I hope one of you clever guys will be able to help me.
My computer has several user accounts and Avira detected JS/Redirect.CH in
C:\Users\Rachel\Appdata\Local\702331b6-0878-4f3e-8294-0e67b4b2fa03.crx. I instructed Avira to quarantine the file.
Shortly after, Avira reported blocking TR/Crypt.ZPACK.Gen8 in C:\Users\Rachel\Appdata\Roaming\arosv.dll, murtf.dll and cakrec.dll. I instructed Avira to quarantine these.
I looked in C:\Users\Rachel\Appdata\Roaming to confirm removal of the dll files (which they had), but noted that the .crx file was still in the \Local folder. I rescanned this folder with Avira and quarantined the file, which this time did remove it.
I tried a system scan with Avira which seemed to hang at 3% (but maybe I didn't allow it long enough), so did a scan with Malwarebytes and SuperAntiSpyware which both came up clean.
Now when Rachel logs on, a warning window appears for each of the removed .dll files - "Error loading ***.dll. The specified module could not be found." Clicking OK appears to allow normal operation to continue.
Can someone help me to get rid of these warnings and confirm that my computer is now clean? I ran OTL from my account with 'scan all users' selected - should I have run it from Rachel's account? The OTL report is below. Many thanks.
OTL logfile created on: 22/01/2013 07:53:48 - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = D:\Computer\Security\OTL
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 0.87 Gb Available Physical Memory | 29.08% Memory free
6.21 Gb Paging File | 3.99 Gb Available in Paging File | 64.18% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 921.17 Gb Total Space | 656.39 Gb Free Space | 71.26% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 755.25 Gb Free Space | 81.08% Space Free | Partition Type: NTFS
Drive E: | 10.00 Gb Total Space | 5.17 Gb Free Space | 51.66% Space Free | Partition Type: NTFS
Drive L: | 465.76 Gb Total Space | 144.49 Gb Free Space | 31.02% Space Free | Partition Type: NTFS
Drive M: | 149.01 Gb Total Space | 64.11 Gb Free Space | 43.02% Space Free | Partition Type: NTFS
Drive N: | 1863.01 Gb Total Space | 1028.93 Gb Free Space | 55.23% Space Free | Partition Type: NTFS
Drive S: | 465.76 Gb Total Space | 124.31 Gb Free Space | 26.69% Space Free | Partition Type: NTFS
Drive T: | 931.51 Gb Total Space | 197.64 Gb Free Space | 21.22% Space Free | Partition Type: NTFS
Computer Name: HOME-PC | User Name: Charles | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Computer\Security\OTL\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_5_502_146.exe (Adobe Systems, Inc.)
PRC - C:\Program Files\XYplorer\XYplorer.exe (www.xyplorer.com)
PRC - C:\Program Files\Serviio\bin\ServiioConsole.exe ()
PRC - C:\Program Files\Serviio\bin\ServiioService.exe ()
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avscan.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Avira\AntiVir Desktop\avcenter.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Cobian Backup 11\cbVSCService11.exe (CobianSoft, Luis Cobian)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Users\Charles\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
PRC - C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe (Sphinx Software)
PRC - C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe (Sphinx Software)
PRC - C:\Program Files\Microsoft Office 2010\Office14\MSOSYNC.EXE (Microsoft Corporation)
PRC - C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Canon\Solution Menu EX\CNSEUPDT.EXE (CANON INC.)
PRC - C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
PRC - C:\Program Files\Codebox\BitMeter\BitMeter2.exe ( )
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conime.exe (Microsoft Corporation)
PRC - C:\Program Files\JGsoft\EditPadLite\EditPadLite.exe (Just Great Software)
PRC - C:\Program Files\Windows Mail\WinMail.exe (Microsoft Corporation)
PRC - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\pmxmiced.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Windows\System32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\004bc6615f9c06df5c98859d35149fe6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\0c3da9004b277959e24a9fd606d3dd05\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll ()
MOD - C:\Program Files\Serviio\bin\ServiioConsole.exe ()
MOD - C:\Program Files\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll ()
MOD - C:\Users\Charles\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\Tablet\Pen\libxml2.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\IZArc\IZArcCM.dll ()
MOD - C:\Program Files\Microsoft Office 2010\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files\Unlocker\UnlockerCOM.dll ()
========== Services (SafeList) ==========
SRV - (MozillaMaintenance) -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Serviio) -- C:\Program Files\Serviio\bin\ServiioService.exe ()
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office 2010\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (KooRaRooMediaServer) -- C:\Program Files\KooRaRoo Media\KooRaRooMediaServer.exe (Programming Sunrise)
SRV - (AdobeActiveFileMonitor11.0) -- C:\Program Files\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (cbVSCService11) -- C:\Program Files\Cobian Backup 11\cbVSCService11.exe (CobianSoft, Luis Cobian)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (AMD External Events Utility) -- C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (AcrSch2Svc) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (Windows7FirewallService) -- C:\Program Files\Windows7FirewallControl\Windows7FirewallService.exe (Sphinx Software)
SRV - (TabletServicePen) -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (TouchServicePen) -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (sprtsvc_dellsupportcenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (KService) -- C:\Program Files\Kontiki\KService.exe ()
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (rpcapd) -- C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies)
SRV - (AdobeActiveFileMonitor6.0) -- C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe ()
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (cpuz135) -- C:\Windows\TEMP\cpuz135\cpuz135_x32.sys File not found
DRV - (blbdrive) -- C:\Windows\system32\drivers\blbdrive.sys File not found
DRV - (ALSysIO) -- C:\Users\Charles\AppData\Local\Temp\ALSysIO.sys File not found
DRV - (avipbb) -- C:\Windows\System32\drivers\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV - (avgntflt) -- C:\Windows\System32\drivers\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV - (avkmgr) -- C:\Windows\System32\drivers\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV - (ssmdrv) -- C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (timounter) -- C:\Windows\System32\drivers\timntr.sys (Acronis)
DRV - (vididr) -- C:\Windows\System32\drivers\vididr.sys (Acronis)
DRV - (vidsflt53) -- C:\Windows\System32\drivers\vsflt53.sys (Acronis)
DRV - (snapman) -- C:\Windows\System32\drivers\snapman.sys (Acronis)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdag) -- C:\Windows\System32\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV - (amdkmdap) -- C:\Windows\System32\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV - (wacmoumonitor) -- C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (wacommousefilter) -- C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) -- C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (speedfan) -- C:\Windows\System32\speedfan.sys (Almico Software)
DRV - (Apowersoft_AudioDevice) -- C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys (Wondershare)
DRV - (AtiHDAudioService) -- C:\Windows\System32\drivers\AtihdLH3.sys (Advanced Micro Devices)
DRV - (tifsfilter) -- C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (WacomVTHid) -- C:\Windows\System32\drivers\WacomVTHid.sys (Wacom Technology)
DRV - (BVRPMPR5) -- C:\Windows\System32\drivers\BVRPMPR5.SYS (Avanquest Software)
DRV - (UnlockerDriver5) -- C:\Program Files\Unlocker\UnlockerDriver5.sys ()
DRV - (e1express) -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (pmxmouse) -- C:\Windows\System32\drivers\pmxmouse.sys (Primax Electronics Ltd.)
DRV - (pmxusblf) -- C:\Windows\System32\drivers\pmxusblf.sys (Primax Electronics Ltd.)
DRV - (NPF) -- C:\Windows\System32\drivers\aztech_npf32.sys (CACE Technologies)
DRV - (giveio) -- C:\Windows\System32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...ie7&rlz=1I7DKUK
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7FDUM_enGB496
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google SSL"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "www.google.co.uk|www.ebay.co.uk|www.talkphotography.co.uk/forums/|www.giveawayoftheday.com|http://www.topcashback.co.uk|http://www.searchlotto.co.uk//index.php"
FF - prefs.js..extensions.enabledAddons: %7B11483926-db67-4190-91b1-ef20fcec5f33%7D:0.4.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: {11483926-db67-4190-91b1-ef20fcec5f33}:0.4.3
FF - prefs.js..extensions.enabledItems: {BC0AE9E6-E549-4554-A222-EA083A894683}:1.0.0.47
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.4
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@entriq.com/Download Manager Plugin Version Chk,version=3.8.2.9: C:\Program Files\Entriq\MediaSphere\3.8.2.9 [2008/07/24 16:59:53 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@entriq.com/Download Manager Plugin,version=3.8.2.9: C:\Program Files\Entriq\MediaSphere\3.8.2.9 [2008/07/24 16:59:53 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.11.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI7967~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Photosynth,version=2.0: C:\Program Files\Photosynth\npPhotosynthMozilla.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI7967~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.1.13: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.1.13: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.1.13: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.1.13: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.10: C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.3: C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wtPlugin,version=2.0.0.1: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\@entriq.com/Download Manager Plugin Version Chk,version=3.8.2.9: C:\Program Files\Entriq\MediaSphere\3.8.2.9 [2008/07/24 16:59:53 | 000,000,000 | ---D | M]
FF - HKCU\Software\MozillaPlugins\@entriq.com/Download Manager Plugin,version=3.8.2.9: C:\Program Files\Entriq\MediaSphere\3.8.2.9 [2008/07/24 16:59:53 | 000,000,000 | ---D | M]
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Charles\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\en.pixelplan.pl/PIXELPLANWebViewer: C:\Users\Charles\AppData\Roaming\Pixelplan\Pixelplan O4C Viewer Web\1.2.7\npPIXELPLANWebViewer.dll (Pixelplan S.C.)
FF - HKCU\Software\MozillaPlugins\wacom.com/WacomTabletPlugin: C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/08/05 22:13:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/18 22:06:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/18 22:06:49 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/18 22:06:51 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/01/18 22:06:49 | 000,000,000 | ---D | M]
[2008/07/16 18:43:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Extensions
[2010/08/08 20:29:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\89qxfs7x.test\extensions
[2010/08/08 20:29:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\89qxfs7x.test\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/08/08 20:29:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\89qxfs7x.test\extensions\staged-xpis
[2012/12/13 08:55:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions
[2012/08/05 22:13:35 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/06/21 22:50:22 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(14)
[2009/08/18 07:17:57 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(147)
[2009/11/21 08:47:16 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}(35)
[2009/03/18 13:40:42 | 000,019,153 | ---- | M] () (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\89qxfs7x.test\extensions\staged-xpis\{20a82645-c095-46ed-80e3-08825760534b}\MicrosoftDotNetFrameworkAssistant.xpi
[2012/12/13 08:55:25 | 002,151,598 | ---- | M] () (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\[email protected]
[2011/12/31 09:58:42 | 000,074,526 | ---- | M] () (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{11483926-db67-4190-91b1-ef20fcec5f33}.xpi
[2012/11/23 22:45:37 | 000,804,627 | ---- | M] () (No name found) -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2010/08/12 22:36:19 | 000,001,820 | ---- | M] () -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\searchplugins\bing.xml
[2012/12/08 14:10:49 | 000,002,641 | ---- | M] () -- C:\Users\Charles\AppData\Roaming\Mozilla\Firefox\Profiles\9kjkuxho.default\searchplugins\google-ssl.xml
[2013/01/18 22:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/01/18 22:06:48 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/01/18 22:06:51 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2013/01/11 15:12:58 | 000,001,738 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2013/01/11 15:12:58 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/01/11 15:12:58 | 000,001,148 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2013/01/11 15:12:58 | 000,001,379 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2013/01/11 15:12:58 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2013/01/11 15:12:58 | 000,001,334 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}&sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.52\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_4_402_287.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.52\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\24.0.1312.52\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI7967~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI7967~1\Office14\NPSPWRAP.DLL
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: getPlusPlus for Adobe 16248 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np_gp.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 6 U33 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.330.3 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: WacomTabletPlugin (Enabled) = C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files\TabletPlugins\npwacom.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Charles\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Pixelplan Web Viewer (Enabled) = C:\Users\Charles\AppData\Roaming\Pixelplan\Pixelplan O4C Viewer Web\1.2.7\npPIXELPLANWebViewer.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: ServiioTube = C:\Users\Charles\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakaojhfbcaonblkoflkbfjpmehpgmbc\1.3_0\
CHR - Extension: Adblock Plus = C:\Users\Charles\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.3.4_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Charles\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
O1 HOSTS File: ([2013/01/19 22:01:51 | 001,047,938 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 31489 more lines...
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office 2010\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [PMX Daemon] C:\Windows\System32\ico.exe (Primax Electronics Ltd.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [StartupDelayer] C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher.exe (r2 studios)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Windows7FirewallControl] C:\Program Files\Windows7FirewallControl\Windows7FirewallControl.exe (Sphinx Software)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-500675024-2545780642-2448618569-1000..\Run: [DriverMax_RESTART] File not found
O4 - Startup: C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O7 - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-500675024-2545780642-2448618569-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office 2010\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office 2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 2010\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 2010\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Expression\Web 2\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O9 - Extra 'Tools' menuitem : Sothink SWF Catcher - {E19ADC6E-3909-43E4-9A89-B7B676377EE3} - C:\Program Files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.11.2)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.11.2)
O16 - DPF: {E7637F18-B2C8-43E4-BCFE-BC3437DF469F} https://s.userzoom.com/s/UserZoom.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F46DDA2-E12C-4FF2-A700-9FA57281BE1A}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{542F07E1-2D71-4B25-92CA-08DBBBA83221}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\dellwall3.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\dellwall3.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office 2010\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 21:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2008/03/29 09:59:00 | 000,000,038 | ---- | M] () - L:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012/08/04 22:39:53 | 000,000,026 | ---- | M] () - M:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2010/02/15 03:53:50 | 000,000,027 | ---- | M] () - N:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2012/08/05 08:03:17 | 000,000,000 | RH-D | M] - S:\autorun -- [ NTFS ]
O32 - AutoRun File - [2012/08/05 09:31:48 | 000,000,041 | -H-- | M] () - S:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2008/05/05 13:14:18 | 000,000,025 | ---- | M] () - T:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{c3f35877-911d-11df-b30e-001d098948ac}\Shell - "" = AutoRun
O33 - MountPoints2\{c3f35877-911d-11df-b30e-001d098948ac}\Shell\AutoRun\command - "" = M:\sources\sperr32.exe x64
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/01/21 20:08:13 | 000,000,000 | ---D | C] -- C:\Users\Charles\AppData\Roaming\SUPERAntiSpyware.com
[2013/01/21 20:07:36 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2013/01/19 23:16:03 | 000,000,000 | ---D | C] -- C:\Users\Charles\LuminanceHDR
[2013/01/19 23:15:57 | 000,000,000 | ---D | C] -- C:\Program Files\Luminance HDR
[2013/01/18 22:06:48 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/01/15 22:19:07 | 000,000,000 | ---D | C] -- C:\Users\Charles\AppData\Roaming\XYplorer
[2013/01/15 22:19:02 | 000,000,000 | ---D | C] -- C:\Program Files\XYplorer
[2013/01/14 22:21:54 | 000,000,000 | ---D | C] -- C:\Users\Charles\Documents\Callum
[2013/01/12 09:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft
[2013/01/07 23:08:33 | 000,000,000 | ---D | C] -- C:\PhSp_CS2_UE_Ret
[2013/01/07 22:39:28 | 000,000,000 | ---D | C] -- C:\CS_2.0_WWE_Extras_2
[2013/01/03 22:54:33 | 000,000,000 | ---D | C] -- C:\Program Files\Two Pilots
[2013/01/03 22:54:32 | 000,000,000 | ---D | C] -- C:\Program Files\Retouch Pilot
[2012/12/31 13:06:27 | 000,000,000 | ---D | C] -- C:\Users\Charles\AppData\Roaming\vlc
[3 C:\Users\Charles\AppData\Roaming\*.tmp files -> C:\Users\Charles\AppData\Roaming\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/22 07:54:44 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/22 07:53:00 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/22 07:52:04 | 000,001,493 | -H-- | M] () -- C:\Users\Charles\Application Data\Microsoft\Internet Explorer\Quick Launch\tlbdata.xml
[2013/01/22 07:48:24 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/22 07:48:24 | 000,003,696 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/21 19:53:17 | 000,645,088 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/01/21 19:53:17 | 000,123,148 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/01/21 19:47:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/21 19:47:26 | 3219,312,640 | -HS- | M] () -- C:\hiberfil.sys
[2013/01/19 23:17:14 | 000,000,020 | ---- | M] () -- C:\ProgramData\PKP_DLbx.DAT
[2013/01/19 22:01:51 | 001,047,938 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2013/01/15 22:20:38 | 000,000,898 | ---- | M] () -- C:\Users\Charles\Application Data\Microsoft\Internet Explorer\Quick Launch\XYplorer.lnk
[2013/01/14 22:13:04 | 000,001,997 | ---- | M] () -- C:\Users\Charles\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/10 08:11:10 | 002,111,392 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/01/08 20:27:23 | 001,047,576 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130119-220150.backup
[2013/01/07 23:56:25 | 000,001,172 | ---- | M] () -- C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2013/01/05 12:30:25 | 000,000,020 | ---- | M] () -- C:\ProgramData\PKP_DLet.DAT
[2013/01/03 23:41:15 | 000,000,632 | RHS- | M] () -- C:\Users\Charles\ntuser.pol
[2012/12/29 14:21:28 | 000,000,844 | ---- | M] () -- C:\Users\Charles\Desktop\TeamViewer.lnk
[2012/12/28 10:21:08 | 001,047,576 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20130108-202723.backup
[3 C:\Users\Charles\AppData\Roaming\*.tmp files -> C:\Users\Charles\AppData\Roaming\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/01/15 22:20:38 | 000,000,898 | ---- | C] () -- C:\Users\Charles\Application Data\Microsoft\Internet Explorer\Quick Launch\XYplorer.lnk
[2013/01/11 15:06:58 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2013/01/08 23:14:30 | 000,001,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help Center.lnk
[2013/01/08 20:06:08 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS2.lnk
[2013/01/08 20:06:08 | 000,001,921 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady CS2.lnk
[2013/01/07 23:56:25 | 000,001,172 | ---- | C] () -- C:\Users\Charles\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2013/01/07 23:55:56 | 000,001,874 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge.lnk
[2012/12/29 14:21:28 | 000,000,844 | ---- | C] () -- C:\Users\Charles\Desktop\TeamViewer.lnk
[2012/12/03 23:12:32 | 000,000,376 | ---- | C] () -- C:\Users\Charles\AppData\Roaming\burnaware.ini
[2012/11/23 19:03:18 | 000,000,000 | ---- | C] () -- C:\ProgramData\SingleFiles
[2012/11/18 12:11:10 | 000,000,057 | ---- | C] () -- C:\ProgramData\Ament.ini
[2012/10/31 20:57:19 | 000,000,332 | -H-- | C] () -- C:\Users\Charles\AppData\Roaming\15a05a1824a8793fae296ac6f79b78023a0c9d3c
[2012/10/31 20:57:19 | 000,000,268 | ---- | C] () -- C:\ProgramData\15a05a1824a8793fae296ac6f79b78023a0c9d3c
[2012/09/15 08:09:15 | 000,000,094 | ---- | C] () -- C:\Users\Charles\AppData\Roaming\AlamySizeCheck Preferences
[2012/08/24 16:15:55 | 000,060,304 | ---- | C] () -- C:\Users\Charles\g2mdlhlpx.exe
[2012/08/22 20:31:21 | 000,037,585 | ---- | C] () -- C:\Users\Charles\avira.jpg
[2012/08/20 14:41:53 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\StatusSheet
[2012/08/20 14:41:53 | 000,000,268 | R--- | C] () -- C:\ProgramData\Strings
[2012/08/20 14:41:53 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLes.DAT
[2012/08/20 14:41:53 | 000,000,012 | R--- | C] () -- C:\ProgramData\Textures
[2012/08/20 14:41:12 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\Stingers
[2012/08/20 14:41:12 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\Static Library
[2012/08/20 14:41:12 | 000,000,268 | R--- | C] () -- C:\ProgramData\Super Strings
[2012/08/20 14:41:12 | 000,000,268 | R--- | C] () -- C:\ProgramData\String Ensemble
[2012/08/20 14:41:12 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLev.DAT
[2012/08/20 14:41:12 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLet.DAT
[2012/08/20 14:41:12 | 000,000,012 | R--- | C] () -- C:\ProgramData\Track Settings
[2012/08/20 14:40:55 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\Synth Textures
[2012/08/20 14:40:55 | 000,000,268 | R--- | C] () -- C:\ProgramData\Techno Kit
[2012/08/20 14:40:55 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLeo.DAT
[2012/08/20 14:40:55 | 000,000,012 | R--- | C] () -- C:\ProgramData\deskjet
[2012/08/11 07:10:44 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/09 21:44:27 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/08/07 16:37:41 | 000,000,193 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/07/04 05:09:18 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2012/07/04 01:32:18 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012/04/26 21:27:59 | 000,065,536 | -H-- | C] () -- C:\Windows\System32\WebCamLib.dll
[2012/03/16 21:16:00 | 022,657,871 | ---- | C] () -- C:\Users\Charles\frensham.psd
[2012/03/16 21:06:46 | 000,421,798 | ---- | C] () -- C:\Users\Charles\frensham7.jpg
[2012/03/16 21:05:36 | 000,463,452 | ---- | C] () -- C:\Users\Charles\frensham6.jpg
[2012/03/16 21:04:07 | 000,414,203 | ---- | C] () -- C:\Users\Charles\farnham6.jpg
[2012/03/16 20:27:18 | 000,317,484 | ---- | C] () -- C:\Users\Charles\farnham5.jpg
[2012/03/16 20:18:11 | 000,466,311 | ---- | C] () -- C:\Users\Charles\frensham4.jpg
[2012/03/16 20:17:41 | 000,487,535 | ---- | C] () -- C:\Users\Charles\frensham3.jpg
[2012/03/16 20:17:16 | 000,428,779 | ---- | C] () -- C:\Users\Charles\frensham2.jpg
[2012/03/16 20:16:50 | 000,481,327 | ---- | C] () -- C:\Users\Charles\frensham1.jpg
[2012/03/06 17:59:32 | 000,618,823 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012/02/24 21:43:28 | 000,652,243 | ---- | C] () -- C:\Users\Charles\catfood.pdf
[2012/01/12 23:08:30 | 000,212,420 | ---- | C] () -- C:\Users\Charles\tim label.jpg
[2012/01/12 23:08:12 | 000,699,792 | ---- | C] () -- C:\Users\Charles\tim label.psd
[2012/01/12 22:59:07 | 028,189,252 | ---- | C] () -- C:\Users\Charles\tim1.tif
[2012/01/12 22:49:54 | 001,483,292 | ---- | C] () -- C:\Users\Charles\tim1 copy.jpg
[2012/01/12 22:49:26 | 028,372,176 | ---- | C] () -- C:\Users\Charles\tim1.psd
[2012/01/09 22:51:48 | 000,166,141 | ---- | C] () -- C:\Users\Charles\2012-01-09_225141.jpg
[2012/01/08 22:51:39 | 000,180,094 | ---- | C] () -- C:\Users\Charles\excel.jpg
[2011/10/31 23:20:34 | 000,000,218 | ---- | C] () -- C:\Users\Charles\.recently-used.xbel
[2011/10/05 21:56:44 | 004,643,559 | ---- | C] () -- C:\Users\Charles\P1120593 edit4.jpg
[2011/10/05 21:28:31 | 004,605,156 | ---- | C] () -- C:\Users\Charles\P1120593 edit3.jpg
[2011/10/05 21:14:20 | 003,983,669 | ---- | C] () -- C:\Users\Charles\P1120593 edit2.jpg
[2011/10/05 19:46:37 | 003,131,077 | ---- | C] () -- C:\Users\Charles\P1120593 edit.jpg
[2011/09/12 22:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011/07/26 16:26:46 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011/07/26 16:26:46 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011/07/26 16:26:46 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011/07/26 16:26:46 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011/07/18 19:09:12 | 017,965,737 | ---- | C] () -- C:\Users\Charles\test2.nef
[2011/07/18 19:08:53 | 017,802,365 | ---- | C] () -- C:\Users\Charles\test1.nef
[2011/07/18 19:08:24 | 016,996,321 | ---- | C] () -- C:\Users\Charles\test.nef
[2011/06/27 17:14:29 | 000,000,412 | ---- | C] () -- C:\Users\Charles\AppData\Roaming\All CPU Meter_Settings.ini
[2011/04/27 20:06:38 | 000,134,080 | ---- | C] () -- C:\Windows\ColorPic Uninstaller.exe
[2010/04/23 15:47:35 | 000,013,646 | ---- | C] () -- C:\Users\Charles\backup.tabletprefs
[2010/03/06 18:02:34 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\Spacious
[2010/03/06 18:02:34 | 000,000,268 | R--- | C] () -- C:\ProgramData\Standard
[2010/03/06 18:02:34 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLdu.DAT
[2010/03/06 18:02:34 | 000,000,012 | R--- | C] () -- C:\ProgramData\String Comparison
[2009/07/27 22:24:23 | 000,208,771 | ---- | C] () -- C:\Users\Charles\vodafone.jpg
[2008/12/05 19:52:11 | 000,000,268 | RH-- | C] () -- C:\Users\Charles\AppData\Roaming\Audio
[2008/12/05 19:52:11 | 000,000,268 | R--- | C] () -- C:\ProgramData\Automatic Filter
[2008/12/05 19:44:30 | 000,000,020 | ---- | C] () -- C:\ProgramData\PKP_DLbx.DAT
[2008/06/17 22:37:31 | 000,000,582 | ---- | C] () -- C:\Users\Charles\AppData\Roaming\wklnhst.dat
[2008/06/11 17:19:17 | 000,001,356 | ---- | C] () -- C:\Users\Charles\AppData\Local\d3d9caps.dat
[2008/06/01 14:24:23 | 000,000,632 | RHS- | C] () -- C:\Users\Charles\ntuser.pol
[2008/05/30 22:42:00 | 000,053,760 | ---- | C] () -- C:\Users\Charles\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 12:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 17:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 06:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 06:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/09/24 14:49:32 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Alien Skin
[2009/02/27 16:47:30 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Ashampoo
[2012/09/25 14:30:59 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Audacity
[2012/12/14 16:17:37 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Canon
[2010/05/29 12:10:56 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\CPS Labs
[2009/04/06 08:49:59 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Expression Media 2
[2012/11/04 19:13:52 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\iSpring Solutions
[2008/05/20 22:31:00 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\LinkManager 4.0
[2009/02/07 20:10:46 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\NIKON
[2013/01/10 22:46:22 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\onOne Software
[2012/11/24 20:07:12 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\ProcessLasso
[2011/05/17 19:01:58 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Publish Providers
[2011/08/04 12:29:01 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Samsung
[2011/05/17 19:01:51 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Sony
[2012/08/22 16:09:10 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Unity
[2009/01/25 15:38:07 | 000,000,000 | ---D | M] -- C:\Users\Callum\AppData\Roaming\Xara
[2012/06/07 20:41:25 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\.mono
[2012/07/20 19:15:15 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Acronis
[2011/11/20 22:36:40 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Alien Skin
[2012/02/10 23:06:58 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Anthropics
[2011/11/26 22:33:00 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Anvsoft
[2012/04/26 21:27:59 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Apowersoft
[2011/10/26 22:54:33 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Ashampoo
[2012/09/15 22:35:00 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Audacity
[2009/11/06 23:05:08 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Auslogics
[2009/07/26 15:32:24 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\avidemux
[2012/04/18 21:51:04 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Bitmeter2
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Burn4U
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Byngo
[2012/12/14 17:07:59 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Canon
[2012/12/16 22:28:20 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\CD-LabelPrint
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\CodedColor
[2010/01/02 21:26:08 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\ColorCop
[2008/11/20 20:33:52 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/12/30 10:16:36 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\CoreFTP
[2008/07/09 21:31:56 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\CPS Labs
[2012/10/05 15:03:32 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Digiarty
[2008/05/25 21:15:29 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\DisplayTune
[2009/02/24 18:33:47 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Expression Media 2
[2010/08/11 21:46:58 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\fdrtools.com
[2013/01/13 23:01:14 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\FileZilla
[2011/03/26 17:55:00 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\FreeStone Group
[2010/07/21 22:49:50 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Genie-Soft
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\GetRightToGo
[2012/10/07 10:19:18 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\HandBrake
[2010/02/10 23:33:29 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\HDRsoft
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\HippoEDIT
[2012/08/05 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\IcoFX
[2010/02/07 08:29:05 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\ImgBurn
[2009/04/28 21:24:50 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Instant Housecall
[2012/10/31 20:57:43 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\iSpring Solutions
[2011/07/15 22:20:04 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\JAlbum
[2011/02/23 18:07:02 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Jalbum AB
[2008/07/14 18:52:55 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\JGsoft
[2011/12/27 17:40:51 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\KeePass
[2011/01/13 21:56:56 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Keynote Systems
[2010/01/06 12:55:38 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\kompozer.net
[2011/01/20 21:16:05 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Kristanix Software
[2012/08/05 09:35:46 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Leadertech
[2008/05/20 21:22:57 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\LinkManager 4.0
[2012/10/06 07:58:20 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\M8 Software
[2012/10/07 10:41:14 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\mkvtoolnix
[2011/01/19 20:39:36 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Morpheus Software
[2012/12/02 16:48:25 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\NeatImage SL 32
[2012/08/05 22:13:35 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\NetMeter
[2012/08/20 14:44:31 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Nikon
[2012/08/05 22:13:35 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\OneTouch 4.0
[2013/01/10 22:53:36 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\onOne Software
[2008/07/05 13:18:52 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Opera
[2012/08/05 22:13:35 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\PanoViewer
[2011/07/18 18:02:19 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Picturenaut
[2012/09/12 22:00:06 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Pixelplan
[2012/08/05 22:13:35 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Pixpedia Publisher
[2013/01/04 20:27:21 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\ProcessLasso
[2010/09/06 20:16:06 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Publish Providers
[2010/02/06 07:57:26 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\r2 Studios
[2008/12/30 20:29:12 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\RawTherapee
[2012/12/01 12:46:19 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\RetouchPilot
[2011/08/03 21:04:05 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Samsung
[2012/08/05 22:13:36 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Scribus
[2012/08/05 09:39:38 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Seagate
[2012/10/01 21:56:02 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Serif
[2010/09/10 17:54:36 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Sony
[2010/09/10 17:50:01 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Sony Creative Software Inc
[2012/10/12 13:09:33 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Spotify
[2012/12/29 14:20:29 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\TeamViewer
[2008/09/21 07:49:14 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Template
[2012/05/31 17:49:39 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Unity
[2012/12/14 17:24:29 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\uTorrent
[2008/09/18 21:08:10 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Xara
[2013/01/21 23:44:35 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\XYplorer
[2012/10/03 21:03:37 | 000,000,000 | ---D | M] -- C:\Users\Charles\AppData\Roaming\Zoner
[2013/01/10 22:47:46 | 000,000,000 | ---D | M] -- C:\Users\Email\AppData\Roaming\onOne Software
[2013/01/11 10:40:06 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\Canon
[2009/05/04 13:32:32 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\CPS Labs
[2009/04/13 18:09:19 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\Expression Media 2
[2008/05/20 21:59:04 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\LinkManager 4.0
[2009/08/18 16:19:59 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\NetMeter
[2011/09/29 16:42:30 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\NIKON
[2013/01/10 22:48:05 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\onOne Software
[2012/08/05 22:13:37 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\ProcessLasso
[2010/12/02 17:01:55 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\Publish Providers
[2010/12/02 17:01:49 | 000,000,000 | ---D | M] -- C:\Users\Kirstie\AppData\Roaming\Sony
[2012/12/14 22:01:06 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Canon
[2008/05/25 21:43:01 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\DisplayTune
[2012/08/05 22:13:39 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\IcoFX
[2008/08/29 20:55:22 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\JGsoft
[2008/05/20 22:38:32 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\LinkManager 4.0
[2009/08/18 15:45:57 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\NetMeter
[2009/12/09 09:14:33 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\NIKON
[2012/08/05 22:13:40 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\OneTouch 4.0
[2013/01/10 22:50:24 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\onOne Software
[2012/08/05 22:13:40 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\ProcessLasso
[2009/01/11 15:26:46 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Serif
[2010/05/30 19:41:28 | 000,000,000 | ---D | M] -- C:\Users\Rachel\AppData\Roaming\Zoner
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Web:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Updater:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Recipes:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Presentations:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\My Scanned Documents:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\My OneTouch Archive:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\My Google Gadgets:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\My Albums:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\MoviePlus:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Memberships:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Mail Attachments:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Hart:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Expression:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\Downloads:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\dixons order.jpg:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Charles\Documents\AdobeStockPhotos:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Program Files\Restore Point Shortcut:Roxio EMC Stream
@Alternate Data Stream - 332 bytes -> C:\ProgramData:iSpring Converter 6
@Alternate Data Stream - 194 bytes -> C:\ProgramData\TEMP:867C1254
@Alternate Data Stream - 193 bytes -> C:\ProgramData\TEMP:63CD0333
@Alternate Data Stream - 190 bytes -> C:\ProgramData\TEMP:335CB24A
@Alternate Data Stream - 184 bytes -> C:\ProgramData\TEMP:DCD39382
@Alternate Data Stream - 171 bytes -> C:\ProgramData\TEMP:F8B88761
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:CF778051
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >
Edited by f1charlie, 22 January 2013 - 03:43 AM.