OTL logfile created on: 2/8/2014 2:45:50 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Main\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.34 Gb Available Physical Memory | 77.99% Memory free
4.34 Gb Paging File | 3.88 Gb Available in Paging File | 89.39% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 31.86 Gb Free Space | 45.65% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 812.62 Gb Free Space | 87.24% Space Free | Partition Type: NTFS
Computer Name: CARLOSDESKTOP | User Name: Main | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2014/02/08 13:57:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Main\Desktop\OTL.exe
PRC - [2014/02/05 03:48:32 | 004,915,040 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe
PRC - [2014/02/05 03:48:31 | 012,493,152 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\TeamViewer.exe
PRC - [2014/02/05 03:35:14 | 000,202,592 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version9\tv_w32.exe
PRC - [2014/01/10 15:06:50 | 003,362,336 | R--- | M] (Fitbit, Inc.) -- C:\Program Files\Fitbit Connect\Fitbit Connect.exe
PRC - [2014/01/10 15:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) -- C:\Program Files\Fitbit Connect\FitbitConnectService.exe
PRC - [2014/01/07 10:47:52 | 000,182,696 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2013/12/06 15:47:44 | 020,203,904 | ---- | M] (Google) -- C:\Program Files\Google\Drive\googledrivesync.exe
PRC - [2013/04/05 01:56:49 | 001,642,496 | ---- | M] (Moo0) -- C:\Program Files\Moo0\WindowMenuPlus 1.16\WindowMenuPlus.exe
PRC - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2013/04/04 14:50:32 | 000,532,040 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
PRC - [2012/08/23 11:37:16 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2011/03/11 17:47:36 | 000,517,632 | ---- | M] (Document Capture Technologies, Inc.) -- C:\Program Files\DocuCap\DocketSCAN II\DocketSCAN.exe
PRC - [2010/05/06 17:55:21 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2014/02/08 14:01:14 | 001,175,040 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._core_.pyd
MOD - [2014/02/08 14:01:14 | 001,153,024 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_ssl.pyd
MOD - [2014/02/08 14:01:14 | 001,062,400 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._controls_.pyd
MOD - [2014/02/08 14:01:14 | 000,811,008 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._windows_.pyd
MOD - [2014/02/08 14:01:14 | 000,805,888 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._gdi_.pyd
MOD - [2014/02/08 14:01:14 | 000,735,232 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._misc_.pyd
MOD - [2014/02/08 14:01:14 | 000,711,680 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_hashlib.pyd
MOD - [2014/02/08 14:01:14 | 000,686,080 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\unicodedata.pyd
MOD - [2014/02/08 14:01:14 | 000,557,056 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\pysqlite2._sqlite.pyd
MOD - [2014/02/08 14:01:14 | 000,521,680 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\windows._lib_cacheinvalidation.pyd
MOD - [2014/02/08 14:01:14 | 000,364,544 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\pythoncom27.dll
MOD - [2014/02/08 14:01:14 | 000,320,512 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32com.shell.shell.pyd
MOD - [2014/02/08 14:01:14 | 000,128,512 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_elementtree.pyd
MOD - [2014/02/08 14:01:14 | 000,127,488 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\pyexpat.pyd
MOD - [2014/02/08 14:01:14 | 000,122,368 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._wizard.pyd
MOD - [2014/02/08 14:01:14 | 000,119,808 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32file.pyd
MOD - [2014/02/08 14:01:14 | 000,110,080 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\PyWinTypes27.dll
MOD - [2014/02/08 14:01:14 | 000,108,544 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32security.pyd
MOD - [2014/02/08 14:01:14 | 000,098,816 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32api.pyd
MOD - [2014/02/08 14:01:14 | 000,087,040 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_ctypes.pyd
MOD - [2014/02/08 14:01:14 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\wx._html2.pyd
MOD - [2014/02/08 14:01:14 | 000,044,032 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_socket.pyd
MOD - [2014/02/08 14:01:14 | 000,038,912 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32inet.pyd
MOD - [2014/02/08 14:01:14 | 000,035,840 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32process.pyd
MOD - [2014/02/08 14:01:14 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\_multiprocessing.pyd
MOD - [2014/02/08 14:01:14 | 000,025,600 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32pdh.pyd
MOD - [2014/02/08 14:01:14 | 000,024,064 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32pipe.pyd
MOD - [2014/02/08 14:01:14 | 000,022,528 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32ts.pyd
MOD - [2014/02/08 14:01:14 | 000,018,432 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32event.pyd
MOD - [2014/02/08 14:01:14 | 000,017,408 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32profile.pyd
MOD - [2014/02/08 14:01:14 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\win32crypt.pyd
MOD - [2014/02/08 14:01:14 | 000,010,240 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\temp\_MEI1242\select.pyd
MOD - [2013/01/02 01:49:10 | 001,292,288 | ---- | M] () -- C:\WINDOWS\system32\quartz.dll
MOD - [2012/04/14 02:24:14 | 000,221,696 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.ServiceProce#\d7fbfc6836ce7e53486ddb79b598ca8d\System.ServiceProcess.ni.dll
MOD - [2012/04/14 02:19:25 | 000,762,368 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\01e360ed3a3cb2b0a3c47c7f3eb09e58\System.Runtime.Remoting.ni.dll
MOD - [2012/04/14 02:19:22 | 000,786,944 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.EnterpriseSe#\47a2b7b2fa872de3078d49d0a4c10cb2\System.EnterpriseServices.ni.dll
MOD - [2012/04/14 02:19:20 | 000,646,656 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Transactions\c3a03bb69e38f5ed9ebce72d48a722ef\System.Transactions.ni.dll
MOD - [2012/04/14 02:16:38 | 006,798,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Data\97586cdb698c29ba95fd83e44a0c0ca6\System.Data.ni.dll
MOD - [2012/04/14 02:16:18 | 005,618,176 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Xml\21071fcc838660d96f10920c4c3cd206\System.Xml.ni.dll
MOD - [2012/04/14 02:16:11 | 000,980,480 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Configuration\363b05dd092178671e56531a9c4999b6\System.Configuration.ni.dll
MOD - [2012/04/14 02:16:08 | 007,054,336 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Core\a2b1103ad3d9f329e0c9164994137c81\System.Core.ni.dll
MOD - [2012/04/14 02:15:53 | 013,137,920 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\f28df9c2988724883cf19532d7f9f151\System.Windows.Forms.ni.dll
MOD - [2012/04/14 02:15:34 | 001,652,736 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System.Drawing\2ff57b810eb920860469184dd683cb8a\System.Drawing.ni.dll
MOD - [2012/04/14 02:15:28 | 009,090,560 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\System\3ff4657a86a0e14b4be577969e0ec762\System.ni.dll
MOD - [2012/04/14 02:15:15 | 014,407,680 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v4.0.30319_32\mscorlib\52f4f785f7cf45a64606a8e13c8cf04c\mscorlib.ni.dll
MOD - [2012/02/20 20:29:04 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/02/20 20:28:42 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/02/04 17:48:30 | 000,291,840 | ---- | M] () -- C:\WINDOWS\system32\sbe.dll
MOD - [2009/11/05 07:39:40 | 000,087,552 | ---- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2008/04/13 19:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 19:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
========== Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- %SystemRoot%\System32\hidserv.dll -- (HidServ)
SRV - [2014/02/05 11:43:40 | 000,118,896 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014/02/05 08:32:18 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/05 03:48:32 | 004,915,040 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe -- (TeamViewer9)
SRV - [2014/01/10 15:06:48 | 001,435,680 | R--- | M] (Fitbit, Inc.) [Auto | Running] -- C:\Program Files\Fitbit Connect\FitbitConnectService.exe -- (Fitbit Connect)
SRV - [2014/01/07 10:47:52 | 000,182,696 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe -- (JavaQuickStarterService)
SRV - [2013/04/04 14:50:32 | 000,701,512 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2013/04/04 14:50:32 | 000,418,376 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe -- (MBAMScheduler)
SRV - [2012/08/23 11:37:16 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2004/03/18 15:55:48 | 000,065,536 | ---- | M] (HP) [Disabled | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | System | Stopped] -- system32\DRIVERS\wanatw4.sys -- (wanatw)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - File not found [Kernel | System | Stopped] -- System32\Drivers\MpFirewall.sys -- (MPFIREWL)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (bvrp_pci)
DRV - [2013/04/04 14:50:32 | 000,022,856 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2009/10/28 09:59:06 | 000,035,384 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PcaSp50.sys -- (PcaSp50)
DRV - [2008/05/06 01:01:50 | 000,016,512 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [2007/01/04 10:07:00 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2006/06/07 14:02:46 | 000,008,552 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\asctrm.sys -- (ASCTRM)
DRV - [2005/11/16 20:36:00 | 001,047,816 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2005/08/04 03:10:18 | 001,273,344 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/03/10 15:27:18 | 000,011,264 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asapiW2k.sys -- (ASAPIW2k)
DRV - [2003/11/17 20:59:20 | 000,212,224 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSFHWBS2.sys -- (HSFHWBS2)
DRV - [2003/11/17 20:58:02 | 000,680,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys -- (winachsf)
DRV - [2003/11/17 20:56:26 | 001,042,432 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSF_DP.sys -- (HSF_DP)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..\SearchScopes\{EF88FBE5-A333-41C1-A8D1-FEB210179659}: "URL" =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="
FF - prefs.js..browser.startup.homepage: "
www.google.com"
FF - prefs.js..extensions.enabledAddons: %7B65e41d20-f092-41b7-bb83-c6e8a9ab0f57%7D:1.2.1
FF - prefs.js..extensions.enabledAddons: %7B66E978CD-981F-47DF-AC42-E3CF417C1467%7D:0.4.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:27.0
FF - prefs.js..extensions.enabledItems: {66E978CD-981F-47DF-AC42-E3CF417C1467}:0.4.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems:
jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.911
FF - prefs.js..extensions.enabledItems: {65e41d20-f092-41b7-bb83-c6e8a9ab0f57}:1.0
FF - prefs.js..keyword.enabled: false
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf: C:\PROGRAM FILES\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.45.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Main\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Documents and Settings\Main\Application Data\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Main\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Main\Local Settings\Application Data\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Main\Local Settings\Application Data\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 27.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2014/02/05 11:43:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 24.3.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2009/12/10 23:38:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Extensions
[2009/12/10 23:38:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009/03/13 20:44:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Extensions\
uploadr@flickr.com
[2014/01/29 17:42:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Firefox\Profiles\ri1alb3k.default\extensions
[2010/05/17 20:56:30 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Main\Application Data\Mozilla\Firefox\Profiles\ri1alb3k.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/07 12:35:51 | 000,000,000 | ---D | M] (New Tab Homepage) -- C:\Documents and Settings\Main\Application Data\Mozilla\Firefox\Profiles\ri1alb3k.default\extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}
[2009/12/02 23:30:12 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Sunbird\Profiles\rn6hdk6z.default\extensions
[2009/12/02 23:29:18 | 000,000,000 | ---D | M] (Provider for Google Calendar) -- C:\Documents and Settings\Main\Application Data\Mozilla\Sunbird\Profiles\rn6hdk6z.default\extensions\{a62ef8ec-5fdc-40c2-873c-223b8a6925cc}
[2013/04/09 21:45:03 | 000,046,841 | ---- | M] () (No name found) -- C:\Documents and Settings\Main\Application Data\Mozilla\Firefox\Profiles\ri1alb3k.default\extensions\{65e41d20-f092-41b7-bb83-c6e8a9ab0f57}.xpi
[2014/02/05 11:43:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\browser\extensions
[2014/02/05 11:43:41 | 000,000,000 | ---D | M] (Default) -- C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
O1 HOSTS File: ([2014/02/08 13:28:58 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Fitbit Connect] C:\Program Files\Fitbit Connect\Fitbit Connect.exe (Fitbit, Inc.)
O4 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005..\Run: [Fitbit Connect] C:\Program Files\Fitbit Connect\Fitbit Connect.exe (Fitbit, Inc.)
O4 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\DocketSCAN II.lnk = C:\Program Files\DocuCap\DocketSCAN II\DocketSCAN.exe (Document Capture Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\Main\Start Menu\Programs\Startup\Moo0 Window Menu Plus 1.16.lnk = C:\Program Files\Moo0\WindowMenuPlus 1.16\WindowMenuPlus.exe (Moo0)
O4 - Startup: C:\Documents and Settings\United Automated\Start Menu\Programs\Startup\DocketSCAN II.lnk = C:\Program Files\DocuCap\DocketSCAN II\DocketSCAN.exe (Document Capture Technologies, Inc.)
O4 - Startup: C:\Documents and Settings\United Automated\Start Menu\Programs\Startup\Moo0 Window Menu Plus 1.16.lnk = C:\Program Files\Moo0\WindowMenuPlus 1.16\WindowMenuPlus.exe (Moo0)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..Trusted Domains: microsoft.com ([v4.windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..Trusted Domains: microsoft.com ([windowsupdate] http in Trusted sites)
O15 - HKU\S-1-5-21-1783572605-1027540281-3929261840-1005\..Trusted Domains: windowsupdate.com ([download] http in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.microsoft.com/download/E/3/9/E39C664F-A8E3-4F69-A109-1AE9849204EE/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4505-8fb8-d0d2d160e512/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273545058640 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Value error.)
O16 - DPF: {C7DB51B4-BCF7-4923-8874-7F1A0DC92277}
http://office.microsoft.com/officeupdate/content/opuc4.cab (Office Update Installation Engine)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 10.45.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0561BE97-5170-46A7-BA38-B64E1E1D5429}: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/16 16:40:07 | 000,000,095 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2014/02/08 14:03:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2014/02/08 13:58:13 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/02/08 13:56:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Main\Desktop\OTL.exe
[2014/02/08 13:56:50 | 001,037,530 | ---- | C] (Thisisu) -- C:\Documents and Settings\Main\Desktop\JRT.exe
[2014/02/08 13:56:44 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2014/02/08 13:07:01 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2014/02/08 08:47:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Application Data\TuneUp Software
[2014/02/08 08:44:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Local Settings\Application Data\MFAData
[2014/02/08 08:44:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2014/02/08 08:44:08 | 004,436,944 | ---- | C] (AVG Technologies) -- C:\Documents and Settings\Main\Desktop\avg_free_stb_all_2014_4259_cnet.exe
[2014/02/07 13:34:58 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2014/02/07 13:34:58 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2014/02/07 13:34:58 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2014/02/07 13:34:58 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2014/02/07 13:34:15 | 000,000,000 | ---D | C] -- C:\Qoobox
[2014/02/07 13:19:29 | 012,217,544 | ---- | C] (OPSWAT, Inc.) -- C:\Documents and Settings\Main\Desktop\AppRemover.exe
[2014/02/07 13:16:54 | 005,180,173 | R--- | C] (Swearware) -- C:\Documents and Settings\Main\Desktop\ComboFix.exe
[2014/02/07 11:39:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes' Anti-Malware (portable)
[2014/02/07 11:38:42 | 000,052,312 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/02/07 11:38:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Desktop\mbar
[2014/02/07 11:37:21 | 012,589,848 | ---- | C] (Malwarebytes Corp.) -- C:\Documents and Settings\Main\Desktop\mbar-1.07.0.1009.exe
[2014/02/07 11:27:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Desktop\RK_Quarantine
[2014/02/06 04:11:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\TeamViewer 9
[2014/02/05 17:05:07 | 000,688,992 | R--- | C] (Swearware) -- C:\Documents and Settings\Main\Desktop\dds.com
[2014/02/05 12:05:20 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Thunderbird
[2014/02/05 11:43:22 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox
[2014/01/28 10:59:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Application Data\tinySpell
[2014/01/26 20:06:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Main\Desktop\Karpack
[2014/01/20 10:23:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Fitbit Connect
[2014/01/20 10:22:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\FitbitConnect
[2014/01/20 10:22:56 | 000,000,000 | ---D | C] -- C:\Program Files\Fitbit Connect
[2014/01/15 14:01:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Foxit Software
[2014/01/15 12:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\FOXIT SOFTWARE
[2014/01/13 10:32:02 | 000,073,368 | ---- | C] (Hola Networks Ltd.) -- C:\WINDOWS\System32\drivers\hola_mon_drv.sys
========== Files - Modified Within 30 Days ==========
[2014/02/08 14:42:00 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2014/02/08 14:32:00 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2014/02/08 14:08:00 | 000,000,974 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1783572605-1027540281-3929261840-1005UA.job
[2014/02/08 14:05:25 | 000,483,004 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2014/02/08 14:05:25 | 000,080,408 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2014/02/08 14:02:16 | 000,000,761 | ---- | M] () -- C:\Documents and Settings\Main\Start Menu\Programs\Startup\DocketSCAN II.lnk
[2014/02/08 14:01:11 | 000,000,878 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2014/02/08 14:01:07 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2014/02/08 14:01:05 | 3219,279,872 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/08 13:57:00 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Main\Desktop\OTL.exe
[2014/02/08 13:56:52 | 001,037,530 | ---- | M] (Thisisu) -- C:\Documents and Settings\Main\Desktop\JRT.exe
[2014/02/08 13:56:36 | 001,166,132 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\adwcleaner.exe
[2014/02/08 13:28:58 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2014/02/08 12:08:56 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{A16C0537-1C6B-4FDD-BED4-67BCC7B25F24}.job
[2014/02/08 08:44:18 | 004,436,944 | ---- | M] (AVG Technologies) -- C:\Documents and Settings\Main\Desktop\avg_free_stb_all_2014_4259_cnet.exe
[2014/02/08 00:08:00 | 000,000,922 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1783572605-1027540281-3929261840-1005Core.job
[2014/02/07 13:20:04 | 012,217,544 | ---- | M] (OPSWAT, Inc.) -- C:\Documents and Settings\Main\Desktop\AppRemover.exe
[2014/02/07 13:17:00 | 005,180,173 | R--- | M] (Swearware) -- C:\Documents and Settings\Main\Desktop\ComboFix.exe
[2014/02/07 11:38:42 | 000,052,312 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamchameleon.sys
[2014/02/07 11:37:28 | 012,589,848 | ---- | M] (Malwarebytes Corp.) -- C:\Documents and Settings\Main\Desktop\mbar-1.07.0.1009.exe
[2014/02/07 11:25:26 | 003,809,792 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\RogueKiller.exe
[2014/02/06 15:59:36 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\Application Data\prvlcl.dat
[2014/02/06 11:32:58 | 000,193,696 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\2014 Co 1 Roster for Web.pdf
[2014/02/06 04:11:52 | 000,000,815 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 9.lnk
[2014/02/05 17:05:09 | 000,688,992 | R--- | M] (Swearware) -- C:\Documents and Settings\Main\Desktop\dds.com
[2014/02/04 17:05:42 | 000,038,021 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\NJSUCCESS.pdf
[2014/02/04 14:36:57 | 000,100,696 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\Chelsea Passport App.pdf
[2014/01/31 09:45:25 | 000,049,664 | ---- | M] () -- C:\Documents and Settings\Main\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/01/29 16:55:40 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/01/29 15:52:23 | 000,281,350 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\chupa.jpg
[2014/01/27 15:31:40 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2014/01/27 15:29:22 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2014/01/20 13:29:46 | 000,001,769 | ---- | M] () -- C:\Documents and Settings\Main\Desktop\Google Drive.lnk
[2014/01/15 03:16:32 | 000,190,592 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2014/01/13 10:32:02 | 000,073,368 | ---- | M] (Hola Networks Ltd.) -- C:\WINDOWS\System32\drivers\hola_mon_drv.sys
========== Files Created - No Company Name ==========
[2014/02/08 13:56:34 | 001,166,132 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\adwcleaner.exe
[2014/02/07 13:34:58 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2014/02/07 13:34:58 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2014/02/07 13:34:58 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2014/02/07 13:34:58 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2014/02/07 13:34:58 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2014/02/07 13:26:08 | 000,158,674 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1783572605-1027540281-3929261840-1007-0.dat
[2014/02/07 11:25:20 | 003,809,792 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\RogueKiller.exe
[2014/02/06 11:00:52 | 000,193,696 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\2014 Co 1 Roster for Web.pdf
[2014/02/04 17:05:41 | 000,038,021 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\NJSUCCESS.pdf
[2014/02/04 14:31:03 | 000,100,696 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\Chelsea Passport App.pdf
[2014/01/29 16:55:40 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2014/01/29 15:50:54 | 000,281,350 | ---- | C] () -- C:\Documents and Settings\Main\Desktop\chupa.jpg
[2014/01/27 15:29:22 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2014/01/11 20:52:55 | 000,000,815 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TeamViewer 9.lnk
[2013/11/10 10:52:39 | 000,216,064 | ---- | C] () -- C:\WINDOWS\System32\gcapi_dll.dll
[2012/04/14 02:32:09 | 003,379,098 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1783572605-1027540281-3929261840-1005-0.dat
[2012/04/14 02:32:08 | 000,158,674 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/04/12 19:11:45 | 000,000,744 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Microsoft.SqlServer.Compact.400.32.bc
[2012/02/15 09:04:40 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2010/05/17 19:24:05 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Main\Local Settings\Application Data\prvlcl.dat
[2009/03/24 19:52:45 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Limiter
[2009/03/24 19:51:24 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\Licenses
[2009/03/11 17:02:16 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdw.DAT
[2009/03/11 17:02:16 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\Logs
[2009/03/11 17:00:15 | 000,000,000 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLdu.DAT
[2009/03/11 17:00:15 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\Light Machine
[2008/10/15 17:29:03 | 000,038,444 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\Microsoft Excel.ADR
[2007/05/28 19:06:45 | 000,003,584 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\dvd.bmk
[2006/07/11 16:47:24 | 000,002,170 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/06/14 16:10:43 | 000,061,678 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\PFP120JPR.{PB
[2006/06/14 16:10:43 | 000,012,358 | ---- | C] () -- C:\Documents and Settings\Main\Application Data\PFP120JCM.{PB
[2006/06/14 09:36:52 | 000,049,664 | ---- | C] () -- C:\Documents and Settings\Main\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/06/12 21:21:13 | 000,000,127 | ---- | C] () -- C:\Documents and Settings\Main\Local Settings\Application Data\fusioncache.dat
========== ZeroAccess Check ==========
[2005/08/16 03:39:16 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 19:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 07:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 19:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/03/15 08:44:12 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/07/30 11:34:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DocuCap
[2009/03/11 17:02:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2014/01/20 10:23:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FitbitConnect
[2006/08/13 21:39:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HotSync
[2009/03/20 17:36:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\livepim
[2014/02/08 13:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2008/07/24 15:14:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Musicnotes
[2008/02/16 16:44:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2008/02/16 16:36:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio
[2014/02/05 15:54:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sonos,_Inc
[2009/03/11 17:02:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2011/02/03 07:10:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2013/08/12 15:04:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Foxit Software
[2009/07/17 18:47:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\TeamViewer
[2009/01/02 21:19:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/09/02 22:33:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\DVDVideoSoft
[2009/03/25 17:49:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\EBookSys
[2009/03/13 20:44:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Flickr
[2014/01/15 12:44:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Foxit Software
[2010/02/06 15:25:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\HandBrake
[2006/08/13 21:38:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\HotSync
[2006/08/13 21:42:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Leadertech
[2013/09/13 11:05:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Mp3tag
[2011/07/30 11:35:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\NewSoft
[2009/03/11 17:16:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Nikon
[2009/03/20 17:30:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\OfficeUpdate12
[2008/01/28 19:14:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Opera
[2010/05/14 15:57:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\proDAD
[2012/09/03 16:55:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\RoboBasket3
[2013/12/03 11:15:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\TeamViewer
[2009/12/10 23:37:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Thunderbird
[2014/01/28 11:00:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\tinySpell
[2014/02/08 08:47:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\TuneUp Software
[2008/04/10 18:47:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Main\Application Data\Yapta
[2014/01/15 12:45:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\United Automated\Application Data\Foxit Software
[2014/01/24 05:03:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\United Automated\Application Data\TeamViewer
[2014/01/06 11:48:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\United Automated\Application Data\Thunderbird
========== Purity Check ==========
< End of report >