1. explorer.exe crashes often
2. a redirect ended up on my computer about 2 weeks ago (tho I believed I had conquered it)
3. eset online found MANY problems
4. I have lots of out of date and unneeded programs...but some won't uninstall.
Please, I believe i have multiple trojans, many holes in my security from old out of date versions of programs, and probably a ton of registry and start up problems.
Below is the otl.exe log
any and all help appreciated
OTL logfile created on: 3/24/2013 4:50:16 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Owner\Desktop
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19400)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 1.47 Gb Available Physical Memory | 45.25% Memory free
6.70 Gb Paging File | 4.26 Gb Available in Paging File | 63.54% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 929.44 Gb Total Space | 238.89 Gb Free Space | 25.70% Space Free | Partition Type: NTFS
Drive D: | 2.00 Gb Total Space | 1.06 Gb Free Space | 52.91% Space Free | Partition Type: NTFS
Drive G: | 14.89 Gb Total Space | 14.89 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive H: | 1397.26 Gb Total Space | 736.03 Gb Free Space | 52.68% Space Free | Partition Type: NTFS
Drive J: | 1863.01 Gb Total Space | 557.12 Gb Free Space | 29.90% Space Free | Partition Type: NTFS
Drive L: | 596.17 Gb Total Space | 58.86 Gb Free Space | 9.87% Space Free | Partition Type: NTFS
Drive R: | 596.17 Gb Total Space | 224.38 Gb Free Space | 37.64% Space Free | Partition Type: NTFS
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/03/24 16:38:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
PRC - [2013/03/02 11:33:04 | 001,086,816 | ---- | M] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2013/02/27 14:38:14 | 000,384,640 | ---- | M] (AppWork GmbH) -- C:\Users\Owner\AppData\Local\JDownloader 2.0\JDownloader2.exe
PRC - [2013/01/20 17:49:56 | 000,969,104 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2012/12/14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/12/14 17:49:28 | 000,512,360 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/07/25 05:12:03 | 000,864,104 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2012/07/25 05:11:50 | 001,820,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012/07/24 18:05:00 | 001,258,856 | R--- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,258,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MpCmdRun.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2011/10/27 16:56:35 | 000,470,528 | ---- | M] (Livescribe) -- C:\Program Files\Common Files\Livescribe\PenComm\PenCommService.exe
PRC - [2011/03/26 00:11:28 | 000,108,544 | ---- | M] (Montpellier-Informatique) -- C:\Program Files\Predator2\PredatorACE.exe
PRC - [2010/12/20 18:10:14 | 000,352,256 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMonTaskbar.exe
PRC - [2010/12/20 18:09:52 | 000,505,856 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files\UltraMon\UltraMon.exe
PRC - [2010/07/12 14:03:50 | 000,196,912 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe
PRC - [2009/04/10 23:27:38 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/10 23:27:30 | 000,069,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conime.exe
PRC - [2008/09/29 13:15:00 | 000,155,648 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
PRC - [2008/09/10 13:31:36 | 000,114,688 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe
PRC - [2007/05/28 09:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
========== Modules (No Company Name) ==========
MOD - [2013/03/23 00:04:56 | 000,879,630 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-1671177\libstdc++-6.dll
MOD - [2013/03/23 00:04:55 | 002,342,624 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-1671177\lib7-Zip-JBinding.dll
MOD - [2013/03/23 00:04:55 | 000,047,972 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-1671177\mingwm10.dll
MOD - [2013/03/23 00:04:55 | 000,043,008 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-1671177\libgcc_s_dw2-1.dll
MOD - [2013/03/23 00:04:54 | 000,879,630 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-8261432\libstdc++-6.dll
MOD - [2013/03/23 00:04:54 | 000,047,972 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-8261432\mingwm10.dll
MOD - [2013/03/23 00:04:54 | 000,043,008 | ---- | M] () -- C:\Users\Owner\AppData\Local\JDownloader 2.0\tmp\7zip\SevenZipJBinding-8261432\libgcc_s_dw2-1.dll
MOD - [2013/03/10 17:22:06 | 000,459,728 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\ppgooglenaclpluginchrome.dll
MOD - [2013/03/10 17:22:05 | 012,662,224 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
MOD - [2013/03/10 17:22:04 | 004,050,896 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\pdf.dll
MOD - [2013/03/10 17:21:18 | 000,596,944 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\libglesv2.dll
MOD - [2013/03/10 17:21:18 | 000,124,368 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\libegl.dll
MOD - [2013/03/10 17:21:16 | 001,552,848 | ---- | M] () -- C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\ffmpegsumo.dll
MOD - [2013/02/20 13:22:24 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b5df40c22ab563a816103629e2ca99d4\System.Runtime.Remoting.ni.dll
MOD - [2013/02/20 13:22:10 | 011,820,544 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\421cb77e6a4c21f94e3c5ddf766de23b\System.Web.ni.dll
MOD - [2013/02/20 13:21:37 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\b757806657fa5db2b1ed1a89b026b463\System.Xml.ni.dll
MOD - [2013/02/20 13:21:18 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\e64304962098e90f0d3f4c33c1b080a6\System.Windows.Forms.ni.dll
MOD - [2013/02/20 13:21:10 | 001,593,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\78157a494dc9a7e52be8840decfcd9cc\System.Drawing.ni.dll
MOD - [2013/02/20 13:18:27 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\cc149d08e75f8c53cd28ac926b38c370\System.ni.dll
MOD - [2013/02/20 13:18:12 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\2227d1559f87943255069398608d5c56\mscorlib.ni.dll
MOD - [2012/09/08 13:16:30 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2012/09/08 13:16:20 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2012/02/29 04:04:35 | 014,413,824 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\44ae9f9afb2373055136d57ac6db3f96\mscorlib.ni.dll
MOD - [2012/02/20 21:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 21:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/03/21 11:19:50 | 000,094,208 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2009/07/13 20:50:04 | 000,325,120 | ---- | M] () -- C:\Program Files\TeraCopy\TeraCopy.dll
MOD - [2009/06/21 23:26:00 | 000,305,664 | ---- | M] () -- C:\Program Files\TeraCopy\TeraCopyExt.dll
