OTL logfile created on: 1/23/2013 10:16:41 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\user\Desktop
Windows Vista Home Premium Edition (Version = 6.0.6000) - Type = NTWorkstation
Internet Explorer (Version = 7.0.6000.16982)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.87 Gb Total Physical Memory | 0.57 Gb Available Physical Memory | 30.57% Memory free
3.96 Gb Paging File | 2.07 Gb Available in Paging File | 52.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 291.83 Gb Total Space | 107.08 Gb Free Space | 36.69% Space Free | Partition Type: NTFS
Drive D: | 6.26 Gb Total Space | 0.88 Gb Free Space | 14.12% Space Free | Partition Type: NTFS
Computer Name: USER-PC | User Name: user | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/01/23 22:14:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
PRC - [2012/11/23 11:43:43 | 000,968,592 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2012/11/20 20:08:12 | 000,652,128 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/11/14 06:58:03 | 002,413,600 | ---- | M] () -- C:\ProgramData\PC Performer Manager\2.5.912.8\{16cdff19-861d-48e3-a751-d99a27784753}\pcpmngr.exe
PRC - [2012/11/02 04:10:42 | 013,538,584 | ---- | M] (Xportsoft Technologies) -- C:\Program Files\PC Optimizer Pro\PCOptimizerPro.exe
PRC - [2012/10/11 08:43:36 | 000,067,656 | ---- | M] (Simplygen) -- C:\Program Files\Protected Search\ProtectedSearch.exe
PRC - [2012/10/09 20:22:24 | 000,195,216 | ---- | M] (Smart PC Cleaner) -- C:\Program Files\Smart PC Cleaner\SPCSmartScan.exe
PRC - [2012/10/09 20:22:10 | 000,216,208 | ---- | M] (Smart PC Cleaner) -- C:\Program Files\Smart PC Cleaner\SPCReminder.exe
PRC - [2012/09/28 14:42:08 | 000,298,376 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
PRC - [2012/09/28 14:19:16 | 007,392,648 | ---- | M] (LeapFrog Enterprises, Inc.) -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe
PRC - [2012/07/11 14:37:12 | 000,138,096 | ---- | M] (Facebook Inc.) -- C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe
PRC - [2012/06/06 08:16:30 | 000,185,856 | ---- | M] () -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe
PRC - [2012/06/01 15:15:40 | 000,217,200 | ---- | M] (SPAMfighter ApS) -- C:\Program Files\Fighters\FULL-DISKfighter\Common Toolkit Tools.exe
PRC - [2012/05/10 13:11:24 | 001,267,264 | ---- | M] (SPAMfighter ApS) -- C:\Program Files\Fighters\FighterSuiteService.exe
PRC - [2012/05/04 10:58:08 | 001,226,240 | ---- | M] (Inbox.com, Inc.) -- C:\Program Files\RebateInformer\RebateInf.exe
PRC - [2012/04/23 13:07:52 | 000,326,504 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\driverscanner.exe
PRC - [2012/04/23 13:07:52 | 000,025,464 | ---- | M] (Uniblue Systems Limited) -- C:\Program Files\Uniblue\DriverScanner\dsmonitor.exe
PRC - [2012/03/20 12:49:09 | 000,126,392 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton PC Checkup\Engine\2.0.18.6\ccSvcHst.exe
PRC - [2012/03/20 12:47:32 | 000,123,320 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton PC Checkup\Engine\2.0.18.6\SymcPCCULaunchSvc.exe
PRC - [2012/02/23 20:20:28 | 007,697,496 | ---- | M] (MicroSmarts LLC.) -- C:\Program Files\SpeedItup Free\speeditupfree.exe
PRC - [2012/02/14 22:18:56 | 000,079,728 | ---- | M] (Driver-Soft Inc.) -- C:\Program Files\Driver-Soft\DriverGenius\StarterW3i.exe
PRC - [2012/02/10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE
PRC - [2012/02/10 10:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) -- C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE
PRC - [2012/01/18 17:36:46 | 001,452,680 | ---- | M] (SPAMfighter ApS) -- C:\Program Files\Fighters\Tray\FightersTray.exe
PRC - [2011/04/28 09:14:01 | 000,036,864 | ---- | M] (CouponAlert) -- C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe
PRC - [2011/04/28 09:14:01 | 000,027,648 | ---- | M] (CouponAlert) -- C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe
PRC - [2011/04/08 07:17:40 | 000,176,848 | ---- | M] (iWin Inc.) -- C:\Users\user\Jewel Quest Games\iWin Games\iWinTrusted.exe
PRC - [2010/11/02 21:06:06 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe
PRC - [2010/01/15 04:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
PRC - [2008/10/28 22:20:29 | 002,923,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2006/11/02 04:35:35 | 000,176,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wpcumi.exe
PRC - [2006/11/02 01:45:39 | 000,150,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\schtasks.exe
PRC - [2006/11/02 01:45:34 | 000,020,480 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RacAgent.exe
PRC - [2006/11/02 01:45:21 | 000,165,376 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lpksetup.exe
PRC - [2006/11/02 01:45:21 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\lpremove.exe
========== Modules (No Company Name) ==========
MOD - [2012/11/14 06:58:03 | 002,413,600 | ---- | M] () -- C:\ProgramData\PC Performer Manager\2.5.912.8\{16cdff19-861d-48e3-a751-d99a27784753}\pcpmngr.exe
MOD - [2012/11/14 06:56:36 | 002,148,896 | ---- | M] () -- c:\ProgramData\PC Performer Manager\2.5.912.8\{16cdff19-861d-48e3-a751-d99a27784753}\pcpmngr.dll
MOD - [2012/05/30 19:06:48 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/05/30 19:06:30 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/04/23 13:07:52 | 000,406,888 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\locale\en\en.dll
MOD - [2012/04/23 13:07:52 | 000,071,016 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\InstallerExtensions.dll
MOD - [2012/04/23 13:07:52 | 000,018,792 | ---- | M] () -- C:\Program Files\Uniblue\DriverScanner\cwebpage.dll
MOD - [2009/10/15 02:23:50 | 011,486,720 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\17f572b09facdc5fda9431558eb7a26e\mscorlib.ni.dll
========== Services (SafeList) ==========
SRV - [2012/11/20 20:08:12 | 000,652,128 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012/11/14 06:58:03 | 002,413,600 | ---- | M] () [Auto | Running] -- C:\ProgramData\PC Performer Manager\2.5.912.8\{16cdff19-861d-48e3-a751-d99a27784753}\pcpmngr.exe -- (PC Performer Manager)
SRV - [2012/09/28 14:19:16 | 007,392,648 | ---- | M] (LeapFrog Enterprises, Inc.) [Auto | Running] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/06/06 08:16:30 | 000,185,856 | ---- | M] () [Auto | Running] -- C:\Program Files\Web Assistant\ExtensionUpdaterService.exe -- (Web Assistant Updater)
SRV - [2012/06/01 15:15:40 | 000,217,200 | ---- | M] (SPAMfighter ApS) [On_Demand | Running] -- C:\Program Files\Fighters\FULL-DISKfighter\Common Toolkit Tools.exe -- (Common Toolkit Tools)
SRV - [2012/05/10 13:11:24 | 001,267,264 | ---- | M] (SPAMfighter ApS) [Auto | Running] -- C:\Program Files\Fighters\FighterSuiteService.exe -- (Suite Service)
SRV - [2012/03/20 12:49:09 | 000,126,392 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton PC Checkup\Engine\2.0.18.6\ccSvcHst.exe -- (PCCUJobMgr)
SRV - [2012/03/20 12:47:32 | 000,123,320 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton PC Checkup\Engine\2.0.18.6\SymcPCCULaunchSvc.exe -- (Norton PC Checkup Application Launcher)
SRV - [2012/02/10 10:28:06 | 000,240,408 | ---- | M] (Microsoft Corporation.) [On_Demand | Running] -- C:\Program Files\Microsoft\BingBar\7.1.361.0\SeaPort.EXE -- (BBUpdate)
SRV - [2012/02/10 10:28:06 | 000,193,816 | ---- | M] (Microsoft Corporation.) [Auto | Stopped] -- C:\Program Files\Microsoft\BingBar\7.1.361.0\BBSvc.EXE -- (BBSvc)
SRV - [2011/04/28 09:14:01 | 000,036,864 | ---- | M] (CouponAlert) [Auto | Running] -- C:\Program Files\CouponAlert_2p\bar\1.bin\2pbarsvc.exe -- (CouponAlert_2pService)
SRV - [2011/04/08 07:17:40 | 000,176,848 | ---- | M] (iWin Inc.) [Auto | Running] -- C:\Users\user\Jewel Quest Games\iWin Games\iWinTrusted.exe -- (iWinTrusted)
SRV - [2010/11/02 21:06:06 | 000,365,336 | ---- | M] (Kaspersky Lab ZAO) [Auto | Running] -- C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe -- (AVP)
SRV - [2010/10/12 09:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/01/15 04:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService)
SRV - [2008/03/18 15:52:32 | 000,020,480 | ---- | M] (Intuit) [Disabled | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2007/04/18 02:01:02 | 000,265,912 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2006/11/09 15:30:14 | 000,065,536 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2005/04/18 10:38:59 | 000,046,680 | R--- | M] (America Online) [On_Demand | Stopped] -- C:\Program Files\Common Files\aol\acs\AOLacsd.exe -- (AOL ACS)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2011/05/13 02:21:06 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus)
DRV - [2010/10/01 09:37:42 | 000,488,536 | ---- | M] (Kaspersky Lab) [File_System | System | Running] -- C:\Windows\System32\drivers\klif.sys -- (KLIF)
DRV - [2010/06/09 15:43:52 | 000,011,352 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\kl2.sys -- (kl2)
DRV - [2010/06/09 15:43:50 | 000,132,184 | ---- | M] (Kaspersky Lab ZAO) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\kl1.sys -- (KL1)
DRV - [2010/04/22 17:07:34 | 000,022,104 | ---- | M] (Kaspersky Lab ZAO) [Kernel | System | Running] -- C:\Windows\System32\drivers\klim6.sys -- (KLIM6)
DRV - [2009/11/02 18:27:16 | 000,019,984 | ---- | M] (Kaspersky Lab) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\klmouflt.sys -- (klmouflt)
DRV - [2009/10/09 21:23:06 | 000,033,792 | ---- | M] (Belcarra Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\btblan.sys -- (LeapFrog-USBLAN)
DRV - [2009/05/13 11:41:02 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscemdm.sys -- (sscemdm)
DRV - [2009/05/13 11:41:02 | 000,090,240 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscebus.sys -- (sscebus)
DRV - [2009/05/13 11:41:02 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscemdfl.sys -- (sscemdfl)
DRV - [2008/05/08 04:05:18 | 000,266,752 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSXHWBS2.sys -- (HSXHWBS2)
DRV - [2008/05/08 04:03:18 | 000,980,992 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HSX_DP.sys -- (HSF_DP)
DRV - [2007/10/18 06:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/07/06 20:15:00 | 007,568,832 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2007/06/18 20:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2007/05/04 01:29:10 | 001,065,384 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2005/12/12 08:27:00 | 000,019,072 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PS2.sys -- (Ps2)
DRV - [2003/01/10 13:13:04 | 000,033,588 | ---- | M] (America Online, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wanatw4.sys -- (wanatw)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.protec...e=true&tid=3026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.protec...e=true&tid=3026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.protec...rue&tid=3026&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.protec...e=true&tid=3026
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.protec...e=true&tid=3026
IE - HKLM\..\URLSearchHook: {238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files\WiseConvert\prxtbWise.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files\A_Free_Ride_Games_Bar\prxtbA_F0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}
IE - HKLM\..\SearchScopes\{2CC70DD6-A9A3-4A4E-837B-65604BE5B7B6}: "URL" = http://search.yahoo....ing}&fr=hp-pvdt
IE - HKLM\..\SearchScopes\{2F9692BA-B015-45C6-9E34-1076E967AE57}: "URL" = http://search.live.c...#38;FORM=HVDUS7
IE - HKLM\..\SearchScopes\{46247275-B91A-44B5-9D9F-144803602B5F}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpd
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3196716
IE - HKLM\..\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKLM\..\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.google.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Default_Page_URL = http://search.protec...e=true&tid=3026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsea...B&si=pconverter
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Bar = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Search Page = http://search.protec...rue&tid=3026&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Default_Page_URL = http://search.protec...e=true&tid=3026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = http://search.protec...e=true&tid=3026
IE - HKCU\..\URLSearchHook: {238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files\WiseConvert\prxtbWise.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files\A_Free_Ride_Games_Bar\prxtbA_F0.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {56256A51-B582-467e-B8D4-7786EDA79AE0}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylo...0000018f3f26cd3
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT3196716
IE - HKCU\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" = http://toolbar.inbox...id=80565&lng=en
IE - HKCU\..\SearchScopes\{cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8}: "URL" = http://search.mywebs...r={searchTerms}
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.Incre...IAXwR5Objl&i=38
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1167637.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@CouponAlert_2p.com/Plugin: C:\Program Files\CouponAlert_2p\bar\1.bin\NP2pStub.dll (CouponAlert)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@exent.com/npExentCtl,version=7.0.0.0: C:\Program Files\Free Ride Games\npExentCtl.dll (Exent Technologies Ltd.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.3: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\user\AppData\Roaming\Move Networks\plugins\npqmp071500000347.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files\MyWebSearch\bar\1.bin\NPMyWebS.dll File not found
FF - HKLM\Software\MozillaPlugins\@real.com/npracplug;version=1.0.0.0: C:\Program Files\Real\RealArcade\Plugins\Mozilla\npracplug.dll (RealNetworks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@TotalRecipeSearch_14.com/Plugin: C:\Program Files\TotalRecipeSearch_14\bar\1.bin\NP14Stub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@unity3d.com/UnityPlayer: C:\Program Files\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKLM\Software\MozillaPlugins\@VideoDownloadConverter_4z.com/Plugin: C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\NP4zStub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\[email protected]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files\Yahoo!\Common\npyaxmpb.dll File not found
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\user\AppData\Roaming\Move Networks\plugins\npqmp071500000347.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\user\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\user\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C176060C-6A46-4720-8BD5-23C0958ACE27}: C:\Users\user\AppData\Local\{C176060C-6A46-4720-8BD5-23C0958ACE27} [2010/01/07 17:54:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\2pffxtbr@CouponAlert_2p.com: C:\Program Files\CouponAlert_2p\bar\1.bin [2013/01/23 21:49:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\MyWebSearch\bar\1.bin [2013/01/23 21:55:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[email protected] [2011/07/16 19:33:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[email protected] [2011/07/16 19:33:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\FFExt\[email protected] [2011/07/16 19:33:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\14ffxtbr@TotalRecipeSearch_14.com: C:\Program Files\TotalRecipeSearch_14\bar\1.bin [2013/01/23 21:55:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/06/27 17:46:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\4zffxtbr@VideoDownloadConverter_4z.com: C:\Program Files\VideoDownloadConverter_4z\bar\1.bin [2013/01/23 21:55:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\user\AppData\Roaming\Move Networks [2009/06/06 08:04:56 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\user\AppData\Local\ArcadeCandy\[email protected] [2012/07/02 10:33:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{182812ed-1c22-4e1f-9a8d-990282d594da}: C:\ProgramData\PC Performer Manager\2.5.912.8\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/11/20 20:10:38 | 000,000,000 | ---D | M]
[2011/04/30 15:37:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Extensions
[2009/12/24 07:13:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Extensions\[email protected]
[2012/01/26 09:55:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\extensions
[2012/01/26 09:55:25 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\user\AppData\Roaming\Mozilla\Firefox\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2012/11/20 20:13:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
========== Chrome ==========
CHR - default_search_provider: ()
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.459_0\
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpimglhojapikoeeifcifanbeinephdm\2.3.10.3_0\
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjlkjjohncghchjiniokhljcgmlajgpb\1.6_0\
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnfegheljpcijmdgonkecjpcaopjlpac\1.22.359_0\
CHR - Extension: No name found = C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgafcinpmmpklohkojmllohdhomoefph\1.0_0\
O1 HOSTS File: ([2010/01/20 21:20:38 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Incredibar-Games EN Toolbar) - {238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll (Conduit Ltd.)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll File not found
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll (Babylon BHO)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (Protected Toolbar) - {61096323-3324-48fb-925b-4206f342e162} - C:\Users\user\AppData\Roaming\ProtectedToolbar\ProtectedToolbar.dll (Simplytech Ltd.)
O2 - BHO: (AppGraffiti) - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\Program Files\AppGraffiti\AppGraffiti.dll (Omega Partners Ltd)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Users\user\Jewel Quest Games\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (ArcadeCandy Games) - {AB6BD08C-DB6B-4F02-8A22-4BD343E990FF} - C:\Users\user\AppData\Local\ArcadeCandy\candyEX.dll (ArcadeCandy LLC)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (no name) - {CCB69577-088B-4004-9ED8-FF5BCC83A039} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O2 - BHO: (Inbox Toolbar) - {D3D233D5-9F6D-436C-B6C7-E63F77503B30} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O2 - BHO: (WeCareReminder Class) - {D824F0DE-3D60-4F57-9EB1-66033ECD8ABB} - C:\ProgramData\WeCareReminder\IEHelperv2.5.0.dll (We-Care.com)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (WiseConvert Toolbar) - {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files\WiseConvert\prxtbWise.dll (Conduit Ltd.)
O2 - BHO: (A Free Ride Games Bar Toolbar) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files\A_Free_Ride_Games_Bar\prxtbA_F0.dll (Conduit Ltd.)
O2 - BHO: (Yontoo) - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo\YontooIEClient.dll (Yontoo LLC)
O3 - HKLM\..\Toolbar: (Incredibar-Games EN Toolbar) - {238d4b4c-d63c-42a7-b6d8-dc96c8c0f5b9} - C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll File not found
O3 - HKLM\..\Toolbar: (VideoDownloadConverter) - {48586425-6bb7-4f51-8dc6-38c88e3ebb58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll File not found
O3 - HKLM\..\Toolbar: (Protected Toolbar) - {61096323-3324-48fb-925b-4206f342e162} - C:\Users\user\AppData\Roaming\ProtectedToolbar\ProtectedToolbar.dll (Simplytech Ltd.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\7.1.361.0\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (uTorrentBar Toolbar) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {D0F4A166-B8D4-48b8-9D63-80849FE137CB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O3 - HKLM\..\Toolbar: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKLM\..\Toolbar: (WiseConvert Toolbar) - {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - C:\Program Files\WiseConvert\prxtbWise.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (A Free Ride Games Bar Toolbar) - {f92a9fe4-2850-4198-b9d5-279880e49b16} - C:\Program Files\A_Free_Ride_Games_Bar\prxtbA_F0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Incredibar-Games EN Toolbar) - {238D4B4C-D63C-42A7-B6D8-DC96C8C0F5B9} - C:\Program Files\Incredibar-Games_EN\prxtbIncr.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\Spyware Doctor\BDT\PCTBrowserDefender.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (VideoDownloadConverter) - {48586425-6BB7-4F51-8DC6-38C88E3EBB58} - C:\Program Files\VideoDownloadConverter_4z\bar\1.bin\4zbar.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar Toolbar) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - C:\Program Files\uTorrentBar\prxtbuTor.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (BearShare MediaBar) - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll (BearShare)
O3 - HKCU\..\Toolbar\WebBrowser: (&Inbox Toolbar) - {D7E97865-918F-41E4-9CD0-25AB1C574CE8} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WiseConvert Toolbar) - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - C:\Program Files\WiseConvert\prxtbWise.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (A Free Ride Games Bar Toolbar) - {F92A9FE4-2850-4198-B9D5-279880E49B16} - C:\Program Files\A_Free_Ride_Games_Bar\prxtbA_F0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVP] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [CommonToolkitTray] C:\Program Files\Fighters\Tray\FightersTray.exe (SPAMfighter ApS)
O4 - HKLM..\Run: [CouponAlert_2p Browser Plugin Loader] C:\Program Files\CouponAlert_2p\bar\1.bin\2pbrmon.exe (CouponAlert)
O4 - HKLM..\Run: [Monitor] C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [NPSStartup] File not found
O4 - HKLM..\Run: [SpeetItUpFree] C:\Program Files\SpeedItup Free\speeditupfree.exe (MicroSmarts LLC.)
O4 - HKLM..\Run: [Starter] C:\Program Files\Driver-Soft\DriverGenius\StarterW3i.exe (Driver-Soft Inc.)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe File not found
O4 - HKCU..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\Launcher.exe (Uniblue Systems Limited)
O4 - HKCU..\Run: [Exetender] C:\Program Files\Free Ride Games\GPlayer.exe (Exent Technologies Ltd.)
O4 - HKCU..\Run: [Facebook Update] C:\Users\user\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [FDPRO-501] C:\Program Files\Fighters\FighterLauncher.exe (SPAMfighter ApS)
O4 - HKCU..\Run: [RebateInformer] C:\Program Files\RebateInformer\RebateInf.exe (Inbox.com, Inc.)
O4 - HKCU..\Run: [Smart PC Cleaner] C:\Program Files\Smart PC Cleaner\SPCLauncher.exe (Smart PC Cleaner)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MRI_DISABLED [2010/11/24 09:49:06 | 000,000,000 | -H-D | M]
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableStatusMessages = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra Button: &Virtual Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: buy-security-essentials.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: download-soft-package.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: download-software-package.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: get-key-se10.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: is-software-download.com ([]http in Trusted sites)
O16 - DPF: {00085C14-0000-0000-0000-000000000000} https://cwscp.sbcis....igInstaller.cab (Reg Error: Key error.)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455} (ExentInf Class)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D913DF22-085F-461E-9049-97410F6329D3}: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\inbox {37540F19-DD4C-478B-B2DF-C19281BCAF27} - C:\Program Files\Inbox Toolbar\Inbox.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll File not found
O18 - Protocol\Handler\rebinfo {AF808758-C780-404C-A4EE-4526323FD9B6} - C:\Program Files\RebateInformer\RebateI.dll (Inbox.com, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (c:\progra~2\pcperf~1\25912~1.8\{16cdf~1\pcpmngr.dll satulosu.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2011\mzvkbd3.dll (Kaspersky Lab ZAO)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\Userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\user\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/12/09 13:16:52 | 000,000,074 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{1a2154f5-139e-11df-acf4-00038a000015}\Shell - "" = AutoRun
O33 - MountPoints2\{1a2154f5-139e-11df-acf4-00038a000015}\Shell\AutoRun\command - "" = L:\NPSAI.exe
O33 - MountPoints2\{48fceae9-f01c-11dc-9c31-0018f3f26cd3}\Shell - "" = AutoRun
O33 - MountPoints2\{48fceae9-f01c-11dc-9c31-0018f3f26cd3}\Shell\AutoRun\command - "" = L:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk /p \??\K:)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/01/23 22:14:11 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2013/01/23 22:10:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Live Add-in
[2013/01/22 21:16:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/22 21:16:01 | 000,021,104 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/01/22 21:16:01 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2008/02/29 09:44:09 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/01/23 22:14:30 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\user\Desktop\OTL.exe
[2013/01/23 22:03:03 | 000,671,196 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/01/23 22:03:03 | 000,124,520 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/01/23 22:01:23 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/23 22:01:11 | 000,000,032 | ---- | M] () -- C:\ProgramData\ftstate.ini
[2013/01/23 22:01:04 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\PC Optimizer Pro startups.job
[2013/01/23 22:00:57 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/23 22:00:34 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\DriverScanner.job
[2013/01/23 21:55:38 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/23 21:55:37 | 000,003,456 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/23 21:55:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/01/23 21:42:25 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3573830000-260418385-2138264800-1000UA.job
[2013/01/23 20:13:02 | 000,000,270 | ---- | M] () -- C:\Windows\tasks\PC Performer_UPDATES.job
[2013/01/23 20:00:04 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\CandyUpdater.job
[2013/01/23 16:47:30 | 000,000,416 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{BA83A949-3E47-42DA-A9E5-9C3DE16332D1}.job
[2013/01/23 15:56:16 | 000,000,436 | ---- | M] () -- C:\Windows\tasks\PC Optimizer Pro Updates.job
[2013/01/23 15:42:03 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3573830000-260418385-2138264800-1000Core.job
[2013/01/23 15:01:44 | 000,000,262 | ---- | M] () -- C:\Windows\tasks\PC Performer_DEFAULT.job
[2013/01/23 06:58:10 | 000,001,957 | ---- | M] () -- C:\Users\user\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/22 14:23:00 | 000,000,434 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for user.job
[2013/01/22 11:00:11 | 000,000,404 | ---- | M] () -- C:\Windows\tasks\PC Optimizer Pro Scan.job
[2013/01/21 20:00:00 | 000,000,662 | ---- | M] () -- C:\Windows\tasks\Norton Internet Security - Run Full System Scan - user.job
[2013/01/12 22:58:56 | 000,000,556 | ---- | M] () -- C:\Windows\System32\MyDefrag.debuglog
[2013/01/11 03:22:36 | 000,000,318 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForuser.job
[2012/12/26 21:24:28 | 000,000,761 | ---- | M] () -- C:\Users\Public\Desktop\Play Pirate101.lnk
[2012/12/26 18:34:57 | 000,000,755 | ---- | M] () -- C:\Users\user\Desktop\Play Wizard101.lnk
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\Windows\System32\mobagudo
[2013/01/12 22:58:56 | 000,000,556 | ---- | C] () -- C:\Windows\System32\MyDefrag.debuglog
[2012/12/26 21:24:28 | 000,000,761 | ---- | C] () -- C:\Users\Public\Desktop\Play Pirate101.lnk
[2012/12/26 18:34:57 | 000,000,755 | ---- | C] () -- C:\Users\user\Desktop\Play Wizard101.lnk
[2012/12/03 16:53:59 | 000,000,032 | ---- | C] () -- C:\ProgramData\ftstate.ini
[2012/11/02 18:14:11 | 000,015,432 | ---- | C] () -- C:\Windows\Launcher.exe
[2012/07/02 16:15:12 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2012/05/01 20:03:13 | 000,000,552 | ---- | C] () -- C:\Users\user\AppData\Local\d3d8caps.dat
[2011/07/16 19:08:11 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2011/07/16 19:08:11 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2011/02/10 13:51:27 | 000,000,013 | ---- | C] () -- C:\Users\user\cvdm.err
[2010/04/20 15:17:45 | 000,000,632 | RHS- | C] () -- C:\Users\user\ntuser.pol
[2010/02/18 22:07:39 | 000,000,008 | ---- | C] () -- C:\Users\user\AppData\Roaming\wpp.exe
[2010/01/07 17:54:50 | 000,000,000 | ---- | C] () -- C:\Users\user\AppData\Local\Vkone.bin
[2010/01/07 17:54:48 | 000,000,120 | ---- | C] () -- C:\Users\user\AppData\Local\Btidejo.dat
[2009/12/01 09:42:41 | 000,027,150 | ---- | C] () -- C:\Users\user\AppData\Local\slot1.mm1
[2009/01/03 16:55:42 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\7340f9db2b8cbd45
[2009/01/03 16:55:37 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\c7a25efb5811a9ca
[2009/01/03 16:55:17 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\31554495acb84a74
[2009/01/03 16:54:17 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\aaed748a2b0c0a67
[2009/01/03 16:54:12 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\e0ec521d7ed9069a
[2008/12/26 15:31:55 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\c673d89093f6c494
[2008/12/26 15:23:04 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\2bb753373a9cc2a7
[2008/12/26 15:19:34 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\1e8607d712983b24
[2008/12/26 15:19:19 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\f927f14863fcf804
[2008/12/26 15:12:13 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\35c1a60090c47e0e
[2008/12/26 15:12:08 | 000,003,262 | ---- | C] () -- C:\Users\user\AppData\Roaming\198881056b266b47
[2008/12/23 17:30:38 | 000,000,165 | ---- | C] () -- C:\ProgramData\service.dat
[2008/08/26 00:03:01 | 000,007,268 | ---- | C] () -- C:\Users\user\AppData\Local\d3d9caps.dat
[2007/04/23 09:45:14 | 000,000,092 | ---- | C] () -- C:\Users\user\AppData\Local\fusioncache.dat
[2007/03/05 12:29:22 | 000,005,678 | ---- | C] () -- C:\Users\user\AppData\Roaming\wklnhst.dat
[2007/02/04 14:34:58 | 000,016,384 | ---- | C] () -- C:\Users\user\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 04:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2008/11/06 04:57:06 | 011,315,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/03/02 20:16:12 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2006/11/02 01:46:13 | 000,348,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== Alternate Data Streams ==========
@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:09CD1DC6
@Alternate Data Stream - 153 bytes -> C:\ProgramData\TEMP:F878F14A
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:4790A691
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FEB4D048
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:2530BFBE
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:F5D81BA1
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:F1020F9B
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:EF84937D
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:E6B3E318
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:8396B0AE
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:0E1DD4C5
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:F49E02D5
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:8DF2258A
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:501DF0E0
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:08390D61
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:FE49EF15
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EBDA021F
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:C76BA037
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:9A1A77DD
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:665C0715
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:407F3936
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:22910851
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:0C889ACE
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F24AD862
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C72A744C
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:8B09E09D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:678F890D
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:5E86F333
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:C5CE2DF6
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:AE531EFF
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:9F47F32C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:75A5CED2
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:6C1FEFDE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:3BA734DE
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:07F6D9E4
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:F5B3D15A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:E7730732
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C92A6B45
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:7434FA5A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:093F44E8
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:6F6F26B0
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:685F5579
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:679E30C6
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:F662888F
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:A46FE1DB
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:933604B8
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:B29E86D2
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:985F2B95
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:8164A00A
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:7CC16245
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:6348AC97
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:DB2BB17F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:ACE7A9BB
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:76C56CCB
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:51EFAA18
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E8382F78
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E21D3CA0
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:7BB47057
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:5BEA5951
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:15606AA7
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:07A0D262
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:A93A1878
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CBB4BFCD
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:94124B85
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:1C23B857
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:E3BD4B99
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D2A5A561
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:3FA3A49D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:335F49EA
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:172B8774
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:0E22C5DB
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:C81971AB
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:8B4640AA
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:FEB8979F
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:EF258AD5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:40464012
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8B2A48B2
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8459971E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:4F31D675
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:298B8F0F
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:20D4F98B
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:15B5F596
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:DADCBB58
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:A18D1A5B
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:53B5A0D5
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:52C5F022
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:33C6377A
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:2540E96D
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:B35A4CE2
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:9BAFBDA0
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:245D8023
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:243034F9
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:148B621E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:F71B881A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0407674B
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:66C6A515
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:4D3521E6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:16D21E17
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0E544CF5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:6A37FCC3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:3D4041D5
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:3D2D7F22
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:C3CB23B4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:AED4FFF5
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:68684FAE
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:0E660858
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:F0CAA752
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:E5DE9C8F
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:6A46CD9E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:0F83FB96
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:06E98522
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:D29B16C5
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:AA199F0F
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:5064C5F0
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:4A3B96F5
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:C62F5141
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9EBA3797
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3318EE32
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F6A0889A
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:CFF654D3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:7FC2B38E
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:E98B604F
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:7FD199E4
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:4C801DF0
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:3BB3AE6B
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:2E426A1F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:FE53E4F7
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:3BCA993F
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:1E93E0ED
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:F6C0CA66
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D387C245
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:4A0829E0
< End of report >