Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Slow, no Start Menu, can't dowload or Run programs. [Closed]


  • This topic is locked This topic is locked

#1
worldwidewandering

worldwidewandering

    Member

  • Member
  • PipPip
  • 22 posts
Hello,

I have a badly infected laptop that I can do very little with and I'm having to use the desktop to download the required software and post to this forum.

I can't download anything from the internet from the laptop (I can now since uninstalling some items). I cannot access the Start menu at all to get to the control panel to try to uninstall anything. The Start menu simply shows a blank white screen (I can get into Windows Explorer to get to files, including Control Panel.). I downloaded some programs from my desktop to a thumb drive: CCleaner, Spybot Search and Destroy, and MalwareBytes, when I remembered geeks to go and downloaded OTL to the thumb-drive and ran it on my laptop. (I did eventually run CCleaner and Spybot search and destroy but could not run Malwarbytes. When I clicked "Scan" it would start to run but then shut down, I figured I'd go through the geeks to go process step by step.)

I am still unable to run Malwarebytes.

I started running a full scan with OTL, and it had been running for awhile, when I realized it was set to scan files created and/or modified within a 30 day file age. This laptop has been broken for a lot longer than 30 days and has just been sitting unused for several months. I let the 30 day scan run its course and create a log file, then ran another scan to scan Files Created Within All and Files Modified Within All files. I'm attaching both log files.

After I realized I could access the Control Panel via Windows Explorer I uninstalled many programs including AVS4USoftware Manager and associated files,

After uninstalling all of this stuff I re-ran the OTL program one last time to scan Files Created Within All and Files Modified Within All files. I'm attaching this log file as well.

The Attachement named OTL-30-day-file-age-scan.txt is the first OTL scan I ran, before uninstalling programs and running CClearner and Spybot, and it was only for a 30 day file age. The attahcment named OTL-latest-all-files.txt is the one I just ran that included all file ages.

Thanks,

Eric

-----------
- OTL Log -
-----------

OTL logfile created on: 9/9/2013 3:27:06 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = G:\Computer Fix
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.37 Gb Total Physical Memory | 2.17 Gb Available Physical Memory | 64.37% Memory free
6.93 Gb Paging File | 5.76 Gb Available in Paging File | 83.17% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.21 Gb Total Space | 10.26 Gb Free Space | 10.34% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.04 Gb Free Space | 60.36% Space Free | Partition Type: NTFS
Drive G: | 29.06 Gb Total Space | 28.89 Gb Free Space | 99.42% Space Free | Partition Type: FAT32

Computer Name: WORLWIDE-PC | User Name: worlwidewandering | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/09/08 13:05:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- G:\Computer Fix\OTL.exe
PRC - [2013/09/08 12:18:49 | 000,914,264 | ---- | M] (BitTorrent Inc.) -- C:\Users\worlwidewandering\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2013/08/29 23:43:40 | 000,206,624 | ---- | M] (LinkSwift) -- C:\Program Files\LinkSwift\updateLinkSwift.exe
PRC - [2013/07/30 22:56:08 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2013/07/25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/05/16 10:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/05/16 10:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/05/15 13:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013/05/10 03:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/05/08 02:18:34 | 002,852,640 | ---- | M] (Conduit) -- C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\bin\cltmng.exe
PRC - [2013/05/08 02:18:34 | 000,097,056 | ---- | M] (Conduit) -- C:\Program Files\SearchProtect\bin\CltMngSvc.exe
PRC - [2013/04/16 03:07:08 | 000,039,056 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/01/25 12:51:40 | 000,422,360 | ---- | M] (PC Utilities Pro) -- C:\Program Files\Optimizer Pro\OptProSmartScan.exe
PRC - [2012/08/21 05:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/08/21 05:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009/05/21 11:55:32 | 000,206,064 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/08/13 18:32:40 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/08/04 09:45:16 | 005,779,456 | -H-- | M] () -- c:\xampp\mysql\bin\mysqld-nt.exe
PRC - [2008/07/07 03:34:59 | 000,167,936 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2008/01/19 03:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/09/07 14:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/09/07 14:23:36 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
PRC - [2007/08/29 17:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/08/29 01:54:58 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM02Mon.exe


========== Modules (No Company Name) ==========

MOD - [2013/08/23 05:10:12 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\59eba2680c01c33b2b3f5385979e32c6\System.Web.ni.dll
MOD - [2013/08/23 05:09:19 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b167ef6967ad27503c6ac6aabcef1aff\System.Runtime.Remoting.ni.dll
MOD - [2013/08/23 05:01:47 | 005,462,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09f5b3f7a363b742a73937e818595597\System.Xml.ni.dll
MOD - [2013/08/23 04:49:26 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\d7153acb7b6ccb5a6a886d6f0ab732b1\System.ni.dll
MOD - [2013/08/07 15:25:24 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2013/07/20 15:13:19 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll
MOD - [2013/05/16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2007/12/12 02:01:24 | 000,054,784 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2007/08/14 04:40:54 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007/03/02 13:44:34 | 000,073,728 | -H-- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
MOD - [2007/01/17 12:36:38 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2013/08/29 23:43:40 | 000,206,624 | ---- | M] (LinkSwift) [Auto | Running] -- C:\Program Files\LinkSwift\updateLinkSwift.exe -- (Update LinkSwift)
SRV - [2013/08/22 04:45:52 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/10 03:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/05/08 02:18:34 | 000,097,056 | ---- | M] (Conduit) [Auto | Running] -- C:\Program Files\SearchProtect\bin\CltMngSvc.exe -- (CltMngSvc)
SRV - [2013/04/16 03:07:08 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/08/21 05:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/05/25 15:14:34 | 000,053,248 | -H-- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper)
SRV - [2009/12/01 20:43:02 | 000,051,384 | -H-- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper)
SRV - [2008/09/21 16:54:26 | 000,654,848 | -H-- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/08/13 18:32:40 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/08/04 09:45:16 | 005,779,456 | -H-- | M] () [Auto | Running] -- c:\xampp\mysql\bin\mysqld-nt.exe -- (mysql)
SRV - [2008/07/30 04:53:08 | 000,587,776 | -H-- | M] (FileZilla Project) [On_Demand | Stopped] -- c:\xampp\FileZillaFTP\FileZillaServer.exe -- (FileZilla Server)
SRV - [2008/06/14 13:02:12 | 000,017,408 | -H-- | M] (Apache Software Foundation) [Auto | Stopped] -- c:\xampp\apache\bin\apache.exe -- (Apache2.2)
SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/07 09:58:18 | 003,004,416 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90)
SRV - [2007/09/07 14:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/08/29 17:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/05/31 11:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 11:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\BCM42RLY.sys -- (BCM42RLY)
DRV - [2013/09/09 13:53:19 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/08/21 05:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/08/21 05:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/08/21 05:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/08/21 05:13:14 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012/08/21 05:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/08/21 05:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2008/12/30 11:57:54 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2008/12/13 11:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/07 03:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/09/07 14:26:04 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/08/29 01:55:06 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2007/08/29 01:54:56 | 000,235,520 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/08/14 04:40:52 | 002,593,280 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2007/08/14 04:40:52 | 002,593,280 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2006/11/21 08:25:44 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/15 04:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/14 23:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/14 21:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/02 03:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2006/10/30 12:23:12 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2006/08/04 20:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {B8FAC445-74FE-4E40-B933-4414C9CCA206}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...ie7&rlz=1I7DKUS
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.alistapart.com/articles [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...2E-F24E7593AB03
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\URLSearchHook: {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {B8FAC445-74FE-4E40-B933-4414C9CCA206}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7DKUS_enUS293
IE - HKCU\..\SearchScopes\{B8FAC445-74FE-4E40-B933-4414C9CCA206}: "URL" = http://search.condui...3291569406&UM=2
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 68.234.11.193:52931

========== FireFox ==========



FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/03 10:50:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/07/30 23:19:13 | 000,000,000 | ---D | M]

[2010/02/28 16:02:13 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Extensions
[2010/02/28 16:02:13 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2013/09/09 09:13:44 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions
[2011/04/09 15:19:56 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/25 22:16:10 | 000,000,000 | -H-D | M] (SeoQuake) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2012/08/01 00:43:46 | 000,000,000 | ---D | M] (uTorrentControl2) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/10/10 13:43:37 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2008/09/21 23:03:17 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus®)) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2013/04/29 13:50:29 | 000,000,000 | ---D | M] ("Supreme Savings") -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
[2012/09/03 10:52:47 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
[2013/09/09 09:13:47 | 000,000,000 | ---D | M] (Define Ext) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
[2013/04/29 13:50:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome\content\extensionCode
[2012/07/31 13:33:00 | 000,375,811 | -H-- | M] () (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
[2008/09/22 13:53:13 | 000,001,504 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\searchplugins\imdb.xml
[2013/09/09 09:13:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/18 09:08:16 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2013/09/09 09:13:21 | 000,000,000 | ---D | M] (Define Ext) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.condui...=CT3298569&UM=2
CHR - default_search_provider: suggest_url = http://suggest.searc...8439382629&UM=2
CHR - homepage: http://search.condui...0295029404&UM=2
CHR - plugin: First user (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Error reading preferences file
CHR - Extension: Entanglement Web App = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\3.4.9_0\
CHR - Extension: TidyNetwork.com = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\didgecifffmcpanneoplfbplpfamlfbo\5.0.0.0_0\
CHR - Extension: Define Ext = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjkpcnacdgdlpfejlgflolpaigoicibh\1_0\
CHR - Extension: RealDownloader = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0\
CHR - Extension: Poppit = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\

O1 HOSTS File: ([2012/07/31 21:14:54 | 000,444,955 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 15287 more lines...
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (LinkSwift) - {323420b6-65e5-4657-8106-a27392d4d4aa} - C:\Program Files\LinkSwift\LinkSwiftBHO.dll (LinkSwift)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (BrowserPlus2 Toolbar) - {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - {7736C7FA-512D-11E2-B871-DEC36088709B} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (Define) - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Users\worlwidewandering\AppData\Local\DefineExt\temp.dat ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (BrowserPlus2 Toolbar) - {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe File not found
O4 - HKCU..\Run: [ConduitFloatingPlugin_iigplimlmgilpobjilfbfeilnpiigpgl] C:\Program Files\Conduit\CT3309350\plugins\TBVerifier.dll (Conduit Ltd.)
O4 - HKCU..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)
O4 - HKCU..\Run: [SearchProtect] C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKCU..\Run: [uTorrent] C:\Users\worlwidewandering\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A6D045D-F913-4C55-8264-412D607133E2}: DhcpNameServer = 65.32.5.111 65.32.5.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7621F659-A2C4-45EC-A429-0FC6962D71F1}: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Users\worlwidewandering\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\worlwidewandering\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/04/14 22:54:30 | 000,000,166 | ---- | M] () - G:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{b9153ec7-b122-11e0-ac69-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b9153ec7-b122-11e0-ac69-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b9153f2a-b122-11e0-ac69-001d09b9bf0f}\Shell - "" = AutoRun
O33 - MountPoints2\{b9153f2a-b122-11e0-ac69-001d09b9bf0f}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within (All) ==========

[2013/09/09 09:39:39 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\FileZilla
[2013/09/09 09:37:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2013/09/09 09:36:50 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2013/09/09 09:29:46 | 000,000,000 | ---D | C] -- C:\Program Files\LinkSwift
[2013/09/09 09:23:10 | 000,000,000 | ---D | C] -- C:\Program Files\BrowserPlus2
[2013/09/09 09:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\SearchProtect
[2013/09/09 09:19:36 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\SearchProtect
[2013/09/09 09:17:20 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro
[2013/09/09 09:17:08 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013/09/09 09:15:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro
[2013/09/09 09:14:58 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro
[2013/09/09 09:14:32 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Define Ext
[2013/09/09 09:12:53 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Local\DefineExt
[2013/09/09 09:12:32 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com
[2013/09/08 19:45:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/09/08 19:44:30 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe
[2013/09/08 19:43:08 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2
[2013/09/08 19:08:25 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\InstallShield
[2013/08/23 04:04:03 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2013/07/20 14:11:59 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2013/07/20 03:21:36 | 000,000,000 | ---D | C] -- C:\e6693ab7f41805e9ea12f632db0240
[2013/07/16 01:57:30 | 000,000,000 | ---D | C] -- C:\ca62737c8491fca7d51dab
[2013/06/01 23:16:10 | 000,000,000 | ---D | C] -- C:\e07e4e18708b61a361
[2013/05/17 03:37:43 | 000,000,000 | ---D | C] -- C:\2ff1017f2c771a07529a4e4aac62a7c9
[2013/05/13 05:35:43 | 000,000,000 | ---D | C] -- C:\SearchProtect
[2013/03/31 00:40:40 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Documents\New Folder
[2013/03/25 22:30:07 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Documents\Wondershare Video Editor
[2012/11/05 15:48:50 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Documents\AVS4YOU
[2012/10/10 13:42:50 | 000,018,776 | ---- | C] (Systweak Inc., (www.systweak.com)) -- C:\Windows\System32\roboot.exe
[2012/08/20 13:20:29 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Desktop\My Vaults
[2012/08/13 21:19:19 | 027,311,232 | ---- | C] (Gemalto N.V.) -- C:\Users\worlwidewandering\Desktop\RunSanDiskSecureAccess_Win.exe
[2012/08/13 20:25:12 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Desktop\SanDiskSecureAccess
[2012/08/13 20:24:40 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Desktop\club_application
[2012/08/13 20:23:16 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Desktop\Internet Marketing
[2012/08/13 20:21:08 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Desktop\Bus Schedule
[2012/07/31 13:25:22 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012/07/02 16:16:51 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\invoice_7-1
[2011/07/19 01:59:35 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\EU2011A
[2011/07/19 01:55:51 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\100NCD50
[2011/07/18 05:53:14 | 000,621,056 | ---- | C] (DiBcom SA) -- C:\Windows\System32\drivers\mod7700.sys
[2011/07/18 05:53:14 | 000,112,128 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys
[2011/07/18 05:53:14 | 000,103,040 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbfake.sys
[2011/07/18 05:53:14 | 000,102,784 | ---- | C] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys
[2011/07/18 05:53:14 | 000,023,424 | ---- | C] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys
[2011/07/17 13:19:00 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\2002 with Anne
[2011/07/16 12:37:46 | 000,086,016 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2011/07/14 20:43:07 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\Germany
[2011/05/13 06:28:19 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2011/04/30 16:51:07 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/04/18 22:36:20 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\OneNote Notebooks
[2011/04/15 22:17:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2011/04/15 22:17:41 | 000,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2011/04/15 22:17:40 | 000,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2011/04/15 20:38:48 | 000,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2011/04/15 10:41:41 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/04/15 10:40:19 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/04/11 00:33:03 | 000,000,000 | -H-D | C] -- C:\fa25e7e723494764a221a0
[2011/04/10 11:47:26 | 000,000,000 | ---D | C] -- C:\Windows\System32\WindowsPowerShell
[2011/04/09 19:30:16 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\2011
[2011/04/09 14:59:21 | 000,729,752 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/04/09 13:40:53 | 000,044,544 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe
[2010/08/20 15:22:27 | 000,034,816 | ---- | C] (Absolute Software Corporation) -- C:\Windows\System32\identprv.dll
[2010/08/20 15:22:27 | 000,032,256 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\instd32.exe
[2010/08/03 13:00:21 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2010/07/23 20:30:54 | 000,000,000 | -H-D | C] -- C:\ArchonMedia
[2010/07/23 20:00:47 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\Web2Mayhem
[2010/05/18 08:48:52 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\swiss sciences_laptop
[2010/05/08 16:04:35 | 000,021,256 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/08 16:04:34 | 000,355,632 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2010/05/08 16:04:31 | 000,035,928 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2010/05/08 16:04:29 | 000,054,232 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2010/05/08 16:04:24 | 000,058,680 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/08 16:02:41 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2009/11/02 20:51:14 | 000,009,728 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\wceprv.dll
[2009/02/13 22:05:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\js
[2009/02/13 22:05:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\images
[2009/02/13 22:05:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\html
[2009/02/13 22:05:05 | 000,000,000 | ---D | C] -- C:\Windows\System32\css
[2009/02/13 21:33:30 | 000,000,000 | ---D | C] -- C:\Windows\symbols
[2009/02/13 21:32:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\1033
[2009/02/13 21:23:03 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Visual Studio 2008
[2009/01/21 19:02:15 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\Flash Professional CS3
[2008/12/20 17:02:29 | 000,000,000 | -H-D | C] -- C:\xampp
[2008/12/17 23:28:03 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\My Websites
[2008/11/27 19:02:03 | 000,000,000 | ---D | C] -- C:\PerfLogs
[2008/10/17 22:19:30 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2008/10/12 12:46:37 | 000,000,000 | ---D | C] -- C:\Windows\System32\Profiles
[2008/10/09 23:11:32 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Drawing1_files
[2008/10/08 20:55:41 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\MM_DWCS3
[2008/10/07 23:00:35 | 000,000,000 | --SD | C] -- C:\Users\worlwidewandering\Documents\Minhas Formas
[2008/10/02 22:46:08 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Read
[2008/10/01 21:44:44 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Web Learning
[2008/10/01 18:54:55 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\Photoshop CS3 Creative Photographic Techniques
[2008/09/28 22:28:59 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\tidy4aug00
[2008/09/28 10:01:51 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Money
[2008/09/27 22:57:00 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Desktop\Photoshop CS3 for Web Designers
[2008/09/27 16:31:52 | 000,000,000 | -H-D | C] -- C:\Users\Public\Documents\Yahoo
[2008/09/26 20:43:27 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\ConvertXtoDVD
[2008/09/26 09:42:09 | 000,116,736 | ---- | C] (MagicISO, Inc.) -- C:\Windows\System32\drivers\mcdbus.sys
[2008/09/22 19:33:58 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\AdobeStockPhotos
[2008/09/22 19:08:53 | 000,047,360 | -H-- | C] (VSO Software) -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.sys
[2008/09/22 19:08:53 | 000,047,360 | ---- | C] (VSO Software) -- C:\Windows\System32\drivers\pcouffin.sys
[2008/09/22 19:08:41 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2008/09/22 19:08:40 | 000,626,688 | ---- | C] (On2.com) -- C:\Windows\System32\vp7vfw.dll
[2008/09/22 19:01:16 | 000,000,000 | ---D | C] -- C:\Windows\WinRAR
[2008/09/22 00:12:21 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\My Google Gadgets
[2008/09/22 00:09:23 | 000,000,000 | -HSD | C] -- C:\Users\worlwidewandering\Documents\My Videos
[2008/09/22 00:09:23 | 000,000,000 | -HSD | C] -- C:\Users\worlwidewandering\Documents\My Pictures
[2008/09/22 00:09:23 | 000,000,000 | -HSD | C] -- C:\Users\worlwidewandering\Documents\My Music
[2008/09/21 23:17:16 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Videos
[2008/09/21 23:17:16 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Pictures
[2008/09/21 23:17:16 | 000,000,000 | -HSD | C] -- C:\Users\Public\Documents\My Music
[2008/09/21 22:31:44 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\School
[2008/09/21 15:34:54 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2008/09/21 15:29:13 | 000,000,000 | ---D | C] -- C:\Windows\SHELLNEW
[2008/09/21 15:27:30 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2008/09/21 15:10:09 | 000,000,000 | -H-D | C] -- C:\Users\worlwidewandering\Documents\Downloads
[2008/09/21 14:16:09 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2008/07/07 03:40:49 | 000,056,108 | ---- | C] (PowerISO Computing, Inc.) -- C:\Windows\System32\drivers\scdemu.sys
[2008/01/21 21:43:33 | 000,049,152 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\instw32.exe
[2008/01/12 00:45:32 | 000,043,520 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rimsptsk.sys
[2008/01/12 00:45:32 | 000,037,376 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rixdptsk.sys
[2008/01/12 00:45:32 | 000,032,256 | ---- | C] (REDC) -- C:\Windows\System32\drivers\rimmptsk.sys
[2008/01/12 00:45:27 | 000,811,008 | ---- | C] (Pizzolato Davide - www.xdp.it) -- C:\Windows\System32\cximage.dll
[2008/01/12 00:45:27 | 000,007,424 | ---- | C] (EyePower Games Pte. Ltd.) -- C:\Windows\System32\drivers\OEM02Vfx.sys
[2008/01/12 00:45:26 | 000,110,592 | ---- | C] (Synaptics, Inc.) -- C:\Windows\System32\SynTPCo4.dll
[2008/01/12 00:45:25 | 000,196,608 | ---- | C] (Synaptics, Inc.) -- C:\Windows\System32\SynCtrl.dll
[2008/01/12 00:45:25 | 000,163,840 | ---- | C] (Synaptics, Inc.) -- C:\Windows\System32\SynCOM.dll
[2008/01/12 00:45:25 | 000,143,360 | ---- | C] (Synaptics, Inc.) -- C:\Windows\System32\SynTPAPI.dll
[2008/01/12 00:45:20 | 000,182,456 | ---- | C] (Synaptics, Inc.) -- C:\Windows\System32\drivers\SynTP.sys
[2008/01/12 00:45:16 | 000,595,968 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stapo.dll
[2008/01/12 00:45:16 | 000,330,240 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\drivers\stwrt.sys
[2008/01/12 00:45:16 | 000,328,704 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stcplx.dll
[2008/01/12 00:45:16 | 000,299,520 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stapi32.dll
[2008/01/12 00:45:16 | 000,146,944 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\staco.dll
[2008/01/12 00:31:43 | 000,000,000 | ---D | C] -- C:\Windows\Users
[2008/01/12 00:26:06 | 000,000,000 | -H-D | C] -- C:\doctemp
[2008/01/12 00:23:55 | 000,000,000 | ---D | C] -- C:\Windows\System32\oem
[2008/01/12 00:23:54 | 000,000,000 | -H-D | C] -- C:\Drivers
[2008/01/12 00:23:54 | 000,000,000 | -H-D | C] -- C:\DELL
[2008/01/11 17:19:25 | 000,000,000 | -H-D | C] -- C:\Documents and Settings
[2008/01/11 17:18:51 | 005,627,904 | ---- | C] (Reallusion Inc.) -- C:\Windows\System32\LiveCamVirtual.ocx
[2008/01/11 17:17:36 | 000,000,000 | ---D | C] -- C:\Windows\Downloaded Installations
[2008/01/11 17:08:47 | 000,000,000 | ---D | C] -- C:\Windows\java
[2008/01/11 17:05:49 | 000,000,000 | -HSD | C] -- C:\Windows\Installer
[2008/01/11 17:04:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2008/01/11 16:52:17 | 000,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2008/01/11 16:51:39 | 004,947,968 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stacgui.cpl
[2008/01/11 16:51:39 | 000,102,400 | ---- | C] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
[2007/05/17 15:38:24 | 000,014,848 | ---- | C] (Absolute Software Corp.) -- C:\Windows\System32\DIAGDLL64.DLL
[2006/11/10 18:01:29 | 000,000,000 | ---D | C] -- C:\Windows\Debug
[2006/11/10 18:00:07 | 000,000,000 | ---D | C] -- C:\Windows\Prefetch
[2006/11/10 17:59:19 | 000,000,000 | ---D | C] -- C:\Windows\Panther
[2006/11/10 17:59:05 | 000,000,000 | -HSD | C] -- C:\Boot
[2006/11/02 08:45:10 | 000,000,000 | ---D | C] -- C:\Windows\Setup
[2006/11/02 08:45:07 | 000,000,000 | ---D | C] -- C:\Windows\ServiceProfiles
[2006/11/02 08:45:01 | 000,000,000 | --SD | C] -- C:\Windows\System32\Microsoft
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\winrm
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\WindowsMobile
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\slmgr
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\UMDF\en-US
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\en-US
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\en-US
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\en
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\Branding
[2006/11/02 08:40:00 | 000,000,000 | ---D | C] -- C:\Windows\System32\0409
[2006/11/02 08:39:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\WCN
[2006/11/02 08:39:59 | 000,000,000 | ---D | C] -- C:\Windows\System32\Printing_Admin_Scripts
[2006/11/02 08:39:01 | 000,004,096 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\en-US\pscr.sys.mui
[2006/11/02 08:39:01 | 000,004,096 | ---- | C] (SCM Microsystems) -- C:\Windows\System32\drivers\en-US\SCR111.sys.mui
[2006/11/02 08:39:01 | 000,004,096 | ---- | C] (Gemplus) -- C:\Windows\System32\drivers\en-US\grserial.sys.mui
[2006/11/02 08:39:01 | 000,003,584 | ---- | C] (Gemplus) -- C:\Windows\System32\drivers\en-US\gpr400.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | C] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\en-US\stcusb.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | C] (OMNIKEY) -- C:\Windows\System32\drivers\en-US\cxbp0wdm.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | C] (OMNIKEY AG) -- C:\Windows\System32\drivers\en-US\cmbp0wdm.sys.mui
[2006/11/02 08:38:55 | 000,010,240 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\en-US\BrSerId.sys.mui
[2006/11/02 08:38:53 | 000,009,728 | ---- | C] (Agere Systems) -- C:\Windows\System32\drivers\en-US\ltmdmnt.sys.mui
[2006/11/02 08:38:53 | 000,005,632 | ---- | C] (Marvell) -- C:\Windows\System32\drivers\en-US\yk60x86.sys.mui
[2006/11/02 08:38:32 | 000,004,096 | ---- | C] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\en-US\ntrigdigi.sys.mui
[2006/11/02 08:38:27 | 000,002,560 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\en-US\BrParwdm.sys.mui
[2006/11/02 08:35:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\XPSViewer
[2006/11/02 08:35:51 | 000,000,000 | ---D | C] -- C:\Windows\twain_32
[2006/11/02 08:35:51 | 000,000,000 | ---D | C] -- C:\Windows\System32\restore
[2006/11/02 08:35:51 | 000,000,000 | ---D | C] -- C:\Windows\Performance
[2006/11/02 08:35:51 | 000,000,000 | ---D | C] -- C:\Windows\DigitalLocker
[2006/11/02 07:18:44 | 000,000,000 | -H-D | C] -- C:\Windows\tracing
[2006/11/02 07:18:44 | 000,000,000 | ---D | C] -- C:\Windows\winsxs
[2006/11/02 07:18:44 | 000,000,000 | ---D | C] -- C:\Windows\Web
[2006/11/02 07:18:44 | 000,000,000 | ---D | C] -- C:\Windows\Temp
[2006/11/02 07:18:44 | 000,000,000 | ---D | C] -- C:\Windows\Tasks
[2006/11/02 07:18:44 | 000,000,000 | ---D | C] -- C:\Windows\tapi
[2006/11/02 07:18:43 | 000,000,000 | -H-D | C] -- C:\Windows\System32\Tasks
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\zh-TW
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\zh-HK
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\zh-CN
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\winevt
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\wfp
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\WDI
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\wbem
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\uk-UA
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\tr-TR
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\th-TH
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\sysprep
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\sv-SE
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\sr-Latn-CS
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\spool
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\Speech
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\SMI
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\SLUI
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\sl-SI
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\sk-SK
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\setup
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\ru-RU
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\ro-RO
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\RemInst
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\ras
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\pt-PT
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\pt-BR
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\pl-PL
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\oobe
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\nl-NL
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\networklist
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\NDF
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\nb-NO
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\MUI
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\Msdtc
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\migwiz
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\migration
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\manifeststore
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\lv-LV
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\lt-LT
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\LogFiles
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\licensing
[2006/11/02 07:18:43 | 000,000,000 | ---D | C] -- C:\Windows\System32\ko-KR
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\ja-JP
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\it-IT
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\inetsrv
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\IME
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\icsxml
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\ias
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\hu-HU
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\hr-HR
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\he-IL
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\GroupPolicyUsers
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\GroupPolicy
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\fr-FR
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\fi-FI
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\et-EE
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\es-ES
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\en-US
[2006/11/02 07:18:42 | 000,000,000 | ---D | C] -- C:\Windows\System32\el-GR
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\UMDF
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\system
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\Speech
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\servicing
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\security
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\schemas
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\SchCache
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\Resources
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\rescache
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\registration
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\Provisioning
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\PolicyDefinitions
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers\etc
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\DriverStore
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\drivers
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\de-DE
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\da-DK
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\cs-CZ
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\config
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\com
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\CodeIntegrity
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot2
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\catroot
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\Boot
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\bg-BG
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\ar-SA
[2006/11/02 07:18:36 | 000,000,000 | ---D | C] -- C:\Windows\System32\AdvancedInstallers
[2006/11/02 07:18:35 | 000,000,000 | R-SD | C] -- C:\Windows\Media
[2006/11/02 07:18:35 | 000,000,000 | R--D | C] -- C:\Windows\Offline Web Pages
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\PLA
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\nap
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\MSAgent
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\ModemLogs
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\Microsoft.NET
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\Logs
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\LiveKernelReports
[2006/11/02 07:18:35 | 000,000,000 | ---D | C] -- C:\Windows\L2Schemas
[2006/11/02 07:18:34 | 000,000,000 | --SD | C] -- C:\Windows\Downloaded Program Files
[2006/11/02 07:18:34 | 000,000,000 | R-SD | C] -- C:\Windows\Fonts
[2006/11/02 07:18:34 | 000,000,000 | R-SD | C] -- C:\Windows\assembly
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\inf
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\IME
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\Help
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\Globalization
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\Cursors
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\Branding
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\Boot
[2006/11/02 07:18:34 | 000,000,000 | ---D | C] -- C:\Windows\AppPatch
[2006/11/02 07:18:33 | 000,000,000 | R--D | C] -- C:\Users
[2006/11/02 07:18:33 | 000,000,000 | R--D | C] -- C:\Program Files
[2006/11/02 07:18:33 | 000,000,000 | -H-D | C] -- C:\ProgramData
[2006/11/02 07:17:19 | 000,000,000 | -HSD | C] -- C:\$Recycle.Bin
[2006/11/02 06:32:57 | 000,101,888 | ---- | C] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll
[2006/11/02 06:32:57 | 000,082,432 | ---- | C] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll
[2006/11/02 05:38:56 | 000,013,568 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltLo.sys
[2006/11/02 05:38:00 | 000,011,904 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbSer.sys
[2006/11/02 05:37:31 | 000,012,160 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbMdm.sys
[2006/11/02 05:37:24 | 000,005,248 | ---- | C] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltUp.sys
[2006/11/02 05:36:51 | 000,062,336 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerWdm.sys
[2006/11/02 05:36:34 | 000,017,408 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\brcoinst.dll
[2006/11/02 05:22:06 | 000,071,808 | ---- | C] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerId.sys
[2006/11/02 03:36:50 | 000,020,608 | ---- | C] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\ntrigdigi.sys
[2006/11/02 03:36:49 | 000,071,272 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\djsvs.sys
[2006/11/02 03:36:48 | 000,235,112 | ---- | C] (ULi Electronics Inc.) -- C:\Windows\System32\drivers\uliahci.sys
[2006/11/02 03:36:48 | 000,071,784 | ---- | C] (Silicon Integrated Systems) -- C:\Windows\System32\drivers\sisraid4.sys
[2006/11/02 03:36:45 | 000,035,944 | ---- | C] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteatapi.sys
[2006/11/02 03:36:44 | 000,316,520 | ---- | C] (Emulex) -- C:\Windows\System32\drivers\elxstor.sys
[2006/11/02 03:36:44 | 000,067,688 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arcsas.sys
[2006/11/02 03:36:44 | 000,067,688 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arc.sys
[2006/11/02 03:36:44 | 000,035,944 | ---- | C] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteraid.sys
[2006/11/02 03:36:43 | 000,420,968 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adp94xx.sys
[2006/11/02 03:36:43 | 000,297,576 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpahci.sys
[2006/11/02 03:36:43 | 000,147,048 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu320.sys
[2006/11/02 03:36:43 | 000,098,408 | ---- | C] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu160m.sys
[2006/09/17 01:36:50 | 000,770,048 | ---- | C] (Gracenote) -- C:\Windows\System32\CDDBUIRoxio.dll
[2006/09/17 01:36:50 | 000,643,072 | ---- | C] (Gracenote, Inc.) -- C:\Windows\System32\CDDBControlRoxio.dll
[2006/09/17 01:36:50 | 000,585,728 | ---- | C] (Gracenote) -- C:\Windows\System32\CddbMusicIDRoxio.dll
[2006/09/17 01:36:50 | 000,090,112 | ---- | C] (Gracenote) -- C:\Windows\System32\CddbWOManagerRoxio.dll
[2006/09/17 01:36:48 | 000,147,456 | ---- | C] (Gracenote) -- C:\Windows\System32\CddbCleanRoxio.dll

========== Files - Modified Within (All) ==========

[2013/09/09 16:35:51 | 012,845,056 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat
[2013/09/09 16:09:39 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/09 15:40:06 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/09 15:16:03 | 000,000,644 | ---- | M] () -- C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/09/09 15:14:27 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/09 15:13:27 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/09 15:13:26 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/09 15:13:12 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2013/09/09 15:12:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/09/09 13:53:19 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/09/09 09:28:11 | 000,000,009 | ---- | M] () -- C:\END
[2013/09/09 09:15:33 | 000,000,861 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Optimizer Pro.lnk
[2013/09/08 23:24:06 | 000,000,616 | ---- | M] () -- C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/09/08 23:24:06 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/09/08 19:45:17 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/09/08 19:22:36 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/09/08 19:18:21 | 000,000,040 | ---- | M] () -- C:\Users\Public\Documents\_rgpl
[2013/09/08 18:40:31 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013/09/08 18:40:21 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TMContainer00000000000000000001.regtrans-ms
[2013/09/08 18:40:21 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TM.blf
[2013/09/08 18:39:54 | 003,068,279 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Local\IconCache.db
[2013/09/08 14:05:27 | 000,001,973 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/09/08 13:13:35 | 000,843,252 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2013/09/08 13:13:35 | 000,702,262 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/09/08 13:13:35 | 000,142,546 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/07/30 23:20:57 | 000,000,847 | ---- | M] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/07/30 22:57:16 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2013/07/29 14:50:39 | 209,901,568 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Leave It To Beaver S02E08 The Shave.avi
[2013/07/28 07:31:10 | 209,905,664 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Leave It To Beaver S02E02 Eddie's Girl.avi
[2013/07/28 03:31:14 | 005,848,361 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Hgwt1960-07-31089MySonMustDie.mp3
[2013/07/28 03:30:15 | 005,874,353 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Hgwt1958-11-23001StrangeVendettadonMiquelRojas.mp3
[2013/07/26 23:14:45 | 000,000,080 | ---- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\mbam.context.scan
[2013/07/20 14:43:02 | 001,773,008 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2013/07/19 20:36:58 | 000,001,842 | ---- | M] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/07/19 20:36:45 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2013/07/04 21:26:32 | 000,002,633 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Microsoft Office Outlook 2007.lnk
[2013/06/11 23:31:32 | 000,020,992 | ---- | M] () -- C:\Users\worlwidewandering\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/31 14:41:19 | 000,000,680 | ---- | M] () -- C:\Users\worlwidewandering\AppData\Local\d3d9caps.dat
[2013/05/17 06:26:17 | 000,000,039 | ---- | M] () -- C:\Windows\vbaddin.ini
[2013/05/15 01:07:02 | 000,000,751 | ---- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2013/05/15 01:07:01 | 000,000,771 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\µTorrent.lnk
[2013/05/07 01:36:22 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TMContainer00000000000000000002.regtrans-ms
[2013/05/07 01:26:12 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TMContainer00000000000000000001.regtrans-ms
[2013/05/07 01:26:12 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TM.blf
[2013/05/07 00:56:58 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TMContainer00000000000000000002.regtrans-ms
[2013/05/07 00:44:20 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TMContainer00000000000000000001.regtrans-ms
[2013/05/07 00:44:20 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TM.blf
[2013/05/06 22:24:29 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 22:14:10 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 22:14:10 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TM.blf
[2013/05/06 19:20:53 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 18:53:45 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 18:53:45 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TM.blf
[2013/05/06 18:31:44 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 18:21:14 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 18:21:14 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TM.blf
[2013/05/06 02:09:04 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 01:58:55 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 01:58:55 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TM.blf
[2013/05/05 21:46:43 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/05 21:37:34 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TMContainer00000000000000000001.regtrans-ms
[2013/05/05 21:37:34 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TM.blf
[2013/05/05 19:26:51 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TMContainer00000000000000000002.regtrans-ms
[2013/05/05 19:17:30 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2013/05/05 19:17:30 | 000,065,536 | -HS- | M] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2013/05/05 18:09:30 | 000,000,000 | ---- | M] () -- C:\ProgramData\3f262138383b3d2d442337_c
[2013/04/29 13:46:05 | 000,119,552 | ---- | M] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT
[2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2013/03/15 21:37:50 | 000,002,627 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\Microsoft Office Word 2007.lnk
[2013/02/28 16:27:24 | 000,018,776 | ---- | M] (Systweak Inc., (www.systweak.com)) -- C:\Windows\System32\roboot.exe
[2013/02/08 01:01:31 | 000,001,997 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/20 19:54:58 | 000,000,940 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/11/15 04:02:01 | 000,000,219 | ---- | M] () -- C:\Windows\win.ini
[2012/09/30 17:45:05 | 000,000,854 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\TrafficRobot.lnk
[2012/08/21 05:13:15 | 000,729,752 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012/08/21 05:13:15 | 000,355,632 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012/08/21 05:13:15 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012/08/21 05:13:14 | 000,058,680 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012/08/21 05:13:14 | 000,035,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012/08/21 05:13:13 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012/08/21 05:12:33 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/08/21 05:12:23 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012/08/20 13:20:36 | 000,000,288 | ---- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\.backup.dm
[2012/07/31 21:48:51 | 000,000,854 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\TrafficRobot (2).lnk
[2012/07/31 21:48:19 | 000,000,885 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\TheBestSpinner (2).lnk
[2012/07/31 21:47:34 | 000,000,908 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\mbam - Shortcut.lnk
[2012/07/31 21:14:54 | 000,444,955 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/07/31 21:13:44 | 000,444,955 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20120731-211454.backup
[2012/07/31 13:43:24 | 000,000,368 | ---- | M] () -- C:\ProgramData\h17vDZggBw4Evi
[2012/07/31 13:39:31 | 000,000,064 | ---- | M] () -- C:\ProgramData\-h17vDZggBw4Evir
[2012/07/31 13:39:31 | 000,000,064 | ---- | M] () -- C:\ProgramData\-h17vDZggBw4Evi
[2012/07/31 13:39:25 | 000,000,633 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/07/26 12:24:30 | 000,000,048 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\example.html
[2012/07/23 18:06:28 | 000,010,991 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\VitalChek Order Receipt.htm
[2012/06/02 10:57:50 | 000,000,003 | ---- | M] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/06/02 10:34:21 | 000,000,003 | ---- | M] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/03/27 01:39:43 | 000,008,798 | ---- | M] () -- C:\Windows\System32\icrav03.rat
[2012/03/27 01:39:43 | 000,001,988 | ---- | M] () -- C:\Windows\System32\ticrf.rat
[2012/03/27 01:39:30 | 000,072,822 | ---- | M] () -- C:\Windows\System32\ieuinit.inf
[2012/03/26 14:03:50 | 000,030,208 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Be alert of new information changes .msg
[2011/07/21 20:27:09 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLbx.DAT
[2011/07/19 10:24:34 | 000,110,592 | ---- | M] () -- C:\Users\worlwidewandering\Desktop\RunClubSanDisk.exe
[2011/07/16 12:37:33 | 000,001,994 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\The Rosetta Stone.lnk
[2011/07/08 15:14:58 | 000,001,795 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\TheBestSpinner.lnk
[2011/06/30 21:13:08 | 001,252,352 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\get rich.msam
[2011/06/29 10:56:42 | 027,311,232 | ---- | M] (Gemalto N.V.) -- C:\Users\worlwidewandering\Desktop\RunSanDiskSecureAccess_Win.exe
[2011/06/10 16:44:25 | 000,000,830 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Web2Mayhem.lnk
[2011/06/07 23:02:35 | 000,071,680 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\turnaround king.msam
[2011/06/07 13:09:27 | 000,872,448 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\sales training.msam
[2011/06/05 22:30:04 | 001,336,952 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\skin care products.msam-journal
[2011/06/05 22:30:03 | 001,326,080 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\skin care products.msam
[2011/05/30 09:42:51 | 000,240,640 | ---- | M] () -- C:\Windows\System32\xvidvfw.dll
[2011/05/23 05:52:08 | 000,153,088 | ---- | M] () -- C:\Windows\System32\xvid.ax
[2011/05/23 03:46:31 | 000,645,632 | ---- | M] () -- C:\Windows\System32\xvidcore.dll
[2011/05/13 00:48:35 | 000,000,945 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/04/30 16:49:37 | 000,075,924 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\cc_20110430_164905_registry_backup.reg
[2011/04/30 02:46:01 | 000,136,192 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\health.msam
[2011/04/23 16:00:47 | 001,510,400 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\beri ultimate.msam
[2011/04/18 00:35:05 | 020,533,281 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\vlc-1.1.9-win32.exe
[2011/04/17 23:18:34 | 000,119,144 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Local\GDIPFONTCACHEV1.DAT
[2011/04/17 23:04:59 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/04/17 23:04:28 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/04/16 00:45:35 | 000,433,448 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20120731-211344.backup
[2011/04/15 23:48:01 | 000,001,057 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Spybot - Search & Destroy.lnk
[2011/04/15 23:27:08 | 000,433,448 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110416-004535.backup
[2011/04/12 02:42:46 | 000,036,047 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\win7_upgrade_report.mht
[2011/04/11 12:15:25 | 000,001,726 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2011/04/09 13:41:07 | 000,044,544 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\agremove.exe
[2011/02/15 16:33:42 | 000,034,816 | ---- | M] (Absolute Software Corporation) -- C:\Windows\System32\identprv.dll
[2010/08/03 13:12:20 | 000,000,394 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Swiss Sciences - Shortcut.lnk
[2010/07/23 20:30:55 | 000,001,976 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\KeywordCorral.lnk
[2010/05/18 09:16:10 | 000,000,048 | -H-- | M] () -- C:\ProgramData\ezsidmv.dat
[2010/02/28 22:42:53 | 012,644,650 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\FindYourBodyType+2010-02-28.csv
[2010/02/28 16:04:24 | 000,016,449 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\terms.html
[2010/02/28 13:24:38 | 000,049,152 | ---- | M] () -- C:\Windows\SPInstall.etl
[2009/11/02 20:51:14 | 000,009,728 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\wceprv.dll
[2009/09/09 19:34:08 | 000,049,152 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\instw32.exe
[2009/08/01 02:27:37 | 000,201,184 | ---- | M] () -- C:\Windows\System32\winrm.vbs
[2009/07/16 13:30:03 | 000,004,675 | ---- | M] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2009/07/16 13:30:03 | 000,002,426 | ---- | M] () -- C:\Windows\System32\WsmTxt.xsl
[2009/07/11 13:03:56 | 002,501,921 | ---- | M] () -- C:\Windows\System32\wlan.tmf
[2009/04/11 02:36:36 | 000,333,257 | RHS- | M] () -- C:\bootmgr
[2009/04/11 02:28:21 | 000,368,640 | ---- | M] () -- C:\Windows\System32\msjetoledb40.dll
[2009/04/11 02:28:19 | 000,117,248 | ---- | M] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/04/11 00:48:19 | 000,344,698 | ---- | M] () -- C:\Windows\System32\eaphost.tmf
[2009/04/11 00:46:15 | 000,208,966 | ---- | M] () -- C:\Windows\System32\WFP.TMF
[2009/04/11 00:43:51 | 000,442,788 | ---- | M] () -- C:\Windows\System32\dot3.tmf
[2009/04/11 00:43:37 | 000,392,170 | ---- | M] () -- C:\Windows\System32\onex.tmf
[2009/04/10 21:59:51 | 000,107,612 | ---- | M] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/04/10 21:54:25 | 003,662,128 | ---- | M] () -- C:\Windows\System32\locale.nls
[2009/04/04 20:54:12 | 000,000,668 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\vso_ts_preview.xml
[2009/03/06 21:11:16 | 000,130,008 | ---- | M] () -- C:\Windows\System32\systemsf.ebd
[2009/02/20 10:32:24 | 000,000,947 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\DataSafeDotNet.exe
[2009/02/19 20:20:51 | 000,009,239 | ---- | M] () -- C:\Windows\System32\spcinstrumentation.man
[2009/02/19 20:20:51 | 000,009,212 | ---- | M] () -- C:\Windows\System32\RacUR.xml
[2009/02/18 14:43:18 | 000,000,153 | ---- | M] () -- C:\Windows\System32\RacUREx.xml
[2009/02/18 14:39:57 | 000,092,918 | ---- | M] () -- C:\Windows\System32\slmgr.vbs
[2009/02/17 20:38:12 | 000,112,128 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbnet.sys
[2009/02/13 22:06:21 | 000,000,306 | ---- | M] () -- C:\Windows\ODBC.INI
[2009/01/25 13:14:20 | 000,015,224 | ---- | M] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe
[2009/01/21 19:23:08 | 000,000,952 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Adobe Flash CS3 Professional.lnk
[2008/12/30 11:57:54 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbfake.sys
[2008/12/20 17:14:02 | 000,000,393 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\XAMPP Control Panel.lnk
[2008/12/13 11:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\Windows\System32\drivers\ewusbmdm.sys
[2008/12/10 12:03:54 | 000,000,840 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\css_notes - Shortcut.lnk
[2008/12/10 01:03:05 | 001,352,284 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\ESG_US_SharedHosting.pdf
[2008/11/29 23:37:36 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2008/11/29 23:21:21 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2008/11/27 19:20:39 | 000,000,749 | RH-- | M] () -- C:\Windows\WindowsShell.Manifest
[2008/11/27 10:23:46 | 000,101,888 | ---- | M] (Infineon Technologies AG) -- C:\Windows\System32\ifxcardm.dll
[2008/11/27 10:23:38 | 000,082,432 | ---- | M] (Gemalto, Inc.) -- C:\Windows\System32\axaltocm.dll
[2008/11/19 20:43:20 | 000,031,266 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\cc_20081119_194114.reg
[2008/11/04 10:05:55 | 000,002,677 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook 2007.lnk
[2008/10/21 19:41:49 | 000,001,767 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Photomatix Pro 3.lnk
[2008/10/13 19:30:28 | 008,200,242 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-5.psd
[2008/10/13 19:30:22 | 009,319,809 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-4.psd
[2008/10/13 19:30:16 | 008,203,475 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-3.psd
[2008/10/13 19:30:07 | 009,304,698 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-2.psd
[2008/10/13 19:29:58 | 008,211,044 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-1.psd
[2008/10/13 19:29:50 | 009,317,243 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-6.psd
[2008/10/13 19:29:16 | 001,507,677 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-6.jpg
[2008/10/13 19:28:54 | 001,620,898 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-5.jpg
[2008/10/13 19:28:37 | 001,494,117 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-4.jpg
[2008/10/13 19:26:54 | 001,437,779 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-1.jpg
[2008/10/13 19:26:39 | 001,402,155 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-2.jpg
[2008/10/13 19:26:17 | 001,594,368 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-3.jpg
[2008/10/13 19:18:36 | 011,343,593 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex.pdf
[2008/10/11 19:01:37 | 000,000,764 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\RegCure.lnk
[2008/10/09 23:11:36 | 000,017,381 | -H-- | M] () -- C:\Users\worlwidewandering\Documents\Drawing1.htm
[2008/10/08 23:40:21 | 000,001,674 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Visio For Dummies.lnk
[2008/10/06 09:06:46 | 003,099,740 | RH-- | M] () -- C:\Users\worlwidewandering\Documents\27 uger 0 dage 005 (07.09.08).JPG
[2008/09/28 23:00:33 | 000,000,884 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\More Eric Meyer on CSS.lnk
[2008/09/28 20:11:18 | 000,000,894 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\CSS Cookbook 2nd Edition - Shortcut.lnk
[2008/09/28 20:11:12 | 000,000,869 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\CSS Hacks & Filters - Shortcut.lnk
[2008/09/28 20:10:12 | 000,001,044 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\The Zen of CSS Design Visual Enlightenment for the Web - Shortcut.lnk
[2008/09/28 09:39:17 | 000,000,908 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\css.lnk
[2008/09/28 01:16:08 | 000,000,020 | -H-- | M] () -- C:\ProgramData\PKP_DLck.DAT
[2008/09/28 01:16:07 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Audio Units
[2008/09/28 01:16:07 | 000,000,268 | RH-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\Application Support
[2008/09/28 01:16:07 | 000,000,012 | RH-- | M] () -- C:\ProgramData\Flange Saw
[2008/09/28 01:16:04 | 000,000,268 | RH-- | M] () -- C:\ProgramData\Authentication
[2008/09/28 01:16:04 | 000,000,268 | RH-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\Applications
[2008/09/28 01:16:04 | 000,000,012 | RH-- | M] () -- C:\ProgramData\Flowers
[2008/09/27 23:22:32 | 000,001,882 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Bulletproof.Web.Design.lnk
[2008/09/27 22:42:30 | 000,001,774 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2008/09/27 22:35:00 | 000,001,278 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Guide to the Nikon D50.lnk
[2008/09/25 23:18:23 | 000,001,610 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\MagicISO.lnk
[2008/09/25 21:43:57 | 000,000,335 | ---- | M] () -- C:\Windows\nsreg.dat
[2008/09/25 21:43:15 | 000,008,653 | ---- | M] () -- C:\Windows\mozver.dat
[2008/09/25 21:42:48 | 000,118,784 | ---- | M] () -- C:\Windows\GREUninstall.exe
[2008/09/25 20:54:55 | 000,001,275 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Dreamweaver CS3 (The Missing Manual Series) - Shortcut.lnk
[2008/09/22 20:18:57 | 000,000,940 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2008/09/22 19:08:53 | 000,087,608 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\inst.exe
[2008/09/22 19:08:53 | 000,047,360 | -H-- | M] (VSO Software) -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.sys
[2008/09/22 19:08:53 | 000,047,360 | ---- | M] (VSO Software) -- C:\Windows\System32\drivers\pcouffin.sys
[2008/09/22 19:08:53 | 000,007,887 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.cat
[2008/09/22 19:08:53 | 000,001,144 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.inf
[2008/09/22 19:08:49 | 000,000,987 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\ConvertXtoDvd 3.lnk
[2008/09/22 09:34:59 | 000,001,649 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG Free 8.0.lnk
[2008/09/22 09:14:07 | 000,001,421 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Illustrator.lnk
[2008/09/22 09:13:31 | 000,000,990 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Photoshop.lnk
[2008/09/22 00:09:23 | 000,000,020 | -HS- | M] () -- C:\Users\worlwidewandering\ntuser.ini
[2008/09/21 22:15:30 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2008/09/21 21:56:43 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf
[2008/09/21 18:59:29 | 000,001,014 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Dreamweaver.lnk
[2008/09/21 15:59:45 | 000,524,288 | -HS- | M] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms
[2008/09/21 14:46:22 | 000,265,449 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20110415-232708.backup
[2008/09/21 14:17:03 | 000,265,449 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts.20080921-144622.backup
[2008/09/21 12:41:27 | 000,001,824 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Dell DataSafe Online.lnk
[2008/07/28 17:19:28 | 000,116,736 | ---- | M] (MagicISO, Inc.) -- C:\Windows\System32\drivers\mcdbus.sys
[2008/07/07 03:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) -- C:\Windows\System32\drivers\scdemu.sys
[2008/05/27 00:59:40 | 000,018,904 | ---- | M] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/04/22 19:39:44 | 000,008,192 | ---- | M] ( ) -- C:\Windows\System32\cshost.dll
[2008/04/14 09:36:42 | 000,621,056 | ---- | M] (DiBcom SA) -- C:\Windows\System32\drivers\mod7700.sys
[2008/01/12 00:45:47 | 000,004,926 | RH-- | M] () -- C:\dell.sdr
[2008/01/12 00:45:31 | 000,744,740 | ---- | M] () -- C:\Windows\System32\oem8.inf
[2008/01/12 00:38:58 | 000,001,820 | ---- | M] () -- C:\Windows\System32\rasctrnm.h
[2008/01/12 00:26:05 | 000,004,926 | ---- | M] () -- C:\Windows\System32\drivers\1028_Dell_INS_I1521.mrk
[2008/01/11 17:41:43 | 000,000,071 | ---- | M] () -- C:\SystemInfo.ini
[2008/01/11 17:20:49 | 000,022,729 | ---- | M] () -- C:\newkey
[2008/01/11 17:20:49 | 000,022,729 | ---- | M] () -- C:\newfile.enc
[2008/01/11 17:19:39 | 000,000,080 | RHS- | M] () -- C:\Windows\CT4CET.bin
[2008/01/11 17:04:24 | 006,291,456 | ---- | M] () -- C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2008/01/11 17:04:23 | 000,049,152 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2008/01/11 17:04:23 | 000,016,384 | ---- | M] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2008/01/11 17:00:13 | 000,001,623 | ---- | M] () -- C:\Users\Public\Desktop\Internet Explorer.lnk
[2008/01/11 16:51:34 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2008/01/05 07:34:00 | 000,015,181 | ---- | M] () -- C:\Windows\System32\gatherWirelessInfo.vbs
[2008/01/05 07:31:14 | 000,145,455 | ---- | M] () -- C:\Windows\System32\perfmon.msc
[2008/01/05 07:23:28 | 000,060,124 | ---- | M] () -- C:\Windows\System32\tcpmon.ini
[2008/01/05 07:22:37 | 000,144,909 | ---- | M] () -- C:\Windows\System32\fsmgmt.msc
[2008/01/05 07:21:39 | 000,012,198 | ---- | M] () -- C:\Windows\System32\gatherWiredInfo.vbs
[2007/12/12 02:02:14 | 000,024,064 | ---- | M] () -- C:\Windows\System32\WLTRYSVC.EXE
[2007/12/12 02:02:10 | 000,001,591 | ---- | M] () -- C:\Windows\System32\Uninst_EAPModules.bat
[2007/12/12 02:02:10 | 000,000,416 | ---- | M] () -- C:\Windows\System32\vcredist_x86.bat
[2007/12/12 02:01:24 | 000,054,784 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
[2007/11/08 05:04:45 | 011,967,524 | ---- | M] () -- C:\Windows\System32\korwbrkr.lex
[2007/09/07 14:26:04 | 000,330,240 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\drivers\stwrt.sys
[2007/09/07 14:25:42 | 000,328,704 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stcplx.dll
[2007/09/07 14:25:24 | 000,595,968 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stapo.dll
[2007/09/07 14:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
[2007/09/07 14:24:32 | 004,947,968 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacgui.cpl
[2007/09/07 14:24:04 | 000,146,944 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\staco.dll
[2007/09/07 14:23:24 | 000,299,520 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stapi32.dll
[2007/08/29 01:55:06 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) -- C:\Windows\System32\drivers\OEM02Vfx.sys
[2007/08/29 01:55:04 | 000,057,656 | ---- | M] () -- C:\Windows\System32\drivers\OEM02Pvc.bmp
[2007/08/29 01:55:00 | 000,057,656 | ---- | M] () -- C:\Windows\System32\drivers\OEM02PC.bmp
[2007/08/29 01:54:52 | 000,260,330 | ---- | M] () -- C:\Windows\System32\OEM02Cvw.bff
[2007/08/29 01:54:50 | 000,004,510 | ---- | M] () -- C:\Windows\OEM002.uns
[2007/08/29 01:54:48 | 000,811,008 | ---- | M] (Pizzolato Davide - www.xdp.it) -- C:\Windows\System32\cximage.dll
[2007/08/14 04:40:56 | 000,042,960 | ---- | M] () -- C:\Windows\System32\drivers\ativvpxx.vp
[2007/08/14 04:40:56 | 000,002,096 | ---- | M] () -- C:\Windows\System32\drivers\ativpkxx.vp
[2007/08/14 04:40:54 | 003,107,788 | ---- | M] () -- C:\Windows\System32\atiumdva.dat
[2007/08/14 04:40:54 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
[2007/08/14 04:40:54 | 000,002,096 | ---- | M] () -- C:\Windows\System32\drivers\ativdkxx.vp
[2007/08/14 04:40:52 | 000,145,050 | ---- | M] () -- C:\Windows\System32\atiicdxx.dat
[2007/08/14 04:40:52 | 000,011,441 | ---- | M] () -- C:\Windows\atiogl.xml
[2007/08/09 04:06:40 | 000,023,424 | ---- | M] (Huawei Tech. Co., Ltd.) -- C:\Windows\System32\drivers\ewdcsc.sys
[2007/04/27 20:35:56 | 000,182,456 | ---- | M] (Synaptics, Inc.) -- C:\Windows\System32\drivers\SynTP.sys
[2007/04/27 20:34:00 | 000,110,592 | ---- | M] (Synaptics, Inc.) -- C:\Windows\System32\SynTPCo4.dll
[2007/04/27 19:49:38 | 000,143,360 | ---- | M] (Synaptics, Inc.) -- C:\Windows\System32\SynTPAPI.dll
[2007/04/27 19:42:36 | 000,196,608 | ---- | M] (Synaptics, Inc.) -- C:\Windows\System32\SynCtrl.dll
[2007/04/27 19:42:12 | 000,163,840 | ---- | M] (Synaptics, Inc.) -- C:\Windows\System32\SynCOM.dll
[2007/03/14 20:30:18 | 000,032,256 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\instd32.exe
[2007/02/20 17:04:02 | 002,463,976 | ---- | M] () -- C:\Windows\System32\NPSWF32.dll
[2007/02/14 14:27:48 | 005,627,904 | ---- | M] (Reallusion Inc.) -- C:\Windows\System32\LiveCamVirtual.ocx
[2007/01/22 14:58:46 | 000,231,008 | ---- | M] () -- C:\Windows\System32\DMdm32.cpl
[2006/11/22 19:33:02 | 000,014,848 | ---- | M] (Absolute Software Corp.) -- C:\Windows\System32\DIAGDLL64.DLL
[2006/11/15 04:16:24 | 000,032,256 | ---- | M] (REDC) -- C:\Windows\System32\drivers\rimmptsk.sys
[2006/11/14 23:42:46 | 000,043,520 | ---- | M] (REDC) -- C:\Windows\System32\drivers\rimsptsk.sys
[2006/11/14 21:35:20 | 000,037,376 | ---- | M] (REDC) -- C:\Windows\System32\drivers\rixdptsk.sys
[2006/11/10 18:04:32 | 000,041,176 | ---- | M] () -- C:\Windows\System32\license.rtf
[2006/11/10 17:59:07 | 000,008,192 | R-S- | M] () -- C:\BOOTSECT.BAK
[2006/11/07 15:25:58 | 000,000,000 | ---- | M] () -- C:\Windows\System32\px.ini
[2006/11/02 09:08:31 | 000,049,152 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2006/11/02 08:54:16 | 000,033,792 | ---- | M] () -- C:\Windows\System32\umstartup000.etl
[2006/11/02 08:53:22 | 000,001,741 | ---- | M] () -- C:\Windows\System32\migwiz.lnk
[2006/11/02 08:51:30 | 000,001,699 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\Notepad.lnk
[2006/11/02 08:47:50 | 000,000,258 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2006/11/02 08:47:50 | 000,000,240 | -H-- | M] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2006/11/02 08:39:01 | 000,004,096 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\en-US\pscr.sys.mui
[2006/11/02 08:39:01 | 000,004,096 | ---- | M] (SCM Microsystems) -- C:\Windows\System32\drivers\en-US\SCR111.sys.mui
[2006/11/02 08:39:01 | 000,004,096 | ---- | M] (Gemplus) -- C:\Windows\System32\drivers\en-US\grserial.sys.mui
[2006/11/02 08:39:01 | 000,003,584 | ---- | M] (Gemplus) -- C:\Windows\System32\drivers\en-US\gpr400.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | M] (SCM Microsystems, Inc.) -- C:\Windows\System32\drivers\en-US\stcusb.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | M] (OMNIKEY) -- C:\Windows\System32\drivers\en-US\cxbp0wdm.sys.mui
[2006/11/02 08:39:01 | 000,003,072 | ---- | M] (OMNIKEY AG) -- C:\Windows\System32\drivers\en-US\cmbp0wdm.sys.mui
[2006/11/02 08:38:55 | 000,010,240 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\en-US\BrSerId.sys.mui
[2006/11/02 08:38:53 | 000,009,728 | ---- | M] (Agere Systems) -- C:\Windows\System32\drivers\en-US\ltmdmnt.sys.mui
[2006/11/02 08:38:53 | 000,005,632 | ---- | M] (Marvell) -- C:\Windows\System32\drivers\en-US\yk60x86.sys.mui
[2006/11/02 08:38:32 | 000,004,096 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\en-US\ntrigdigi.sys.mui
[2006/11/02 08:38:27 | 000,002,560 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\en-US\BrParwdm.sys.mui
[2006/11/02 08:34:54 | 000,316,640 | ---- | M] () -- C:\Windows\WMSysPr9.prx
[2006/11/02 08:34:06 | 000,093,702 | ---- | M] () -- C:\Windows\System32\SubRange.uce
[2006/11/02 08:34:06 | 000,060,458 | ---- | M] () -- C:\Windows\System32\ideograf.uce
[2006/11/02 08:34:06 | 000,024,006 | ---- | M] () -- C:\Windows\System32\gb2312.uce
[2006/11/02 08:34:06 | 000,022,984 | ---- | M] () -- C:\Windows\System32\bopomofo.uce
[2006/11/02 08:34:06 | 000,016,740 | ---- | M] () -- C:\Windows\System32\ShiftJIS.uce
[2006/11/02 08:34:06 | 000,012,876 | ---- | M] () -- C:\Windows\System32\korean.uce
[2006/11/02 08:34:06 | 000,008,484 | ---- | M] () -- C:\Windows\System32\kanji_2.uce
[2006/11/02 08:34:06 | 000,006,948 | ---- | M] () -- C:\Windows\System32\kanji_1.uce
[2006/11/02 08:33:45 | 000,000,933 | ---- | M] () -- C:\Windows\System32\gatherWirelessInfo.xslt
[2006/11/02 05:51:38 | 000,420,968 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adp94xx.sys
[2006/11/02 05:51:34 | 000,316,520 | ---- | M] (Emulex) -- C:\Windows\System32\drivers\elxstor.sys
[2006/11/02 05:51:32 | 000,297,576 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpahci.sys
[2006/11/02 05:51:25 | 000,235,112 | ---- | M] (ULi Electronics Inc.) -- C:\Windows\System32\drivers\uliahci.sys
[2006/11/02 05:51:00 | 000,147,048 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu320.sys
[2006/11/02 05:50:35 | 000,098,408 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\adpu160m.sys
[2006/11/02 05:50:16 | 000,071,784 | ---- | M] (Silicon Integrated Systems) -- C:\Windows\System32\drivers\sisraid4.sys
[2006/11/02 05:50:11 | 000,071,272 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\djsvs.sys
[2006/11/02 05:50:10 | 000,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arcsas.sys
[2006/11/02 05:50:09 | 000,067,688 | ---- | M] (Adaptec, Inc.) -- C:\Windows\System32\drivers\arc.sys
[2006/11/02 05:50:09 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteraid.sys
[2006/11/02 05:50:07 | 000,035,944 | ---- | M] (Integrated Technology Express, Inc.) -- C:\Windows\System32\drivers\iteatapi.sys
[2006/11/02 05:46:02 | 000,017,408 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\brcoinst.dll
[2006/11/02 05:20:21 | 000,287,440 | ---- | M] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 05:20:19 | 000,030,674 | ---- | M] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 04:25:24 | 000,071,808 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerId.sys
[2006/11/02 04:24:47 | 000,011,904 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbSer.sys
[2006/11/02 04:24:46 | 000,005,248 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltUp.sys
[2006/11/02 04:24:45 | 000,013,568 | ---- | M] (Brother Industries, Ltd.) -- C:\Windows\System32\drivers\BrFiltLo.sys
[2006/11/02 04:24:44 | 000,062,336 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrSerWdm.sys
[2006/11/02 04:24:44 | 000,012,160 | ---- | M] (Brother Industries Ltd.) -- C:\Windows\System32\drivers\BrUsbMdm.sys
[2006/11/02 04:20:17 | 000,004,453 | ---- | M] () -- C:\Windows\System32\odbcconf.rsp
[2006/11/02 03:46:49 | 000,043,131 | ---- | M] () -- C:\Windows\mib.bin
[2006/11/02 03:36:50 | 000,020,608 | ---- | M] (N-trig Innovative Technologies) -- C:\Windows\System32\drivers\ntrigdigi.sys
[2006/11/02 03:10:37 | 000,053,536 | ---- | M] () -- C:\Windows\System32\dosx.exe
[2006/11/02 03:10:02 | 000,000,718 | ---- | M] () -- C:\Windows\System32\mscdexnt.exe
[2006/11/02 03:10:00 | 000,002,842 | ---- | M] () -- C:\Windows\System32\redir.exe
[2006/11/02 03:09:59 | 000,019,694 | ---- | M] () -- C:\Windows\System32\GRAPHICS.COM
[2006/11/02 03:09:59 | 000,000,882 | ---- | M] () -- C:\Windows\System32\share.exe
[2006/11/02 03:09:59 | 000,000,882 | ---- | M] () -- C:\Windows\System32\fastopen.exe
[2006/11/02 03:09:57 | 000,014,710 | ---- | M] () -- C:\Windows\System32\KB16.COM
[2006/11/02 03:09:56 | 000,007,052 | ---- | M] () -- C:\Windows\System32\nlsfunc.exe
[2006/11/02 03:09:55 | 000,039,274 | ---- | M] () -- C:\Windows\System32\mem.exe
[2006/11/02 03:09:55 | 000,001,131 | ---- | M] () -- C:\Windows\System32\LOADFIX.COM
[2006/11/02 03:09:53 | 000,011,753 | ---- | M] () -- C:\Windows\System32\setver.exe
[2006/11/02 03:09:52 | 000,020,634 | ---- | M] () -- C:\Windows\System32\debug.exe
[2006/11/02 03:09:51 | 000,008,424 | ---- | M] () -- C:\Windows\System32\exe2bin.exe
[2006/11/02 03:09:50 | 000,012,642 | ---- | M] () -- C:\Windows\System32\edlin.exe
[2006/11/02 03:09:49 | 000,050,648 | ---- | M] () -- C:\Windows\System32\COMMAND.COM
[2006/11/02 03:09:49 | 000,012,498 | ---- | M] () -- C:\Windows\System32\append.exe
[2006/11/02 03:09:45 | 000,027,097 | ---- | M] () -- C:\Windows\System32\country.sys
[2006/11/02 03:09:44 | 000,042,809 | ---- | M] () -- C:\Windows\System32\KEY01.SYS
[2006/11/02 03:09:44 | 000,042,537 | ---- | M] () -- C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 03:09:42 | 000,009,029 | ---- | M] () -- C:\Windows\System32\ANSI.SYS
[2006/11/02 03:09:41 | 000,004,768 | ---- | M] () -- C:\Windows\System32\HIMEM.SYS
[2006/11/02 03:09:40 | 000,029,274 | ---- | M] () -- C:\Windows\System32\NTDOS412.SYS
[2006/11/02 03:09:38 | 000,029,370 | ---- | M] () -- C:\Windows\System32\NTDOS411.SYS
[2006/11/02 03:09:35 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS404.SYS
[2006/11/02 03:09:31 | 000,029,146 | ---- | M] () -- C:\Windows\System32\NTDOS804.SYS
[2006/11/02 03:09:29 | 000,027,866 | ---- | M] () -- C:\Windows\System32\NTDOS.SYS
[2006/11/02 03:09:26 | 000,035,536 | ---- | M] () -- C:\Windows\System32\NTIO412.SYS
[2006/11/02 03:09:24 | 000,035,776 | ---- | M] () -- C:\Windows\System32\NTIO411.SYS
[2006/11/02 03:09:23 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO404.SYS
[2006/11/02 03:09:22 | 000,034,672 | ---- | M] () -- C:\Windows\System32\NTIO804.SYS
[2006/11/02 03:09:20 | 000,033,952 | ---- | M] () -- C:\Windows\System32\NTIO.SYS
[2006/11/02 03:08:47 | 000,000,610 | ---- | M] () -- C:\Windows\System32\WdsUnattendTemplate.xml
[2006/10/01 17:10:35 | 000,328,162 | ---- | M] () -- C:\Windows\System32\drivers\ativcaxx.cpa
[2006/10/01 17:10:35 | 000,002,096 | ---- | M] () -- C:\Windows\System32\drivers\ativokxx.vp
[2006/10/01 17:10:35 | 000,000,929 | ---- | M] () -- C:\Windows\System32\drivers\ativcaxx.vp
[2006/09/29 16:14:18 | 000,144,360 | ---- | M] () -- C:\Windows\System32\drivers\del1028.cty
[2006/09/19 07:41:44 | 000,008,286 | ---- | M] () -- C:\Windows\HomeBasic.xml
[2006/09/18 17:49:00 | 000,001,041 | ---- | M] () -- C:\Windows\System32\tcpbidi.xml
[2006/09/18 17:48:59 | 000,003,577 | ---- | M] () -- C:\Windows\System32\sysprtj.sep
[2006/09/18 17:48:59 | 000,003,214 | ---- | M] () -- C:\Windows\System32\sysprint.sep
[2006/09/18 17:48:59 | 000,000,051 | ---- | M] () -- C:\Windows\System32\pscript.sep
[2006/09/18 17:48:58 | 000,000,114 | ---- | M] () -- C:\Windows\System32\pcl.sep
[2006/09/18 17:47:31 | 000,066,384 | ---- | M] () -- C:\Windows\System32\normnfkc.nls
[2006/09/18 17:47:31 | 000,060,294 | ---- | M] () -- C:\Windows\System32\normnfkd.nls
[2006/09/18 17:47:31 | 000,059,342 | ---- | M] () -- C:\Windows\System32\normidna.nls
[2006/09/18 17:47:31 | 000,045,794 | ---- | M] () -- C:\Windows\System32\normnfc.nls
[2006/09/18 17:47:31 | 000,039,284 | ---- | M] () -- C:\Windows\System32\normnfd.nls
[2006/09/18 17:47:29 | 000,008,838 | ---- | M] () -- C:\Windows\System32\l_intl.nls
[2006/09/18 17:47:28 | 000,180,770 | ---- | M] () -- C:\Windows\System32\C_20932.NLS
[2006/09/18 17:47:28 | 000,177,698 | ---- | M] () -- C:\Windows\System32\C_20949.NLS
[2006/09/18 17:47:28 | 000,173,602 | ---- | M] () -- C:\Windows\System32\C_20936.NLS
[2006/09/18 17:47:27 | 000,195,618 | ---- | M] () -- C:\Windows\System32\C_10002.NLS
[2006/09/18 17:47:27 | 000,177,698 | ---- | M] () -- C:\Windows\System32\C_10003.NLS
[2006/09/18 17:47:27 | 000,173,602 | ---- | M] () -- C:\Windows\System32\C_10008.NLS
[2006/09/18 17:47:27 | 000,162,850 | ---- | M] () -- C:\Windows\System32\C_10001.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_869.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_866.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_865.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_864.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_863.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_862.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_861.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_860.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_858.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_857.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_855.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_852.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_850.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_775.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_737.NLS
[2006/09/18 17:47:27 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_437.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28605.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\c_28603.nls
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28599.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28598.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28597.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28596.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28595.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28594.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28593.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28592.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_28591.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20269.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10082.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10081.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10079.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10029.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10021.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10017.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10010.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10007.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10006.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10005.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10004.NLS
[2006/09/18 17:47:27 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_10000.NLS
[2006/09/18 17:47:26 | 000,196,642 | ---- | M] () -- C:\Windows\System32\C_950.NLS
[2006/09/18 17:47:26 | 000,196,642 | ---- | M] () -- C:\Windows\System32\C_949.NLS
[2006/09/18 17:47:26 | 000,189,986 | ---- | M] () -- C:\Windows\System32\C_1361.NLS
[2006/09/18 17:47:26 | 000,187,938 | ---- | M] () -- C:\Windows\System32\C_20005.NLS
[2006/09/18 17:47:26 | 000,186,402 | ---- | M] () -- C:\Windows\System32\C_20001.NLS
[2006/09/18 17:47:26 | 000,185,378 | ---- | M] () -- C:\Windows\System32\C_20003.NLS
[2006/09/18 17:47:26 | 000,180,258 | ---- | M] () -- C:\Windows\System32\C_20004.NLS
[2006/09/18 17:47:26 | 000,180,258 | ---- | M] () -- C:\Windows\System32\C_20000.NLS
[2006/09/18 17:47:26 | 000,173,602 | ---- | M] () -- C:\Windows\System32\C_20002.NLS
[2006/09/18 17:47:26 | 000,139,810 | ---- | M] () -- C:\Windows\System32\C_20261.NLS
[2006/09/18 17:47:26 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_720.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_875.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_870.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_708.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_500.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_21866.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_21027.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_21025.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20924.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20905.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20880.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20871.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20866.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20838.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20833.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20424.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20423.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20420.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20297.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20290.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20285.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20284.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20280.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20278.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20277.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20273.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20127.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20108.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20107.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20106.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_20105.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1149.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1148.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1147.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1146.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1145.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1144.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1143.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1142.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1141.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1140.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1047.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1026.NLS
[2006/09/18 17:47:26 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_037.NLS
[2006/09/18 17:47:25 | 000,196,642 | ---- | M] () -- C:\Windows\System32\C_936.NLS
[2006/09/18 17:47:25 | 000,162,850 | ---- | M] () -- C:\Windows\System32\C_932.NLS
[2006/09/18 17:47:25 | 000,066,594 | ---- | M] () -- C:\Windows\System32\C_874.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1258.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1257.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1256.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1255.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1254.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1253.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1252.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1251.NLS
[2006/09/18 17:47:25 | 000,066,082 | ---- | M] () -- C:\Windows\System32\C_1250.NLS
[2006/09/18 17:46:04 | 000,000,219 | ---- | M] () -- C:\Windows\system.ini
[2006/09/18 17:45:54 | 000,145,640 | ---- | M] () -- C:\Windows\System32\devmgmt.msc
[2006/09/18 17:44:13 | 000,144,862 | ---- | M] () -- C:\Windows\System32\tpm.msc
[2006/09/18 17:43:59 | 000,028,420 | ---- | M] () -- C:\Windows\System32\bios1.rom
[2006/09/18 17:43:59 | 000,018,832 | ---- | M] () -- C:\Windows\System32\v7vga.rom
[2006/09/18 17:43:59 | 000,008,191 | ---- | M] () -- C:\Windows\System32\bios4.rom
[2006/09/18 17:43:58 | 000,000,707 | ---- | M] () -- C:\Windows\_default.pif
[2006/09/18 17:43:44 | 000,021,232 | ---- | M] () -- C:\Windows\System32\graphics.pro
[2006/09/18 17:43:40 | 000,069,886 | ---- | M] () -- C:\Windows\System32\edit.com
[2006/09/18 17:43:40 | 000,010,790 | ---- | M] () -- C:\Windows\System32\EDIT.HLP
[2006/09/18 17:43:37 | 000,013,312 | ---- | M] () -- C:\Windows\System32\win87em.dll
[2006/09/18 17:43:37 | 000,000,010 | ---- | M] () -- C:\config.sys
[2006/09/18 17:43:36 | 000,001,688 | ---- | M] () -- C:\Windows\System32\autoexec.nt
[2006/09/18 17:43:36 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2006/09/18 17:43:30 | 000,000,843 | ---- | M] () -- C:\Windows\System32\onlinesetup.cmd
[2006/09/18 17:43:11 | 000,002,650 | ---- | M] () -- C:\Windows\System32\xwizard.dtd
[2006/09/18 17:41:30 | 000,017,244 | ---- | M] () -- C:\Windows\System32\drivers\etc\services
[2006/09/18 17:41:30 | 000,003,683 | ---- | M] () -- C:\Windows\System32\drivers\etc\lmhosts.sam
[2006/09/18 17:41:30 | 000,001,358 | ---- | M] () -- C:\Windows\System32\drivers\etc\protocol
[2006/09/18 17:41:30 | 000,000,761 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.20080921-141703.backup
[2006/09/18 17:41:30 | 000,000,407 | ---- | M] () -- C:\Windows\System32\drivers\etc\networks
[2006/09/18 17:40:16 | 000,001,559 | ---- | M] () -- C:\Windows\System32\WsmPty.xsl
[2006/09/18 17:40:16 | 000,000,035 | ---- | M] () -- C:\Windows\System32\winrm.cmd
[2006/09/18 17:39:30 | 000,215,943 | ---- | M] () -- C:\Windows\System32\dssec.dat
[2006/09/18 17:39:21 | 000,062,599 | ---- | M] () -- C:\Windows\System32\WmiMgmt.msc
[2006/09/18 17:38:24 | 000,211,938 | ---- | M] () -- C:\Windows\System32\lcphrase.tbl
[2006/09/18 17:38:24 | 000,024,114 | ---- | M] () -- C:\Windows\System32\lcptr.tbl
[2006/09/18 17:37:50 | 000,145,059 | ---- | M] () -- C:\Windows\System32\taskschd.msc
[2006/09/18 17:37:43 | 000,145,127 | ---- | M] () -- C:\Windows\System32\eventvwr.msc
[2006/09/18 17:37:26 | 000,000,741 | ---- | M] () -- C:\Windows\System32\NOISE.DAT
[2006/09/18 17:37:25 | 000,017,952 | ---- | M] () -- C:\Windows\System32\EventViewer_EventDetails.xsl
[2006/09/18 17:37:18 | 000,063,070 | ---- | M] () -- C:\Windows\System32\certmgr.msc
[2006/09/18 17:37:10 | 000,013,750 | ---- | M] () -- C:\Windows\System32\pacerprf.ini
[2006/09/18 17:37:10 | 000,003,010 | ---- | M] () -- C:\Windows\System32\pacercnt.h
[2006/09/18 17:37:01 | 000,002,060 | ---- | M] () -- C:\Windows\System32\noise.jpn
[2006/09/18 17:35:28 | 000,000,697 | ---- | M] () -- C:\Windows\System32\NOISE.THA
[2006/09/18 17:35:26 | 000,001,486 | ---- | M] () -- C:\Windows\System32\noise.kor
[2006/09/18 17:35:22 | 000,001,696 | ---- | M] () -- C:\Windows\System32\NOISE.CHT
[2006/09/18 17:35:04 | 000,001,696 | ---- | M] () -- C:\Windows\System32\NOISE.CHS
[2006/09/18 17:35:02 | 000,062,753 | ---- | M] () -- C:\Windows\System32\WF.msc
[2006/09/18 17:34:14 | 000,127,213 | ---- | M] () -- C:\Windows\System32\ega.cpi
[2006/09/18 17:34:01 | 000,047,679 | ---- | M] () -- C:\Windows\System32\diskmgmt.msc
[2006/09/18 17:33:53 | 000,063,412 | ---- | M] () -- C:\Windows\System32\NAPCLCFG.MSC
[2006/09/18 17:33:33 | 000,144,998 | ---- | M] () -- C:\Windows\System32\lusrmgr.msc
[2006/09/18 17:33:22 | 000,673,088 | ---- | M] () -- C:\Windows\System32\mlang.dat
[2006/09/18 17:32:09 | 001,228,100 | ---- | M] () -- C:\Windows\System32\8point1.wav
[2006/09/18 17:30:37 | 000,001,405 | ---- | M] () -- C:\Windows\msdfmap.ini
[2006/09/18 17:29:40 | 000,092,745 | ---- | M] () -- C:\Windows\System32\services.msc
[2006/09/18 17:29:38 | 000,113,256 | ---- | M] () -- C:\Windows\System32\compmgmt.msc
[2006/09/18 17:29:37 | 000,041,587 | ---- | M] () -- C:\Windows\System32\azman.msc
[2006/09/18 17:29:11 | 000,000,743 | ---- | M] () -- C:\Windows\System32\gatherWiredInfo.xslt
[2006/09/18 17:28:51 | 000,002,233 | ---- | M] () -- C:\Windows\System32\12520850.cpx
[2006/09/18 17:28:51 | 000,002,151 | ---- | M] () -- C:\Windows\System32\12520437.cpx
[2006/09/18 17:28:31 | 000,000,565 | ---- | M] () -- C:\Windows\System32\NdfEventView.xml
[2006/09/18 17:28:28 | 000,124,118 | ---- | M] () -- C:\Windows\System32\comexp.msc
[2006/09/18 17:26:46 | 003,440,660 | ---- | M] () -- C:\Windows\System32\drivers\gm.dls
[2006/09/17 01:36:50 | 000,770,048 | ---- | M] (Gracenote) -- C:\Windows\System32\CDDBUIRoxio.dll
[2006/09/17 01:36:50 | 000,643,072 | ---- | M] (Gracenote, Inc.) -- C:\Windows\System32\CDDBControlRoxio.dll
[2006/09/17 01:36:50 | 000,585,728 | ---- | M] (Gracenote) -- C:\Windows\System32\CddbMusicIDRoxio.dll
[2006/09/17 01:36:50 | 000,520,192 | ---- | M] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | ---- | M] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/09/17 01:36:50 | 000,090,112 | ---- | M] (Gracenote) -- C:\Windows\System32\CddbWOManagerRoxio.dll
[2006/09/17 01:36:48 | 000,147,456 | ---- | M] (Gracenote) -- C:\Windows\System32\CddbCleanRoxio.dll
[2006/06/14 15:55:28 | 000,095,270 | ---- | M] () -- C:\Windows\System32\sqlncli.chm
[2006/05/11 20:21:00 | 000,626,688 | ---- | M] (On2.com) -- C:\Windows\System32\vp7vfw.dll
[2006/03/09 14:58:00 | 001,060,424 | ---- | M] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/07/27 04:11:48 | 000,055,296 | ---- | M] () -- C:\Windows\System32\SQLServerManager.msc
[2005/05/06 23:06:00 | 000,016,480 | ---- | M] () -- C:\Windows\System32\rixdicon.dll
[1999/12/17 10:13:04 | 000,086,016 | ---- | M] (MindVision Software) -- C:\Windows\unvise32.exe
[1999/01/08 10:19:42 | 000,025,360 | ---- | M] () -- C:\Windows\System32\VBAPTB32.OLB
[1996/05/15 14:26:12 | 000,069,500 | -H-- | M] () -- C:\Users\worlwidewandering\Desktop\MO.TTF

========== Files Created - No Company Name ==========

[2013/09/09 09:15:33 | 000,000,861 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Optimizer Pro.lnk
[2013/09/08 19:46:27 | 000,000,446 | ---- | C] () -- C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/09/08 19:46:25 | 000,000,616 | ---- | C] () -- C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/09/08 19:46:23 | 000,000,644 | ---- | C] () -- C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/09/08 19:45:17 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/09/08 19:45:17 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/09/08 19:22:36 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/09/08 19:18:21 | 000,000,040 | ---- | C] () -- C:\Users\Public\Documents\_rgpl
[2013/07/31 01:15:06 | 003,068,279 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Local\IconCache.db
[2013/07/30 23:20:57 | 000,000,847 | ---- | C] () -- C:\Users\Public\Desktop\RealPlayer.lnk
[2013/07/29 14:54:42 | 209,901,568 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Leave It To Beaver S02E08 The Shave.avi
[2013/07/28 17:48:54 | 209,905,664 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Leave It To Beaver S02E02 Eddie's Girl.avi
[2013/07/28 03:30:56 | 005,848,361 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Hgwt1960-07-31089MySonMustDie.mp3
[2013/07/28 03:28:23 | 005,874,353 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Hgwt1958-11-23001StrangeVendettadonMiquelRojas.mp3
[2013/05/15 01:07:02 | 000,000,751 | ---- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2013/05/15 01:07:01 | 000,000,771 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\µTorrent.lnk
[2013/05/07 21:07:55 | 000,000,680 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Local\d3d9caps.dat
[2013/05/07 01:36:22 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TMContainer00000000000000000002.regtrans-ms
[2013/05/07 01:36:22 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TMContainer00000000000000000001.regtrans-ms
[2013/05/07 01:36:22 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{c5a16e57-b6d4-11e2-a36b-fbe7e3f5a822}.TM.blf
[2013/05/07 00:56:58 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TMContainer00000000000000000002.regtrans-ms
[2013/05/07 00:56:58 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TMContainer00000000000000000001.regtrans-ms
[2013/05/07 00:56:57 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{4145c833-b6d0-11e2-b099-8f4c3e92655c}.TM.blf
[2013/05/06 22:24:29 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 22:24:29 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 22:24:28 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{5b28e097-b6bb-11e2-a539-adb105ebd95d}.TM.blf
[2013/05/06 19:20:53 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 19:20:53 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 19:20:53 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{48485c6e-b69f-11e2-ba67-c4095c43ec5d}.TM.blf
[2013/05/06 18:31:44 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 18:31:44 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 18:31:44 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{147b80f7-b69a-11e2-a487-001d09b9bf0f}.TM.blf
[2013/05/06 02:09:04 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/06 02:09:03 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/06 02:09:03 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{42fc86c4-b611-11e2-b93f-abbd75df065f}.TM.blf
[2013/05/05 21:46:43 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TMContainer00000000000000000002.regtrans-ms
[2013/05/05 21:46:43 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TMContainer00000000000000000001.regtrans-ms
[2013/05/05 21:46:43 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{b38eabf4-b5ec-11e2-8332-dbb4b2c2f15f}.TM.blf
[2013/05/05 19:26:51 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TMContainer00000000000000000002.regtrans-ms
[2013/05/05 19:26:50 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TMContainer00000000000000000001.regtrans-ms
[2013/05/05 19:26:50 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat{f5fcbea4-b5d8-11e2-aa74-9029e44e385c}.TM.blf
[2013/05/05 18:09:30 | 000,000,000 | ---- | C] () -- C:\ProgramData\3f262138383b3d2d442337_c
[2013/03/25 18:20:45 | 000,000,009 | ---- | C] () -- C:\END
[2013/03/25 18:19:21 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2013/03/25 18:19:21 | 000,153,088 | ---- | C] () -- C:\Windows\System32\xvid.ax
[2013/03/25 18:19:20 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2013/03/25 18:16:35 | 000,119,552 | ---- | C] () -- C:\Windows\System32\GDIPFONTCACHEV1.DAT
[2012/12/13 04:09:31 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/12/13 04:09:31 | 000,000,003 | ---- | C] () -- C:\Windows\System32\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/08/31 16:30:52 | 000,001,842 | ---- | C] () -- C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2012/08/20 13:20:36 | 000,000,288 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\.backup.dm
[2012/08/13 21:18:45 | 000,110,592 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\RunClubSanDisk.exe
[2012/08/13 20:22:26 | 000,010,991 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\VitalChek Order Receipt.htm
[2012/08/01 20:59:01 | 000,000,080 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\mbam.context.scan
[2012/07/31 21:48:51 | 000,000,854 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\TrafficRobot (2).lnk
[2012/07/31 21:48:19 | 000,000,885 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\TheBestSpinner (2).lnk
[2012/07/31 21:47:34 | 000,000,908 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\mbam - Shortcut.lnk
[2012/07/31 21:14:54 | 000,444,955 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts.20120731-211454.backup
[2012/07/31 13:39:31 | 000,000,064 | ---- | C] () -- C:\ProgramData\-h17vDZggBw4Evir
[2012/07/31 13:39:31 | 000,000,064 | ---- | C] () -- C:\ProgramData\-h17vDZggBw4Evi
[2012/07/31 13:39:25 | 000,000,633 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\File_Recovery.lnk
[2012/07/31 13:39:20 | 000,000,368 | ---- | C] () -- C:\ProgramData\h17vDZggBw4Evi
[2012/07/31 10:13:38 | 000,000,854 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\TrafficRobot.lnk
[2012/07/26 12:24:30 | 000,000,048 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\example.html
[2012/06/22 09:11:31 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/03/27 01:39:30 | 000,072,822 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2012/03/26 14:03:50 | 000,030,208 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Be alert of new information changes .msg
[2011/07/16 12:37:33 | 000,001,994 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\The Rosetta Stone.lnk
[2011/07/08 15:14:58 | 000,001,795 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\TheBestSpinner.lnk
[2011/06/30 12:01:06 | 001,252,352 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\get rich.msam
[2011/06/07 13:10:15 | 000,071,680 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\turnaround king.msam
[2011/06/05 22:29:57 | 001,336,952 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\skin care products.msam-journal
[2011/06/03 13:19:49 | 001,326,080 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\skin care products.msam
[2011/04/30 16:49:29 | 000,075,924 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\cc_20110430_164905_registry_backup.reg
[2011/04/29 18:52:14 | 000,136,192 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\health.msam
[2011/04/22 19:59:32 | 001,510,400 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\beri ultimate.msam
[2011/04/18 02:26:06 | 000,000,940 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/04/18 00:28:35 | 020,533,281 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\vlc-1.1.9-win32.exe
[2011/04/17 23:04:59 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2011/04/17 23:04:28 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
[2011/04/12 02:42:46 | 000,036,047 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\win7_upgrade_report.mht
[2011/04/11 20:09:18 | 000,872,448 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\sales training.msam
[2011/04/11 12:15:25 | 000,001,726 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox (2).lnk
[2011/04/10 11:39:17 | 000,201,184 | ---- | C] () -- C:\Windows\System32\winrm.vbs
[2011/04/10 11:39:17 | 000,004,675 | ---- | C] () -- C:\Windows\System32\wsmanconfig_schema.xml
[2011/04/10 11:39:17 | 000,002,426 | ---- | C] () -- C:\Windows\System32\WsmTxt.xsl
[2010/08/03 13:12:20 | 000,000,394 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Swiss Sciences - Shortcut.lnk
[2010/07/23 20:30:55 | 000,001,976 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\KeywordCorral.lnk
[2010/07/23 20:09:02 | 000,000,830 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Web2Mayhem.lnk
[2010/05/18 09:24:56 | 000,000,886 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/18 09:24:52 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/18 09:16:10 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/05/18 09:13:53 | 000,001,997 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/05/18 09:13:53 | 000,001,973 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2010/02/28 22:42:44 | 012,644,650 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\FindYourBodyType+2010-02-28.csv
[2010/02/28 16:04:17 | 000,016,449 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\terms.html
[2010/02/27 17:23:14 | 000,049,152 | ---- | C] () -- C:\Windows\SPInstall.etl
[2010/02/21 16:59:37 | 000,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2010/02/21 16:59:33 | 000,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man
[2010/02/21 16:59:18 | 000,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf
[2010/02/21 16:59:14 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2010/02/21 16:59:13 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2010/02/21 16:59:01 | 003,662,128 | ---- | C] () -- C:\Windows\System32\locale.nls
[2010/02/21 16:59:00 | 000,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf
[2010/02/21 16:58:50 | 000,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf
[2010/02/21 16:58:06 | 000,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF
[2010/02/21 16:58:00 | 000,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs
[2010/02/21 16:57:41 | 000,368,640 | ---- | C] () -- C:\Windows\System32\msjetoledb40.dll
[2010/02/21 16:54:11 | 000,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml
[2010/02/21 16:53:20 | 000,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
[2009/12/12 11:52:11 | 002,501,921 | ---- | C] () -- C:\Windows\System32\wlan.tmf
[2009/01/21 19:23:08 | 000,000,952 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Adobe Flash CS3 Professional.lnk
[2009/01/21 19:08:47 | 002,463,976 | ---- | C] () -- C:\Windows\System32\NPSWF32.dll
[2008/12/20 17:14:02 | 000,000,393 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\XAMPP Control Panel.lnk
[2008/12/10 12:03:54 | 000,000,840 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\css_notes - Shortcut.lnk
[2008/12/10 01:03:05 | 001,352,284 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\ESG_US_SharedHosting.pdf
[2008/12/08 11:00:10 | 000,000,947 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\DataSafeDotNet.exe
[2008/11/30 12:34:13 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2008/11/30 12:34:00 | 011,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2008/11/29 23:37:36 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2008/11/29 23:21:21 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
[2008/11/19 20:41:20 | 000,031,266 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\cc_20081119_194114.reg
[2008/11/13 22:16:26 | 000,069,500 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\MO.TTF
[2008/11/05 17:24:25 | 000,002,633 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Microsoft Office Outlook 2007.lnk
[2008/11/04 10:05:55 | 000,002,677 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook 2007.lnk
[2008/10/21 19:41:49 | 000,001,767 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Photomatix Pro 3.lnk
[2008/10/13 19:30:26 | 008,200,242 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-5.psd
[2008/10/13 19:30:20 | 009,319,809 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-4.psd
[2008/10/13 19:30:10 | 008,203,475 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-3.psd
[2008/10/13 19:30:01 | 009,304,698 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-2.psd
[2008/10/13 19:29:56 | 008,211,044 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-1.psd
[2008/10/13 19:29:47 | 009,317,243 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-6.psd
[2008/10/13 19:29:11 | 001,507,677 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-6.jpg
[2008/10/13 19:28:50 | 001,620,898 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-5.jpg
[2008/10/13 19:28:32 | 001,494,117 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-4.jpg
[2008/10/13 19:26:48 | 001,437,779 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-1.jpg
[2008/10/13 19:26:33 | 001,402,155 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-2.jpg
[2008/10/13 19:26:08 | 001,594,368 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex-3.jpg
[2008/10/13 19:18:33 | 011,343,593 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\J-Vision Tex.pdf
[2008/10/11 18:30:55 | 000,000,764 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\RegCure.lnk
[2008/10/09 23:11:31 | 000,017,381 | -H-- | C] () -- C:\Users\worlwidewandering\Documents\Drawing1.htm
[2008/10/08 23:40:21 | 000,001,674 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Visio For Dummies.lnk
[2008/10/07 22:55:20 | 000,000,039 | ---- | C] () -- C:\Windows\vbaddin.ini
[2008/10/07 22:51:50 | 000,000,306 | ---- | C] () -- C:\Windows\ODBC.INI
[2008/10/06 09:30:43 | 003,099,740 | RH-- | C] () -- C:\Users\worlwidewandering\Documents\27 uger 0 dage 005 (07.09.08).JPG
[2008/09/28 23:00:33 | 000,000,884 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\More Eric Meyer on CSS.lnk
[2008/09/28 20:11:18 | 000,000,894 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\CSS Cookbook 2nd Edition - Shortcut.lnk
[2008/09/28 20:11:12 | 000,000,869 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\CSS Hacks & Filters - Shortcut.lnk
[2008/09/28 20:10:12 | 000,001,044 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\The Zen of CSS Design Visual Enlightenment for the Web - Shortcut.lnk
[2008/09/28 09:39:17 | 000,000,908 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\css.lnk
[2008/09/28 01:16:07 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Audio Units
[2008/09/28 01:16:07 | 000,000,268 | RH-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\Application Support
[2008/09/28 01:16:07 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLck.DAT
[2008/09/28 01:16:07 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Flange Saw
[2008/09/28 01:16:04 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Authentication
[2008/09/28 01:16:04 | 000,000,268 | RH-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\Applications
[2008/09/28 01:16:04 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Flowers
[2008/09/28 01:09:18 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLbx.DAT
[2008/09/27 23:22:32 | 000,001,882 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Bulletproof.Web.Design.lnk
[2008/09/27 22:42:30 | 000,001,774 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\QuickTime Player.lnk
[2008/09/27 22:35:00 | 000,001,278 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Guide to the Nikon D50.lnk
[2008/09/25 23:18:23 | 000,001,610 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\MagicISO.lnk
[2008/09/25 21:43:57 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2008/09/25 21:42:48 | 000,118,784 | ---- | C] () -- C:\Windows\GREUninstall.exe
[2008/09/25 21:42:41 | 000,008,653 | ---- | C] () -- C:\Windows\mozver.dat
[2008/09/25 20:54:55 | 000,001,275 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Dreamweaver CS3 (The Missing Manual Series) - Shortcut.lnk
[2008/09/24 12:15:36 | 000,060,124 | ---- | C] () -- C:\Windows\System32\tcpmon.ini
[2008/09/24 12:13:08 | 000,012,198 | ---- | C] () -- C:\Windows\System32\gatherWiredInfo.vbs
[2008/09/24 12:13:07 | 000,015,181 | ---- | C] () -- C:\Windows\System32\gatherWirelessInfo.vbs
[2008/09/24 12:13:06 | 000,144,909 | ---- | C] () -- C:\Windows\System32\fsmgmt.msc
[2008/09/24 12:13:01 | 000,145,455 | ---- | C] () -- C:\Windows\System32\perfmon.msc
[2008/09/22 20:18:57 | 000,000,940 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnk
[2008/09/22 19:11:40 | 000,000,668 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\vso_ts_preview.xml
[2008/09/22 19:08:53 | 000,087,608 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\inst.exe
[2008/09/22 19:08:53 | 000,007,887 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.cat
[2008/09/22 19:08:53 | 000,001,144 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.inf
[2008/09/22 19:08:49 | 000,000,987 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\ConvertXtoDvd 3.lnk
[2008/09/22 09:34:59 | 000,001,649 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\AVG Free 8.0.lnk
[2008/09/22 09:14:07 | 000,001,421 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Illustrator.lnk
[2008/09/22 09:13:31 | 000,000,990 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Photoshop.lnk
[2008/09/22 00:11:20 | 000,119,144 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/09/22 00:09:23 | 000,000,020 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.ini
[2008/09/22 00:09:22 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000002.regtrans-ms
[2008/09/22 00:09:22 | 000,524,288 | -HS- | C] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TMContainer00000000000000000001.regtrans-ms
[2008/09/22 00:09:22 | 000,065,536 | -HS- | C] () -- C:\Users\worlwidewandering\NTUSER.DAT{d8932e6d-6a6f-11db-b6ab-a038f15a5785}.TM.blf
[2008/09/22 00:09:21 | 012,845,056 | -HS- | C] () -- C:\Users\worlwidewandering\ntuser.dat
[2008/09/22 00:09:21 | 000,001,699 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Notepad.lnk
[2008/09/22 00:09:21 | 000,000,258 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2008/09/22 00:09:21 | 000,000,240 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2008/09/21 22:21:53 | 000,020,992 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/09/21 22:15:30 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdMtpDr_01_00_00.Wdf
[2008/09/21 21:56:43 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\UMDF\Msft_User_WpdFs_01_00_00.Wdf
[2008/09/21 19:00:18 | 000,002,627 | ---- | C] () -- C:\Users\worlwidewandering\Desktop\Microsoft Office Word 2007.lnk
[2008/09/21 18:59:29 | 000,001,014 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Dreamweaver.lnk
[2008/09/21 14:46:22 | 000,265,449 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts.20080921-144622.backup
[2008/09/21 14:17:03 | 000,000,761 | ---- | C] () -- C:\Windows\System32\drivers\etc\hosts.20080921-141703.backup
[2008/09/21 13:50:02 | 000,001,057 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Spybot - Search & Destroy.lnk
[2008/09/21 12:41:27 | 000,001,824 | -H-- | C] () -- C:\Users\worlwidewandering\Desktop\Dell DataSafe Online.lnk
[2008/09/21 12:18:37 | 000,000,945 | -H-- | C] () -- C:\Users\worlwidewandering\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2008/04/30 17:10:27 | 000,008,192 | ---- | C] ( ) -- C:\Windows\System32\cshost.dll
[2008/01/12 00:45:47 | 000,004,926 | RH-- | C] () -- C:\dell.sdr
[2008/01/12 00:45:35 | 000,011,441 | ---- | C] () -- C:\Windows\atiogl.xml
[2008/01/12 00:45:34 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008/01/12 00:45:34 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008/01/12 00:45:34 | 000,145,050 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008/01/12 00:45:34 | 000,042,960 | ---- | C] () -- C:\Windows\System32\drivers\ativvpxx.vp
[2008/01/12 00:45:34 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativpkxx.vp
[2008/01/12 00:45:34 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativdkxx.vp
[2008/01/12 00:45:32 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[2008/01/12 00:45:28 | 000,144,360 | ---- | C] () -- C:\Windows\System32\drivers\del1028.cty
[2008/01/12 00:45:27 | 000,260,330 | ---- | C] () -- C:\Windows\System32\OEM02Cvw.bff
[2008/01/12 00:45:27 | 000,057,656 | ---- | C] () -- C:\Windows\System32\drivers\OEM02Pvc.bmp
[2008/01/12 00:45:27 | 000,057,656 | ---- | C] () -- C:\Windows\System32\drivers\OEM02PC.bmp
[2008/01/12 00:45:27 | 000,004,510 | ---- | C] () -- C:\Windows\OEM002.uns
[2008/01/12 00:45:20 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2008/01/12 00:38:58 | 000,001,820 | ---- | C] () -- C:\Windows\System32\rasctrnm.h
[2008/01/12 00:26:05 | 000,004,926 | ---- | C] () -- C:\Windows\System32\drivers\1028_Dell_INS_I1521.mrk
[2008/01/11 17:41:43 | 000,000,071 | ---- | C] () -- C:\SystemInfo.ini
[2008/01/11 17:21:00 | 000,001,591 | ---- | C] () -- C:\Windows\System32\Uninst_EAPModules.bat
[2008/01/11 17:21:00 | 000,000,416 | ---- | C] () -- C:\Windows\System32\vcredist_x86.bat
[2008/01/11 17:20:58 | 000,054,784 | ---- | C] () -- C:\Windows\System32\bcmwlrmt.dll
[2008/01/11 17:20:54 | 000,024,064 | ---- | C] () -- C:\Windows\System32\WLTRYSVC.EXE
[2008/01/11 17:20:49 | 000,022,729 | ---- | C] () -- C:\newkey
[2008/01/11 17:20:49 | 000,022,729 | ---- | C] () -- C:\newfile.enc
[2008/01/11 17:19:39 | 000,000,080 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2008/01/11 17:07:18 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2008/01/11 17:00:13 | 006,291,456 | ---- | C] () -- C:\Windows\ocsetup_install_OEMHelpCustomization.etl
[2008/01/11 17:00:13 | 000,049,152 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.perf
[2008/01/11 17:00:13 | 000,016,384 | ---- | C] () -- C:\Windows\ocsetup_cbs_install_OEMHelpCustomization.dpx
[2008/01/11 17:00:13 | 000,001,623 | ---- | C] () -- C:\Users\Public\Desktop\Internet Explorer.lnk
[2008/01/11 16:52:34 | 000,744,740 | ---- | C] () -- C:\Windows\System32\oem8.inf
[2008/01/11 16:51:34 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_SynTP_01000.Wdf
[2007/01/22 14:58:46 | 000,231,008 | ---- | C] () -- C:\Windows\System32\DMdm32.cpl
[2006/11/10 17:59:07 | 000,008,192 | R-S- | C] () -- C:\BOOTSECT.BAK
[2006/11/10 17:59:06 | 000,333,257 | RHS- | C] () -- C:\bootmgr
[2006/11/07 15:25:58 | 000,000,000 | ---- | C] () -- C:\Windows\System32\px.ini
[2006/11/02 08:58:10 | 000,000,006 | -H-- | C] () -- C:\Windows\tasks\SA.DAT
[2006/11/02 08:53:49 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 08:53:49 | 000,041,176 | ---- | C] () -- C:\Windows\System32\license.rtf
[2006/11/02 08:53:22 | 000,001,741 | ---- | C] () -- C:\Windows\System32\migwiz.lnk
[2006/11/02 08:48:00 | 000,000,749 | RH-- | C] () -- C:\Windows\WindowsShell.Manifest
[2006/11/02 08:45:09 | 000,003,552 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2006/11/02 08:45:09 | 000,003,552 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2006/11/02 08:44:56 | 000,049,152 | ---- | C] () -- C:\Windows\System32\umstartup.etl
[2006/11/02 08:44:56 | 000,033,792 | ---- | C] () -- C:\Windows\System32\umstartup000.etl
[2006/11/02 08:44:53 | 001,773,008 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2006/11/02 08:34:54 | 000,316,640 | ---- | C] () -- C:\Windows\WMSysPr9.prx
[2006/11/02 08:34:06 | 000,093,702 | ---- | C] () -- C:\Windows\System32\SubRange.uce
[2006/11/02 08:34:06 | 000,060,458 | ---- | C] () -- C:\Windows\System32\ideograf.uce
[2006/11/02 08:34:06 | 000,024,006 | ---- | C] () -- C:\Windows\System32\gb2312.uce
[2006/11/02 08:34:06 | 000,022,984 | ---- | C] () -- C:\Windows\System32\bopomofo.uce
[2006/11/02 08:34:06 | 000,016,740 | ---- | C] () -- C:\Windows\System32\ShiftJIS.uce
[2006/11/02 08:34:06 | 000,012,876 | ---- | C] () -- C:\Windows\System32\korean.uce
[2006/11/02 08:34:06 | 000,008,484 | ---- | C] () -- C:\Windows\System32\kanji_2.uce
[2006/11/02 08:34:06 | 000,006,948 | ---- | C] () -- C:\Windows\System32\kanji_1.uce
[2006/11/02 08:33:45 | 000,000,933 | ---- | C] () -- C:\Windows\System32\gatherWirelessInfo.xslt
[2006/11/02 08:33:03 | 000,008,286 | ---- | C] () -- C:\Windows\HomeBasic.xml
[2006/11/02 06:33:01 | 000,843,252 | ---- | C] () -- C:\Windows\System32\PerfStringBackup.INI
[2006/11/02 06:33:01 | 000,702,262 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2006/11/02 06:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2006/11/02 06:33:01 | 000,142,546 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2006/11/02 06:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2006/11/02 06:25:44 | 000,328,162 | ---- | C] () -- C:\Windows\System32\drivers\ativcaxx.cpa
[2006/11/02 06:25:44 | 000,002,096 | ---- | C] () -- C:\Windows\System32\drivers\ativokxx.vp
[2006/11/02 06:25:44 | 000,000,929 | ---- | C] () -- C:\Windows\System32\drivers\ativcaxx.vp
[2006/11/02 06:24:31 | 000,001,405 | ---- | C] () -- C:\Windows\msdfmap.ini
[2006/11/02 06:23:50 | 000,444,955 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts
[2006/11/02 06:23:50 | 000,433,448 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts.20120731-211344.backup
[2006/11/02 06:23:50 | 000,433,448 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts.20110416-004535.backup
[2006/11/02 06:23:50 | 000,265,449 | R--- | C] () -- C:\Windows\System32\drivers\etc\hosts.20110415-232708.backup
[2006/11/02 06:23:50 | 000,017,244 | ---- | C] () -- C:\Windows\System32\drivers\etc\services
[2006/11/02 06:23:50 | 000,001,358 | ---- | C] () -- C:\Windows\System32\drivers\etc\protocol
[2006/11/02 06:23:50 | 000,000,407 | ---- | C] () -- C:\Windows\System32\drivers\etc\networks
[2006/11/02 06:23:31 | 000,000,219 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 06:23:31 | 000,000,219 | ---- | C] () -- C:\Windows\system.ini
[2006/11/02 06:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2006/11/02 06:23:09 | 000,002,577 | ---- | C] () -- C:\Windows\System32\config.nt
[2006/11/02 06:23:09 | 000,001,688 | ---- | C] () -- C:\Windows\System32\autoexec.nt
[2006/11/02 06:23:09 | 000,000,024 | ---- | C] () -- C:\autoexec.bat
[2006/11/02 04:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2006/11/02 04:56:06 | 000,000,743 | ---- | C] () -- C:\Windows\System32\gatherWiredInfo.xslt
[2006/11/02 04:25:14 | 000,003,577 | ---- | C] () -- C:\Windows\System32\sysprtj.sep
[2006/11/02 04:25:14 | 000,003,214 | ---- | C] () -- C:\Windows\System32\sysprint.sep
[2006/11/02 04:25:14 | 000,000,114 | ---- | C] () -- C:\Windows\System32\pcl.sep
[2006/11/02 04:25:14 | 000,000,051 | ---- | C] () -- C:\Windows\System32\pscript.sep
[2006/11/02 04:23:43 | 000,001,041 | ---- | C] () -- C:\Windows\System32\tcpbidi.xml
[2006/11/02 04:20:18 | 000,004,453 | ---- | C] () -- C:\Windows\System32\odbcconf.rsp
[2006/11/02 04:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2006/11/02 04:11:31 | 000,002,233 | ---- | C] () -- C:\Windows\System32\12520850.cpx
[2006/11/02 04:11:31 | 000,002,151 | ---- | C] () -- C:\Windows\System32\12520437.cpx
[2006/11/02 04:11:00 | 000,002,060 | ---- | C] () -- C:\Windows\System32\noise.jpn
[2006/11/02 04:10:55 | 000,001,486 | ---- | C] () -- C:\Windows\System32\noise.kor
[2006/11/02 04:10:48 | 000,000,697 | ---- | C] () -- C:\Windows\System32\NOISE.THA
[2006/11/02 03:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2006/11/02 03:40:29 | 000,003,010 | ---- | C] () -- C:\Windows\System32\pacercnt.h
[2006/11/02 03:39:48 | 000,063,412 | ---- | C] () -- C:\Windows\System32\NAPCLCFG.MSC
[2006/11/02 03:38:51 | 000,062,753 | ---- | C] () -- C:\Windows\System32\WF.msc
[2006/11/02 03:31:17 | 000,047,679 | ---- | C] () -- C:\Windows\System32\diskmgmt.msc
[2006/11/02 03:30:32 | 000,124,118 | ---- | C] () -- C:\Windows\System32\comexp.msc
[2006/11/02 03:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2006/11/02 03:24:20 | 000,144,998 | ---- | C] () -- C:\Windows\System32\lusrmgr.msc
[2006/11/02 03:17:14 | 000,063,070 | ---- | C] () -- C:\Windows\System32\certmgr.msc
[2006/11/02 03:16:33 | 000,001,559 | ---- | C] () -- C:\Windows\System32\WsmPty.xsl
[2006/11/02 03:16:33 | 000,000,035 | ---- | C] () -- C:\Windows\System32\winrm.cmd
[2006/11/02 03:15:44 | 000,145,127 | ---- | C] () -- C:\Windows\System32\eventvwr.msc
[2006/11/02 03:15:44 | 000,017,952 | ---- | C] () -- C:\Windows\System32\EventViewer_EventDetails.xsl
[2006/11/02 03:15:43 | 000,145,059 | ---- | C] () -- C:\Windows\System32\taskschd.msc
[2006/11/02 03:15:35 | 000,062,599 | ---- | C] () -- C:\Windows\System32\WmiMgmt.msc
[2006/11/02 03:13:33 | 000,092,745 | ---- | C] () -- C:\Windows\System32\services.msc
[2006/11/02 03:13:32 | 000,113,256 | ---- | C] () -- C:\Windows\System32\compmgmt.msc
[2006/11/02 03:13:32 | 000,041,587 | ---- | C] () -- C:\Windows\System32\azman.msc
[2006/11/02 03:11:29 | 000,211,938 | ---- | C] () -- C:\Windows\System32\lcphrase.tbl
[2006/11/02 03:11:29 | 000,024,114 | ---- | C] () -- C:\Windows\System32\lcptr.tbl
[2006/11/02 03:10:37 | 000,053,536 | ---- | C] () -- C:\Windows\System32\dosx.exe
[2006/11/02 03:10:02 | 000,000,718 | ---- | C] () -- C:\Windows\System32\mscdexnt.exe
[2006/11/02 03:10:00 | 000,002,842 | ---- | C] () -- C:\Windows\System32\redir.exe
[2006/11/02 03:09:59 | 000,069,886 | ---- | C] () -- C:\Windows\System32\edit.com
[2006/11/02 03:09:59 | 000,021,232 | ---- | C] () -- C:\Windows\System32\graphics.pro
[2006/11/02 03:09:59 | 000,019,694 | ---- | C] () -- C:\Windows\System32\GRAPHICS.COM
[2006/11/02 03:09:59 | 000,010,790 | ---- | C] () -- C:\Windows\System32\EDIT.HLP
[2006/11/02 03:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\share.exe
[2006/11/02 03:09:59 | 000,000,882 | ---- | C] () -- C:\Windows\System32\fastopen.exe
[2006/11/02 03:09:57 | 000,014,710 | ---- | C] () -- C:\Windows\System32\KB16.COM
[2006/11/02 03:09:56 | 000,007,052 | ---- | C] () -- C:\Windows\System32\nlsfunc.exe
[2006/11/02 03:09:55 | 000,039,274 | ---- | C] () -- C:\Windows\System32\mem.exe
[2006/11/02 03:09:55 | 000,001,131 | ---- | C] () -- C:\Windows\System32\LOADFIX.COM
[2006/11/02 03:09:53 | 000,011,753 | ---- | C] () -- C:\Windows\System32\setver.exe
[2006/11/02 03:09:52 | 000,020,634 | ---- | C] () -- C:\Windows\System32\debug.exe
[2006/11/02 03:09:51 | 000,008,424 | ---- | C] () -- C:\Windows\System32\exe2bin.exe
[2006/11/02 03:09:50 | 000,012,642 | ---- | C] () -- C:\Windows\System32\edlin.exe
[2006/11/02 03:09:49 | 000,050,648 | ---- | C] () -- C:\Windows\System32\COMMAND.COM
[2006/11/02 03:09:49 | 000,012,498 | ---- | C] () -- C:\Windows\System32\append.exe
[2006/11/02 03:09:45 | 000,027,097 | ---- | C] () -- C:\Windows\System32\country.sys
[2006/11/02 03:09:44 | 000,042,809 | ---- | C] () -- C:\Windows\System32\KEY01.SYS
[2006/11/02 03:09:44 | 000,042,537 | ---- | C] () -- C:\Windows\System32\KEYBOARD.SYS
[2006/11/02 03:09:42 | 000,009,029 | ---- | C] () -- C:\Windows\System32\ANSI.SYS
[2006/11/02 03:09:41 | 000,004,768 | ---- | C] () -- C:\Windows\System32\HIMEM.SYS
[2006/11/02 03:09:40 | 000,029,274 | ---- | C] () -- C:\Windows\System32\NTDOS412.SYS
[2006/11/02 03:09:38 | 000,029,370 | ---- | C] () -- C:\Windows\System32\NTDOS411.SYS
[2006/11/02 03:09:35 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS404.SYS
[2006/11/02 03:09:31 | 000,029,146 | ---- | C] () -- C:\Windows\System32\NTDOS804.SYS
[2006/11/02 03:09:29 | 000,027,866 | ---- | C] () -- C:\Windows\System32\NTDOS.SYS
[2006/11/02 03:09:26 | 000,035,536 | ---- | C] () -- C:\Windows\System32\NTIO412.SYS
[2006/11/02 03:09:24 | 000,035,776 | ---- | C] () -- C:\Windows\System32\NTIO411.SYS
[2006/11/02 03:09:23 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO404.SYS
[2006/11/02 03:09:22 | 000,034,672 | ---- | C] () -- C:\Windows\System32\NTIO804.SYS
[2006/11/02 03:09:20 | 000,033,952 | ---- | C] () -- C:\Windows\System32\NTIO.SYS
[2006/11/02 03:08:47 | 000,000,610 | ---- | C] () -- C:\Windows\System32\WdsUnattendTemplate.xml
[2006/11/02 03:04:09 | 000,000,707 | ---- | C] () -- C:\Windows\_default.pif
[2006/11/02 03:04:04 | 000,028,420 | ---- | C] () -- C:\Windows\System32\bios1.rom
[2006/11/02 03:04:04 | 000,018,832 | ---- | C] () -- C:\Windows\System32\v7vga.rom
[2006/11/02 03:04:04 | 000,008,191 | ---- | C] () -- C:\Windows\System32\bios4.rom
[2006/11/02 02:59:36 | 000,145,640 | ---- | C] () -- C:\Windows\System32\devmgmt.msc
[2006/11/02 02:58:59 | 000,066,384 | ---- | C] () -- C:\Windows\System32\normnfkc.nls
[2006/11/02 02:58:59 | 000,060,294 | ---- | C] () -- C:\Windows\System32\normnfkd.nls
[2006/11/02 02:58:59 | 000,059,342 | ---- | C] () -- C:\Windows\System32\normidna.nls
[2006/11/02 02:58:59 | 000,045,794 | ---- | C] () -- C:\Windows\System32\normnfc.nls
[2006/11/02 02:58:59 | 000,039,284 | ---- | C] () -- C:\Windows\System32\normnfd.nls
[2006/11/02 02:55:07 | 000,144,862 | ---- | C] () -- C:\Windows\System32\tpm.msc
[2006/11/02 02:47:32 | 000,001,696 | ---- | C] () -- C:\Windows\System32\NOISE.CHT
[2006/11/02 02:47:32 | 000,001,696 | ---- | C] () -- C:\Windows\System32\NOISE.CHS
[2006/11/02 02:43:31 | 001,228,100 | ---- | C] () -- C:\Windows\System32\8point1.wav
[2006/11/02 02:43:30 | 003,440,660 | ---- | C] () -- C:\Windows\System32\drivers\gm.dls
[2006/11/02 02:38:42 | 000,003,683 | ---- | C] () -- C:\Windows\System32\drivers\etc\lmhosts.sam
[2006/11/02 02:38:17 | 000,000,565 | ---- | C] () -- C:\Windows\System32\NdfEventView.xml
[2006/11/02 02:38:03 | 000,002,650 | ---- | C] () -- C:\Windows\System32\xwizard.dtd
[2006/11/02 02:32:53 | 000,008,798 | ---- | C] () -- C:\Windows\System32\icrav03.rat
[2006/11/02 02:32:53 | 000,001,988 | ---- | C] () -- C:\Windows\System32\ticrf.rat
[2006/11/02 02:27:30 | 000,127,213 | ---- | C] () -- C:\Windows\System32\ega.cpi
[2006/11/02 02:25:37 | 000,000,843 | ---- | C] () -- C:\Windows\System32\onlinesetup.cmd
[2006/11/02 02:25:08 | 000,013,312 | ---- | C] () -- C:\Windows\System32\win87em.dll
[2006/11/02 02:25:08 | 000,000,010 | ---- | C] () -- C:\config.sys
[2006/11/02 02:25:02 | 000,195,618 | ---- | C] () -- C:\Windows\System32\C_10002.NLS
[2006/11/02 02:25:02 | 000,177,698 | ---- | C] () -- C:\Windows\System32\C_10003.NLS
[2006/11/02 02:25:02 | 000,173,602 | ---- | C] () -- C:\Windows\System32\C_10008.NLS
[2006/11/02 02:25:02 | 000,162,850 | ---- | C] () -- C:\Windows\System32\C_10001.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_869.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_866.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_865.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_864.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_863.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_862.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_861.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_860.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_858.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_857.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_855.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_852.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_850.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_775.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_737.NLS
[2006/11/02 02:25:02 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_437.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28605.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\c_28603.nls
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28599.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28598.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28597.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10082.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10081.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10079.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10029.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10021.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10017.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10010.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10007.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10006.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10005.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10004.NLS
[2006/11/02 02:25:02 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_10000.NLS
[2006/11/02 02:25:01 | 000,189,986 | ---- | C] () -- C:\Windows\System32\C_1361.NLS
[2006/11/02 02:25:01 | 000,187,938 | ---- | C] () -- C:\Windows\System32\C_20005.NLS
[2006/11/02 02:25:01 | 000,186,402 | ---- | C] () -- C:\Windows\System32\C_20001.NLS
[2006/11/02 02:25:01 | 000,185,378 | ---- | C] () -- C:\Windows\System32\C_20003.NLS
[2006/11/02 02:25:01 | 000,180,770 | ---- | C] () -- C:\Windows\System32\C_20932.NLS
[2006/11/02 02:25:01 | 000,180,258 | ---- | C] () -- C:\Windows\System32\C_20004.NLS
[2006/11/02 02:25:01 | 000,180,258 | ---- | C] () -- C:\Windows\System32\C_20000.NLS
[2006/11/02 02:25:01 | 000,177,698 | ---- | C] () -- C:\Windows\System32\C_20949.NLS
[2006/11/02 02:25:01 | 000,173,602 | ---- | C] () -- C:\Windows\System32\C_20936.NLS
[2006/11/02 02:25:01 | 000,173,602 | ---- | C] () -- C:\Windows\System32\C_20002.NLS
[2006/11/02 02:25:01 | 000,139,810 | ---- | C] () -- C:\Windows\System32\C_20261.NLS
[2006/11/02 02:25:01 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_720.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_875.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_870.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_708.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_500.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28596.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28595.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28594.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28593.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28592.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_28591.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_21866.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_21027.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_21025.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20924.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20905.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20880.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20871.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20866.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20838.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20833.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20424.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20423.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20420.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20297.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20290.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20285.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20284.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20280.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20278.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20277.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20273.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20269.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20127.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20108.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20107.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20106.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_20105.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1149.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1148.NLS
[2006/11/02 02:25:01 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1147.NLS
[2006/11/02 02:25:01 | 000,008,838 | ---- | C] () -- C:\Windows\System32\l_intl.nls
[2006/11/02 02:25:00 | 000,196,642 | ---- | C] () -- C:\Windows\System32\C_950.NLS
[2006/11/02 02:25:00 | 000,196,642 | ---- | C] () -- C:\Windows\System32\C_949.NLS
[2006/11/02 02:25:00 | 000,196,642 | ---- | C] () -- C:\Windows\System32\C_936.NLS
[2006/11/02 02:25:00 | 000,162,850 | ---- | C] () -- C:\Windows\System32\C_932.NLS
[2006/11/02 02:25:00 | 000,066,594 | ---- | C] () -- C:\Windows\System32\C_874.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1258.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1257.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1256.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1255.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1254.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1253.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1252.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1251.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1250.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1146.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1145.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1144.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1143.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1142.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1141.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1140.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1047.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_1026.NLS
[2006/11/02 02:25:00 | 000,066,082 | ---- | C] () -- C:\Windows\System32\C_037.NLS
[2006/09/17 01:36:50 | 000,520,192 | ---- | C] () -- C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/09/17 01:36:50 | 000,204,800 | ---- | C] () -- C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/06/14 15:55:28 | 000,095,270 | ---- | C] () -- C:\Windows\System32\sqlncli.chm
[2005/07/27 04:11:48 | 000,055,296 | ---- | C] () -- C:\Windows\System32\SQLServerManager.msc
[1999/01/08 10:19:42 | 000,025,360 | ---- | C] () -- C:\Windows\System32\VBAPTB32.OLB

========== ZeroAccess Check ==========

[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 02:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2008/09/22 09:33:02 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/09/21 12:38:18 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\DataSafeOnline
[2013/03/25 18:20:43 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\File Scout
[2013/09/09 09:44:10 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\FileZilla
[2008/10/21 19:47:12 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\HDRsoft
[2011/07/08 14:54:10 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\JonathanLeger.com
[2011/04/11 19:46:52 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2008/09/27 16:31:48 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\MusicNet
[2012/10/10 13:53:51 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Nico Mak Computing
[2008/09/28 01:16:17 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Nikon
[2013/09/09 09:17:20 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro
[2013/03/25 23:02:23 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\PerformerSoft
[2013/04/29 18:33:35 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\player
[2013/09/09 09:29:59 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\SearchProtect
[2013/04/29 18:35:00 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Systweak
[2012/06/22 09:15:09 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\tmp
[2012/10/17 22:10:55 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\TrafficRobot
[2013/09/09 17:22:38 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\uTorrent
[2013/09/08 19:27:22 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Vso
[2011/06/30 20:38:45 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Web2Mayhem

========== Purity Check ==========



< End of report >

Attached Files


Edited by worldwidewandering, 09 September 2013 - 06:52 PM.

  • 0

Advertisements


#2
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Hello and welcome to Geeks to Go. I am sorry that you are having troubles with your computer and will try my best to help you. I know that being infected is very frustrating, but I will be here to help you through the whole process of cleaning. Removing malware can be difficult and complicated and will most likely take many steps, so please stick with me until I have declared your computer clean. I always recommend printing my instructions before following them in case you cannot keep this webpage open. Please be sure to alway follow all steps exactly as they are written and let me know what happens each time. Stop and ask if something unexpected happens or if you are unsure of how to proceed.

Please respect my volunteered time and stay with me until I declare your computer clean. If you are going to be delayed for a while, please let me know.

Let's me look over your logs and work up a fix. In the meantime, please download and run this (if you can). I would avoid using the flash drive with the infected computer for now.


Download aswMBR.exe to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#3
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Thank you, Buddierdl. I ran the scan. Below is the result:

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-09-10 11:52:51
-----------------------------
11:52:51.878 OS Version: Windows 6.0.6002 Service Pack 2
11:52:51.878 Number of processors: 2 586 0x6801
11:52:51.909 ComputerName: WORLWIDE-PC UserName:
11:53:06.276 Initialize success
11:53:12.267 AVAST engine defs: 13091000
11:53:20.426 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-1
11:53:20.613 Disk 0 Vendor: WDC_WD1200BEVS-75UST0 01.01A01 Size: 114473MB BusType: 3
11:53:20.847 Disk 0 MBR read successfully
11:53:20.909 Disk 0 MBR scan
11:53:21.003 Disk 0 Windows VISTA default MBR code
11:53:21.065 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 78 MB offset 63
11:53:21.159 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 161792
11:53:21.315 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 101593 MB offset 21133312
11:53:21.362 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 229195776
11:53:21.471 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 229197824
11:53:21.549 Disk 0 scanning sectors +234438656
11:53:21.783 Disk 0 scanning C:\Windows\system32\drivers
11:54:40.126 Service scanning
11:56:33.117 Modules scanning
11:56:55.035 Disk 0 trace - called modules:
11:56:55.175 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
11:56:55.238 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x862c3ac8]
11:56:55.316 3 CLASSPNP.SYS[8bd9e8b3] -> nt!IofCallDriver -> [0x862de918]
11:56:55.394 5 acpi.sys[834136bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-1[0x862cf8a0]
11:56:57.546 AVAST engine scan C:\Windows
11:57:05.986 AVAST engine scan C:\Windows\system32
12:15:16.691 AVAST engine scan C:\Windows\system32\drivers
12:16:20.043 AVAST engine scan C:\Users\worlwidewandering
13:04:36.245 File: C:\Users\worlwidewandering\Downloads\Piranha 3DD 2012 HDRIP XVID-DQ1_secure.exe **INFECTED** Win32:Adware-gen [Adw]
13:10:03.892 AVAST engine scan C:\ProgramData
13:24:34.263 Scan finished successfully
13:29:07.122 Disk 0 MBR has been saved successfully to "G:\Computer Fix\MBR.dat"
13:29:07.216 The log file has been saved successfully to "G:\Computer Fix\aswMBR.txt"
  • 0

#4
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Please run the following. Did you want PrivitizeVPN?


You have the following Peer-to-Peer program(s) installed:

uTorrent

GeeksToGo does not recommend using such programs, but you should read the description of Peer-to-Peer programs below before deciding for yourself.

Description of Peer-to-Peer (P2P) software.
P2P(Peer-to-Peer) may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. The program(s) may be safe, but there's no way to tell if the file being shared is infected. P2P programs, more often than not, install adware and/or spyware and worse still, some worms spread via P2P networks, infecting you as well.
Once upon a time, P2P file sharing was fairly safe. This is no longer true. P2P programs form a direct conduit inside your computer, their security measures are easily circumvented, and malware writers are increasingly exploiting them to spread their wares on to your computer. If your P2P program is not configured correctly, your computer may also be sharing more files than you realize. There have been cases where people's passwords, address books and other personal, private, and financial details have been exposed to a file sharing network by a badly configured program.

If you need convincing, please read these short reports on the dangers of peer-2-peer programs and file sharing.We advise removing any P2P programs you have now and avoiding this type of software application. Whether you remove them or not is your decision. But if you decide to keep and use Peer-to-Peer programs I can guarantee that you will be coming back to this forum or another malware forum. If you do choose to keep the program(s), please do not use it / them until the computer is clean and I give the all clear.


Please be aware that this fix will delete your temporary files. If the virus has "hidden" any of your files, please do not run the fix, but stop and let me know.

Start OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :Commands
    [createrestorepoint]
    
    :OTL
    SRV - [2013/08/29 23:43:40 | 000,206,624 | ---- | M] (LinkSwift) [Auto | Running] -- C:\Program Files\LinkSwift\updateLinkSwift.exe -- (Update LinkSwift)
    SRV - [2013/05/08 02:18:34 | 000,097,056 | ---- | M] (Conduit) [Auto | Running] -- C:\Program Files\SearchProtect\bin\CltMngSvc.exe -- (CltMngSvc)
    IE - HKLM\..\URLSearchHook: {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
    IE - HKLM\..\SearchScopes,DefaultScope = {B8FAC445-74FE-4E40-B933-4414C9CCA206}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...2E-F24E7593AB03
    IE - HKCU\..\URLSearchHook: {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
    IE - HKCU\..\SearchScopes,DefaultScope = {B8FAC445-74FE-4E40-B933-4414C9CCA206}
    IE - HKCU\..\SearchScopes\{B8FAC445-74FE-4E40-B933-4414C9CCA206}: "URL" = http://search.condui...3291569406&UM=2
    
    [2010/02/28 16:02:13 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
    [2013/04/29 13:50:29 | 000,000,000 | ---D | M] ("Supreme Savings") -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
    [2012/09/03 10:52:47 | 000,000,000 | ---D | M] (PlayBryte) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
    [2013/09/09 09:13:47 | 000,000,000 | ---D | M] (Define Ext) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]
    [2013/09/09 09:13:21 | 000,000,000 | ---D | M] (Define Ext) -- C:\Program Files\Mozilla Firefox\extensions\[email protected]
    
    CHR - default_search_provider: search_url = http://search.condui...=CT3298569&UM=2
    CHR - default_search_provider: suggest_url = http://suggest.searc...8439382629&UM=2
    CHR - homepage: http://search.condui...0295029404&UM=2
    
    O2 - BHO: (LinkSwift) - {323420b6-65e5-4657-8106-a27392d4d4aa} - C:\Program Files\LinkSwift\LinkSwiftBHO.dll (LinkSwift)
    O2 - BHO: (BrowserPlus2 Toolbar) - {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
    O2 - BHO: (no name) - {7736C7FA-512D-11E2-B871-DEC36088709B} - No CLSID value found.
    O2 - BHO: (Define) - {B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE} - C:\Users\worlwidewandering\AppData\Local\DefineExt\temp.dat ()
    
    O3 - HKLM\..\Toolbar: (BrowserPlus2 Toolbar) - {650598e1-b35a-45d3-b607-896d7acb64c3} - C:\Program Files\BrowserPlus2\prxtbBrow.dll (Conduit Ltd.)
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    
    O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files\SearchProtect\bin\cltmng.exe (Conduit)
    O4 - HKLM..\Run: [Wondershare Helper Compact.exe] C:\Program Files\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe File not found
    O4 - HKCU..\Run: [ConduitFloatingPlugin_iigplimlmgilpobjilfbfeilnpiigpgl] C:\Program Files\Conduit\CT3309350\plugins\TBVerifier.dll (Conduit Ltd.)
    O4 - HKCU..\Run: [Optimizer Pro] C:\Program Files\Optimizer Pro\OptProLauncher.exe (PC Utilities Pro)
    O4 - HKCU..\Run: [SearchProtect] C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\bin\cltmng.exe (Conduit)
    
    O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
    
    [2013/09/09 09:29:46 | 000,000,000 | ---D | C] -- C:\Program Files\LinkSwift
    [2013/09/09 09:23:10 | 000,000,000 | ---D | C] -- C:\Program Files\BrowserPlus2
    [2013/09/09 09:20:51 | 000,000,000 | ---D | C] -- C:\Program Files\SearchProtect
    [2013/09/09 09:19:36 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\SearchProtect
    [2013/09/09 09:17:20 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro
    [2013/09/09 09:15:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro
    [2013/09/09 09:14:58 | 000,000,000 | ---D | C] -- C:\Program Files\Optimizer Pro
    [2013/09/09 09:14:32 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Define Ext
    [2013/09/09 09:12:53 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Local\DefineExt
    [2013/09/09 09:12:32 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com
    [2013/05/13 05:35:43 | 000,000,000 | ---D | C] -- C:\SearchProtect
    
    [2012/07/31 13:43:24 | 000,000,368 | ---- | M] () -- C:\ProgramData\h17vDZggBw4Evi
    [2012/07/31 13:39:31 | 000,000,064 | ---- | M] () -- C:\ProgramData\-h17vDZggBw4Evir
    [2012/07/31 13:39:31 | 000,000,064 | ---- | M] () -- C:\ProgramData\-h17vDZggBw4Evi
    [2011/05/13 06:28:19 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
    
    [2013/09/09 09:17:20 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro
    
    :Commands
    [emptytemp]
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • Post the log it produces in your next reply. The log should be saved in C:\_OTL\MovedFiles and should be named with numbers describing the date and time it was run.


Posted Image Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

  • 0

#5
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
No, I don't want want PrivitizeVPN.

I have a question before I run OTL. In this line:

"Please be aware that this fix will delete your temporary files. If the virus has "hidden" any of your files, please do not run the fix, but stop and let me know."

How would I know if the virus has hidden any of my files? Am I supposed to run a scan with OTL firt? Before I paste the code for the custom scans/fixes?
  • 0

#6
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Here is the OTL Custom Fix:

All processes killed
========== COMMANDS ==========
Restore point Set: OTL Restore Point
========== OTL ==========
Error: Unable to stop service Update LinkSwift!
Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Update LinkSwift deleted successfully.
File move failed. C:\Program Files\LinkSwift\updateLinkSwift.exe scheduled to be moved on reboot.
Service CltMngSvc stopped successfully!
Service CltMngSvc deleted successfully!
C:\Program Files\SearchProtect\bin\CltMngSvc.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{650598e1-b35a-45d3-b607-896d7acb64c3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{650598e1-b35a-45d3-b607-896d7acb64c3}\ deleted successfully.
C:\Program Files\BrowserPlus2\prxtbBrow.dll moved successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{650598e1-b35a-45d3-b607-896d7acb64c3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{650598e1-b35a-45d3-b607-896d7acb64c3}\ not found.
File C:\Program Files\BrowserPlus2\prxtbBrow.dll not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B8FAC445-74FE-4E40-B933-4414C9CCA206}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B8FAC445-74FE-4E40-B933-4414C9CCA206}\ not found.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a} folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\skin folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\en-US folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome\content\extensionCode folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome\content\core folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome\content\api folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome\content folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\chrome folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected] folder moved successfully.
Folder C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\ not found.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]hjcpzmeselzlp.org\resources\api-utils\lib\windows\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\windows folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\window folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\utils folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\traits folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\tabs folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\system folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\l10n folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\events folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\event folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\dom folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\content folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\addon folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\lib folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\data folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\api-utils folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\lib folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\data folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\addon-kit folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\tests folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\lib folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\data folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\a folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\resources folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\locale folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\defaults folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\tmp\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\tmp\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\tmp\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\tmp folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\text-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\props folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn\prop-base folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected]\.svn folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\[email protected] folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\windows folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\window folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\utils folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\traits folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\tabs folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\system folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\l10n folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\events folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\event folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\dom folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\content folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\addon folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\lib folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\data folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\api-utils folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\lib folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\data folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\addon-kit folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\tests folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\lib folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\data folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\a folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\resources folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\locale folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\preferences folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\defaults folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\tmp\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\tmp\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\tmp\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\tmp folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\text-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\props folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn\prop-base folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected]\.svn folder moved successfully.
C:\Program Files\Mozilla Firefox\extensions\[email protected] folder moved successfully.
Use Chrome's Settings page to remove the default_search_provider items.
Use Chrome's Settings page to remove the default_search_provider items.
Use Chrome's Settings page to change the HomePage.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{323420b6-65e5-4657-8106-a27392d4d4aa}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{323420b6-65e5-4657-8106-a27392d4d4aa}\ deleted successfully.
C:\Program Files\LinkSwift\LinkSwiftBHO.dll moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{650598e1-b35a-45d3-b607-896d7acb64c3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{650598e1-b35a-45d3-b607-896d7acb64c3}\ not found.
File C:\Program Files\BrowserPlus2\prxtbBrow.dll not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7736C7FA-512D-11E2-B871-DEC36088709B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7736C7FA-512D-11E2-B871-DEC36088709B}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{7736C7FA-512D-11E2-B871-DEC36088709B}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B78F92C8-DEB3-11E2-9A0A-FB64281D6ADE}\ deleted successfully.
C:\Users\worlwidewandering\AppData\Local\DefineExt\temp.dat moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{650598e1-b35a-45d3-b607-896d7acb64c3} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{650598e1-b35a-45d3-b607-896d7acb64c3}\ not found.
File C:\Program Files\BrowserPlus2\prxtbBrow.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{A057A204-BACC-4D26-9990-79A187E2698E} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtectAll deleted successfully.
C:\Program Files\SearchProtect\bin\cltmng.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Wondershare Helper Compact.exe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ConduitFloatingPlugin_iigplimlmgilpobjilfbfeilnpiigpgl deleted successfully.
File move failed. C:\Program Files\Conduit\CT3309350\plugins\TBVerifier.dll scheduled to be moved on reboot.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro not found.
File C:\Program Files\Optimizer Pro\OptProLauncher.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SearchProtect deleted successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\bin\cltmng.exe moved successfully.
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\GD\\http deleted successfully.
Folder move failed. C:\Program Files\LinkSwift scheduled to be moved on reboot.
C:\Program Files\BrowserPlus2 folder moved successfully.
C:\Program Files\SearchProtect\ffprotect folder moved successfully.
C:\Program Files\SearchProtect\Dialogs\spsd\images folder moved successfully.
C:\Program Files\SearchProtect\Dialogs\spsd folder moved successfully.
C:\Program Files\SearchProtect\Dialogs\spbd\images folder moved successfully.
C:\Program Files\SearchProtect\Dialogs\spbd folder moved successfully.
C:\Program Files\SearchProtect\Dialogs\lib folder moved successfully.
C:\Program Files\SearchProtect\Dialogs folder moved successfully.
C:\Program Files\SearchProtect\bin folder moved successfully.
C:\Program Files\SearchProtect folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\SProtectorRepository folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd\images folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spsd folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd\images folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs\spbd folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs\lib folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect\Dialogs folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\ffprotect folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs\spsd\images folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs\spsd folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs\spbd\images folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs\spbd folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs\lib folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\Dialogs folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect\bin folder moved successfully.
C:\Users\worlwidewandering\AppData\Roaming\SearchProtect folder moved successfully.
Folder C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro\ not found.
Folder C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Optimizer Pro\ not found.
Folder C:\Program Files\Optimizer Pro\ not found.
C:\Users\worlwidewandering\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Define Ext folder moved successfully.
C:\Users\worlwidewandering\AppData\Local\DefineExt folder moved successfully.
C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com folder moved successfully.
C:\SearchProtect\ffprotect folder moved successfully.
C:\SearchProtect folder moved successfully.
C:\ProgramData\h17vDZggBw4Evi moved successfully.
C:\ProgramData\-h17vDZggBw4Evir moved successfully.
C:\ProgramData\-h17vDZggBw4Evi moved successfully.
C:\Windows\System32\%APPDATA%\Microsoft\Windows\IETldCache folder moved successfully.
C:\Windows\System32\%APPDATA%\Microsoft\Windows folder moved successfully.
C:\Windows\System32\%APPDATA%\Microsoft folder moved successfully.
C:\Windows\System32\%APPDATA% folder moved successfully.
Folder C:\Users\worlwidewandering\AppData\Roaming\Optimizer Pro\ not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 57482 bytes
->Flash cache emptied: 56466 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Public

User: worlwidewandering
->Temp folder emptied: 50917128 bytes
->Temporary Internet Files folder emptied: 16999718 bytes
->Java cache emptied: 55053 bytes
->FireFox cache emptied: 76233239 bytes
->Google Chrome cache emptied: 6091650 bytes
->Flash cache emptied: 57776 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 9819585 bytes
RecycleBin emptied: 2051769100 bytes

Total Files Cleaned = 2,110.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 09102013_165820

Files\Folders moved on Reboot...
C:\Program Files\LinkSwift\updateLinkSwift.exe moved successfully.
C:\Program Files\Conduit\CT3309350\plugins\TBVerifier.dll moved successfully.
C:\Program Files\LinkSwift folder moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
  • 0

#7
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Don't forget this:

Posted Image Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.


  • 0

#8
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
Here's the JRT File:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.5.9 (09.07.2013:1)
OS: Windows Vista ™ Home Basic x86
Ran by worlwidewandering on Tue 09/10/2013 at 18:33:48.64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{2CE4D4CF-B278-4126-AD1E-B622DA2E8339}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\distromatic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\filescout
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\softonic
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\startsearch
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduit
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\conduitsearchscopes
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\crossrider
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\pricegong
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\smartbar
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\toolbar
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\domaiq
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\supreme savings
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\linkswift
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\domaiq uninstaller
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0019962.BHO
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0019962.BHO.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0019962.Sandbox
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CrossriderApp0019962.Sandbox.1
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{11111111-1111-1111-1111-110111991162}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{22222222-2222-2222-2222-220122992262}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{55555555-5555-5555-5555-550155995562}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\Interface\{66666666-6666-6666-6666-660166996662}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\TypeLib\{44444444-4444-4444-4444-440144994462}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0019962.BHO
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0019962.BHO.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0019962.Sandbox
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\CrossriderApp0019962.Sandbox.1
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3072253
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3220468
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3227981
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3298569
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Toolbar.CT3309350
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{55555555-5555-5555-5555-550155995562}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\Interface\{66666666-6666-6666-6666-660166996662}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\TypeLib\{44444444-4444-4444-4444-440144994462}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{11111111-1111-1111-1111-110111991162}
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{11111111-1111-1111-1111-110111991162}



~~~ Files

Successfully deleted: [File] "C:\Windows\system32\roboot.exe"
Successfully deleted: [File] "C:\end"



~~~ Folders

Successfully deleted: [Folder] "C:\ProgramData\ibupdaterservice"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\AppData\Roaming\file scout"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\AppData\Roaming\performersoft"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\AppData\Roaming\systweak"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\appdata\local\conduit"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\appdata\locallow\conduit"
Successfully deleted: [Folder] "C:\Users\worlwidewandering\appdata\locallow\pricegong"
Successfully deleted: [Folder] "C:\Program Files\conduit"
Successfully deleted: [Folder] "C:\Program Files\domaiq uninstaller"
Successfully deleted: [Folder] "C:\Program Files\tuguu sl"
Successfully deleted: [Folder] "C:\Program Files\winzip registry optimizer"
Successfully deleted: [Folder] "C:\Program Files\Common Files\wondershare"



~~~ Chrome

Successfully deleted: [Folder] C:\Users\worlwidewandering\appdata\local\Google\Chrome\User Data\Default\Extensions\gjkpcnacdgdlpfejlgflolpaigoicibh
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\ejpbbhjlbipncjklfjjaedaieimbmdda



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 09/10/2013 at 19:10:22.81
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#9
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
How is the computer running now?

Please open OTL and run a "Quick Scan."
  • 0

#10
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
The computer is running better now. There are still some issues. I'm attaching the OTL log (I ran the scan before installing firefox. I've also uninstalled some programs after having run the scan, including bitTorrent). For one thing, the start menu is still a blank white section with only the "All Programs" link visible. Malware Bytes still does not run. When I try to start a scan it shuts down.

I am having trouble installing Firefox. But the same thing has happened that was happening before - I've installed firefox but cannot run it. When I try to open it I get a window that says that Firefox is running and the process needs to be closed first, but in task manager it doesn't show any firefox process running.

I still have a conduit search program I can't seem to get rid of. Other than that it seems fine. I just need to get my start menu back and get Malwarebytes to work, and firefox to work. I'm thinking if I'm having trouble with that program (and I had just updated to the latest version) that there must be some greater issue causing it. I also get a bubble box that pops up saying "Windows has blocked some startup programs". The OTL scan below was run before installing firefox and uninstalling several programs, as I said.

------------------
- OTL Quick Scan -
------------------

OTL logfile created on: 9/11/2013 9:27:20 AM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = G:\Computer Fix
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.37 Gb Total Physical Memory | 1.86 Gb Available Physical Memory | 55.02% Memory free
6.96 Gb Paging File | 5.67 Gb Available in Paging File | 81.43% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.21 Gb Total Space | 11.81 Gb Free Space | 11.90% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.04 Gb Free Space | 60.36% Space Free | Partition Type: NTFS
Drive G: | 29.06 Gb Total Space | 28.82 Gb Free Space | 99.18% Space Free | Partition Type: FAT32

Computer Name: WORLWIDE-PC | User Name: worlwidewandering | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/09/08 13:05:16 | 000,602,112 | ---- | M] (OldTimer Tools) -- G:\Computer Fix\OTL.exe
PRC - [2013/09/08 12:18:49 | 000,914,264 | ---- | M] (BitTorrent Inc.) -- C:\Users\worlwidewandering\AppData\Roaming\uTorrent\uTorrent.exe
PRC - [2013/07/30 22:56:08 | 000,295,512 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2013/07/25 11:19:26 | 005,624,784 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2013/05/16 10:56:34 | 001,033,688 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2013/05/16 10:56:30 | 001,817,560 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2013/05/15 13:21:32 | 000,171,928 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2013/05/10 03:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/04/16 03:07:08 | 000,039,056 | ---- | M] () -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2012/08/21 05:12:26 | 004,282,728 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/08/21 05:12:25 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2009/05/21 11:55:32 | 000,206,064 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtcmd.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/08/13 18:32:40 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe
PRC - [2008/08/04 09:45:16 | 005,779,456 | -H-- | M] () -- c:\xampp\mysql\bin\mysqld-nt.exe
PRC - [2008/07/07 03:34:59 | 000,167,936 | ---- | M] (PowerISO Computing, Inc.) -- C:\Program Files\PowerISO\PWRISOVM.EXE
PRC - [2008/01/19 03:38:38 | 001,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/09/07 14:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/09/07 14:23:36 | 000,405,504 | ---- | M] (IDT, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
PRC - [2007/08/29 17:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/08/29 01:54:58 | 000,036,864 | ---- | M] (Creative Technology Ltd.) -- C:\Windows\OEM02Mon.exe


========== Modules (No Company Name) ==========

MOD - [2013/08/23 05:10:12 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\59eba2680c01c33b2b3f5385979e32c6\System.Web.ni.dll
MOD - [2013/08/23 05:09:19 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b167ef6967ad27503c6ac6aabcef1aff\System.Runtime.Remoting.ni.dll
MOD - [2013/08/23 05:01:47 | 005,462,016 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09f5b3f7a363b742a73937e818595597\System.Xml.ni.dll
MOD - [2013/08/23 04:49:26 | 007,977,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\d7153acb7b6ccb5a6a886d6f0ab732b1\System.ni.dll
MOD - [2013/08/07 15:25:24 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2013/07/20 15:13:19 | 011,497,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\6a938df70a8b7996a3890b4f34c83906\mscorlib.ni.dll
MOD - [2013/05/16 10:55:26 | 000,113,496 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2013/05/16 10:55:24 | 000,416,600 | ---- | M] () -- C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2007/12/12 02:01:24 | 000,054,784 | ---- | M] () -- C:\Windows\System32\bcmwlrmt.dll
MOD - [2007/08/14 04:40:54 | 000,159,744 | ---- | M] () -- C:\Windows\System32\atitmmxx.dll
MOD - [2007/01/17 12:36:38 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDWSCService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDUpdateService)
SRV - File not found [Auto | Running] -- C:\Program Files\Spybot -- (SDScannerService)
SRV - [2013/09/10 19:40:55 | 000,257,416 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/05/10 03:57:22 | 000,065,640 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/04/16 03:07:08 | 000,039,056 | ---- | M] () [Auto | Running] -- C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe -- (RealNetworks Downloader Resolver Service)
SRV - [2012/11/09 12:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/08/21 05:12:25 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/05/25 15:14:34 | 000,053,248 | -H-- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper_3004.dll -- (nosGetPlusHelper)
SRV - [2009/12/01 20:43:02 | 000,051,384 | -H-- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper)
SRV - [2008/09/21 16:54:26 | 000,654,848 | -H-- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2008/08/13 18:32:40 | 000,201,968 | -H-- | M] (SupportSoft, Inc.) [Auto | Running] -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe -- (sprtsvc_dellsupportcenter)
SRV - [2008/08/04 09:45:16 | 005,779,456 | -H-- | M] () [Auto | Running] -- c:\xampp\mysql\bin\mysqld-nt.exe -- (mysql)
SRV - [2008/07/30 04:53:08 | 000,587,776 | -H-- | M] (FileZilla Project) [On_Demand | Stopped] -- c:\xampp\FileZillaFTP\FileZillaServer.exe -- (FileZilla Server)
SRV - [2008/06/14 13:02:12 | 000,017,408 | -H-- | M] (Apache Software Foundation) [Auto | Stopped] -- c:\xampp\apache\bin\apache.exe -- (Apache2.2)
SRV - [2008/01/19 03:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/11/07 09:58:18 | 003,004,416 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe -- (msvsmon90)
SRV - [2007/09/07 14:25:12 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/08/29 17:25:16 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/05/31 11:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 11:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\BCM42RLY.sys -- (BCM42RLY)
DRV - [2013/09/10 01:50:32 | 000,040,776 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2012/08/21 05:13:15 | 000,729,752 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/08/21 05:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/08/21 05:13:15 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/08/21 05:13:14 | 000,058,680 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2012/08/21 05:13:14 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/08/21 05:13:13 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2008/12/30 11:57:54 | 000,103,040 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbfake.sys -- (hwusbfake)
DRV - [2008/12/13 11:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/07/07 03:40:49 | 000,056,108 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\scdemu.sys -- (SCDEmu)
DRV - [2007/09/07 14:26:04 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/08/29 01:55:06 | 000,007,424 | ---- | M] (EyePower Games Pte. Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Vfx.sys -- (OEM02Vfx)
DRV - [2007/08/29 01:54:56 | 000,235,520 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\OEM02Dev.sys -- (OEM02Dev)
DRV - [2007/08/14 04:40:52 | 002,593,280 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2007/08/14 04:40:52 | 002,593,280 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2006/11/21 08:25:44 | 000,045,568 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2006/11/15 04:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/14 23:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/14 21:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/02 03:30:55 | 000,200,704 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2006/10/30 12:23:12 | 000,007,680 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2006/08/04 20:39:10 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...ie7&rlz=1I7DKUS
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.alistapart.com/articles [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7DKUS_enUS293
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search...p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 68.234.11.193:52931

========== FireFox ==========

FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.2: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.2.32: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2012/09/03 10:50:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FCE04E1F-9378-4f39-96F6-5689A9159E45}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/07/30 23:19:13 | 000,000,000 | ---D | M]

[2013/09/10 17:03:13 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Extensions
[2013/09/10 17:09:32 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions
[2011/04/09 15:19:56 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/25 22:16:10 | 000,000,000 | -H-D | M] (SeoQuake) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
[2012/08/01 00:43:46 | 000,000,000 | ---D | M] (uTorrentControl2) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2012/10/10 13:43:37 | 000,000,000 | ---D | M] (uTorrentControl_v2) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
[2008/09/21 23:03:17 | 000,000,000 | -H-D | M] (Adobe DLM (powered by getPlus®)) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
[2012/07/31 13:33:00 | 000,375,811 | -H-- | M] () (No name found) -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
[2008/09/22 13:53:13 | 000,001,504 | -H-- | M] () -- C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\searchplugins\imdb.xml
[2013/09/10 17:14:59 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/18 09:08:16 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}

========== Chrome ==========

CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url = http://search.condui...=CT3298569&UM=2
CHR - default_search_provider: suggest_url = http://suggest.searc...8439382629&UM=2
CHR - homepage: http://search.condui...0295029404&UM=2
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\29.0.1547.66\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.0.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement Web App = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\3.4.9_0\
CHR - Extension: TidyNetwork.com = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\didgecifffmcpanneoplfbplpfamlfbo\5.0.0.0_0\
CHR - Extension: RealDownloader = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0\
CHR - Extension: Poppit = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\

O1 HOSTS File: ([2012/07/31 21:14:54 | 000,444,955 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 15287 more lines...
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {650598E1-B35A-45D3-B607-896D7ACB64C3} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DELL Webcam Manager] C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [PrivitizeVPN] C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe (OOO Industry)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Users\worlwidewandering\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 65.32.5.111 65.32.5.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3A6D045D-F913-4C55-8264-412D607133E2}: DhcpNameServer = 65.32.5.111 65.32.5.112
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7621F659-A2C4-45EC-A429-0FC6962D71F1}: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O24 - Desktop WallPaper: C:\Users\worlwidewandering\Desktop\Germany\105CANON\IMG_0588.JPG
O24 - Desktop BackupWallPaper: C:\Users\worlwidewandering\Desktop\Germany\105CANON\IMG_0588.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2010/04/14 22:54:30 | 000,000,166 | ---- | M] () - G:\autorun.inf -- [ FAT32 ]
O33 - MountPoints2\{b9153ec7-b122-11e0-ac69-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b9153ec7-b122-11e0-ac69-806e6f6e6963}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{b9153f2a-b122-11e0-ac69-001d09b9bf0f}\Shell - "" = AutoRun
O33 - MountPoints2\{b9153f2a-b122-11e0-ac69-001d09b9bf0f}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2013/09/10 21:00:55 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\Documents\Clete
[2013/09/10 18:33:34 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/09/10 18:30:39 | 001,029,490 | ---- | C] (Thisisu) -- C:\Users\worlwidewandering\Desktop\JRT.exe
[2013/09/09 09:39:39 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\FileZilla
[2013/09/09 09:37:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2013/09/09 09:36:50 | 000,000,000 | ---D | C] -- C:\Program Files\FileZilla FTP Client
[2013/09/09 09:17:08 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2013/09/08 19:45:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/09/08 19:44:30 | 000,015,224 | ---- | C] (Safer Networking Limited) -- C:\Windows\System32\sdnclean.exe
[2013/09/08 19:43:08 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy 2
[2013/09/08 19:08:25 | 000,000,000 | ---D | C] -- C:\Users\worlwidewandering\AppData\Roaming\InstallShield
[2013/08/23 04:04:03 | 000,000,000 | ---D | C] -- C:\Windows\System32\MRT
[2008/09/22 19:08:53 | 000,047,360 | -H-- | C] (VSO Software) -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.sys

========== Files - Modified Within 30 Days ==========

[2013/09/11 09:40:05 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/11 09:36:56 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/11 09:36:56 | 000,003,552 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/11 09:19:48 | 000,000,644 | ---- | M] () -- C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/09/11 09:19:32 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/09/11 09:09:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/09/11 07:36:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/09/10 18:15:42 | 001,029,490 | ---- | M] (Thisisu) -- C:\Users\worlwidewandering\Desktop\JRT.exe
[2013/09/10 17:48:24 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2013/09/10 01:50:32 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2013/09/08 23:24:06 | 000,000,616 | ---- | M] () -- C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/09/08 23:24:06 | 000,000,446 | ---- | M] () -- C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/09/08 19:45:17 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/09/08 19:22:36 | 000,000,806 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/09/08 19:18:21 | 000,000,040 | ---- | M] () -- C:\Users\Public\Documents\_rgpl
[2013/09/08 14:05:27 | 000,001,973 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2013/09/08 13:13:35 | 000,702,262 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/09/08 13:13:35 | 000,142,546 | ---- | M] () -- C:\Windows\System32\perfc009.dat

========== Files Created - No Company Name ==========

[2013/09/08 19:46:27 | 000,000,446 | ---- | C] () -- C:\Windows\tasks\Scan the system (Spybot - Search & Destroy).job
[2013/09/08 19:46:25 | 000,000,616 | ---- | C] () -- C:\Windows\tasks\Refresh immunization (Spybot - Search & Destroy).job
[2013/09/08 19:46:23 | 000,000,644 | ---- | C] () -- C:\Windows\tasks\Check for updates (Spybot - Search & Destroy).job
[2013/09/08 19:45:17 | 000,001,972 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/09/08 19:45:17 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/09/08 19:22:36 | 000,000,806 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2013/09/08 19:18:21 | 000,000,040 | ---- | C] () -- C:\Users\Public\Documents\_rgpl
[2013/05/07 21:07:55 | 000,000,680 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Local\d3d9caps.dat
[2013/05/05 18:09:30 | 000,000,000 | ---- | C] () -- C:\ProgramData\3f262138383b3d2d442337_c
[2013/03/25 18:19:21 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2013/03/25 18:19:20 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/08/20 13:20:36 | 000,000,288 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\.backup.dm
[2012/08/01 20:59:01 | 000,000,080 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\mbam.context.scan
[2010/05/18 09:16:10 | 000,000,048 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2008/12/08 11:00:10 | 000,000,947 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\DataSafeDotNet.exe
[2008/09/28 01:16:07 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Audio Units
[2008/09/28 01:16:07 | 000,000,268 | RH-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\Application Support
[2008/09/28 01:16:07 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLck.DAT
[2008/09/28 01:16:07 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Flange Saw
[2008/09/28 01:16:04 | 000,000,268 | RH-- | C] () -- C:\ProgramData\Authentication
[2008/09/28 01:16:04 | 000,000,268 | RH-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\Applications
[2008/09/28 01:16:04 | 000,000,012 | RH-- | C] () -- C:\ProgramData\Flowers
[2008/09/28 01:09:18 | 000,000,020 | -H-- | C] () -- C:\ProgramData\PKP_DLbx.DAT
[2008/09/22 19:11:40 | 000,000,668 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\vso_ts_preview.xml
[2008/09/22 19:08:53 | 000,087,608 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\inst.exe
[2008/09/22 19:08:53 | 000,007,887 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.cat
[2008/09/22 19:08:53 | 000,001,144 | -H-- | C] () -- C:\Users\worlwidewandering\AppData\Roaming\pcouffin.inf
[2008/09/21 22:21:53 | 000,020,992 | ---- | C] () -- C:\Users\worlwidewandering\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== ZeroAccess Check ==========

[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 02:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2008/09/22 09:33:02 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2008/09/21 12:38:18 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\DataSafeOnline
[2013/09/09 09:44:10 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\FileZilla
[2008/10/21 19:47:12 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\HDRsoft
[2011/07/08 14:54:10 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\JonathanLeger.com
[2011/04/11 19:46:52 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2008/09/27 16:31:48 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\MusicNet
[2012/10/10 13:53:51 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Nico Mak Computing
[2008/09/28 01:16:17 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Nikon
[2013/04/29 18:33:35 | 000,000,000 | ---D | M] -- C:\Users\worlwidewandering\AppData\Roaming\player
[2012/06/22 09:15:09 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\tmp
[2012/10/17 22:10:55 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\TrafficRobot
[2013/09/11 10:06:23 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\uTorrent
[2013/09/08 19:27:22 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Vso
[2011/06/30 20:38:45 | 000,000,000 | -H-D | M] -- C:\Users\worlwidewandering\AppData\Roaming\Web2Mayhem

========== Purity Check ==========



< End of report >
  • 0

Advertisements


#11
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Ok. I see the Conduit in Chrome. Let's try this to get rid of it. If not, we'll have to go in manually. It looks like it is only in chrome?

After this, we'll tackle the other issues.


Click on this link to download : ADWCleaner Click on the Download Now button and save it to your desktop.

NOTE: If using Internet Explorer and you get an alert that stops the program downloading click on Tools > Smartscreen Filter > Turn off Smartscreen Filter then click on OK in the box that opens. Then click on the link again.

Close your browser and double click on this icon on your desktop:

Posted Image

You will then see the screen below, click on the Scan button (as indicated), accept any prompts that appear and allow it to run, it may take several minutes to complete, when it is done click on the Clean button, accept any prompts that appear and allow the system to reboot. You will then be presented with the report, Copy & Paste it into your next post.

Posted Image

Then, let's run another scan to have a look.


Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. You will need the 32-bit edition.
  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

  • 0

#12
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
I'm not sure if the conduit program is in the other browsers. I've not really been using the others. Firefox I have not been able to run at all.

-------------------
- AdwCleaner Scan -
-------------------

# AdwCleaner v3.003 - Report created 11/09/2013 at 20:42:35
# Updated 07/09/2013 by Xplode
# Operating System : Windows Vista ™ Home Basic Service Pack 2 (32 bits)
# Username : worlwidewandering - WORLWIDE-PC
# Running from : C:\Users\worlwidewandering\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\Program Files\Common Files\AVG Secure Search
Folder Deleted : C:\Users\worlwidewandering\AppData\LocalLow\BrowserPlus2
Folder Deleted : C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\StumbleUpon
Folder Deleted : C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
Folder Deleted : C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{7473b6bd-4691-4744-a82b-7854eb3d70b6}
Folder Deleted : C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof

***** [ Shortcuts ] *****


***** [ Registry ] *****

Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[email protected]]
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\grusskartencenter.com
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\grusskartencenter.com
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{A83013E6-BF8A-410F-B343-E9D1E597A36E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{FD9BC852-BEE3-47CC-8EDC-D54E269E9B8B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7E860E05-C38F-44E5-BCB5-D5F4B590F89F}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{650598E1-B35A-45D3-B607-896D7ACB64C3}]
Key Deleted : HKCU\Software\InstallCore
Key Deleted : HKCU\Software\AppDataLow\Software\BrowserPlus2
Key Deleted : HKLM\Software\AVG Security Toolbar
Key Deleted : HKLM\Software\BrowserPlus2
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EBE677C0-CBCB-4EBF-8098-E27E1B5271CF}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\RegClean Pro_is1
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\SearchProtect

***** [ Browsers ] *****

-\\ Internet Explorer v9.0.8112.16502


-\\ Mozilla Firefox v23.0.1 (en-US)

[ File : C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\prefs.js ]

Line Deleted : user_pref("browser.search.defaultenginename", "AVG Secure Search");
Line Deleted : user_pref("browser.search.selectedEngine", "AVG Secure Search");

-\\ Google Chrome v29.0.1547.66

[ File : C:\Users\worlwidewandering\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Deleted : homepage
Deleted : icon_url
Deleted : search_url
Deleted : suggest_url
Deleted : keyword
Deleted : urls_to_restore_on_startup

*************************

AdwCleaner[R0].txt - [7317 octets] - [11/09/2013 20:25:11]
AdwCleaner[S0].txt - [7182 octets] - [11/09/2013 20:42:35]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7242 octets] ##########



----------------
- Farbar Scans -
----------------


------------
- FRST.txt -
------------


Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 09-09-2013 02
Ran by worlwidewandering (administrator) on WORLWIDE-PC on 11-09-2013 21:15:04
Running from C:\Users\worlwidewandering\Downloads
Microsoft® Windows Vista™ Home Basic Service Pack 2 (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Normal

==================== Processes (Whitelisted) ===================

(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
(Microsoft Corporation) C:\Windows\system32\SLsvc.exe
(ATI Technologies Inc.) C:\Windows\system32\Ati2evxx.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\bcmwltry.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
(Andrea Electronics Corporation) C:\Windows\system32\aestsrv.exe
(Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
() c:\xampp\mysql\bin\mysqld-nt.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(IDT, Inc.) C:\Windows\system32\STacSV.exe
(Conexant Systems, Inc.) C:\Windows\system32\DRIVERS\xaudio.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Creative Technology Ltd.) C:\Windows\OEM02Mon.exe
(Microsoft Corporation) C:\Windows\WindowsMobile\wmdc.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(Apple Computer, Inc.) C:\Program Files\QuickTime\qttask.exe
(IDT, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtcmd.exe
(AVAST Software) C:\Program Files\Alwil Software\Avast5\AvastUI.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Windows Defender] - C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-19] (Microsoft Corporation)
HKLM\...\Run: [ECenter] - C:\Dell\E-Center\EULALauncher.exe [17920 2007-05-25] ( )
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [857648 2007-04-27] (Synaptics, Inc.)
HKLM\...\Run: [OEM02Mon.exe] - C:\Windows\OEM02Mon.exe [36864 2007-08-29] (Creative Technology Ltd.)
HKLM\...\Run: [Windows Mobile Device Center] - C:\Windows\WindowsMobile\wmdc.exe [648072 2007-05-31] (Microsoft Corporation)
HKLM\...\Run: [DELL Webcam Manager] - C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe [118784 2007-07-27] (Creative Technology Ltd.)
HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Windows\system32\WLTRAY.exe [3444736 2007-12-12] (Dell Inc.)
HKLM\...\Run: [] - [x]
HKLM\...\Run: [dscactivate] - C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [16384 2007-10-09] ( )
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\qttask.exe [155648 2008-09-27] (Apple Computer, Inc.)
HKLM\...\Run: [SigmatelSysTrayApp] - C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-09-07] (IDT, Inc.)
HKLM\...\Run: [dellsupportcenter] - "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [avast] - C:\Program Files\Alwil Software\Avast5\avastUI.exe [4282728 2012-08-21] (AVAST Software)
HKLM\...\Run: [PrivitizeVPN] - C:\Program Files\PrivitizeVPN\PrivitizeVPN.exe [196784 2012-08-31] (OOO Industry)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-07-30] (RealNetworks, Inc.)
HKLM\...\Run: [SDTray] - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKCU\...\Run: [Xvid] - C:\Program Files\Xvid\CheckUpdate.exe [8192 2011-01-17] ()
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2008-01-11] (Google Inc.)
MountPoints2: {b9153ec7-b122-11e0-ac69-806e6f6e6963} - G:\AutoRun.exe
MountPoints2: {b9153f2a-b122-11e0-ac69-001d09b9bf0f} - G:\AutoRun.exe
HKU\Default\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\Default User\...\Run: [WindowsWelcomeCenter] - rundll32.exe oobefldr.dll,ShowWelcomeCenter
BootExecute: autocheck autochk * sdnclean.exe

==================== Internet (Whitelisted) ====================

ProxyServer: 68.234.11.193:52931
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.alistapar...s/customcorners
http://www.csszengar...ile=013/013.css
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
SearchScopes: HKCU - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} URL = http://us.yhs.search...p={searchTerms}
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll (Safer Networking Limited)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7227.1100\swg.dll (Google Inc.)
BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKLM - avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU -Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [94208] (Apple Computer, Inc.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 65.32.5.111 65.32.5.112

FireFox:
========
FF ProfilePath: C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default
FF Homepage: hxxp://mysearch.avg.com/?cid={600B9750-6672-4E2A-B1AF-9D1E4E5649AF}&mid=bbf05d3c0d0747d38895d1544f5d56fc-0a0759aaf7c1cfa59a12925f780637ce1c807e98&lang=en&ds=co012&pr=sa&d=2013-09-11 12:13:46&v=15.4.0.5&pid=safeguard&sg=0&sap=hp
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @real.com/nppl3260;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlchromebrowserrecordext;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlhtml5videoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprndlpepperflashvideoshim;version=1.3.2 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin: @real.com/nprpplugin;version=16.0.2.32 - c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\searchplugins\imdb.xml
FF Extension: Microsoft .NET Framework Assistant - C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF Extension: SeoQuake - C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{317B5128-0B0B-49b2-B2DB-1E7560E16C74}
FF Extension: Adobe DLM (powered by getPlus®) - C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}
FF Extension: No Name - C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox\Profiles\2bl30s2o.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi
FF Extension: Skype extension for Firefox - C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF Extension: avast! WebRep - C:\Program Files\Alwil Software\Avast5\WebRep\FF
FF HKLM\...\Firefox\Extensions: [{FCE04E1F-9378-4f39-96F6-5689A9159E45}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchURL: (Conduit) - http://search.condui...=CT3309350&UM=2
CHR DefaultSuggestURL: (Conduit) - http://suggest.searc...0295029404&UM=2
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\29.0.1547.66\gcswf32.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (2007 Microsoft Office system) - C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL (Microsoft Corporation)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll (Apple Computer, Inc.)
CHR Plugin: (QuickTime Plug-in 7.0.4) - C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll (Apple Computer, Inc.)
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Extension: (RealDownloader) - C:\Users\WORLWI~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji\1.3.2_0
CHR HKLM\...\Chrome\Extension: [icmlaeflemplmjndnaapfdbbnpncnbda] - C:\Program Files\Alwil Software\Avast5\WebRep\Chrome\aswWebRepChrome.crx
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
CHR HKLM\...\Chrome\Extension: [iigplimlmgilpobjilfbfeilnpiigpgl] - C:\Users\worlwidewandering\AppData\Local\CRE\iigplimlmgilpobjilfbfeilnpiigpgl.crx
CHR HKLM\...\Chrome\Extension: [mmlkabjddkpgkgfhdhpimhcbonapngoh] - C:\Users\worlwidewandering\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx
CHR HKLM\...\Chrome\Extension: [odpccdgkmiicgocepijnaeihjnjnomca] - C:\Program Files\LinkSwift\odpccdgkmiicgocepijnaeihjnjnomca.crx
CHR HKLM\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\worlwidewandering\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx
CHR HKLM\...\Chrome\Extension: [ppppebhepbpibjjecehmkoipieddjeff] - C:\Users\worlwidewandering\AppData\Local\CRE\ppppebhepbpibjjecehmkoipieddjeff.crx

========================== Services (Whitelisted) =================

S2 Apache2.2; c:\xampp\apache\bin\apache.exe [17408 2008-06-14] (Apache Software Foundation)
R2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [44808 2012-08-21] (AVAST Software)
S3 FileZilla Server; c:\xampp\FileZillaFTP\FileZillaServer.exe [587776 2008-07-30] (FileZilla Project)
S3 getPlusHelper; C:\Program Files\NOS\bin\getPlus_Helper.dll [51384 2009-12-01] (NOS Microsystems Ltd.)
S3 GoogleDesktopManager; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1838592 2008-01-11] (Google)
S2 gupdate1caf68b68b171f8; C:\Program Files\Google\Update\GoogleUpdate.exe [133104 2010-05-18] (Google Inc.)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
S4 msvsmon90; C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x86\msvsmon.exe [3004416 2007-11-07] (Microsoft Corporation)
R2 mysql; c:\xampp\mysql\bin\my.cnf [5282 2008-12-20] ()
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-04-16] ()
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-08-13] (SupportSoft, Inc.)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2506752 2007-12-12] (Dell Inc.)
S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x]

==================== Drivers (Whitelisted) ====================

R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [21256 2012-08-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [58680 2012-08-21] (AVAST Software)
R1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [35928 2012-08-21] (AVAST Software)
R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [729752 2012-08-21] (AVAST Software)
R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [355632 2012-08-21] (AVAST Software)
R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [54232 2012-08-21] (AVAST Software)
R1 avgtp; C:\Windows\system32\drivers\avgtpx86.sys [37664 2013-09-11] (AVG Technologies)
R0 CLFS; C:\Windows\System32\CLFS.sys [245736 2009-04-11] (Microsoft Corporation)
S3 hwusbfake; C:\Windows\System32\DRIVERS\ewusbfake.sys [103040 2008-12-30] (Huawei Technologies Co., Ltd.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-09-11] (Malwarebytes Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [x]
S4 blbdrive; \SystemRoot\system32\drivers\blbdrive.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-11 21:09 - 2013-09-11 21:09 - 01082587 _____ (Farbar) C:\Users\worlwidewandering\Downloads\FRST.exe
2013-09-11 20:19 - 2013-09-11 20:44 - 00000000 ____D C:\AdwCleaner
2013-09-11 20:18 - 2013-09-11 20:19 - 00343718 _____ C:\Users\worlwidewandering\Downloads\Setup (3).exe
2013-09-11 20:15 - 2013-09-11 20:15 - 01037278 _____ C:\Users\worlwidewandering\Downloads\AdwCleaner.exe
2013-09-11 19:10 - 2013-09-11 19:12 - 00197610 _____ C:\Users\worlwidewandering\Documents\cc_20130911_191039.reg
2013-09-11 18:13 - 2013-09-11 18:13 - 00000848 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-11 18:13 - 2013-09-11 18:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-09-11 12:19 - 2013-09-11 15:07 - 00000952 _____ C:\Users\worlwidewandering\Desktop\Continue Firefox Installation.lnk
2013-09-11 12:19 - 2013-09-11 12:19 - 00000000 ____D C:\Users\worlwidewandering\AppData\Local\AVG SafeGuard toolbar
2013-09-11 12:17 - 2013-09-11 17:18 - 00000322 _____ C:\Windows\Tasks\UpdaterEX.job
2013-09-11 12:17 - 2013-09-11 12:17 - 22404568 _____ (Mozilla) C:\Users\worlwidewandering\Downloads\Firefox_Setup [1].exe
2013-09-11 12:17 - 2013-09-11 12:17 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\UpdaterEX
2013-09-11 12:15 - 2013-09-11 12:15 - 00281776 _____ (Mozilla) C:\Users\worlwidewandering\Downloads\Firefox Setup Stub 23.0.1.exe
2013-09-11 12:13 - 2013-09-11 12:13 - 00676344 _____ C:\Users\worlwidewandering\Downloads\Firefox_Setup (1).exe
2013-09-11 12:13 - 2013-09-11 12:10 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2013-09-11 12:12 - 2013-09-11 19:57 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-09-11 12:11 - 2013-09-11 12:11 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar
2013-09-11 12:02 - 2013-09-11 12:02 - 00676344 _____ C:\Users\worlwidewandering\Downloads\Firefox_Setup.exe
2013-09-10 21:00 - 2013-09-10 21:02 - 00000000 ____D C:\Users\worlwidewandering\Documents\Clete
2013-09-10 18:33 - 2013-09-10 18:33 - 00000000 ____D C:\Windows\ERUNT
2013-09-10 18:30 - 2013-09-10 18:15 - 01029490 _____ (Thisisu) C:\Users\worlwidewandering\Desktop\JRT.exe
2013-09-09 09:40 - 2013-09-09 09:40 - 04812567 _____ (Tim Kosse) C:\Users\worlwidewandering\Downloads\FileZilla_3.7.3_win32-setup.exe
2013-09-09 09:39 - 2013-09-09 09:44 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\FileZilla
2013-09-09 09:36 - 2013-09-09 09:42 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2013-09-09 09:31 - 2013-09-09 09:32 - 04521014 _____ C:\Users\worlwidewandering\Downloads\FileZilla_3.5.0_win32-setup.exe
2013-09-09 09:08 - 2013-09-09 09:08 - 00589592 _____ C:\Users\worlwidewandering\Downloads\filezilla-setup.exe
2013-09-08 19:46 - 2013-09-11 20:54 - 00000644 _____ C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2013-09-08 19:46 - 2013-09-08 23:24 - 00000616 _____ C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2013-09-08 19:46 - 2013-09-08 23:24 - 00000446 _____ C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2013-09-08 19:45 - 2013-09-08 19:45 - 00001960 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-09-08 19:44 - 2009-01-25 13:14 - 00015224 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2013-09-08 19:43 - 2013-09-08 19:45 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-09-08 19:22 - 2013-09-08 19:22 - 00000806 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-08 19:18 - 2013-09-08 19:18 - 00000040 _____ C:\Users\Public\Documents\_rgpl
2013-09-08 19:08 - 2013-09-08 19:08 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\InstallShield
2013-09-08 12:27 - 2013-09-08 12:29 - 04454952 _____ (Piriform Ltd) C:\Users\worlwidewandering\Downloads\ccsetup405.exe
2013-09-01 00:43 - 2013-09-01 00:43 - 00028919 _____ C:\Users\worlwidewandering\Downloads\[kickass.to]dexter.s08e09.hdtv.x264.asap.ettv.torrent
2013-08-31 22:49 - 2013-08-02 00:09 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-08-31 21:57 - 2013-08-31 21:57 - 00056170 _____ C:\Users\worlwidewandering\Downloads\[isoHunt] download (8).torrent
2013-08-31 21:44 - 2013-08-31 21:44 - 00056170 _____ C:\Users\worlwidewandering\Downloads\AD6.tmp
2013-08-31 21:43 - 2013-08-31 21:43 - 00056170 _____ C:\Users\worlwidewandering\Downloads\[isoHunt] download (7).torrent
2013-08-23 23:49 - 2013-08-23 23:49 - 00015422 _____ C:\Users\worlwidewandering\Downloads\Zombie_Massacre_(2012).XViD.HQuality.torrent
2013-08-23 04:04 - 2013-08-23 04:20 - 00000000 ____D C:\Windows\system32\MRT
2013-08-23 03:16 - 2013-07-24 22:32 - 01800704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-08-23 03:16 - 2013-07-24 22:26 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-08-23 03:16 - 2013-07-24 22:26 - 01104384 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-08-23 03:16 - 2013-07-24 22:24 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-08-23 03:16 - 2013-07-24 22:24 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-08-23 03:16 - 2013-07-24 22:23 - 01796096 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-08-23 03:16 - 2013-07-24 22:23 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-08-23 03:16 - 2013-07-24 22:23 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-08-23 03:16 - 2013-07-24 22:23 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-08-23 03:16 - 2013-07-24 22:23 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-08-23 03:16 - 2013-07-24 22:22 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-08-23 03:16 - 2013-07-24 22:22 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-08-23 03:16 - 2013-07-24 22:22 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-08-23 03:15 - 2013-07-24 22:40 - 12334080 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-08-23 03:15 - 2013-07-24 22:30 - 09738752 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-08-23 03:15 - 2013-07-24 22:25 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-08-22 04:21 - 2013-06-15 09:22 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2013-08-22 04:21 - 2013-06-15 07:23 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2013-08-22 04:19 - 2013-07-05 00:53 - 00905664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-08-22 04:17 - 2013-07-17 15:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-08-22 04:16 - 2013-07-10 05:47 - 00783360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2013-08-22 04:15 - 2013-07-09 08:10 - 01205168 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-08-22 04:15 - 2013-07-08 00:55 - 03603904 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-08-22 04:15 - 2013-07-08 00:55 - 03551680 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-08-22 04:13 - 2013-07-08 00:20 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2013-08-22 04:13 - 2013-07-08 00:16 - 00992768 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2013-08-22 04:13 - 2013-07-08 00:16 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2013-08-22 04:13 - 2013-07-08 00:16 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll

==================== One Month Modified Files and Folders =======

2013-09-11 21:12 - 2013-09-11 21:12 - 00000000 ____D C:\FRST
2013-09-11 21:09 - 2013-09-11 21:09 - 01082587 _____ (Farbar) C:\Users\worlwidewandering\Downloads\FRST.exe
2013-09-11 21:09 - 2010-05-18 09:24 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-09-11 20:59 - 2013-07-26 12:01 - 01684469 _____ C:\Windows\WindowsUpdate.log
2013-09-11 20:54 - 2013-09-08 19:46 - 00000644 _____ C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2013-09-11 20:52 - 2010-05-18 09:24 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-09-11 20:51 - 2006-11-02 08:45 - 00003552 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-11 20:51 - 2006-11-02 08:45 - 00003552 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-11 20:50 - 2006-11-02 08:58 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-09-11 20:48 - 2008-01-11 17:07 - 00000012 _____ C:\Windows\bthservsdp.dat
2013-09-11 20:48 - 2006-11-02 08:58 - 00032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2013-09-11 20:44 - 2013-09-11 20:19 - 00000000 ____D C:\AdwCleaner
2013-09-11 20:40 - 2012-06-22 09:11 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-09-11 20:19 - 2013-09-11 20:18 - 00343718 _____ C:\Users\worlwidewandering\Downloads\Setup (3).exe
2013-09-11 20:15 - 2013-09-11 20:15 - 01037278 _____ C:\Users\worlwidewandering\Downloads\AdwCleaner.exe
2013-09-11 19:57 - 2013-09-11 12:12 - 00000000 ____D C:\ProgramData\AVG SafeGuard toolbar
2013-09-11 19:12 - 2013-09-11 19:10 - 00197610 _____ C:\Users\worlwidewandering\Documents\cc_20130911_191039.reg
2013-09-11 19:04 - 2008-09-21 13:49 - 00000000 ___HD C:\ProgramData\Spybot - Search & Destroy
2013-09-11 18:55 - 2011-04-15 10:41 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2013-09-11 18:13 - 2013-09-11 18:13 - 00000848 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-09-11 18:13 - 2013-09-11 18:13 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-09-11 18:13 - 2008-09-21 12:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-09-11 17:18 - 2013-09-11 12:17 - 00000322 _____ C:\Windows\Tasks\UpdaterEX.job
2013-09-11 15:07 - 2013-09-11 12:19 - 00000952 _____ C:\Users\worlwidewandering\Desktop\Continue Firefox Installation.lnk
2013-09-11 12:19 - 2013-09-11 12:19 - 00000000 ____D C:\Users\worlwidewandering\AppData\Local\AVG SafeGuard toolbar
2013-09-11 12:17 - 2013-09-11 12:17 - 22404568 _____ (Mozilla) C:\Users\worlwidewandering\Downloads\Firefox_Setup [1].exe
2013-09-11 12:17 - 2013-09-11 12:17 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\UpdaterEX
2013-09-11 12:15 - 2013-09-11 12:15 - 00281776 _____ (Mozilla) C:\Users\worlwidewandering\Downloads\Firefox Setup Stub 23.0.1.exe
2013-09-11 12:13 - 2013-09-11 12:13 - 00676344 _____ C:\Users\worlwidewandering\Downloads\Firefox_Setup (1).exe
2013-09-11 12:11 - 2013-09-11 12:11 - 00000000 ____D C:\Program Files\AVG SafeGuard toolbar
2013-09-11 12:10 - 2013-09-11 12:13 - 00037664 _____ (AVG Technologies) C:\Windows\system32\Drivers\avgtpx86.sys
2013-09-11 12:02 - 2013-09-11 12:02 - 00676344 _____ C:\Users\worlwidewandering\Downloads\Firefox_Setup.exe
2013-09-11 10:06 - 2008-09-21 13:53 - 00000000 ___HD C:\Users\worlwidewandering\AppData\Roaming\uTorrent
2013-09-10 21:04 - 2013-03-31 00:40 - 00000000 ____D C:\Users\worlwidewandering\Documents\Computer Fix
2013-09-10 21:02 - 2013-09-10 21:00 - 00000000 ____D C:\Users\worlwidewandering\Documents\Clete
2013-09-10 19:40 - 2012-06-22 09:11 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2013-09-10 19:40 - 2011-06-02 20:12 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2013-09-10 18:33 - 2013-09-10 18:33 - 00000000 ____D C:\Windows\ERUNT
2013-09-10 18:15 - 2013-09-10 18:30 - 01029490 _____ (Thisisu) C:\Users\worlwidewandering\Desktop\JRT.exe
2013-09-10 04:54 - 2012-07-02 16:16 - 00000000 ___HD C:\Users\worlwidewandering\Desktop\invoice_7-1
2013-09-10 04:02 - 2008-09-28 22:28 - 00000000 ___HD C:\Users\worlwidewandering\Desktop\tidy4aug00
2013-09-09 09:44 - 2013-09-09 09:39 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\FileZilla
2013-09-09 09:42 - 2013-09-09 09:36 - 00000000 ____D C:\Program Files\FileZilla FTP Client
2013-09-09 09:40 - 2013-09-09 09:40 - 04812567 _____ (Tim Kosse) C:\Users\worlwidewandering\Downloads\FileZilla_3.7.3_win32-setup.exe
2013-09-09 09:32 - 2013-09-09 09:31 - 04521014 _____ C:\Users\worlwidewandering\Downloads\FileZilla_3.5.0_win32-setup.exe
2013-09-09 09:10 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\Resources
2013-09-09 09:08 - 2013-09-09 09:08 - 00589592 _____ C:\Users\worlwidewandering\Downloads\filezilla-setup.exe
2013-09-08 23:24 - 2013-09-08 19:46 - 00000616 _____ C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2013-09-08 23:24 - 2013-09-08 19:46 - 00000446 _____ C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2013-09-08 23:15 - 2011-04-15 10:40 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-09-08 19:45 - 2013-09-08 19:45 - 00001960 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2013-09-08 19:45 - 2013-09-08 19:43 - 00000000 ____D C:\Program Files\Spybot - Search & Destroy 2
2013-09-08 19:27 - 2008-09-22 19:08 - 00000000 ___HD C:\Users\worlwidewandering\AppData\Roaming\Vso
2013-09-08 19:25 - 2006-11-10 17:59 - 00000000 ____D C:\Windows\Panther
2013-09-08 19:22 - 2013-09-08 19:22 - 00000806 _____ C:\Users\Public\Desktop\CCleaner.lnk
2013-09-08 19:22 - 2008-11-19 20:28 - 00000000 ____D C:\Program Files\CCleaner
2013-09-08 19:20 - 2011-06-19 04:03 - 00000000 ___HD C:\ProgramData\Skype Extras
2013-09-08 19:18 - 2013-09-08 19:18 - 00000040 _____ C:\Users\Public\Documents\_rgpl
2013-09-08 19:12 - 2008-01-11 17:27 - 00000000 ____D C:\Program Files\CyberLink
2013-09-08 19:08 - 2013-09-08 19:08 - 00000000 ____D C:\Users\worlwidewandering\AppData\Roaming\InstallShield
2013-09-08 19:00 - 2011-04-12 17:30 - 00000000 ___HD C:\Users\worlwidewandering\AppData\Local\Deployment
2013-09-08 17:45 - 2012-11-05 15:05 - 00000000 ____D C:\Program Files\Common Files\AVSMedia
2013-09-08 17:45 - 2012-11-05 15:05 - 00000000 ____D C:\Program Files\AVS4YOU
2013-09-08 14:05 - 2010-05-18 09:13 - 00001973 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2013-09-08 13:13 - 2006-11-02 06:33 - 00843252 _____ C:\Windows\system32\PerfStringBackup.INI
2013-09-08 12:29 - 2013-09-08 12:27 - 04454952 _____ (Piriform Ltd) C:\Users\worlwidewandering\Downloads\ccsetup405.exe
2013-09-01 00:43 - 2013-09-01 00:43 - 00028919 _____ C:\Users\worlwidewandering\Downloads\[kickass.to]dexter.s08e09.hdtv.x264.asap.ettv.torrent
2013-08-31 21:57 - 2013-08-31 21:57 - 00056170 _____ C:\Users\worlwidewandering\Downloads\[isoHunt] download (8).torrent
2013-08-31 21:44 - 2013-08-31 21:44 - 00056170 _____ C:\Users\worlwidewandering\Downloads\AD6.tmp
2013-08-31 21:43 - 2013-08-31 21:43 - 00056170 _____ C:\Users\worlwidewandering\Downloads\[isoHunt] download (7).torrent
2013-08-23 23:49 - 2013-08-23 23:49 - 00015422 _____ C:\Users\worlwidewandering\Downloads\Zombie_Massacre_(2012).XViD.HQuality.torrent
2013-08-23 12:33 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\Microsoft.NET
2013-08-23 05:06 - 2006-11-02 07:18 - 00000000 ____D C:\Windows\rescache
2013-08-23 04:20 - 2013-08-23 04:04 - 00000000 ____D C:\Windows\system32\MRT
2013-08-23 04:03 - 2006-11-02 06:24 - 75778376 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2013-08-23 03:54 - 2008-09-21 15:28 - 00000000 ____D C:\ProgramData\Microsoft Help

Files to move or delete:
====================
C:\ProgramData\PKP_DLbx.DAT
C:\ProgramData\PKP_DLck.DAT
C:\Users\WORLWI~1\AppData\Local\Temp\Quarantine.exe

==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-09-11 21:00

==================== End Of Log ============================






----------------
- Addition.txt -
----------------

Additional scan result of Farbar Recovery Scan Tool (x86) Version: 09-09-2013 02
Ran by worlwidewandering at 2013-09-11 21:22:44
Running from C:\Users\worlwidewandering\Downloads
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

Update for Microsoft Office 2007 (KB2508958)
Acrobat.com (Version: 0.0.0)
Acrobat.com (Version: 1.1.377)
Adobe AIR (Version: 2.6.0.19140)
Adobe Anchor Service CS3 (Version: 1.0)
Adobe Asset Services CS3 (Version: 3)
Adobe Bridge CS3 (Version: 2)
Adobe Bridge Start Meeting (Version: 1.0)
Adobe Camera Raw 4.0 (Version: 4.0)
Adobe CMaps (Version: 1.0)
Adobe Color - Photoshop Specific (Version: 1.0)
Adobe Color Common Settings (Version: 1.0)
Adobe Color EU Extra Settings (Version: 1.0)
Adobe Color JA Extra Settings (Version: 1.0)
Adobe Color NA Recommended Settings (Version: 1.0)
Adobe Default Language CS3 (Version: 1.0)
Adobe Device Central CS3 (Version: 1.0)
Adobe Dreamweaver CS3 (Version: 9)
Adobe Dreamweaver CS3 (Version: 9.0)
Adobe ExtendScript Toolkit 2 (Version: 2.0.2)
Adobe Extension Manager CS3 (Version: 1.8)
Adobe Flash CS3 (Version: 9.0)
Adobe Flash CS3 Professional (Version: 9.0.0)
Adobe Flash Player 11 ActiveX (Version: 11.8.800.168)
Adobe Flash Player 11 Plugin (Version: 11.8.800.168)
Adobe Flash Video Encoder (Version: 2.0)
Adobe Fonts All (Version: 1.0)
Adobe Help Viewer CS3 (Version: 1)
Adobe Illustrator CS3 (Version: 13.0)
Adobe Linguistics CS3 (Version: 3.0.0)
Adobe PDF Library Files (Version: 8.0)
Adobe Photoshop CS3 (Version: 10)
Adobe Photoshop CS3 (Version: 10.0)
Adobe Reader X (10.1.8) (Version: 10.1.8)
Adobe Setup (Version: 1.0)
Adobe Stock Photos CS3 (Version: 1.5)
Adobe Type Support (Version: 1.0)
Adobe Update Manager CS3 (Version: 5.1.0)
Adobe Version Cue CS3 Client (Version: 3)
Adobe WinSoft Linguistics Plugin (Version: 1.0)
Adobe XMP Panels CS3 (Version: 1.0)
Advanced Audio FX Engine
Advanced Video FX Engine
ATI Catalyst Control Center (Version: 1.007.0721.2246)
ATI PCI Express (3GIO) Filter Driver (Version: 1.00.0000.)
avast! Free Antivirus (Version: 7.0.1466.0)
AVG SafeGuard toolbar (Version: 15.4.0.5)
Browser Address Error Redirector (Version: 1.00.0000)
Capture NX 2 (Version: 2.0.0)
Catalyst Control Center - Branding (Version: 1.00.0000)
Catalyst Control Center Core Implementation (Version: 2007.0721.2247.38911)
Catalyst Control Center Graphics Full Existing (Version: 2007.0721.2247.38911)
Catalyst Control Center Graphics Full New (Version: 2007.0721.2247.38911)
Catalyst Control Center Graphics Light (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Chinese Standard (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Chinese Traditional (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Danish (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Dutch (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Finnish (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization French (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization German (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Italian (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Japanese (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Korean (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Norwegian (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Portuguese (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Russian (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Spanish (Version: 2007.0721.2247.38911)
Catalyst Control Center Localization Swedish (Version: 2007.0721.2247.38911)
CCC Help Chinese Standard (Version: 2007.0721.2246.38911)
CCC Help Chinese Traditional (Version: 2007.0721.2246.38911)
CCC Help Danish (Version: 2007.0721.2246.38911)
CCC Help Dutch (Version: 2007.0721.2246.38911)
CCC Help English (Version: 2007.0721.2246.38911)
CCC Help Finnish (Version: 2007.0721.2246.38911)
CCC Help French (Version: 2007.0721.2246.38911)
CCC Help German (Version: 2007.0721.2246.38911)
CCC Help Italian (Version: 2007.0721.2246.38911)
CCC Help Japanese (Version: 2007.0721.2246.38911)
CCC Help Korean (Version: 2007.0721.2246.38911)
CCC Help Norwegian (Version: 2007.0721.2246.38911)
CCC Help Portuguese (Version: 2007.0721.2246.38911)
CCC Help Russian (Version: 2007.0721.2246.38911)
CCC Help Spanish (Version: 2007.0721.2246.38911)
CCC Help Swedish (Version: 2007.0721.2246.38911)
ccc-core-static (Version: 2007.0721.2247.38911)
ccc-utility (Version: 2007.0721.2247.38911)
CCleaner (Version: 4.05)
Cisco EAP-FAST Module (Version: 2.0.26)
Cisco LEAP Module (Version: 1.0.11)
Cisco PEAP Module (Version: 1.0.12)
Conexant HDA D330 MDC V.92 Modem
Content Spinner (Version: 1.1.4)
ConvertXtoDVD 3.2.0.52 (Version: 3.2.0.52)
Crystal Reports Basic for Visual Studio 2008 (Version: 10.5.0.0)
Define Ext (HKCU Version: 8)
Dell DataSafe Online (Version: 1.1.0019)
Dell Getting Started Guide (Version: 1.00.0000)
Dell Support Center (Support Software) (Version: 2.2.09085)
Dell Touchpad (Version: 9.1.18.6)
Dell Webcam Center
Dell Webcam Manager
Dell Wireless WLAN Card (Version: 4.170.25.12)
Digital Line Detect (Version: 1.21)
FileZilla Client 3.7.3 (Version: 3.7.3)
getPlus® for Adobe (Version: 1.5.2.29)
Google AdWords Editor (Version: 7.6.1)
Google Chrome (Version: 29.0.1547.66)
Google Desktop (Version: -)
Google Toolbar for Internet Explorer (Version: 1.0.0)
Google Toolbar for Internet Explorer (Version: 7.3.2710.138)
Google Update Helper (Version: 1.3.21.153)
Internet Service Offers Launcher (Version: 1.00.0000)
Java™ SE Runtime Environment 6 (Version: 1.6.0.0)
KeywordCorral (Version: 1.0.9)
Laptop Integrated Webcam Driver (1.03.02.0719)
Live! Cam Avatar Creator (Version: 4.5.3104.1)
Live! Cam Avatar v1.0 (Version: 1.0)
Malwarebytes' Anti-Malware
Market Samurai (Version: 0.87.75)
MediaDirect (Version: 4.7)
Microsoft .NET Compact Framework 2.0 SP2 (Version: 2.0.7045)
Microsoft .NET Compact Framework 3.5 (Version: 3.5.7283)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Device Emulator version 3.0 - ENU (Version: 9.0.21022)
Microsoft Document Explorer 2008
Microsoft Document Explorer 2008 (Version: 9.0.21022)
Microsoft Office 2007 Service Pack 3 (SP3)
Microsoft Office Access MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Access Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Enterprise 2007 (Version: 12.0.6612.1000)
Microsoft Office Excel MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Groove MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Groove Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office InfoPath MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Outlook MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Portuguese (Brazil)) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (Version: 12.0.4518.1014)
Microsoft Office Proofing (Portuguese (Brazil)) 2007 (Version: 12.0.4518.1019)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
Microsoft Office Publisher MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (Portuguese (Brazil)) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office SharePoint Designer 2007 Service Pack 3 (SP3)
Microsoft Office Visio 2007 Service Pack 3 (SP3)
Microsoft Office Visio Language Pack 2007 - English (Version: 12.0.6612.1000)
Microsoft Office Visio MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio MUI (Portuguese (Brazil)) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visio Professional 2007 (Version: 12.0.6612.1000)
Microsoft Office VisMUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Visual Web Developer 2007 (Version: 12.0.4518.1066)
Microsoft Office Visual Web Developer MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office X MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20513.0)
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) (Version: 9.4.5000.00)
Microsoft SQL Server 2005 Tools Express Edition (Version: 9.4.5000.00)
Microsoft SQL Server Compact 3.5 Design Tools ENU (Version: 3.5.5386.0)
Microsoft SQL Server Compact 3.5 ENU (Version: 3.5.5386.0)
Microsoft SQL Server Compact 3.5 for Devices ENU (Version: 3.5.5386.0)
Microsoft SQL Server Database Publishing Wizard 1.2 (Version: 1.2.0.0)
Microsoft SQL Server Native Client (Version: 9.00.5000.00)
Microsoft SQL Server Setup Support Files (English) (Version: 9.00.5000.00)
Microsoft SQL Server VSS Writer (Version: 9.00.5000.00)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual Studio 2005 Tools for Office Runtime (Version: 8.0.60940.0)
Microsoft Visual Studio 2008 Professional Edition - ENU
Microsoft Visual Studio 2008 Professional Edition - ENU (Version: 9.0.21022)
Microsoft Visual Studio Web Authoring Component (Version: 12.0.4518.1066)
Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools (Version: 3.5.21022)
Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries (Version: 6.1.5288.17011)
Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense (Version: 6.1.5288.17011)
Microsoft Windows SDK for Visual Studio 2008 Tools (Version: 6.1.5288.17011)
Microsoft Windows SDK for Visual Studio 2008 Win32 Tools (Version: 6.1.5288.17011)
Microsoft Works (Version: 08.05.0818)
Mobile Partner (Version: 11.030.01.01.340)
Modem Diagnostic Tool (Version: 1.0.20.0)
Mozilla Firefox 23.0.1 (x86 en-US) (Version: 23.0.1)
Mozilla Maintenance Service (Version: 23.0.1)
MSXML 4.0 SP2 (KB936181) (Version: 4.20.9848.0)
MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0)
Music, Photos & Videos Launcher (Version: 1.00.0000)
NetWaiting (Version: 2.5.44)
Nikon Message Center (Version: 0.92.000)
PDF Settings (Version: 1.0)
Photomatix Pro version 3.1Beta11 (Version: 3.1Beta11)
Picture Control Utility (Version: 1.1.0)
Product Documentation Launcher (Version: 1.00.0000)
QuickSet (Version: 8.2.14)
QuickTime (Version: 7.0.4)
RealDownloader (Version: 1.3.2)
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0)
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0)
RealPlayer (Version: 16.0.2)
Roxio Creator Audio (Version: 3.3.0)
Roxio Creator BDAV Plugin (Version: 3.3.0)
Roxio Creator Copy (Version: 3.3.0)
Roxio Creator Data (Version: 3.3.0)
Roxio Creator DE (Version: 3.3.0)
Roxio Creator Tools (Version: 3.3.0)
Roxio Express Labeler (Version: 2.1.0)
Roxio MyDVD DE (Version: 9.0.116)
Roxio Update Manager (Version: 3.0.0)
Skins (Version: 2007.0721.2247.38911)
Skype Toolbars (Version: 1.0.4051)
Skype™ 6.0 (Version: 6.0.126)
Sonic Activation Module (Version: 1.0)
Spybot - Search & Destroy (Version: 1.6.2)
Spybot - Search & Destroy (Version: 2.1.21)
The Rosetta Stone
TheBestSpinner3
Traffic Robot 0.0.8.3 (Version: 0.0.8.3)
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition
Update for Microsoft Office Outlook 2007 (KB2768023) 32-Bit Edition
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2817642) 32-Bit Edition
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Visio 2007 Help (KB963666)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Microsoft Visual Studio 2008 Professional Edition - ENU (KB972221) (Version: 1)
User's Guides
VC Runtimes MSI (Version: 9.0.21022)
Visual Studio 2005 Tools for Office Second Edition Runtime
Visual Studio Tools for the Office system 3.0 Runtime
Visual Studio Tools for the Office system 3.0 Runtime (Version: 9.0.21022)
VLC media player 1.1.9 (Version: 1.1.9)
Web 2.0 Mayhem 1.0.6.5 (Version: 1.0.6.5)
Web Page Analyzer (Version: 3.02)
Windows 7 Upgrade Advisor (Version: 2.0.5000.0)
Windows Mobile 5.0 SDK R2 for Pocket PC (Version: 5.00.1700.5.14343.06)
Windows Mobile 5.0 SDK R2 for Smartphone (Version: 5.00.1700.5.14343.06)
Windows Mobile Device Center (Version: 6.1.6965.0)
Windows Mobile Device Center Driver Update (Version: 6.1.6965.0)
Windows Movie Maker 2.6 (Version: 2.6.4040.0)
WinRAR
WinZip (Version: 9.0 SR-1 (6224))
XAMPP 1.6.8
Xvid Video Codec (Version: 1.3.2)
Yahoo! Music Jukebox (Version: 2.2.2.058)

==================== Restore Points =========================


==================== Hosts content: ==========================

2006-11-02 06:23 - 2012-07-31 21:14 - 00444955 ____R C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.100888290cs.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.10sek.com
127.0.0.1 10sek.com
127.0.0.1 www.123topsearch.com
127.0.0.1 123topsearch.com
127.0.0.1 www.132.com
127.0.0.1 132.com
127.0.0.1 www.136136.net
127.0.0.1 136136.net
127.0.0.1 www.163ns.com
127.0.0.1 163ns.com
127.0.0.1 171203.com
127.0.0.1 17-plus.com

There are 1000 more lines.


==================== Scheduled Tasks (whitelisted) =============

Task: {0C67D682-0A61-458D-8BAA-570965F672A6} - System32\Tasks\Scan the system (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search &amp; Destroy 2\SDScan.exe
Task: {18DFD9FC-082E-4E9B-8285-5F21D2B4EDAE} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {26337B0D-0252-4528-ACBB-54CF81385E02} - System32\Tasks\Check for updates (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search &amp; Destroy 2\SDUpdate.exe
Task: {29822FB1-64C7-4977-8292-5322D0797CA2} - System32\Tasks\{A90964CF-312D-48A6-93C1-F7D8AEDF2022} => C:\Program Files\Skype\Phone\Skype.exe [2012-11-09] (Skype Technologies S.A.)
Task: {3D844A1D-6445-4C27-A9D4-D24061EC55D0} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-519370656-3981458553-338625627-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {3F66FB96-B0AA-4CA1-9F1C-8567D733CB98} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-18] (Google Inc.)
Task: {4FC88214-8490-41F4-9305-DD883EB1AAA7} - System32\Tasks\Microsoft\Windows\Tcpip\WSHReset => C:\Windows\system32\schtasks.exe [2008-01-19] (Microsoft Corporation)
Task: {5916F864-469C-4391-8604-E4EA141A2699} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-05] ()
Task: {60460F69-EDDF-41DB-A8C4-992BBE6D1568} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\OptinNotification => C:\Windows\System32\wsqmcons.exe [2008-01-19] (Microsoft Corporation)
Task: {64703487-C4A8-4737-BD27-018572484DC4} - System32\Tasks\Microsoft\Windows\Defrag\ManualDefrag => C:\Windows\system32\defrag.exe [2008-01-19] (Microsoft Corp.)
Task: {6EA08291-FDA0-4D37-A796-C8BD7A1FAD90} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-10] (Adobe Systems Incorporated)
Task: {7D2A46B1-5C92-4ACF-A1D5-92B27EA22570} - System32\Tasks\avast! Emergency Update => C:\Program Files\Alwil Software\Avast5\AvastEmUpdate.exe [2012-08-21] (AVAST Software)
Task: {89F17246-9C84-47E8-B265-2203B3265368} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {8B0E6FAB-F43A-4988-AF0A-A21646C212F0} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {8CB2B5AA-604F-4151-A81E-73581C0E8A42} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2008-01-19] (Microsoft Corporation)
Task: {9ED703A9-5FFD-40D5-895A-4385EE1509DE} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-19] (Microsoft Corporation)
Task: {AA9C9A0D-9D98-49F6-86B9-2237F69ACB71} - System32\Tasks\Refresh immunization (Spybot - Search & Destroy) => C:\Program Files\Spybot - Search &amp; Destroy 2\SDImmunize.exe
Task: {B0A7122C-808A-43D9-8AE5-3DE341D4F060} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-519370656-3981458553-338625627-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {CDF6AEB8-FF76-49F0-9EAC-0640F45F7118} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2010-05-18] (Google Inc.)
Task: {DDBDF435-6A3B-420A-A0AE-D6B637A9A7A4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-08-21] (Piriform Ltd)
Task: {DDE67680-057A-49FE-86E3-F75D62B2CEE7} - System32\Tasks\UpdaterEX => C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE
Task: {FAA0EDC9-46F4-4EC2-9FC8-9528ED4CE1CF} - System32\Tasks\TidyNetwork Update => C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com\tidy2update.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE

==================== Loaded Modules (whitelisted) =============

2013-09-08 19:43 - 2013-05-16 10:55 - 00113496 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-08 19:43 - 2013-05-16 10:55 - 03643800 _____ (Project JEDI) C:\Program Files\Spybot - Search & Destroy 2\Jcl150.bpl
2013-09-08 19:43 - 2013-05-16 10:55 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2004-12-17 10:00 - 2004-12-17 10:00 - 00005120 _____ (WinZip Computing, Inc.) C:\Program Files\WinZip\WZSHLSTB.DLL
2007-10-19 16:38 - 2007-01-17 12:36 - 00129024 _____ () C:\Program Files\WinRAR\rarext.dll
2008-01-12 00:45 - 2007-08-14 04:40 - 00159744 _____ () C:\Windows\system32\atitmmxx.dll
2008-01-12 00:45 - 2007-04-27 19:42 - 00163840 _____ (Synaptics, Inc.) C:\Windows\system32\SynCOM.dll
2008-01-12 00:45 - 2007-04-27 19:49 - 00143360 _____ (Synaptics, Inc.) C:\Windows\system32\SynTPAPI.dll
2008-01-11 17:20 - 2007-12-12 02:01 - 00054784 _____ () C:\Windows\System32\bcmwlrmt.dll
2008-01-11 16:51 - 2007-04-10 22:02 - 01601536 _____ (SigmaTel, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\STLang.dll
2008-01-12 00:45 - 2007-09-07 14:23 - 00299520 _____ (IDT, Inc.) C:\Windows\system32\stapi32.dll
2008-10-24 14:07 - 2008-10-24 14:07 - 00073728 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtmessage.dll
2008-08-13 18:32 - 2008-08-13 18:32 - 00881952 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsched.dll
2008-08-13 18:32 - 2008-08-13 18:32 - 00382240 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtevent.dll
2008-08-13 18:32 - 2008-08-13 18:32 - 00398624 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtfod.dll
2008-08-13 18:32 - 2008-08-13 18:32 - 01069056 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\LIBEAY32.dll
2009-05-21 11:55 - 2009-05-21 11:55 - 00881960 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsync.dll
2009-05-21 11:55 - 2009-05-21 11:55 - 00386344 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtui.dll
2008-10-24 14:07 - 2008-10-24 14:07 - 00036864 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.SupportMessage.dll
2008-10-24 14:07 - 2008-10-24 14:07 - 00020480 ____H (SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\SupportSoft.Agent.Sprocket.dll
2013-08-07 15:25 - 2013-08-07 15:25 - 00093696 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2013-09-08 14:00 - 2013-09-02 16:35 - 04053456 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\pdf.dll
2013-09-08 14:01 - 2013-09-02 16:35 - 00410576 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\ppGoogleNaClPluginChrome.dll
2013-09-08 13:59 - 2013-09-02 16:35 - 01604560 _____ () C:\Program Files\Google\Chrome\Application\29.0.1547.66\ffmpegsumo.dll
2013-09-10 18:40 - 2013-09-10 18:40 - 16242568 ____R (Adobe Systems, Inc.) C:\Windows\system32\Macromed\Flash\Flash32_11_8_800_168.ocx

==================== Alternate Data Streams (whitelisted) ==========


==================== Faulty Device Manager Devices =============

Name: Microsoft Tun Miniport Adapter #2
Description: Microsoft Tun Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunmp
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (09/11/2013 08:52:37 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (09/11/2013 06:56:54 PM) (Source: Application Error) (User: )
Description: Faulting application mbam.exe, version 1.75.0.1, time stamp 0x511f8eb2, faulting module OLEAUT32.dll, version 6.0.6002.18508, time stamp 0x4e5674e4, exception code 0xc0000005, fault offset 0x0001412b,
process id 0xb24, application start time 0xmbam.exe0.

Error: (09/11/2013 06:29:29 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (09/11/2013 06:29:28 PM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (09/11/2013 03:05:02 PM) (Source: Application Hang) (User: )
Description: The program Firefox_Setup (1).exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 1674
Start Time: 01ceaf0a8e1e578c
Termination Time: 67

Error: (09/11/2013 11:32:02 AM) (Source: Application Error) (User: )
Description: Faulting application mbam.exe, version 1.75.0.1, time stamp 0x511f8eb2, faulting module OLEAUT32.dll, version 6.0.6002.18508, time stamp 0x4e5674e4, exception code 0xc0000005, fault offset 0x0001412b,
process id 0x98c, application start time 0xmbam.exe0.

Error: (09/11/2013 09:19:51 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (09/11/2013 07:16:43 AM) (Source: SideBySide) (User: )
Description: Activation context generation failed for "rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0"1".
Dependent Assembly rpshellextension.1.0,language="&#x2a;",type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.


System errors:
=============
Error: (09/11/2013 08:57:11 PM) (Source: disk) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (09/11/2013 08:57:11 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:57:11 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:54:31 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:54:29 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:54:25 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:54:19 PM) (Source: Service Control Manager) (User: )
Description: BCM42RLY%%2

Error: (09/11/2013 08:53:41 PM) (Source: Service Control Manager) (User: )
Description: vToolbarUpdater15.4.0%%2

Error: (09/11/2013 08:53:41 PM) (Source: Service Control Manager) (User: )
Description: Spybot-S&D 2 Scanner Service%%1053

Error: (09/11/2013 08:53:41 PM) (Source: Service Control Manager) (User: )
Description: 30000Spybot-S&D 2 Scanner Service


Microsoft Office Sessions:
=========================
Error: (07/08/2011 11:32:18 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 64 seconds with 0 seconds of active time. This session ended with a crash.

Error: (07/08/2011 11:31:00 AM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 120 seconds with 0 seconds of active time. This session ended with a crash.

Error: (04/11/2011 07:00:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 563 seconds with 60 seconds of active time. This session ended with a crash.

Error: (04/11/2011 06:51:13 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 490 seconds with 60 seconds of active time. This session ended with a crash.

Error: (04/11/2011 06:42:52 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 552 seconds with 240 seconds of active time. This session ended with a crash.

Error: (04/11/2011 06:16:07 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 483 seconds with 60 seconds of active time. This session ended with a crash.

Error: (04/11/2011 05:43:45 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 37 seconds with 0 seconds of active time. This session ended with a crash.

Error: (04/11/2011 05:42:04 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 53 seconds with 0 seconds of active time. This session ended with a crash.

Error: (04/11/2011 05:36:46 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 256 seconds with 120 seconds of active time. This session ended with a crash.

Error: (04/11/2011 04:33:04 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1066. This session lasted 39 seconds with 0 seconds of active time. This session ended with a crash.


CodeIntegrity Errors:
===================================
Date: 2013-06-11 19:01:47.692
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\atiumdag.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-06-11 19:01:39.131
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\atiumdag.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-06-11 18:58:32.520
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\atiumdag.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-06-11 18:58:21.245
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\atiumdag.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-28 18:28:31.424
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-28 18:28:30.289
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-18 15:11:56.549
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-18 15:11:55.534
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-18 15:09:19.734
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.

Date: 2013-04-18 15:09:18.756
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Yahoo!\Yahoo! Music Jukebox\DFXDMO.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Percentage of memory in use: 36%
Total physical RAM: 3453.09 MB
Available physical RAM: 2196.13 MB
Total Pagefile: 7125.9 MB
Available Pagefile: 5860.66 MB
Total Virtual: 2047.88 MB
Available Virtual: 1906 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:99.21 GB) (Free:15.16 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (RECOVERY) (Fixed) (Total:10 GB) (Free:6.04 GB) NTFS
Drive g: (KINGSTON) (Removable) (Total:29.06 GB) (Free:28.82 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 112 GB) (Disk ID: E8000000)
Partition 1: (Not Active) - (Size=78 MB) - (Type=DE)
Partition 2: (Not Active) - (Size=10 GB) - (Type=07 NTFS)
Partition 3: (Active) - (Size=99 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=3 GB) - (Type=OF Extended)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 29 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=29 GB) - (Type=0C)

==================== End Of Log ============================
  • 0

#13
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
Ok. This fix should get rid of Conduit (let me know). Please download the attached file to your desktop and also move FRST.exe to your desktop. Then run FRST again and click "Fix." Please post the fixlog.txt that results.

Can you download now?

Let's see if we can fix Firefox. Please uninstall it from the Control Panel and be sure to check the box that says remove all user profiles and settings. Then please also delete these folders, if they still exist:

C:\Users\worlwidewandering\AppData\Roaming\Mozilla\Firefox
C:\Program Files\Mozilla Firefox

Now, see if you can install a fresh download of Firefox.

For the start menu, let's try the simple way first. Right-click on the Start Button and select "Properties." Then under the "Start Menu" tab, select "Customize." Make sure the settings in there are as you want them.

Attached Files


  • 0

#14
worldwidewandering

worldwidewandering

    Member

  • Topic Starter
  • Member
  • PipPip
  • 22 posts
I think I'm rid of conduit. I was able to uninstall then re-install Firefow. I also customized the start menu and now have items in the right side of the start menu box. There are no programs in the left side but I may just need to modify the customizations a bit, and also run programs so they start to show up in that left side. There are usually a couple items at the top left separated from the bottom items by a spacer, programs like Outlook and Firefox, etc. I guess maybe those must also be set withing the customizations. Anyway, here are the contents of the fixlog.txt file:

[Edit] - It looks from the fixlog like conduit is still there, or is this just showing up before I ran the fix?


--------------
- fixlog.txt -
--------------


Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 09-09-2013 02
Ran by worlwidewandering at 2013-09-12 10:18:59 Run:1
Running from C:\Users\worlwidewandering\Desktop
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
CHR DefaultSearchURL: (Conduit) - http://search.condui...=CT3309350&UM=2
CHR DefaultSuggestURL: (Conduit) - http://suggest.searc...0295029404&UM=2
CHR HKLM\...\Chrome\Extension: [iigplimlmgilpobjilfbfeilnpiigpgl] - C:\Users\worlwidewandering\AppData\Local\CRE\iigplimlmgilpobjilfbfeilnpiigpgl.crx
CHR HKLM\...\Chrome\Extension: [mmlkabjddkpgkgfhdhpimhcbonapngoh] - C:\Users\worlwidewandering\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx
CHR HKLM\...\Chrome\Extension: [odpccdgkmiicgocepijnaeihjnjnomca] - C:\Program Files\LinkSwift\odpccdgkmiicgocepijnaeihjnjnomca.crx
CHR HKLM\...\Chrome\Extension: [pacgpkgadgmibnhpdidcnfafllnmeomc] - C:\Users\worlwidewandering\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx
CHR HKLM\...\Chrome\Extension: [ppppebhepbpibjjecehmkoipieddjeff] - C:\Users\worlwidewandering\AppData\Local\CRE\ppppebhepbpibjjecehmkoipieddjeff.crx
C:\Users\worlwidewandering\AppData\Local\CRE
S2 vToolbarUpdater15.4.0; C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.4.0\ToolbarUpdater.exe [x]
C:\Users\WORLWI~1\AppData\Local\Temp\Quarantine.exe
Task: {DDE67680-057A-49FE-86E3-F75D62B2CEE7} - System32\Tasks\UpdaterEX => C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE
Task: {FAA0EDC9-46F4-4EC2-9FC8-9528ED4CE1CF} - System32\Tasks\TidyNetwork Update => C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com\tidy2update.exe
C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1
C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com
Task: C:\Windows\Tasks\UpdaterEX.job => C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE

*****************

CHR DefaultSearchURL: (Conduit) - http://search.condui...=CT3309350&UM=2 ==> The Chrome "Settings" can be used to fix the entry.
CHR DefaultSuggestURL: (Conduit) - http://suggest.searc...0295029404&UM=2 ==> The Chrome "Settings" can be used to fix the entry.
HKLM\SOFTWARE\Google\Chrome\Extensions\iigplimlmgilpobjilfbfeilnpiigpgl => Key deleted successfully.
"C:\Users\worlwidewandering\AppData\Local\CRE\iigplimlmgilpobjilfbfeilnpiigpgl.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\mmlkabjddkpgkgfhdhpimhcbonapngoh => Key deleted successfully.
"C:\Users\worlwidewandering\AppData\Local\CRE\mmlkabjddkpgkgfhdhpimhcbonapngoh.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\odpccdgkmiicgocepijnaeihjnjnomca => Key deleted successfully.
"C:\Program Files\LinkSwift\odpccdgkmiicgocepijnaeihjnjnomca.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\pacgpkgadgmibnhpdidcnfafllnmeomc => Key deleted successfully.
"C:\Users\worlwidewandering\AppData\Local\CRE\pacgpkgadgmibnhpdidcnfafllnmeomc.crx" => File/Directory not found.
HKLM\SOFTWARE\Google\Chrome\Extensions\ppppebhepbpibjjecehmkoipieddjeff => Key deleted successfully.
"C:\Users\worlwidewandering\AppData\Local\CRE\ppppebhepbpibjjecehmkoipieddjeff.crx" => File/Directory not found.
"C:\Users\worlwidewandering\AppData\Local\CRE" => File/Directory not found.
vToolbarUpdater15.4.0 => Service deleted successfully.
C:\Users\WORLWI~1\AppData\Local\Temp\Quarantine.exe => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DDE67680-057A-49FE-86E3-F75D62B2CEE7} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DDE67680-057A-49FE-86E3-F75D62B2CEE7} => Key deleted successfully.
C:\Windows\System32\Tasks\UpdaterEX => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\UpdaterEX => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FAA0EDC9-46F4-4EC2-9FC8-9528ED4CE1CF} => Key deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FAA0EDC9-46F4-4EC2-9FC8-9528ED4CE1CF} => Key deleted successfully.
C:\Windows\System32\Tasks\TidyNetwork Update => Moved successfully.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\TidyNetwork Update => Key deleted successfully.

"C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1" directory move:

C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UpdateProc\config.dat => Moved successfully.
C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1\UpdateProc\prod.dat => Moved successfully.
Could not move "C:\Users\WORLWI~1\AppData\Roaming\UPDATE~1" directory. => Scheduled to move on reboot.

"C:\Users\worlwidewandering\AppData\Local\TidyNetwork.com" => File/Directory not found.
C:\Windows\Tasks\UpdaterEX.job => Moved successfully.

Edited by worldwidewandering, 12 September 2013 - 09:38 AM.

  • 0

#15
Buddierdl

Buddierdl

    Trusted Helper

  • Malware Removal
  • 2,524 posts
It looks like the fix didn't quite complete. Did you let the computer reboot?

We need to go manual to get rid of the rest of conduit. Please access the settings by clicking on the button with 3 bars in the top right-hand corner of the Chrome window. You should see a setting for search providers. Please click "Manage Search Providers" and delete the conduit line (an "X" should appear at the right of the line when you hover over it.) It should be gone now.

Does Firefox work now?

To pin items in your start menu, just right click on the icon for the program and select "Pin to start menu." You can do this for IE, Outlook, etc. The other list should hopefully be populated as you run programs.

Let's also run this: UnHide. It may help as well. Just download and double-click to run. Post the log if it produces one.

Also, let's clean install MBAM to see if we can fix it. First uninstall it from the Control Panel (if possible), then follow the directions below:

  • Free version
  • Please download mbam-clean.exe from here to your desktop and save it.
  • Please close all open applications and temporarily shutdown your antivirus to avoid any conflicts when running the tool.
  • Locate the file mbam-clean.exe and double-click to run it and follow the onscreen prompts.
  • It will ask to restart your computer, please allow it to do so very important
  • After the computer restarts, ensure that your antivirus is enabled and download the latest version of Malwarebytes Anti-Malwarefrom here and save it to your desktop.
  • Now close all open applications including your browser and again temporarily disable your antivirus as before and launch the Malwarebytes installer you just downloaded.
  • If you have never tried the PRO version Trial and wish to do so then leave the Trial checkmark enabled otherwise please make sure to uncheck the Trial checkmark near the end of the installation if you do not wish to try the PRO version features for 14 days.
  • Please make sure you check for updates at the end of the installation as well.
  • Make sure you have re-enabled your Anti-Virus/Internet-Security applications

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP