OTL logfile created on: 2/9/2013 9:12:24 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.97 Gb Total Physical Memory | 1.67 Gb Available Physical Memory | 56.43% Memory free
8.67 Gb Paging File | 7.46 Gb Available in Paging File | 86.08% Paging File free
Paging file location(s): C:\pagefile.sys 6000 8000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 464.19 Gb Total Space | 107.43 Gb Free Space | 23.14% Space Free | Partition Type: NTFS
Drive D: | 1.57 Gb Total Space | 1.54 Gb Free Space | 98.34% Space Free | Partition Type: FAT32
Drive F: | 1397.23 Gb Total Space | 1339.13 Gb Free Space | 95.84% Space Free | Partition Type: NTFS
Computer Name: COLINWS | User Name: Colin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/02/09 21:11:46 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\Downloads\OTL.exe
PRC - [2013/02/01 22:40:12 | 000,079,384 | ---- | M] (Google) -- C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2013/01/18 19:38:55 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/12/12 17:53:02 | 000,060,528 | ---- | M] (SparkLabs) -- C:\Program Files\WiTopia\WiTopiaService.exe
PRC - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) -- C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\ccsvchst.exe
PRC - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe
PRC - [2012/03/26 10:59:14 | 000,152,576 | ---- | M] (CrashPlan) -- C:\Program Files\CrashPlan\CrashPlanService.exe
PRC - [2012/03/26 10:58:47 | 000,217,088 | ---- | M] (Code 42 Software, Inc.) -- C:\Program Files\CrashPlan\CrashPlanTray.exe
PRC - [2011/12/16 13:21:12 | 000,246,688 | R--- | M] (Western Digital) -- C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe
PRC - [2011/12/16 13:21:10 | 001,687,968 | R--- | M] (Western Digital) -- C:\Program Files\Western Digital\WD Apps\WDDriveAutoUnlock.exe
PRC - [2011/12/15 09:25:30 | 001,091,992 | R--- | M] (Western Digital ) -- C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe
PRC - [2011/12/15 09:25:28 | 003,998,616 | R--- | M] (Western Digital Technologies, Inc.) -- C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe
PRC - [2011/12/15 09:25:28 | 001,591,176 | R--- | M] (Western Digital ) -- C:\Program Files\Western Digital\WD SmartWare\WDFME.exe
PRC - [2011/12/15 09:25:26 | 000,265,624 | R--- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe
PRC - [2010/07/08 07:28:56 | 000,815,704 | ---- | M] (GlavSoft LLC.) -- C:\Program Files\TightVNC\tvnserver.exe
PRC - [2010/02/09 16:15:26 | 000,135,168 | ---- | M] () -- C:\WINDOWS\system32\ChgService.exe
PRC - [2009/04/02 14:47:04 | 000,234,888 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
PRC - [2009/04/02 14:47:02 | 000,464,264 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe
PRC - [2009/03/27 06:47:56 | 000,027,184 | ---- | M] () -- C:\WINDOWS\snuvcdsm.exe
PRC - [2008/12/11 09:08:52 | 003,575,808 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
PRC - [2008/07/11 15:49:40 | 000,256,512 | ---- | M] (SafeBoot International) -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe
PRC - [2008/07/08 19:18:32 | 000,019,968 | ---- | M] (Hewlett-Packard Development Company, L.P) -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe
PRC - [2008/06/20 09:37:30 | 000,354,840 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/06/20 09:37:24 | 000,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/06/18 06:10:02 | 000,065,808 | ---- | M] (Bioscrypt Inc.) -- c:\Program Files\Hewlett-Packard\IAM\Bin\asghost.exe
PRC - [2008/06/12 13:21:06 | 001,164,536 | ---- | M] (AuthenTec, Inc.) -- c:\Program Files\Fingerprint Sensor\AtService.exe
PRC - [2008/04/13 18:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/18 09:27:12 | 000,013,312 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2008/02/02 02:20:34 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) -- C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe
PRC - [2007/05/15 17:08:40 | 000,182,576 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe
PRC - [2007/05/15 17:08:38 | 000,095,024 | ---- | M] (ActivIdentity) -- c:\Program Files\ActivIdentity\ActivClient\acevents.exe
PRC - [2007/05/15 17:08:08 | 000,293,168 | ---- | M] (ActivIdentity) -- C:\Program Files\ActivIdentity\ActivClient\accrdsub.exe
PRC - [2006/01/06 13:07:25 | 000,188,416 | ---- | M] (HP) -- C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
========== Modules (No Company Name) ==========
MOD - [2013/01/24 05:58:04 | 001,046,528 | ---- | M] () -- c:\Program Files\ZoomEx\sprotector.dll
MOD - [2013/01/18 19:38:55 | 003,022,232 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/01/10 01:32:22 | 001,218,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Management\51a269b672f2226acfedb5d35843a5c9\System.Management.ni.dll
MOD - [2013/01/10 01:31:01 | 000,148,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuratio#\5b41361ff2b03e15dde4b7c35e82c922\System.Configuration.Install.ni.dll
MOD - [2013/01/10 01:30:58 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\0cefa2c17df1d033e69ed47b0b660ce5\System.ServiceProcess.ni.dll
MOD - [2013/01/10 01:29:48 | 000,786,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\fa85c20ed3068cb8eac3c3e27be91dd6\System.EnterpriseServices.ni.dll
MOD - [2013/01/10 01:29:48 | 000,236,032 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\fa85c20ed3068cb8eac3c3e27be91dd6\System.EnterpriseServices.Wrapper.dll
MOD - [2013/01/10 01:29:44 | 000,646,656 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\04ec78afa0ff1951d16343e81b1228c6\System.Transactions.ni.dll
MOD - [2013/01/10 01:29:17 | 000,011,776 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\Microsoft.VisualC\1ad499733a6435ae1cc80d1e629ba561\Microsoft.VisualC.ni.dll
MOD - [2013/01/10 01:25:29 | 000,212,992 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\f43e890d874ef521aba51f76f64cd97b\System.ServiceProcess.ni.dll
MOD - [2013/01/10 01:24:54 | 000,998,400 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Management\1a6f9e23985e3159e6dd9827fd81c2fd\System.Management.ni.dll
MOD - [2013/01/10 00:16:41 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll
MOD - [2013/01/10 00:12:47 | 007,977,984 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll
MOD - [2013/01/10 00:12:25 | 011,492,352 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll
MOD - [2013/01/10 00:07:43 | 002,048,000 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2013/01/10 00:07:42 | 003,194,880 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2013/01/10 00:07:22 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2013/01/09 23:26:54 | 000,980,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\947b4fe468a1a03516ee26d9b3f4240a\System.Configuration.ni.dll
MOD - [2013/01/09 23:26:51 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\a23c39d504467a0024e5f20c0f962f3f\System.Xml.ni.dll
MOD - [2013/01/09 23:26:45 | 006,797,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\b450b06bded23f58b932084e2674baa9\System.Data.ni.dll
MOD - [2013/01/09 23:26:44 | 013,198,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\d47efad9d2f7f45b45204ae07079a94c\System.Windows.Forms.ni.dll
MOD - [2013/01/09 23:26:38 | 007,053,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\e773b94cc3f3fc25509904acb76cfe08\System.Core.ni.dll
MOD - [2013/01/09 23:26:34 | 001,667,584 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\307bb964c6b7dbc20676e8905ec99df9\System.Drawing.ni.dll
MOD - [2013/01/09 23:26:28 | 009,094,656 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\5f79b00e1aaeafcc07907aa61fd3599e\System.ni.dll
MOD - [2013/01/09 23:26:23 | 000,145,408 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Numerics\221d903193177a76f68965e8ffb8cbb4\System.Numerics.ni.dll
MOD - [2013/01/09 23:26:20 | 014,416,896 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\6a1ccc1e1a79ce267d3d1808af382cd6\mscorlib.ni.dll
MOD - [2013/01/08 22:45:50 | 014,586,888 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll
MOD - [2012/11/08 19:11:06 | 000,166,400 | ---- | M] () -- C:\Program Files\CrashPlan\cpnative.dll
MOD - [2012/03/26 10:58:51 | 000,013,312 | ---- | M] () -- C:\Program Files\CrashPlan\md5.dll
MOD - [2011/12/15 09:25:24 | 000,070,040 | R--- | M] () -- C:\Program Files\Western Digital\WD SmartWare\WDCollections.dll
MOD - [2011/11/03 09:28:36 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2010/11/04 08:51:44 | 000,555,624 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nvShell.dll
MOD - [2010/11/04 08:51:42 | 002,502,248 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\nView\nView.dll
MOD - [2010/11/02 07:33:58 | 000,886,272 | R--- | M] () -- C:\Program Files\Western Digital\WD SmartWare\System.Data.SQLite.dll
MOD - [2010/02/09 16:15:26 | 000,135,168 | ---- | M] () -- C:\WINDOWS\system32\ChgService.exe
MOD - [2009/04/02 14:47:04 | 000,234,888 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
MOD - [2009/04/02 14:47:02 | 000,464,264 | ---- | M] () -- C:\Program Files\AskBarDis\bar\bin\AskService.exe
MOD - [2009/03/27 06:47:56 | 000,027,184 | ---- | M] () -- C:\WINDOWS\snuvcdsm.exe
MOD - [2008/12/11 09:08:52 | 003,575,808 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe
MOD - [2008/04/13 18:12:03 | 000,562,176 | ---- | M] () -- C:\WINDOWS\system32\qedit.dll
MOD - [2008/04/13 18:12:03 | 000,192,512 | ---- | M] () -- C:\WINDOWS\system32\qcap.dll
MOD - [2008/04/13 18:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 18:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv)
SRV - [2013/02/09 21:09:24 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/18 19:38:55 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/12 17:53:02 | 000,060,528 | ---- | M] (SparkLabs) [Auto | Running] -- C:\Program Files\WiTopia\WiTopiaService.exe -- (WiTopiaService)
SRV - [2012/06/15 20:24:19 | 000,138,272 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\ccSvcHst.exe -- (N360)
SRV - [2012/05/04 19:29:46 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2012/04/21 16:16:06 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2012/03/26 10:59:14 | 000,152,576 | ---- | M] (CrashPlan) [Auto | Running] -- C:\Program Files\CrashPlan\CrashPlanService.exe -- (CrashPlanService)
SRV - [2011/12/16 13:21:12 | 000,246,688 | R--- | M] (Western Digital) [Auto | Running] -- C:\Program Files\Western Digital\WD Drive Manager\WDDriveService.exe -- (WDDriveService)
SRV - [2011/12/15 09:25:30 | 001,091,992 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WDRulesEngine.exe -- (WDRulesService)
SRV - [2011/12/15 09:25:28 | 001,591,176 | R--- | M] (Western Digital ) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WDFME.exe -- (WDFMEService)
SRV - [2011/12/15 09:25:26 | 000,265,624 | R--- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WDDMService.exe -- (WDDMService)
SRV - [2011/06/08 11:02:00 | 000,633,856 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/07/08 07:28:56 | 000,815,704 | ---- | M] (GlavSoft LLC.) [Auto | Running] -- C:\Program Files\TightVNC\tvnserver.exe -- (tvnserver)
SRV - [2010/06/21 10:00:24 | 000,037,888 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\personalVPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2010/02/09 16:15:26 | 000,135,168 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\ChgService.exe -- (Change Modem Device Service)
SRV - [2009/04/02 14:47:04 | 000,234,888 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe -- (ASKUpgrade)
SRV - [2009/04/02 14:47:02 | 000,464,264 | ---- | M] () [Auto | Running] -- C:\Program Files\AskBarDis\bar\bin\AskService.exe -- (ASKService)
SRV - [2008/12/11 09:08:52 | 003,575,808 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\Performance Drivers\nvPDsvc.exe -- (NVIDIA Performance Driver Service)
SRV - [2008/07/11 15:49:40 | 000,256,512 | ---- | M] (SafeBoot International) [Auto | Running] -- c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe -- (HpFkCryptService)
SRV - [2008/07/08 19:18:32 | 000,019,968 | ---- | M] (Hewlett-Packard Development Company, L.P) [Auto | Running] -- c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTChangeFilterService.exe -- (HP ProtectTools Service)
SRV - [2008/06/20 09:37:30 | 000,354,840 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
SRV - [2008/06/18 06:05:28 | 000,126,736 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll -- (ASBroker)
SRV - [2008/06/18 06:05:24 | 000,137,488 | ---- | M] (Bioscrypt Inc.) [Auto | Running] -- c:\Program Files\Hewlett-Packard\IAM\Bin\ASChnl.dll -- (ASChannel)
SRV - [2008/06/12 13:21:06 | 001,164,536 | ---- | M] (AuthenTec, Inc.) [Auto | Running] -- c:\Program Files\Fingerprint Sensor\AtService.exe -- (ATService)
SRV - [2008/03/18 09:27:12 | 000,013,312 | ---- | M] (Agere Systems) [Auto | Running] -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio)
SRV - [2008/02/02 02:20:34 | 000,144,672 | ---- | M] (Nuance Communications, Inc.) [Auto | Running] -- C:\Program Files\Nuance\PDF Professional 5\PDFProFiltSrv.exe -- (PDFProFiltSrv)
SRV - [2007/05/15 17:08:40 | 000,182,576 | ---- | M] (ActivIdentity) [Auto | Running] -- c:\Program Files\ActivIdentity\ActivClient\accoca.exe -- (accoca)
SRV - [2006/01/06 13:07:26 | 000,077,824 | ---- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\hphipm11.exe -- (Pml Driver HPH11)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\dwm3gmdm.sys -- (dwm3gmdm)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\Drivers\N360\0308000.029\ccHPx86.sys -- (ccHP)
DRV - [2013/02/01 21:22:35 | 000,097,440 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SMR311.SYS -- (SMR311)
DRV - [2013/01/16 06:36:26 | 001,603,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20130207.025\NAVEX15.SYS -- (NAVEX15)
DRV - [2013/01/16 06:36:26 | 000,093,296 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20130207.025\NAVENG.SYS -- (NAVENG)
DRV - [2013/01/15 20:51:12 | 000,997,464 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\BASHDefs\20130116.013\BHDrvx86.sys -- (BHDrvx86)
DRV - [2012/12/12 17:53:14 | 000,033,760 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\visctap0901.sys -- (visctap0901)
DRV - [2012/10/22 17:29:53 | 000,039,048 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tbhsd.sys -- (tbhsd)
DRV - [2012/10/22 17:29:38 | 000,031,848 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rrnetcap.sys -- (RRNetCapMP)
DRV - [2012/10/22 17:29:38 | 000,031,848 | ---- | M] (RapidSolution Software AG) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rrnetcap.sys -- (RRNetCap)
DRV - [2012/10/04 01:30:11 | 000,376,480 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys -- (eeCtrl)
DRV - [2012/09/26 20:57:12 | 000,020,032 | ---- | M] (Devguru Co., Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - [2012/09/06 04:54:30 | 000,373,728 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\IPSDefs\20130208.004\IDSXpx86.sys -- (IDSxpx86)
DRV - [2012/08/24 09:09:17 | 000,141,944 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2012/08/08 20:47:38 | 000,106,656 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2012/07/05 20:17:57 | 000,574,112 | ---- | M] (Symantec Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\srtsp.sys -- (SRTSP)
DRV - [2012/07/05 20:17:57 | 000,032,928 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\srtspx.sys -- (SRTSPX)
DRV - [2012/06/06 22:43:43 | 000,132,768 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\ccsetx86.sys -- (ccSet_N360)
DRV - [2012/05/21 19:37:12 | 000,924,320 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\symefa.sys -- (SymEFA)
DRV - [2012/04/17 20:13:32 | 000,388,216 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\symtdi.sys -- (SYMTDI)
DRV - [2012/04/17 20:13:31 | 000,044,024 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIMMP)
DRV - [2012/04/17 20:13:31 | 000,044,024 | R--- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SymIM.sys -- (SymIM)
DRV - [2012/04/17 20:13:22 | 000,340,088 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\symds.sys -- (SymDS)
DRV - [2012/04/17 19:42:14 | 000,149,624 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\N360\0604010.00E\ironx86.sys -- (SymIRON)
DRV - [2011/05/18 08:12:38 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/05/18 08:12:36 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/05/18 08:12:32 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/05/18 08:12:28 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/05/18 08:09:48 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2011/05/18 08:09:48 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/01/06 20:27:02 | 000,025,144 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\hpdskflt.sys -- (hpdskflt)
DRV - [2011/01/06 20:26:52 | 000,032,440 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Accelerometer.sys -- (Accelerometer)
DRV - [2010/09/01 09:30:16 | 004,221,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32)
DRV - [2010/06/30 02:27:08 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2010/06/21 10:02:26 | 000,024,960 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/02/25 00:02:56 | 000,014,904 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\CPQBttn.sys -- (HBtnKey)
DRV - [2009/12/17 11:22:52 | 000,103,424 | ---- | M] (Mobile Connector) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\cmnsusbser.sys -- (cmnsusbser)
DRV - [2009/10/20 18:47:46 | 000,113,280 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2009/10/12 15:21:54 | 000,100,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/09/10 14:55:52 | 000,102,528 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2009/03/27 06:48:22 | 001,810,992 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\snp2uvc.sys -- (SNP2UVC)
DRV - [2009/03/26 21:33:56 | 000,239,760 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\e1y5132.sys -- (e1yexpress)
DRV - [2009/01/03 01:40:12 | 000,039,304 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btcusb.sys -- (Btcsrusb)
DRV - [2008/11/21 21:53:40 | 001,204,128 | ---- | M] (Agere Systems) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2008/08/26 08:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/07/11 15:50:26 | 000,051,376 | ---- | M] (SafeBoot N.V.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SbAlg.sys -- (SbAlg)
DRV - [2008/07/11 15:50:22 | 000,012,928 | ---- | M] (SafeBoot International) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\SbFsLock.sys -- (SbFsLock)
DRV - [2008/07/11 15:50:20 | 000,012,496 | ---- | M] (SafeBoot International) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\rsvlock.sys -- (RsvLock)
DRV - [2008/07/11 15:50:18 | 000,109,184 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\SafeBoot.sys -- (SafeBoot)
DRV - [2008/06/24 09:55:12 | 000,047,104 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2008/06/12 15:40:50 | 000,477,696 | ---- | M] (AuthenTec, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ATSwpWDF.sys -- (ATSwpWDF)
DRV - [2008/05/14 02:08:16 | 000,074,688 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\btwusb.sys -- (BTWUSB)
DRV - [2008/05/14 02:08:14 | 000,879,624 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btkrnl.sys -- (BTKRNL)
DRV - [2008/05/14 02:08:14 | 000,037,424 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\btport.sys -- (BTDriver)
DRV - [2008/05/08 08:02:52 | 000,203,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/05/06 16:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/04/13 12:39:44 | 000,092,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2008/03/28 15:14:02 | 000,024,064 | ---- | M] (Sonic Focus, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sfaudio.sys -- (SFAUDIO)
DRV - [2007/07/30 05:54:02 | 000,038,400 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/07/30 04:42:58 | 000,043,008 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2007/06/18 18:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/04/04 13:16:20 | 000,041,216 | ---- | M] (Infineon Technologies AG) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ifxtpm.sys -- (IFXTPM)
DRV - [2006/12/19 19:08:00 | 000,047,616 | ---- | M] (RICOH Company, Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rismc32.sys -- (rismc32)
DRV - [2006/11/02 07:00:08 | 000,039,368 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\winusb.sys -- (WinUSB)
DRV - [2006/01/06 13:07:27 | 000,050,276 | ---- | M] (Hewlett-Packard) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hphs2k11.sys -- (Dot4Storage HPH11)
DRV - [2006/01/06 13:07:27 | 000,018,928 | ---- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hphius11.sys -- (Dot4Usb HPH11)
DRV - [2006/01/06 13:07:27 | 000,016,112 | ---- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hphipr11.sys -- (Dot4Print HPH11)
DRV - [2006/01/06 13:07:26 | 000,050,896 | ---- | M] (HP) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\hphid411.sys -- (Dot4 HPH11)
DRV - [2001/08/17 13:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/...bd-00216a5bec7a
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.c...07&gct=&gc=1&q=
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKLM\..\SearchScopes\{34A4B5D6-2538-45F9-9FA3-1F9040D274A8}: "URL" = http://slirsredirect...hpcmnbie7-en-us
IE - HKLM\..\SearchScopes\{9965BE24-3E2C-01FB-F8AB-B5B30973B7E7}: "URL" = ${SEARCH_URL}{searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://searchab.com/...bd-00216a5bec7a
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://vshare.toolbarhome.com/?hp=df
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
IE - HKCU\..\SearchScopes,DefaultScope = {9965BE24-3E2C-01FB-F8AB-B5B30973B7E7}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{0DE763AC-9EB3-48C5-9971-B01466147AB0}: "URL" = http://www.skip-sear...eferrer:source}
IE - HKCU\..\SearchScopes\{9965BE24-3E2C-01FB-F8AB-B5B30973B7E7}: "URL" = http://searchab.com/...q={searchTerms}
IE - HKCU\..\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}: "URL" = http://www.ask.com/w...il&geo=US&ver=5
IE - HKCU\..\SearchScopes\{C5902679-D24A-4BC0-AAA1-277D3173D04B}: "URL" = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "https://accounts.goo...//twitter.com/"
FF - prefs.js..extensions.enabledAddons: [email protected]:1.0
FF - prefs.js..extensions.enabledAddons: [email protected]:0.22
FF - prefs.js..extensions.enabledAddons: {ab91efd4-6975-4081-8552-1b3922ed79e2}:1.0.11.0
FF - prefs.js..extensions.enabledAddons: {ad48108d-92a6-4eb9-87e4-978aca1dbae4}:1.2.1
FF - prefs.js..extensions.enabledAddons: {ba14329e-9550-4989-b3f2-9732e92d17cc}:3.15.1.0
FF - prefs.js..extensions.enabledAddons: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.10
FF - prefs.js..extensions.enabledAddons: [email protected]:2.2.1.829
FF - prefs.js..extensions.enabledAddons: [email protected]:0.85.36
FF - prefs.js..extensions.enabledAddons: {64161300-e22b-11db-8314-0800200c9a66}:0.9.6.10
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:1.4
FF - prefs.js..extensions.enabledAddons: SkipScreen@SkipScreen:0.7.0
FF - prefs.js..extensions.enabledAddons: [email protected]:2.4.7.4
FF - prefs.js..extensions.enabledAddons: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.5.9
FF - prefs.js..extensions.enabledAddons: [email protected]:3.0.3
FF - prefs.js..extensions.enabledAddons: {5C46D283-ABDE-4dce-B83C-08881401921C}:2.1.7.1
FF - prefs.js..extensions.enabledAddons: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:11.1.1.5 - 2
FF - prefs.js..extensions.enabledAddons: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:2012.5.7.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {ba14329e-9550-4989-b3f2-9732e92d17cc}:2.7.2.0
FF - prefs.js..extensions.enabledItems: repagination@fremea:2010.4.11
FF - prefs.js..extensions.enabledItems: {ad48108d-92a6-4eb9-87e4-978aca1dbae4}:1.1.6
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.7.0.788
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: SkipScreen@SkipScreen:0.5.23s
FF - prefs.js..extensions.enabledItems: {4be68a18-deba-49e0-9e09-ee7796f3b62a}:2.1.1.1
FF - prefs.js..extensions.enabledItems: {902D2C4A-457A-4EF9-AD43-7014562929FF}:0.4.6
FF - prefs.js..extensions.enabledItems: {0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}:2.0.6
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {15a82062-5139-4855-9706-130a8a4be80c}:1.0.2
FF - prefs.js..extensions.enabledItems: {15e67a59-bd3d-49ae-90dd-b3d3fd14c2ed}:1.0.4
FF - prefs.js..extensions.enabledItems: [email protected]:0.79
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe80}:0.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: [email protected]:2.5.2
FF - prefs.js..extensions.enabledItems: {cf47767d-5f3a-4e32-9fce-5d79565c9702}:1.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.2
FF - prefs.js..extensions.enabledItems: {45e16761-660c-41a4-984f-56986fba2137}:1.0
FF - prefs.js..extensions.enabledItems: {1a0c9ebe-ddf9-4b76-b8a3-675c77874d37}:3.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.1
FF - prefs.js..extensions.enabledItems: [email protected]:0.6
FF - prefs.js..extensions.enabledItems: [email protected]:2.3.0
FF - prefs.js..keyword.URL: "http://search.condui...rchSource=2&q="
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.11.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Program Files\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Documents and Settings\Colin\Local Settings\Application Data\Citrix\Plugins\92\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\Colin\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Colin\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Colin\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=8: C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Update\1.2.183.39\npGoogleOneClick8.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\IPSFFPlgn\ [2012/08/24 09:15:55 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\coFFPlgn\ [2013/02/09 17:11:48 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/01/18 19:38:56 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/02/07 07:24:40 | 000,000,000 | ---D | M]
[2012/11/01 22:34:56 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Extensions
[2012/11/01 22:22:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions
[2012/11/01 22:22:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc}
[2013/02/01 22:49:28 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions
[2013/01/26 13:23:11 | 000,000,000 | ---D | M] (Zoomex) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2012/12/06 13:05:33 | 000,000,000 | ---D | M] (DoNotTrackMe) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/01/18 06:22:07 | 000,000,000 | ---D | M] (Diccionario en Español para Venezuela) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/01/20 15:52:04 | 000,000,000 | ---D | M] (HTTPS-Everywhere) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/01/25 08:27:46 | 000,000,000 | ---D | M] (MaskMe) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2012/10/20 09:33:30 | 000,375,322 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\[email protected]
[2012/10/18 18:16:35 | 000,071,037 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\[email protected]
[2012/11/01 13:36:56 | 000,372,140 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{5C46D283-ABDE-4dce-B83C-08881401921C}.xpi
[2012/10/09 20:34:56 | 000,281,285 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi
[2012/10/26 18:14:11 | 000,530,068 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/01/11 07:24:08 | 000,292,116 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{ad48108d-92a6-4eb9-87e4-978aca1dbae4}.xpi
[2012/07/25 14:26:25 | 000,741,958 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2011/10/31 19:18:12 | 000,434,392 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012/10/12 15:52:12 | 000,252,340 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2013/02/01 22:49:28 | 000,130,828 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2012/11/28 22:41:16 | 000,123,385 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/01/16 11:53:06 | 000,389,447 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/02/01 22:49:28 | 001,088,849 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]
[2013/01/31 13:19:04 | 000,533,536 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/02/01 21:16:29 | 000,817,973 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/12/05 09:11:56 | 000,007,919 | ---- | M] () (No name found) -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\x4qhwco5.default\extensions\[email protected]\chrome\content\ff\view_expiry.js
[2012/11/01 22:23:44 | 000,002,497 | ---- | M] () -- C:\Documents and Settings\Colin\Application Data\Mozilla\Firefox\Profiles\drfjkswk.default\searchplugins\safesearch.xml
[2013/01/18 19:38:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/01/23 22:14:30 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/02/09 21:12:39 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\updated\extensions
[2013/02/09 21:12:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\updated\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/02/09 21:12:44 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\updated\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2013/01/18 19:38:55 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/10/13 04:16:18 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/13 04:16:18 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
CHR - Extension: No name found = C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.6.10_0\
CHR - Extension: No name found = C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ojpijjmpahflnipadmlpgbjmagmjchkk\10.14.250.13_0\
CHR - Extension: No name found = C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\peaefoopkjmglhncadbjopnnolahchka\1.0_0\
CHR - Extension: No name found = C:\Documents and Settings\Colin\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2012/10/02 20:22:03 | 000,444,491 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com # Acrobat Pro 9.3 crack instruction
O1 - Hosts: 127.0.0.1 practivate.adobe.com # Acrobat Pro 9.3 crack instruction
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 15265 more lines...
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O2 - BHO: (ZeonIEEventHelper Class) - {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Credential Manager for HP ProtectTools) - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll (Bioscrypt Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Nuance PDF) - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\ShellBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\ShellBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360 Premier Edition\Engine\6.4.1.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O4 - HKLM..\Run: [accrdsub] c:\Program Files\ActivIdentity\ActivClient\accrdsub.exe (ActivIdentity)
O4 - HKLM..\Run: [CognizanceTS] c:\Program Files\Hewlett-Packard\IAM\Bin\ASTSVCC.dll (Bioscrypt Inc.)
O4 - HKLM..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\Cpqset.exe ()
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe (HP)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] nwiz.exe /install File not found
O4 - HKLM..\Run: [PTHOSTTR] c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [snuvcdsm] C:\WINDOWS\snuvcdsm.exe ()
O4 - HKLM..\Run: [WD Drive Unlocker] C:\Program Files\Western Digital\WD Apps\WDDriveAutoUnlock.exe (Western Digital)
O4 - HKLM..\Run: [WD Quick View] C:\Program Files\Western Digital\WD SmartWare\WDDMStatus.exe (Western Digital Technologies, Inc.)
O4 - HKCU..\Run: [Facebook Update] "C:\Documents and Settings\Colin\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver File not found
O4 - HKCU..\Run: [ManicTime] C:\Program Files\ManicTime\ManicTime.exe /minimized /name: File not found
O4 - HKCU..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CrashPlan Tray.lnk = C:\Program Files\CrashPlan\CrashPlanTray.exe (Code 42 Software, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AOL Toolbar Search - C:\Documents and Settings\All Users\Application Data\AOL\ieToolbar\resources\en-US\local\search.html File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html File not found
O8 - Extra context menu item: Append the content of the link to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append the content of the selected links to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Append to existing PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF file from the content of the link - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: Create PDF files from the selected links - C:\Program Files\Nuance\PDF Professional 5\bin\ZeonIEFavClient.dll (Zeon Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Open with Nuance PDF Converter 5.0 - C:\Program Files\Nuance\PDF Professional 5\cnvres_eng.dll ()
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51BCC468-189F-4E91-BD9E-0602145486D7}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\symres {AA1061FE-6C41-421f-9344-69640C9732AB} - C:\Program Files\Norton 360 Premier Edition\Engine\3.8.0.41\coIEPlg.dll File not found
O20 - AppInit_DLLs: (apshook.dll) - C:\WINDOWS\System32\APSHook.dll (Bioscrypt Inc.)
O20 - AppInit_DLLs: (c:\progra~1\zoomex\sprotector.dll) - c:\Program Files\ZoomEx\sprotector.dll ()
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ackpbsc: DllName - (c:\WINDOWS\system32\ackpbsc.dll) - C:\WINDOWS\system32\ackpbsc.dll (ActivIdentity)
O20 - Winlogon\Notify\acunlock: DllName - (c:\Program Files\ActivIdentity\ActivClient\acunlock.dll) - c:\Program Files\ActivIdentity\ActivClient\acunlock.dll (ActivIdentity)
O20 - Winlogon\Notify\OneCard: DllName - (c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll) - c:\Program Files\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll (Bioscrypt Inc.)
O24 - Desktop WallPaper: C:\WINDOWS\HP Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\HP Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/21 15:16:32 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O33 - MountPoints2\{143632f4-5038-11e1-8afa-00216a5bec7a}\Shell - "" = AutoRun
O33 - MountPoints2\{143632f4-5038-11e1-8afa-00216a5bec7a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{143632f4-5038-11e1-8afa-00216a5bec7a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{239cab92-8567-11df-ba92-00216a5bec7a}\Shell - "" = AutoRun
O33 - MountPoints2\{239cab92-8567-11df-ba92-00216a5bec7a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{239cab95-8567-11df-ba92-00216a5bec7a}\Shell - "" = AutoRun
O33 - MountPoints2\{239cab95-8567-11df-ba92-00216a5bec7a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{239cab95-8567-11df-ba92-00216a5bec7a}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{239caba9-8567-11df-ba92-00216a5bec7a}\Shell - "" = AutoRun
O33 - MountPoints2\{239caba9-8567-11df-ba92-00216a5bec7a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{239caba9-8567-11df-ba92-00216a5bec7a}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{3d7aea39-e7c9-11df-bac2-f0ef628e4734}\Shell - "" = AutoRun
O33 - MountPoints2\{3d7aea39-e7c9-11df-bac2-f0ef628e4734}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{3d7aea39-e7c9-11df-bac2-f0ef628e4734}\Shell\AutoRun\command - "" = F:\.\ShowModem.exe
O33 - MountPoints2\{424da702-8b2d-11e1-8b43-00216a5bec7a}\Shell - "" = AutoRun
O33 - MountPoints2\{424da702-8b2d-11e1-8b43-00216a5bec7a}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{424da702-8b2d-11e1-8b43-00216a5bec7a}\Shell\AutoRun\command - "" = F:\launcher.exe
O33 - MountPoints2\{6138be36-fdbf-11df-bacc-0025b3662948}\Shell - "" = AutoRun
O33 - MountPoints2\{6138be36-fdbf-11df-bacc-0025b3662948}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6138be36-fdbf-11df-bacc-0025b3662948}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{9355ca90-401c-11e0-bafb-00216a5bec7a}\Shell\AutoRun\command - "" = F:\Setup_FlipShare.exe
O33 - MountPoints2\{9355ca90-401c-11e0-bafb-00216a5bec7a}\Shell\Setup FlipShare\command - "" = F:\Setup_FlipShare.exe
O33 - MountPoints2\{94ada94f-e950-11df-bac3-0025b3662948}\Shell\AutoRun\command - "" = H:\setup.exe
O33 - MountPoints2\{94ada952-e950-11df-bac3-0025b3662948}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{dcb40d58-fd8e-11df-bac8-0025b3662948}\Shell - "" = AutoRun
O33 - MountPoints2\{dcb40d58-fd8e-11df-bac8-0025b3662948}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{dcb40d58-fd8e-11df-bac8-0025b3662948}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/09 10:46:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Local Settings\Application Data\Western_Digital
[2013/02/09 10:46:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Downloads
[2013/02/09 10:45:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Western Digital
[2013/02/09 10:45:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Western Digital
[2013/02/09 10:44:55 | 000,000,000 | ---D | C] -- C:\Program Files\Western Digital
[2013/02/09 10:44:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Western Digital
[2013/02/09 10:43:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Local Settings\Application Data\Western Digital
[2013/02/02 00:44:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2013/02/01 21:24:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SMR311
[2013/02/01 21:22:35 | 000,097,440 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SMR311.SYS
[2013/02/01 21:22:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Local Settings\Application Data\NPE
[2013/01/29 15:05:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Local Settings\Application Data\Citrix
[2013/01/26 13:22:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ClickIT
[2013/01/26 13:22:15 | 000,000,000 | ---D | C] -- C:\Program Files\ZoomEx
[2013/01/26 13:21:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Zoomex
[2013/01/25 22:49:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\CrashDump
[2013/01/22 20:31:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Desktop\2010_Queen of the Sun -
[2013/01/22 20:31:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Desktop\2012_Beasts Of The Southern Wild -
[2013/01/18 19:38:50 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/01/17 19:19:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Desktop\SolKwan_2012
[2013/01/17 19:17:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Colin\Desktop\Adriana's_130116
[4 C:\Documents and Settings\Colin\Desktop\*.tmp files -> C:\Documents and Settings\Colin\Desktop\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\*.tmp files -> C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/09 22:09:49 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/02/09 22:04:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/09 21:59:00 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3220099953-3417267552-1972214822-1005UA.job
[2013/02/09 19:21:00 | 000,000,998 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3220099953-3417267552-1972214822-1005UA.job
[2013/02/09 19:21:00 | 000,000,976 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3220099953-3417267552-1972214822-1005Core.job
[2013/02/09 17:21:02 | 000,491,153 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2013/02/09 17:09:26 | 000,000,514 | -H-- | M] () -- C:\WINDOWS\tasks\ZoomExUpdaterTask{9ADE6478-F570-41C2-9245-35459316C022}.job
[2013/02/09 17:08:55 | 000,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/02/09 17:08:22 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/09 17:08:13 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/02/09 17:08:05 | 3183,751,168 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/09 17:05:14 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2013/02/09 13:59:00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3220099953-3417267552-1972214822-1005Core.job
[2013/02/09 10:46:13 | 000,000,923 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WD SmartWare.lnk
[2013/02/09 10:45:25 | 000,000,904 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WD Security.lnk
[2013/02/09 10:45:11 | 000,000,841 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WD Drive Utilities.lnk
[2013/02/08 12:39:56 | 000,491,153 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2013/02/07 08:05:38 | 000,001,634 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CrashPlan Tray.lnk
[2013/02/06 11:20:24 | 000,002,004 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Norton 360 Premier Edition.LNK
[2013/02/06 11:18:51 | 000,719,647 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0604010.00E\Cat.DB
[2013/02/06 11:18:30 | 000,014,818 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0604010.00E\VT20130115.021
[2013/02/06 10:41:32 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Colin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2003.lnk
[2013/02/04 07:50:13 | 000,002,513 | ---- | M] () -- C:\Documents and Settings\Colin\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Excel 2003.lnk
[2013/02/02 12:12:06 | 000,040,707 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\Explain This [bleep].jpg
[2013/02/02 00:44:59 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2013/02/02 00:37:18 | 000,000,172 | ---- | M] () -- C:\WINDOWS\System32\drivers\N360\0604010.00E\isolate.ini
[2013/02/01 21:25:40 | 000,000,220 | RHS- | M] () -- C:\boot.ini
[2013/02/01 21:22:35 | 000,097,440 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SMR311.SYS
[2013/01/31 07:05:17 | 000,002,304 | ---- | M] () -- C:\Documents and Settings\Colin\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/01/26 19:32:18 | 000,014,359 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.pdf
[2013/01/26 18:58:44 | 000,012,668 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.jpg
[2013/01/26 16:14:27 | 000,028,672 | ---- | M] () -- C:\Documents and Settings\Colin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/01/26 16:13:11 | 000,025,513 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.png
[2013/01/23 17:06:23 | 166,208,064 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\The.Colbert.Report.2013.01.17.Akhil.Reed.Amar.HDTV.x264-LMAO.[VTV].mp4
[2013/01/23 16:59:22 | 139,606,670 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.17.Lena.Dunham.HDTV.x264-LMAO.[VTV].mp4
[2013/01/23 16:47:58 | 129,856,967 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.16.Jessica.Chastain.HDTV.x264-LMAO.[VTV].mp4
[2013/01/23 13:43:40 | 000,584,973 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\aug_31_2pm.JPG
[2013/01/23 13:43:12 | 000,550,387 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\aug_31_3pm.JPG
[2013/01/23 13:42:55 | 000,656,663 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\dec_21_2pm.JPG
[2013/01/23 13:42:39 | 000,552,817 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\dec_21_3pm.JPG
[2013/01/23 13:42:04 | 000,546,300 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\jun_21_2pm.JPG
[2013/01/23 13:41:34 | 000,546,300 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\jun_21_3pm.JPG
[2013/01/23 01:11:39 | 170,830,599 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\The.Colbert.Report.2013.01.15.Jared.Diamond.HDTV.x264-LMAO.[VTV].mp4
[2013/01/23 01:09:56 | 128,719,435 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.15.Bob.Schieffer.HDTV.x264-LMAO.[VTV].mp4
[2013/01/19 13:21:48 | 000,159,257 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\US Intervention Latin Am Caribbean.jpg
[2013/01/17 18:36:55 | 000,001,867 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\Kies Air Discovery Service.lnk
[2013/01/17 18:31:24 | 000,001,643 | ---- | M] () -- C:\Documents and Settings\Colin\Desktop\Samsung Kies (Lite).lnk
[4 C:\Documents and Settings\Colin\Desktop\*.tmp files -> C:\Documents and Settings\Colin\Desktop\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\*.tmp files -> C:\Documents and Settings\Colin\Desktop\Pueblo Verde House\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/09 10:46:13 | 000,000,923 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WD SmartWare.lnk
[2013/02/09 10:45:25 | 000,000,904 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WD Security.lnk
[2013/02/09 10:45:11 | 000,000,841 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WD Drive Utilities.lnk
[2013/02/07 08:05:38 | 000,001,634 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\CrashPlan Tray.lnk
[2013/02/06 11:20:24 | 000,002,004 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Norton 360 Premier Edition.LNK
[2013/02/02 12:12:05 | 000,040,707 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\Explain This [bleep].jpg
[2013/02/02 00:44:59 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2013/01/26 19:32:18 | 000,014,359 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.pdf
[2013/01/26 16:16:09 | 000,012,668 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.jpg
[2013/01/26 16:13:09 | 000,025,513 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\OpLastResort.png
[2013/01/26 13:22:35 | 000,000,514 | -H-- | C] () -- C:\WINDOWS\tasks\ZoomExUpdaterTask{9ADE6478-F570-41C2-9245-35459316C022}.job
[2013/01/23 11:28:39 | 000,656,663 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\dec_21_2pm.JPG
[2013/01/23 11:28:39 | 000,584,973 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\aug_31_2pm.JPG
[2013/01/23 11:28:39 | 000,552,817 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\dec_21_3pm.JPG
[2013/01/23 11:28:39 | 000,550,387 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\aug_31_3pm.JPG
[2013/01/23 11:28:39 | 000,546,300 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\jun_21_3pm.JPG
[2013/01/23 11:28:39 | 000,546,300 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\jun_21_2pm.JPG
[2013/01/20 23:39:34 | 166,208,064 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\The.Colbert.Report.2013.01.17.Akhil.Reed.Amar.HDTV.x264-LMAO.[VTV].mp4
[2013/01/20 23:38:17 | 170,830,599 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\The.Colbert.Report.2013.01.15.Jared.Diamond.HDTV.x264-LMAO.[VTV].mp4
[2013/01/20 23:31:43 | 139,606,670 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.17.Lena.Dunham.HDTV.x264-LMAO.[VTV].mp4
[2013/01/20 23:30:33 | 129,856,967 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.16.Jessica.Chastain.HDTV.x264-LMAO.[VTV].mp4
[2013/01/20 23:29:12 | 128,719,435 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\The.Daily.Show.2013.01.15.Bob.Schieffer.HDTV.x264-LMAO.[VTV].mp4
[2013/01/19 13:21:46 | 000,159,257 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\US Intervention Latin Am Caribbean.jpg
[2013/01/17 18:31:24 | 000,001,643 | ---- | C] () -- C:\Documents and Settings\Colin\Desktop\Samsung Kies (Lite).lnk
[2012/12/26 05:56:05 | 000,016,876 | ---- | C] () -- C:\Documents and Settings\Colin\.TransferManager.db
[2012/09/26 20:57:16 | 000,030,568 | ---- | C] () -- C:\WINDOWS\MusiccityDownload.exe
[2012/07/04 01:00:49 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Colin\wxDownloadFast.ini
[2012/06/26 16:02:38 | 000,974,848 | ---- | C] () -- C:\WINDOWS\System32\cis-2.4.dll
[2012/06/26 16:02:38 | 000,081,920 | ---- | C] () -- C:\WINDOWS\System32\issacapi_bs-2.3.dll
[2012/06/26 16:02:38 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\issacapi_pe-2.3.dll
[2012/06/26 16:02:38 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\issacapi_se-2.3.dll
[2012/04/21 18:13:58 | 001,270,829 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3220099953-3417267552-1972214822-1005-0.dat
[2012/04/21 18:13:57 | 000,321,746 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/02/16 12:01:49 | 000,060,304 | ---- | C] () -- C:\Documents and Settings\Colin\g2mdlhlpx.exe
[2012/02/14 21:59:40 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2011/07/27 12:11:10 | 000,000,214 | ---- | C] () -- C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2011/06/12 18:06:02 | 000,237,136 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb0.bin
[2011/06/12 18:06:00 | 000,237,136 | ---- | C] () -- C:\WINDOWS\System32\nvdrsdb1.bin
[2011/06/12 18:06:00 | 000,000,001 | ---- | C] () -- C:\WINDOWS\System32\nvdrssel.bin
[2011/05/18 21:10:58 | 000,001,940 | ---- | C] () -- C:\Documents and Settings\Colin\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/18 21:05:55 | 000,001,940 | ---- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/01/09 00:25:02 | 000,000,358 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2010/10/06 17:04:05 | 000,000,169 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2009/10/31 08:33:54 | 000,028,672 | ---- | C] () -- C:\Documents and Settings\Colin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/12 07:50:28 | 000,001,361 | ---- | C] () -- C:\Documents and Settings\Colin\cleaner-config.xml
[2009/08/12 07:50:28 | 000,000,709 | ---- | C] () -- C:\Documents and Settings\Colin\CommandDispatchers.xml
========== ZeroAccess Check ==========
[2004/08/07 07:09:18 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2011/09/05 07:56:22 | 001,510,400 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll -- [2009/02/09 06:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll -- [2008/04/13 18:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/04/21 17:05:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Autodesk
[2009/11/27 19:50:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2011/01/10 14:45:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/01/10 15:01:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonEPP
[2012/03/16 13:00:52 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2011/01/10 15:01:43 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2011/01/10 14:49:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJMSetup
[2011/01/10 15:11:11 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2011/01/10 14:49:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CanonIJWSpt
[2011/08/15 16:39:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cisco Systems
[2013/01/26 13:22:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ClickIT
[2012/08/09 20:37:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\CrashPlan
[2012/02/05 14:29:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DatacardService
[2010/08/31 19:45:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DriverScanner
[2010/12/24 09:07:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flip Video
[2011/09/12 14:07:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2013/01/26 13:22:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InstallMate
[2010/12/17 20:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IsolatedStorage
[2011/10/08 11:21:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2011/10/07 07:48:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2011/01/09 00:25:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nuance
[2012/07/03 23:24:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\OptimizerPro
[2011/09/12 13:34:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2011/06/12 16:15:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCSettings
[2013/01/26 13:22:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Premium
[2012/10/30 21:52:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RapidSolution
[2012/10/20 18:33:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Samsung
[2011/03/20 13:20:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2013/02/01 21:24:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SMR311
[2012/10/14 09:26:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Squeezebox
[2010/12/26 08:39:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2013/02/09 10:45:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Western Digital
[2012/07/04 00:02:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\wxDfast
[2012/07/03 23:47:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WxDFastUpdater
[2011/01/09 00:24:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zeon
[2013/01/29 11:27:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Zoomex
[2009/09/16 15:30:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
[2013/02/07 07:33:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Amazon
[2012/04/21 17:05:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Autodesk
[2013/02/04 00:13:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Azureus
[2010/01/02 15:14:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\BBCiPlayerDesktop.61DB7A798358575D6A969CCD73DDBBD723A6DA9D.1
[2011/01/10 15:11:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Canon
[2009/10/28 15:42:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\COWON
[2012/08/09 20:48:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\CrashPlan
[2009/10/08 10:31:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\dBpoweramp
[2009/10/10 18:41:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Desktopicon
[2013/02/07 06:22:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Dropbox
[2009/12/20 20:23:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\EPSON
[2013/01/25 22:48:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\foobar2000
[2009/09/28 09:00:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Fujitsu
[2009/08/02 02:03:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\GetRightToGo
[2009/09/28 08:28:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Leadertech
[2013/02/07 13:51:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Nokia
[2013/02/07 13:51:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Nokia Ovi Suite
[2012/06/27 19:38:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Oracle
[2011/02/04 08:34:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Participatory Culture Foundation
[2011/09/12 13:34:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\PC Suite
[2011/05/13 10:06:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\PCF-VLC
[2011/06/13 16:06:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\PFU
[2009/10/31 17:27:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\PPMate
[2009/12/20 10:53:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\ppStream
[2013/01/29 11:27:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\PriceGong
[2012/12/09 19:04:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Samsung
[2011/04/09 12:56:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\ScanSoft
[2011/06/22 11:27:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Tific
[2011/03/21 14:39:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\TightVNC
[2009/08/12 07:50:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Uniblue
[2012/12/13 19:13:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\WiTopia
[2011/01/09 00:27:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Colin\Application Data\Zeon
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0574215C
< End of report >