OTL logfile created on: 1/2/2013 2:36:46 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pelico\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.87 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 61.73% Memory free
7.74 Gb Paging File | 6.05 Gb Available in Paging File | 78.13% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 425.27 Gb Total Space | 358.05 Gb Free Space | 84.19% Space Free | Partition Type: NTFS
Drive D: | 40.00 Gb Total Space | 33.94 Gb Free Space | 84.86% Space Free | Partition Type: NTFS
Computer Name: PELICO-PC | User Name: Pelico | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/01/02 14:34:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pelico\Desktop\OTL.exe
PRC - [2012/07/06 01:56:56 | 000,361,472 | ---- | M] (Alcatel-Lucent) -- C:\Program Files (x86)\Common Files\Motive\pcCMService.exe
PRC - [2011/11/09 10:46:34 | 000,247,968 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11c_ActiveX.exe
PRC - [2010/09/10 14:11:16 | 001,154,848 | ---- | M] (Intuit Inc.) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
PRC - [2010/09/10 12:46:32 | 000,045,056 | ---- | M] (Intuit) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2009/06/04 15:48:22 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2009/02/20 08:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
========== Modules (No Company Name) ==========
MOD - [2011/03/16 23:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 14:45:26 | 008,801,120 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
========== Services (SafeList) ==========
SRV:64bit: - [2012/09/12 20:21:48 | 000,368,896 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/09/12 20:21:48 | 000,022,072 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2012/07/06 01:57:02 | 000,441,344 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files\Common Files\Motive\pcCMService.exe -- (pcCMService64)
SRV:64bit: - [2009/07/13 17:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 17:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/06/04 15:48:20 | 000,864,032 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV - [2012/07/06 01:56:56 | 000,361,472 | ---- | M] (Alcatel-Lucent) [Auto | Running] -- C:\Program Files (x86)\Common Files\Motive\pcCMService.exe -- (pcCMService)
SRV - [2010/09/10 12:46:32 | 000,045,056 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/29 23:40:16 | 001,043,584 | ---- | M] (Hewlett-Packard Co.) [Auto | Running] -- C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL -- (HPSLPSVC)
SRV - [2009/07/23 20:10:38 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2009/06/10 13:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/06/10 03:41:10 | 000,309,744 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2009/06/10 03:41:02 | 000,166,384 | ---- | M] (Sonic Solutions) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe -- (RoxWatch10)
SRV - [2009/06/10 03:40:22 | 001,124,848 | ---- | M] (Sonic Solutions) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe -- (RoxMediaDB10)
SRV - [2009/02/20 08:46:52 | 000,030,312 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe -- (BcmSqlStartupSvc)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/08/30 21:03:48 | 000,128,456 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/02/29 22:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/03/10 22:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/10 22:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 05:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 03:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/08/25 19:36:04 | 010,611,552 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2010/01/07 10:33:16 | 000,158,848 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Impcd.sys -- (Impcd)
DRV:64bit: - [2009/07/13 17:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 17:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 17:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 13:59:33 | 005,020,672 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/07/09 02:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/12 14:19:58 | 000,287,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1y62x64.sys -- (e1yexpress)
DRV:64bit: - [2009/06/10 12:35:42 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/06/10 12:35:35 | 000,620,544 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/06/10 12:35:20 | 000,278,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\e1e6032e.sys -- (e1express)
DRV:64bit: - [2009/06/10 12:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 12:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 12:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 12:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/14 10:14:16 | 000,097,056 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2009/05/14 10:14:14 | 000,131,360 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2009/05/14 10:14:10 | 000,019,872 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2009/04/07 15:33:08 | 000,035,104 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV - [2010/04/30 14:09:44 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/04/30 14:09:22 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/07/13 17:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D6 B3 E9 38 B7 59 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = http://search.yahoo....ms}&fr=chr-atty
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/20 13:42:35 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/09/20 13:42:35 | 000,000,000 | ---D | M]
O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Intuit SyncManager] C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe (Intuit Inc. All rights reserved.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe (Sonic Solutions)
O4 - HKLM..\Run: [StartCal.exe] C:\Program Files (x86)\IdeaCom\TSC\StartCal.exe calibrate_private File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: $talisma_url$ ([]https in Trusted sites)
O16 - DPF: {E0FEE963-BB53-4215-81AD-B28C77384644} https://pattcw.att.m...Installer64.cab (WebBrowserType Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{503D4542-68C2-451E-A5E7-B90BDA00C2B5}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9F3B1286-B42F-4861-9ECE-85974B9080ED}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/04/08 12:30:18 | 000,000,048 | -H-- | M] () - D:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/01/02 14:34:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Pelico\Desktop\OTL.exe
[2012/12/29 15:55:43 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Rainbow
[2012/12/29 15:54:13 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Chronicles of Emerland Solitaire
[2012/12/29 15:54:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Chronicles of Emerland Solitaire
[2012/12/29 15:54:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Chronicles of Emerland Solitaire
[2012/12/23 15:39:08 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fishdom 3
[2012/12/23 15:39:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fishdom 3
[2012/12/23 15:39:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fishdom 3
[2012/12/19 16:26:34 | 000,649,864 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\Users\Pelico\Documents\autoruns.exe
[2012/12/14 16:07:55 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Absolutist
[2012/12/12 18:13:26 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Patchworkz
[2012/12/12 18:13:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Patchworkz
[2012/12/12 18:13:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Patchworkz
[2012/12/09 18:59:01 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Phantasmat - Crucible Peak Collector's Edition
[2012/12/09 18:59:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phantasmat - Crucible Peak Collector's Edition
[2012/12/09 18:59:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Phantasmat - Crucible Peak Collector's Edition
[2012/12/06 09:28:03 | 000,000,000 | ---D | C] -- C:\Users\Pelico\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nutcracker Collector's Edition
[2012/12/06 09:28:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Christmas Stories - Nutcracker Collector's Edition
[2012/12/06 09:28:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Christmas Stories - Nutcracker Collector's Edition
========== Files - Modified Within 30 Days ==========
[2013/01/02 14:34:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Pelico\Desktop\OTL.exe
[2013/01/02 12:55:51 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/02 12:55:51 | 000,016,976 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/02 12:52:54 | 000,806,934 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/02 12:52:54 | 000,680,296 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/01/02 12:52:54 | 000,128,744 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/01/02 12:48:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/02 12:48:22 | 3118,342,144 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/29 15:54:55 | 000,002,156 | ---- | M] () -- C:\Users\Public\Desktop\Play The Chronicles of Emerland Solitaire.lnk
[2012/12/29 15:54:55 | 000,001,302 | ---- | M] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2012/12/23 15:39:42 | 000,001,911 | ---- | M] () -- C:\Users\Public\Desktop\Play Fishdom 3.lnk
[2012/12/21 03:16:44 | 000,472,576 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/19 16:26:48 | 000,055,296 | ---- | M] () -- C:\Users\Pelico\Documents\BSOD_Windows7_Vista_v2.64_jcgriff2_.exe
[2012/12/19 16:26:34 | 000,649,864 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\Users\Pelico\Documents\autoruns.exe
[2012/12/13 17:11:49 | 000,002,856 | ---- | M] () -- C:\Users\Pelico\Desktop\startup.rtf
[2012/12/13 10:26:06 | 000,005,651 | ---- | M] () -- C:\Users\Pelico\Desktop\Document.rtf
[2012/12/12 22:46:23 | 000,005,680 | ---- | M] () -- C:\Users\Pelico\Documents\Document.rtf
[2012/12/12 18:14:00 | 000,001,924 | ---- | M] () -- C:\Users\Public\Desktop\Play Patchworkz.lnk
[2012/12/09 19:01:21 | 000,002,278 | ---- | M] () -- C:\Users\Public\Desktop\Play Phantasmat - Crucible Peak Collector's Edition.lnk
[2012/12/06 09:29:49 | 000,002,322 | ---- | M] () -- C:\Users\Public\Desktop\Play Christmas Stories - Nutcracker Collector's Edition.lnk
[2012/12/05 13:47:45 | 000,002,329 | ---- | M] () -- C:\Users\Pelico\Documents\geek.rtf
========== Files Created - No Company Name ==========
[2012/12/29 15:54:55 | 000,002,156 | ---- | C] () -- C:\Users\Public\Desktop\Play The Chronicles of Emerland Solitaire.lnk
[2012/12/29 15:54:55 | 000,001,302 | ---- | C] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2012/12/23 15:39:42 | 000,001,911 | ---- | C] () -- C:\Users\Public\Desktop\Play Fishdom 3.lnk
[2012/12/19 16:26:48 | 000,055,296 | ---- | C] () -- C:\Users\Pelico\Documents\BSOD_Windows7_Vista_v2.64_jcgriff2_.exe
[2012/12/13 17:11:49 | 000,002,856 | ---- | C] () -- C:\Users\Pelico\Desktop\startup.rtf
[2012/12/13 10:26:06 | 000,005,651 | ---- | C] () -- C:\Users\Pelico\Desktop\Document.rtf
[2012/12/12 22:46:23 | 000,005,680 | ---- | C] () -- C:\Users\Pelico\Documents\Document.rtf
[2012/12/12 18:14:00 | 000,001,924 | ---- | C] () -- C:\Users\Public\Desktop\Play Patchworkz.lnk
[2012/12/09 19:01:21 | 000,002,278 | ---- | C] () -- C:\Users\Public\Desktop\Play Phantasmat - Crucible Peak Collector's Edition.lnk
[2012/12/06 09:29:49 | 000,002,322 | ---- | C] () -- C:\Users\Public\Desktop\Play Christmas Stories - Nutcracker Collector's Edition.lnk
[2012/12/05 13:47:45 | 000,002,329 | ---- | C] () -- C:\Users\Pelico\Documents\geek.rtf
========== ZeroAccess Check ==========
[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/08 21:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 17:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 04:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 17:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/12/14 16:07:55 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Absolutist
[2012/07/23 13:26:34 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\AlawarEntertainment
[2012/02/14 11:41:38 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Amulet_of_time
[2012/01/15 17:54:31 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Artifex Mundi
[2012/02/24 14:13:49 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Artogon
[2012/05/20 08:55:39 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Avery
[2012/08/13 17:07:52 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Big Fish Games
[2012/02/23 18:03:48 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\bigwig_media
[2011/11/15 17:46:33 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\BlamGames
[2012/06/02 11:23:00 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Blue Tea Games
[2012/07/13 17:20:40 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Boolat Games
[2013/01/01 13:38:55 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Boomzap
[2012/11/21 15:41:21 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Casual Arts
[2012/04/24 15:11:14 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\CasualMechanics
[2012/06/22 16:35:26 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\cerasus.media
[2012/07/31 15:49:37 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Crown
[2012/02/17 18:02:36 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\DailyMagic
[2012/03/17 15:19:38 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Dark Blue Games
[2012/07/15 14:56:38 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\DAVA
[2012/05/26 17:01:07 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Deep Shadows
[2011/12/14 17:25:08 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\DieselPuppet
[2012/01/31 14:56:35 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\EleFun Games
[2012/12/05 16:22:09 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Elephant Games
[2012/04/18 17:23:04 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Enki Games
[2013/01/01 14:42:23 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\ERS Game Studios
[2011/12/15 16:55:27 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Fanda Games
[2011/10/30 16:56:04 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Floodlight Games
[2012/04/27 15:33:36 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Freeze Tag
[2011/07/09 12:19:33 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Frogwares
[2012/11/24 17:54:27 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\funkitron
[2012/02/27 15:37:35 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\GameInvest
[2012/04/15 09:31:36 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\GameMill Entertainment
[2012/04/27 16:46:37 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\GO Games
[2011/07/31 12:19:23 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Gogii
[2012/03/21 11:59:55 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Gunnar Games
[2012/03/04 14:47:20 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\HitPoint Studios
[2012/02/22 11:12:33 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\JoyBits
[2012/02/06 18:37:07 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\KatGames
[2012/05/04 16:06:31 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Lazy Turtle Games
[2012/04/23 17:07:15 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\LegacyInteractive
[2011/07/11 15:41:43 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\LestaStudio
[2012/01/02 17:59:36 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\MagicIndie
[2012/06/05 11:44:11 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Mariaglorum
[2012/01/31 15:51:19 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\MumboJumbo
[2012/07/23 13:46:10 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Orneon
[2012/05/07 17:26:57 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\PassionFruit Games
[2012/05/27 08:43:51 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Persha Studia
[2011/07/05 16:38:47 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Phantasmat_bf_ce1
[2012/12/23 15:41:15 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Playrix Entertainment
[2012/06/17 16:47:43 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\quickclick
[2012/12/29 15:55:43 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Rainbow
[2012/07/07 16:38:06 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Skunk Studios
[2012/08/04 15:26:44 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Skyborn
[2012/06/21 17:03:13 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\SMIGames
[2012/08/12 12:46:05 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\SpinTop Games
[2011/07/28 16:39:32 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\SulusGames
[2012/04/27 16:29:35 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\tabagames
[2011/11/23 15:39:28 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\TeleportGamesLtd
[2012/01/31 12:37:14 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Ten Heavens
[2011/12/23 16:38:57 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Top Evidence
[2011/08/26 15:40:21 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Twilight Games
[2012/08/05 13:55:59 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Val'Gor 2
[2012/06/22 13:39:51 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\ValGor 2
[2011/07/24 16:35:28 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\VampireSagaHL
[2012/01/31 13:55:27 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Vast Studios
[2011/12/30 16:23:57 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Vogat Interactive
[2011/07/12 13:49:30 | 000,000,000 | ---D | M] -- C:\Users\Pelico\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:1409277B
@Alternate Data Stream - 261 bytes -> C:\ProgramData\TEMP:12258D63
@Alternate Data Stream - 259 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 259 bytes -> C:\ProgramData\TEMP:CA1AFE85
@Alternate Data Stream - 259 bytes -> C:\ProgramData\TEMP:4244811A
@Alternate Data Stream - 258 bytes -> C:\ProgramData\TEMP:84C34762
@Alternate Data Stream - 256 bytes -> C:\ProgramData\TEMP:754E278B
@Alternate Data Stream - 254 bytes -> C:\ProgramData\TEMP:FFC3922F
@Alternate Data Stream - 254 bytes -> C:\ProgramData\TEMP:BECA50FF
@Alternate Data Stream - 252 bytes -> C:\ProgramData\TEMP:5539129F
@Alternate Data Stream - 251 bytes -> C:\ProgramData\TEMP:6CF828C2
@Alternate Data Stream - 250 bytes -> C:\ProgramData\TEMP:6E65510A
@Alternate Data Stream - 250 bytes -> C:\ProgramData\TEMP:2E636DD9
@Alternate Data Stream - 249 bytes -> C:\ProgramData\TEMP:C46848E8
@Alternate Data Stream - 248 bytes -> C:\ProgramData\TEMP:2F474C84
@Alternate Data Stream - 248 bytes -> C:\ProgramData\TEMP:2A874675
@Alternate Data Stream - 247 bytes -> C:\ProgramData\TEMP:E8B61305
@Alternate Data Stream - 247 bytes -> C:\ProgramData\TEMP:6A9CA6CB
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:3487C53E
@Alternate Data Stream - 246 bytes -> C:\ProgramData\TEMP:1A15E356
@Alternate Data Stream - 245 bytes -> C:\ProgramData\TEMP:96372A73
@Alternate Data Stream - 244 bytes -> C:\ProgramData\TEMP:E4E83517
@Alternate Data Stream - 243 bytes -> C:\ProgramData\TEMP:1B90AAB4
@Alternate Data Stream - 242 bytes -> C:\ProgramData\TEMP:65C4D44A
@Alternate Data Stream - 242 bytes -> C:\ProgramData\TEMP:3D4B733E
@Alternate Data Stream - 241 bytes -> C:\ProgramData\TEMP:A6F30843
@Alternate Data Stream - 241 bytes -> C:\ProgramData\TEMP:1224B4C3
@Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:B8791731
@Alternate Data Stream - 240 bytes -> C:\ProgramData\TEMP:54403233
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:E0888117
@Alternate Data Stream - 239 bytes -> C:\ProgramData\TEMP:5E73E1C2
@Alternate Data Stream - 238 bytes -> C:\ProgramData\TEMP:6EE8565A
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:97AAB7F2
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:16F4BC64
@Alternate Data Stream - 237 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:B1786630
@Alternate Data Stream - 236 bytes -> C:\ProgramData\TEMP:5A9F1AE5
@Alternate Data Stream - 235 bytes -> C:\ProgramData\TEMP:FD7DCDA6
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:FF717A18
@Alternate Data Stream - 234 bytes -> C:\ProgramData\TEMP:EBCF5924
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:56FBA78D
@Alternate Data Stream - 233 bytes -> C:\ProgramData\TEMP:120B3AFD
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:D696AA12
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:3EC5BC08
@Alternate Data Stream - 232 bytes -> C:\ProgramData\TEMP:1B389835
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:B0456F0C
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:AABECEFB
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:7A2101AB
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:5ECEFF17
@Alternate Data Stream - 231 bytes -> C:\ProgramData\TEMP:0A74923C
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:B65E763D
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:ADE67221
@Alternate Data Stream - 230 bytes -> C:\ProgramData\TEMP:795F6DEC
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:C3A047E3
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:A2FF62A6
@Alternate Data Stream - 229 bytes -> C:\ProgramData\TEMP:9195103F
@Alternate Data Stream - 228 bytes -> C:\ProgramData\TEMP:F8DE80DB
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:F9689B72
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:6EA64886
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:6294B369
@Alternate Data Stream - 227 bytes -> C:\ProgramData\TEMP:53B8C5D2
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:2F8138B7
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:0474F714
@Alternate Data Stream - 226 bytes -> C:\ProgramData\TEMP:02CC0035
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:5DB36C47
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:EAF954B6
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:B4258C5D
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:65137F0D
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:14B2E0BD
@Alternate Data Stream - 221 bytes -> C:\ProgramData\TEMP:AD2DB2F9
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:88E8CC2E
@Alternate Data Stream - 219 bytes -> C:\ProgramData\TEMP:4D551822
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:9725F1BC
@Alternate Data Stream - 217 bytes -> C:\ProgramData\TEMP:9FD757A9
@Alternate Data Stream - 216 bytes -> C:\ProgramData\TEMP:1968990D
@Alternate Data Stream - 214 bytes -> C:\ProgramData\TEMP:902C848D
@Alternate Data Stream - 212 bytes -> C:\ProgramData\TEMP:ED0B32CA
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:6C5EC3CD
@Alternate Data Stream - 210 bytes -> C:\ProgramData\TEMP:13AA281B
@Alternate Data Stream - 208 bytes -> C:\ProgramData\TEMP:6017A808
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:DA5888A7
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:45912F61
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:1DD8718C
@Alternate Data Stream - 200 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 197 bytes -> C:\ProgramData\TEMP:A3E39C6A
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:6ED8B881
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:1E2D49E0
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:0168CC60
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:62AF94A0
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:4EC7F009
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:E265ED33
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:A6345BDA
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:39B14E09
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:FB71A279
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:9D6EAEC3
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:FD786DCA
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:4AC7B5C1
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:10B970A9
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:895A78C5
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:6896CCCE
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:95D421DF
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:FD6D11C9
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:084612C9
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:EE2DD6CC
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:EDE28CFC
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:2E33E4A6
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:10CB85CA
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:E3615992
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:80253E8D
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:DF5ABA3D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:132714FA
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:302ECBD6
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:FDEE14AC
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:9968F0E2
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:6A0A47E7
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:58E38390
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:F72306CC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:0EC7A545
< End of report >