MOD - [2008/09/16 20:18:06 | 000,132,608 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/04/04 12:27:06 | 000,007,680 | ---- | M] () -- C:\Program Files\Alcohol Soft\Alcohol 120\Plugins\Images\bw5mount.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- C:\Users\Owner\AppData\Local\Temp\DX9\SessionLauncher.exe -- (SessionLauncher)
SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe -- (RoxLiveShare10)
SRV - [2013/03/12 14:24:52 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/12/14 17:49:28 | 000,682,344 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/12/14 17:49:28 | 000,398,184 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/07/24 18:05:00 | 001,258,856 | R--- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/11/23 21:21:24 | 000,025,704 | R--- | M] (Amazon.com) [On_Demand | Stopped] -- C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe -- (ADVService)
SRV - [2011/10/27 16:56:35 | 000,470,528 | ---- | M] (Livescribe) [Auto | Running] -- C:\Program Files\Common Files\Livescribe\PenComm\PenCommService.exe -- (PenCommService)
SRV - [2011/03/26 00:11:28 | 000,108,544 | ---- | M] (Montpellier-Informatique) [Auto | Running] -- C:\Program Files\Predator2\PredatorACE.exe -- (PredatorACE)
SRV - [2011/03/16 11:42:06 | 000,407,336 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2010/11/19 14:29:00 | 004,916,568 | ---- | M] (LeapFrog Enterprises, Inc.) [On_Demand | Stopped] -- C:\Program Files\LeapFrog\LeapFrog Connect\CommandService.exe -- (LeapFrog Connect Device Service)
SRV - [2010/07/12 14:03:50 | 000,196,912 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe -- (NitroReaderDriverReadSpool)
SRV - [2010/01/25 09:22:56 | 000,245,760 | ---- | M] (Brother Industries, Ltd.) [On_Demand | Stopped] -- C:\Program Files\Browny02\BrYNSvc.exe -- (BrYNSvc)
SRV - [2009/12/04 05:07:26 | 000,285,696 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\LogiShrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/10/04 11:58:04 | 000,201,968 | ---- | M] (SupportSoft, Inc.) [Disabled | Stopped] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_DellSupportCenter)
SRV - [2008/09/29 13:15:00 | 000,155,648 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
SRV - [2008/09/10 13:31:36 | 000,114,688 | ---- | M] (NVIDIA) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\System Update\UpdateCenterService.exe -- (UpdateCenterService)
SRV - [2008/01/19 00:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/06 13:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2007/05/28 09:57:54 | 000,275,968 | ---- | M] (Rocket Division Software) [Auto | Running] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2006/02/28 18:10:18 | 000,069,632 | ---- | M] (CrypKey (Canada) Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\Crypserv.exe -- (Crypkey License)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | Boot | Stopped] -- system32\DRIVERS\viamraid.sys -- (viamraid)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\RtHDMIV.sys -- (RTHDMIAzAudService)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\IQE4E94.tmp -- (GarenaPEngine)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Owner\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a4nosxiy)
DRV - [2013/03/24 03:12:03 | 000,029,904 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{50B44A50-3FC0-4967-9A78-DFCEB5F46A5F}\MpKsl929db3e4.sys -- (MpKsl929db3e4)
DRV - [2013/02/09 20:20:39 | 008,944,416 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012/12/14 17:49:28 | 000,021,104 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/08/20 14:48:44 | 000,015,576 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdrvio.sys -- (pwdrvio)
DRV - [2012/08/20 14:48:44 | 000,010,200 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\pwdspio.sys -- (pwdspio)
DRV - [2012/07/02 17:25:18 | 000,149,352 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2012/04/09 17:27:34 | 000,299,024 | ---- | M] (EldoS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cbfs3.sys -- (cbfs3)
DRV - [2012/04/05 22:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2012/04/05 22:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2012/04/05 22:21:10 | 009,334,784 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012/04/05 18:10:22 | 000,275,968 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/12/09 15:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)
DRV - [2011/12/09 15:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)
DRV - [2011/12/09 15:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)
DRV - [2011/12/09 15:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)
DRV - [2011/12/09 15:35:58 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)
DRV - [2011/10/27 16:57:23 | 000,020,480 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\PulseUsb.sys -- (PulseUsb)
DRV - [2011/07/27 11:48:16 | 000,006,656 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\iPodDrv.sys -- (iPodDrv)
DRV - [2010/12/28 18:31:08 | 000,005,632 | ---- | M] () [File_System | System | Running] -- C:\Windows\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2010/12/07 14:23:00 | 000,025,088 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandmodem.sys -- (ANDModem)
DRV - [2010/12/07 14:23:00 | 000,020,736 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lganddiag.sys -- (AndDiag)
DRV - [2010/12/07 14:23:00 | 000,020,096 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandgps.sys -- (AndGps)
DRV - [2010/12/07 14:22:58 | 000,014,336 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandbus.sys -- (Andbus)
DRV - [2010/08/12 15:14:40 | 000,230,736 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2010/08/02 16:19:22 | 000,025,728 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgandadb.sys -- (androidusb)
DRV - [2010/07/29 00:25:22 | 000,025,112 | ---- | M] (Initio Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ivusb.sys -- (ivusb)
DRV - [2010/07/26 11:30:17 | 000,716,272 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009/12/30 10:21:18 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/12/29 22:09:06 | 000,059,904 | ---- | M] (wj32) [Kernel | Disabled | Running] -- C:\Program Files\Process Hacker\kprocesshacker.sys -- (KProcessHacker)
DRV - [2009/11/10 04:55:32 | 000,028,560 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2009/11/10 04:55:08 | 000,037,392 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2009/11/10 04:54:52 | 000,035,984 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2009/09/30 07:31:46 | 000,103,440 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2009/07/13 16:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/06/10 00:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2008/11/14 03:11:30 | 000,017,184 | ---- | M] (Realtime Soft Ltd) [Kernel | Auto | Running] -- C:\Program Files\Common Files\Realtime Soft\UltraMonMirrorDrv\x32\UltraMonUtility.sys -- (UltraMonUtility)
DRV - [2008/11/12 17:02:46 | 000,146,464 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvstor32.sys -- (nvstor32)
DRV - [2008/11/12 17:02:46 | 000,133,152 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\nvrd32.sys -- (nvrd32)
DRV - [2008/09/29 13:17:06 | 000,029,952 | ---- | M] (NVIDIA Corp.) [Kernel | On_Demand | Running] -- C:\Windows\nvoclock.sys -- (NVR0Dev)
DRV - [2008/09/10 13:28:48 | 000,036,896 | ---- | M] (NVidia Corp.) [Kernel | Auto | Running] -- C:\Windows\nvflash.sys -- (NVR0FLASHDev)
DRV - [2008/01/15 04:25:24 | 001,040,544 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2007/11/13 01:21:54 | 000,017,536 | ---- | M] (Anyka (Guangzhou) Software Technology Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbanyka.sys -- (usbanyka)
DRV - [2007/11/06 13:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2007/08/29 04:04:04 | 000,116,264 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SI3112r.sys -- (SI3112r)
DRV - [2007/08/29 04:04:04 | 000,019,240 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2007/03/20 20:33:28 | 000,028,672 | ---- | M] (http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
DRV - [2006/12/28 06:50:26 | 000,016,000 | ---- | M] (Sonix Technology Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\9kdUSBXP.sys -- (SNL320XP)
DRV - [2006/11/02 00:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2006/01/09 19:47:27 | 000,031,846 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\Ckldrv.sys -- (NetworkX)
DRV - [2005/05/03 08:34:02 | 000,027,392 | ---- | M] (SlySoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ElbyCDFL.sys -- (ElbyCDFL)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{5C42B5B9-17ED-4537-8FE8-7363B216ECCA}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{5C42B5B9-17ED-4537-8FE8-7363B216ECCA}: "URL" = http://search.live.c...Box&Form=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost; 127.0.0.1; <local>;*.local
========== FireFox ==========
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: en-US%40dictionaries.addons.mozilla.org:6.0
FF - prefs.js..extensions.enabledAddons: facepad%40lazyrussian.com:0.9.6
FF - prefs.js..extensions.enabledAddons: greasefire%40skrul.com:1.0.8
FF - prefs.js..extensions.enabledAddons: guiconfig%40slosd.net:1.2.2
FF - prefs.js..extensions.enabledAddons: handytag%40elitwork.com:2.2
FF - prefs.js..extensions.enabledAddons: MafiaaFire%40mafiaafire.com:0.9d
FF - prefs.js..extensions.enabledAddons: magnetiser%40hotsexgary.com:0.975
FF - prefs.js..extensions.enabledAddons: multilinks%40plugin:3.0.0.19
FF - prefs.js..extensions.enabledAddons: nosquint%40urandom.ca:2.1.6
FF - prefs.js..extensions.enabledAddons: pl%40dictionaries.addons.mozilla.org:1.0.20110621
FF - prefs.js..extensions.enabledAddons: tagmarks%40felipc.com:1.0.1
FF - prefs.js..extensions.enabledAddons: tineye%40ideeinc.com:1.1
FF - prefs.js..extensions.enabledAddons: VacuumPlacesImproved%40lultimouomo-gmail.com:1.2
FF - prefs.js..extensions.enabledAddons: %7B37E4D8EA-8BDA-4831-8EA1-89053939A250%7D:3.0.0.2
FF - prefs.js..extensions.enabledAddons: %7B3d7eb24f-2740-49df-8937-200b1cc08f8a%7D:1.5.15.1
FF - prefs.js..extensions.enabledAddons: %7B987311C6-B504-4aa2-90BF-60CC49808D42%7D:2.2
FF - prefs.js..extensions.enabledAddons: %7B99B98C2C-7274-45a3-A640-D9DF1A1C8460%7D:1.4
FF - prefs.js..extensions.enabledAddons: %7Bcd617372-6743-4ee4-bac4-fbf60f35719e%7D:2.0
FF - prefs.js..extensions.enabledAddons: %7Bd40f5e7b-d2cf-4856-b441-cc613eeffbe3%7D:1.68
FF - prefs.js..extensions.enabledAddons: %7BD4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389%7D:0.9.10
FF - prefs.js..extensions.enabledAddons: %7BDDC359D1-844A-42a7-9AA1-88A850A938A8%7D:2.0.15
FF - prefs.js..extensions.enabledAddons: %7BFDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3%7D:1.3.5
FF - prefs.js..extensions.enabledAddons: autopager%40mozilla.org:0.8.0.8
FF - prefs.js..extensions.enabledAddons: %7B8b86149f-01fb-4842-9dd8-4d7eb02fd055%7D:0.25.1
FF - prefs.js..extensions.enabledAddons: foxyproxy-basic%40eric.h.jung:3.1.3
FF - prefs.js..extensions.enabledAddons: %7B59c81df5-4b7a-477b-912d-4e0fdf64e5f2%7D:0.9.90
FF - prefs.js..extensions.enabledAddons: support%40lastpass.com:2.0.20
FF - prefs.js..extensions.enabledAddons: %7Bdc572301-7619-498c-a57d-39143191b318%7D:0.4.0.5
FF - prefs.js..extensions.enabledAddons: anttoolbar%40ant.com:2.4.7.6
FF - prefs.js..extensions.enabledAddons: %7Be4a8a97b-f2ed-450b-b12d-ee082ba24781%7D:1.8
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.5.8
FF - prefs.js..extensions.enabledAddons: personas%40christopher.beard:1.6.5
FF - prefs.js..extensions.enabledAddons: firefox%40ghostery.com:2.9.2
FF - prefs.js..extensions.enabledAddons: %7B19503e42-ca3c-4c27-b1e2-9cdb2170ee34%7D:1.5.4.3
FF - prefs.js..extensions.enabledAddons: %7BE0B8C461-F8FB-49b4-8373-FE32E9252800%7D:5.5.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.2.4
FF - prefs.js..extensions.enabledItems: {d40f5e7b-d2cf-4856-b441-cc613eeffbe3}:1.49
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.6
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.4
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.4
FF - prefs.js..extensions.enabledItems: {FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}:1.3.5
FF - prefs.js..extensions.enabledItems: multilinks@plugin:3.0.0.14
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.20110211
FF - prefs.js..extensions.enabledItems: {cd617372-6743-4ee4-bac4-fbf60f35719e}:2.0
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.2
FF - prefs.js..extensions.enabledItems: [email protected]:2.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.1
FF - prefs.js..extensions.enabledItems: {E0B8C461-F8FB-49b4-8373-FE32E9252800}:4.0.0.131046
FF - prefs.js..extensions.enabledItems: [email protected]:1.72.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.8.5
FF - prefs.js..extensions.enabledItems: [email protected]:2.1
FF - prefs.js..extensions.enabledItems: {987311C6-B504-4aa2-90BF-60CC49808D42}:2.2
FF - prefs.js..extensions.enabledItems: {e0204bd5-9d31-402b-a99d-a6aa8ffebdca}:1.2.5
FF - prefs.js..extensions.enabledItems: {99B98C2C-7274-45a3-A640-D9DF1A1C8460}:1.4
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.0.9.9
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {340c2bbc-ce74-4362-90b5-7c26312808ef}:1.7
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.2.8.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [email protected]:2.5.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0
FF - prefs.js..extensions.enabledItems: {BB359C50-BFC9-4f40-8302-3FE5A499A859}:3.6.1
FF - prefs.js..extensions.enabledItems: {29852C08-1E91-4889-A6BF-C77F91D6A8F3}:1.8.71
FF - prefs.js..extensions.enabledItems: {a78f0ac6-753b-491b-9021-cd2aec3502d9}:3.6
FF - prefs.js..network.proxy.socks_remote_dns: true
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@doubletwist.com/NPPodcast: C:\Program Files\Common Files\doubleTwist\NPPodcast.dll (doubleTwist Corporation)
FF - HKLM\Software\MozillaPlugins\@fluxdvd.com/NPAPIX: C:\Program Files\Common Files\fluxDVD\APIX\NPAPIX.dll ()
FF - HKLM\Software\MozillaPlugins\@fluxdvd.com/NPFluxBrowserHelper: C:\Program Files\Common Files\fluxDVD\BrowserIntegration\NPFluxBrowserHelper.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.15.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll (TVU networks)
FF - HKLM\Software\MozillaPlugins\@protectdisc.com/NPMPDRM: C:\Program Files\Common Files\mpDRM\NPMPDRM.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Owner\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\amazon.com/AmazonMP3DownloaderPlugin: C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll (Amazon.com, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{400F0BDB-6C49-43A4-BE1F-76D7327A604D}: C:\Program Files\Common Files\fluxDVD\Download Manager\Mozilla [2009/06/12 15:35:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/20 23:18:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/12 14:24:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
[2010/01/08 09:27:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions
[2010/01/08 09:27:40 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Extensions\[email protected]
[2013/03/21 01:16:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions
[2009/08/05 08:24:15 | 000,000,000 | ---D | M] (Options Menu) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{1a6907cb-d310-4d82-bded-c0dd31f8d9a2}
[2009/11/02 14:37:04 | 000,000,000 | ---D | M] (Objection) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{289F3A4A-F3FF-4173-B994-DBC887E9C468}
[2011/02/07 08:29:25 | 000,000,000 | ---D | M] (PDF Download) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2013/02/08 19:38:58 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/07/14 20:22:29 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(63)
[2010/02/15 23:09:42 | 000,000,000 | ---D | M] (NoScript) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}(89)
[2013/01/24 11:11:18 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2010/04/17 09:53:08 | 000,000,000 | ---D | M] (BugMeNot) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{987311C6-B504-4aa2-90BF-60CC49808D42}
[2010/06/30 23:49:58 | 000,000,000 | ---D | M] (CookieCuller) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{99B98C2C-7274-45a3-A640-D9DF1A1C8460}
[2010/06/17 15:19:59 | 000,000,000 | ---D | M] (Penn State Nittany Lions) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{a78f0ac6-753b-491b-9021-cd2aec3502d9}
[2009/06/10 22:57:05 | 000,000,000 | ---D | M] (HalloFF) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{bbf8fc30-5280-11db-b0de-0800200c9a66}
[2010/07/23 00:55:24 | 000,000,000 | ---D | M] ("Show my Password") -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{cd617372-6743-4ee4-bac4-fbf60f35719e}
[2010/11/03 14:11:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}-trash
[2010/07/14 20:22:30 | 000,000,000 | ---D | M] (Download Statusbar) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}(64)
[2010/06/30 23:49:58 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2013/03/12 18:34:12 | 000,000,000 | ---D | M] (Evernote Web Clipper) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}
[2011/03/10 21:21:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}-trash
[2009/09/14 20:42:14 | 000,000,000 | ---D | M] (IE View Lite) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{FDD8ECF0-451A-414D-8C8F-7B7F78B0ECD3}
[2012/09/21 17:38:36 | 000,000,000 | ---D | M] (adblockvideo) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/03/04 12:26:11 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2010/07/15 22:19:31 | 000,000,000 | ---D | M] (CheckPlaces) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\checkplaces@andyhalford(61).com
[2012/05/22 10:29:39 | 000,000,000 | ---D | M] (United States English Spellchecker) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/01/20 21:31:49 | 000,000,000 | ---D | M] (PhotoJacker: Photo Album Downloader for Facebook (fka FacePAD)) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/03/06 21:04:15 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/11/26 13:53:23 | 000,000,000 | ---D | M] (TVU Web Player) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2009/08/13 19:10:21 | 000,000,000 | ---D | M] (FlashLoader) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/02/02 10:59:41 | 000,000,000 | ---D | M] (FoxyProxy Standard) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2010/12/21 23:53:40 | 000,000,000 | ---D | M] ("Handytag") -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2009/07/21 13:46:01 | 000,000,000 | ---D | M] (Next Tab) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2010/07/14 20:22:29 | 000,000,000 | ---D | M] (Omnibar) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\omnibar@ajitk(62).com
[2011/06/29 07:01:47 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2010/02/15 23:09:42 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\support@lastpass(88).com
[2013/03/21 01:16:51 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2009/11/27 21:03:51 | 000,000,000 | ---D | M] (Tabberwocky) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2010/01/23 20:47:39 | 000,000,000 | ---D | M] (Tagmarks) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/02/21 22:53:53 | 000,000,000 | ---D | M] (TinEye Reverse Image Search) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/01/20 21:31:49 | 000,000,000 | ---D | M] (Vacuum Places Improved) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2009/05/11 07:45:22 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Sunbird\Profiles\uwu58twj.default\extensions
[2012/01/08 16:56:03 | 000,854,402 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/01/14 13:21:29 | 000,347,340 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/02/08 19:18:52 | 000,224,945 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2012/05/22 10:29:39 | 005,438,448 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/10/22 16:02:34 | 000,174,405 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2012/02/17 09:23:15 | 000,123,007 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2012/02/17 09:23:16 | 000,019,291 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2011/12/31 14:37:59 | 000,038,090 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2012/09/20 20:28:16 | 000,113,112 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/03/06 21:04:12 | 000,386,363 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/01/06 17:28:31 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\[email protected]
[2013/03/12 18:34:12 | 000,348,483 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi
[2013/03/03 18:59:23 | 000,493,403 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{29852C08-1E91-4889-A6BF-C77F91D6A8F3}.xpi
[2011/07/17 11:43:27 | 000,097,169 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}.xpi
[2013/03/04 12:25:45 | 000,531,283 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2012/10/18 08:48:37 | 001,494,925 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{BB359C50-BFC9-4f40-8302-3FE5A499A859}.xpi
[2013/03/06 12:13:51 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/01/23 12:49:05 | 000,138,614 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi
[2011/10/30 17:30:14 | 000,434,392 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2013/03/04 12:25:45 | 000,754,446 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
[2012/09/20 20:28:16 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2013/03/04 12:25:45 | 000,269,007 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2009/06/10 22:57:05 | 000,828,588 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\extensions\{bbf8fc30-5280-11db-b0de-0800200c9a66}\chrome\tmp.xpi
[2009/08/20 16:58:43 | 000,001,625 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\wvymb9q7.default\searchplugins\startpage-https.xml
[2013/03/12 14:24:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2013/03/12 14:24:53 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/03/02 06:17:24 | 000,095,200 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPAPIX.dll
[2007/01/17 04:18:04 | 000,095,200 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPFluxBrowserHelper.dll
[2010/01/18 13:32:01 | 000,075,208 | ---- | M] (Foxit Software Company) -- C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2007/07/02 08:42:20 | 000,103,064 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\NPMPDRM.dll
[2011/12/09 10:23:32 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2012/09/21 17:27:21 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/03/12 14:24:28 | 000,002,086 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Startpage HTTPS (Enabled)
CHR - default_search_provider: search_url = https://startpage.co...anguage=english
CHR - default_search_provider: suggest_url = ,
CHR - homepage: http://whatreallyhappened.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Owner\AppData\Local\Google\Chrome\Application\25.0.1364.172\pdf.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Active Process Information eXchange (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPAPIX.dll
CHR - plugin: fluxDVD (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPFluxBrowserHelper.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: NPMPDRM License Acquisition Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPMPDRM.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Winamp Application Detector (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: AmazonMP3DownloaderPlugin (Enabled) = C:\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: doubletwist Plugin 1, 3, 0, 0 (Enabled) = C:\Program Files\Common Files\doubleTwist\NPPodcast.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Java Platform SE 7 U15 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: TVU Web Player for FireFox (Enabled) = C:\Program Files\TVUPlayer\npTVUAx.dll
CHR - plugin: Veetle TV Player (Enabled) = C:\Program Files\Veetle\Player\npvlc.dll
CHR - plugin: Veetle TV Core (Enabled) = C:\Program Files\Veetle\plugins\npVeetle.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Hulu Desktop (Enabled) = C:\Users\Owner\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_6_602_168.dll
CHR - plugin: Java Deployment Toolkit 7.0.150.3 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - Extension: Google Translate = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\1.2.4_0\
CHR - Extension: Google Drive = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Bookmark Sentry = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdglbbcbmgnimogcmcdenggkpdmihlga\1.7.13_0\
CHR - Extension: Adblock Plus = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.4_0\
CHR - Extension: GroovesharkMenu = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\clfmokiidpofbgincdbjagbdkihkjfla\0.2.5_0\
CHR - Extension: Google Search = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Bookmarks Tagger = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpiecafonfminhngabegejbligdagjfc\1.1.1_0\
CHR - Extension: Gmail Offline = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.19_0\
CHR - Extension: Google Calendar = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn\4.5.3_0\
CHR - Extension: Facebook Disconnect = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejpepffjfmamnambagiibghpglaidiec\1.3.0_0\
CHR - Extension: Grooveshark Remote = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbpifhknilaflibiifjhhofddbbchmhh\1.6.3_0\
CHR - Extension: Ghost incognito = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gedeaafllmnkkgbinfnleblcglamgebg\1.0.3_0\
CHR - Extension: FlashBlock = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gofhjkjmkpinhpoiabjplobcaignabnl\0.9.31_0\
CHR - Extension: Ads-free Grooveshark = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\hafggjhmihflaeblhdhjpbdadcofgfaf\0.5.1_0\
CHR - Extension: LastPass = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.21_0\
CHR - Extension: Evernote Web = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol\1.0.7_0\
CHR - Extension: Linkclump = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj\2.7.2_0\
CHR - Extension: AdSweep = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\milkhonmecplandlkfbjplfbdenjlkmp\2.1.6_0\
CHR - Extension: Ghostery = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.0_0\
CHR - Extension: AutoPager Chrome = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmgagnmbebdebebbcleklifnobamjonh\0.8.0.4_0\
CHR - Extension: Docs PDF/PowerPoint Viewer (by Google) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn\3.10_0\
CHR - Extension: Click&Clean App = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Evernote Web Clipper = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.9.12_0\
CHR - Extension: Gmail = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Privacyfix by Privacychoice = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmejhjjecaldkllonlokhkglbdbkdcni\4.0_0\
O1 HOSTS File: ([2011/10/05 21:46:31 | 000,437,128 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15061 more lines...
O2 - BHO: (Download Manager Browser Helper Object) - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\Program Files\Common Files\fluxDVD\Download Manager\XEBDLHelper.dll (Protect Software GmbH)
O2 - BHO: (PodcastBHO Class) - {65134FDF-F8A5-4B3D-91D9-CDF273CFD578} - C:\Program Files\Common Files\doubleTwist\IEPodcastPlugin.dll (doubleTwist Corporation)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Evernote extension) - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O2 - BHO: (LastPass Vault) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe ()
O4 - HKCU..\Run: [BackgroundSwitcher] C:\Program Files\johnsadventures.com\John's Background Switcher\BackgroundSwitcher.exe (johnsadventures.com)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [InstallShieldSetup] "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -reboot"C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\reboot.ini" File not found
O4 - Startup: C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Clip selection - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=3 File not found
O8 - Extra context menu item: Clip this page - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=1 File not found
O8 - Extra context menu item: Clip URL - C:\Program Files\Evernote\Evernote\\EvernoteIERes\Clip.html?clipAction=0 File not found
O8 - Extra context menu item: lastpass - file://C:\Users\Owner\AppData\LocalLow\lastpass\context.html?cmd=lastpass File not found
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Owner\AppData\LocalLow\lastpass\context.html?cmd=fillforms File not found
O8 - Extra context menu item: New Note - C:\Program Files\Evernote\Evernote\\EvernoteIERes\NewNote.html ()
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files\LastPass\LPToolbar.dll (LastPass)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\\EvernoteIERes\AddNote.html ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: dell.com ([]* in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.15.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3591D13-9B5E-4723-A2DB-7C45784771D3}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3591D13-9B5E-4723-A2DB-7C45784771D3}: NameServer = 208.201.224.11,208.201.224.33
O18 - Protocol\Handler\navnet {AD6E5643-7B0C-46AA-95AD-9773FF2A857A} - C:\Program Files\NavNetApp\ComUtilities.dll (MH)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\System32\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Users\Owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Owner\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/08/03 01:29:29 | 000,000,000 | ---D | M] - L:\Automatically Add to iTunes -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/03/24 16:38:38 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2013/03/22 15:46:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\backups
[2013/03/22 15:37:35 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Users\Owner\Desktop\HijackThis.exe
[2013/03/21 12:18:04 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2013/03/21 01:16:07 | 000,000,000 | ---D | C] -- C:\Program Files\LastPass
[2013/03/20 22:17:49 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\CRE
[2013/03/20 22:00:53 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\NVIDIA
[2013/03/13 00:01:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\JDownloader 2.0
[2013/03/13 00:01:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\i4j_jres
[2013/03/12 14:24:15 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2013/03/05 12:54:53 | 000,000,000 | ---D | C] -- C:\Program Files\share
[2013/03/04 00:46:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2013/03/01 00:41:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
[2013/03/01 00:41:49 | 000,000,000 | ---D | C] -- C:\Program Files\Seagate
[2012/01/30 11:56:25 | 010,965,504 | ---- | C] (LastPass) -- C:\Program Files\Common Files\lpuninstall.exe
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/24 16:38:47 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2013/03/24 16:35:41 | 000,008,512 | ---- | M] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
[2013/03/24 15:59:01 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1500155505-1741706647-2289308542-1000UA.job
[2013/03/24 15:49:47 | 000,003,568 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/03/24 15:49:47 | 000,003,568 | ---- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/03/24 00:38:17 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2013/03/24 00:38:15 | 000,245,760 | ---- | M] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/03/23 21:59:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1500155505-1741706647-2289308542-1000Core.job
[2013/03/22 15:38:11 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\Owner\Desktop\HijackThis.exe
[2013/03/22 12:40:40 | 000,707,006 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/03/22 12:40:40 | 000,143,862 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/03/22 09:26:07 | 000,002,401 | ---- | M] () -- C:\Users\Public\Desktop\SeaTools for Windows.lnk
[2013/03/21 01:16:57 | 010,965,504 | ---- | M] (LastPass) -- C:\Program Files\Common Files\lpuninstall.exe
[2013/03/21 01:16:52 | 000,001,128 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\My LastPass Vault.lnk
[2013/03/20 23:51:03 | 000,002,359 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk
[2013/03/20 23:49:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/03/20 20:39:15 | 000,000,864 | ---- | M] () -- C:\Users\Owner\AppData\Local\recently-used.xbel
[2013/03/20 19:49:21 | 000,016,505 | ---- | M] () -- C:\Users\Owner\Documents\maxUntitled 1.odt
[2013/03/20 19:49:04 | 000,029,054 | ---- | M] () -- C:\Users\Owner\Documents\Untitled 3.ods
[2013/03/18 23:52:47 | 000,016,084 | ---- | M] () -- C:\Users\Owner\Desktop\seagate.odt
[2013/03/14 06:04:04 | 000,002,086 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/03/13 00:06:08 | 000,001,900 | ---- | M] () -- C:\Users\Owner\Desktop\JDownloader.lnk
[2013/03/13 00:06:08 | 000,001,850 | ---- | M] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2013/03/10 01:00:23 | 000,506,717 | ---- | M] () -- C:\Users\Owner\Desktop\American_Spanish_Phrases-USL.pdf
[4 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/21 01:16:43 | 000,001,128 | ---- | C] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\My LastPass Vault.lnk
[2013/03/20 20:39:15 | 000,000,864 | ---- | C] () -- C:\Users\Owner\AppData\Local\recently-used.xbel
[2013/03/20 19:49:19 | 000,016,505 | ---- | C] () -- C:\Users\Owner\Documents\maxUntitled 1.odt
[2013/03/20 19:49:02 | 000,029,054 | ---- | C] () -- C:\Users\Owner\Documents\Untitled 3.ods
[2013/03/18 18:27:48 | 000,016,084 | ---- | C] () -- C:\Users\Owner\Desktop\seagate.odt
[2013/03/12 23:50:55 | 000,001,900 | ---- | C] () -- C:\Users\Owner\Desktop\JDownloader.lnk
[2013/03/12 23:50:55 | 000,001,850 | ---- | C] () -- C:\Users\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\JDownloader.lnk
[2013/03/12 23:50:42 | 000,001,850 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader.lnk
[2013/03/12 23:50:41 | 000,001,913 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Uninstaller.lnk
[2013/03/12 23:50:41 | 000,001,671 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JDownloader Update.lnk
[2013/03/10 01:00:17 | 000,506,717 | ---- | C] () -- C:\Users\Owner\Desktop\American_Spanish_Phrases-USL.pdf
[2013/03/01 00:41:55 | 000,002,401 | ---- | C] () -- C:\Users\Public\Desktop\SeaTools for Windows.lnk
[2012/12/07 16:52:24 | 000,000,233 | ---- | C] () -- C:\Windows\Brpfx04a.ini
[2012/12/07 16:52:24 | 000,000,093 | ---- | C] () -- C:\Windows\brpcfx.ini
[2012/12/07 16:44:49 | 000,000,066 | ---- | C] () -- C:\Windows\Brfaxrx.ini
[2012/12/07 16:44:49 | 000,000,000 | ---- | C] () -- C:\Windows\brdfxspd.dat
[2012/12/07 16:44:36 | 000,045,056 | ---- | C] () -- C:\Windows\System32\BRTCPCON.DLL
[2012/12/07 16:44:34 | 000,000,114 | ---- | C] () -- C:\Windows\System32\BRLMW03A.INI
[2012/12/07 16:44:33 | 000,000,050 | ---- | C] () -- C:\Windows\System32\BRADM10A.DAT
[2012/09/28 15:36:56 | 000,180,224 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012/09/06 09:28:58 | 002,872,000 | ---- | C] () -- C:\Windows\System32\pwNative.exe
[2012/09/06 09:28:56 | 000,015,576 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys
[2012/09/06 09:27:12 | 000,010,200 | ---- | C] () -- C:\Windows\System32\pwdspio.sys
[2012/07/28 13:16:21 | 000,000,106 | ---- | C] () -- C:\Users\Owner\EnableUSBWrite.reg
[2012/07/25 08:14:42 | 000,429,416 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2012/05/05 16:16:21 | 000,008,512 | ---- | C] () -- C:\Users\Owner\AppData\Local\d3d9caps.dat
[2012/01/20 22:17:01 | 000,191,727 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\gd.db
[2012/01/20 22:17:01 | 000,000,283 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\groovedown.settings
[2011/10/09 16:03:01 | 000,000,071 | ---- | C] () -- C:\Windows\Crypkey.ini
[2011/10/09 16:02:59 | 000,031,846 | ---- | C] () -- C:\Windows\System32\Ckldrv.sys
[2011/10/09 16:02:59 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
[2011/10/09 16:02:59 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2011/10/09 16:02:59 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
[2011/10/01 15:45:29 | 000,005,163 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\elul
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/09/25 13:48:51 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011/09/12 16:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2011/07/28 13:59:58 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2011/07/28 13:59:58 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2011/06/30 13:55:58 | 000,000,140 | ---- | C] () -- C:\Windows\System32\ptl5.dat.{B03B289B-C438-4D0F-B3B0-52F9FE7B661D}
[2011/06/30 13:51:31 | 000,000,016 | ---- | C] () -- C:\Windows\System32\ptlx55.dat.{5728B11F-B697-47AA-9C1B-8ECB545B5193}
[2011/06/30 12:57:58 | 000,138,056 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\PnkBstrK.sys
[2010/05/09 21:47:11 | 000,000,600 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\winscp.rnd
[2009/11/22 15:01:00 | 000,000,090 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\default.pls
[2009/11/05 08:54:35 | 000,000,004 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\sgeaxael3kiitbyhsirgbnkdqbs5vr4
[2009/08/27 12:06:32 | 000,000,081 | ---- | C] () -- C:\Users\Owner\notalonrecent
[2009/05/10 18:31:52 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2009/05/09 12:05:38 | 000,001,024 | ---- | C] () -- C:\Users\Owner\.rnd
[2009/05/06 20:48:55 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2009/04/24 21:00:26 | 000,000,004 | RHS- | C] () -- C:\ProgramData\sysqcl1129139270.dat
[2009/04/24 20:30:41 | 000,245,760 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/24 20:22:24 | 000,000,418 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/04/24 16:41:17 | 002,621,440 | -HS- | C] () -- C:\Users\Owner\ntuser.bak
========== ZeroAccess Check ==========
[2006/11/02 05:53:06 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 10:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 23:28:20 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 23:28:26 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/03/04 22:07:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\.Tribler
[2010/03/06 17:31:27 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\1morebee
[2009/07/14 19:26:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Aisle 5 Games, Inc
[2009/11/25 15:50:05 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Alawar
[2011/02/07 09:45:24 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Amazon
[2010/10/12 11:01:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Anarchy
[2009/08/05 18:25:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Any Video Converter Professional
[2010/10/29 18:44:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Artifex Mundi
[2009/06/11 14:27:55 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Ashampoo
[2012/09/27 23:51:07 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Audacity
[2009/08/16 09:19:49 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Babylonia
[2012/09/28 00:02:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\backpocket.com
[2010/09/25 19:02:02 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Big Fish Games
[2009/08/25 15:13:54 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\blg
[2012/06/10 20:25:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\BoneCraft
[2010/05/27 11:18:09 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Braintonik
[2013/01/25 11:08:19 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\calibre
[2009/05/09 11:01:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Canneverbe_Limited
[2009/08/03 12:56:09 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CasualForge
[2010/04/20 13:25:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\CD Art Display
[2013/02/20 13:35:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\com.livescribe.LivescribeConnect
[2012/08/19 16:12:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\com.ninjakiwi.BloonsTD5Deluxe
[2010/05/04 11:20:16 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ContentGuard
[2012/12/07 17:02:51 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ControlCenter4
[2009/12/03 20:40:19 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Curious Sense
[2010/04/25 19:33:40 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DiskSpaceFan
[2011/10/09 19:04:25 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DisneyInteractiveStudios
[2011/01/01 12:51:33 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DivoGames
[2010/07/17 19:05:58 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Downloaded Installations
[2009/05/19 11:41:16 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Dreamsdwell Stories
[2012/11/23 18:04:27 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Dropbox
[2012/10/02 12:30:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DVDFab
[2009/11/05 11:29:51 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ElementalsTheMagicKey
[2010/01/17 09:58:24 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ERS G-Studio
[2009/09/11 11:51:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\EscapeFromParadise2
[2009/04/24 16:52:13 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ESET
[2009/07/02 13:41:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Faerie Solitaire
[2010/03/07 13:07:52 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Farm Mania 2
[2010/05/07 22:09:19 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\FileZilla
[2013/03/18 00:32:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\foobar2000
[2009/08/06 22:58:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Foxit
[2010/02/05 15:32:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Foxit Software
[2011/02/11 11:17:24 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Friday's games
[2009/09/18 21:03:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\funkitron
[2009/11/25 20:20:14 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Gamers Digital
[2009/10/13 11:17:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Games
[2009/10/23 16:58:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GamesCafe
[2011/10/09 14:10:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GetRightToGo
[2009/08/15 15:24:22 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GraveyardShift
[2012/02/12 20:03:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Groovedown
[2011/08/07 01:45:59 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\gtk-2.0
[2009/10/16 22:26:13 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GTM_Bodie
[2010/01/12 19:41:26 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\HandBrake
[2012/02/25 16:27:59 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Hothead Games
[2009/05/27 20:34:36 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\HuruBeachParty
[2009/07/04 14:45:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\IronCode
[2009/10/22 07:39:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\iWin_generic
[2009/09/21 21:12:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\johnsadventures.com
[2009/06/07 14:26:23 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KeePass
[2012/01/20 22:17:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\lang
[2009/12/15 21:05:48 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Leadertech
[2011/06/03 08:27:16 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Lionhead Studios
[2010/01/22 10:10:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Magic Academy 2
[2010/05/26 20:56:33 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\MegaplexMadnessSummerBlockbuster
[2009/11/06 16:00:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Merscom
[2012/06/10 17:12:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\MinMaxGames
[2009/10/13 11:59:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Montpellier-Informatique
[2012/06/29 01:49:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Mp3tag
[2010/08/07 20:53:33 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\NavNet Solutions
[2013/02/20 15:25:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Nitro PDF
[2010/05/07 22:35:22 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Nvu
[2009/04/25 12:27:07 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\OpenOffice.org
[2010/03/27 07:59:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Peace Craft
[2009/06/13 00:21:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Pi Eye Games
[2011/02/11 10:54:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2009/11/14 14:00:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Playrix Entertainment
[2010/01/10 13:49:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Process Hacker
[2011/03/23 22:14:08 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PunkBuster
[2012/09/18 13:51:28 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\qBittorrent
[2012/06/01 21:24:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\redsn0w
[2009/07/16 21:47:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Reflexive JanesZOO
[2012/08/28 08:54:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\RenPy
[2009/11/16 21:46:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\RIM Palm&PPC Upgrade Wizard
[2010/06/21 21:01:24 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\rockbox.org
[2010/10/23 01:15:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Sahmon Games
[2013/03/23 12:14:55 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Samsung
[2011/07/01 16:35:23 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SanDisk
[2010/01/08 09:27:14 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Songbird2
[2009/08/24 18:46:15 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Stellarium
[2010/04/04 18:17:51 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\StreamTorrent
[2009/08/10 19:11:01 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SystemRequirementsLab
[2011/07/01 16:30:08 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Teleca
[2013/03/24 16:39:09 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TeraCopy
[2012/04/21 17:18:19 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TrueCrypt
[2012/05/11 19:17:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TuneUpMedia
[2010/12/21 20:01:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Ubisoft
[2009/06/28 08:29:02 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\UClick
[2011/02/13 20:30:54 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Unity
[2013/03/24 17:06:02 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2010/01/09 10:33:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ValuSoft
[2010/01/01 18:34:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Virtual City
[2013/03/22 21:29:08 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Warner Bros. Interactive Entertainment
[2010/11/07 17:59:44 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\YoudaGames
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:CEE4A457
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:4A966CC2
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C9B27A06
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:C8B8CEBD
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:751D6870
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:4B1CFD78
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:7631EA83
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:7EC01D6D
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6BFA43EB
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:99AC3203
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:8DD20B4A
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:7ADCE5D2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:1E86ADD2
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:151760F0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:EA7D76BE
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:EE7AAC75
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:8DD36B71
< End of report >