-Internet browsers have a Babylon toolbar that cannot be uninstalled by traditional means
-cannot use any Google search engines
-at start-up computer prompts for a system recovery and will scan and scan and never get anywhere. You cancel and it restarts and then you may log in.
Any help will be greatly appreciated!
OTL logfile created on: 8/16/2012 12:24:48 PM - Run 1
OTL by OldTimer - Version 3.2.57.0 Folder = E:\Virus Removal
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.96 Gb Total Physical Memory | 2.95 Gb Available Physical Memory | 74.50% Memory free
7.92 Gb Paging File | 6.73 Gb Available in Paging File | 84.95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 451.07 Gb Total Space | 328.64 Gb Free Space | 72.86% Space Free | Partition Type: NTFS
Drive D: | 407.92 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive E: | 7.51 Gb Total Space | 1.66 Gb Free Space | 22.07% Space Free | Partition Type: NTFS
Computer Name: AMANDA-PC | User Name: Amanda | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/14 15:53:56 | 000,596,992 | ---- | M] (OldTimer Tools) -- E:\Virus Removal\OTL.exe
PRC - [2012/07/14 00:11:46 | 000,186,832 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.21.115\GoogleCrashHandler.exe
PRC - [2012/05/22 15:59:29 | 000,281,088 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Microsoft\36C9\ADB.exe
PRC - [2012/04/11 09:30:54 | 000,186,368 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe
PRC - [2012/04/02 12:13:45 | 000,167,936 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\9ED00\ABC36.exe
PRC - [2012/02/01 11:20:35 | 000,100,912 | ---- | M] (Microsoft Corporation) -- C:\ProgramData\ctfdevice.exe
PRC - [2010/03/04 13:28:08 | 000,658,656 | ---- | M] (SoftThinks) -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe
PRC - [2009/07/13 21:14:45 | 000,020,480 | ---- | M] () -- \\.\globalroot\systemroot\svchost.exe
PRC - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2009/06/04 21:03:32 | 000,186,904 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2009/05/21 10:59:14 | 001,025,264 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\gs_agent\dsc.exe
PRC - [2009/05/21 10:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe
PRC - [2009/05/21 10:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) -- C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe
========== Modules (No Company Name) ==========
MOD - [2012/05/22 15:59:29 | 000,281,088 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Microsoft\36C9\ADB.exe
MOD - [2012/05/19 17:05:47 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll
MOD - [2012/05/19 17:05:40 | 007,952,384 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll
MOD - [2012/05/19 17:05:29 | 011,490,816 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll
MOD - [2012/04/11 09:30:54 | 000,186,368 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe
MOD - [2012/04/02 12:13:45 | 000,167,936 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\9ED00\ABC36.exe
MOD - [2009/07/13 21:15:51 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2009/07/13 21:15:51 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - File not found [Auto | Stopped] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe /McCoreSvc -- (McMPFSvc)
SRV:64bit: - [2009/07/16 21:06:22 | 000,033,280 | ---- | M] () [Auto | Running] -- C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE -- (wltrysvc)
SRV:64bit: - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\SysNative\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\stacsv64.exe -- (STacSV)
SRV:64bit: - [2009/06/09 12:11:14 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2012/07/19 13:33:14 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2010/07/31 23:24:23 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/08 21:03:58 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2010/03/04 13:28:08 | 000,658,656 | ---- | M] (SoftThinks) [Auto | Running] -- C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe -- (SftService)
SRV - [2009/06/29 00:44:38 | 000,240,128 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe -- (STacSV)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/05 20:07:28 | 000,250,616 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent\Dell Games\Dell Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2009/06/04 21:03:06 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2009/05/21 10:59:08 | 000,206,064 | ---- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/03/01 02:54:38 | 000,022,896 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/09/17 21:21:40 | 000,415,360 | ---- | M] (Phoenix Technologies Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CryptOSD.sys -- (CryptOSD)
DRV:64bit: - [2009/07/16 21:06:20 | 000,022,520 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\bcm42rly.sys -- (BCM42RLY)
DRV:64bit: - [2009/07/16 21:06:18 | 002,769,400 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2009/07/13 21:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/13 21:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 05:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/29 00:44:38 | 000,487,424 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2009/06/15 15:06:42 | 000,172,704 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtClsFlt.sys -- (CtClsFlt)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/04 06:54:36 | 000,408,600 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2009/06/02 23:16:56 | 007,333,472 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/05/19 23:10:00 | 000,393,728 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/05/08 04:15:18 | 000,215,552 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:64bit: - [2009/02/05 07:54:10 | 000,225,328 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Apfiltr.sys -- (ApfiltrService)
DRV:64bit: - [2006/11/01 13:51:00 | 000,151,656 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WimFltr.sys -- (WimFltr)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{2E58D3AF-7ED6-49D5-B98B-E72303684EC1}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {afdbddaa-5d3f-42ee-b79c-185a7020515b}
IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" = http://slirsredirect...mrud=24-09-2010
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{A2FD40B5-F212-4F45-87F7-12D44E490828}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2786678
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 0A 57 5E 12 C8 7E F1 44 B1 88 E2 DE ED E4 BE 1B [binary data]
IE - HKCU\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...search&AF=18556
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7ADFA_enUS396
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKCU\..\SearchScopes\{c8b322ce-7838-418e-adb2-6aa25235aa35}: "URL" = http://slirsredirect...mrud=24-09-2010
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:54424
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "uTorrentBar Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "uTorrentBar Customized Web Search"
FF - prefs.js..keyword.URL: "http://search.condui...d=CT2786678&q="
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 54424
FF - prefs.js..network.proxy.type: 1
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Amanda\AppData\Roaming\Move Networks\plugins\npqmp071701000002.dll (Move Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2010/08/28 00:10:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/08/12 15:53:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/19 13:33:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Amanda\AppData\Roaming\Move Networks [2010/06/03 21:18:41 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/19 13:33:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/06/22 18:49:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Extensions
[2012/07/16 22:51:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\z2ftmcfi.default\extensions
[2011/07/04 11:33:24 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\z2ftmcfi.default\extensions\{817e63e5-f17f-44ff-ab6e-18d2b1fd6657}
[2012/07/16 22:51:27 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\z2ftmcfi.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/01/03 18:29:10 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\z2ftmcfi.default\extensions\[email protected]
[2011/12/06 06:04:42 | 000,000,925 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Mozilla\Firefox\Profiles\z2ftmcfi.default\searchplugins\conduit.xml
[2012/06/21 13:19:55 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/03 21:18:41 | 000,000,000 | ---D | M] (Move Media Player) -- C:\USERS\AMANDA\APPDATA\ROAMING\MOVE NETWORKS
[2012/07/19 13:33:15 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/14 18:19:40 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/14 18:19:40 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - Extension: YouTube = C:\Users\Amanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\Amanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Amanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Gmail = C:\Users\Amanda\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2012/02/22 00:55:14 | 000,000,882 | RH-- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 94.63.147.16 www.google.com
O1 - Hosts: 94.63.147.17 www.bing.com
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~2\mcafee\msk\mskapbho.dll File not found
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {30F9B915-B755-4826-820B-08FBA6BD249D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4:64bit: - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [ADB.exe] C:\Program Files (x86)\LP\36C9\ADB.exe ()
O4 - HKLM..\Run: [ctfdevice] C:\ProgramData\ctfdevice.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dlldevice] C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\dlldevice.exe (Microsoft Corporation)
O4 - HKLM..\Run: [dplaysvr] C:\Windows\system32\config\systemprofile\AppData\Local\dplaysvr.exe File not found
O4 - HKCU..\Run: [ADB.exe] C:\Users\Amanda\AppData\Roaming\Microsoft\36C9\ADB.exe ()
O4 - HKCU..\Run: [ctfdevice] C:\ProgramData\ctfdevice.exe (Microsoft Corporation)
O4 - HKCU..\Run: [dlldevice] C:\Users\Amanda\AppData\Roaming\dlldevice.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O4 - Startup: C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Amanda\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
F3:64bit: - HKCU WinNT: Load - (C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe) - C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe ()
F3 - HKCU WinNT: Load - (C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe) - C:\Users\Amanda\AppData\Roaming\00FC0\lvvm.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {03A89EFD-E023-A200-A22D-45F77558EB4C} http://content9.mite...XCltInstall.dll (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{422FE7BC-A81F-4C80-871E-C292E096401E}: DhcpNameServer = 65.32.5.111 65.32.5.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9E68976-1801-4D34-912A-9ABABC121316}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\cozi - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Users\Amanda\AppData\Roaming\9ED00\ABC36.exe) - C:\Users\Amanda\AppData\Roaming\9ED00\ABC36.exe ()
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{34e678d5-a61c-11e1-9375-a4badbabc36c}\Shell - "" = AutoRun
O33 - MountPoints2\{34e678d5-a61c-11e1-9375-a4badbabc36c}\Shell\AutoRun\command - "" = E:\iStudio.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKCU\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = ah] -- Reg Error: Key error. File not found
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = ah] -- Reg Error: Key error. File not found
O37 - HKCU\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=consrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/11 21:30:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012/08/11 21:30:51 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Adobe
[2012/08/11 21:30:47 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Adobe
[2012/08/10 15:35:14 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2012/08/10 15:34:31 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Dropbox
[2012/08/10 02:33:33 | 000,000,000 | ---D | C] -- C:\Temp
[2012/08/09 16:08:55 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Adobe-BackupByPhotoshopCS6Portable
[2012/08/09 16:08:50 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Adobe-BackupByPhotoshopCS6Portable
[2012/08/08 18:25:02 | 000,000,000 | ---D | C] -- C:\Windows\Fonts\.svn
[2012/08/08 17:13:27 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Samsung
[2012/08/08 17:13:19 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Roaming\Samsung
[2012/08/08 17:13:09 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Documents\samsung
[2012/08/08 17:09:14 | 000,013,800 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadwh.sys
[2012/08/08 17:09:12 | 000,013,288 | ---- | C] (MCCI Corporation) -- C:\Windows\SysNative\drivers\ssadcm.sys
[2012/08/08 17:07:26 | 004,659,712 | ---- | C] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2012/08/08 17:06:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MarkAny
[2012/08/08 17:06:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Samsung
[2012/08/08 17:03:25 | 000,000,000 | ---D | C] -- C:\Users\Amanda\AppData\Local\Downloaded Installations
[2012/08/08 16:52:41 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\phone content
[2012/08/06 18:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe-BackupByPhotoshopCS6Portable
[2012/08/01 19:06:52 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\copy and paste
[2012/08/01 17:06:38 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\myc july2012
[2012/07/18 21:31:49 | 000,000,000 | ---D | C] -- C:\Users\Amanda\Desktop\devitt
[2012/02/01 11:53:04 | 000,100,912 | ---- | C] (Microsoft Corporation) -- C:\Users\Amanda\AppData\Roaming\dlldevice.exe
[2012/02/01 11:20:35 | 000,100,912 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\ctfdevice.exe
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/16 12:29:41 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/16 12:29:41 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/16 12:27:06 | 000,713,888 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/16 12:27:06 | 000,615,360 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/08/16 12:27:06 | 000,103,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/08/16 12:22:08 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/16 12:21:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/16 12:21:28 | 3190,050,816 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/16 07:31:05 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At16.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At14.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At12.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At10.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At15.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At13.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At11.job
[2012/08/16 07:31:04 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At9.job
[2012/08/12 21:07:01 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At44.job
[2012/08/12 21:07:01 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At43.job
[2012/08/11 21:55:36 | 000,336,036 | ---- | M] () -- C:\Users\Amanda\Desktop\j.jpg
[2012/08/11 21:53:53 | 000,164,130 | ---- | M] () -- C:\Users\Amanda\Desktop\IMG_20120811_214208.jpg
[2012/08/11 21:35:01 | 000,216,016 | ---- | M] () -- C:\Users\Amanda\Desktop\7762048924_70047b9210.jpg
[2012/08/11 21:21:33 | 000,145,150 | ---- | M] () -- C:\Users\Amanda\Desktop\7762041900_2922ff20db.jpg
[2012/08/11 21:20:16 | 000,146,488 | ---- | M] () -- C:\Users\Amanda\Desktop\7762049140_01d831308f.jpg
[2012/08/11 21:16:04 | 002,394,108 | ---- | M] () -- C:\Users\Amanda\Desktop\20120811_182023-1.jpg
[2012/08/10 23:07:02 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At48.job
[2012/08/10 23:07:02 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At47.job
[2012/08/10 22:45:24 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At46.job
[2012/08/10 22:45:24 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At45.job
[2012/08/10 22:45:23 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At42.job
[2012/08/10 22:45:23 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At41.job
[2012/08/10 22:45:22 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At40.job
[2012/08/10 22:45:21 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At39.job
[2012/08/10 18:49:20 | 000,081,634 | ---- | M] () -- C:\Users\Amanda\Desktop\527060_390688404319426_528452038_n.jpg
[2012/08/10 18:42:49 | 000,030,893 | ---- | M] () -- C:\Users\Amanda\Desktop\424289_10151102203121907_836461213_n.jpg
[2012/08/10 18:32:33 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At38.job
[2012/08/10 18:32:33 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At37.job
[2012/08/10 18:32:32 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At36.job
[2012/08/10 18:32:31 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At35.job
[2012/08/10 16:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At34.job
[2012/08/10 16:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At33.job
[2012/08/10 16:01:03 | 000,001,005 | ---- | M] () -- C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/10 15:58:03 | 000,214,215 | ---- | M] () -- C:\Users\Amanda\Desktop\1.jpg
[2012/08/10 03:46:21 | 005,133,912 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/08/10 03:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At8.job
[2012/08/10 03:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At7.job
[2012/08/10 02:30:23 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2012/08/10 02:21:06 | 001,664,515 | ---- | M] () -- C:\Users\Amanda\Desktop\20120303_020929.jpg
[2012/08/10 02:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At6.job
[2012/08/10 02:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At5.job
[2012/08/09 16:41:54 | 000,658,876 | ---- | M] () -- C:\Users\Amanda\Desktop\Untitled-1.jpg
[2012/08/09 15:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At32.job
[2012/08/09 15:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At31.job
[2012/08/09 14:06:47 | 366,501,003 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/08/08 17:41:17 | 000,000,378 | ---- | M] () -- C:\Users\Amanda\Desktop\Document.rtf
[2012/08/08 17:17:39 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2012/08/07 14:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At30.job
[2012/08/07 14:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At29.job
[2012/08/07 13:07:01 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At28.job
[2012/08/07 13:07:01 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At27.job
[2012/08/07 12:47:22 | 000,047,612 | ---- | M] () -- C:\Users\Amanda\Desktop\552083_10151085909814701_171552911_n.jpg
[2012/08/07 12:12:21 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At26.job
[2012/08/07 12:12:21 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At25.job
[2012/08/07 03:00:22 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At4.job
[2012/08/07 03:00:22 | 000,000,346 | ---- | M] () -- C:\Windows\tasks\At2.job
[2012/08/07 03:00:22 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At3.job
[2012/08/07 03:00:22 | 000,000,344 | ---- | M] () -- C:\Windows\tasks\At1.job
[2012/07/30 14:16:48 | 004,659,712 | ---- | M] (Dmitry Streblechenko) -- C:\Windows\SysWow64\Redemption.dll
[2012/07/18 22:44:56 | 000,000,112 | -H-- | M] () -- C:\F3F9DCABD663
[2012/07/18 22:44:56 | 000,000,112 | -H-- | M] () -- C:\3C23943CFE43
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/11 21:55:34 | 000,336,036 | ---- | C] () -- C:\Users\Amanda\Desktop\j.jpg
[2012/08/11 21:53:52 | 000,164,130 | ---- | C] () -- C:\Users\Amanda\Desktop\IMG_20120811_214208.jpg
[2012/08/11 21:21:33 | 000,145,150 | ---- | C] () -- C:\Users\Amanda\Desktop\7762041900_2922ff20db.jpg
[2012/08/11 21:20:16 | 000,146,488 | ---- | C] () -- C:\Users\Amanda\Desktop\7762049140_01d831308f.jpg
[2012/08/11 21:20:01 | 000,216,016 | ---- | C] () -- C:\Users\Amanda\Desktop\7762048924_70047b9210.jpg
[2012/08/11 21:16:00 | 002,394,108 | ---- | C] () -- C:\Users\Amanda\Desktop\20120811_182023-1.jpg
[2012/08/10 18:49:18 | 000,081,634 | ---- | C] () -- C:\Users\Amanda\Desktop\527060_390688404319426_528452038_n.jpg
[2012/08/10 18:42:49 | 000,030,893 | ---- | C] () -- C:\Users\Amanda\Desktop\424289_10151102203121907_836461213_n.jpg
[2012/08/10 15:40:09 | 000,214,215 | ---- | C] () -- C:\Users\Amanda\Desktop\1.jpg
[2012/08/10 15:35:25 | 000,001,005 | ---- | C] () -- C:\Users\Amanda\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2012/08/10 02:30:23 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_WinUsb_01007.Wdf
[2012/08/10 02:21:40 | 002,390,797 | ---- | C] () -- C:\Users\Amanda\Desktop\20120303_020542.jpg
[2012/08/10 02:21:40 | 002,151,538 | ---- | C] () -- C:\Users\Amanda\Desktop\20120303_020546.jpg
[2012/08/10 02:21:40 | 001,934,483 | ---- | C] () -- C:\Users\Amanda\Desktop\20120303_020528.jpg
[2012/08/10 02:21:39 | 001,950,128 | ---- | C] () -- C:\Users\Amanda\Desktop\20120303_020513.jpg
[2012/08/09 16:14:58 | 000,658,876 | ---- | C] () -- C:\Users\Amanda\Desktop\Untitled-1.jpg
[2012/08/09 16:10:27 | 000,111,482 | ---- | C] () -- C:\Users\Amanda\Desktop\934_untitled_325 (2).jpg
[2012/08/09 16:10:20 | 000,129,065 | ---- | C] () -- C:\Users\Amanda\Desktop\934_untitled_304.jpg
[2012/08/08 17:41:17 | 000,000,378 | ---- | C] () -- C:\Users\Amanda\Desktop\Document.rtf
[2012/08/08 17:17:39 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_ssadadb_01005.Wdf
[2012/08/07 12:47:21 | 000,047,612 | ---- | C] () -- C:\Users\Amanda\Desktop\552083_10151085909814701_171552911_n.jpg
[2012/07/18 22:44:56 | 000,000,112 | -H-- | C] () -- C:\F3F9DCABD663
[2012/07/18 22:44:56 | 000,000,112 | -H-- | C] () -- C:\3C23943CFE43
[2012/06/26 16:02:38 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012/06/26 16:02:38 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012/06/26 16:02:38 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012/06/26 16:02:38 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012/06/21 13:36:13 | 000,281,088 | ---- | C] () -- C:\Users\Amanda\AppData\Roaming\firefox.exe
[2012/06/21 13:16:54 | 000,281,088 | ---- | C] () -- C:\Users\Amanda\AppData\Roaming\iexplore.exe
[2011/12/12 22:30:52 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/12/12 22:30:52 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/12/09 19:13:21 | 000,011,732 | -HS- | C] () -- C:\ProgramData\2058024917
[2011/12/09 15:00:48 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\1nj7H.com.b
[2011/12/09 14:58:39 | 000,000,112 | ---- | C] () -- C:\ProgramData\OQU8Mgm2.dat
[2011/12/09 14:48:41 | 000,011,736 | -HS- | C] () -- C:\Users\Amanda\AppData\Local\jqrpys0j5vyo7wyk6jdl2e230v3q
[2011/12/09 14:48:41 | 000,011,736 | -HS- | C] () -- C:\ProgramData\jqrpys0j5vyo7wyk6jdl2e230v3q
[2011/12/09 12:47:08 | 000,012,910 | -HS- | C] () -- C:\Users\Amanda\AppData\Local\ceexxb5c1dhw3mbd0art2r660v3r
[2011/12/09 12:47:08 | 000,012,910 | -HS- | C] () -- C:\ProgramData\ceexxb5c1dhw3mbd0art2r660v3r
[2011/08/10 23:27:58 | 000,009,216 | ---- | C] () -- C:\Users\Amanda\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/29 11:03:44 | 000,010,904 | -HS- | C] () -- C:\Users\Amanda\AppData\Local\pu806jx5yg0imjt4ot0gjdt21t3yw2621i1ca11gk8m4
[2011/07/29 11:03:44 | 000,010,904 | -HS- | C] () -- C:\ProgramData\pu806jx5yg0imjt4ot0gjdt21t3yw2621i1ca11gk8m4
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\Users\Amanda\AppData\Local\yxwe.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\Users\Amanda\AppData\Local\yigo.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\ProgramData\xrwg.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\ProgramData\ouay.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\ProgramData\myar.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\Users\Amanda\AppData\Local\lymn.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\ProgramData\linp.exe
[2011/07/29 11:03:43 | 000,000,000 | ---- | C] () -- C:\Users\Amanda\AppData\Local\cqkt.exe
[2011/07/13 08:21:30 | 000,000,040 | ---- | C] () -- C:\ProgramData\4e5008c7
[2010/06/02 18:57:55 | 000,000,482 | ---- | C] () -- C:\Users\Amanda\AppData\Roaming\wklnhst.dat
========== LOP Check ==========
[2012/06/21 13:10:27 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\00FC0
[2012/06/21 13:15:40 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\9ED00
[2010/07/30 22:11:31 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\acccore
[2011/11/07 12:31:06 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\BD22oonF4pmHsQ7
[2011/11/07 12:31:07 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\cmmmG55aQJ6dK8R
[2012/08/16 12:31:19 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Dropbox
[2011/11/07 12:31:05 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\gcSS11ivD3on4mH
[2011/11/07 12:49:49 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\JUUUCCekIBrzNyA
[2012/08/12 21:08:15 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Samsung
[2010/06/06 22:44:43 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/06/15 19:28:18 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Template
[2012/03/15 15:10:22 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\uTorrent
[2012/01/25 21:39:22 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\Windows Live Writer
[2011/11/07 12:31:12 | 000,000,000 | ---D | M] -- C:\Users\Amanda\AppData\Roaming\zLLL9hhTXq
[2012/08/07 03:00:22 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At1.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At10.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At11.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At12.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At13.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At14.job
[2012/08/16 07:31:05 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At15.job
[2012/08/16 07:31:05 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At16.job
[2012/01/25 11:26:48 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At17.job
[2012/01/25 11:26:48 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At18.job
[2012/07/10 12:45:46 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At19.job
[2012/08/07 03:00:22 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At2.job
[2012/07/10 12:45:46 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At20.job
[2012/07/10 12:45:46 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At21.job
[2012/07/10 12:45:46 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At22.job
[2012/07/10 12:45:46 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At23.job
[2012/07/10 12:45:46 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At24.job
[2012/08/07 12:12:21 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At25.job
[2012/08/07 12:12:21 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At26.job
[2012/08/07 13:07:01 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At27.job
[2012/08/07 13:07:01 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At28.job
[2012/08/07 14:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At29.job
[2012/08/07 03:00:22 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At3.job
[2012/08/07 14:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At30.job
[2012/08/09 15:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At31.job
[2012/08/09 15:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At32.job
[2012/08/10 16:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At33.job
[2012/08/10 16:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At34.job
[2012/08/10 18:32:31 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At35.job
[2012/08/10 18:32:32 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At36.job
[2012/08/10 18:32:33 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At37.job
[2012/08/10 18:32:33 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At38.job
[2012/08/10 22:45:21 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At39.job
[2012/08/07 03:00:22 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At4.job
[2012/08/10 22:45:22 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At40.job
[2012/08/10 22:45:23 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At41.job
[2012/08/10 22:45:23 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At42.job
[2012/08/12 21:07:01 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At43.job
[2012/08/12 21:07:01 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At44.job
[2012/08/10 22:45:24 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At45.job
[2012/08/10 22:45:24 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At46.job
[2012/08/10 23:07:02 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At47.job
[2012/08/10 23:07:02 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At48.job
[2012/06/21 13:37:04 | 000,000,384 | ---- | M] () -- C:\Windows\Tasks\At49.job
[2012/08/10 02:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At5.job
[2012/08/10 02:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At6.job
[2012/08/10 03:07:00 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At7.job
[2012/08/10 03:07:00 | 000,000,346 | ---- | M] () -- C:\Windows\Tasks\At8.job
[2012/08/16 07:31:04 | 000,000,344 | ---- | M] () -- C:\Windows\Tasks\At9.job
[2012/06/06 01:22:54 | 000,032,564 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\system64] -> \systemroot\system32 -> Mount Point
< End of report >