.
DDS (Ver_2011-08-26.01) - NTFSAMD64
Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 1.6.0_31
Run by JAMSYM at 18:41:09 on 2012-05-26
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.44.1033.18.4095.1002 [GMT 1:00]
.
AV: COMODO Antivirus *Disabled/Updated* {458BB331-2324-0753-3D5F-1472EB102AC0}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: COMODO Defense+ *Disabled/Updated* {FEEA52D5-051E-08DD-07EF-2F009097607D}
FW: COMODO Firewall *Disabled* {7DB03214-694B-060B-1600-BD4715C36DBB}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files (x86)\3 Mobile Broadband\3Connect\BecHelperService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
C:\Windows\SysWOW64\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\pg_ctl.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Windows\system32\conhost.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files (x86)\PostgreSQL\8.3\bin\postgres.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\ModLEDKey.exe
C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe
C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
C:\Program Files (x86)\hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\CNYHKEY.exe
C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe
C:\Program Files (x86)\Panda USB Vaccine\USBVaccine.exe
C:\Windows\system32\DllHost.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Windows Live\Companion\companionuser.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\System32\svchost.exe -k swprv
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
c:\program files\windows defender\MpCmdRun.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\system32\conhost.exe
C:\Windows\SysWOW64\cscript.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://
www.google.co.uk/
uDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Pavilion&pf=cndt
mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Pavilion&pf=cndt
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_GB&c=94&bd=Pavilion&pf=cndt
uInternet Settings,ProxyOverride = *.local
mWinlogon: Userinit=userinit.exe,
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: Babylon toolbar helper: {2eecd738-5844-4a99-b4b6-146bf802613b} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: Internet Explorer Form-Fill Plug-In: {5425b4b8-87f9-4e9c-8b51-8aaba82eba64} - C:\Program Files (x86)\NETELLER app\plugins\IE\Neteller.dll
BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO: AOL Toolbar BHO: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: DealPly: {a6174f27-1fff-e1d6-a93f-ba48ad5dd448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB: AOL Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
TB: Babylon Toolbar: {98889811-442d-49dd-99d7-dc866be87dbc} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
uRun: [HPADVISOR] C:\Program Files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe view=DOCKVIEW
uRun: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
uRun: [Google Update] "C:\Users\JAMSYM\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [NETELLER app] "C:\Program Files (x86)\NETELLER app\NETELLER-app.exe" /BOOT
uRun: [CPN Notifier] C:\Program Files (x86)\Cake Poker 2.0\PokerNotifier.exe
uRun: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
mRun: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
mRun: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [<NO NAME>]
mRun: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
mRun: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &AOL Toolbar Search - C:\ProgramData\AOL\ieToolbar\resources\en-GB\local\search.html
IE: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
IE: {90EAE591-7E7E-434a-8E28-ECFD00071806} - C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe
IE: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
IE: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} - hxxp://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{EB4FA4E2-540B-4B62-B359-EB3AFC563BE7} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{EB4FA4E2-540B-4B62-B359-EB3AFC563BE7}\244564F4E4 : DhcpNameServer = 192.168.22.22 192.168.22.23
TCP: Interfaces\{EB4FA4E2-540B-4B62-B359-EB3AFC563BE7}\244584F6D656845726D244236373 : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{EB4FA4E2-540B-4B62-B359-EB3AFC563BE7}\2445F40756E6A7F6E656 : DhcpNameServer = 192.168.22.22 192.168.22.23
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
AppInit_DLLs: C:\Windows\SysWOW64\guard32.dll
SEH: EasyBits ShellExecute Hook: {e54729e8-bb3d-4270-9d49-7389ea579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
mASetup: {2D46B6DC-2207-486B-B523-A557E6D54B47} - C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
BHO-X64: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO-X64: AcroIEHelperStub - No File
BHO-X64: Babylon toolbar helper: {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\bh\BabylonToolbar.dll
BHO-X64: Babylon toolbar helper - No File
BHO-X64: RealPlayer Download and Record Plugin for Internet Explorer: {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO-X64: Internet Explorer Form-Fill Plug-In: {5425B4B8-87F9-4E9C-8B51-8AABA82EBA64} - C:\Program Files (x86)\NETELLER app\plugins\IE\Neteller.dll
BHO-X64: NetellerBHO - No File
BHO-X64: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll
BHO-X64: AOL Toolbar BHO: {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
BHO-X64: AOL Toolbar BHO - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO-X64: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO-X64: DealPly: {A6174F27-1FFF-E1D6-A93F-BA48AD5DD448} - C:\Program Files (x86)\DealPly\DealPlyIE.dll
BHO-X64: Google Toolbar Helper: {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
BHO-X64: Skype Browser Helper: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO-X64: SkypeIEPluginBHO - No File
BHO-X64: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
TB-X64: AOL Toolbar: {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files (x86)\AOL\AOL Toolbar 5.0\aoltb.dll
TB-X64: Babylon Toolbar: {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.5.3.17\BabylonToolbarTlbr.dll
TB-X64: Google Toolbar: {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
mRun-x64: [hpsysdrv] c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe
mRun-x64: [BATINDICATOR] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\BATINDICATOR.exe
mRun-x64: [LaunchHPOSIAPP] C:\Program Files (x86)\Hewlett-Packard\HP MAINSTREAM KEYBOARD\LaunchApp.exe
mRun-x64: [HP Remote Solution] %ProgramFiles%\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe
mRun-x64: [HP Software Update] c:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun-x64: [(Default)]
mRun-x64: [NortonOnlineBackupReminder] "C:\Program Files (x86)\Symantec\Norton Online Backup\Activation\NobuActivation.exe" UNATTENDED
mRun-x64: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe
mRun-x64: [UpdatePRCShortCut] "C:\Program Files (x86)\Hewlett-Packard\Recovery\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Hewlett-Packard\Recovery" UpdateWithCreateOnce "Software\CyberLink\PowerRecover"
mRun-x64: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun-x64: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
mRun-x64: [TkBellExe] "C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe" -osboot
mRun-x64: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
mRun-x64: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun-x64: [COMODO] C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLA.exe
mRun-x64: [CPA] C:\Program Files\COMODO\COMODO GeekBuddy\VALA.exe
IE-X64: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe
IE-X64: {90EAE591-7E7E-434a-8E28-ECFD00071806} - C:\Program Files (x86)\PokerStars.FR\PokerStarsUpdate.exe
IE-X64: {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe
IE-X64: {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files (x86)\Bodog Poker\BPGame.exe
IE-X64: {00710644-edb6-40fb-b3e2-51b615e97d5a} - C:\Users\JAMSYM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RPM Poker\RPM Poker.lnk
IE-X64: {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - C:\Users\JAMSYM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\UB\UB.lnk
IE-X64: {20791AD6-CD8D-47AB-AB10-D27ACC73728F} - C:\Microgaming\Poker\PokerTimeMPP\MPPoker.exe
IE-X64: {34DCB6F7-1F17-48EC-9652-F1C978E96E88} - C:\Microgaming\Poker\stanjamesgibMPP\MPPoker.exe
IE-X64: {e4e8c758-34b4-44bb-8ef9-1f0786e81d2d} - C:\Users\JAMSYM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CarbonPoker\CarbonPoker.lnk
AppInit_DLLs-X64: C:\Windows\SysWOW64\guard32.dll
SEH-X64: EasyBits ShellExecute Hook: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWow64\EZUPBH~1.DLL
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\
FF - prefs.js: browser.search.selectedEngine -
FF - prefs.js: browser.startup.homepage - hxxp://search.babylon.com/?babsrc=HP_ss&affID=101385&mntrId=c41f998a00000000000000225feb9783
FF - component: C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
FF - component: C:\Program Files (x86)\NETELLER app\plugins\Firefox\neteller\components\Neteller.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordext.dll
FF - component: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext\components\nprpffbrowserrecordlegacyext.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko10.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko11.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko12.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko19.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko5.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko6.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko7.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko8.dll
FF - component: C:\Users\JAMSYM\AppData\Roaming\Mozilla\Firefox\Profiles\ga8dgjuk.default\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}\components\RadioWMPCoreGecko9.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.93\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.21.99\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\npjpi160_31.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Users\JAMSYM\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
FF - Ext: ST-Eng7 Community Toolbar: {414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3} - %profile%\extensions\{414b6d9d-4a95-4e8d-b5b1-149dd2d93bb3}
FF - Ext: Babylon:
ffxtlbr@babylon.com - %profile%\extensions\
ffxtlbr@babylon.com
FF - Ext: DealPly: {EB9394A3-4AD6-4918-9537-31A1FD8E8EDF} - %profile%\extensions\{EB9394A3-4AD6-4918-9537-31A1FD8E8EDF}
FF - Ext: NETELLER:
neteller.desktop@klipfolio - C:\Program Files (x86)\NETELLER app\plugins\Firefox\neteller
FF - Ext: RealPlayer Browser Record Plugin: {ABDE892B-13A8-4d1b-88E6-365A6E755758} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext
.
---- FIREFOX POLICIES ----
FF - user.js: extensions.BabylonToolbar_i.id - c41f998a00000000000000225feb9783
FF - user.js: extensions.BabylonToolbar_i.hardId - c41f998a00000000000000225feb9783
FF - user.js: extensions.BabylonToolbar_i.instlDay - 15413
FF - user.js: extensions.BabylonToolbar_i.vrsn - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsni - 1.5.3.17
FF - user.js: extensions.BabylonToolbar_i.vrsnTs - 1.5.3.1713:59:01
FF - user.js: extensions.BabylonToolbar_i.prtnrId - babylon
FF - user.js: extensions.BabylonToolbar_i.prdct - BabylonToolbar
FF - user.js: extensions.BabylonToolbar_i.aflt - babsst
FF - user.js: extensions.BabylonToolbar_i.smplGrp - none
FF - user.js: extensions.BabylonToolbar_i.tlbrId - base
FF - user.js: extensions.BabylonToolbar_i.newTab - false
FF - user.js: extensions.BabylonToolbar_i.babTrack - affID=101385
FF - user.js: extensions.BabylonToolbar_i.babExt -
FF - user.js: extensions.BabylonToolbar_i.srcExt - ss
FF - user.js: extensions.BabylonToolbar_i.instlRef - sst
.
user_pref('extensions.dealply.partner', 'vita');
.
user_pref('extensions.dealply.channel', 'vitafilewin');
.
user_pref('extensions.dealply.installId', 'v23500256101115962458192012031413591739');
.
user_pref('extensions.dealply.installIdSource', 'inst');
.
user_pref('extensions.dealply.sampleGroup', '9');
.
============= SERVICES / DRIVERS ===============
.
R1 cmderd;COMODO Internet Security Eradication Driver;C:\Windows\system32\DRIVERS\cmderd.sys --> C:\Windows\system32\DRIVERS\cmderd.sys [?]
R1 cmdGuard;COMODO Internet Security Sandbox Driver;C:\Windows\system32\DRIVERS\cmdguard.sys --> C:\Windows\system32\DRIVERS\cmdguard.sys [?]
R1 cmdHlp;COMODO Internet Security Helper Driver;C:\Windows\system32\DRIVERS\cmdhlp.sys --> C:\Windows\system32\DRIVERS\cmdhlp.sys [?]
R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?]
R2 {55662437-DA8C-40c0-AADA-2C816A897A49};Power Control [2010/03/22 08:06:15];C:\Program Files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2010-3-22 146928]
R2 BecHelperService;BecHelperService;C:\Program Files (x86)\3 Mobile Broadband\3Connect\BecHelperService.exe [2010-10-5 1737464]
R2 CLPSLS;COMODO livePCsupport Service;C:\Program Files\COMODO\COMODO GeekBuddy\CLPSLS.exe [2011-11-23 1267000]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
R2 DragonUpdater;COMODO Dragon Update Service;C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2012-5-16 412304]
R2 ezSharedSvc;Easybits Shared Services for Windows;C:\Windows\system32\svchost.exe -k netsvcs [2009-7-14 20992]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2011-9-9 86072]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-3-28 94264]
R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-5-25 654408]
R2 postgresql-8.3;PostgreSQL Server 8.3;C:/Program Files (x86)/PostgreSQL/8.3/bin/pg_ctl.exe runservice -N "postgresql-8.3" -D "C:/Program Files (x86)/PostgreSQL/8.3/data" -w --> C:/Program Files (x86)/PostgreSQL/8.3/bin/pg_ctl.exe runservice -N postgresql-8.3 [?]
R2 Skype C2C Service;Skype C2C Service;C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe [2012-4-9 3063968]
R2 TeamViewer7;TeamViewer 7;C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2012-2-23 2666880]
R3 AVER_H193;AVerMedia H193 Video Capture;C:\Windows\system32\drivers\AVer888RC_64.sys --> C:\Windows\system32\drivers\AVer888RC_64.sys [?]
R3 CXCIR;AVerMedia Consumer Infrared Receiver;C:\Windows\system32\DRIVERS\AVer888RCIR_64.sys --> C:\Windows\system32\DRIVERS\AVer888RCIR_64.sys [?]
R3 MBAMProtector;MBAMProtector;\??\C:\Windows\system32\drivers\mbam.sys --> C:\Windows\system32\drivers\mbam.sys [?]
R3 netr7364;RT73 USB Extensible Wireless LAN Card Driver;C:\Windows\system32\DRIVERS\netr7364.sys --> C:\Windows\system32\DRIVERS\netr7364.sys [?]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;C:\Windows\system32\drivers\nvhda64v.sys --> C:\Windows\system32\drivers\nvhda64v.sys [?]
S2 gupdate;Google Update Service (gupdate);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-4 136176]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-29 158856]
S2 VMCService;Vodafone Mobile Connect Service;C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2009-9-18 9216]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-12 257696]
S3 gupdatem;Google Update Service (gupdatem);C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-11-4 136176]
S3 massfilter;ZTE Mass Storage Filter Driver;C:\Windows\System32\drivers\massfilter.sys [2009-9-7 9216]
S3 Netaapl;Apple Mobile Device Ethernet Service;C:\Windows\system32\DRIVERS\netaapl64.sys --> C:\Windows\system32\DRIVERS\netaapl64.sys [?]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe --> C:\Windows\system32\Wat\WatAdminSvc.exe [?]
.
=============== Created Last 30 ================
.
2012-05-26 16:10:40 -------- d-----w- C:\ProgramData\Panda Security
2012-05-26 16:10:34 -------- d-----w- C:\Program Files (x86)\Panda USB Vaccine
2012-05-26 12:37:34 -------- d-----w- C:\ProgramData\CPA_VA
2012-05-26 12:36:53 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{5BDB4677-B72E-404C-95E8-5415956DB861}
2012-05-26 12:36:34 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{37D06FAD-E36C-4FB2-8722-95F4DA81EF20}
2012-05-26 12:36:15 -------- d--h--w- C:\VritualRoot
2012-05-26 12:01:19 -------- d-----w- C:\ProgramData\Comodo
2012-05-26 12:01:15 -------- d-----w- C:\Program Files\COMODO
2012-05-26 12:01:09 -------- d-----w- C:\Users\JAMSYM\AppData\Local\Comodo
2012-05-26 12:00:59 -------- d-----w- C:\Program Files (x86)\Comodo
2012-05-25 17:22:50 -------- d-----w- C:\Program Files (x86)\SkyPoker
2012-05-25 16:21:41 -------- d-----w- C:\Users\JAMSYM\AppData\Roaming\Malwarebytes
2012-05-25 16:21:37 24904 ----a-w- C:\Windows\System32\drivers\mbam.sys
2012-05-25 16:21:37 -------- d-----w- C:\ProgramData\Malwarebytes
2012-05-25 16:21:37 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-05-25 16:00:42 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{4EFA9B4D-C769-41C7-BCC1-35B11BAF10B5}
2012-05-25 16:00:32 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{6E5CBD6E-E1D5-4355-A743-42E2C220CDE5}
2012-05-23 15:18:55 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{F0CA11F5-AF3E-4A44-B034-7B61B9D238F5}
2012-05-23 15:18:33 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{AA512BBD-B3F2-40C5-A05A-4BDB7B8094A3}
2012-05-23 03:18:19 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{25312D7D-D498-4DC6-A398-FC0D188D84FC}
2012-05-23 03:17:57 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{0F055BCE-51AB-4B29-9D53-02D3A08F8DB0}
2012-05-22 15:15:54 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{D7C1984F-F41A-49ED-9DEE-43E5D0BCAB0C}
2012-05-22 15:14:41 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{3A308B94-17B4-4B17-826A-791350BF0C58}
2012-05-22 12:47:32 -------- d-----w- C:\DOSGAMES
2012-05-22 12:44:55 -------- d-----w- C:\Program Files (x86)\DOSBox-0.74
2012-05-22 03:10:45 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{C30E7BE3-642F-4A9B-9365-9E19F1A124EE}
2012-05-22 03:10:35 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{CF361608-2C51-4ED8-89C6-AA16CC92C81A}
2012-05-21 15:10:09 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9E6562C8-2D6B-4804-89EA-74778CBB461D}
2012-05-21 15:09:47 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{8A03C5C1-BF81-4B83-B181-01212AF40B44}
2012-05-21 12:19:28 -------- d-----w- C:\Users\JAMSYM\VirtualBox VMs
2012-05-21 12:18:41 -------- d-----w- C:\Users\JAMSYM\.VirtualBox
2012-05-21 12:18:11 224048 ----a-w- C:\Windows\System32\drivers\VBoxDrv.sys
2012-05-21 12:17:59 130864 ----a-w- C:\Windows\System32\drivers\VBoxUSBMon.sys
2012-05-21 11:33:07 -------- d-----w- C:\Program Files (x86)\Maxis
2012-05-21 11:17:04 304128 ----a-w- C:\Windows\IsUninst.exe
2012-05-21 03:09:19 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9D0AF7AF-AAB9-46C3-9750-333275F6B3AC}
2012-05-21 03:08:57 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{CE69A348-113F-4130-8014-6434161D3B0A}
2012-05-20 15:08:40 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E4BD2B26-9DF9-4DA1-8E07-917E0719D21B}
2012-05-20 15:08:18 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E845B396-F516-4350-BA16-96EDE6A7C189}
2012-05-20 03:08:04 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{D087676C-694B-428D-A8F3-288DE51A6B18}
2012-05-20 03:07:39 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{50F5C98B-CBBF-4789-999C-749F5836EB5F}
2012-05-19 15:07:25 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{1C2FE063-FD35-4233-B66C-40CFC30A6331}
2012-05-19 15:07:03 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{D5252A37-60BA-4ACE-B7C3-E5C407987399}
2012-05-19 03:06:50 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{6EF8903A-B210-4EEE-9BE8-7F3B1B3F7D92}
2012-05-19 03:06:28 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9DF9E1BC-BC3A-40F1-8303-94060ADB2CD8}
2012-05-18 15:06:13 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{FC24E416-A07A-4B80-8A03-04D210B43B96}
2012-05-18 15:05:51 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{5055FCEC-594F-4570-A68B-E67540648527}
2012-05-18 03:05:37 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9B889142-0914-46AB-B9DF-9C8A42AB8600}
2012-05-18 03:05:16 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{F8D39158-E403-4D12-902C-35C0F73A517D}
2012-05-17 15:05:03 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9997EEDB-3832-43D5-B6E9-C67F0F35BAAD}
2012-05-17 15:04:40 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{375C3557-F8C7-4F9C-8C57-9D921623B76A}
2012-05-17 03:04:29 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{0D5D598A-A99B-4D04-AF60-B9F95590E9C5}
2012-05-17 03:04:07 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{CB9D1694-1802-4E11-A4BF-FFDBAB9AEB82}
2012-05-16 15:03:55 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{578E0376-997A-4B54-B937-03A0B79C1D86}
2012-05-16 15:03:33 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{A954B465-EDE8-45C4-B053-C2F1D41D360D}
2012-05-16 03:03:13 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{C0061663-7194-4207-9A50-06D41CAEDB8A}
2012-05-16 03:03:02 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E6CD64AB-AD6D-4EB3-97BC-3035369C4C1A}
2012-05-15 14:40:44 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{5B2B6AB4-0685-40AB-A080-F64AAB6CF977}
2012-05-15 14:40:22 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{18F4324D-BA26-4DD8-903B-DD0E0C467467}
2012-05-15 02:40:09 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{A89624F3-4D6D-4A30-9857-1F1AFA63E263}
2012-05-15 02:39:47 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{648D926A-91F7-4BF7-8C98-B339A0A438C5}
2012-05-14 19:36:37 -------- d-----w- C:\ProgramData\boost_interprocess
2012-05-14 14:39:35 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{A1CC4312-374E-4A43-A8A1-BC4A7E5C9851}
2012-05-14 14:39:13 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{A537E9BF-C72C-4FAA-96A5-8F5203ED274F}
2012-05-14 02:39:00 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{519FB6C5-C696-4F3D-8AB4-DD4606AF79DB}
2012-05-14 02:38:38 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E1777018-E870-47E6-A84E-4394A2EB3456}
2012-05-13 14:38:22 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{809299F5-9C9D-444F-BA34-62DCF99C8249}
2012-05-13 14:37:58 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{621655B8-8F38-41DC-A9CD-884C892C5DBE}
2012-05-13 01:56:41 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{2C93621A-B31F-4754-B1A8-2E43A661037B}
2012-05-13 01:56:20 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{0DF7D9F6-4C1D-407F-93E5-057E56B794F6}
2012-05-12 13:56:07 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{3FEA885D-4C86-4E11-B502-9A28B3E2281E}
2012-05-12 13:55:45 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{0CF9C18B-5D7A-4A74-94F6-67A3547D213B}
2012-05-12 01:55:32 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{FBF8F876-4899-4411-9C79-55080CDF8982}
2012-05-12 01:55:10 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{683945E4-9466-4156-B49A-27A9BD1CEE3F}
2012-05-11 13:54:55 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{BA4DB30E-040B-41B6-AAAC-D10C60769AF4}
2012-05-11 13:54:40 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{B913CA4B-969A-488B-AC94-B3E37DBF48E9}
2012-05-10 23:41:47 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{BE6C5962-386A-4E76-A39B-0C8CCCBF04CD}
2012-05-10 23:41:25 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{0AB65314-7830-4066-9995-AB9B17D10AFA}
2012-05-10 11:41:14 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{DF6F234D-6845-4F5A-80A5-06F7DBA21AD8}
2012-05-10 11:40:52 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{274BA458-697C-49AE-BD3E-7008DC3D00DE}
2012-05-09 23:40:39 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{20DA6661-5141-43E7-9D81-B6828D38314D}
2012-05-09 23:40:18 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{65795992-31B0-4B1B-BB91-807848950C46}
2012-05-09 11:40:05 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9648BCA8-7119-4760-844E-FCD4A6BFFDCA}
2012-05-09 11:39:43 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{4BF09ABD-0834-41FA-81CC-E2752401C204}
2012-05-08 23:39:30 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{1D6ABCFE-4195-46AE-8A7E-0D168908F6D0}
2012-05-08 23:39:08 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{64564C9C-7B3A-4B72-A9F0-C9BD186A6FA7}
2012-05-08 11:38:54 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{6C380728-A2C3-42FE-B475-7D79D6D3A582}
2012-05-08 11:38:40 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{3795531A-08A4-4C7F-BB40-5F428232F143}
2012-05-07 16:59:51 -------- d-----w- C:\Windows\en
2012-05-07 16:53:17 89944 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e664e1701cd2c7101\DSETUP.dll
2012-05-07 16:53:17 537432 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e664e1701cd2c7101\DXSETUP.exe
2012-05-07 16:53:17 1801048 ----a-w- C:\Program Files (x86)\Common Files\Windows Live\.cache\e664e1701cd2c7101\dsetup32.dll
2012-05-07 16:52:42 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{4BD0310B-A0A8-40B0-9A27-C4B61EB03ECF}
2012-05-07 16:52:21 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{B14BC67A-23DC-4CE5-9AB1-C839BA445C68}
2012-05-05 10:14:53 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{2D9126CA-D70E-4DA7-A2E3-DB93F12263E7}
2012-05-05 10:14:28 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{9BEA89CF-6D4B-4327-AF25-30FC4EF041CE}
2012-05-05 09:10:40 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{4E36DA14-6BCA-4760-BD47-88F2975DD3FD}
2012-05-05 09:10:20 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{126989DE-7116-4A29-97B4-22A39BB1F5F5}
2012-05-04 10:00:17 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{5BC2ABB3-6474-4364-8D76-757E030B7D7E}
2012-05-04 09:59:57 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{11F76A88-7D49-4D41-A664-D2F12CBF2C67}
2012-05-03 14:38:28 77312 ----a-w- C:\Windows\System32\rdpwsx.dll
2012-05-03 14:38:28 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll
2012-05-03 14:33:48 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{51CA3E04-5B66-4CEE-A68F-739BB7E84468}
2012-05-03 14:33:23 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E6F4457F-B9E7-4B71-B34E-672493DC13D0}
2012-05-03 14:09:23 -------- d-----w- C:\Windows\System32\SPReview
2012-05-03 14:08:30 -------- d-----w- C:\Windows\System32\EventProviders
2012-05-03 14:02:21 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{C7B52A58-7EAA-4A47-8BC5-EA2745897C91}
2012-05-03 09:38:30 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E78D037B-13E1-4C74-8A3A-42E9A756DDC0}
2012-05-03 09:38:07 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{C284A61E-A16D-461A-BF1D-7C5ADA27EF84}
2012-05-02 21:38:08 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{E0A55F3B-70F3-41EB-BFEB-F240B3452C0B}
2012-05-02 20:40:00 -------- d-----w- C:\Users\JAMSYM\AppData\Roaming\YachtingPoker
2012-05-02 20:39:26 -------- d-----w- C:\Program Files (x86)\YachtingPoker
2012-04-28 01:33:31 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{B76F04EF-8155-4553-A90B-CE652953C907}
2012-04-28 01:33:09 -------- d-----w- C:\Users\JAMSYM\AppData\Local\{918A5A97-8193-4579-99AC-0B71B4464DB2}
.
==================== Find3M ====================
.
2012-05-05 17:34:07 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2012-05-05 17:34:07 419488 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2012-05-05 17:34:05 8744608 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe
2012-05-03 14:19:31 175616 ----a-w- C:\Windows\System32\msclmd.dll
2012-05-03 14:19:31 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll
2012-04-12 17:12:56 147248 ----a-w- C:\Windows\System32\drivers\VBoxNetAdp.sys
2012-04-06 23:20:38 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll
2012-03-31 06:05:57 5559664 ----a-w- C:\Windows\System32\ntoskrnl.exe
2012-03-31 04:39:37 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2012-03-31 04:39:37 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2012-03-31 03:10:03 3146240 ----a-w- C:\Windows\System32\win32k.sys
2012-03-30 11:35:47 1918320 ----a-w- C:\Windows\System32\drivers\tcpip.sys
2012-03-17 07:58:57 75120 ----a-w- C:\Windows\System32\drivers\partmgr.sys
2012-03-11 20:13:42 577824 ----a-w- C:\Windows\System32\drivers\cmdGuard.sys
2012-03-11 20:13:42 43248 ----a-w- C:\Windows\System32\drivers\cmdhlp.sys
2012-03-11 20:13:40 22696 ----a-w- C:\Windows\System32\drivers\cmderd.sys
2012-03-11 20:13:22 41200 ----a-w- C:\Windows\System32\cmdcsr.dll
2012-03-11 20:13:20 301224 ----a-w- C:\Windows\SysWow64\guard32.dll
2012-03-11 20:13:18 389840 ----a-w- C:\Windows\System32\guard64.dll
2012-03-08 17:50:28 49016 ----a-w- C:\Windows\SysWow64\sirenacm.dll
2012-03-08 17:37:20 302448 ----a-w- C:\Windows\WLXPGSS.SCR
2012-03-03 06:35:38 1544704 ----a-w- C:\Windows\System32\DWrite.dll
2012-03-03 05:31:19 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll
2012-03-01 06:46:16 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys
2012-03-01 06:38:27 220672 ----a-w- C:\Windows\System32\wintrust.dll
2012-03-01 06:33:50 81408 ----a-w- C:\Windows\System32\imagehlp.dll
2012-03-01 06:28:47 5120 ----a-w- C:\Windows\System32\wmi.dll
2012-03-01 05:37:41 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll
2012-03-01 05:33:23 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll
2012-03-01 05:29:16 5120 ----a-w- C:\Windows\SysWow64\wmi.dll
.
============= FINISH: 18:42:49.39 ===============