When clicking links in Google or Yahoo search results, a new tab or window gets opened instead of the search link and is sent to "get-answers-fast.com" or "8.26.70.252" with some (what I assumed to be) bogus links/ads. I've never clicked on any of them and just close the window. Next time I click the google/yahoo search link, it goes to the right place.
The help I got here last time was outstanding (Essexboy, if I remember correctly), so thanks in advance!
OTL log:
OTL logfile created on: 7/27/2012 2:38:45 PM - Run 1
OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Ryan2011\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.97 Gb Total Physical Memory | 1.75 Gb Available Physical Memory | 44.25% Memory free
7.93 Gb Paging File | 5.66 Gb Available in Paging File | 71.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 453.69 Gb Total Space | 396.80 Gb Free Space | 87.46% Space Free | Partition Type: NTFS
Computer Name: RYAN2011-PC | User Name: Ryan2011 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/27 14:36:15 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan2011\Desktop\OTL.exe
PRC - [2012/07/02 17:12:50 | 000,021,432 | ---- | M] () -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012/07/02 17:12:42 | 003,524,536 | ---- | M] (Samsung Electronics Co., Ltd.) -- C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
PRC - [2012/07/02 17:12:40 | 000,975,288 | ---- | M] (Samsung) -- C:\Program Files (x86)\Samsung\Kies\Kies.exe
PRC - [2012/05/24 14:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/02/22 20:49:58 | 006,591,800 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010/03/03 21:16:06 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/03/03 21:16:04 | 000,284,696 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
========== Modules (No Company Name) ==========
MOD - [2012/07/17 09:40:15 | 000,221,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\26e0457a9776a0e9f23e3986686d90a5\System.ServiceProcess.ni.dll
MOD - [2012/07/17 09:39:56 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\d0e1cdaff8f9055187f8e7b52c060dff\System.Management.ni.dll
MOD - [2012/07/17 09:38:48 | 000,762,880 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\31fab24c51c0cfe8b8115f24545f169f\System.Runtime.Remoting.ni.dll
MOD - [2012/07/17 09:38:42 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\b68bee05c7e518172982cc92059c3315\System.Xaml.ni.dll
MOD - [2012/07/17 09:05:09 | 000,115,137 | ---- | M] () -- C:\Users\Ryan2011\AppData\Local\Temp\99cab429-f99d-4f69-9d04-113ad532bd0f\CliSecureRT.dll
MOD - [2012/07/17 08:58:29 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\00a4922fbf869a79c043b665035516b6\System.Windows.Forms.ni.dll
MOD - [2012/07/17 08:58:25 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\608d29d7cc89f3a9a195c91354561915\PresentationFramework.Aero.ni.dll
MOD - [2012/07/17 08:58:20 | 018,019,840 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\d239f585ee55f833dbe21e897e1265ac\PresentationFramework.ni.dll
MOD - [2012/07/17 08:58:20 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\4230ed1c7990e4ee8352baf67a2a85fa\System.Drawing.ni.dll
MOD - [2012/07/17 08:58:10 | 000,982,528 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\a84262e1224189f93e10cd3c403a9527\System.Configuration.ni.dll
MOD - [2012/07/17 08:58:08 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\9abe44a0f82070ead5f1256683a4d25a\System.Xml.ni.dll
MOD - [2012/07/17 08:58:07 | 011,522,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b7de318e9fd1ef519ca6c1f3b5dba8e0\PresentationCore.ni.dll
MOD - [2012/07/17 08:58:03 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\09bd2126bba2ab4f29ed52afde1470d7\System.Core.ni.dll
MOD - [2012/07/17 08:57:59 | 003,881,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\a6e37a05b8d0cedbc5c3ea266ae3fc31\WindowsBase.ni.dll
MOD - [2012/07/17 08:57:57 | 009,092,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\a6be120e49f895ef6b00e9918402395b\System.ni.dll
MOD - [2012/07/17 08:57:52 | 014,414,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\c1af4ec9a36f671617a8ecaec00373f4\mscorlib.ni.dll
MOD - [2012/07/02 17:12:50 | 000,021,432 | ---- | M] () -- C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2012/06/15 08:05:35 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/06/15 08:05:29 | 001,591,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/05/10 10:16:50 | 000,452,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\635b3aec298ad5e8c903b2323d79cc5a\IAStorUtil.ni.dll
MOD - [2012/05/10 08:45:43 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\03dee80574f4ec770b6f77ca030ded6c\System.Runtime.Remoting.ni.dll
MOD - [2012/05/10 08:45:08 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\46fce56db7685a586d3eeb7c373e3c1c\WindowsBase.ni.dll
MOD - [2012/05/10 08:45:04 | 005,452,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/05/10 08:45:01 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/05/10 08:45:00 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/05/10 08:44:56 | 011,492,864 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/02/22 20:49:56 | 000,921,600 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2012/02/22 20:49:38 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2007/06/25 22:17:18 | 000,567,024 | ---- | M] ( ) [Auto | Running] -- C:\Windows\SysNative\dlbkcoms.exe -- (dlbk_device)
SRV - [2012/07/27 13:47:24 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/02/29 09:16:46 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/16 10:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/10/22 13:08:18 | 001,039,360 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2010/09/10 04:03:37 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/03 21:16:06 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/06/04 03:59:20 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:64bit: - [2012/06/04 03:59:20 | 000,099,384 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/06/10 07:34:52 | 000,539,240 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/11 19:16:38 | 010,628,640 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/12/21 01:55:02 | 000,172,104 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdm.sys -- (sscdmdm)
DRV:64bit: - [2010/12/21 01:55:02 | 000,136,264 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdbus.sys -- (sscdbus)
DRV:64bit: - [2010/12/21 01:55:02 | 000,019,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:39:20 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 22:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/05/26 08:13:10 | 000,138,752 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {DC718571-D9D1-419F-8C55-D9E6BD5837E5}
IE:64bit: - HKLM\..\SearchScopes\{DC718571-D9D1-419F-8C55-D9E6BD5837E5}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {B0774E76-A7A8-4B69-B75F-965BB88F7716}
IE - HKLM\..\SearchScopes\{B0774E76-A7A8-4B69-B75F-965BB88F7716}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {C2D80772-E9E2-4A44-B4C3-37316F4FC994}
IE - HKCU\..\SearchScopes\{C2D80772-E9E2-4A44-B4C3-37316F4FC994}: "URL" = http://www.google.co...utputEncoding?}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Ryan2011\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3252b9ae-c69a-4eaf-9502-dc9c1f6c009e}: C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Default Manager\DMExtension\ [2011/02/21 17:58:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/03 10:03:31 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/04/03 10:03:31 | 000,000,000 | ---D | M]
[2011/02/03 15:09:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan2011\AppData\Roaming\Mozilla\Extensions
[2011/02/03 15:09:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ryan2011\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Ryan2011\AppData\Local\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Ryan2011\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Ryan2011\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Ryan2011\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
O1 HOSTS File: ([2012/07/13 14:14:41 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [masqform.exe] C:\Program Files (x86)\PureEdge\Viewer 6.1\masqform.exe (PureEdge™ Solutions Inc.)
O4 - HKCU..\Run: [KiesAirMessage] C:\Program Files (x86)\Samsung\Kies\KiesAirMessage.exe -startup File not found
O4 - HKCU..\Run: [KiesPDLR] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKCU..\Run: [KiesPreload] C:\Program Files (x86)\Samsung\Kies\Kies.exe (Samsung)
O4 - HKCU..\Run: [PackageAware] C:\Users\Ryan2011\AppData\Local\SCE\PackageAware\jqjsvyzea.dll (Microsoft Corporation)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Ryan2011\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Ryan2011\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.appl...ex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} Reg Error: Value error. (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.1)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2DBCD195-5512-4C7A-8C99-29D6593BD0FF}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\text/xml - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\GoToAssist: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\igfxcui: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/27 14:36:15 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Ryan2011\Desktop\OTL.exe
[2012/07/27 14:20:13 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\syncdb
[2012/07/27 14:16:17 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Roaming\Roxio Log Files
[2012/07/27 08:11:09 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{B1D60830-4A93-4DD2-9AF3-3E309EAC19D2}
[2012/07/27 08:10:47 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{2B62DCF9-0282-428D-9E56-CEF32B476034}
[2012/07/26 12:16:05 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{00B8FCBF-70A2-4C2D-9CA7-C4DEAC75A4F7}
[2012/07/26 12:15:43 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{01FDE9C7-60EB-43DD-8448-AE6344D6CABC}
[2012/07/25 09:44:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{411A4653-5544-4199-B64D-51025A86D65F}
[2012/07/25 09:43:44 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{95F8FB28-3C61-48C9-A5C9-3A15E4E9E528}
[2012/07/25 09:12:01 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{4BAAEBD8-80A5-44D3-A0C8-987483F0898C}
[2012/07/25 08:40:05 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{C466CFEF-CA85-4EEB-9483-2CE160EFE8D4}
[2012/07/24 08:51:22 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{10C6D68A-1403-4481-933F-A1D0120305C9}
[2012/07/24 08:51:12 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{E53A20AD-F015-445B-97DC-C489763F7217}
[2012/07/24 08:50:38 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{78B95329-AF27-483E-AC0B-CAB2E571F339}
[2012/07/23 08:40:54 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{53426008-2DED-4F7E-83CC-513ED6C42285}
[2012/07/23 08:40:32 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{35A44E51-3640-489C-BF50-21281E382D07}
[2012/07/20 16:27:20 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\Documents\Amazon MP3
[2012/07/20 16:27:20 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Roaming\Amazon
[2012/07/20 16:27:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon
[2012/07/20 16:26:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Amazon
[2012/07/20 15:50:27 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Roaming\Mp3tag
[2012/07/20 15:50:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
[2012/07/20 15:50:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mp3tag
[2012/07/20 10:53:26 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{7D08391D-9FE3-4871-A874-4104E6EEF3E4}
[2012/07/20 10:53:04 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{2B1C6FDF-30E0-4476-9658-393F923AAF24}
[2012/07/19 10:09:34 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{36F9D855-FAC8-4ED4-B85B-5FBB41FCAD5B}
[2012/07/19 10:09:12 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{81FA7950-AAF0-4F46-B42C-30BD86D02FDF}
[2012/07/18 10:54:07 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{C621C82E-225F-42D3-9B0B-C4224FA3A38E}
[2012/07/18 10:53:45 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{C6B700AD-E0B6-47FD-A2A5-0541581CBF54}
[2012/07/18 09:44:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{9EC7C4F6-01CA-4D9C-8C06-848E973D701B}
[2012/07/17 16:05:00 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{61E94070-CFF3-4F5A-B3F5-FC0183760D98}
[2012/07/17 16:04:38 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{0F9F57AB-69B2-49BA-89AC-422C7CE7BE39}
[2012/07/17 09:05:07 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\Samsung
[2012/07/17 09:05:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Roaming\Samsung
[2012/07/17 09:05:03 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\Documents\samsung
[2012/07/17 09:01:18 | 000,203,320 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudmdm.sys
[2012/07/17 09:01:18 | 000,099,384 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\SysNative\drivers\ssudbus.sys
[2012/07/17 08:59:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012/07/17 08:53:44 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\Downloaded Installations
[2012/07/16 09:04:35 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{2EDC88E6-C36B-4FA8-8284-6D7315B1B724}
[2012/07/16 09:04:13 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{869DAA39-FE59-4F99-AF4F-6488417176C0}
[2012/07/13 14:33:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/07/13 14:32:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oracle
[2012/07/13 11:48:48 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{6DF4A0FD-DB0E-4815-9385-7923F72A587F}
[2012/07/13 11:48:26 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{FF85A945-8B16-444B-AF87-7EB89306A957}
[2012/07/12 15:31:18 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/07/12 15:26:19 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/12 10:33:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/07/12 10:33:55 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/07/12 09:52:48 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012/07/12 08:09:40 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{2619D69C-25F9-47FF-8D7B-B6EF8EBABD9C}
[2012/07/12 08:09:18 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{04F1100D-E76F-478A-9676-1666AA4BDFF0}
[2012/07/11 09:33:29 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{FFD0C2A0-4BC8-4EEF-A969-E772575F4DA0}
[2012/07/11 08:17:23 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{806461CF-D781-43DE-86CD-839A519A5299}
[2012/07/10 11:21:34 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{756BD6CD-DBE3-41E4-8F56-35D6E32666AB}
[2012/07/10 11:21:12 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{834BB3F5-02D8-4686-A68E-57BBD8015BCA}
[2012/07/10 10:25:18 | 000,000,000 | ---D | C] -- C:\Program Files\DIPS64
[2012/07/10 08:52:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/07/10 08:52:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/07/10 08:52:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/07/10 08:44:27 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\Documents\CC Reg Backups
[2012/07/10 08:41:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012/07/10 08:41:39 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012/07/10 08:37:59 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Roaming\Malwarebytes
[2012/07/10 08:35:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/10 08:35:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/10 08:35:06 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/10 08:35:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/10 08:12:06 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{C2FF3145-8E92-48C5-91DC-7AB134F9CE04}
[2012/07/09 11:57:09 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{09DBCA92-5A7B-40BE-9DE5-0084817972BF}
[2012/07/09 11:56:58 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{A66CF218-D6BF-4DF1-8ED5-A19970275BB5}
[2012/07/09 11:54:33 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{E52E2322-A992-4080-9A2B-0C03663096D4}
[2012/07/09 09:56:12 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{BA5D8A76-7393-4CA2-AF0E-3C5B2C7252ED}
[2012/07/09 08:57:23 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/07/06 10:42:19 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{50834F22-CE21-4DC9-8F44-1038F678A563}
[2012/07/06 10:41:57 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{3FA88EB0-B16A-4CF5-97FE-434D50BBBF08}
[2012/07/05 08:15:52 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{7CDF4D0B-567F-42A7-876B-E90D8156C147}
[2012/07/05 08:15:30 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{B2A6936A-81C6-4FBA-8EEA-6AE826746F85}
[2012/07/03 09:00:45 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{055110B1-778B-4F50-90F4-27A1D5A355A5}
[2012/07/03 09:00:24 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{89FD1525-D754-42EF-BD2F-962F59BFCCB1}
[2012/07/02 07:56:52 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{86F4E93E-C4E8-4C05-B99F-8554F294CE07}
[2012/07/02 07:56:30 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{1CD2C962-BD1C-44AE-A9A3-5BE9CDF347A4}
[2012/06/29 09:19:19 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{90E2F70B-F4F5-4721-BA96-8F09E19258F4}
[2012/06/29 09:18:57 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{AED0B808-0483-4F1E-A0EF-CEBEA243418B}
[2012/06/28 13:01:18 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{D9CFB5D7-9DBA-4568-BB24-734AAAAC29F1}
[2012/06/28 13:00:56 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{4322312C-A6CB-45D7-AF68-01413C85CCB5}
[2012/06/28 12:25:45 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{A3E1CC50-1C87-4481-8883-52794E7387AB}
[2012/06/28 11:43:29 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{653A6100-C324-42F7-A997-663FB95BCF0E}
[2012/06/28 11:43:07 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{A6B8DC2B-4573-4E5B-BA8E-34C1EE8F5037}
[2012/06/28 11:13:57 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{31F72151-E589-4BEB-9F71-09C983DADF81}
[2012/06/28 09:59:23 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{4AAC560E-0DA0-4347-9CCC-9C26BA563523}
[2012/06/28 08:49:47 | 000,000,000 | ---D | C] -- C:\Users\Ryan2011\AppData\Local\{32FB2E10-1ED9-4FED-9F41-5B25D795C590}
========== Files - Modified Within 30 Days ==========
[2012/07/27 14:38:01 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000UA.job
[2012/07/27 14:36:15 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Ryan2011\Desktop\OTL.exe
[2012/07/27 13:47:25 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/27 11:44:07 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/27 11:44:07 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/27 07:49:57 | 000,733,884 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/27 07:49:57 | 000,629,194 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/27 07:49:57 | 000,108,410 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/27 07:45:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/27 07:45:32 | 3193,688,064 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/20 16:27:00 | 000,002,217 | ---- | M] () -- C:\Users\Public\Desktop\Amazon Cloud Player.lnk
[2012/07/20 15:50:16 | 000,000,985 | ---- | M] () -- C:\Users\Public\Desktop\Mp3tag.lnk
[2012/07/17 09:06:17 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/07/17 09:04:28 | 000,001,959 | ---- | M] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/07/17 09:00:03 | 000,001,983 | ---- | M] () -- C:\Users\Ryan2011\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2012/07/16 13:14:29 | 000,001,278 | ---- | M] () -- C:\Users\Ryan2011\Desktop\Blank Invoice.lnk
[2012/07/13 14:14:41 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2012/07/12 10:34:08 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/07/12 10:33:59 | 000,747,542 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/12 09:40:02 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/12 04:39:44 | 000,002,423 | ---- | M] () -- C:\Users\Ryan2011\Desktop\Google Chrome.lnk
[2012/07/11 23:38:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1237553287-1429794397-2156527687-1000Core.job
[2012/07/11 08:43:48 | 000,285,640 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/10 10:07:47 | 000,443,048 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts.20120712-102059.backup
[2012/07/10 08:52:12 | 000,001,264 | ---- | M] () -- C:\Users\Ryan2011\Desktop\Spybot - Search & Destroy.lnk
[2012/07/10 08:41:40 | 000,000,784 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/09 16:58:00 | 002,988,155 | ---- | M] () -- C:\Users\Ryan2011\Documents\facebook-cheat-sheet-sizes-and-dimensions1.pdf
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
========== Files Created - No Company Name ==========
[2012/07/20 16:27:00 | 000,002,217 | ---- | C] () -- C:\Users\Public\Desktop\Amazon Cloud Player.lnk
[2012/07/20 15:50:16 | 000,000,985 | ---- | C] () -- C:\Users\Public\Desktop\Mp3tag.lnk
[2012/07/17 09:06:17 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2012/07/17 09:04:28 | 000,001,959 | ---- | C] () -- C:\Users\Public\Desktop\Samsung Kies.lnk
[2012/07/17 09:00:03 | 000,001,983 | ---- | C] () -- C:\Users\Ryan2011\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2012/07/16 13:14:29 | 000,001,278 | ---- | C] () -- C:\Users\Ryan2011\Desktop\Blank Invoice.lnk
[2012/07/12 10:34:01 | 000,001,877 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/07/12 09:40:02 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/10 08:52:12 | 000,001,264 | ---- | C] () -- C:\Users\Ryan2011\Desktop\Spybot - Search & Destroy.lnk
[2012/07/10 08:41:40 | 000,000,784 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/09 16:58:00 | 002,988,155 | ---- | C] () -- C:\Users\Ryan2011\Documents\facebook-cheat-sheet-sizes-and-dimensions1.pdf
[2012/06/26 16:02:40 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/06/26 16:02:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012/06/26 16:02:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012/06/26 16:02:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012/06/26 16:02:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012/06/14 11:24:04 | 000,059,755 | ---- | C] () -- C:\Users\Ryan2011\Grim Dawn keys.pdf
[2012/04/06 16:21:07 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2012/04/03 10:01:10 | 000,205,999 | ---- | C] () -- C:\Windows\hpoins46.dat
[2012/04/03 10:01:10 | 000,000,601 | ---- | C] () -- C:\Windows\hpomdl46.dat
[2011/11/22 10:08:38 | 000,059,067 | ---- | C] () -- C:\Users\Ryan2011\Binaries_and_Source-1013-1-0.zip
[2011/02/14 12:22:06 | 000,000,601 | ---- | C] () -- C:\Windows\hpomdl46.dat.temp
[2011/02/03 15:09:43 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/03 08:52:46 | 000,000,094 | ---- | C] () -- C:\Windows\dellstat.ini
[2011/02/02 11:31:34 | 000,462,848 | ---- | C] () -- C:\Windows\SysWow64\IIFILE.EXE
[2011/02/02 11:31:34 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\RelMon.DLL
[2011/01/31 17:37:38 | 000,747,542 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/31 17:25:09 | 000,000,376 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/09/10 06:29:37 | 000,134,592 | ---- | C] () -- C:\Windows\SysWow64\igfcg500.bin
[2010/08/25 20:34:30 | 000,982,240 | ---- | C] () -- C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | ---- | C] () -- C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | ---- | C] () -- C:\Windows\SysWow64\igfcg500m.bin
========== LOP Check ==========
[2012/07/20 16:27:20 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Amazon
[2012/07/27 09:01:53 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Dropbox
[2012/07/24 16:51:57 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Mp3tag
[2011/02/01 11:43:32 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\PureEdge
[2012/07/17 09:05:06 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Samsung
[2011/02/03 15:09:43 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Thunderbird
[2011/06/07 15:08:35 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Unity
[2011/02/21 10:40:16 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Windows Live Writer
[2011/04/26 10:18:56 | 000,000,000 | ---D | M] -- C:\Users\Ryan2011\AppData\Roaming\Wizards of the Coast
[2012/04/30 07:44:57 | 000,032,624 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >