) -- H:\Windows\SGDetectionTool.dll1052.old
[2011/09/30 17:51:26 | 000,149,456 | ---- | C] (PC Tools) -- H:\Windows\SGDetectionTool.dll1027.old
[2011/09/30 17:51:26 | 000,149,456 | ---- | C] (PC Tools) -- H:\Windows\SGDetectionTool.dll1000.old
[2011/09/30 17:09:07 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Spyware Doctor
[2011/09/30 17:09:07 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\PC Tools
[2011/09/30 17:09:07 | 000,000,000 | ---D | C] -- H:\ProgramData\PC Tools
[2011/09/30 17:09:07 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Common Files\PC Tools
[2011/09/30 16:20:36 | 000,000,000 | ---D | C] -- H:\ProgramData\TEMP
[2011/09/30 16:04:09 | 000,000,000 | ---D | C] -- H:\ProgramData\SecTaskMan
[2011/09/19 13:03:14 | 000,000,000 | -HSD | C] -- H:\found.003
[2011/09/18 11:55:26 | 000,000,000 | ---D | C] -- H:\Windows\CheckSur
[2011/09/18 10:31:48 | 000,000,000 | -HSD | C] -- H:\found.002
[2011/09/18 09:28:50 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Registry Cleaner
[2011/09/18 09:28:49 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\Eusing Free Registry Cleaner
[2011/09/17 01:31:20 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Tific
[2011/09/17 01:31:09 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Local\Symantec
[2011/09/17 00:37:10 | 000,000,000 | -HSD | C] -- H:\found.001
[2011/09/16 17:49:20 | 000,000,000 | -HSD | C] -- H:\Config.Msi
[2011/09/16 14:43:28 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Malwarebytes
[2011/09/16 14:43:19 | 000,000,000 | ---D | C] -- H:\ProgramData\Malwarebytes
[2011/09/16 14:43:16 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- H:\Windows\System32\drivers\mbam.sys
[2011/09/16 13:14:25 | 000,000,000 | ---D | C] -- H:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
[2011/09/16 13:14:25 | 000,000,000 | ---D | C] -- H:\Program Files (x86)\NirSoft
[2011/09/16 12:15:48 | 000,000,000 | -HSD | C] -- H:\found.000
[2011/09/14 11:13:23 | 000,000,000 | ---D | C] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 pro x64
[2011/09/14 11:13:22 | 000,000,000 | ---D | C] -- H:\Program Files\zabkat
[4 H:\Windows\System32\*.tmp files -> H:\Windows\System32\*.tmp -> ]
[1 H:\ProgramData\*.tmp files -> H:\ProgramData\*.tmp -> ]
[1 H:\ProgramData\*.tmp files -> H:\ProgramData\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2011/10/11 12:10:22 | 000,067,584 | --S- | M] () -- H:\Windows\bootstat.dat
[2011/10/11 12:10:04 | 2146,267,135 | -HS- | M] () -- H:\hiberfil.sys
[2011/10/06 09:33:45 | 000,003,288 | ---- | M] () -- H:\bootsqm.dat
[2011/10/04 21:08:20 | 000,015,040 | -H-- | M] () -- H:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/04 21:08:20 | 000,015,040 | -H-- | M] () -- H:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/04 20:57:18 | 000,024,580 | -H-- | M] () -- H:\docs\.DS_Store
[2011/10/04 20:26:23 | 000,002,082 | ---- | M] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2011/10/04 20:26:23 | 000,002,070 | ---- | M] () -- H:\Users\Public\Desktop\Belarc Advisor.lnk
[2011/10/04 20:26:23 | 000,001,310 | ---- | M] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2011/10/04 18:14:48 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safer Networking
[2011/10/04 18:05:37 | 000,000,930 | ---- | M] () -- H:\Users\admin\Desktop\NTREGOPT.lnk
[2011/10/04 18:05:37 | 000,000,911 | ---- | M] () -- H:\Users\admin\Desktop\ERUNT.lnk
[2011/10/04 18:05:37 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/10/04 18:01:03 | 000,006,785 | ---- | M] () -- H:\Users\admin\AppData\Roaming\PrimoPDFSet.xml
[2011/10/04 16:21:07 | 000,001,288 | ---- | M] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/10/04 16:21:07 | 000,001,264 | ---- | M] () -- H:\Users\admin\Desktop\Spybot - Search & Destroy.lnk
[2011/10/04 16:21:07 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/10/04 13:51:40 | 000,002,120 | ---- | M] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2011/10/04 13:50:12 | 000,002,096 | ---- | M] () -- H:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2011/10/04 13:50:11 | 000,002,108 | ---- | M] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011/10/04 13:44:52 | 000,002,052 | ---- | M] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/10/04 13:42:11 | 000,001,156 | ---- | M] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/04 13:42:11 | 000,001,144 | ---- | M] () -- H:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/04 13:24:30 | 001,742,966 | ---- | M] () -- H:\Windows\System32\drivers\Cat.DB
[2011/10/04 13:24:18 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/10/04 12:33:40 | 000,000,000 | ---- | M] () -- H:\Windows\SysWow64\SM.lock
[2011/10/03 19:40:54 | 001,182,680 | ---- | M] (PC Tools) -- H:\Windows\is-CAMTS.exe
[2011/10/03 19:40:54 | 000,021,031 | ---- | M] () -- H:\Windows\is-CAMTS.msg
[2011/10/03 19:40:54 | 000,000,284 | ---- | M] () -- H:\Windows\is-CAMTS.lst
[2011/10/01 20:38:18 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Utilities
[2011/10/01 00:02:22 | 000,672,662 | ---- | M] () -- H:\Windows\System32\perfh009.dat
[2011/10/01 00:02:22 | 000,125,394 | ---- | M] () -- H:\Windows\System32\perfc009.dat
[2011/09/30 17:47:39 | 000,003,384 | ---- | M] () -- H:\{FE78D6E4-9C9E-421F-946A-53FF7F174791}
[2011/09/30 14:34:58 | 000,470,912 | ---- | M] () -- H:\Windows\System32\FNTCACHE.DAT
[2011/09/17 15:27:22 | 000,002,640 | ---- | M] () -- H:\{4BFEC432-8037-4A0F-BC27-779DB63F7A72}
[2011/09/17 13:41:30 | 000,000,978 | ---- | M] () -- H:\Users\Public\Desktop\xplorer2.lnk
[2011/09/16 18:11:47 | 000,772,990 | ---- | M] () -- H:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/16 12:47:29 | 502,738,679 | ---- | M] () -- H:\Windows\MEMORY.DMP
[2011/09/14 14:39:41 | 000,000,205 | -H-- | M] () -- H:\docs\Drawing1.dwl2
[2011/09/14 14:39:41 | 000,000,055 | -H-- | M] () -- H:\docs\Drawing1.dwl
[2011/09/14 11:13:24 | 000,000,000 | ---D | M] -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 pro x64
[4 H:\Windows\System32\*.tmp files -> H:\Windows\System32\*.tmp -> ]
[1 H:\ProgramData\*.tmp files -> H:\ProgramData\*.tmp -> ]
[1 H:\ProgramData\*.tmp files -> H:\ProgramData\*.tmp -> ]
========== Files Created - No Company Name ========== [2011/10/06 09:33:45 | 000,003,288 | ---- | C] () -- H:\bootsqm.dat
[2011/10/04 20:26:23 | 000,002,082 | ---- | C] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
[2011/10/04 20:26:23 | 000,002,070 | ---- | C] () -- H:\Users\Public\Desktop\Belarc Advisor.lnk
[2011/10/04 20:26:23 | 000,001,310 | ---- | C] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Belarc Advisor.lnk
[2011/10/04 18:05:37 | 000,000,930 | ---- | C] () -- H:\Users\admin\Desktop\NTREGOPT.lnk
[2011/10/04 18:05:37 | 000,000,911 | ---- | C] () -- H:\Users\admin\Desktop\ERUNT.lnk
[2011/10/04 16:21:07 | 000,001,288 | ---- | C] () -- H:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/10/04 16:21:07 | 000,001,264 | ---- | C] () -- H:\Users\admin\Desktop\Spybot - Search & Destroy.lnk
[2011/10/04 13:50:11 | 000,002,108 | ---- | C] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk
[2011/10/04 13:50:11 | 000,002,096 | ---- | C] () -- H:\Users\Public\Desktop\Mozilla Thunderbird.lnk
[2011/10/04 13:42:11 | 000,001,156 | ---- | C] () -- H:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/04 13:42:11 | 000,001,144 | ---- | C] () -- H:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/04 12:50:56 | 001,732,608 | ---- | C] () -- H:\Windows\System32\msicpl.dll
[2011/10/04 12:50:56 | 000,052,072 | ---- | C] () -- H:\Windows\System32\startup.exe
[2011/10/04 12:50:56 | 000,009,939 | ---- | C] () -- H:\Windows\System32\nvdisp.nvu
[2011/10/04 12:33:40 | 000,000,000 | ---- | C] () -- H:\Windows\SysWow64\SM.lock
[2011/10/03 19:40:54 | 000,021,031 | ---- | C] () -- H:\Windows\is-CAMTS.msg
[2011/10/03 19:40:54 | 000,000,284 | ---- | C] () -- H:\Windows\is-CAMTS.lst
[2011/10/01 20:38:13 | 000,040,416 | ---- | C] () -- H:\Windows\System32\CleanMFT64.exe
[2011/10/01 13:24:46 | 001,742,966 | ---- | C] () -- H:\Windows\System32\drivers\Cat.DB
[2011/09/30 17:51:26 | 000,767,952 | ---- | C] () -- H:\Windows\BDTSupport.dll1052.old
[2011/09/30 17:51:26 | 000,767,952 | ---- | C] () -- H:\Windows\BDTSupport.dll1027.old
[2011/09/30 17:51:26 | 000,767,952 | ---- | C] () -- H:\Windows\BDTSupport.dll1000.old
[2011/09/30 17:47:38 | 000,003,384 | ---- | C] () -- H:\{FE78D6E4-9C9E-421F-946A-53FF7F174791}
[2011/09/30 17:09:12 | 000,007,353 | ---- | C] () -- H:\Windows\System32\drivers\pctplsg64.cat
[2011/09/17 15:27:21 | 000,002,640 | ---- | C] () -- H:\{4BFEC432-8037-4A0F-BC27-779DB63F7A72}
[2011/09/14 14:39:41 | 000,000,205 | -H-- | C] () -- H:\docs\Drawing1.dwl2
[2011/09/14 14:39:41 | 000,000,055 | -H-- | C] () -- H:\docs\Drawing1.dwl
[2011/09/14 11:13:24 | 000,000,978 | ---- | C] () -- H:\Users\Public\Desktop\xplorer2.lnk
[2011/08/11 04:08:18 | 000,004,096 | -H-- | C] () -- H:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/10 22:56:19 | 000,002,073 | ---- | C] () -- H:\Windows\checkip.dat
[2011/08/03 03:31:54 | 000,311,912 | ---- | C] () -- H:\Windows\SysWow64\nvStreaming.exe
[2011/07/07 08:03:42 | 000,252,928 | ---- | C] () -- H:\Windows\SysWow64\DShowRdpFilter.dll
[2011/07/07 08:03:38 | 000,302,592 | ---- | C] () -- H:\Windows\SysWow64\cmd.exe
[2011/07/07 08:02:59 | 000,073,216 | ---- | C] () -- H:\Windows\SysWow64\msiexec.exe
[2011/07/07 08:02:54 | 000,030,720 | ---- | C] () -- H:\Windows\SysWow64\msdmo.dll
[2011/07/01 06:31:55 | 000,159,741 | ---- | C] () -- H:\Windows\U-Clean Uninstaller.exe
[2011/05/28 09:36:14 | 000,159,609 | ---- | C] () -- H:\Windows\U-Surf Uninstaller.exe
[2011/05/19 22:10:38 | 000,001,940 | ---- | C] () -- H:\Users\admin\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/04 20:48:18 | 000,000,153 | ---- | C] () -- H:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/05/04 19:53:52 | 000,772,990 | ---- | C] () -- H:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/17 08:46:20 | 000,000,760 | ---- | C] () -- H:\Users\admin\AppData\Roaming\setup_ldm.iss
[2011/04/15 21:16:59 | 000,007,631 | ---- | C] () -- H:\Users\admin\AppData\Local\resmon.resmoncfg
[2011/02/25 03:12:17 | 000,117,054 | ---- | C] () -- H:\Windows\CPICWPPR.DAT
[2011/01/10 17:01:00 | 000,006,785 | ---- | C] () -- H:\Users\admin\AppData\Roaming\PrimoPDFSet.xml
[2010/12/10 02:44:40 | 000,186,368 | ---- | C] () -- H:\Users\admin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/06 18:38:06 | 000,000,376 | ---- | C] () -- H:\Windows\ODBC.INI
[2010/11/21 03:33:33 | 000,000,000 | ---- | C] () -- H:\Windows\HPMProp.INI
[2010/11/21 02:38:55 | 000,000,126 | ---- | C] () -- H:\Windows\QUICKEN.INI
[2009/12/20 21:42:18 | 000,000,314 | ---- | C] () -- H:\Windows\primopdf.ini
[2009/08/17 21:24:28 | 000,000,108 | RHS- | C] () -- H:\Windows\neoqaz2.dll
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- H:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- H:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- H:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- H:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- H:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 18:25:04 | 000,197,632 | ---- | C] () -- H:\Windows\SysWow64\ir32_32.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- H:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- H:\Windows\SysWow64\mlang.dat
[2000/07/15 00:00:00 | 000,030,720 | ---- | C] () -- H:\Windows\regtlib.exe
========== LOP Check ========== [2011/05/04 21:12:26 | 000,000,000 | ---D | M] -- H:\ProgramData\2012
[2010/11/21 02:19:43 | 000,000,000 | ---D | M] -- H:\ProgramData\Amazon
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Application Data
[2011/07/09 11:55:47 | 000,000,000 | ---D | M] -- H:\ProgramData\Autodesk
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Desktop
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Documents
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Favorites
[2011/06/02 16:33:16 | 000,000,000 | ---D | M] -- H:\ProgramData\HiWired
[2010/12/21 04:32:56 | 000,000,000 | ---D | M] -- H:\ProgramData\Nitro PDF
[2011/06/02 16:03:51 | 000,000,000 | ---D | M] -- H:\ProgramData\Radialpoint
[2011/10/04 16:18:57 | 000,000,000 | ---D | M] -- H:\ProgramData\SecTaskMan
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Start Menu
[2011/10/04 14:25:35 | 000,000,000 | ---D | M] -- H:\ProgramData\TEMP
[2009/07/14 01:08:56 | 000,000,000 | -HSD | M] -- H:\ProgramData\Templates
[2011/06/02 16:03:36 | 000,000,000 | ---D | M] -- H:\ProgramData\Windstream
[2011/10/01 10:54:40 | 000,025,942 | ---- | M] () -- H:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 8256 bytes -> H:\docs\Adult.sdsk:Backup
@Alternate Data Stream - 76 bytes -> H:\docs\zims dog.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Recovery Disk.stx:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\PDF's:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\gund end stage.gif:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Falcon Soccer Match Label.stx:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Falcon Soccer 2.stx:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\everlife.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Dino.bmp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\BIG Claws.bmp:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Banquet 2007.dmsd:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\Ableton:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\1ST WIN 2007.stx:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> H:\docs\1ST WIN 2007 2.stx:Roxio EMC Stream
@Alternate Data Stream - 150 bytes -> H:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 136 bytes -> H:\ProgramData\TEMP:0D786AE3
@Alternate Data Stream - 127 bytes -> H:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 115 bytes -> H:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 108 bytes -> H:\Windows:
< End of report >