part 2
IE - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}:0.3.8.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files (x86)\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Elliot\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Elliot\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Elliot\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Elliot\AppData\Local\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Elliot\AppData\Local\Google\Update\1.3.21.93\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/12/22 11:14:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/12/22 11:14:57 | 000,000,000 | ---D | M]
[2011/02/19 17:05:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Elliot\AppData\Roaming\Mozilla\Extensions
[2012/01/09 18:44:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Elliot\AppData\Roaming\Mozilla\Firefox\Profiles\jlj4gjgr.default\extensions
[2011/03/07 20:06:24 | 000,000,000 | ---D | M] (Edit Cookies) -- C:\Users\Elliot\AppData\Roaming\Mozilla\Firefox\Profiles\jlj4gjgr.default\extensions\{ea2b95c2-9be8-48ed-bdd1-5fcd2ad0ff99}
[2012/01/09 18:44:17 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/04/05 15:41:06 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/04/14 15:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/04/09 13:25:11 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/09 13:25:11 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/09 13:25:11 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/04/09 13:25:11 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/01/15 15:30:00 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20110608190706.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20110608190706.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [DellStage] C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe ()
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe (Dell, Inc.)
O4 - HKLM..\Run: [Desktop Disc Tool] C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RoxWatchTray] C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe (Sonic Solutions)
O4 - HKLM..\Run: [ShwiconXP9106] C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WD Anywhere Backup] C:\Program Files (x86)\WD\WD Anywhere Backup\MemeoLauncher2.exe (Memeo Inc.)
O4 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000..\Run: [Facebook Update] C:\Users\Elliot\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKLM..\RunOnce: ["C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe"] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpdate.exe (Dell)
O4 - HKU\.DEFAULT..\RunOnce: [DeleteEngineAfterUpdate] reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine /f File not found
O4 - HKU\S-1-5-18..\RunOnce: [DeleteEngineAfterUpdate] reg DELETE HKCU\Software\AppDataLow\Software\ConduitEngine /f File not found
O4 - Startup: C:\Users\Elliot\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Elliot\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O15 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKU\S-1-5-21-2497366735-1331177007-3287805736-1000\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {82E5DF24-51E8-47CD-864A-F4BD5005AA73}
https://www.icloud.com/system/iCloud.cab (iCloud Web App Plugin)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4992DDE0-4E46-4A99-B003-70B28911F6FA}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C8CB7EEF-2D14-45AA-A68A-AC835BB4F425}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D95F3F13-1B54-464E-A0CE-B9D7A88B903A}: DhcpNameServer = 198.142.0.51 61.88.88.88
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/07/30 09:44:07 | 000,000,088 | ---- | M] () - Z:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:
64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/01/21 15:19:21 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{86430B88-D1AB-4A99-9AEF-252B555B3915}
[2012/01/15 16:27:18 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Elliot\Desktop\OTL.exe
