I am still not running as I should though. I no longer lock up - however I can't there are things I can't install at all (nor can I update Windows) and my son is going nuts cause World of Warcraft freaks out on him. ALSO - when I tried installing Microsoft Security Essentials - it .. wanted a disk.
(It didn't before - at least not consistently.)
Help!
Here is my OTL info - and thank you for looking.
OTL logfile created on: 7/2/2012 4:25:32 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\fred\Downloads
Windows Vista Home Basic Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6001.18000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.98 Gb Available Physical Memory | 52.24% Memory free
3.98 Gb Paging File | 3.01 Gb Available in Paging File | 75.52% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 139.05 Gb Total Space | 40.03 Gb Free Space | 28.79% Space Free | Partition Type: NTFS
Computer Name: FRED-PC | User Name: fred | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/02 16:25:09 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\fred\Downloads\OTL.exe
PRC - [2008/10/29 01:29:41 | 002,927,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/28 05:28:56 | 000,438,296 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppgooglenaclpluginchrome.dll
MOD - [2012/06/28 05:28:54 | 003,972,120 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
MOD - [2012/06/28 05:27:40 | 000,554,520 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\libglesv2.dll
MOD - [2012/06/28 05:27:38 | 000,117,784 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\libegl.dll
MOD - [2012/06/28 05:27:29 | 000,140,328 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\avutil-51.dll
MOD - [2012/06/28 05:27:28 | 000,262,184 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\avformat-54.dll
MOD - [2012/06/28 05:27:26 | 002,386,984 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\avcodec-54.dll
MOD - [2012/06/28 03:27:26 | 009,252,040 | ---- | M] () -- C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (osppsvc)
SRV - File not found [Auto | Stopped] -- -- (AMPingService)
SRV - [2012/06/03 21:18:05 | 000,529,232 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/05/15 05:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Disabled | Stopped] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/05/04 15:28:10 | 000,257,696 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/04/04 00:53:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/03/07 15:32:23 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/03/04 08:10:55 | 000,079,360 | ---- | M] (Creative Labs) [Disabled | Stopped] -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2011/04/27 15:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2008/11/18 14:15:30 | 000,307,200 | ---- | M] (Creative Technology Ltd) [Disabled | Stopped] -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2008/07/22 21:14:28 | 000,012,800 | ---- | M] (Agere Systems) [Disabled | Stopped] -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2008/06/11 13:18:30 | 000,024,576 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\EMACHINES\eMachines Recovery Management\Service\ETService.exe -- (ETService)
SRV - [2008/01/20 21:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- -- (SmartDefragDriver)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslfeb6c46c)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslfb132974)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslf5b6203e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslf47f537e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslf0dfd038)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslef651635)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslec9ac82c)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle7c9df3a)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle541ad81)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle4d8c87f)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle15de7ef)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle144669a)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsle0773905)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsld7914c71)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsld38d2322)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslcab9d791)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslc9f88f33)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslc5171ad5)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslc477291f)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslb7d346f5)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslb64e8d7d)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslb3d89bb4)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslb3b9f164)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslaf57a46a)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslad61eef3)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslacc8af68)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKslab453b2c)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla871476f)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla6e5a17e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla4d1cfd6)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla46ad7c6)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla391318b)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla2ac10db)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla15bcd1c)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsla0a77c34)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl9df4bad9)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl9b906d74)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl9b369bf4)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl93eecf63)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl9237fc5b)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl89b1d53b)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl87967334)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl856bcbb0)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl83ef4bf0)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl8312add5)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl775f739c)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl76000d41)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl64c472b3)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl6368b9fd)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl6307ac92)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl6116e6b1)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl5f3c5a9e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl5a58d381)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl58faae3e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl5791bdb7)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl5686b82b)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl55f280be)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl539b5fab)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl53765a4a)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl51db1323)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl4f05003a)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl4b3d62d6)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl4af12ddf)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl455374f1)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl450a992e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl42e49e87)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl349dc924)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl2a7945fd)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl1ea81d75)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl1bf56b1b)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl14cea0a3)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl145b7da0)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl13e4c2b2)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl12f85c8e)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl114313cc)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl0c761660)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl067c3c19)
DRV - File not found [Kernel | System | Stopped] -- -- (MpKsl03d0e3e3)
DRV - File not found [Kernel | Auto | Stopped] -- -- (MCSTRM)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2012/06/09 10:45:20 | 000,023,456 | ---- | M] (Phoenix Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\DrvAgent32.sys -- (DrvAgent32)
DRV - [2012/05/15 05:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2011/04/27 15:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/18 13:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2010/07/04 14:51:26 | 000,004,096 | ---- | M] () [Kernel | Unavailable | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV - [2010/03/10 16:56:21 | 000,247,320 | ---- | M] (silex technology, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\sxuptp.sys -- (sxuptp)
DRV - [2010/02/24 14:11:40 | 000,023,920 | ---- | M] (MediaMall Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\povrtdev.sys -- (msvad_simple)
DRV - [2009/10/16 03:11:56 | 001,168,896 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\P17.sys -- (P17)
DRV - [2009/03/28 08:38:00 | 000,034,128 | ---- | M] (DemoForge, LLC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dfmirage.sys -- (dfmirage)
DRV - [2008/08/18 19:58:00 | 000,145,952 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008/07/22 21:14:24 | 001,203,808 | ---- | M] (Agere Systems) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/06/11 13:13:24 | 000,015,392 | ---- | M] (Acer, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\int15.sys -- (int15)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {6c3a1de1-94ca-4ad6-acdf-c1324adc487b} - SOFTWARE\Classes\CLSID\{6c3a1de1-94ca-4ad6-acdf-c1324adc487b}\InprocServer32 File not found
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...ng}&rlz=1I7ACEW
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2548838
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.facebook.com/?ref=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://nikeplus.nike.com/nikeplus/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {66bd2442-241b-44cd-8c7a-b51037053cdb} - No CLSID value found
IE - HKCU\..\URLSearchHook: {b54561db-0bbb-41b4-a814-df8301fe0a8e} - No CLSID value found
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = Yahoo!
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...&rlz=1I7GGLL_en
IE - HKCU\..\SearchScopes\{76E9350E-0392-9C19-F83A-99BC015260AF}: "URL" = http://www.bing.com/...039&form=ZGAIDF
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2548838
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://inboxtoolbar....id=80544&lng=en
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....&fr=chr-offrhap
IE - HKCU\..\SearchScopes\{E5F5D888-2587-E012-A817-7038F5690F26}: "URL" = http://bing.zugo.com...fg=2-80-0-1r6H7
IE - HKCU\..\SearchScopes\Yahoo!: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@comrade.gamespy.com/comrade: C:\Program Files\GameSpy\Comrade\npcomrade.dll (IGN Entertainment)
FF - HKLM\Software\MozillaPlugins\@dimdim.com/DimdimPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@playstation.com/PsndlCheck,version=1.00: C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=15.0.4.53: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realarcade.com/RAClient: C:\ProgramData\RealArcade\npraclient.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: File not found
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\@tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\fred\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\fred\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\fred\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\fred\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\fred\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\mattelinc.com/HotWheelsLoader: C:\Users\fred\AppData\Local\sswat_hwrc_win_live\npHotWheelsLoader.dll (Mattel, Inc)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/25 22:35:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{97E22097-9A2F-45b1-8DAF-36AD648C7EF4}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/06/25 22:35:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/12/01 23:52:15 | 000,000,000 | ---D | M]
[2011/12/11 17:52:14 | 000,000,000 | ---D | M] (No name found) -- C:\Users\fred\AppData\Roaming\Mozilla\Extensions
[2011/12/05 20:52:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/08/17 19:41:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2009/04/03 11:43:24 | 000,000,000 | ---D | M] (The Browser Highlighter) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2010/12/04 14:23:34 | 000,000,000 | ---D | M] (QuickStores-Toolbar) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
[2011/08/17 19:39:49 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2000/01/01 03:00:00 | 000,167,704 | ---- | M] (Tracker Software Products Ltd.) -- C:\Program Files\mozilla firefox\plugins\npPDFXCviewNPPlugin.dll
[2009/03/30 17:13:54 | 000,098,304 | ---- | M] (RealNetworks) -- C:\Program Files\mozilla firefox\plugins\npraclient.dll
========== Chrome ==========
CHR - default_search_provider: images.search.yahoo.com (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo....p={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\fred\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\fred\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U30 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Users\fred\AppData\Local\Google\Chrome\Application\plugins\npatgpc.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\fred\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\fred\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Web Player\npdivx32.dll
CHR - plugin: Comrade Plugin (Enabled) = C:\Program Files\GameSpy\Comrade\npcomrade.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Musicnotes\npsibelius.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Media Go Detector (Enabled) = C:\Program Files\Sony\Media Go\npmediago.dll
CHR - plugin: PlayStation®Network Downloader Check Plug-in (Enabled) = C:\Program Files\Sony\PLAYSTATION Network Downloader\nppsndl.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
CHR - plugin: WildTangent Games App Presence Detector (Enabled) = C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\5\NP_wtapp.dll
CHR - plugin: RealArcade NPAPI Plugin (Enabled) = C:\ProgramData\RealArcade\npraclient.dll
CHR - plugin: RealNetworks RealPlayer Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\fred\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\fred\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: HotWheels Loader (Enabled) = C:\Users\fred\AppData\Local\sswat_hwrc_win_live\npHotWheelsLoader.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files\real\realplayer\Netscape6\nprjplug.dll
CHR - Extension: YouTube = C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Gmail = C:\Users\fred\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/03/10 22:25:36 | 000,302,589 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 10431 more lines...
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {66BD2442-241B-44CD-8C7A-B51037053CDB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Isohunt-vuze Toolbar) - {6C3A1DE1-94CA-4AD6-ACDF-C1324ADC487B} - Reg Error: Value error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - Reg Error: Value error. File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O8 - Extra context menu item: &Search - ?p=ZKfox000 File not found
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creat...13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creat...015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...10926/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{72503EEE-C220-4622-AD9A-2EFD31CB7797}: DhcpNameServer = 192.168.2.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\fred\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\fred\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/06/29 00:44:20 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\aliasworlds
[2012/06/29 00:42:57 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kingdom Chronicles Collector's Edition
[2012/06/29 00:42:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kingdom Chronicles Collector's Edition
[2012/06/29 00:42:57 | 000,000,000 | ---D | C] -- C:\Program Files\Kingdom Chronicles Collector's Edition
[2012/06/28 15:40:07 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/06/28 14:01:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/06/28 13:58:46 | 000,453,424 | ---- | C] (Microsoft Corporation) -- C:\Users\fred\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/06/28 13:12:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2
[2012/06/28 02:52:40 | 000,000,000 | ---D | C] -- C:\WINSSLog
[2012/06/28 02:13:31 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free Registry Defrag
[2012/06/28 02:13:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Registry Defrag
[2012/06/28 02:13:31 | 000,000,000 | ---D | C] -- C:\Program Files\Eusing Free Registry Defrag
[2012/06/28 01:56:35 | 000,000,000 | ---D | C] -- C:\Program Files\OApps
[2012/06/28 01:48:49 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\FixCleaner
[2012/06/28 01:48:24 | 000,000,000 | ---D | C] -- C:\Program Files\FixCleaner
[2012/06/28 01:47:39 | 000,000,000 | ---D | C] -- C:\Program Files\Downloaded Installers
[2012/06/28 00:21:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpaceMonger
[2012/06/28 00:21:11 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\SpaceMonger
[2012/06/28 00:21:11 | 000,000,000 | ---D | C] -- C:\Program Files\SpaceMonger
[2012/06/28 00:12:11 | 000,000,000 | ---D | C] -- C:\Users\fred\Desktop\New Folder
[2012/06/25 23:10:00 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Pokémon Trading Card Game Online
[2012/06/25 22:35:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealNetworks
[2012/06/21 16:52:41 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse
[2012/06/18 13:42:57 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\f-secure
[2012/06/18 13:42:36 | 000,000,000 | ---D | C] -- C:\ProgramData\F-Secure
[2012/06/14 20:17:29 | 019,607,872 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvoglv32.dll
[2012/06/14 20:17:29 | 011,354,944 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\drivers\nvlddmkm.sys
[2012/06/14 20:17:28 | 017,551,680 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcompiler.dll
[2012/06/14 20:17:28 | 005,982,528 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuda.dll
[2012/06/14 20:17:28 | 002,524,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvid.dll
[2012/06/14 20:17:28 | 002,445,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\System32\nvcuvenc.dll
[2012/06/09 10:45:20 | 000,023,456 | ---- | C] (Phoenix Technologies) -- C:\Windows\System32\drivers\DrvAgent32.sys
[2012/06/09 10:45:20 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Local\eSupport.com
[2012/06/04 18:53:48 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\WeatherLord
[2012/06/04 18:53:48 | 000,000,000 | ---D | C] -- C:\ProgramData\WeatherLord
[2012/06/04 18:00:24 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Weather Lord
[2012/06/04 18:00:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Weather Lord
[2012/06/04 18:00:24 | 000,000,000 | ---D | C] -- C:\Program Files\Weather Lord
[2012/06/04 17:33:49 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Roaming\Rainbow
[2012/06/03 12:25:37 | 000,000,000 | ---D | C] -- C:\Users\fred\AppData\Local\CutePDF Writer
[2012/06/03 12:22:48 | 000,000,000 | ---D | C] -- C:\Program Files\Acro Software
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\fred\*.tmp files -> C:\Users\fred\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/02 16:28:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/02 16:01:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1286577877-1167854462-976776892-1000UA.job
[2012/07/02 15:47:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/02 15:47:01 | 000,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/02 13:16:01 | 000,000,420 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{DF351888-2C7F-48D3-8BA2-401173E31F50}.job
[2012/07/02 11:01:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1286577877-1167854462-976776892-1000Core.job
[2012/07/01 21:16:53 | 000,002,072 | ---- | M] () -- C:\Users\fred\Desktop\Google Chrome.lnk
[2012/07/01 21:16:53 | 000,002,034 | ---- | M] () -- C:\Users\fred\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/07/01 20:37:40 | 000,000,882 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2012/07/01 20:28:08 | 000,007,046 | ---- | M] () -- C:\Users\fred\profiles.xml
[2012/07/01 18:00:00 | 000,000,292 | ---- | M] () -- C:\Windows\tasks\next.job
[2012/07/01 15:47:01 | 000,000,380 | ---- | M] () -- C:\Windows\tasks\AutoSmartDefrag.job
[2012/07/01 15:46:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/29 00:43:48 | 000,035,369 | ---- | M] () -- C:\Windows\wininit.ini
[2012/06/29 00:43:44 | 000,001,981 | ---- | M] () -- C:\Users\Public\Desktop\Play Kingdom Chronicles Collector's Edition.lnk
[2012/06/29 00:43:44 | 000,001,600 | ---- | M] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2012/06/28 13:58:50 | 000,453,424 | ---- | M] (Microsoft Corporation) -- C:\Users\fred\Desktop\IE9-WindowsVista-x86-enu.exe
[2012/06/28 03:07:43 | 000,002,234 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/28 02:36:34 | 000,264,771 | ---- | M] () -- C:\Users\fred\AppData\Local\census.cache
[2012/06/28 02:36:27 | 000,187,966 | ---- | M] () -- C:\Users\fred\AppData\Local\ars.cache
[2012/06/28 02:13:31 | 000,000,861 | ---- | M] () -- C:\Users\fred\Desktop\Eusing Free Registry Defrag.lnk
[2012/06/28 01:38:59 | 000,275,629 | ---- | M] () -- C:\Windows\Let's Clean Up! Plus Uninstaller.exe
[2012/06/25 22:35:52 | 000,000,847 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/06/25 22:35:27 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012/06/25 22:35:19 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012/06/25 22:35:19 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012/06/21 16:52:41 | 000,000,312 | ---- | M] () -- C:\Users\fred\Desktop\Curse Client.appref-ms
[2012/06/09 10:46:04 | 000,000,950 | ---- | M] () -- C:\Users\fred\Desktop\Find Drivers with DriverAgent.lnk
[2012/06/09 10:45:20 | 000,023,456 | ---- | M] (Phoenix Technologies) -- C:\Windows\System32\drivers\DrvAgent32.sys
[2012/06/05 16:21:17 | 000,541,961 | ---- | M] () -- C:\Users\fred\Desktop\heart-wallpaper-love-10959423-1280-1024.jpg
[2012/06/04 18:00:54 | 000,001,733 | ---- | M] () -- C:\Users\Public\Desktop\Play Weather Lord.lnk
[2012/06/03 12:35:10 | 036,956,558 | ---- | M] () -- C:\Users\fred\Documents\Easyunsecured.pdf
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Users\fred\*.tmp files -> C:\Users\fred\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/06/29 09:22:56 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\The Sims™ Medieval.lnk
[2012/06/29 00:43:44 | 000,001,981 | ---- | C] () -- C:\Users\Public\Desktop\Play Kingdom Chronicles Collector's Edition.lnk
[2012/06/29 00:43:44 | 000,001,600 | ---- | C] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2012/06/28 02:13:31 | 000,000,861 | ---- | C] () -- C:\Users\fred\Desktop\Eusing Free Registry Defrag.lnk
[2012/06/25 22:35:52 | 000,000,847 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2012/06/09 10:46:04 | 000,000,950 | ---- | C] () -- C:\Users\fred\Desktop\Find Drivers with DriverAgent.lnk
[2012/06/05 16:21:36 | 000,541,961 | ---- | C] () -- C:\Users\fred\Desktop\heart-wallpaper-love-10959423-1280-1024.jpg
[2012/06/04 18:00:54 | 000,001,733 | ---- | C] () -- C:\Users\Public\Desktop\Play Weather Lord.lnk
[2012/06/03 12:36:21 | 036,956,558 | ---- | C] () -- C:\Users\fred\Documents\Easyunsecured.pdf
[2012/03/03 19:07:09 | 000,001,463 | ---- | C] () -- C:\Windows\System32\AudioDrv.ini
[2012/03/03 19:05:08 | 000,166,912 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2012/03/03 19:05:08 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2012/02/22 08:50:57 | 000,001,534 | ---- | C] () -- C:\ProgramData\ss.ini
[2012/02/18 22:37:41 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/12/26 22:26:43 | 000,275,629 | ---- | C] () -- C:\Windows\Let's Clean Up! Plus Uninstaller.exe
[2011/12/21 18:09:35 | 000,148,928 | ---- | C] () -- C:\Windows\hpoins19.dat
[2011/12/21 18:09:20 | 000,026,952 | ---- | C] () -- C:\Windows\hpomdl19.dat
[2011/12/06 22:16:07 | 000,264,771 | ---- | C] () -- C:\Users\fred\AppData\Local\census.cache
[2011/12/06 22:15:43 | 000,187,966 | ---- | C] () -- C:\Users\fred\AppData\Local\ars.cache
[2011/12/06 21:06:12 | 000,000,036 | ---- | C] () -- C:\Users\fred\AppData\Local\housecall.guid.cache
[2011/10/06 21:22:35 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2011/09/20 23:58:48 | 000,007,046 | ---- | C] () -- C:\Users\fred\profiles.xml
[2011/09/03 11:52:13 | 000,000,218 | ---- | C] () -- C:\Users\fred\.recently-used.xbel.USWK1V
[2011/07/20 12:29:56 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/05/04 11:36:26 | 000,000,127 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2011/03/02 19:48:00 | 000,000,008 | ---- | C] () -- C:\Users\fred\AppData\Roaming\DofusAppId0_1
[2011/03/02 18:33:28 | 000,000,169 | ---- | C] () -- C:\Users\fred\AppData\Roaming\D2Info0
[2011/03/02 18:33:28 | 000,000,008 | ---- | C] () -- C:\Users\fred\AppData\Roaming\DofusAppId0_2
[2011/02/14 20:54:50 | 000,000,552 | ---- | C] () -- C:\Users\fred\AppData\Local\d3d8caps.dat
[2010/11/28 22:24:08 | 000,011,164 | ---- | C] () -- C:\Windows\System32\drivers\nvphy.bin
[2010/11/01 16:21:17 | 000,002,048 | ---- | C] () -- C:\Users\fred\writeordiesettings.db
[2010/07/05 18:35:47 | 000,000,050 | ---- | C] () -- C:\Users\fred\jagex__preferences3.dat
[2010/07/05 18:35:46 | 000,000,117 | ---- | C] () -- C:\Users\fred\jagex_runescape_preferences2.dat
[2010/07/05 18:34:29 | 000,000,046 | ---- | C] () -- C:\Users\fred\jagex_runescape_preferences.dat
[2009/11/03 23:32:43 | 000,034,800 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/11/03 22:46:48 | 000,034,800 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/10/14 15:00:07 | 000,000,680 | ---- | C] () -- C:\Users\fred\AppData\Local\d3d9caps.dat
[2009/08/06 19:00:23 | 000,070,984 | ---- | C] () -- C:\Users\fred\g2mdlhlpx.exe
[2009/06/09 16:02:28 | 000,000,000 | -H-- | C] () -- C:\ProgramData\pjwllw
[2009/06/01 15:39:00 | 000,000,000 | ---- | C] () -- C:\Users\fred\AppData\Local\prvlcl.dat
[2009/04/16 19:00:21 | 000,001,458 | ---- | C] () -- C:\Users\fred\.recently-used.xbel
[2009/03/21 11:35:03 | 000,000,092 | ---- | C] () -- C:\Users\fred\AppData\Local\fusioncache.dat
[2009/03/06 22:25:25 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008/12/13 21:01:14 | 000,005,115 | ---- | C] () -- C:\ProgramData\N360BUOptions.ini
[2008/12/01 17:41:17 | 000,000,004 | ---- | C] () -- C:\Users\fred\AppData\Roaming\C8CBD2
[2008/12/01 17:41:16 | 000,870,128 | ---- | C] () -- C:\Users\fred\AppData\Roaming\mcs.rma
[2008/11/05 02:11:44 | 000,022,528 | ---- | C] () -- C:\Users\fred\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:9EC86225
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:900BE829
@Alternate Data Stream - 97 bytes -> C:\ProgramData\TEMP:14750D76
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:DDEB08FD
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:538B96B5
@Alternate Data Stream - 257 bytes -> C:\ProgramData\TEMP:A039EDF9
@Alternate Data Stream - 243 bytes -> C:\ProgramData\TEMP:36608448
@Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:371A321E
@Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:A2B3764A
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:0E67073E
@Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:9D6EAEC3
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:9CF728A6
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:D0AB0B4A
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:F2CEC0E8
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:5F1019FF
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:3766E957
@Alternate Data Stream - 220 bytes -> C:\ProgramData\TEMP:E8BF029E
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:0D52F295
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:DD629819
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:6378B6B8
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:A4AF8D0D
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:723E56EC
@Alternate Data Stream - 200 bytes -> C:\ProgramData\TEMP:18897B1D
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:F1F936DF
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:E6B6120A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:6ECD2470
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:41B89F80
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:93F3E4C9
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:EB9EF516
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:E6540C35
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:3A4C8FE7
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F53B274A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:B790962B
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A819A132
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:A652BC99
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:0E5CFA74
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:413E2927
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:0DE96CF5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:F3591DDB
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:CAF8DAC8
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:AE289451
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:35629AE6
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:D770A15D
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:9D03192E
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:1BEAD68C
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:F35AE645
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E9900C74
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:DCA79AB3
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:BB718C46
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:701B92FB
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7DF1EF45
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:517EFA90
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:3FB71C37
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:0968E571
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F98E6C67
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4C21784C
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:FEECF2C8
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A1A86E40
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:7E4E56EA
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:F5FC5DCE
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:1A15C0AF
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D3A89E47
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:5313B881
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:E6EC5C2A
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:C4870D32
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:B1E64E47
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:6DA18708
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:44E16D4A
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:1B3549F2
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:EB5BDBB0
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:92DB4653
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3FAE5A2A
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:3A4676D7
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:06C34166
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:CFC8A5FD
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:1CA73D29
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:10CFA7D4
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:C43C957E
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6BFA43EB
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:014BC3B4
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:E6537A16
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:AED4FFF5
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:96646EC1
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:80E965A3
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:3AC0ED43
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:AEEC88F6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:417B6FAC
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:04BB186B
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:290A724C
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:10D45FC3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0DFE2AE1
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0ACF1AF5
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D576A536
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D01ACC06
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:7AF9CAEB
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:73B78E79
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:162E02F7
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:BA24E689
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6DDFD746
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:3C9B05C4
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:385BC52C
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:9B2BD056
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:38D2EA83
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:E4EE99EF
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:D6DD5F62
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:CFF6B3FF
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9857FAE3
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:69FE2EE4
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5D17C178
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:28819F45
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2216A431
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1B262C29
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:EA7D76BE
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:48FEA089
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:ADFAD95A
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:A688EF17
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:42478B0E
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:29C0641D
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:EE49CE4E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:EB68CA55
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:6F1F66C0
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:349E5B74
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:A6CDBCAC
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:041C0562
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:A9ABA3FF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:393F7B1E
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:07C99568
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:C80C7DFB
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:294F888B
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:15752405
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:0BF96601
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:A00BCDEF
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:A561576B
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:423A67E6
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:13DF9DD1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:A0C7D68A
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:8247A199
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:48081133
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:24E8169B
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:883EDFB5
< End of report >
On an embarrassing note - I am seeing the word *sex* in this file... what IS THAT?? My son is to young for that stuff!!
OH - also - I am trying to get as much garbage off this computer as I can - so feel free to make all the suggestions you like. Basically this is a (bad) WoW/internet surfing computer