Over the last couple of days, my computer has been behaving oddly. I do not remember installing or downloading anything specifically dubious within the specified timeframe, but my understanding is that my computer is infected with a worm or malware of some sort. Complete scans with AVG, Avast!, CCleaner and Malwarebytes have reported no specific issues, or anyway, none that could be fixed.
Among the effects noticed, my Internet connection is much slower than usual (unusual lag on YouTube, long time to connect to webpages, unexplainable high ping in video games) and anything related to Google will not load in any browswer (making it impossible to use the search feature on some websites and using captcha). AVG reports unusual amounts of memory (300MB - 400 MB) being spent in Firefox every now and then. It has also become a gamble to boot up in safe mode for it'll only work a few times out of many. I could also not run any version OTL in normal mode since an error message concerning a faulty driver/peripheral kept popping up; I had to run OTL.exe in safe mode.
A detail worth noting, I suppose, is that I have only used Mozilla Firefox as a browser untill the problem showed up. Then I started trying to use Chrome and Explorer, to see if anything would be different. Turns out everything's affected.
Avast! keeps reporting blocked connection attempts to URLS and an IP adress I have never seen before, by svchost.exe. The last pop-up gave the following information:
URL: http://colexity777.com/x/
Process: C:\Windows\system32\svchost.exe
Infection: URL:Mal
And here is the OTL log (also attached to post for convenience):
OTL logfile created on: 2012-08-11 12:41:47 - Run 2
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Ian\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19272)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
3,00 Gb Total Physical Memory | 2,58 Gb Available Physical Memory | 85,92% Memory free
6,19 Gb Paging File | 5,98 Gb Available in Paging File | 96,49% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 134,36 Gb Total Space | 29,79 Gb Free Space | 22,17% Space Free | Partition Type: NTFS
Drive E: | 14,65 Gb Total Space | 6,41 Gb Free Space | 43,77% Space Free | Partition Type: NTFS
Drive F: | 7,59 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: PC-DE-IAN | User Name: Ian | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012-08-09 17:17:50 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Ian\Downloads\OTL.exe
PRC - [2009-04-11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2002-04-17 10:49:16 | 000,077,824 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
========== Modules (No Company Name) ==========
MOD - [2002-04-17 10:49:22 | 000,024,576 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnfps.dll
MOD - [2002-04-17 10:49:16 | 000,077,824 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
========== Win32 Services (SafeList) ==========
SRV - [2012-07-17 17:00:02 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012-07-03 12:21:29 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Stopped] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012-07-03 02:13:51 | 000,529,232 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012-06-27 12:29:22 | 001,385,896 | ---- | M] (LogMeIn Inc.) [Auto | Stopped] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012-06-25 14:27:54 | 000,696,320 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Kilgray\memoQ60\AUClient.exe -- (Kilgray: memoQ update permissions manager. 9841208.)
SRV - [2012-06-05 15:17:44 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2011-11-02 14:50:06 | 000,696,320 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Kilgray\memoQ40\AUClient.exe -- (Kilgray: memoQ update permissions manager. 979430.)
SRV - [2011-10-12 06:25:22 | 004,433,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2011-08-02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Stopped] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2011-06-05 16:44:52 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010-09-30 11:31:14 | 004,195,960 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2008-12-18 14:05:28 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Stopped] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008-12-15 00:13:46 | 000,241,746 | ---- | M] (IDT, Inc.) [Auto | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\stacsv.exe -- (STacSV)
SRV - [2008-12-15 00:13:30 | 000,081,920 | ---- | M] (Andrea Electronics Corporation) [Auto | Stopped] -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_ae0b52e0\AEstSrv.exe -- (AESTFilters)
SRV - [2008-05-07 18:41:14 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Stopped] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008-01-20 22:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007-01-04 17:38:08 | 000,024,652 | ---- | M] (Viewpoint Corporation) [Auto | Stopped] -- C:\Program Files\Viewpoint\Common\ViewpointService.exe -- (Viewpoint Manager Service)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\PROGRA~1\DELLSU~1\HWDiag\bin\PCD5SRVC.pkms -- (PCD5SRVC{3F6A8B78-EC003E00-05040104})
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Ian\AppData\Local\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - [2012-07-03 12:21:54 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012-07-03 12:21:53 | 000,721,000 | ---- | M] (AVAST Software) [File_System | System | Stopped] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012-07-03 12:21:53 | 000,353,688 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012-07-03 12:21:53 | 000,057,656 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012-07-03 12:21:53 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012-07-03 12:21:53 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2012-05-14 22:35:52 | 000,079,104 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rzudd.sys -- (rzudd)
DRV - [2012-04-10 14:51:16 | 000,021,744 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\Dell Support Center\pcdsrvc.pkms -- (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2011-10-07 06:23:48 | 000,230,608 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2011-10-04 06:21:16 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2011-09-13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\avgrkx86.sys -- (Avgrkx86)
DRV - [2011-08-08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Stopped] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2011-07-11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2011-07-11 01:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2011-07-11 01:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AVGIDSEH.sys -- (AVGIDSEH)
DRV - [2011-07-11 01:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010-06-17 18:18:24 | 000,193,640 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010-04-12 04:44:34 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2010-01-16 19:01:26 | 000,691,696 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009-12-01 16:49:54 | 000,034,384 | ---- | M] (Screaming Bee LLC) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ScreamingBAudio.sys -- (SCREAMINGBDRIVER)
DRV - [2009-05-08 21:14:21 | 000,030,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2009-04-11 00:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009-03-18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009-01-21 02:57:22 | 004,172,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2009-01-21 02:57:22 | 004,172,288 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2008-12-22 06:32:18 | 000,018,424 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\bcm42rly.sys -- (BCM42RLY)
DRV - [2008-12-15 00:13:54 | 000,393,216 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2008-09-04 01:29:08 | 000,170,032 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008-01-20 22:32:51 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2007-05-30 21:32:34 | 000,099,648 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\V0420Vid.sys -- (V0420VID)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {4ABC00A3-EB23-4605-87D1-4B6DD72C06F1}
IE - HKLM\..\SearchScopes\{4ABC00A3-EB23-4605-87D1-4B6DD72C06F1}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/23
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/USCON/23
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {4ABC00A3-EB23-4605-87D1-4B6DD72C06F1}
IE - HKCU\..\SearchScopes\{4ABC00A3-EB23-4605-87D1-4B6DD72C06F1}: "URL" = http://search.live.c...rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Ant.com"
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.radio-can...grands-titres/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: [email protected]:2.3.0
FF - prefs.js..extensions.enabledItems: [email protected]:3.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.11
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {d5bc46d8-67c7-11dc-8c1d-0097498c2b7a}:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Media Player\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AutocompletePro\[email protected] [2010-08-02 14:46:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012-08-08 10:41:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2012-08-09 00:10:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-17 17:00:03 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-06-08 21:14:12 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-07-17 17:00:03 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012-06-08 21:14:12 | 000,000,000 | ---D | M]
[2009-06-20 03:42:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ian\AppData\Roaming\mozilla\Extensions
[2009-06-20 03:42:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ian\AppData\Roaming\mozilla\Extensions\[email protected]
[2012-08-04 03:04:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions
[2012-06-10 14:34:37 | 000,000,000 | ---D | M] (Module d'Antidote) -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions\[email protected]
[2012-07-18 02:48:45 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions\[email protected]
[2011-10-09 17:22:39 | 000,000,000 | ---D | M] (Dictionnaire français «Classique») -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions\[email protected]
[2012-03-25 17:23:59 | 000,000,000 | ---D | M] (CodecC) -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions\[email protected]
[2012-07-15 13:00:48 | 000,000,000 | ---D | M] (Youtube MP3 Podcaster) -- C:\Users\Ian\AppData\Roaming\mozilla\Firefox\Profiles\mvz0ttcf.default\extensions\[email protected](113).com
[2012-08-07 10:32:48 | 000,001,088 | ---- | M] () -- C:\Users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\mvz0ttcf.default\searchplugins\dictionarycom.xml
[2010-08-05 18:08:43 | 000,001,196 | ---- | M] () -- C:\Users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\mvz0ttcf.default\searchplugins\winamp-search.xml
[2012-05-06 23:35:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011-11-07 21:22:33 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-08-08 10:41:47 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2012-07-29 21:12:34 | 000,197,500 | ---- | M] () (No name found) -- C:\USERS\IAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MVZ0TTCF.DEFAULT\EXTENSIONS\[email protected]
[2008-01-20 22:33:22 | 000,004,819 | ---- | M] () (No name found) -- C:\USERS\IAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MVZ0TTCF.DEFAULT\EXTENSIONS\[email protected]
[2011-10-21 20:56:54 | 000,143,480 | ---- | M] () (No name found) -- C:\USERS\IAN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MVZ0TTCF.DEFAULT\EXTENSIONS\[email protected]
[2009-09-02 03:00:28 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012-07-17 17:00:03 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-04-13 19:06:43 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2007-04-16 13:07:12 | 000,180,293 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npViewpoint.dll
[2010-07-12 12:33:56 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012-06-19 12:47:16 | 000,001,525 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-06-19 12:47:16 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-06-19 12:47:16 | 000,000,935 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012-06-19 12:47:16 | 000,001,166 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012-06-19 12:47:16 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012-06-19 12:47:16 | 000,001,121 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\21.0.1180.75\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: MetaStream 3 Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npViewpoint.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: DNA Plug-in (Enabled) = C:\Program Files\DNA\plugins\npbtdna.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Microsoft Office Live Plug-in for Firefox (Enabled) = C:\Program Files\Microsoft\Office Live\npOLW.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: CodecC = C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekdjfcdinekpfcedakhpngcnaamhiihn\1.0_0\
CHR - Extension: avast! WebRep = C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
O1 HOSTS File: ([2006-09-18 17:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AC-Pro) - {0FB6A909-6086-458F-BD92-1F8EE10042A0} - C:\Program Files\AutocompletePro\AutocompletePro.dll (SimplyGen)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [agentantidote.exe] C:\Program Files\Druide\Antidote 7\Programmes32\agentantidote.exe (Druide informatique inc.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN File not found
O4 - HKLM..\Run: [C:\Windows\system32\V0420Ext.ax] C:\Windows\System32\V0420Ext.ax (Creative Technology Ltd.)
O4 - HKLM..\Run: [ContentTransferWMDetector.exe] C:\Program Files\Sony\Content Transfer\ContentTransferWMDetector.exe (Sony Corporation)
O4 - HKLM..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter File not found
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [Easy Dock] File not found
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [V0420Mon.exe] C:\Windows\V0420Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h File not found
O4 - HKCU..\Run: [CreativeTaskScheduler] C:\Program Files\Creative\Shared Files\CTSched.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...ri_4.4.21.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{27CE149E-9C35-4DA0-9A42-B1BF15695566}: DhcpNameServer = 132.210.13.2 132.210.10.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{64165795-5090-40BB-B377-B60A44F01738}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ian\Dossiers divers\Images\Lulz\Wallpapers\tumblr_lxz8bhC8wU1r5x74wo1_1280.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ian\Dossiers divers\Images\Lulz\Wallpapers\tumblr_lxz8bhC8wU1r5x74wo1_1280.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006-09-18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{7e1baacd-23bf-11df-9c8b-0023ae24a631}\Shell - "" = AutoRun
O33 - MountPoints2\{7e1baacd-23bf-11df-9c8b-0023ae24a631}\Shell\AutoRun\command - "" = D:\Startup.exe
O33 - MountPoints2\{d81be46f-6590-11de-96c9-0023ae24a631}\Shell\AutoRun\command - "" = D:\rcaeasyrip_setup.exe
O33 - MountPoints2\{d81be46f-6590-11de-96c9-0023ae24a631}\Shell\install\command - "" = D:\rcaeasyrip_setup.exe
O33 - MountPoints2\{d81be46f-6590-11de-96c9-0023ae24a631}\Shell\usermanualEnglish\command - "" = D:\rcaeasyrip_setup.exe /pdf_English
O33 - MountPoints2\{d81be46f-6590-11de-96c9-0023ae24a631}\Shell\usermanualFrench\command - "" = D:\rcaeasyrip_setup.exe /pdf_French
O33 - MountPoints2\{d81be46f-6590-11de-96c9-0023ae24a631}\Shell\usermanualSpanish\command - "" = D:\rcaeasyrip_setup.exe /pdf_Spanish
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\Setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012-08-11 11:44:14 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{39311C15-F9E0-48D9-A551-64791F50C40A}
[2012-08-11 11:44:00 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{8FABB927-C644-41ED-8866-CABCF0E1AB34}
[2012-08-10 22:12:59 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{A93C7367-5392-4014-82C2-2400EC33808A}
[2012-08-10 22:12:24 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{281B05F4-8739-46A0-9F03-FAD3AAD4154E}
[2012-08-10 18:23:18 | 000,000,000 | ---D | C] -- C:\Users\Ian\Desktop\Proof of ID
[2012-08-10 10:11:52 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{C109840B-A912-40C4-9715-7A7D63CCA7C1}
[2012-08-10 10:11:09 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{25B0B5A2-5E07-421C-8C05-D224413936FC}
[2012-08-09 19:56:01 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012-08-09 17:22:52 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Visual Basic 2005 Power Packs
[2012-08-09 17:22:52 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\Microsoft Help
[2012-08-09 17:22:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 8
[2012-08-09 17:22:51 | 000,000,000 | ---D | C] -- C:\Users\Ian\Documents\Microsoft Visual Basic 2005 Power Packs
[2012-08-09 17:22:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Basic 2005 Power Packs
[2012-08-09 17:22:51 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2012-08-09 17:22:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012-08-09 11:03:56 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{969014D8-835E-460F-B80A-F18E3A74B9A1}
[2012-08-09 11:03:01 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{C6561128-8339-4786-85A8-3034F82F7614}
[2012-08-09 01:33:28 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012-08-09 00:12:00 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Roaming\AVG2012
[2012-08-09 00:10:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012
[2012-08-09 00:10:27 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012-08-09 00:10:27 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\AVG
[2012-08-09 00:09:57 | 000,000,000 | ---D | C] -- C:\Program Files\AVG
[2012-08-09 00:01:49 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012-08-09 00:01:22 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012-08-08 23:02:10 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{310CF479-4B79-478E-8018-C2C6A295A2CA}
[2012-08-08 23:01:53 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{3EC1A408-91C7-45B9-9E6A-6FD272A92E35}
[2012-08-08 17:26:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012-08-08 17:23:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2012-08-08 17:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2012-08-08 10:39:31 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{4DAFA293-D81A-43D2-BE5D-CE33C4CE4D79}
[2012-08-08 10:38:39 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{67EBB44F-4180-4717-B76B-1632D9108DB4}
[2012-08-08 10:18:11 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{8910C032-FEB7-4559-92A7-3EB37D20297E}
[2012-08-08 03:33:01 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{15079CA2-1E74-4489-B5D9-804417B63FF2}
[2012-08-07 15:21:52 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{6B783FC2-6C22-4D05-ADD4-D8953E49E323}
[2012-08-07 15:21:17 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{B138D50D-B9ED-4595-8D92-C7E62E909F1D}
[2012-08-07 03:21:19 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{DDCA2ED2-9B99-473F-94C2-6E09470FE7AE}
[2012-08-06 10:08:19 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{9CED1E3F-2676-49BC-8821-E7DDD9218C82}
[2012-08-06 10:07:43 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{91A199B3-FC75-41A1-B74B-989BEC5F4FE5}
[2012-08-04 00:29:35 | 000,000,000 | ---D | C] -- C:\Users\Ian\Desktop\asssssssssjhlkl
[2012-08-03 10:08:57 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{6AB6915C-EE63-44A3-82E1-188661116BDF}
[2012-08-03 10:08:03 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{124F82F2-E291-43CE-BCC7-A1B6120CE7D6}
[2012-08-02 10:27:26 | 000,000,000 | ---D | C] -- C:\Users\Ian\Desktop\Stormblade
[2012-08-02 10:07:18 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{C004858D-903D-4F32-B973-F99297134552}
[2012-08-02 10:06:18 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{3BCD5921-A9FA-4DC0-8C44-5361AC78315D}
[2012-08-02 03:23:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Audio Pack
[2012-08-02 03:23:06 | 000,479,232 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudioVisu.dll
[2012-08-02 03:23:06 | 000,458,752 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudPlayer.dll
[2012-08-02 03:23:06 | 000,454,656 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudioRecord.dll
[2012-08-02 03:23:06 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\WMAFile.dll
[2012-08-02 03:23:05 | 002,084,864 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudDesign.dll
[2012-08-02 03:23:05 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudFile.dll
[2012-08-02 03:23:05 | 001,212,416 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudioInfos.dll
[2012-08-02 03:23:05 | 000,417,792 | ---- | C] (NCT Company Ltd.) -- C:\Windows\System32\AudDisplay.dll
[2012-08-02 03:23:03 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Roaming\FreeAudioPack
[2012-08-02 03:23:03 | 000,000,000 | ---D | C] -- C:\Program Files\Free mp3 Wma Converter
[2012-08-01 23:26:07 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{7A0644A3-BB6F-4518-839A-F5CC61BAAA53}
[2012-08-01 10:10:03 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{8D1F5F3E-2238-41E7-A52C-3A8F6BB71A37}
[2012-08-01 10:09:07 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{13A6CEA9-83C0-41E2-8710-2BC077340741}
[2012-07-31 22:08:53 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{B6298023-C2F4-43CD-BCC8-313CAEA296FC}
[2012-07-31 22:07:55 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{88A4A29B-77E4-4D26-9AA6-633958CF6601}
[2012-07-31 10:07:16 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{17DDD854-01E5-4726-ADEB-8AADFC83C53B}
[2012-07-31 10:05:58 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{CD9B98D5-5823-470B-A8EF-8D08621E6690}
[2012-07-30 10:09:12 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{125BE422-3352-498A-B44B-D2FD6AFED8CC}
[2012-07-30 10:08:16 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{A6DFAC41-05B9-4687-A51E-270FAA34C45A}
[2012-07-30 02:58:43 | 000,086,683 | ---- | C] (Open Source Software community project) -- C:\Windows\System32\pthreadGC2.dll
[2012-07-30 02:58:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AoA Audio Extractor Platinum
[2012-07-30 02:58:40 | 000,000,000 | ---D | C] -- C:\Program Files\AoA Audio Extractor Platinum
[2012-07-29 12:07:40 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{346276E0-F986-49E0-94F6-952E0C6FB476}
[2012-07-27 22:10:31 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{DD7A3C1F-B979-4F42-9C66-754A0D441152}
[2012-07-27 22:09:03 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{AD9938F1-4CCD-4AF0-9907-C3FFA6109942}
[2012-07-27 10:07:42 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{13671CA5-00BC-4F74-AD60-71D27BC904B7}
[2012-07-27 10:06:05 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{EFEEF196-F553-408E-8353-DA81CC146AF2}
[2012-07-26 10:08:29 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{1D4F0F82-A6B5-4FCF-B788-433D1ED34450}
[2012-07-26 10:07:48 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{69DF9E69-B8F1-47EA-97D2-7A37FB406080}
[2012-07-25 11:56:50 | 000,000,000 | ---D | C] -- C:\Users\Ian\Desktop\FMC
[2012-07-25 10:09:58 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{D85A8D60-2E60-4525-A5F8-F547BC470800}
[2012-07-25 10:09:24 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{E7991644-9EE0-4A15-9DFB-FEA211C69E6F}
[2012-07-24 22:08:57 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{C8B23C1B-9B7D-4F91-90A3-E6CE0850FBE6}
[2012-07-24 22:08:09 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{8ED8823F-E521-4BD6-913B-1FFB59E9190F}
[2012-07-24 10:07:34 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{084B0E04-8C94-47F9-869E-C0E4C7872F82}
[2012-07-24 10:06:25 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{A14DBB6D-3266-497D-B46C-A6B0284C7D47}
[2012-07-23 10:07:06 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{374ACB4B-6AAF-40F1-A07E-4B5BBA2B9FCB}
[2012-07-23 10:05:54 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{D41E6B7D-2E62-4848-9090-30E37CEA334D}
[2012-07-20 10:46:17 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{41CB8D95-1612-4212-BB41-30B7F6068EA3}
[2012-07-20 10:45:35 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{D4E9D350-BFEB-424C-BA2B-AA4659B771D8}
[2012-07-19 22:44:44 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{A91FDD68-C331-4267-95F3-09BE9C099E92}
[2012-07-19 22:43:38 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{681643AD-1472-46F7-8CBB-B7F1F75976CF}
[2012-07-19 10:07:15 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{FCF73A82-8E35-45C6-AEC4-83F3EBC79014}
[2012-07-19 10:06:28 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{A3615BA3-5ACC-4752-B4DB-8D52D225C436}
[2012-07-18 21:31:48 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\LogMeIn Hamachi
[2012-07-18 21:30:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012-07-18 21:30:52 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2012-07-18 10:06:27 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{CDAD3843-C55D-405D-BD5B-F47152CD2BD7}
[2012-07-18 10:05:52 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{BEB4B3AD-2A6E-4EE5-95F1-43EE0139ECE4}
[2012-07-17 10:06:49 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{80E43C60-2493-483D-B6BE-2379F7C3307E}
[2012-07-17 10:05:16 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{485A5D72-CA5E-40D5-8953-967A349725CF}
[2012-07-16 13:58:45 | 000,000,000 | ---D | C] -- C:\Users\Ian\Desktop\QC FR vs FR FR
[2012-07-16 10:12:24 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{0064500B-0976-4755-A087-809C28CBDD5F}
[2012-07-16 10:11:47 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{35D5335E-90D7-4556-A69C-59BA89D44F9A}
[2012-07-13 10:25:26 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{C9FB85DB-A5F1-49E3-8C99-293BEC165762}
[2012-07-13 10:24:53 | 000,000,000 | ---D | C] -- C:\Users\Ian\AppData\Local\{01DD1A9E-2181-4062-8F6F-600BF2C5EE53}
[2006-06-26 01:33:46 | 000,163,840 | ---- | C] (アリスソフト) -- C:\Users\Ian\AppData\Local\Tempals_inst.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-08-11 12:46:56 | 000,007,512 | ---- | M] () -- C:\Users\Ian\AppData\Local\d3d9caps.dat
[2012-08-11 12:40:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012-08-11 12:39:39 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012-08-11 12:39:39 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012-08-11 12:26:08 | 000,729,886 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2012-08-11 12:26:08 | 000,641,070 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012-08-11 12:26:08 | 000,149,692 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2012-08-11 12:26:08 | 000,122,954 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012-08-11 12:22:02 | 000,001,050 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012-08-11 12:22:02 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012-08-11 11:46:26 | 103,576,853 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2012-08-11 11:42:44 | 000,001,046 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012-08-11 03:22:12 | 000,222,720 | ---- | M] () -- C:\Users\Ian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-08-10 18:30:26 | 001,697,858 | ---- | M] () -- C:\Users\Ian\Desktop\ID Check_Fafard.zip
[2012-08-09 00:10:56 | 000,000,818 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012-08-08 17:26:57 | 000,001,933 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-08-08 17:26:57 | 000,001,917 | ---- | M] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-08-08 17:23:27 | 000,000,766 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-08-08 10:42:22 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012-08-08 10:29:09 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-08-06 15:38:30 | 000,108,299 | ---- | M] () -- C:\Users\Ian\Desktop\tumblr_m8c8cgqaOU1qg7mi3o2_1280.png
[2012-08-06 15:38:22 | 000,110,325 | ---- | M] () -- C:\Users\Ian\Desktop\tumblr_m8c8cgqaOU1qg7mi3o1_1280.png
[2012-08-06 15:28:03 | 000,539,289 | ---- | M] () -- C:\Users\Ian\Desktop\Katenborough.wma
[2012-08-06 15:24:49 | 000,054,369 | ---- | M] () -- C:\Users\Ian\Desktop\gdsfgdf.wma
[2012-08-06 00:57:41 | 002,424,975 | ---- | M] () -- C:\Users\Ian\Desktop\IMG_0715.JPG
[2012-08-05 20:44:11 | 001,294,112 | ---- | M] () -- C:\Users\Ian\Desktop\Sequence 0.mp3
[2012-08-05 01:24:45 | 000,063,603 | ---- | M] () -- C:\Users\Ian\Desktop\il_570xN.338299320.jpg
[2012-08-05 01:24:36 | 000,071,685 | ---- | M] () -- C:\Users\Ian\Desktop\il_570xN.331527045.jpg
[2012-08-05 01:24:25 | 000,044,159 | ---- | M] () -- C:\Users\Ian\Desktop\il_570xN.331489489.jpg
[2012-08-05 01:24:08 | 000,059,008 | ---- | M] () -- C:\Users\Ian\Desktop\il_570xN.362726639_934s.jpg
[2012-08-05 01:23:59 | 000,100,743 | ---- | M] () -- C:\Users\Ian\Desktop\il_570xN.362724681_2231.jpg
[2012-08-04 03:37:21 | 000,221,732 | ---- | M] () -- C:\Users\Ian\Desktop\Ray_Lederer-TESV-Spriggan.jpg
[2012-08-03 02:41:32 | 001,484,596 | ---- | M] () -- C:\Users\Ian\Desktop\gggbbbbb.wav
[2012-08-03 02:34:24 | 005,497,004 | ---- | M] () -- C:\Users\Ian\Desktop\gggg.wav
[2012-08-03 02:07:11 | 000,009,899 | ---- | M] () -- C:\Users\Ian\Desktop\credits.png
[2012-08-02 03:23:12 | 000,001,093 | ---- | M] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy Audio Cutter.lnk
[2012-08-02 03:23:12 | 000,001,077 | ---- | M] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Free CD Ripper.lnk
[2012-08-02 03:23:12 | 000,001,075 | ---- | M] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Mp3 Wma Converter.lnk
[2012-08-02 03:23:12 | 000,001,069 | ---- | M] () -- C:\Users\Ian\Desktop\Easy Audio Cutter.lnk
[2012-08-02 03:23:12 | 000,001,051 | ---- | M] () -- C:\Users\Ian\Desktop\Free Mp3 Wma Converter.lnk
[2012-07-30 12:02:38 | 000,000,472 | ---- | M] () -- C:\Users\Ian\Desktop\Ant Videos.lnk
[2012-07-30 02:58:43 | 000,000,914 | ---- | M] () -- C:\Users\Public\Desktop\AoA Audio Extractor Platinum.lnk
[2012-07-29 12:05:37 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012-07-16 03:17:37 | 000,001,802 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012-07-16 03:12:26 | 001,619,520 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-08-11 11:46:26 | 103,576,853 | ---- | C] () -- C:\Windows\System32\drivers\AVG\incavi.avm
[2012-08-10 18:30:26 | 001,697,858 | ---- | C] () -- C:\Users\Ian\Desktop\ID Check_Fafard.zip
[2012-08-09 00:10:56 | 000,000,818 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk
[2012-08-08 17:26:57 | 000,001,933 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012-08-08 17:26:57 | 000,001,917 | ---- | C] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012-08-08 17:23:27 | 000,000,766 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012-08-08 10:29:09 | 000,000,868 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012-08-06 15:38:30 | 000,108,299 | ---- | C] () -- C:\Users\Ian\Desktop\tumblr_m8c8cgqaOU1qg7mi3o2_1280.png
[2012-08-06 15:38:20 | 000,110,325 | ---- | C] () -- C:\Users\Ian\Desktop\tumblr_m8c8cgqaOU1qg7mi3o1_1280.png
[2012-08-06 15:28:03 | 000,539,289 | ---- | C] () -- C:\Users\Ian\Desktop\Katenborough.wma
[2012-08-06 15:24:48 | 000,054,369 | ---- | C] () -- C:\Users\Ian\Desktop\gdsfgdf.wma
[2012-08-06 00:57:40 | 002,424,975 | ---- | C] () -- C:\Users\Ian\Desktop\IMG_0715.JPG
[2012-08-05 20:44:05 | 001,294,112 | ---- | C] () -- C:\Users\Ian\Desktop\Sequence 0.mp3
[2012-08-05 01:24:44 | 000,063,603 | ---- | C] () -- C:\Users\Ian\Desktop\il_570xN.338299320.jpg
[2012-08-05 01:24:35 | 000,071,685 | ---- | C] () -- C:\Users\Ian\Desktop\il_570xN.331527045.jpg
[2012-08-05 01:24:24 | 000,044,159 | ---- | C] () -- C:\Users\Ian\Desktop\il_570xN.331489489.jpg
[2012-08-05 01:24:07 | 000,059,008 | ---- | C] () -- C:\Users\Ian\Desktop\il_570xN.362726639_934s.jpg
[2012-08-05 01:23:57 | 000,100,743 | ---- | C] () -- C:\Users\Ian\Desktop\il_570xN.362724681_2231.jpg
[2012-08-04 03:37:19 | 000,221,732 | ---- | C] () -- C:\Users\Ian\Desktop\Ray_Lederer-TESV-Spriggan.jpg
[2012-08-03 02:41:32 | 001,484,596 | ---- | C] () -- C:\Users\Ian\Desktop\gggbbbbb.wav
[2012-08-03 02:34:24 | 005,497,004 | ---- | C] () -- C:\Users\Ian\Desktop\gggg.wav
[2012-08-03 02:07:11 | 000,009,899 | ---- | C] () -- C:\Users\Ian\Desktop\credits.png
[2012-08-02 03:23:12 | 000,001,093 | ---- | C] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Easy Audio Cutter.lnk
[2012-08-02 03:23:12 | 000,001,077 | ---- | C] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Free CD Ripper.lnk
[2012-08-02 03:23:12 | 000,001,075 | ---- | C] () -- C:\Users\Ian\Application Data\Microsoft\Internet Explorer\Quick Launch\Free Mp3 Wma Converter.lnk
[2012-08-02 03:23:12 | 000,001,069 | ---- | C] () -- C:\Users\Ian\Desktop\Easy Audio Cutter.lnk
[2012-08-02 03:23:12 | 000,001,051 | ---- | C] () -- C:\Users\Ian\Desktop\Free Mp3 Wma Converter.lnk
[2012-08-02 03:23:06 | 000,116,296 | ---- | C] () -- C:\Windows\System32\NCTWMAProfiles.prx
[2012-08-02 03:23:04 | 000,484,352 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2012-07-30 12:02:38 | 000,000,472 | ---- | C] () -- C:\Users\Ian\Desktop\Ant Videos.lnk
[2012-07-30 02:58:43 | 000,000,914 | ---- | C] () -- C:\Users\Public\Desktop\AoA Audio Extractor Platinum.lnk
[2012-06-11 10:12:10 | 000,000,223 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012-03-05 14:45:56 | 000,000,148 | -H-- | C] () -- C:\Windows\System32\WN125047.bin
[2012-03-05 14:45:56 | 000,000,148 | -H-- | C] () -- C:\Windows\AC841540.bin
[2010-12-02 22:57:47 | 000,172,471 | ---- | C] () -- C:\Users\Ian\Picture 6.png
[2010-12-02 22:57:37 | 000,166,133 | ---- | C] () -- C:\Users\Ian\Picture 19.png
[2010-11-04 16:51:51 | 000,000,097 | ---- | C] () -- C:\Windows\Antidote7.ini
[2010-10-17 00:22:55 | 000,000,000 | ---- | C] () -- C:\Windows\setup32.INI
[2010-09-28 22:27:14 | 000,000,000 | ---- | C] () -- C:\Users\Ian\shaved head
[2010-09-12 12:06:46 | 000,031,369 | ---- | C] () -- C:\Windows\System32\xvid-uninstall.exe
[2010-08-06 17:52:09 | 000,000,712 | ---- | C] () -- C:\Users\Ian\AppData\Roaming\isomaster.ini
[2010-08-01 13:55:24 | 000,007,676 | ---- | C] () -- C:\Users\Ian\.recently-used.xbel
[2010-02-23 15:21:14 | 000,000,091 | ---- | C] () -- C:\Users\Ian\AppData\Local\fusioncache.dat
[2009-10-19 22:42:36 | 000,000,235 | ---- | C] () -- C:\Users\Ian\AppData\Roaming\devices.xml
[2009-10-19 22:42:36 | 000,000,012 | ---- | C] () -- C:\Users\Ian\AppData\Roaming\settings.xml
[2009-06-30 01:25:46 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2009-05-06 13:59:11 | 000,006,836 | ---- | C] () -- C:\Users\Ian\AppData\Local\d3d9caps.dat
[2009-05-03 00:49:42 | 000,000,290 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009-05-01 04:19:11 | 000,222,720 | ---- | C] () -- C:\Users\Ian\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2010-04-03 22:27:05 | 000,000,000 | -HSD | M] -- C:\Users\Ian\AppData\Roaming\.#
[2012-06-25 00:09:10 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\.minecraft
[2010-08-02 02:21:25 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\ACAMPREF
[2009-05-06 23:38:22 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\acccore
[2012-07-30 03:04:22 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Audacity
[2012-08-09 00:12:00 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\AVG2012
[2010-11-24 12:14:31 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\avidemux
[2011-07-23 00:35:17 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Beat Hazard
[2011-01-13 20:06:44 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Bioshock
[2012-06-10 13:42:59 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\BitTorrent
[2012-08-08 17:28:51 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\DAEMON Tools Lite
[2012-08-08 17:28:51 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\DAEMON Tools Pro
[2009-06-08 16:35:48 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Dossier de telechargement Share-to-Web
[2009-06-08 16:35:48 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Dossier de telechargement Share-to-Web
[2009-05-06 00:14:15 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Dossier de téléchargement Share-to-Web
[2009-05-06 00:14:15 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Dossier de téléchargement Share-to-Web
[2010-11-04 16:50:56 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Druide
[2012-08-02 03:23:21 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\FreeAudioPack
[2012-06-25 04:56:14 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\FreeFLVConverter
[2010-08-01 13:51:18 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\gtk-2.0
[2011-07-10 16:41:07 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\HandBrake
[2009-06-20 04:11:49 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\LimeWire
[2010-03-02 04:15:02 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Locktime
[2011-07-16 23:46:23 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\LolClient
[2012-05-26 17:40:25 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\LolClient2
[2010-08-02 02:14:42 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\MakeMusic
[2012-08-10 16:42:22 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\MemoQ
[2011-02-21 19:01:29 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Mount&Blade
[2011-07-04 19:57:14 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Mount&Blade Warband
[2011-07-03 01:43:18 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Mount&Blade With Fire and Sword
[2010-06-09 23:36:15 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\My Games
[2010-06-01 21:57:18 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\NCH Swift Sound
[2010-12-11 13:57:05 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\PCDr
[2010-08-05 18:15:12 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Plane9
[2012-07-15 22:08:33 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Rainmeter
[2009-07-13 04:40:41 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Recordpad
[2010-02-12 23:49:07 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Screaming Bee
[2010-08-05 18:29:39 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\SoundSpectrum
[2009-11-27 16:26:48 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\SPORE
[2012-02-20 14:00:02 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\SystemRequirementsLab
[2009-12-19 20:09:29 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\thriXXX
[2010-11-13 17:00:32 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Transcend
[2012-08-08 17:28:43 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\TS3Client
[2012-08-08 17:28:44 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\uTorrent
[2010-08-02 03:24:29 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\Winsome Technologies
[2010-02-17 19:28:01 | 000,000,000 | ---D | M] -- C:\Users\Ian\AppData\Roaming\XnView
[2012-07-29 12:05:37 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2012-08-11 12:39:29 | 000,032,494 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012-08-11 12:22:02 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 166 bytes -> C:\ProgramData\TEMP:8CE646EE
< End of report >
I hope you can help me restore my machine, and I thank you for your time!
Attached Files
Edited by IanF, 11 August 2012 - 11:32 AM.