[2012/01/15 15:39:43 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/01/15 15:17:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/01/15 14:55:01 | 001,932,256 | ---- | C] (Symantec Corporation) -- C:\Users\Elliot\Desktop\FixTDSS.exe
[2012/01/15 11:49:37 | 000,083,968 | ---- | C] (Esage Lab) -- C:\Users\Elliot\Desktop\boot_cleaner.exe
[2012/01/15 11:47:24 | 004,713,472 | ---- | C] (AVAST Software) -- C:\Users\Elliot\Desktop\aswMBR.exe
[2012/01/15 11:21:04 | 001,972,528 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Elliot\Desktop\tdsskiller.exe
[2012/01/14 16:53:13 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Elliot\Desktop\dds.scr
[2012/01/14 16:53:04 | 007,956,512 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-rules.exe
[2012/01/14 15:42:04 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/14 15:42:04 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/14 15:42:04 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/14 15:41:47 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/14 15:40:46 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/14 15:40:38 | 004,383,253 | R--- | C] (Swearware) -- C:\Users\Elliot\Desktop\ComboFix.exe
[2012/01/14 15:34:36 | 001,153,912 | ---- | C] (Emsi Software GmbH) -- C:\Users\Elliot\Desktop\BlitzBlank.exe
[2012/01/14 15:28:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/14 15:27:57 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/01/14 13:11:34 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{7F0C2A54-8BB3-4229-B5A1-3B4F9B3660A2}
[2012/01/14 13:11:15 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{CC309D7B-4749-4140-A12C-1897BD29C757}
[2012/01/14 13:10:33 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Roaming\Ybews
[2012/01/14 13:10:33 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Roaming\Okm
[2012/01/14 12:51:31 | 009,851,496 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-setup.exe
[2012/01/14 12:36:33 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{E87EB522-5391-4000-9D54-E89864A9AB05}
[2012/01/14 12:26:38 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{1E7212CF-A89E-4115-810D-0E49CEB6D7D8}
[2012/01/14 12:09:58 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{03BE3113-C494-4232-829F-74812936379B}
[2012/01/14 12:03:28 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{B3F75082-B40B-4D66-9A33-E2D0D60EA57A}
[2012/01/14 11:56:48 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{F9D0D57F-F344-484F-A393-6D4765D61DE5}
[2012/01/14 11:50:25 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{7638B5C0-E615-4B41-A1E2-86D6F3FEC357}
[2012/01/14 11:43:37 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Roaming\BACS.exe
[2012/01/14 11:16:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Broadcom
[2012/01/14 11:16:28 | 000,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2012/01/14 11:15:37 | 000,000,000 | ---D | C] -- C:\Windows\Dell
[2012/01/14 11:14:21 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\Downloaded Installations
[2012/01/14 11:10:57 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{169A4083-9479-4A84-A27B-189BB719033B}
[2012/01/14 08:38:49 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{B2C514AF-F436-47F8-873A-ACF8256F15BA}
[2012/01/13 19:45:32 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Roaming\Malwarebytes
[2012/01/13 19:45:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/13 19:45:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/13 17:55:37 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{55DCD8A1-247B-49A4-82B5-FE14DF9D2FB8}
[2012/01/13 05:55:12 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{D255449F-4D4C-4B06-ABA3-7A4A8FAACF61}
[2012/01/12 17:54:41 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{F4922F54-966D-4D00-A7B0-A777F66EDD86}
[2012/01/12 17:54:27 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{414697F0-EDF7-4998-B6C9-F89933EA8449}
[2012/01/12 05:54:00 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{42FEE5CE-558B-407D-9266-AE24FFD9C64E}
[2012/01/12 05:53:48 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{D63E16EE-6FA2-4992-A726-AFE79F014D7B}
[2012/01/11 17:53:22 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{D7C74817-631D-4B66-A4E9-B5C8621AF6E8}
[2012/01/11 05:52:57 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{CA3E10DE-7F7B-47C8-AA49-73AD26076395}
[2012/01/10 17:52:32 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{6B2E45D4-FB27-429D-A6EA-9EFF0EE578A2}
[2012/01/10 17:52:20 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{4AFBC1AB-3F5C-4DE3-9BD2-1A70B7871E93}
[2012/01/08 15:53:17 | 000,000,000 | ---D | C] -- C:\Users\Elliot\Desktop\New folder
[2012/01/08 15:53:06 | 000,000,000 | ---D | C] -- C:\Users\Elliot\Desktop\The League
[2012/01/08 15:46:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultra MKV Converter
[2012/01/08 15:46:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ultra MKV Converter
[2012/01/08 15:17:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/08 15:16:46 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/01/08 15:16:45 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/01/06 14:09:25 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{D1819E09-5FD6-45C1-876A-11354F876A86}
[2012/01/06 14:09:14 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{1676F130-970A-48E8-9689-9B5B7E1CF675}
[2012/01/05 10:09:12 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{0F108CCC-BE43-4F3F-9FBB-5CCB5BF1106E}
[2012/01/05 10:08:59 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{4B826CF5-FED7-4A29-A2DD-5EDE8C6278EE}
[2012/01/04 16:12:26 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{F03A50DD-52C0-4891-8939-E12ABAF9FD0A}
[2012/01/04 16:12:10 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{87F581B8-69E2-480A-A7C9-EB344499CD91}
[2012/01/03 23:22:49 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{B60E9068-4931-4F6F-8BFC-0D844F225177}
[2012/01/03 11:22:22 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{AA7669B1-FCFC-4CA2-B264-E6A5AE9C3797}
[2012/01/03 11:22:08 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{E7260A23-8E11-4EEC-BA96-98201E33F403}
[2012/01/02 23:21:34 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{8A02F6E5-EEF9-43CD-B64D-202BC0E33686}
[2012/01/02 11:21:00 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{51E6446F-1E91-41BF-B9FF-CE56650FE543}
[2012/01/02 11:20:44 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{9491AB75-C0EC-4589-A52F-3D7ECE689A05}
[2012/01/01 15:36:15 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{71F8AC65-1412-4DB9-9696-EBE0023B0962}
[2012/01/01 15:36:03 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{357BF5A0-2B5A-4D17-A410-3063081FCF24}
[2011/12/29 11:13:16 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{6FACED6F-2F90-4337-8FE3-C16790AD83C4}
[2011/12/28 01:27:56 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{B6519709-2290-4A0D-88FB-A00D8584E5E2}
[2011/12/27 13:27:31 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{BD7F99F4-8D44-4F79-817B-D9651C2808E0}
[2011/12/27 13:27:18 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{BBF59B7B-4229-4727-ADC4-842AF763B3F5}
[2011/12/27 00:14:23 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{4E55B001-7666-43EC-BF22-4AB700967D8B}
[2011/12/27 00:14:12 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{D0434FFD-3F32-4F59-A6D8-F0BD7607D028}
[2011/12/26 13:31:20 | 000,016,200 | ---- | C] (McAfee, Inc.) -- C:\Windows\stinger.sys
[2011/12/26 12:13:43 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{AB21B693-3FE3-41A9-964E-41BC0C41AEBE}
[2011/12/26 12:13:26 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{9A4C6228-9654-4E33-A067-6D87586D2C4D}
[2011/12/25 12:04:53 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{EEA6EDBE-63C1-4EA7-9B20-CB648BF6A25A}
[2011/12/25 12:04:41 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{3A57AEF3-2444-4841-B206-E195D9C44C8F}
[2011/12/25 00:04:10 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{9A497DE1-6101-4780-A878-D7B286EA81DD}
[2011/12/25 00:03:39 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{7A7D6783-A9B0-4AB7-BD72-9EF380C50213}
[2011/12/24 23:38:14 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{6A7C2575-BEA4-4C18-88C0-CC69B105101F}
[2011/12/24 11:37:47 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{94FE5017-3E19-41E8-B37B-197432A4BBB5}
[2011/12/24 11:37:32 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{8081BAAB-D81F-4D69-AA65-ADACDDE30F44}
[2011/12/23 12:24:18 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{7EC7428E-9B44-43F8-BD7C-D45F00FAF696}
[2011/12/23 12:23:46 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{A1B17974-0322-4752-915C-DA8AC3F12F57}
[2011/12/23 00:26:34 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{963A54D4-27E1-42FA-B616-B43B5FF02F26}
[2011/12/22 23:04:01 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Roaming\Macrovision
[2011/12/22 12:26:03 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{61F695ED-2B04-4BCB-A9F6-A8EA176B4352}
[2011/12/22 12:25:30 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{64420133-859B-4D9B-87EE-B7A0EFBC9EB8}
[2011/12/21 18:43:16 | 000,000,000 | ---D | C] -- C:\Users\Elliot\Desktop\Music George
[2011/12/21 15:59:22 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{2B3594C0-B7AC-40B0-BFBC-B7DBC7130D98}
[2011/12/21 15:59:08 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{357B0A25-A8C0-4BCE-B37D-F00849C53BAF}
[2011/12/21 02:24:42 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{3F77B649-071C-409D-A767-E16EB2F04C17}
[2011/12/20 14:26:36 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{76DD4E1B-BA96-4194-9C85-42B5420A0388}
[2011/12/20 02:26:08 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{4A230B68-0FEE-45A2-8A4F-FC30BBDC9D1C}
[2011/12/19 14:25:45 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{271DAEB1-41E3-4680-9530-92A6A3DB81CC}
[2011/12/19 02:25:21 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{E58B822E-9BBE-4C77-811C-14A6141E94FF}
[2011/12/18 14:24:47 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{83D6C388-056D-4D67-B024-06F1EB311234}
[2011/12/18 14:24:35 | 000,000,000 | ---D | C] -- C:\Users\Elliot\AppData\Local\{5FB91B70-7AC9-45C5-B3B4-67E6501BAF07}
[2011/12/17 11:06:01 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2 C:\Users\Elliot\Desktop\*.tmp files -> C:\Users\Elliot\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/15 16:00:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000UA.job
[2012/01/15 16:00:00 | 000,000,416 | ---- | M] () -- C:\Windows\tasks\vtscheduletask.job
[2012/01/15 15:30:00 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/15 15:27:41 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/15 15:27:41 | 000,014,240 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/15 15:16:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/15 15:16:48 | 2133,676,031 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/15 14:56:13 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/01/15 13:46:03 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000UA.job
[2012/01/15 11:49:00 | 000,044,607 | ---- | M] () -- C:\Users\Elliot\Desktop\bootkit_remover.zip
[2012/01/15 11:48:19 | 000,000,512 | ---- | M] () -- C:\Users\Elliot\Desktop\MBR.dat
[2012/01/14 22:00:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000Core.job
[2012/01/14 16:43:01 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2497366735-1331177007-3287805736-1000Core.job
[2012/01/14 16:37:56 | 000,302,592 | ---- | M] () -- C:\Users\Elliot\Desktop\hwwu458l.exe
[2012/01/14 15:28:00 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2012/01/14 12:54:02 | 009,851,496 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Elliot\Desktop\mbam-setup.exe
[2012/01/14 12:43:17 | 001,196,748 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/14 12:43:17 | 000,391,680 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/14 12:43:17 | 000,005,396 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/14 12:32:10 | 000,003,364 | ---- | M] () -- C:\Users\Elliot\Desktop\firewall.reg
[2012/01/14 12:31:38 | 000,001,495 | ---- | M] () -- C:\Users\Elliot\Desktop\bfe.reg
[2012/01/14 12:18:40 | 050,331,648 | ---- | M] () -- C:\Users\Elliot\Desktop\R282233.exe
[2012/01/14 11:06:50 | 000,000,017 | ---- | M] () -- C:\Users\Elliot\AppData\Local\resmon.resmoncfg
[2012/01/14 09:02:10 | 004,383,253 | R--- | M] (Swearware) -- C:\Users\Elliot\Desktop\ComboFix.exe
[2012/01/13 23:02:08 | 001,972,528 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Elliot\Desktop\tdsskiller.exe
[2012/01/13 21:32:14 | 000,024,576 | ---- | M] () -- C:\Users\Elliot\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/01/13 19:44:39 | 000,000,000 | ---- | M] () -- C:\ProgramData\Vqr5BO8X.dat
[2012/01/13 19:36:12 | 000,014,440 | -HS- | M] () -- C:\Users\Elliot\AppData\Local\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
[2012/01/13 19:36:12 | 000,014,440 | -HS- | M] () -- C:\ProgramData\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
[2012/01/13 09:22:46 | 000,799,545 | ---- | M] () -- C:\Users\Elliot\Desktop\ListParts64.exe
[2012/01/12 00:01:50 | 000,303,000 | -H-- | M] () -- C:\Users\Elliot\Desktop\ZbThumbnail.info
[2012/01/10 18:00:25 | 000,024,277 | ---- | M] () -- C:\Users\Elliot\Desktop\censor-beep-2.mp3
[2012/01/10 17:59:26 | 000,014,873 | ---- | M] () -- C:\Users\Elliot\Desktop\censor-beep-1.mp3
[2012/01/10 10:51:53 | 000,002,048 | ---- | M] () -- C:\Users\Elliot\AppData\Roaming\Photobook Designer Prefs
[2012/01/10 04:42:36 | 000,334,125 | ---- | M] () -- C:\Users\Elliot\Desktop\FSS.exe
[2012/01/09 23:20:14 | 000,253,536 | ---- | M] () -- C:\Users\Elliot\Desktop\SpeedScheduler_1.6.0.jar
[2012/01/08 15:46:40 | 000,001,059 | ---- | M] () -- C:\Users\Public\Desktop\Ultra MKV Converter.lnk
[2012/01/08 15:17:26 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/07 04:37:34 | 004,713,472 | ---- | M] (AVAST Software) -- C:\Users\Elliot\Desktop\aswMBR.exe
[2012/01/05 20:15:35 | 000,039,495 | ---- | M] () -- C:\Users\Elliot\Desktop\Aloe Blacc.jpg
[2012/01/05 17:24:01 | 000,803,300 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/01/02 11:20:50 | 000,001,045 | ---- | M] () -- C:\Users\Elliot\Desktop\Dropbox.lnk
[2011/12/27 21:45:48 | 000,396,071 | ---- | M] () -- C:\Users\Elliot\Desktop\MiniToolBox.exe
[2011/12/26 13:31:20 | 000,016,200 | ---- | M] (McAfee, Inc.) -- C:\Windows\stinger.sys
[2011/12/26 13:29:15 | 002,021,790 | ---- | M] () -- C:\Windows\SysWow64\67cBEBC.mht
[2011/12/25 00:02:49 | 591,262,457 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/12/24 11:36:52 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/12/23 22:01:46 | 003,161,519 | ---- | M] () -- C:\Users\Elliot\Desktop\photo 2.JPG
[2011/12/19 18:41:34 | 000,082,226 | ---- | M] () -- C:\Users\Elliot\Desktop\378017_10150420092736143_614116142_8841797_639134752_n.jpg
[2 C:\Users\Elliot\Desktop\*.tmp files -> C:\Users\Elliot\Desktop\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/15 14:38:24 | 000,799,545 | ---- | C] () -- C:\Users\Elliot\Desktop\ListParts64.exe
[2012/01/15 11:49:31 | 000,044,607 | ---- | C] () -- C:\Users\Elliot\Desktop\bootkit_remover.zip
[2012/01/15 11:48:19 | 000,000,512 | ---- | C] () -- C:\Users\Elliot\Desktop\MBR.dat
[2012/01/14 16:38:56 | 000,302,592 | ---- | C] () -- C:\Users\Elliot\Desktop\hwwu458l.exe
[2012/01/14 16:20:26 | 000,396,071 | ---- | C] () -- C:\Users\Elliot\Desktop\MiniToolBox.exe
[2012/01/14 16:13:37 | 000,334,125 | ---- | C] () -- C:\Users\Elliot\Desktop\FSS.exe
[2012/01/14 15:42:04 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/14 15:42:04 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/14 15:42:04 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/14 15:42:04 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/14 15:28:00 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2012/01/14 12:34:41 | 000,003,364 | ---- | C] () -- C:\Users\Elliot\Desktop\firewall.reg
[2012/01/14 12:34:41 | 000,001,495 | ---- | C] () -- C:\Users\Elliot\Desktop\bfe.reg
[2012/01/14 12:31:09 | 050,331,648 | ---- | C] () -- C:\Users\Elliot\Desktop\R282233.exe
[2012/01/14 11:06:50 | 000,000,017 | ---- | C] () -- C:\Users\Elliot\AppData\Local\resmon.resmoncfg
[2012/01/13 19:44:39 | 000,000,000 | ---- | C] () -- C:\ProgramData\Vqr5BO8X.dat
[2012/01/13 19:32:55 | 000,014,440 | -HS- | C] () -- C:\Users\Elliot\AppData\Local\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
[2012/01/13 19:32:55 | 000,014,440 | -HS- | C] () -- C:\ProgramData\db2am60oby25758xy4e00f7d271u4p355010g2o2s7gsn
[2012/01/10 18:00:25 | 000,024,277 | ---- | C] () -- C:\Users\Elliot\Desktop\censor-beep-2.mp3
[2012/01/10 17:59:26 | 000,014,873 | ---- | C] () -- C:\Users\Elliot\Desktop\censor-beep-1.mp3
[2012/01/09 23:20:14 | 000,253,536 | ---- | C] () -- C:\Users\Elliot\Desktop\SpeedScheduler_1.6.0.jar
[2012/01/08 15:46:40 | 000,001,059 | ---- | C] () -- C:\Users\Public\Desktop\Ultra MKV Converter.lnk
[2012/01/08 15:46:39 | 000,129,024 | ---- | C] () -- C:\Windows\SysWow64\AVERM.dll
[2012/01/08 15:46:39 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2012/01/08 15:17:26 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/05 20:24:17 | 000,039,495 | ---- | C] () -- C:\Users\Elliot\Desktop\Aloe Blacc.jpg
[2012/01/03 16:42:02 | 000,702,004 | ---- | C] () -- C:\Users\Elliot\Desktop\IMG_8931-3.JPG
[2012/01/02 11:20:50 | 000,001,045 | ---- | C] () -- C:\Users\Elliot\Desktop\Dropbox.lnk
[2011/12/26 13:29:15 | 002,021,790 | ---- | C] () -- C:\Windows\SysWow64\67cBEBC.mht
[2011/12/23 22:01:28 | 003,161,519 | ---- | C] () -- C:\Users\Elliot\Desktop\photo 2.JPG
[2011/12/19 18:41:41 | 000,082,226 | ---- | C] () -- C:\Users\Elliot\Desktop\378017_10150420092736143_614116142_8841797_639134752_n.jpg
[2011/12/17 11:06:08 | 000,000,564 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2011/12/17 11:06:06 | 000,000,506 | ---- | C] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2011/12/04 20:02:09 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/08/31 22:34:15 | 000,803,300 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/08/19 09:26:20 | 010,898,456 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 09:26:20 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 09:26:20 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011/06/09 09:02:30 | 000,833,024 | ---- | C] () -- C:\Windows\SysWow64\user.dat
[2011/04/05 14:45:30 | 000,002,048 | ---- | C] () -- C:\Users\Elliot\AppData\Roaming\Photobook Designer Prefs
[2011/03/13 19:25:04 | 000,002,048 | ---- | C] () -- C:\Users\Elliot\AppData\Roaming\albumworks Prefs
[2011/03/05 13:27:31 | 000,197,728 | ---- | C] () -- C:\Windows\WinVd32.sys
[2011/03/05 13:27:30 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\WinFLsrv.exe
[2011/02/20 20:25:59 | 000,024,576 | ---- | C] () -- C:\Users\Elliot\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/11 18:50:23 | 000,722,382 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/02/01 14:25:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/01/31 22:40:27 | 000,001,264 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2011/01/31 22:40:27 | 000,001,247 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2011/01/31 22:40:27 | 000,001,247 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2011/01/31 22:40:17 | 000,177,664 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011/01/31 22:40:17 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2010/09/17 18:17:02 | 000,002,888 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2009/07/14 16:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 08:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2000/08/31 11:00:00 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe