OTL logfile created on: 8/23/2011 10:50:40 PM - Run 1
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Users\easyhome\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.75 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 52.07% Memory free
7.50 Gb Paging File | 5.67 Gb Available in Paging File | 75.64% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 911.88 Gb Total Space | 755.53 Gb Free Space | 82.85% Space Free | Partition Type: NTFS
Computer Name: EASYHOME-PC | User Name: easyhome | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/08/23 22:48:25 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\easyhome\Desktop\OTL.exe
PRC - [2011/08/16 21:54:40 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/11/09 23:50:50 | 000,613,992 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/09/27 19:49:38 | 000,124,136 | ---- | M] (CyberLink Corp.) -- C:\Program Files (x86)\Gateway\Gateway TouchPortal\Touch Movie\TouchMovieService.exe
PRC - [2010/09/21 17:22:20 | 000,309,104 | ---- | M] (Pelmorex Media Inc.) -- C:\Users\easyhome\AppData\Local\TheWeatherNetwork\WeatherEye\WeatherEye.exe
PRC - [2010/09/09 17:58:12 | 000,155,752 | ---- | M] (Acer Corp.) -- C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe
PRC - [2010/09/09 17:50:38 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
PRC - [2010/01/08 10:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
PRC - [2009/07/13 21:55:16 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE
PRC - [2009/07/07 06:35:48 | 000,438,376 | ---- | M] (Acer Corp.) -- C:\Program Files (x86)\Gateway\Gateway TouchPortal\TouchPortalLauncher.exe
PRC - [2009/07/07 06:32:42 | 001,346,048 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\THX TruStudio PRO\THXAudioCP\THXAudio.exe
========== Modules (No Company Name) ==========
MOD - [2011/08/18 20:28:50 | 003,356,672 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\7ea26f73b1db8ffa4afa9c96a1cbe9e5\WindowsBase.ni.dll
MOD - [2011/08/18 14:34:37 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\23bc3936180ff789f44259a211dfc7fc\mscorlib.ni.dll
MOD - [2011/08/16 21:54:40 | 001,846,232 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/08/09 22:12:37 | 006,277,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/07/31 15:51:34 | 000,077,312 | ---- | M] () -- C:\Users\easyhome\AppData\Roaming\Mozilla\Firefox\Profiles\jb57vp1e.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}\components\RadioWMPCoreGecko6.dll
MOD - [2011/05/04 16:34:29 | 003,178,496 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
MOD - [2011/03/29 16:31:57 | 005,025,792 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
MOD - [2010/11/09 23:51:28 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyHook.dll
MOD - [2010/11/09 23:50:50 | 000,613,992 | ---- | M] () -- C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/03/02 17:24:26 | 005,279,744 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
MOD - [2010/03/02 17:24:26 | 004,214,784 | ---- | M] () -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
MOD - [2009/07/13 22:35:46 | 000,098,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\UIAutomationTypes\3.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll
MOD - [2009/07/13 22:35:46 | 000,040,960 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\UIAutomationProvider\3.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll
MOD - [2009/07/13 22:35:42 | 000,196,608 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\PresentationFramework.Aero\3.0.0.0__31bf3856ad364e35\PresentationFramework.Aero.dll
MOD - [2009/07/13 18:46:40 | 002,048,000 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.Xml.dll
MOD - [2009/07/13 18:46:36 | 000,303,104 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2009/07/13 18:46:34 | 000,626,688 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
MOD - [2009/07/13 18:46:30 | 000,425,984 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.dll
MOD - [2009/07/13 18:46:22 | 000,610,304 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
MOD - [2009/07/13 18:46:14 | 000,010,752 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\Accessibility\2.0.0.0__b03f5f7f11d50a3a\Accessibility.dll
MOD - [2009/07/07 06:36:08 | 000,014,368 | ---- | M] () -- C:\Program Files (x86)\Gateway\Gateway TouchPortal\LanguageDll\TouchPortalLauncher-en.dll
MOD - [2009/07/07 06:32:48 | 000,181,248 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
MOD - [2003/02/02 20:06:02 | 000,153,088 | ---- | M] () -- C:\Windows\SysWOW64\UNRAR3.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/08/09 09:01:25 | 008,205,576 | RH-- | M] () [Auto | Running] -- C:\Windows\SysNative\servicescache.exe -- (systemCheck)
SRV:64bit: - [2011/08/09 08:59:24 | 000,199,944 | -HS- | M] () [Unknown | Running] -- C:\Windows\SysNative\CNGKeyLock.exe -- (CNGKeyLock)
SRV:64bit: - [2011/08/09 08:59:23 | 008,350,984 | RHS- | M] () [Unknown | Stopped] -- C:\Windows\SysNative\sysDriverHardWare.exe -- (MicrosoftHardwareDriver)
SRV:64bit: - [2011/08/09 08:59:22 | 008,355,080 | RHS- | M] () [Unknown | Stopped] -- C:\Windows\SysNative\sysSecurityCheck.exe -- (SysCacheDriver)
SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/09/22 21:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/09/09 17:50:38 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/08/10 21:01:06 | 000,206,880 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV:64bit: - [2009/08/10 21:01:04 | 000,626,208 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM))
SRV:64bit: - [2009/07/13 21:54:04 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/07/06 19:52:38 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2010/06/01 20:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/04/03 21:01:24 | 000,246,520 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe -- (GameConsoleService)
SRV - [2010/01/15 18:08:38 | 000,935,208 | ---- | M] (Nero AG) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2010/01/08 10:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/07/13 18:46:26 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/08/09 09:01:26 | 000,020,104 | R--- | M] () [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\akerneldrv64.sys -- (akerneldrv)
DRV:64bit: - [2011/08/09 09:01:26 | 000,016,008 | R--- | M] () [File_System | Boot | Running] -- C:\Windows\SysNative\Drivers\pcrasys64.sys -- (pcrasys)
DRV:64bit: - [2011/07/06 19:52:42 | 000,025,912 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2011/03/11 00:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 00:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/09/09 18:18:10 | 000,339,744 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvmf6264.sys -- (NVNET)
DRV:64bit: - [2010/09/09 18:18:08 | 000,690,208 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL8192su.sys -- (RTL8192su)
DRV:64bit: - [2009/07/13 20:53:42 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/07/13 19:59:34 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 19:59:32 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/13 19:59:32 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/07 06:17:22 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
DRV:64bit: - [2009/06/30 10:37:16 | 000,033,800 | ---- | M] (Panda Security, S.L.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\pavboot64.sys -- (pavboot)
DRV:64bit: - [2009/06/10 18:37:34 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/06/10 18:35:34 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 18:34:32 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 18:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 18:34:22 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV - [2009/07/13 21:17:56 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://gateway.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://gateway.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.shaw.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Web Search..."
FF - prefs.js..browser.search.defaultthis.engineName: " "
FF - prefs.js..browser.search.defaulturl: "http://search.condui...={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://start.shaw.ca/start/enCA/"
FF - prefs.js..extensions.enabledItems: [email protected]:2.0.5
FF - prefs.js..extensions.enabledItems: [email protected]:4.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.34
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: [email protected]:4.1.8
FF - prefs.js..extensions.enabledItems: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}:3.2.5.2
FF - prefs.js..extensions.enabledItems: vshare@toolbar:1.0.2
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:14.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {c8f71e5b-88f8-42a7-98bb-e4c506161de9}:0.4
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.20101009
FF - prefs.js..keyword.URL: "http://vshare.toolba...spx?srch=ku&q="
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/09/09 17:41:43 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/09/09 17:41:43 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandasecurity.com/activescan: C:\Program Files (x86)\Panda Security\ActiveScan 2.0\npwrapper.dll (Panda Security, S.L.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/08/16 21:54:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2011/02/28 22:36:42 | 000,000,000 | ---D | M] (No name found) -- C:\Users\easyhome\AppData\Roaming\mozilla\Extensions
[2011/08/21 10:30:30 | 000,000,000 | ---D | M] (No name found) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions
[2011/08/09 22:05:37 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/08/15 14:18:18 | 000,000,000 | ---D | M] (uTorrentBar Community Toolbar) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\{bf7380fa-e3b4-4db2-af3e-9d8783a45bfc}
[2011/02/26 21:08:53 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2011/08/09 22:05:44 | 000,000,000 | ---D | M] ("CyberSearch") -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\[email protected]
[2011/02/26 21:08:35 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\[email protected]
[2011/02/26 21:08:35 | 000,000,000 | ---D | M] (Illimitux) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\[email protected]
[2011/02/26 21:08:38 | 000,000,000 | ---D | M] (Portalarium Player) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\[email protected]
[2011/02/26 21:08:47 | 000,000,000 | ---D | M] (vShare) -- C:\Users\easyhome\AppData\Roaming\mozilla\Firefox\Profiles\jb57vp1e.default\extensions\vshare@toolbar
[2011/01/09 13:45:28 | 000,000,863 | ---- | M] () -- C:\Users\easyhome\AppData\Roaming\Mozilla\Firefox\Profiles\jb57vp1e.default\searchplugins\conduit.xml
[2010/05/01 21:03:17 | 000,000,266 | ---- | M] () -- C:\Users\easyhome\AppData\Roaming\Mozilla\Firefox\Profiles\jb57vp1e.default\searchplugins\Search.xml
[2011/01/30 19:01:03 | 000,001,583 | ---- | M] () -- C:\Users\easyhome\AppData\Roaming\Mozilla\Firefox\Profiles\jb57vp1e.default\searchplugins\web-search.xml
[2011/08/10 21:38:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/08/10 21:38:15 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
File not found (No name found) --
() (No name found) -- C:\USERS\EASYHOME\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\JB57VP1E.DEFAULT\EXTENSIONS\[email protected]
[2011/08/16 21:54:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/01/01 02:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
Hosts file not found
O2 - BHO: (no name) - {EAEE5C74-6D0D-4aca-9232-0DA4A7B866BA} - C:\Program Files (x86)\PicLensIE\cooliris.dll (Cooliris Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [THXCfg64] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [TouchORB] C:\Program Files (x86)\TouchSettings\TouchPortalOBR.exe (Acer Corp.)
O4:64bit: - HKLM..\Run: [TouchPortalV3Launcher] C:\Program Files (x86)\Gateway\Gateway TouchPortal\TouchPortalLauncher.exe (Acer Corp.)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Gateway\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [MDS_Menu] C:\Program Files (x86)\Gateway\Gateway TouchPortal\MediaShow Espresso\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TaskTray] File not found
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PRO\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [TouchMovieService] C:\Program Files (x86)\Gateway\Gateway TouchPortal\Touch Movie\TouchMovieService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [TouchPortalV3Launcher] C:\Program Files (x86)\Gateway\Gateway TouchPortal\TouchPortalLauncher.exe (Acer Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [WeatherEye] C:\Users\easyhome\AppData\Local\TheWeatherNetwork\WeatherEye\WeatherEye.exe (Pelmorex Media Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Launch Cooliris - {3437D640-C91A-458f-89F5-B9095EA4C28B} - C:\Program Files (x86)\PicLensIE\cooliris.dll (Cooliris Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nvLsp.dll (NVIDIA)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} http://acs.pandasoft...s/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.1.254
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - Reg Error: Key error. File not found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/08/23 22:48:20 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Users\easyhome\Desktop\OTL.exe
[2011/08/23 22:22:32 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1CA94C84-3EFD-4113-A89A-3198BDA4B398}
[2011/08/23 22:13:13 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{4E3AFF1B-7E6C-4681-8211-95415B772CF4}
[2011/08/23 20:48:06 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acer
[2011/08/23 20:48:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Acer
[2011/08/23 11:02:45 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{08C4EF53-AA28-4073-A848-782FCBC9F9F7}
[2011/08/23 10:28:05 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E03D3F18-3040-497E-948B-7AD28EF0BAB3}
[2011/08/23 07:55:21 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{FBB328C8-C249-4201-ABE5-ABE48AEA42EA}
[2011/08/23 07:03:44 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{2410255F-2A6D-412F-AC25-856DDDEC8CFB}
[2011/08/22 21:44:18 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9CD262F0-2104-4668-8FA2-6A3698BE1F13}
[2011/08/22 20:01:13 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{FA99406C-A357-4BBB-9359-8E897D8135D8}
[2011/08/22 19:23:17 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\CleanMyPC Software
[2011/08/22 19:22:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CleanMyPC
[2011/08/22 19:21:32 | 000,000,000 | ---D | C] -- C:\registrycleaner
[2011/08/22 18:51:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{06858AF1-73DE-4A8D-8FFB-D8FE520F6346}
[2011/08/22 18:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2011/08/22 18:09:26 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\GetRightToGo
[2011/08/22 13:49:55 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{12F54B3F-0E09-4142-BEB3-A95E89E74589}
[2011/08/22 10:56:09 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1411B689-2F1F-42D4-948B-8DDE132CADD9}
[2011/08/22 10:03:27 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0438D4F5-6968-436F-A28D-E5FB1121231E}
[2011/08/22 09:58:53 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{A6F895E7-6139-44A8-A5E0-642BC04B68C7}
[2011/08/21 20:12:00 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{C2CC1BED-A7BB-4864-851A-199452082BAF}
[2011/08/21 12:34:25 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{C2E04CE0-739A-4681-A595-187D623BD434}
[2011/08/21 09:16:15 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/08/21 09:12:46 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E4A7B2C4-84CF-477F-B5DD-8C5A7E3AA22A}
[2011/08/21 09:02:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows Genuine Advantage
[2011/08/20 13:09:17 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{D3E22284-198D-4B03-8BCF-F44901651186}
[2011/08/19 17:13:32 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{3A18C3CF-AEEA-4EBB-B158-D33D95AD9074}
[2011/08/19 10:12:46 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E5D08D6B-69E4-48FC-9F58-B5AE4D732598}
[2011/08/19 00:11:03 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{5C25F32A-B0C3-44EF-9612-D375111F10BF}
[2011/08/18 23:49:12 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{8F0BE1F2-F403-48C9-B0F2-E3F918D77AB2}
[2011/08/18 20:42:44 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{2BA6D897-AB9F-4706-9AD0-4B08B5DDFB41}
[2011/08/18 20:11:02 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1F947CD7-02BC-4F10-8A5A-F7196CF3C566}
[2011/08/18 19:53:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Genius Professional Edition
[2011/08/18 19:53:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Driver-Soft
[2011/08/18 19:51:53 | 000,000,000 | ---D | C] -- C:\drivergenius
[2011/08/18 18:39:05 | 000,000,000 | ---D | C] -- C:\processexp
[2011/08/18 15:50:15 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{47828F8B-3CAC-4ABE-BB4F-6B850910F6A9}
[2011/08/18 13:26:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2011/08/18 13:23:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011/08/18 13:06:03 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{160F230B-14E7-427E-810C-8E7628B00BB4}
[2011/08/18 09:52:44 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{FEB63173-CF85-453C-92AB-DEAAFEBF70D5}
[2011/08/18 09:46:29 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{ED010BA6-B399-44B6-98F8-6728B31EE194}
[2011/08/17 13:27:31 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{CB33CF7F-5C42-4EF2-B372-5FBEE35C8BB5}
[2011/08/17 12:30:52 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{AF489237-016F-497A-80E8-C4B56CD7DB58}
[2011/08/17 10:47:08 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9DBB5A25-1D34-4490-A932-8D2D0855978F}
[2011/08/16 22:01:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011/08/16 21:53:36 | 000,033,800 | ---- | C] (Panda Security, S.L.) -- C:\Windows\SysNative\drivers\pavboot64.sys
[2011/08/16 21:53:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
[2011/08/16 13:24:00 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1569294B-4EE1-44FD-AEDC-A24E381F044E}
[2011/08/16 11:07:07 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{B14B8F06-5434-4CAC-993C-98E9297D3159}
[2011/08/16 08:30:09 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{AD8CB99B-08B6-4C84-BFDC-1D3994043588}
[2011/08/15 22:18:06 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{671AC9D7-DD96-4A61-AF48-FE7ADD32007A}
[2011/08/15 20:17:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/08/15 20:17:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/08/15 20:17:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2011/08/15 17:22:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{ECC06D14-8C21-4DE6-89DB-E54CD3AECA53}
[2011/08/15 17:06:04 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E02F83DE-1FFB-43E3-A789-F64EAE63B465}
[2011/08/15 10:14:49 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{D278C048-409C-4BE5-B09E-26FDA51C6560}
[2011/08/15 08:43:45 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{B46BE585-BB86-4ACA-ACAC-85C2CCC3AAE9}
[2011/08/15 08:22:05 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{C6932D6F-BCE6-4CBE-AE31-ECBFDC69FFDF}
[2011/08/14 22:58:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/08/14 22:38:54 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/08/14 21:54:15 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{7CC90DB4-527D-486E-958E-7012AC937282}
[2011/08/14 21:53:36 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{65DCCDA8-7493-4803-80B8-8C80FD7EB8F1}
[2011/08/14 21:35:43 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{568CEDFA-6E00-4D10-AC59-6D23B6B2E87B}
[2011/08/14 18:13:37 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9EFD0270-D812-4ED2-88F3-114EAABDCC53}
[2011/08/14 13:04:03 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{28B47389-D678-4058-8F54-8C853D88D6D9}
[2011/08/14 12:56:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1BFCAD49-B182-498D-B4B3-223711596CAF}
[2011/08/14 01:21:13 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{4E9E4855-F3D8-4A15-84A5-C4589A8C9A13}
[2011/08/12 21:13:19 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{5CA4307B-C757-4203-BFBF-FBB74FD4B821}
[2011/08/12 20:52:28 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{812640BC-D72A-483C-83FF-9E82EA5DB0E3}
[2011/08/12 17:56:25 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/08/12 17:56:25 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/08/12 17:56:25 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/08/12 17:46:04 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/08/12 17:20:07 | 004,170,159 | R--- | C] (Swearware) -- C:\Users\easyhome\Desktop\puppy.exe
[2011/08/12 14:16:26 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{B8396A0C-E930-4ECF-B734-FBAD6136C360}
[2011/08/12 11:03:54 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{2A42E3CA-0AE8-474D-94DC-BFE8F068A8B9}
[2011/08/12 08:59:59 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9F00EF5D-EA3F-4BF3-A567-6792E8D5E6A8}
[2011/08/12 07:56:31 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{51583D6E-FFC6-4CC3-A1A6-FF29F203256B}
[2011/08/12 06:57:27 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{29DD3B1B-250E-489F-BD26-552169900B2A}
[2011/08/11 21:17:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011/08/11 07:31:31 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{46A6F414-E9A7-47B6-9D1D-8A7E57FDC756}
[2011/08/10 21:42:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PopCap Games
[2011/08/10 21:42:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PopCap Games
[2011/08/10 21:41:46 | 000,000,000 | ---D | C] -- C:\bjblitxcrack
[2011/08/10 21:18:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The KMPlayer
[2011/08/10 21:03:09 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{128F13D0-3842-47B1-9B89-5B21197523E5}
[2011/08/10 19:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2011/08/10 19:44:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trojan Remover
[2011/08/10 19:44:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trojan Remover
[2011/08/10 19:44:32 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\Simply Super Software
[2011/08/10 19:44:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Simply Super Software
[2011/08/10 19:42:53 | 000,000,000 | ---D | C] -- C:\trojanremover
[2011/08/10 19:41:09 | 000,000,000 | ---D | C] -- C:\ProgramData\ConeXware
[2011/08/10 19:40:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PatchBeam
[2011/08/10 19:40:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerArchiver
[2011/08/10 19:40:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PowerArchiver
[2011/08/10 19:26:13 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{7FF28835-FF6F-4DB9-9F5D-7BB64D1ECC22}
[2011/08/10 14:52:19 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{502F35FB-46CC-42FD-930A-2ECD26AAE7F6}
[2011/08/10 00:42:31 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2011/08/10 00:26:51 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{3F11519D-B896-4A02-86B8-F90226FE3F13}
[2011/08/10 00:10:47 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{BA8FF579-3346-474F-A4C4-1EA01F7EF93A}
[2011/08/09 22:27:49 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\Conduit
[2011/08/09 22:27:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2011/08/09 22:27:02 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\uTorrent
[2011/08/09 22:13:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011/08/09 22:13:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2011/08/09 22:04:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2011/08/09 20:33:49 | 000,000,000 | ---D | C] -- C:\ProgramData\PopCap Games
[2011/08/09 20:33:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bejeweled Blitz
[2011/08/09 18:39:48 | 000,041,272 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/08/09 18:39:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/08/09 18:39:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/08/09 18:39:44 | 000,025,912 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/08/09 18:39:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/08/09 18:30:42 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/08/09 09:01:32 | 008,007,680 | R--- | C] ( ) -- C:\Windows\SysNative\Microsoft.mshtml.dll
[2011/08/09 09:01:32 | 000,126,976 | R--- | C] ( ) -- C:\Windows\SysNative\Interop.SHDocVw.dll
[2011/08/09 08:05:49 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E36CF281-1FA8-4472-913F-78A6273FCB97}
[2011/08/09 06:53:26 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2011/08/09 06:53:26 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2011/08/09 05:05:46 | 000,000,000 | ---D | C] -- C:\book
[2011/08/09 04:04:35 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{69B3D09B-92EF-4753-BAFD-89EB9BA1182B}
[2011/08/09 04:01:41 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\Vaco
[2011/08/09 04:01:41 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Roaming\Diik
[2011/08/09 03:56:05 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/08/09 03:52:59 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0EA25A2A-C61D-49A1-B9D1-9DF6BAE8FBD8}
[2011/08/09 03:39:26 | 008,007,680 | ---- | C] ( ) -- C:\Windows\SysWow64\Microsoft.mshtml.dll
[2011/08/09 03:39:24 | 000,126,976 | ---- | C] ( ) -- C:\Windows\SysWow64\Interop.SHDocVw.dll
[2011/08/09 03:22:52 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2011/08/08 19:39:14 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0E4A281B-2BD6-45BB-9C19-C94FFE192F75}
[2011/08/08 19:25:46 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0A47FAC2-29AD-4BE7-8A0A-7BE1C41208BC}
[2011/08/08 19:25:34 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{AE5E8579-B81F-4BA8-BE4B-8CB298AF60F5}
[2011/08/08 18:01:25 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0A72364B-BB87-467B-8818-9D37614F6BC6}
[2011/08/08 18:01:12 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{68118980-E043-4B09-BD76-9042E1C5CD70}
[2011/08/08 12:17:38 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{38EAFFCD-198B-4E96-B9AE-B1FEF08EAC44}
[2011/08/08 12:17:26 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{BFF90156-A729-4D31-AC76-63A4D1998C84}
[2011/08/08 08:13:00 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{A0A8FD55-1CE2-4F93-B76C-40B60BA685E8}
[2011/08/07 18:10:45 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{05F241D3-7BAD-4F73-A748-E1DD4809C448}
[2011/08/07 18:10:33 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{346C1192-5F4F-41C3-B1C9-48AB60FFD952}
[2011/08/07 10:25:47 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{A884CBD8-E104-4206-BBC1-DD41E9107521}
[2011/08/07 09:59:54 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0FA4B5A9-BCA4-4E62-890A-06EF128DD735}
[2011/08/06 16:11:09 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{2C0B8277-62FD-4C06-AAB0-562374BDB1EB}
[2011/08/06 16:10:57 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{82D6673D-4ED2-4ABA-A5A6-F98243DE63DF}
[2011/08/06 11:24:43 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{BFE1533C-0B76-4BA0-BB6E-E5688271AD81}
[2011/08/06 11:24:31 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{886995DD-5CB7-42BE-AF8D-91B5539BE0BE}
[2011/08/06 09:57:54 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{40A6733D-F3A0-400B-A5E2-F2E678329A69}
[2011/08/06 09:57:42 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{CEC9925C-D75B-4B36-B88B-D96EE8CE9837}
[2011/08/05 23:02:42 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1AD5572E-D6C5-4640-AEFE-D16CAF6C43FE}
[2011/08/05 21:54:14 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9D581322-1AC2-48DD-8D52-9D4E0BCA6553}
[2011/08/05 21:54:02 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{19AFA376-B360-4340-8CBC-7517CBBC5664}
[2011/08/05 21:46:31 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{3BF716BC-8F99-4D99-89E9-665CDA70492A}
[2011/08/05 21:46:19 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{6E072E50-4440-4E65-89CE-581E33BAD446}
[2011/08/05 21:29:48 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{E037766F-F316-459E-B714-D11382469A88}
[2011/08/05 21:16:58 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{EA859097-F242-465C-986F-A1D88B4E1E84}
[2011/08/05 20:48:59 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{F68E30F0-E21C-494A-A5A5-674528C3B484}
[2011/08/05 20:12:46 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{038DA731-209D-4808-A4B7-C56613943B44}
[2011/08/05 20:09:56 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{93D84BD2-9282-49CD-B7F0-8B6B9C7CE118}
[2011/08/05 20:09:44 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{75F84332-8CFA-440B-93B7-E058F3C5C7E0}
[2011/08/05 17:19:42 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{41C643B7-2A6D-4D89-BECA-2012F39B9A3B}
[2011/08/05 17:19:30 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{D03DD6A2-0FFE-4D8C-915B-D9A8763FA473}
[2011/08/05 14:16:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{8281DF27-A431-4923-9B4A-C2E86720FC62}
[2011/08/05 13:49:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{003E81D6-66BF-42B8-A65C-94465BDB08E9}
[2011/08/05 13:49:12 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{4B894D5E-D7F1-4496-82D3-77683CB1B184}
[2011/08/05 13:09:42 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{4EA2046D-3D3F-4B3F-98BC-B15645CDCA5E}
[2011/08/05 13:09:30 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{89F94A6E-77F8-450F-AA4F-59CBDAE078AD}
[2011/08/05 12:57:40 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{DB6C586A-2FEE-4CB9-B981-C43181EBFF4B}
[2011/08/05 12:57:28 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{2E5137B3-3FE8-472B-9E77-02526A97CF9A}
[2011/08/05 09:17:49 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{82BAABC5-69AC-440D-B709-F2FC201E231D}
[2011/08/04 15:46:52 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{08BA59A4-6BB8-41A2-89C3-ACD137BE0787}
[2011/08/03 23:01:13 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{8735469D-5A4F-4640-9E5D-D27B10514B35}
[2011/08/03 07:08:37 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{0936B113-4245-491C-985C-EDDC3CACF66B}
[2011/08/02 14:54:00 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{784787BC-B213-4B8F-B1A7-2B3FCBF931E4}
[2011/08/02 12:56:44 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\assembly
[2011/08/02 12:56:37 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\IsolatedStorage
[2011/08/02 07:22:34 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{AEAD8942-4F08-45AD-B632-8E8EAB342299}
[2011/08/01 11:11:15 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{7838615B-9C41-4E63-B951-0B433B241C4D}
[2011/07/31 02:20:15 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{4AC3F808-BE39-4197-8C22-7E45CFC01EE3}
[2011/07/30 08:59:33 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{03C3A0F3-84BF-4E25-8ACF-557E0E8974A6}
[2011/07/29 07:06:50 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{1A8A632F-9448-4784-A125-B74CFC03F123}
[2011/07/28 18:23:56 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{ECF27A40-1C44-4EF0-B964-D21BF6C4F698}
[2011/07/28 12:09:12 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{B07B71E7-EE38-4040-A981-C387EE06D59B}
[2011/07/27 08:57:17 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{78A596E8-D0E5-4E39-8F03-552BF4D22612}
[2011/07/27 08:41:49 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{9E6047F2-32AB-463A-A46A-B2795C9E878E}
[2011/07/26 18:47:06 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{AA41ADFB-7BC8-48EE-B96E-D1C3F5B9978D}
[2011/07/26 16:02:53 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{DD805767-80CF-43BB-A634-8EF2484AA64F}
[2011/07/26 11:41:58 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{512C2389-9B3D-40C5-990F-A5E60DCB3C9F}
[2011/07/25 16:20:59 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{41951FF5-DAD9-400F-BCDA-3AE0CD28FE4B}
[2011/07/25 11:14:24 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{F44F0E5A-B219-41F0-9B2B-CC91BD95DEE0}
[2011/07/24 23:01:00 | 000,000,000 | ---D | C] -- C:\Users\easyhome\AppData\Local\{D58009C0-20F5-4C74-BC5D-AD3DCC51BE43}
[2011/03/25 12:39:21 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\easyhome\AppData\Roaming\pcouffin.sys
========== Files - Modified Within 30 Days ==========
[2011/08/23 22:48:25 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\easyhome\Desktop\OTL.exe
[2011/08/23 22:43:26 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/23 22:43:26 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/23 22:42:14 | 001,390,139 | ---- | M] () -- C:\Users\easyhome\Desktop\tdsskiller.zip
[2011/08/23 22:25:49 | 000,082,796 | RHS- | M] () -- C:\Windows\SysNative\masteraclini.enu
[2011/08/23 22:25:49 | 000,000,116 | R--- | M] () -- C:\Windows\SysNative\masteraclbini.enu
[2011/08/23 22:10:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/23 19:28:33 | 000,717,260 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/08/23 19:28:33 | 000,621,306 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/08/23 19:28:33 | 000,108,388 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/08/23 19:23:27 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/23 19:23:06 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/08/23 19:23:03 | 3019,296,768 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/22 22:01:04 | 000,000,017 | ---- | M] () -- C:\Users\easyhome\AppData\Local\resmon.resmoncfg
[2011/08/22 19:23:57 | 003,828,341 | ---- | M] () -- C:\Users\easyhome\Documents\backup.cab
[2011/08/18 19:57:01 | 000,001,725 | ---- | M] () -- C:\Users\easyhome\Desktop\DriverGenius - Shortcut.lnk
[2011/08/18 19:11:00 | 000,422,382 | ---- | M] () -- C:\Users\easyhome\Desktop\Untitled.jpg
[2011/08/18 13:44:56 | 000,289,152 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/08/18 13:26:35 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/08/18 13:26:21 | 000,722,382 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/15 20:17:52 | 000,001,269 | ---- | M] () -- C:\Users\easyhome\Desktop\Spybot - Search & Destroy.lnk
[2011/08/15 19:16:14 | 000,000,755 | -HS- | M] () -- C:\Windows\SysNative\settings.ini
[2011/08/15 19:06:11 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/08/15 19:06:09 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011/08/12 17:43:25 | 469,277,857 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/08/12 17:20:30 | 004,170,159 | R--- | M] (Swearware) -- C:\Users\easyhome\Desktop\puppy.exe
[2011/08/10 21:42:36 | 000,001,258 | ---- | M] () -- C:\Users\Public\Desktop\Bejeweled Blitz.lnk
[2011/08/10 21:42:36 | 000,000,200 | ---- | M] () -- C:\Users\Public\Desktop\Play More Great Games!.url
[2011/08/10 21:18:25 | 000,001,046 | ---- | M] () -- C:\Users\easyhome\Desktop\KMPlayer.lnk
[2011/08/10 19:44:55 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2011/08/10 19:40:40 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\PowerArchiver.lnk
[2011/08/10 07:11:17 | 000,002,351 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/08/09 22:27:41 | 000,000,954 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/08/09 22:04:56 | 000,001,149 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/08/09 18:39:49 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/08/09 09:01:32 | 008,007,680 | R--- | M] ( ) -- C:\Windows\SysNative\Microsoft.mshtml.dll
[2011/08/09 09:01:32 | 002,096,904 | RH-- | M] () -- C:\Windows\SysNative\WinSystemProcess.exe
[2011/08/09 09:01:32 | 001,369,088 | RH-- | M] () -- C:\Windows\SysNative\7z.dll
[2011/08/09 09:01:32 | 000,256,000 | RH-- | M] () -- C:\Windows\SysNative\SevenZipSharp.dll
[2011/08/09 09:01:32 | 000,200,704 | R--- | M] () -- C:\Windows\SysNative\ICSharpCode.SharpZipLib.dll
[2011/08/09 09:01:32 | 000,126,976 | R--- | M] ( ) -- C:\Windows\SysNative\Interop.SHDocVw.dll
[2011/08/09 09:01:32 | 000,095,496 | RHS- | M] () -- C:\Windows\SysNative\FireWallDart.exe
[2011/08/09 09:01:32 | 000,061,192 | RH-- | M] () -- C:\Windows\SysNative\messagePop.exe
[2011/08/09 09:01:30 | 000,003,535 | RHS- | M] () -- C:\Windows\SysNative\{master}(1)avg.enu
[2011/08/09 09:01:30 | 000,001,786 | RHS- | M] () -- C:\Windows\SysNative\masterlock.enu
[2011/08/09 09:01:26 | 000,069,762 | -H-- | M] () -- C:\Windows\SysWow64\masteraclini.enu
[2011/08/09 09:01:26 | 000,020,104 | R--- | M] () -- C:\Windows\SysNative\drivers\akerneldrv64.sys
[2011/08/09 09:01:26 | 000,019,080 | R--- | M] () -- C:\Windows\SysNative\drivers\apcmci64.sys
[2011/08/09 09:01:26 | 000,016,008 | R--- | M] () -- C:\Windows\SysNative\drivers\pcrasys64.sys
[2011/08/09 09:01:26 | 000,004,697 | RHS- | M] () -- C:\Windows\SysNative\{master}(0)nrt.enu
[2011/08/09 09:01:26 | 000,003,618 | RHS- | M] () -- C:\Windows\SysNative\{master}(99)misc.enu
[2011/08/09 09:01:26 | 000,003,445 | RHS- | M] () -- C:\Windows\SysNative\{master}(9)com.enu
[2011/08/09 09:01:26 | 000,003,439 | RHS- | M] () -- C:\Windows\SysNative\{master}(2)cas.enu
[2011/08/09 09:01:26 | 000,003,427 | RHS- | M] () -- C:\Windows\SysNative\{master}(8)pro.enu
[2011/08/09 09:01:26 | 000,003,391 | RHS- | M] () -- C:\Windows\SysNative\{master}(3)pan.enu
[2011/08/09 09:01:26 | 000,003,354 | RHS- | M] () -- C:\Windows\SysNative\{master}(zz)Template.enu
[2011/08/09 09:01:26 | 000,003,347 | RHS- | M] () -- C:\Windows\SysNative\{master}(1a)avgi.enu
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\suspendoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\spynetkeepon
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\restorerunoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\rebootoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\overridenomonitor
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\nukeoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | M] () -- C:\Windows\firewalloff
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\SuspendOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\SpyNetKeepOn
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\RestoreRunOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\RebootOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\OverrideNoMonitor
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\NukeOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\FireWallOff
[2011/08/09 09:01:25 | 008,205,576 | RH-- | M] () -- C:\Windows\SysNative\servicescache.exe
[2011/08/09 08:59:24 | 000,199,944 | -HS- | M] () -- C:\Windows\SysNative\CNGKeyLock.exe
[2011/08/09 08:59:23 | 008,350,984 | RHS- | M] () -- C:\Windows\SysNative\sysDriverHardWare.exe
[2011/08/09 08:59:22 | 008,355,080 | RHS- | M] () -- C:\Windows\SysNative\sysSecurityCheck.exe
[2011/08/09 03:39:27 | 008,007,680 | ---- | M] ( ) -- C:\Windows\SysWow64\Microsoft.mshtml.dll
[2011/08/09 03:39:24 | 000,126,976 | ---- | M] ( ) -- C:\Windows\SysWow64\Interop.SHDocVw.dll
[2011/08/09 03:18:02 | 001,056,768 | ---- | M] () -- C:\Windows\SysWow64\defltbase.sdb
[2011/07/27 06:20:07 | 000,008,610 | ---- | M] () -- C:\Users\easyhome\Desktop\tugboat.jpg
========== Files Created - No Company Name ==========
[2011/08/23 22:42:09 | 001,390,139 | ---- | C] () -- C:\Users\easyhome\Desktop\tdsskiller.zip
[2011/08/22 22:01:04 | 000,000,017 | ---- | C] () -- C:\Users\easyhome\AppData\Local\resmon.resmoncfg
[2011/08/22 19:23:57 | 003,828,341 | ---- | C] () -- C:\Users\easyhome\Documents\backup.cab
[2011/08/18 19:57:01 | 000,001,725 | ---- | C] () -- C:\Users\easyhome\Desktop\DriverGenius - Shortcut.lnk
[2011/08/18 19:11:00 | 000,422,382 | ---- | C] () -- C:\Users\easyhome\Desktop\Untitled.jpg
[2011/08/15 20:17:52 | 000,001,269 | ---- | C] () -- C:\Users\easyhome\Desktop\Spybot - Search & Destroy.lnk
[2011/08/15 19:18:32 | 000,001,454 | ---- | C] () -- C:\Users\easyhome\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2011/08/15 19:16:14 | 000,000,755 | -HS- | C] () -- C:\Windows\SysNative\settings.ini
[2011/08/15 19:06:11 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/08/15 19:06:09 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/08/12 17:56:25 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/08/12 17:56:25 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/08/12 17:56:25 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/08/12 17:56:25 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/08/12 17:56:25 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/08/10 21:42:36 | 000,001,258 | ---- | C] () -- C:\Users\Public\Desktop\Bejeweled Blitz.lnk
[2011/08/10 21:18:25 | 000,001,046 | ---- | C] () -- C:\Users\easyhome\Desktop\KMPlayer.lnk
[2011/08/10 19:44:55 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Trojan Remover.lnk
[2011/08/10 19:44:43 | 000,162,304 | ---- | C] () -- C:\Windows\SysWow64\ztvunrar36.dll
[2011/08/10 19:44:43 | 000,153,088 | ---- | C] () -- C:\Windows\SysWow64\UNRAR3.dll
[2011/08/10 19:44:43 | 000,077,312 | ---- | C] () -- C:\Windows\SysWow64\ztvunace26.dll
[2011/08/10 19:44:43 | 000,075,264 | ---- | C] () -- C:\Windows\SysWow64\unacev2.dll
[2011/08/10 19:40:40 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\PowerArchiver.lnk
[2011/08/09 22:27:41 | 000,000,954 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2011/08/09 22:13:48 | 000,002,351 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/08/09 22:13:26 | 000,000,902 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/08/09 22:13:24 | 000,000,898 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/08/09 22:04:56 | 000,001,161 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/08/09 22:04:56 | 000,001,149 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/08/09 09:01:32 | 002,096,904 | RH-- | C] () -- C:\Windows\SysNative\WinSystemProcess.exe
[2011/08/09 09:01:32 | 001,369,088 | RH-- | C] () -- C:\Windows\SysNative\7z.dll
[2011/08/09 09:01:32 | 000,256,000 | RH-- | C] () -- C:\Windows\SysNative\SevenZipSharp.dll
[2011/08/09 09:01:32 | 000,200,704 | R--- | C] () -- C:\Windows\SysNative\ICSharpCode.SharpZipLib.dll
[2011/08/09 09:01:32 | 000,095,496 | RHS- | C] () -- C:\Windows\SysNative\FireWallDart.exe
[2011/08/09 09:01:32 | 000,061,192 | RH-- | C] () -- C:\Windows\SysNative\messagePop.exe
[2011/08/09 09:01:26 | 014,039,304 | RHS- | C] () -- C:\Windows\SysNative\BackupSys.exe
[2011/08/09 09:01:26 | 008,205,576 | RH-- | C] () -- C:\Windows\SysNative\servicescache.exe
[2011/08/09 09:01:26 | 000,405,504 | RHS- | C] () -- C:\Windows\SysNative\vshadow.exe
[2011/08/09 09:01:26 | 000,364,032 | RHS- | C] () -- C:\Windows\SysNative\vshadowamd64.exe
[2011/08/09 09:01:26 | 000,352,256 | RHS- | C] () -- C:\Windows\SysNative\vshadowXP.exe
[2011/08/09 09:01:26 | 000,019,080 | R--- | C] () -- C:\Windows\SysNative\drivers\apcmci64.sys
[2011/08/09 09:01:26 | 000,003,347 | RHS- | C] () -- C:\Windows\SysNative\{master}(1a)avgi.enu
[2011/08/09 09:01:26 | 000,000,116 | R--- | C] () -- C:\Windows\SysNative\masteraclbini.enu
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\suspendoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\spynetkeepon
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\restorerunoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\rebootoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\overridenomonitor
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\nukeoff
[2011/08/09 09:01:26 | 000,000,064 | ---- | C] () -- C:\Windows\firewalloff
[2011/08/09 09:01:26 | 000,000,038 | RHS- | C] () -- C:\Windows\SysNative\masteracl.enu
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\SuspendOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\SpyNetKeepOn
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\RestoreRunOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\RebootOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\OverrideNoMonitor
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\NukeOff
[2011/08/09 09:01:26 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\FireWallOff
[2011/08/09 08:59:23 | 008,350,984 | RHS- | C] () -- C:\Windows\SysNative\sysDriverHardWare.exe
[2011/08/09 08:59:21 | 008,355,080 | RHS- | C] () -- C:\Windows\SysNative\sysSecurityCheck.exe
[2011/08/09 05:05:47 | 000,069,762 | -H-- | C] () -- C:\Windows\SysWow64\masteraclini.enu
[2011/08/09 03:57:51 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/08/09 03:57:22 | 000,722,382 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/09 03:22:40 | 469,277,857 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2011/08/09 03:18:00 | 001,056,768 | ---- | C] () -- C:\Windows\SysWow64\defltbase.sdb
[2011/08/09 03:16:28 | 3019,296,768 | -HS- | C] () -- C:\hiberfil.sys
[2011/08/08 10:34:15 | 000,000,200 | ---- | C] () -- C:\Users\Public\Desktop\Play More Great Games!.url
[2011/07/27 06:20:30 | 000,008,610 | ---- | C] () -- C:\Users\easyhome\Desktop\tugboat.jpg
[2011/03/25 12:39:21 | 000,007,859 | ---- | C] () -- C:\Users\easyhome\AppData\Roaming\pcouffin.cat
[2011/03/25 12:39:21 | 000,001,167 | ---- | C] () -- C:\Users\easyhome\AppData\Roaming\pcouffin.inf
[2009/07/14 03:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:35:50 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 00:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 22:10:28 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 21:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 19:03:58 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/07/07 06:32:48 | 000,181,248 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2009/07/07 06:32:48 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2009/07/07 06:32:48 | 000,001,411 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2009/07/07 06:32:48 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2009/07/07 06:32:48 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2009/06/10 19:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/08/22 19:23:17 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\CleanMyPC Software
[2011/06/01 17:52:18 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Coby
[2011/06/01 18:06:04 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Coby Media Manager
[2011/03/31 21:32:27 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\DAEMON Tools Lite
[2011/08/09 18:51:08 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Diik
[2011/08/22 18:09:59 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\GetRightToGo
[2011/03/31 21:48:21 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\LucasArts
[2011/02/12 05:23:43 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\MyJournals
[2011/04/02 10:00:14 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\OEM
[2011/02/27 16:30:50 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\OpenOffice.org
[2011/03/07 22:13:49 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Packard Bell
[2011/08/18 17:06:12 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\PowerCinema
[2011/05/22 19:54:09 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Replay Media Catcher 4
[2011/08/10 19:44:32 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Simply Super Software
[2011/06/13 06:46:58 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Smilebox
[2011/08/16 15:54:35 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\TouchBrowser
[2011/08/18 17:05:33 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\TouchGadget
[2011/02/09 08:15:59 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\TouchPortalV3
[2011/08/23 19:41:57 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\uTorrent
[2011/08/09 08:05:39 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Vaco
[2011/07/19 21:48:47 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Vso
[2011/02/12 05:23:44 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\WebClip
[2011/02/19 09:57:56 | 000,000,000 | ---D | M] -- C:\Users\easyhome\AppData\Roaming\Windows Live Writer
[2011/08/22 09:29:22 | 000,013,312 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:ECF54A0E
< End of report >
One more thing this is a leased (rent to own computer) from easy home. so they're are root kits installed for they're security.
I did use tdsskiller and it found some malware and removed it for me. not sure if that was the problem though
Since I used tdsskiller ping.exe has not come on in the task manager so hopefully that was the problem. but still not 100% sure.
I'm not sure if he virus that tdsskiller found was the cause of my problem.(forgot to save a log) But it seemed to be an unknown driver that it detected and deleted for me. Don't mean to bump my post
not sure if problem solved or not
Mod Edit: Last 5 posts merged to clean thread up.--ST
Edited by rshaffer61, 28 August 2011 - 05:04 PM.