Two days ago I noticed that when I hovered over a link an advertisement box appeared. I do not remember which link that was. I was not concerned because I thought the problem was site-related.
But today I noticed the same problem again when I went to download "numba" to work with python. The site's address is
http://numba.pydata.org/
When I hover my mouse over the download link an "iPhona 5....etc." adv. appears. And if I click on the link (I did try that...) I am re-directed elsewhere.
Also a few minutes ago, in my attempt to reset password and sign in with you, as I clicked on the "proceed" button (if I recall) -I was trying to go to the page where I would change my old password-, instead of going to that page, a new quite suspicious page (copy of my yahoo mail) opened, beside the one that was already open. I closed it immediately of course.
Before contacting you, I tried to solve the problem with Malwarebytes, TDSSKiller and Microsoft Security Essentials. After conducting quick scans, the first two of them found something and deleted it. But the problem persists.
Thank you in advance for any help.
The OTL report is this:
OTL logfile created on: 17/2/2013 12:59:03 πμ - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\SR\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000408 | Country: Ελλάδα | Language: ELL | Date Format: d/M/yyyy
11,99 Gb Total Physical Memory | 9,83 Gb Available Physical Memory | 81,99% Memory free
23,98 Gb Paging File | 21,60 Gb Available in Paging File | 90,07% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 931,41 Gb Total Space | 414,70 Gb Free Space | 44,52% Space Free | Partition Type: NTFS
Drive E: | 931,51 Gb Total Space | 370,91 Gb Free Space | 39,82% Space Free | Partition Type: NTFS
Drive G: | 931,51 Gb Total Space | 856,75 Gb Free Space | 91,97% Space Free | Partition Type: NTFS
Computer Name: SR-PC | User Name: SR | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/02/17 00:58:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\SR\Downloads\OTL.exe
PRC - [2013/02/10 13:24:26 | 001,808,240 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_5_502_149.exe
PRC - [2013/02/06 15:44:30 | 000,917,400 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2013/01/31 10:38:54 | 003,289,208 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/08/17 16:22:06 | 000,207,163 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE expression.exe
PRC - [2012/08/17 16:21:27 | 000,207,163 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE smart.exe
PRC - [2012/08/14 18:28:22 | 000,207,127 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE down arrow.exe
PRC - [2012/08/14 18:28:13 | 000,207,125 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE up arrow.exe
PRC - [2012/08/14 18:28:03 | 000,207,127 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE left arrow.exe
PRC - [2012/08/14 18:27:54 | 000,207,129 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE right arrow.exe
PRC - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/03/19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2011/06/22 10:17:14 | 000,395,392 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2011/06/22 10:15:44 | 002,637,824 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe
PRC - [2010/01/11 21:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/09/08 09:48:55 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe
PRC - [2009/09/08 09:47:07 | 004,513,792 | ---- | M] (PostgreSQL Global Development Group) -- C:\Program Files (x86)\PostgreSQL\8.4\bin\postgres.exe
PRC - [2008/05/02 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
PRC - [2008/04/29 13:25:50 | 000,671,863 | ---- | M] (E-MU Systems) -- C:\Program Files (x86)\Creative Professional\E-MU PatchMix DSP\EmuPMixDSP.exe
PRC - [2008/03/20 15:35:04 | 000,023,040 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTHELPER.EXE
PRC - [2008/01/07 10:04:10 | 000,057,344 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\AstSrv.exe
========== Modules (No Company Name) ==========
MOD - [2013/02/10 13:24:26 | 014,586,736 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll
MOD - [2013/02/06 15:44:14 | 003,023,256 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2012/08/17 16:22:06 | 000,207,163 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE expression.exe
MOD - [2012/08/17 16:21:27 | 000,207,163 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE smart.exe
MOD - [2012/08/14 18:28:22 | 000,207,127 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE down arrow.exe
MOD - [2012/08/14 18:28:13 | 000,207,125 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE up arrow.exe
MOD - [2012/08/14 18:28:03 | 000,207,127 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE left arrow.exe
MOD - [2012/08/14 18:27:54 | 000,207,129 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE right arrow.exe
MOD - [2010/01/21 01:34:10 | 008,793,952 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2010/01/09 20:18:18 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2008/05/02 04:00:00 | 000,077,824 | ---- | M] () -- C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
========== Services (SafeList) ==========
SRV:64bit: - [2012/12/04 11:55:10 | 000,089,600 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files\PostgreSQL\9.2\bin\pg_ctl.exe -- (postgresql-x64-9.2)
SRV:64bit: - [2010/11/11 14:36:38 | 000,282,616 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2010/11/11 14:36:38 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2008/09/18 21:17:16 | 000,093,848 | ---- | M] (SiSoftware) [On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\RpcAgentSrv.exe -- (SandraAgentSrv)
SRV:64bit: - [2008/05/02 02:49:54 | 000,160,272 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2013/02/06 15:44:30 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/01/31 10:38:54 | 003,289,208 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/07/27 22:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/19 13:38:47 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2011/06/22 10:18:40 | 001,191,656 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 12:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/10 20:27:37 | 000,658,432 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/01/11 21:00:00 | 000,240,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2009/09/08 09:48:55 | 000,066,048 | ---- | M] (PostgreSQL Global Development Group) [Auto | Running] -- C:\Program Files (x86)\PostgreSQL\8.4\bin\pg_ctl.exe -- (postgresql-8.4)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/01/07 10:04:10 | 000,057,344 | ---- | M] () [Auto | Running] -- C:\Windows\SysWow64\\AstSrv.exe -- (Ast Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/11/29 11:50:06 | 000,073,552 | ---- | M] (Dataram, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RAMDiskVE.sys -- (RAMDiskVE)
DRV:64bit: - [2011/11/03 02:01:00 | 000,056,208 | ---- | M] (Rovi Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2011/10/18 12:07:39 | 000,971,360 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2011/10/18 12:07:23 | 000,210,016 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vididr.sys -- (vididr)
DRV:64bit: - [2011/10/18 12:07:20 | 000,141,920 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vsflt53.sys -- (vidsflt53)
DRV:64bit: - [2011/10/18 12:07:18 | 000,275,552 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2010/10/24 21:25:38 | 000,072,064 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2010/04/27 15:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)
DRV:64bit: - [2010/04/27 15:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)
DRV:64bit: - [2010/04/27 13:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)
DRV:64bit: - [2010/04/27 13:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)
DRV:64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:64bit: - [2009/08/07 22:46:56 | 000,023,112 | ---- | M] (SiSoftware) [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2011.SP5\WNt500x64\sandra.sys -- (SANDRA)
DRV:64bit: - [2009/07/14 03:52:21 | 000,106,576 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2009/07/14 03:52:21 | 000,028,752 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 22:35:33 | 000,389,120 | ---- | M] (Marvell) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2008/03/26 15:55:00 | 000,033,792 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64modem.sys -- (USBModem)
DRV:64bit: - [2008/03/26 15:55:00 | 000,027,136 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64diag.sys -- (UsbDiag)
DRV:64bit: - [2008/03/26 15:55:00 | 000,017,408 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lgx64bus.sys -- (usbbus)
DRV:64bit: - [2008/03/20 18:03:20 | 001,020,952 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HA10KX2K.SYS -- (ha10kx2k)
DRV:64bit: - [2008/03/20 18:02:50 | 000,118,296 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\EMUPIA2K.SYS -- (emupia)
DRV:64bit: - [2008/03/20 18:01:52 | 000,213,016 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTSFM2K.SYS -- (ctsfm2k)
DRV:64bit: - [2008/03/20 18:01:14 | 000,015,896 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTPRXY2K.SYS -- (ctprxy2k)
DRV:64bit: - [2008/03/20 18:00:48 | 000,178,712 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTOSS2K.SYS -- (ossrv)
DRV:64bit: - [2008/03/20 17:59:14 | 000,684,440 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTAUD2K.SYS -- (ctaud2k)
DRV:64bit: - [2008/03/20 17:58:32 | 000,580,632 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAC32K.SYS -- (ctac32k)
DRV:64bit: - [2008/03/20 17:47:52 | 001,417,752 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.SYS -- (CTEXFIFX.SYS)
DRV:64bit: - [2008/03/20 17:47:52 | 001,417,752 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.SYS -- (CTEXFIFX)
DRV:64bit: - [2008/03/20 17:46:40 | 000,158,232 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEDSPIO.SYS -- (CTEDSPIO.SYS)
DRV:64bit: - [2008/03/20 17:46:40 | 000,158,232 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEDSPIO.SYS -- (CTEDSPIO)
DRV:64bit: - [2008/03/20 17:46:14 | 000,338,456 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEDSPSY.SYS -- (CTEDSPSY.SYS)
DRV:64bit: - [2008/03/20 17:46:14 | 000,338,456 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEDSPSY.SYS -- (CTEDSPSY)
DRV:64bit: - [2008/03/20 17:45:48 | 000,094,744 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.SYS -- (CTHWIUT.SYS)
DRV:64bit: - [2008/03/20 17:45:48 | 000,094,744 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.SYS -- (CTHWIUT)
DRV:64bit: - [2008/03/20 17:45:24 | 000,202,776 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.SYS -- (CT20XUT.SYS)
DRV:64bit: - [2008/03/20 17:45:24 | 000,202,776 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.SYS -- (CT20XUT)
DRV:64bit: - [2008/03/20 17:44:44 | 000,116,248 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.SYS -- (CTERFXFX.SYS)
DRV:64bit: - [2008/03/20 17:44:44 | 000,116,248 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTERFXFX.SYS -- (CTERFXFX)
DRV:64bit: - [2008/03/20 17:44:12 | 000,287,256 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEDSPFX.SYS -- (CTEDSPFX.SYS)
DRV:64bit: - [2008/03/20 17:44:12 | 000,287,256 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEDSPFX.SYS -- (CTEDSPFX)
DRV:64bit: - [2008/03/20 17:43:44 | 000,187,416 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEAPSFX.SYS -- (CTEAPSFX.SYS)
DRV:64bit: - [2008/03/20 17:43:44 | 000,187,416 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEAPSFX.SYS -- (CTEAPSFX)
DRV:64bit: - [2008/03/20 17:42:34 | 000,589,848 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTSBLFX.SYS -- (CTSBLFX.SYS)
DRV:64bit: - [2008/03/20 17:42:34 | 000,589,848 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTSBLFX.SYS -- (CTSBLFX)
DRV:64bit: - [2008/03/20 17:42:04 | 000,588,824 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAUDFX.SYS -- (CTAUDFX.SYS)
DRV:64bit: - [2008/03/20 17:42:04 | 000,588,824 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTAUDFX.SYS -- (CTAUDFX)
DRV:64bit: - [2008/03/20 17:41:06 | 000,123,928 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\COMMONFX.SYS -- (COMMONFX.SYS)
DRV:64bit: - [2008/03/20 17:41:06 | 000,123,928 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\COMMONFX.SYS -- (COMMONFX)
DRV:64bit: - [2008/02/29 03:16:52 | 000,057,360 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2008/02/29 03:16:44 | 000,054,800 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2007/01/26 10:04:36 | 000,009,600 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\whfltr2k.sys -- (whfltr2k)
DRV:64bit: - [2005/03/29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.comoestamos.com/search/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.comoestamos.com/search/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.comoestamos.com/search/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comoestamos.com/search/
IE - HKLM\..\SearchScopes,DefaultScope = {76434FE2-B79A-4DFE-A374-D716B8B03CF7}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{081230F8-EA50-42A9-983C-D22ABC2EED3B}: "URL" = http://www.qemit.com...q={searchTerms}
IE - HKLM\..\SearchScopes\{76434FE2-B79A-4DFE-A374-D716B8B03CF7}: "URL" = http://www.comoestam...q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.comoestamos.com/search/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...&ctid=CT2269050
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.comoestamos.com/search/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = el
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 69 32 7B 94 1A A7 CA 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{081230F8-EA50-42A9-983C-D22ABC2EED3B}: "URL" = http://www.qemit.com...q={searchTerms}
IE - HKCU\..\SearchScopes\{76434FE2-B79A-4DFE-A374-D716B8B03CF7}: "URL" = http://www.comoestam...q={searchTerms}
IE - HKCU\..\SearchScopes\{8A5A76FE-6433-46AD-8367-F875F4D51E63}: "URL" = http://search.yahoo....p={searchTerms}
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2269050
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultthis.engineName: "Search"
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=971163"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledAddons: el-en%40dictionaries.addons.mozilla.org:0.5.5
FF - prefs.js..extensions.enabledAddons: %7BACAA314B-EEBA-48e4-AD47-84E31C44796C%7D:4.2.1.9
FF - prefs.js..extensions.enabledAddons: addon%40freecorder.com:7.0.0.12
FF - prefs.js..extensions.enabledAddons: %7B317B5128-0B0B-49b2-B2DB-1E7560E16C74%7D:2.8.7
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0037-ABCDEFFEDCBA%7D:6.0.37
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0039-ABCDEFFEDCBA%7D:6.0.39
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:18.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [email protected]:0.5.5
FF - prefs.js..extensions.enabledItems: {317B5128-0B0B-49b2-B2DB-1E7560E16C74}:2.7.1
FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.2.0.7165
FF - prefs.js..keyword.URL: "http://www.google.co...ient&gfns=1&q="
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_149.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_149.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_39: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files (x86)\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files (x86)\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/10/11 20:51:21 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/02/06 15:44:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 18.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/02/06 15:44:10 | 000,000,000 | ---D | M]
[2010/02/06 12:55:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\SR\AppData\Roaming\Mozilla\Extensions
[2013/02/17 00:17:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions
[2013/01/27 02:30:01 | 000,000,000 | ---D | M] (SeoQuake) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2013/01/26 00:13:40 | 000,000,000 | ---D | M] (Freecorder) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\[email protected]
[2011/01/22 14:50:35 | 000,000,000 | ---D | M] (Greek-English Spelling dictionary) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\[email protected]
[2012/05/21 00:15:26 | 000,000,000 | ---D | M] (Lavasoft Search Plugin) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\jid1-yZwVFzbsyfMrqQ@jetpack
[2012/12/19 01:10:02 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\[email protected]
[2012/12/12 13:47:00 | 000,036,098 | ---- | M] () (No name found) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
[2013/02/17 00:17:23 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2010/02/21 13:25:00 | 000,000,873 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\searchplugins\conduit.xml
[2012/01/13 18:22:34 | 000,002,057 | ---- | M] () -- C:\Users\SR\AppData\Roaming\Mozilla\Firefox\Profiles\y4rlmwp7.default\searchplugins\youtube-video-search.xml
[2013/02/06 15:44:08 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/02/06 15:44:08 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/02/06 15:44:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/02/06 15:44:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/02/06 15:44:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA}
[2013/02/06 15:44:04 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\Adobe_Photoshop_CS5_Portable_YeNiCeRi\Adobe Photoshop CS5\Plug-ins\Extensions
[2013/02/06 15:44:30 | 000,262,552 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/02/22 22:50:51 | 000,061,848 | ---- | M] (WebEx Communications, Inc) -- C:\Program Files (x86)\mozilla firefox\plugins\npatgpc.dll
[2012/09/13 23:29:12 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/10/13 19:27:54 | 000,002,058 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60129.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\24.0.1312.56\pdf.dll
CHR - plugin: ActiveTouch General Plugin Container (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npatgpc.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files (x86)\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files (x86)\Veetle\plugins\npVeetle.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\SR\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: Skype Click to Call = C:\Users\SR\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.5.0.11422_0\
CHR - Extension: Poppit = C:\Users\SR\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2012/08/28 21:15:57 | 000,004,534 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O1 - Hosts: 127.0.0.1 ci-main.loginregistration.eadm.ea.com
O1 - Hosts: 127.0.0.1 motd.dm.origin.com
O1 - Hosts: 127.0.0.1 store.origin.com
O1 - Hosts: 127.0.0.1 drh.img.digitalriver.com
O1 - Hosts: 86 more lines...
O2:64bit: - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HelperObject Class) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\SnagIt 7\SnagItBHO.dll (TechSmith Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Freecorder extension) - {B15BBE59-42F5-4206-B3F0-BE98F5DC4B93} - C:\Program Files (x86)\Freecorder extension\ScriptHost.dll (Applian Technologies Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (SnagIt) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\SnagIt 7\SnagItIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {081230F8-EA50-42A9-983C-D22ABC2EED3B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4:64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AsioThk32Reg] C:\Windows\SysWow64\CTASIO.DLL (Creative Technology Ltd)
O4 - HKLM..\Run: [CTHelper] C:\Windows\SysWow64\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\CTXFIHLP.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis)
O4 - HKLM..\Run: [WheelMouse] C:\Advanced Wheel Mouse\wh_exec.exe ()
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE down arrow.exe ()
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE expression.exe ()
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE left arrow.exe ()
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE right arrow.exe ()
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE smart.exe ()
O4 - Startup: C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\FINALE up arrow.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: E&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8:64bit: - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\SR\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&ξαγωγή στο Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\SR\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-0016-0000-0039-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_39)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_39)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{668CA91D-EF0A-4635-B961-6FDCD15D3205}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{913617FE-775B-4717-A72D-0EB92080F057}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{fdb5269d-1349-11df-a3b6-90e6ba888201}\Shell - "" = AutoRun
O33 - MountPoints2\{fdb5269d-1349-11df-a3b6-90e6ba888201}\Shell\AutoRun\command - "" = F:\Installer.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/16 23:20:02 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Malwarebytes
[2013/02/16 23:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/02/16 23:19:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2013/02/16 23:19:39 | 000,024,176 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2013/02/16 23:19:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/02/07 03:22:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PureSync
[2013/02/06 15:44:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/02/06 02:19:56 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Resolver One
[2013/02/06 02:14:00 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Resolver One
[2013/02/06 02:13:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Resolver One
[2013/02/05 19:06:09 | 000,000,000 | ---D | C] -- C:\msysgit
[2013/01/31 16:20:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/01/31 16:20:41 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2013/01/27 14:24:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital Corporation
[2013/01/27 14:24:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Western Digital Corporation
[2013/01/26 00:28:07 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Local\Freecorder 7 Audio
[2013/01/26 00:17:32 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Freecorder 7 Audio
[2013/01/26 00:17:32 | 000,000,000 | ---D | C] -- C:\Users\SR\Documents\Freecorder
[2013/01/26 00:17:31 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Local\Jaksta_Technologies_Pty_L
[2013/01/25 23:35:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Abyssmedia
[2013/01/25 23:24:43 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\GetRightToGo
[2013/01/25 23:16:34 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Abyssmedia
[2013/01/25 15:53:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Applian Technologies
[2013/01/25 15:52:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freecorder extension
[2013/01/24 23:15:18 | 000,000,000 | -H-D | C] -- C:\SGLDABC2C75F16E9F97
[2013/01/24 23:15:18 | 000,000,000 | -H-D | C] -- C:\BU82807267DABC2C75F16E9F97
[2013/01/24 23:14:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hokfelt ComputerWorks
[2013/01/24 22:54:43 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Local\Equilab
[2013/01/24 22:52:05 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Local\Downloaded Installations
[2013/01/24 21:49:57 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Local\PokerSleuth
[2013/01/24 21:49:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PokerSleuth
[2013/01/24 19:07:05 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\RealNetworks
[2013/01/24 19:06:33 | 000,000,000 | ---D | C] -- C:\ProgramData\RealNetworks
[2013/01/24 19:05:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Real
[2013/01/24 19:05:19 | 000,000,000 | ---D | C] -- C:\Users\SR\AppData\Roaming\Real
[2013/01/24 19:03:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2013/01/23 01:57:10 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2013/01/18 15:49:41 | 000,000,000 | ---D | C] -- C:\Users\SR\Documents\FIFA 13
[2013/01/18 15:47:51 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2013/01/18 15:38:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FIFA 13
[6 C:\Users\SR\Desktop\*.tmp files -> C:\Users\SR\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/02/17 00:44:00 | 000,001,176 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/02/17 00:44:00 | 000,001,172 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/02/17 00:03:34 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/02/17 00:03:34 | 000,020,768 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/02/16 23:55:56 | 000,000,194 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2013/02/16 23:55:45 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/02/16 23:55:37 | 1066,749,950 | -HS- | M] () -- C:\hiberfil.sys
[2013/02/16 23:54:50 | 000,011,564 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000008-00000000-00000001-00001102-00000008-40041102}.rfx
[2013/02/16 23:54:50 | 000,001,284 | ---- | M] () -- C:\Windows\SysNative\BMXCtrlState-{00000008-00000000-00000001-00001102-00000008-40041102}.rfx
[2013/02/16 23:54:50 | 000,001,284 | ---- | M] () -- C:\Windows\SysNative\BMXBkpCtrlState-{00000008-00000000-00000001-00001102-00000008-40041102}.rfx
[2013/02/16 23:54:50 | 000,000,072 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000008-00000000-00000001-00001102-00000008-40041102}.rfx
[2013/02/16 23:54:50 | 000,000,072 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000008-00000000-00000001-00001102-00000008-40041102}.rfx
[2013/02/16 23:19:44 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/16 16:29:49 | 000,577,536 | ---- | M] () -- C:\Users\SR\Documents\SR Home Budgets.fp7
[2013/02/09 23:19:31 | 000,135,680 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands7.csv
[2013/02/08 22:55:15 | 000,288,937 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands6.csv
[2013/02/07 19:24:08 | 000,483,287 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands5.csv
[2013/02/07 14:36:06 | 000,002,044 | ---- | M] () -- C:\Users\SR\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/02/07 03:22:44 | 000,000,937 | ---- | M] () -- C:\Users\Public\Desktop\PureSync.lnk
[2013/02/07 03:19:19 | 000,311,504 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands4.csv
[2013/02/02 23:30:01 | 000,322,567 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands3.csv
[2013/02/01 13:31:05 | 005,084,464 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/01/31 16:36:21 | 000,227,664 | ---- | M] () -- C:\Users\SR\Documents\cc_20130131_163452.reg
[2013/01/31 03:36:41 | 000,363,451 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands2.csv
[2013/01/29 03:02:47 | 000,457,901 | ---- | M] () -- C:\Users\SR\Desktop\EnumeratedHands1.csv
[2013/01/29 00:07:54 | 000,124,927 | ---- | M] () -- C:\Users\SR\Desktop\Experimental.csv
[2013/01/27 22:10:23 | 000,800,182 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/01/27 22:10:23 | 000,665,950 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/01/27 22:10:23 | 000,126,980 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/01/27 14:24:56 | 000,001,308 | ---- | M] () -- C:\Users\SR\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Lifeguard Diagnostic for Windows.lnk
[2013/01/25 22:26:28 | 000,000,828 | ---- | M] () -- C:\Users\Public\Desktop\REAPER (x64).lnk
[2013/01/24 18:58:15 | 008,612,981 | ---- | M] () -- C:\Users\SR\Documents\_Just Friends_ Charlie Parker.flv
[2013/01/24 01:00:31 | 000,001,325 | ---- | M] () -- C:\Users\SR\AppData\Local\recently-used.xbel
[2013/01/20 22:59:43 | 000,195,481 | ---- | M] () -- C:\Users\SR\Documents\install.air
[2013/01/18 13:05:12 | 2602,448,895 | ---- | M] () -- C:\Users\SR\Desktop\rld-fifa13.iso
[2013/01/18 12:07:02 | 000,005,482 | ---- | M] () -- C:\Users\SR\Desktop\reloaded.nfo
[6 C:\Users\SR\Desktop\*.tmp files -> C:\Users\SR\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/02/16 23:19:44 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/02/09 23:19:31 | 000,135,680 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands7.csv
[2013/02/07 19:18:59 | 000,288,937 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands6.csv
[2013/02/07 03:22:44 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\PureSync.lnk
[2013/02/05 03:47:21 | 000,483,287 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands5.csv
[2013/02/02 23:58:19 | 000,311,504 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands4.csv
[2013/02/01 22:13:49 | 000,322,567 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands3.csv
[2013/01/31 16:35:08 | 000,227,664 | ---- | C] () -- C:\Users\SR\Documents\cc_20130131_163452.reg
[2013/01/29 23:41:26 | 000,363,451 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands2.csv
[2013/01/29 02:59:11 | 000,457,901 | ---- | C] () -- C:\Users\SR\Desktop\EnumeratedHands1.csv
[2013/01/29 00:06:06 | 000,124,927 | ---- | C] () -- C:\Users\SR\Desktop\Experimental.csv
[2013/01/27 14:24:56 | 000,001,308 | ---- | C] () -- C:\Users\SR\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Lifeguard Diagnostic for Windows.lnk
[2013/01/24 23:14:46 | 000,001,318 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QED Poker Simulator.lnk
[2013/01/24 18:55:28 | 008,612,981 | ---- | C] () -- C:\Users\SR\Documents\_Just Friends_ Charlie Parker.flv
[2013/01/24 01:00:31 | 000,001,325 | ---- | C] () -- C:\Users\SR\AppData\Local\recently-used.xbel
[2013/01/20 23:00:22 | 000,195,481 | ---- | C] () -- C:\Users\SR\Documents\install.air
[2013/01/18 15:30:38 | 2602,448,895 | ---- | C] () -- C:\Users\SR\Desktop\rld-fifa13.iso
[2012/12/26 15:15:55 | 000,004,877 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
[2012/12/16 03:47:33 | 000,000,045 | ---- | C] () -- C:\Users\SR\AppData\Local\machpro.dat
[2012/12/16 03:41:51 | 000,000,000 | ---- | C] () -- C:\Windows\HMHud.INI
[2012/10/11 19:17:32 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2012/09/28 23:22:17 | 000,014,368 | ---- | C] () -- C:\Windows\skype.dat
[2012/09/28 21:36:39 | 000,032,854 | ---- | C] () -- C:\Windows\iniLS.dat
[2012/07/23 08:31:38 | 004,428,800 | ---- | C] () -- C:\Windows\SysWow64\x264vfw.dll
[2012/07/02 19:28:06 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2012/06/09 18:21:56 | 000,178,688 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/05/21 17:28:58 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\mlc.dll
[2012/01/28 18:07:57 | 000,000,135 | ---- | C] () -- C:\Windows\AutoKMS.ini
[2011/12/07 22:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2011/10/28 23:37:37 | 000,744,286 | ---- | C] () -- C:\Windows\unins000.exe
[2011/10/28 23:37:37 | 000,001,048 | ---- | C] () -- C:\Windows\unins000.dat
[2011/10/24 17:52:02 | 000,006,966 | ---- | C] () -- C:\ProgramData\DYNAMiCS.nfo
[2011/10/24 17:46:52 | 000,006,966 | ---- | C] () -- C:\Program Files\DYNAMiCS.nfo
[2011/10/12 21:50:34 | 011,165,696 | ---- | C] () -- C:\Users\SR\AppData\Roaming\Sandra.mdb
[2011/09/28 16:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/08/18 16:20:30 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\DBCDBF32.DLL
[2011/08/18 16:20:30 | 000,184,320 | ---- | C] () -- C:\Windows\SysWow64\dbcmdb32.dll
[2011/08/18 16:20:30 | 000,141,824 | ---- | C] () -- C:\Windows\SysWow64\dbcjpg32.dll
[2011/08/18 16:20:30 | 000,135,168 | ---- | C] () -- C:\Windows\SysWow64\DBCMEM32.DLL
[2011/08/18 16:20:30 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\dbcgeo32.dll
[2011/08/14 11:11:41 | 000,000,000 | ---- | C] () -- C:\Users\SR\AppData\Local\{5A7DAA57-5D0C-4C90-9F84-33323514FEB0}
[2011/07/19 18:14:36 | 000,164,864 | ---- | C] () -- C:\Windows\SysWow64\patchw32.dll
[2011/07/19 18:14:36 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\MSWTHK32.DLL
[2011/07/19 18:14:36 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\IMPLODE.DLL
[2011/07/19 18:14:36 | 000,003,360 | ---- | C] () -- C:\Windows\SysWow64\MSWTHK16.DLL
[2011/07/19 18:14:35 | 000,158,720 | ---- | C] () -- C:\Windows\SysWow64\LFCMP61N.DLL
[2011/07/19 18:14:35 | 000,110,080 | ---- | C] () -- C:\Windows\SysWow64\Lfpng61n.dll
[2011/07/19 18:14:35 | 000,043,008 | ---- | C] () -- C:\Windows\SysWow64\LTFIL61N.DLL
[2011/06/17 17:03:06 | 000,000,309 | ---- | C] () -- C:\Users\SR\AppData\Local\HamsterVideoConverterSettings.cfg
[2011/04/21 11:19:20 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/04/21 11:19:20 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/04/13 19:21:08 | 000,000,008 | RH-- | C] () -- C:\Users\SR\hwid
[2011/03/10 20:38:21 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/08/31 17:33:41 | 000,000,008 | ---- | C] () -- C:\ProgramData\VYAAUFMZPWSP.SYS
[2010/05/17 17:13:06 | 000,000,132 | ---- | C] () -- C:\Users\SR\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/05/16 14:37:07 | 000,001,456 | ---- | C] () -- C:\Users\SR\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/04/05 13:25:29 | 000,001,074 | ---- | C] () -- C:\ProgramData\ss.ini
[2010/04/05 13:24:59 | 000,000,034 | ---- | C] () -- C:\Users\SR\AppData\Roaming\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/04/05 13:24:57 | 000,000,033 | ---- | C] () -- C:\ProgramData\{081230F8-EA50-42A9-983C-D22ABC2EED3B}.ini
[2010/02/19 11:13:09 | 000,000,760 | ---- | C] () -- C:\Users\SR\AppData\Roaming\setup_ldm.iss
[2010/02/10 20:12:34 | 000,007,654 | ---- | C] () -- C:\Users\SR\AppData\Local\Resmon.ResmonCfg
========== ZeroAccess Check ==========
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2010/07/27 16:59:11 | 014,162,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2010/07/27 16:03:24 | 012,867,584 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/01/25 23:16:34 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Abyssmedia
[2011/10/18 12:09:15 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Acronis
[2013/01/03 23:06:50 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\ActiveState
[2010/09/05 20:35:18 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\AnvSoft
[2013/01/24 18:35:22 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Audacity
[2013/01/31 16:31:13 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\BitTorrent
[2010/02/07 13:38:20 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Cakewalk
[2010/05/16 14:43:32 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/08/17 20:54:14 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Conversations Network
[2013/01/25 15:59:45 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Cool Record Edit Pro
[2013/01/31 16:31:15 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\DAEMON Tools Lite
[2011/01/13 17:38:37 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\DVDVideoSoftIEHelpers
[2010/03/03 00:37:44 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\EmuPatchMixDSP
[2010/02/21 13:24:18 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\eMusic
[2012/08/06 23:28:40 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\ExpressFiles
[2012/12/17 01:53:30 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\FMRTE13
[2012/08/06 23:14:10 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\FMRTEv5
[2013/01/18 01:16:19 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\fpdb
[2012/01/18 18:04:32 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Free Sound Recorder
[2013/01/26 00:17:32 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Freecorder 7 Audio
[2013/01/25 23:25:06 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\GetRightToGo
[2010/09/06 21:31:57 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\HamsterSoft
[2012/12/17 00:10:31 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\HEM Data
[2012/12/26 15:14:24 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\HoldemManager
[2011/11/02 01:24:21 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Hoyle
[2011/09/29 19:42:39 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Hoyle FaceCreator
[2013/02/07 03:22:50 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Jumping Bytes
[2010/02/10 20:28:04 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Leadertech
[2010/02/19 11:44:16 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\LG Electronics
[2012/04/10 22:18:13 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Lite
[2011/10/24 17:47:33 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\MakeMusic
[2012/09/30 17:31:51 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\MusE
[2010/08/31 16:26:51 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\NCH Swift Sound
[2012/10/06 19:21:15 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\NeatImage PS 64
[2013/01/13 21:27:26 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Notepad++
[2012/10/11 19:17:31 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\PACE Anti-Piracy
[2012/10/11 19:13:43 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\PDAppFlex
[2012/10/26 14:36:11 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\pdfforge
[2013/01/25 22:31:54 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\REAPER
[2013/02/06 02:19:56 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Resolver One
[2011/07/20 22:32:35 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Simple Sudoku
[2012/12/16 04:07:55 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Sports Interactive
[2012/08/28 21:19:53 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/02/12 16:44:44 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Steinberg
[2010/02/24 20:55:34 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Sync App Settings
[2010/07/16 18:43:11 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\ubi.com
[2013/01/31 16:31:13 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\uTorrent
[2012/08/13 15:45:00 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Win7codecs
[2012/04/08 00:23:26 | 000,000,000 | ---D | M] -- C:\Users\SR\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:2784C21E
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:8CE646EE
@Alternate Data Stream - 1242 bytes -> C:\Users\SR\AppData\Local\Temp:nCBUdN93C1bBsrroDSCkWm8z
@Alternate Data Stream - 1085 bytes -> C:\ProgramData\Microsoft:Zhu5pMeIjZBETGlrtvMKRBEHWnz6
@Alternate Data Stream - 1075 bytes -> C:\ProgramData\Microsoft:VGpm8FHaLLYnYnrKjrhD9zG
< End of report >