Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

HELP my Computer acting strange


  • Please log in to reply

#1
kid@hrt

kid@hrt

    Member

  • Member
  • PipPip
  • 55 posts
Hi

My PC is running slow and often crashes. The Administration permissions have been changed. When I try to delete a folder an error message tells me I don't have permission. I am the administrator.

I am always getting error messages, EXample... -- internet connection failed --

Sometimes MS Word icons will appear on the desktop that are invalid and look like this ~$sswords


Also Folder-Properties-Security I found an unknown account it is listed like this Account Unknown (S-1-5-21-2005915866-3535303436-4220142520-1011)
I tried removing the user and a error pops up
that says that it I can't remove the object because the object is inheriting permission from the parent

Thanks in advance for your help.
LISA

OTL Log:

OTL logfile created on: 4/20/2013 9:00:57 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Mom\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

6.00 Gb Total Physical Memory | 4.68 Gb Available Physical Memory | 77.98% Memory free
12.00 Gb Paging File | 10.72 Gb Available in Paging File | 89.37% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.73 Gb Total Space | 161.33 Gb Free Space | 69.32% Space Free | Partition Type: NTFS
Drive Z: | 100.00 Mb Total Space | 71.31 Mb Free Space | 71.31% Space Free | Partition Type: NTFS

Computer Name: MOM-PC | User Name: Mom | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/04/20 20:50:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mom\Desktop\OTL.exe
PRC - [2013/04/09 04:57:09 | 001,312,720 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2013/02/26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/12/18 15:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/09/06 11:32:12 | 000,519,920 | ---- | M] (iWin Inc.) -- C:\Program Files (x86)\Pogo Games\PGMTrusted.exe


========== Modules (No Company Name) ==========


========== Services (SafeList) ==========

SRV:64bit: - [2009/07/13 21:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 21:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2013/04/20 20:11:33 | 000,256,904 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/04/11 14:31:17 | 000,115,608 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2013/02/26 00:32:22 | 001,260,320 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/01/18 08:14:20 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2013/01/06 16:29:15 | 000,541,760 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/12/18 15:08:28 | 000,065,192 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/09/06 11:32:12 | 000,519,920 | ---- | M] (iWin Inc.) [Auto | Running] -- C:\Program Files (x86)\Pogo Games\PGMTrusted.exe -- (PGMTrusted)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/10 17:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/02/12 00:12:06 | 000,019,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usb8023x.sys -- (usb_rndisx)
DRV:64bit: - [2013/01/08 10:21:28 | 000,031,080 | ---- | M] (Wondershare) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VirtualAudio.sys -- (WsAudio_Device)
DRV:64bit: - [2012/07/03 11:25:16 | 000,189,288 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012/03/01 02:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/03/11 02:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 02:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 09:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 07:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 07:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/09/23 03:46:09 | 000,069,152 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2010/08/12 12:07:50 | 000,350,952 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2009/07/13 21:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 21:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 21:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/13 20:35:32 | 000,012,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\serscan.sys -- (StillCam)
DRV:64bit: - [2009/06/10 16:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 16:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 16:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 16:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 16:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2006/10/31 03:25:02 | 000,014,136 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BIOS64.sys -- (BIOS)
DRV - [2009/07/13 21:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2006/10/31 03:25:02 | 000,014,136 | R--- | M] (BIOSTAR Group) [Kernel | System | Running] -- C:\Windows\SysWOW64\drivers\BIOS64.sys -- (BIOS)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 A1 65 E4 A1 AD CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3256E555-06A8-47D2-B89F-EA400826E77F}: "URL" = http://www.mysearchr...q={searchTerms}
IE - HKCU\..\SearchScopes\{86A48AD6-8735-4506-9258-4E7D4CD05292}: "URL" = http://websearch.ask...11-F6676F7CE72D
IE - HKCU\..\SearchScopes\{D4D1E28B-32B3-481E-83A8-CFCB769E971E}: "URL" = http://us.yhs4.searc...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.14\npapicomadapter.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Mom\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Mom\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/04/11 14:31:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/04/11 14:31:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/11/15 16:15:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins [2013/02/20 15:15:45 | 000,000,000 | ---D | M]

[2013/04/07 21:14:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mom\AppData\Roaming\Mozilla\Extensions
[2010/12/05 19:37:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mom\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/04/12 13:52:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Mom\AppData\Roaming\Mozilla\Firefox\Profiles\oirl65bi.default-1365377985248\extensions
[2013/04/12 13:52:42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/11 14:31:17 | 000,263,064 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/09 10:43:47 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/02/28 11:21:09 | 000,002,086 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2013/04/20 20:26:59 | 000,000,194 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKCU..\Run: [C77B34DEB73DE0849E4BE289D36231EA4CA83D43._service_run] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Mom\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: RestrictRun = 0
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {1D082E71-DF20-4AAF-863B-596428C49874} http://www.worldwinn...0/tpir/tpir.cab (TPIR Control)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} http://www.worldwinn...ed/wwlaunch.cab (Wwlaunch Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F5AA37F8-C1BB-4651-A345-B8D6F02AE8C5}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F5AA37F8-C1BB-4651-A345-B8D6F02AE8C5}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found
O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...com [@ = comfile] -- Reg Error: Key error. File not found
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/04/20 20:50:46 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Mom\Desktop\OTL.exe
[2013/04/20 20:40:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2013/04/20 20:36:52 | 016,409,960 | ---- | C] (Safer Networking Limited ) -- C:\Users\Mom\Desktop\spybotsd162.exe
[2013/04/20 20:29:36 | 000,000,000 | ---D | C] -- C:\32788R22FWJFW
[2013/04/20 18:55:06 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Personal Payroll Manager
[2013/04/20 18:55:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Personal Payroll Manager
[2013/04/20 18:55:05 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ppm
[2013/04/19 17:34:14 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\Curious Sense
[2013/04/19 17:34:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Curious Sense
[2013/04/19 17:31:41 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Find Your Own Way Home
[2013/04/19 17:31:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Find Your Own Way Home
[2013/04/19 17:31:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Find Your Own Way Home
[2013/04/19 11:03:07 | 000,933,376 | ---- | C] (Synactis) -- C:\Windows\SysWow64\PDF_IN_THE_BOX.OCX
[2013/04/18 14:48:48 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Local\webkit
[2013/04/12 20:52:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2013/04/12 20:52:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Foto2Avi
[2013/04/12 13:43:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\InfoAtoms
[2013/04/12 10:57:43 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Local\12Pay_Ltd
[2013/04/11 17:12:10 | 000,000,000 | ---D | C] -- C:\Users\Mom\.thumbnails
[2013/04/11 14:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/04/10 22:33:01 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2013/04/10 22:04:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2013/04/10 14:23:45 | 003,717,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2013/04/10 14:23:45 | 003,217,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2013/04/10 14:23:44 | 000,158,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aaclient.dll
[2013/04/10 14:23:44 | 000,131,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\aaclient.dll
[2013/04/10 14:23:44 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2013/04/10 14:23:44 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2013/04/10 14:23:25 | 000,735,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2013/04/10 14:23:23 | 000,247,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2013/04/10 14:23:23 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2013/04/10 14:23:23 | 000,134,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2013/04/10 14:23:23 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2013/04/10 14:23:23 | 000,097,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2013/04/10 14:23:23 | 000,067,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2013/04/10 14:23:17 | 005,550,424 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2013/04/10 14:23:16 | 003,968,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2013/04/10 14:23:16 | 003,913,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2013/04/10 14:23:15 | 000,112,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\smss.exe
[2013/04/10 14:23:15 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\csrsrv.dll
[2013/04/10 14:23:15 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\apisetschema.dll
[2013/04/10 13:57:37 | 000,000,000 | R--D | C] -- C:\Users\Mom\Dropbox
[2013/04/10 13:54:16 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
[2013/04/10 13:00:22 | 000,000,000 | ---D | C] -- C:\ProgramData\xml_param
[2013/04/10 12:06:54 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\iSkysoft Video Converter Ultimate
[2013/04/10 12:06:52 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\{950EB46C-6AC7-4ACC-AB36-9A6A77C08B6A}
[2013/04/10 12:06:33 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Local\iSkysoft
[2013/04/10 12:06:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\iSkysoft
[2013/04/10 12:06:28 | 000,031,080 | ---- | C] (Wondershare) -- C:\Windows\SysNative\drivers\VirtualAudio.sys
[2013/04/10 12:06:24 | 000,000,000 | ---D | C] -- C:\ProgramData\iSkysoft Video Converter Ultimate
[2013/04/10 12:06:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iSkysoft
[2013/04/09 16:00:43 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/04/09 16:00:19 | 000,000,000 | ---D | C] -- C:\Users\Mom\Desktop\Van--Lean Daily
[2013/04/09 15:29:36 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/04/09 15:18:07 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/04/09 15:18:07 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/04/09 15:18:07 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/04/09 15:18:04 | 000,000,000 | ---D | C] -- C:\ComboFix
[2013/04/09 15:18:02 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/04/09 15:09:21 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERSetup
[2013/04/07 19:49:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2013/04/07 19:48:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/04/07 19:39:47 | 000,000,000 | ---D | C] -- C:\Users\Mom\Old Firefox Data
[2013/04/07 19:03:09 | 000,000,000 | R--D | C] -- C:\Users\Mom\Documents\Scanned Documents
[2013/04/07 19:03:09 | 000,000,000 | ---D | C] -- C:\Users\Mom\Documents\Fax
[2013/04/07 18:04:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2013/04/07 15:33:04 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\SUPERAntiSpyware.com
[2013/04/07 14:47:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox.bak
[2013/04/06 21:48:01 | 000,278,528 | ---- | C] (Simple Star, Inc.) -- C:\Windows\PhotoShow.scr
[2013/04/06 21:46:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Simple Star Shared
[2013/04/06 21:46:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simple Star
[2013/04/06 21:16:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sage Software
[2013/04/06 16:35:24 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\Simple Star
[2013/04/06 16:21:30 | 000,000,000 | ---D | C] -- C:\ProgramData\QuickTime
[2013/04/06 15:59:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Ulead Systems
[2013/04/06 15:41:10 | 000,249,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Ftsrch.dll
[2013/04/06 15:41:10 | 000,027,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CTL3DV2.DLL
[2013/04/06 15:40:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ulead Systems
[2013/04/05 16:07:12 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Local\Spotify
[2013/04/03 14:09:58 | 000,000,000 | ---D | C] -- C:\Users\Mom\Desktop\Van--More Daily
[2013/04/01 16:47:28 | 000,000,000 | ---D | C] -- C:\Program Files\Movie Maker
[2013/04/01 15:51:02 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\FreeCDRipper
[2013/03/31 19:49:25 | 000,164,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\COMCT232.OCX
[2013/03/31 19:49:24 | 002,084,864 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudDesign.dll
[2013/03/31 19:49:24 | 001,986,560 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudFile.dll
[2013/03/31 19:49:24 | 001,212,416 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudioInfos.dll
[2013/03/31 19:49:24 | 000,479,232 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudioVisu.dll
[2013/03/31 19:49:24 | 000,458,752 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudPlayer.dll
[2013/03/31 19:49:24 | 000,454,656 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudioRecord.dll
[2013/03/31 19:49:24 | 000,417,792 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\AudDisplay.dll
[2013/03/31 19:49:24 | 000,348,160 | ---- | C] (NCT Company Ltd.) -- C:\Windows\SysWow64\WMAFile.dll
[2013/03/31 19:49:24 | 000,119,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VB6FR.DLL
[2013/03/31 19:49:24 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\VB6STKIT.DLL
[2013/03/31 19:49:24 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetfr.DLL
[2013/03/31 19:49:23 | 000,141,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MSCMCFR.DLL
[2013/03/31 19:49:23 | 000,059,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\Mscc2fr.dll
[2013/03/31 19:49:23 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\CMDLGFR.DLL
[2013/03/31 19:49:23 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TABCTFR.DLL
[2013/03/31 19:49:23 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Roaming\FreeAudioPack
[2013/03/31 19:48:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Free mp3 Wma Converter
[2013/03/31 18:07:12 | 000,000,000 | ---D | C] -- C:\Users\Mom\AppData\Local\WMTools Downloaded Files
[2013/03/31 17:54:30 | 000,518,064 | ---- | C] (Codejock Software) -- C:\Windows\SysWow64\framework.ocx
[2013/03/31 17:54:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Movie Maker
[2013/03/25 22:05:40 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023x.sys
[2013/03/25 22:05:40 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usb8023.sys
[2 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/20 21:03:01 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2005915866-3535303436-4220142520-1000UA.job
[2013/04/20 20:50:49 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Mom\Desktop\OTL.exe
[2013/04/20 20:48:06 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/20 20:39:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/04/20 20:37:08 | 000,017,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/20 20:37:08 | 000,017,040 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/20 20:37:03 | 016,409,960 | ---- | M] (Safer Networking Limited ) -- C:\Users\Mom\Desktop\spybotsd162.exe
[2013/04/20 20:32:09 | 000,000,888 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/04/20 20:31:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/04/20 20:31:44 | 536,371,199 | -HS- | M] () -- C:\hiberfil.sys
[2013/04/20 20:26:59 | 000,000,194 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/04/20 20:23:44 | 000,816,128 | ---- | M] () -- C:\Users\Mom\Desktop\RogueKiller.exe
[2013/04/20 20:13:22 | 000,792,590 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/20 20:13:22 | 000,669,064 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/04/20 20:13:22 | 000,125,250 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/04/20 20:11:33 | 000,691,592 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/04/20 20:11:33 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/04/20 19:03:00 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2005915866-3535303436-4220142520-1000Core.job
[2013/04/20 15:43:48 | 000,029,622 | ---- | M] () -- C:\Users\Mom\AppData\Roaming\wklnhst.dat
[2013/04/19 17:33:02 | 000,001,274 | ---- | M] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2013/04/19 11:03:07 | 000,933,376 | ---- | M] (Synactis) -- C:\Windows\SysWow64\PDF_IN_THE_BOX.OCX
[2013/04/19 10:02:55 | 000,020,669 | ---- | M] () -- C:\Users\Mom\Documents\camping-checklist.pdf
[2013/04/18 15:14:38 | 000,008,526 | ---- | M] () -- C:\Users\Mom\AppData\Local\recently-used.xbel
[2013/04/17 14:55:16 | 000,032,531 | ---- | M] () -- C:\Users\Mom\Desktop\Gottshall_IBX_Temp_Card_04-17-13.pdf
[2013/04/12 10:57:31 | 000,000,000 | ---- | M] () -- C:\Users\Mom\AppData\Roaming\bibstats
[2013/04/10 23:47:36 | 000,485,632 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2013/04/10 22:30:54 | 000,000,426 | ---- | M] () -- C:\Windows\wininit.ini
[2013/04/10 13:57:37 | 000,001,035 | ---- | M] () -- C:\Users\Mom\Desktop\Dropbox.lnk
[2013/04/10 13:54:30 | 000,001,045 | ---- | M] () -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/04/10 11:34:58 | 000,319,277 | ---- | M] () -- C:\Users\Mom\Desktop\PA Extention.pdf
[2013/04/09 18:04:41 | 000,067,366 | ---- | M] () -- C:\Users\Mom\FDExtensionPDF.pdf
[2013/04/07 15:06:58 | 000,009,018 | ---- | M] () -- C:\Users\Mom\Documents\NPOFF12.zip
[2013/04/06 21:57:55 | 000,000,383 | ---- | M] () -- C:\Windows\ulead32.ini
[2013/04/06 21:50:39 | 000,001,409 | ---- | M] () -- C:\Windows\SysWow64\tmp5A166.FOT
[2013/04/06 21:50:39 | 000,001,409 | ---- | M] () -- C:\Windows\SysWow64\tmp3E166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | M] () -- C:\Windows\SysWow64\tmp90166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | M] () -- C:\Windows\SysWow64\tmp74166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | M] () -- C:\Windows\SysWow64\tmp67166.FOT
[2013/04/05 16:07:11 | 000,001,793 | ---- | M] () -- C:\Users\Mom\Spotify.lnk
[2013/04/01 16:43:41 | 011,543,552 | ---- | M] () -- C:\Users\Mom\Documents\wmm6_win7_64bit.msi
[2013/04/01 14:36:27 | 000,007,680 | ---- | M] () -- C:\Users\Mom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2 C:\Program Files (x86)\*.tmp files -> C:\Program Files (x86)\*.tmp -> ]
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/20 20:23:34 | 000,816,128 | ---- | C] () -- C:\Users\Mom\Desktop\RogueKiller.exe
[2013/04/19 17:33:02 | 000,001,274 | ---- | C] () -- C:\Users\Public\Desktop\More Great Games.lnk
[2013/04/19 10:02:55 | 000,020,669 | ---- | C] () -- C:\Users\Mom\Documents\camping-checklist.pdf
[2013/04/18 15:14:38 | 000,008,526 | ---- | C] () -- C:\Users\Mom\AppData\Local\recently-used.xbel
[2013/04/17 14:55:15 | 000,032,531 | ---- | C] () -- C:\Users\Mom\Desktop\Gottshall_IBX_Temp_Card_04-17-13.pdf
[2013/04/12 10:57:08 | 000,000,000 | ---- | C] () -- C:\Users\Mom\AppData\Roaming\bibstats
[2013/04/10 23:58:11 | 000,000,892 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2013/04/10 22:30:53 | 000,000,426 | ---- | C] () -- C:\Windows\wininit.ini
[2013/04/10 13:57:37 | 000,001,035 | ---- | C] () -- C:\Users\Mom\Desktop\Dropbox.lnk
[2013/04/10 13:54:30 | 000,001,045 | ---- | C] () -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/04/10 12:06:28 | 000,721,917 | ---- | C] () -- C:\Windows\SysWow64\ISCM64.dll
[2013/04/10 11:34:58 | 000,319,277 | ---- | C] () -- C:\Users\Mom\Desktop\PA Extention.pdf
[2013/04/09 18:04:41 | 000,067,366 | ---- | C] () -- C:\Users\Mom\FDExtensionPDF.pdf
[2013/04/09 15:18:07 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/04/09 15:18:07 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/04/09 15:18:07 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/04/09 15:18:07 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/04/09 15:18:07 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/04/07 15:06:58 | 000,009,018 | ---- | C] () -- C:\Users\Mom\Documents\NPOFF12.zip
[2013/04/06 21:50:39 | 000,001,409 | ---- | C] () -- C:\Windows\SysWow64\tmp5A166.FOT
[2013/04/06 21:50:39 | 000,001,409 | ---- | C] () -- C:\Windows\SysWow64\tmp3E166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | C] () -- C:\Windows\SysWow64\tmp90166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | C] () -- C:\Windows\SysWow64\tmp74166.FOT
[2013/04/06 21:50:38 | 000,001,409 | ---- | C] () -- C:\Windows\SysWow64\tmp67166.FOT
[2013/04/06 15:45:37 | 000,000,383 | ---- | C] () -- C:\Windows\ulead32.ini
[2013/04/05 16:07:11 | 000,001,793 | ---- | C] () -- C:\Users\Mom\Spotify.lnk
[2013/04/05 16:07:11 | 000,001,779 | ---- | C] () -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
[2013/04/01 16:47:28 | 000,000,987 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Movie Maker 6.0.lnk
[2013/04/01 16:43:14 | 011,543,552 | ---- | C] () -- C:\Users\Mom\Documents\wmm6_win7_64bit.msi
[2013/03/31 19:49:53 | 000,001,320 | ---- | C] () -- C:\Users\Mom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free mp3 Wma Converter.lnk
[2013/03/31 19:49:24 | 000,116,296 | ---- | C] () -- C:\Windows\SysWow64\NCTWMAProfiles.prx
[2013/03/31 17:59:55 | 000,007,680 | ---- | C] () -- C:\Users\Mom\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/12/25 14:33:34 | 000,000,091 | ---- | C] () -- C:\Users\Mom\AppData\Local\fusioncache.dat
[2012/11/21 18:25:19 | 000,000,102 | ---- | C] () -- C:\Users\Mom\jobq.dat
[2012/11/05 18:57:09 | 000,000,090 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2012/10/11 12:29:27 | 000,012,770 | ---- | C] () -- C:\Users\Mom\AppData\Local\slot1.mm1
[2012/06/24 16:09:18 | 000,007,603 | ---- | C] () -- C:\Users\Mom\AppData\Local\Resmon.ResmonCfg
[2012/06/18 02:15:36 | 000,000,362 | R-S- | C] () -- C:\ProgramData\ntuser.pol
[2012/05/11 19:14:43 | 000,000,515 | ---- | C] () -- C:\Windows\Viewer.INI
[2012/02/18 17:31:24 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2011/04/24 16:49:45 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/04/24 16:49:45 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/01/05 20:31:26 | 000,029,622 | ---- | C] () -- C:\Users\Mom\AppData\Roaming\wklnhst.dat

========== ZeroAccess Check ==========

[2009/07/14 00:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/06/09 01:43:10 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/09 00:41:00 | 012,873,728 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 21:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 08:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 21:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 96 bytes -> C:\ProgramData\TEMP:60A4BB64
@Alternate Data Stream - 404 bytes -> C:\ProgramData\TEMP:DC03B162
@Alternate Data Stream - 350 bytes -> C:\ProgramData\TEMP:214562D2
@Alternate Data Stream - 253 bytes -> C:\ProgramData\TEMP:D987CB43
@Alternate Data Stream - 224 bytes -> C:\ProgramData\TEMP:E4FCDFD9
@Alternate Data Stream - 222 bytes -> C:\ProgramData\TEMP:A02025CE
@Alternate Data Stream - 220 bytes -> C:\ProgramData\TEMP:27790C06
@Alternate Data Stream - 218 bytes -> C:\ProgramData\TEMP:BD27B7FC
@Alternate Data Stream - 201 bytes -> C:\ProgramData\TEMP:4E6B8D68
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:CD609535
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:984285E6
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:501DF0E0
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EBDA021F
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:1C159B9A
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:721C42E8
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:405D842B
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3FAE5A2A
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7D288858
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:409D7106
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:C682ED73
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:F3BA8C7D
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:8B1756C2
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:43982D5E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:56C66609
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:4A01545C
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:BADF2274
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:3571475C
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:EF258AD5
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:32211F93
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:993185CB
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:D4A06B44
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5D2A2F0A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:90876BA3
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:FCD3A761
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:4977A107
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:17927369
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:12EA4DC9
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:6C5EC3CD
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:DF0BC727

< End of report >
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP