I've spent a lot of time reading here, so I hope I've done this right.
My Firefox (not my other installed browsers) redirects to my-search-now.com when performing a google search.
I'm behind a corporate firewall, running Trend Officescan. Trend blocks the site from loading, and throws an error stating that it has done so. Each time this occurs, there is an extra slash at the end of the reported URL followed by a very long string of seemingly random characters.
I have tried the following: SpyBot Search & Destroy, Ad-aware, HJT, Malwarebytes, CWShredder, TDSSKiller, SpywareBlaster. None of these identify it as a problem.
I've run OTL according to the instructions in the user guide with these settings:
1. Standard Registry = All
2. LOP and Purity checked
I have also edited the following:
1. my name in the the file paths has been changed to "myusername"
2. my domain has been changed to "mycorporatedomain"
3. browser home pages have been changed to "myhomepage"
Hoping that's all ok, and I am appreciated of any help that can be offered. Pasted OTL.txt follows .....
---------------------------------------------
OTL logfile created on: 20/02/2012 1:12:21 PM - Run 3
OTL by OldTimer - Version 3.2.32.0 Folder = C:\Documents and Settings\myusername\Desktop\utils
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
1.95 Gb Total Physical Memory | 1.45 Gb Available Physical Memory | 74.26% Memory free
3.80 Gb Paging File | 3.44 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 96.44 Gb Free Space | 64.71% Space Free | Partition Type: NTFS
Drive U: | 1900.00 Gb Total Space | 211.64 Gb Free Space | 11.14% Space Free | Partition Type: NTFS
Drive W: | 232.88 Gb Total Space | 199.37 Gb Free Space | 85.61% Space Free | Partition Type: NTFS
Drive X: | 79.45 Gb Total Space | 40.86 Gb Free Space | 51.43% Space Free | Partition Type: NTFS
Drive Y: | 79.45 Gb Total Space | 40.86 Gb Free Space | 51.43% Space Free | Partition Type: NTFS
Drive Z: | 1855.46 Gb Total Space | 411.30 Gb Free Space | 22.17% Space Free | Partition Type: NTFS
Computer Name: IT11298 | User Name: myusername | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\myusername\Desktop\utils\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\PccNTMon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmListen.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\NTRtScan.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\CNTAoSMgr.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Trend Micro Inc.)
PRC - C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (Xmarks.com)
PRC - C:\Program Files\Fuji Medical System\Synapse\Workstation\SynapseUpdateManager.exe (FUJIFILM Medical Systems U.S.A., Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe (Trend Micro Inc.)
PRC - C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
PRC - C:\Program Files\Lenovo\Mouse Suite\PELMICED.EXE (Primax Electronics Ltd.)
PRC - C:\Program Files\Lenovo\Mouse Suite\ico.exe (Primax Electronics Ltd.)
PRC - C:\Program Files\Lenovo\Mouse Suite\FSRremoS.EXE ()
PRC - C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\RealVNC\VNC4\winvnc4.exe (RealVNC Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Documents and Settings\myusername\Local Settings\Application Data\lanCommsTray\compatUserPath.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Lenovo\Mouse Suite\FSRremoS.EXE ()
========== Win32 Services (SafeList) ==========
SRV - (Hpnmpppm) -- File not found
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (tmlisten) -- C:\Program Files\Trend Micro\OfficeScan Client\tmlisten.exe (Trend Micro Inc.)
SRV - (ntrtscan) -- C:\Program Files\Trend Micro\OfficeScan Client\ntrtscan.exe (Trend Micro Inc.)
SRV - (TMBMServer) -- C:\Program Files\Trend Micro\OfficeScan Client\..\BM\TMBMSRV.exe ()
SRV - (SynapseUpdateSvc) -- C:\Program Files\Fuji Medical System\Synapse\Workstation\SynapseUpdateManager.exe (FUJIFILM Medical Systems U.S.A., Inc.)
SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (TmPfw) -- C:\Program Files\Trend Micro\OfficeScan Client\TmPfw.exe (Trend Micro Inc.)
SRV - (TmProxy) -- C:\Program Files\Trend Micro\OfficeScan Client\TmProxy.exe (Trend Micro Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (UNS) Intel® -- C:\Program Files\Common Files\Intel\Privacy Icon\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® -- C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
SRV - (WinVNC4) -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd.)
SRV - (IDriverT) -- C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
========== Driver Services (SafeList) ==========
DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys ()
DRV - (BANTExt) -- C:\WINDOWS\System32\Drivers\BANTExt.sys ()
DRV - (TmFilter) -- C:\Program Files\Trend Micro\OfficeScan Client\tmxpflt.sys (Trend Micro Inc.)
DRV - (TmPreFilter) -- C:\Program Files\Trend Micro\OfficeScan Client\tmpreflt.sys (Trend Micro Inc.)
DRV - (VSApiNt) -- C:\Program Files\Trend Micro\OfficeScan Client\VsapiNT.sys (Trend Micro Inc.)
DRV - (HssDrv) -- C:\WINDOWS\system32\drivers\HssDrv.sys (AnchorFree Inc.)
DRV - (tmactmon) -- C:\WINDOWS\system32\drivers\tmactmon.sys (Trend Micro Inc.)
DRV - (tmevtmgr) -- C:\WINDOWS\system32\drivers\tmevtmgr.sys (Trend Micro Inc.)
DRV - (tmcomm) -- C:\WINDOWS\system32\drivers\tmcomm.sys (Trend Micro Inc.)
DRV - (tmcfw) -- C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) -- C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (ctxusbm) -- C:\WINDOWS\system32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (hamachi) -- C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (pelusblf) -- C:\WINDOWS\system32\drivers\pelusblf.sys (TPMX Electronics Ltd.)
DRV - (pelmouse) -- C:\WINDOWS\system32\drivers\PELMOUSE.SYS (TPMX Electronics Ltd.)
DRV - (NAL) -- C:\WINDOWS\system32\drivers\iqvw32.sys (Intel Corporation )
DRV - (e1kexpress) Intel® -- C:\WINDOWS\system32\drivers\e1k5132.sys (Intel Corporation)
DRV - (IFXTPM) -- C:\WINDOWS\system32\drivers\ifxtpm.sys (Infineon Technologies AG)
DRV - (HECI) Intel® -- C:\WINDOWS\system32\drivers\HECI.sys (Intel Corporation)
DRV - (SFAUDIO) -- C:\WINDOWS\system32\drivers\sfaudio.sys (Sonic Focus, Inc)
DRV - (HPKBCCID) -- C:\WINDOWS\system32\drivers\HPKBCCID.sys (Hewlett-Packard Company)
DRV - (pelps2m) -- C:\WINDOWS\system32\drivers\PELPS2M.SYS (Primax Electronics Ltd.)
DRV - (USBCCID) -- C:\WINDOWS\system32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (DHEAPDMP) -- C:\WINDOWS\system32\drivers\dheapdmp.sys (Microsoft Corporation)
DRV - (STC2DFU) -- C:\WINDOWS\system32\drivers\Stc2Dfu.sys (SCM Microsystems Inc.)
DRV - (PalmUSBD) -- C:\WINDOWS\system32\drivers\PalmUSBD.sys (Palm, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhomepage
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.myhomepage
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.myhomepage
IE - HKCU\..\URLSearchHook: {3D31A26E-04D4-4B45-AFD4-DA4E1AE4AF1B} - C:\Program Files\Fuji Medical System\Synapse\Workstation\FujiFld.dll (FUJIFILM Medical Systems U.S.A., Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.myhomepage"
FF - prefs.js..extensions.enabledItems: [email protected]:3.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: [email protected]:3.6.20101102
FF - prefs.js..extensions.enabledItems: {0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}:1.0.1
FF - prefs.js..extensions.enabledItems: {53c4d698-0a74-873e-7946-7d19bb035667}:2.6
FF - prefs.js..extensions.enabledItems: [email protected]:0.1
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.6.2.1
FF - prefs.js..extensions.enabledItems: {34c51bf3-5fb2-4799-8cca-d5b8567cf7ef}:1.3
FF - prefs.js..extensions.enabledItems: {45d8ff86-d909-11db-9705-005056c00008}:1.0.5
FF - prefs.js..extensions.enabledItems: {723AAF16-AF1F-4404-A5D7-0BFE39766605}:0.3.4
FF - prefs.js..extensions.enabledItems: {a0faa0a4-f1a7-4098-9a74-21efc3a92372}:6.0.0
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.10
FF - prefs.js..extensions.enabledItems: {5362CD9D-AC69-43e5-8E7D-92EDE5CEF304}:0.8.1
FF - prefs.js..extensions.enabledItems: {B9C8BE50-7105-4ec6-8FB4-4935C0671648}:0.5.995
FF - prefs.js..extensions.enabledItems: goParentFolder@alice:2.5
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.11
FF - prefs.js..extensions.enabledItems: {aff87fa2-a58e-4edd-b852-0a20203c1e17}:0.8
FF - prefs.js..extensions.enabledItems: {3f0da09b-c1ab-40c5-8d7f-53f475ac3fe8}:0.10.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.2
FF - prefs.js..extensions.enabledItems: {1dbc4a33-ea62-4330-966c-7bdad3455322}:1.0.6.10
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {EF522540-89F5-46b9-B6FE-1829E2B572C6}:5.0.6
FF - prefs.js..extensions.enabledItems: showParentFolder@alice:1.8
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.6
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.3
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.9
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {46551EC9-40F0-4e47-8E18-8E5CF550CFB8}:1.2.2
FF - prefs.js..extensions.enabledItems: {6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}:0.9.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.2
FF - prefs.js..extensions.enabledItems: {01A8CA0A-4C96-465b-A49B-65C46FAD54F9}:6.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:5.0.1
FF - prefs.js..extensions.enabledItems: {582195F5-92E7-40a0-A127-DB71295901D7}:0.6.4.1
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.95
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.http: "wwwproxy.unimelb.edu.au"
FF - prefs.js..network.proxy.http_port: 8000
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files\Virtual Earth 3D\ [2011/02/01 15:27:42 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.17.4: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=5.2.5.48: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2010/12/02 13:25:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.2\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.5.2\extensions\\Plugins: C:\Program Files\Flock\plugins [2012/01/27 12:27:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.1\extensions\\Plugins: C:\Program Files\Flock\plugins [2012/01/27 12:27:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.2\extensions\\Components: C:\Program Files\Flock\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Flock 2.6.2\extensions\\Plugins: C:\Program Files\Flock\plugins [2012/01/27 12:27:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/20 11:14:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/15 13:14:52 | 000,000,000 | ---D | M]
[2012/02/16 09:56:59 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Extensions
[2009/10/27 17:00:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Extensions\{a463f10c-3994-11da-9945-000d60ca027b}
[2012/02/20 11:53:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (Auto Copy) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{0FED7D55-65D4-47b6-A6DE-9A4ADB55355F}
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (Remove It Permanently) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{1dbc4a33-ea62-4330-966c-7bdad3455322}
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2012/02/16 09:59:42 | 000,000,000 | ---D | M] (OperaView) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{87f54a61-c9b3-4138-a38a-33c31770bb9e}
[2012/02/16 09:59:42 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2012/02/16 09:59:42 | 000,000,000 | ---D | M] (Web Developer) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2012/02/16 09:59:42 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/02/16 09:59:41 | 000,000,000 | ---D | M] (IE View Lite) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2012/02/16 09:59:41 | 000,000,000 | ---D | M] (Mouse Gestures Redox) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{FFA36170-80B1-4535-B0E3-A4569E497DD0}
[2012/02/16 09:59:41 | 000,000,000 | ---D | M] (LO-FI) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\{lofi-0.1}
[2012/02/16 09:59:50 | 000,000,000 | ---D | M] (ColorSuckr) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:49 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:47 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:47 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\gohome
[2012/02/16 09:59:47 | 000,000,000 | ---D | M] ("Go Parent Folder") -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\goParentFolder@alice
[2012/02/16 09:59:46 | 000,000,000 | ---D | M] ("Link Alert") -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:46 | 000,000,000 | ---D | M] (Personas) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:45 | 000,000,000 | ---D | M] (Cooliris) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\[email protected]
[2012/02/16 09:59:44 | 000,000,000 | ---D | M] ("Show Parent Folder") -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\showParentFolder@alice
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (SphereGnome) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\SphereGnome
[2012/02/20 11:51:38 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\staged
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\tabbin
[2012/02/16 09:59:43 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\extensions\temp
[2005/09/15 10:19:13 | 000,000,377 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\alistapart.gif
[2005/11/22 09:43:27 | 000,000,657 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\alistapart.png
[2009/07/31 10:11:31 | 000,001,718 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\alistapart.src
[2008/03/14 10:05:25 | 000,001,672 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\amazondotcom.xml
[2012/02/13 09:49:12 | 000,002,371 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\blekko-https.xml
[2007/03/13 14:06:15 | 000,000,773 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\BracebridgePL.png
[2009/07/31 10:11:32 | 000,001,829 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\BracebridgePL.src
[2010/06/04 15:48:24 | 000,002,220 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\cheaprivercom.xml
[2011/10/04 09:15:29 | 000,001,698 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\compact-oxford-english-dict.xml
[2011/09/09 10:09:39 | 000,001,293 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\creativecommons-1.xml
[2007/03/14 12:59:18 | 000,001,293 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\creativecommons.xml
[2011/09/09 10:09:39 | 000,001,920 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\dogpile-1.xml
[2007/03/14 12:59:18 | 000,001,920 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\dogpile.xml
[2011/07/04 18:26:30 | 000,000,762 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\Dorlands.xml
[2011/09/26 14:18:48 | 000,001,982 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\duckduckgo-ssl.xml
[2007/03/13 14:45:38 | 000,000,189 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\firefoxsearch.gif
[2010/12/02 09:07:03 | 000,001,038 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\firefoxsearch.src
[2011/09/09 10:09:40 | 000,002,114 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\google-1.xml
[2008/06/02 10:18:50 | 000,002,180 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\google-maps.xml
[2007/03/14 12:59:19 | 000,002,114 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\google.xml
[2011/09/09 10:09:40 | 000,001,026 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\googlesearchmash-1.xml
[2008/03/03 09:25:33 | 000,001,026 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\googlesearchmash.xml
[2008/06/25 10:13:47 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\imdb.xml
[2010/10/04 15:00:17 | 000,002,550 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\isbn-lookup.xml
[2010/06/15 11:50:36 | 000,002,484 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\ixquick.xml
[2011/10/10 12:23:24 | 000,001,327 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\library-catalogue-by-author.xml
[2012/02/20 08:58:39 | 000,001,291 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\library-catalogue-by-title.xml
[2011/09/09 10:09:40 | 000,001,364 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\medicspl-1.xml
[2007/03/14 12:59:19 | 000,001,364 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\medicspl.xml
[2008/06/02 10:18:52 | 000,001,130 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\oald.xml
[2006/09/01 13:27:05 | 000,001,370 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\omd.gif
[2009/07/31 10:11:33 | 000,002,729 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\omd.src
[2006/08/24 15:17:22 | 000,000,547 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookAll.png
[2009/07/31 10:11:33 | 000,001,509 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookAll.src
[2012/02/13 09:49:09 | 000,001,498 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookAll.xml
[2006/03/22 09:43:07 | 000,000,534 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookDef.png
[2009/08/03 16:16:00 | 000,001,479 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookDef.src
[2012/02/13 09:49:10 | 000,001,468 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookDef.xml
[2006/09/12 13:55:41 | 000,000,533 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookTran.png
[2009/07/31 10:11:32 | 000,001,483 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookTran.src
[2012/02/13 09:49:10 | 000,001,472 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\OneLookTran.xml
[2012/02/13 09:49:11 | 000,002,091 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\quotations-book---search.xml
[2011/09/09 10:09:41 | 000,001,071 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\standardistas-1.xml
[2007/03/14 12:59:21 | 000,001,071 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\standardistas.xml
[2012/02/13 09:49:11 | 000,001,593 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\the-book-depository.xml
[2012/02/13 09:49:11 | 000,001,084 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\thesauruscom.xml
[2010/10/22 15:20:29 | 000,001,709 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\trove.xml
[2008/02/05 16:02:00 | 000,001,068 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\wikipedia-english.xml
[2006/11/08 13:21:07 | 000,000,739 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\wikipedia_google.png
[2009/07/31 10:11:33 | 000,001,826 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Mozilla\Firefox\Profiles\974fls0h.default\searchplugins\wikipedia_google.src
[2012/02/16 09:58:00 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{02450954-CDD9-410F-B1DA-DB804E18C671}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{45D8FF86-D909-11DB-9705-005056C00008}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{582195F5-92E7-40A0-A127-DB71295901D7}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{6D96BB5E-1175-4EBF-8AB5-5F56F1C79F65}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{A0FAA0A4-F1A7-4098-9A74-21EFC3A92372}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{AFF87FA2-A58E-4EDD-B852-0A20203C1E17}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{B22E157D-283C-498F-9554-C3A80E841E91}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\DOCUMENTS AND SETTINGS\myusername\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\974FLS0H.DEFAULT\EXTENSIONS\[email protected]
[2012/02/20 11:14:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/10/12 16:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010/10/12 16:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010/10/12 16:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010/10/12 16:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2010/10/29 12:50:39 | 000,101,768 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\ieatgpc.dll
[2010/10/29 12:50:22 | 000,064,392 | ---- | M] (Cisco WebEx LLC) -- C:\Program Files\mozilla firefox\plugins\npatgpc.dll
[2010/03/27 18:06:04 | 000,067,032 | ---- | M] (Adobe Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npContribute.dll
[2011/05/04 05:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2009/10/28 14:06:48 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/10/12 18:16:54 | 000,484,768 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2010/03/31 10:09:22 | 010,437,264 | ---- | M] (PDFTron Systems Inc.) -- C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 12:36:02 | 000,107,760 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2010/10/12 16:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012/02/09 04:12:58 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/09 04:12:58 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.11\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.11\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.11\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Update\1.3.21.99\npGoogleUpdate3.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Musicnotes\npsibelius.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Web Developer = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\bfbameneiokkgbdmiekhjnmfkcnldhhm\0.3.1_0\
CHR - Extension: Google Search = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.17_0\
CHR - Extension: Glossy Blue = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nheaocaplknjkpcnbadlgfpdfjaabiml\1.0_0\
CHR - Extension: Gmail = C:\Documents and Settings\myusername\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/01/27 11:59:09 | 000,441,010 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15161 more lines...
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (no name) - {1BD0BEFE-F697-4eee-B7E1-76B849A5CB84} - No CLSID value found.
O2 - BHO: (Synapse BHO Class) - {33414365-E6C7-460d-880A-A163BD69E84D} - C:\Program Files\Fuji Medical System\Synapse\Workstation\FujiFld.dll (FUJIFILM Medical Systems U.S.A., Inc.)
O2 - BHO: (Google Analytics Opt-out Browser Add-on) - {75EF13CE-B59E-41ba-8A5A-A944031BD8B4} - C:\Program Files\Google\Google Analytics Opt-Out\gaoptout.dll (Google, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (IE Developer Toolbar BHO) - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Athens Toolbar) - {2E560504-B9C8-48AA-982A-08B79C3FD40E} - C:\Program Files\Eduserv Technologies Limited\Athens Toolbar\AthensToolbar.dll (Eduserv Technologies Limited)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Athens Toolbar) - {2E560504-B9C8-48AA-982A-08B79C3FD40E} - C:\Program Files\Eduserv Technologies Limited\Athens Toolbar\AthensToolbar.dll (Eduserv Technologies Limited)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Mouse Suite 98 Daemon] C:\Program Files\Lenovo\Mouse Suite\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [OfficeScanNT Monitor] C:\Program Files\Trend Micro\OfficeScan Client\pccntmon.exe (Trend Micro Inc.)
O4 - HKCU..\Run: [compatUserPath] C:\Documents and Settings\myusername\Local Settings\Application Data\lanCommsTray\compatUserPath.dll ()
O4 - HKCU..\Run: [Xmarks] C:\Program Files\Xmarks\IE Extension\xmarkssync.exe (Xmarks.com)
O4 - Startup: C:\Documents and Settings\myusername\Start Menu\Programs\Startup\PowerReg Scheduler.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 157
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: disablecad = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWelcomeScreen = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceStartMenuLogOff = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoTaskGrouping = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMBalloonTip = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoAutoTrayNotify = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogonScripts = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {00134F72-5284-44F7-95A8-52A619F70751} https://rchav:4343/o...ll/WinNTChk.cab (ObjWinNTCheck Class)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {08D75BC1-D2B5-11D1-88FC-0080C859833B} https://rchav:4343/o...stall/setup.cab (OfficeScan Corp Edition Web-Deployment SetupCtrl Class)
O16 - DPF: {1FBD11EF-1260-11D1-87A7-444553540001} http://rch-synapse (Synapse)
O16 - DPF: {35C3D91E-401A-4E45-88A5-F3B32CD72DF4} https://rchav:4343/o...root/AtxEnc.cab (Encrypt Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1239245532500 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.100.33 172.16.100.24
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mycorporatedomain
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CE58FBE9-0429-4227-B9D8-68B33FDA66D1}: DhcpNameServer = 172.16.100.33 172.16.100.24
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\myusername\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\myusername\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Documents and Settings\myusername\Application Data\Qualcomm\Eudora\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/27 11:57:20 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2011/06/03 11:18:52 | 000,000,000 | ---- | M] () - W:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\##it13275#d\Shell - "" = AutoRun
O33 - MountPoints2\##it13275#d\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\##it13275#d\Shell\AutoRun\command - "" = Y:\Roxio.exe cmd.exe /c setup.bat
O33 - MountPoints2\{88daf7b6-27e2-11df-a5b3-0026553d3c89}\Shell - "" = AutoRun
O33 - MountPoints2\{88daf7b6-27e2-11df-a5b3-0026553d3c89}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{88daf7b6-27e2-11df-a5b3-0026553d3c89}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{88daf7b7-27e2-11df-a5b3-0026553d3c89}\Shell\AutoRun\command - "" = POPAJ///mornarje.exe
O33 - MountPoints2\{88daf7b7-27e2-11df-a5b3-0026553d3c89}\Shell\open\command - "" = POPAJ///mornarje.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/16 13:12:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\Desktop\opeansans
[2012/02/16 09:34:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\My Documents\firefoxProfile20120216
[2012/02/13 14:19:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\Application Data\Malwarebytes
[2012/02/13 14:19:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/13 14:19:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2012/02/13 14:19:01 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2012/02/13 14:19:01 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/13 10:23:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/02/13 10:23:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\SpywareBlaster
[2012/02/13 10:23:04 | 000,000,000 | ---D | C] -- C:\Program Files\SpywareBlaster
[2012/02/09 08:26:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\Local Settings\Application Data\lanCommsTray
[2012/01/27 15:59:54 | 000,101,720 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/01/27 15:58:02 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2012/01/27 15:58:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft
[2012/01/27 15:58:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2012/01/27 14:55:13 | 000,000,000 | ---D | C] -- C:\Program Files\AutoRuns
[2012/01/27 11:50:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2012/01/27 11:50:21 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2012/01/27 11:50:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2012/01/25 15:48:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\Start Menu\Programs\HiJackThis
[2012/01/25 15:40:28 | 000,000,000 | ---D | C] -- C:\Program Files\TrendMicro
[2012/01/24 10:05:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\myusername\My Documents\EndNote
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\myusername\*.tmp files -> C:\Documents and Settings\myusername\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/20 12:45:00 | 000,000,888 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/20 12:29:00 | 000,000,986 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2100782434-1583570100-1912232085-25644UA.job
[2012/02/20 11:10:58 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\myusername\Desktop\Word 2007.lnk
[2012/02/20 09:29:00 | 000,000,934 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-2100782434-1583570100-1912232085-25644Core.job
[2012/02/20 08:55:45 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/20 08:54:39 | 000,017,646 | ---- | M] () -- C:\WINDOWS\cfgall.ini
[2012/02/20 08:53:10 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/20 08:52:57 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/02/17 19:00:00 | 000,000,346 | ---- | M] () -- C:\WINDOWS\tasks\AdobeAAMUpdater-1.0-DOMAIN-myusername.job
[2012/02/17 15:58:58 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2012/02/17 15:58:47 | 000,000,064 | ---- | M] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/02/17 15:58:47 | 000,000,044 | ---- | M] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/02/17 09:15:30 | 000,000,730 | ---- | M] () -- C:\Documents and Settings\myusername\Desktop\Firefox.lnk
[2012/02/17 09:01:16 | 003,654,176 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2012/02/16 14:30:42 | 000,002,306 | ---- | M] () -- C:\Documents and Settings\myusername\Desktop\Google Chrome.lnk
[2012/02/16 14:30:42 | 000,002,284 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/02/16 13:29:46 | 000,002,443 | ---- | M] () -- C:\Documents and Settings\myusername\Desktop\Publisher 2007.lnk
[2012/02/16 10:01:12 | 000,000,748 | ---- | M] () -- C:\Documents and Settings\myusername\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to firefox.exe.lnk
[2012/02/14 15:37:03 | 002,879,036 | ---- | M] () -- C:\Documents and Settings\myusername\My Documents\SalaryPackagingMealCardANZ.pdf
[2012/02/14 15:02:33 | 000,502,222 | ---- | M] () -- C:\Documents and Settings\myusername\My Documents\SalaryPackagingHolidayClaim.pdf
[2012/02/14 12:03:16 | 001,928,678 | ---- | M] () -- C:\Documents and Settings\myusername\My Documents\bookmarks20121402.html
[2012/02/14 11:19:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/02/13 11:02:25 | 000,244,979 | ---- | M] () -- C:\Documents and Settings\myusername\Desktop\gmail-manager-0.6.4.1.4-tomondev.xpi
[2012/02/06 08:32:41 | 000,006,512 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
[2012/01/27 15:59:52 | 000,101,720 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys
[2012/01/27 15:59:52 | 000,016,432 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2012/01/27 14:30:59 | 000,002,124 | -H-- | M] () -- C:\Documents and Settings\myusername\My Documents\Default.rdp
[2012/01/27 11:59:09 | 000,441,010 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2012/01/27 11:59:09 | 000,441,010 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2012/01/25 16:00:14 | 000,000,195 | RHS- | M] () -- C:\boot.ini
[2012/01/24 08:58:03 | 000,007,620 | RHS- | M] () -- C:\Documents and Settings\myusername\ntuser.pol
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\myusername\*.tmp files -> C:\Documents and Settings\myusername\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/16 15:31:26 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\myusername\Desktop\Firefox.lnk
[2012/02/16 09:58:01 | 000,000,736 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/14 12:03:16 | 001,928,678 | ---- | C] () -- C:\Documents and Settings\myusername\My Documents\bookmarks20121402.html
[2012/02/13 11:02:24 | 000,244,979 | ---- | C] () -- C:\Documents and Settings\myusername\Desktop\gmail-manager-0.6.4.1.4-tomondev.xpi
[2012/01/30 15:59:02 | 000,000,064 | ---- | C] () -- C:\WINDOWS\System32\rp_stats.dat
[2012/01/30 15:59:02 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\rp_rules.dat
[2012/01/27 17:01:12 | 000,016,432 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2012/01/27 15:58:18 | 000,000,486 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011/11/15 21:16:11 | 000,355,032 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2011/10/11 09:06:24 | 000,000,658 | ---- | C] () -- C:\WINDOWS\unins000.dat
[2011/09/22 16:39:30 | 000,000,265 | ---- | C] () -- C:\WINDOWS\xvport.ini
[2011/06/27 16:43:47 | 000,005,632 | ---- | C] () -- C:\Documents and Settings\myusername\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/06 11:34:36 | 000,000,048 | ---- | C] () -- C:\WINDOWS\FileNamesinQueue.ini
[2010/12/02 14:42:40 | 000,077,120 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/11/04 10:55:56 | 000,001,363 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2010/04/29 16:46:37 | 000,003,840 | ---- | C] () -- C:\WINDOWS\System32\drivers\BANTExt.sys
[2010/04/15 17:50:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2010/02/01 15:25:59 | 000,011,264 | ---- | C] () -- C:\WINDOWS\DCEBoot.exe
[2009/11/18 16:06:24 | 000,000,091 | ---- | C] () -- C:\WINDOWS\webshots.ini
[2009/10/30 10:30:31 | 000,036,939 | ---- | C] () -- C:\WINDOWS\System32\insrepim.exe
[2009/10/28 15:41:49 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QUICKI~1.INI
[2009/10/28 13:14:11 | 000,000,503 | R--- | C] () -- C:\WINDOWS\DYMOLS.DAT
[2009/10/27 16:59:16 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2009/10/27 14:30:14 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/04/20 14:20:07 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2009/04/14 12:41:57 | 000,012,288 | ---- | C] () -- C:\WINDOWS\impborl.dll
[2009/04/14 12:41:28 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\FileOps.exe
[2009/04/14 11:34:05 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2009/04/14 11:22:09 | 000,000,395 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/04/14 10:24:37 | 000,017,646 | ---- | C] () -- C:\WINDOWS\cfgall.ini
[2009/04/09 18:26:59 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/04/09 18:25:53 | 003,654,176 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/09 15:59:47 | 002,026,604 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2009/04/09 15:59:46 | 000,442,964 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2009/04/09 15:59:46 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v5016.dll
[2009/04/09 13:12:12 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2009/04/09 13:07:54 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2006/10/12 17:35:56 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\Instx64.exe
[2004/08/04 02:07:22 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/02 15:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2001/08/23 23:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001/08/23 23:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001/08/23 23:00:00 | 000,447,020 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001/08/23 23:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001/08/23 23:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001/08/23 23:00:00 | 000,072,404 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001/08/23 23:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001/08/23 23:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001/08/23 23:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001/08/23 23:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2009/11/18 16:04:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\agi
[2010/12/13 09:04:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2011/05/06 11:41:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DataViz
[2011/09/16 12:46:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\hssff
[2011/09/20 15:05:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Karen's Power Tools
[2009/04/14 11:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2010/12/02 14:11:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2011/11/17 11:04:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith
[2012/02/13 10:56:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/09/05 12:52:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Thomson.ResearchSoft.Installers
[2009/11/23 11:20:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Uninstall
[2011/11/16 10:08:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/12/02 14:28:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/10 15:03:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2011/07/07 12:54:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\com.springbox.mobilizer
[2012/01/10 10:41:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Console
[2011/10/07 15:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Dropbox
[2012/01/24 09:38:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\EndNote
[2012/01/27 12:27:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Flock
[2009/10/28 14:06:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Foxit
[2011/07/26 16:59:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Gmail Backup
[2009/04/09 13:32:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\gtopala
[2010/12/14 09:06:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\ICAClient
[2009/11/23 17:06:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\IrfanView
[2010/01/14 16:02:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Launchy
[2009/10/28 15:27:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Leadertech
[2009/11/30 10:40:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\MusE
[2011/04/19 17:50:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\MySQL
[2011/10/25 14:58:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Notepad++
[2009/11/17 14:45:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\OpenOffice.org
[2011/04/15 16:55:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Opera
[2011/09/22 13:50:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\Qualcomm
[2012/01/16 10:30:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\myusername\Application Data\UBitMenu
[2012/02/17 15:58:58 | 000,000,486 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >