OTL logfile created on: 10/18/2012 10:55:22 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Stephen D. Rains\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 0.69 Gb Available Physical Memory | 34.57% Memory free
4.21 Gb Paging File | 2.73 Gb Available in Paging File | 64.95% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 99.48 Gb Total Space | 48.58 Gb Free Space | 48.83% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 4.44 Gb Free Space | 45.49% Space Free | Partition Type: NTFS
Drive F: | 1.90 Gb Total Space | 0.01 Gb Free Space | 0.29% Space Free | Partition Type: FAT
Drive G: | 15.98 Gb Total Space | 15.97 Gb Free Space | 99.93% Space Free | Partition Type: FAT32
Drive H: | 697.98 Gb Total Space | 251.24 Gb Free Space | 36.00% Space Free | Partition Type: NTFS
Drive I: | 446.77 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive J: | 298.09 Gb Total Space | 21.14 Gb Free Space | 7.09% Space Free | Partition Type: NTFS
Computer Name: BABO-PC | User Name: Stephen D. Rains | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/28 10:47:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stephen D. Rains\Desktop\OTL.exe
PRC - [2012/09/12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\NisSrv.exe
PRC - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/09/12 17:19:44 | 000,947,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/06/04 09:31:40 | 001,466,760 | ---- | M] (Garmin) -- C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe
PRC - [2012/02/12 08:09:09 | 000,399,224 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent\uTorrent.exe
PRC - [2011/06/26 22:36:34 | 000,419,328 | ---- | M] () -- C:\Program Files\GiliSoft\File Lock Pro\FLClient.exe
PRC - [2011/06/09 18:39:14 | 000,086,016 | ---- | M] () -- C:\Program Files\GiliSoft\File Lock Pro\FLService.exe
PRC - [2009/08/17 11:52:08 | 002,043,904 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMStatus.exe
PRC - [2009/08/17 11:52:08 | 000,098,304 | ---- | M] (WDC) -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe
PRC - [2009/08/17 11:50:32 | 008,919,040 | ---- | M] (Western Digital) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWare.exe
PRC - [2009/06/16 10:58:08 | 000,020,480 | ---- | M] (Memeo) -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/06 18:47:50 | 000,184,320 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Dell\MediaDirect\PCMService.exe
PRC - [2008/09/24 00:09:52 | 001,295,656 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DellDock.exe
PRC - [2008/09/24 00:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) -- C:\Program Files\Dell\DellDock\DockLogin.exe
PRC - [2008/05/04 05:25:32 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2008/05/04 05:25:26 | 000,167,936 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2008/05/04 05:25:26 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2008/05/04 05:25:26 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2008/02/22 19:01:38 | 001,193,240 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/09/20 15:31:10 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) -- C:\Windows\System32\AEstSrv.exe
PRC - [2007/09/13 15:45:38 | 000,102,400 | ---- | M] (IDT, Inc.) -- C:\Windows\System32\stacsv.exe
PRC - [2007/03/21 15:00:04 | 000,355,096 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2007/03/21 15:00:00 | 000,174,872 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/13 09:15:22 | 015,880,192 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\MenuSkinning\e4ead33e7390326a9814a511c566054b\MenuSkinning.ni.dll
MOD - [2012/06/13 09:15:11 | 001,711,616 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\2467a133aee73396c830b9b0a9c7ec0d\Microsoft.VisualBasic.ni.dll
MOD - [2012/06/13 09:15:02 | 000,284,160 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\VistaBridgeLibrary\53ff6fb64982a15d164f25e727be6bb4\VistaBridgeLibrary.ni.dll
MOD - [2012/06/13 09:15:01 | 002,500,608 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\DellDock\a2117f9d2b9670193889149f0ec777d5\DellDock.ni.exe
MOD - [2012/06/13 09:14:59 | 000,274,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\MyDock.Util\d8dfd448743194309366caa97c215c21\MyDock.Util.ni.dll
MOD - [2012/06/13 09:14:58 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8bbcd31ecc8edc7d1f9cdd83ef2bb2d3\System.ServiceProcess.ni.dll
MOD - [2012/06/13 09:14:57 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/06/13 09:12:54 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/13 09:12:44 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/13 08:59:34 | 013,198,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\3971e166cf827b6726e142f344061dc9\System.Windows.Forms.ni.dll
MOD - [2012/06/13 08:53:19 | 018,000,896 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\199683f6e79076b634ee6cc0a82c0654\PresentationFramework.ni.dll
MOD - [2012/06/13 08:52:56 | 011,451,904 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\e7dc084827f8df2dbdc819db5c633a0d\PresentationCore.ni.dll
MOD - [2012/06/13 08:52:37 | 003,858,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\21f37f9f5162af7efb52169012bd111e\WindowsBase.ni.dll
MOD - [2012/06/13 08:52:23 | 001,666,048 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\8c40f40ef36622109793788049fbe9ab\System.Drawing.ni.dll
MOD - [2012/05/15 07:52:22 | 000,393,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\4837a5c6204d53e7aa4f7dd94b98207c\System.Xml.Linq.ni.dll
MOD - [2012/05/15 07:52:21 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\d234eceae699d070b5a5712ce776c01f\System.Xaml.ni.dll
MOD - [2012/05/15 07:46:22 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012/05/15 07:46:13 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/15 07:45:54 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/15 07:45:47 | 000,025,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\1b337cf9a031145849bc48c11b2cfe58\Accessibility.ni.dll
MOD - [2012/05/15 07:44:17 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/15 07:43:31 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\bfdd10e0a0aacf46bac557ffc5d55ba5\System.Data.ni.dll
MOD - [2012/05/15 07:42:44 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/15 07:42:33 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012/05/15 04:34:35 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\a5fa2a1cfc6e9fdc39d9a8f2baa57bc9\PresentationFramework.Aero.ni.dll
MOD - [2012/05/15 04:30:58 | 000,736,768 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\5a3beae8b211b91bfc620c029cf4c2d4\System.Security.ni.dll
MOD - [2012/05/15 04:30:45 | 007,069,184 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\ed91b57205429a23bb91f4499059a459\System.Core.ni.dll
MOD - [2012/05/15 04:30:34 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\d1f299160424bad90fe9f658661389e2\System.Xml.ni.dll
MOD - [2012/05/15 04:30:14 | 009,091,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\6f9f0467e8b2dd3f69b015c8e30ac945\System.ni.dll
MOD - [2012/05/15 04:30:06 | 014,412,800 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\3953b1d8b9b57e4957bff8f58145384e\mscorlib.ni.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/06/06 22:16:32 | 000,700,416 | ---- | M] () -- C:\Program Files\GiliSoft\File Lock Pro\KernalUI.dll
MOD - [2011/06/01 15:57:08 | 000,053,248 | ---- | M] () -- C:\Program Files\GiliSoft\File Lock Pro\FolderLockPlugin.dll
MOD - [2009/08/17 11:26:24 | 000,049,152 | ---- | M] () -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\Memeo.API.dll
MOD - [2009/07/29 17:24:14 | 000,504,293 | ---- | M] () -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\sqlite3.dll
MOD - [2009/03/30 00:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
========== Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (TuneUp.UtilitiesSvc)
SRV - File not found [Auto | Stopped] -- -- (sprtsvc_dellsupportcenter)
SRV - [2012/09/12 17:25:24 | 000,287,824 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/09/12 17:25:22 | 000,020,472 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/12/19 16:32:26 | 000,394,672 | ---- | M] (Eastman Kodak Company) [Auto | Stopped] -- C:\Program Files\Kodak\AiO\Center\EKAiOHostService.exe -- (Kodak AiO Network Discovery Service)
SRV - [2011/07/20 04:35:34 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2011/07/07 15:07:59 | 000,655,624 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/06/09 18:39:14 | 000,086,016 | ---- | M] () [Auto | Running] -- C:\Program Files\GiliSoft\File Lock Pro\FLService.exe -- (FLService)
SRV - [2009/08/17 11:52:08 | 000,098,304 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService)
SRV - [2009/06/16 10:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)
SRV - [2008/12/03 06:20:20 | 000,016,680 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) [On_Demand | Stopped] -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe -- (GoToAssist)
SRV - [2008/09/24 00:09:52 | 000,155,648 | ---- | M] (Stardock Corporation) [Auto | Running] -- C:\Program Files\Dell\DellDock\DockLogin.exe -- (DockLoginService)
SRV - [2008/01/20 22:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/09/20 15:31:10 | 000,073,728 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Windows\System32\AEstSrv.exe -- (AESTFilters)
SRV - [2007/09/13 15:45:38 | 000,102,400 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Windows\System32\stacsv.exe -- (STacSV)
SRV - [2007/03/21 15:00:04 | 000,355,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (USBModem)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (UsbDiag)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (usbbus)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (TuneUpUtilitiesDrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (NwlnkFlt)
DRV - File not found [Kernel | System | Stopped] -- system32\drivers\networx.sys -- (networx)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\BCM42RLY.sys -- (BCM42RLY)
DRV - [2012/08/30 22:03:50 | 000,099,272 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/08/04 21:17:24 | 000,035,328 | ---- | M] (Gili Soft Inc.) [File_System | Boot | Running] -- C:\Windows\System32\drivers\FileLock.sys -- (FileLock)
DRV - [2010/11/17 20:36:02 | 000,021,744 | ---- | M] (PC-Doctor, Inc.) [Kernel | On_Demand | Stopped] -- c:\Program Files\Dell Support Center\pcdsrvc.pkms -- (PCDSRVC{E9D79540-57D5953E-06020101}_0)
DRV - [2009/12/30 12:21:16 | 000,027,192 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\revoflt.sys -- (Revoflt)
DRV - [2009/09/30 21:22:08 | 000,049,904 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BVRPMPR5.SYS -- (BVRPMPR5)
DRV - [2009/07/13 19:51:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/04/11 00:45:24 | 000,113,664 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rmcast.sys -- (RMCAST)
DRV - [2009/01/15 10:15:26 | 000,015,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2008/06/26 11:25:28 | 000,197,888 | ---- | M] (Panda Security, S.L.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\neti1634.sys -- (NETIMFLT01060034)
DRV - [2008/06/23 08:45:44 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2008/05/06 17:06:00 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/05/04 05:25:24 | 000,164,400 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2008/03/06 03:58:44 | 000,111,616 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\IntcHdmi.sys -- (IntcHdmiAddService)
DRV - [2008/01/20 22:32:51 | 000,220,672 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1e6032.sys -- (e1express)
DRV - [2007/11/12 07:07:28 | 000,330,240 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2007/09/06 12:35:16 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2007/09/06 12:35:14 | 000,039,936 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2007/09/06 12:35:12 | 000,042,496 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/02 03:36:43 | 002,028,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (R300)
DRV - [2002/07/17 16:20:32 | 000,084,832 | ---- | M] (Adaptec) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ASPI32.SYS -- (ASPI)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}
IE - HKLM\..\SearchScopes\{41396b1b-447e-473b-a34b-bb583136c7fc}: "URL" =
http://search.mywebsearch.com/myweb...8570&st=sb&n=77deabf0&searchfor={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...&oe={outputEncoding}&sourceid=ie7&rlz=1I7DMUS
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" =
http://dts.search-results.com/sr?src=ieb&appid=0&systemid=405&sr=0&q={searchTerms}
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2A69}: "URL" =
http://search.bearshare.com/web?src=ieb&systemid=2&q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1066435
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://my.msn.com/
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?c...pn_sauid=778E16D9-4C7D-4068-BE93-C24ABF3F7BED
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{2038FF9C-F580-4E43-9100-751C41A89DF8}: "URL" =
http://www.bing.com/search?FORM=IEFM1&q={searchTerms}&src={referrer:source?}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{21ED8F41-7CEF-4503-8F7A-33B918FC8400}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=MS8TDF&pc=MS8TDF&src=IE-SearchBox
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{41396b1b-447e-473b-a34b-bb583136c7fc}: "URL" =
http://search.mywebsearch.com/myweb...8570&st=sb&n=77deabf0&searchfor={searchTerms}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{4C5B6047-21C3-4B97-AB8C-7E7FA8E19F69}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=ie8
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{4D9C0429-BC7E-41B5-8162-1B30F5D873A2}: "URL" =
http://2song.net/search?q={searchTerms}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sea...={outputEncoding}&sourceid=ie7&rlz=1I7DMUS_en
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2405}: "URL" =
http://dts.search-results.com/sr?src=ieb&appid=0&systemid=405&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT1066435
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\..\SearchScopes\{C2994D1E-8E88-4995-B1D8-04CD16813AFA}: "URL" =
http://en.wikipedia.org/w/index.php?title=Special:Search&search={searchTerms}
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Search Results"
FF - prefs.js..browser.search.order.1: "Search Results"
FF - prefs.js..browser.search.selectedEngine: "Search Results"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.searchqu.com/405"
FF - prefs.js..extensions.enabledAddons:
firefox@facebook.com:1.8.2
FF - prefs.js..keyword.URL: "
http://dts.search-results.com/sr?src=ffb&appid=0&systemid=405&sr=0&q="
FF - prefs.js..network.proxy.no_proxies_on: "*.local"
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2432.1652\npCIDetect14.dll (Google)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Stephen D. Rains\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/05/26 09:42:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/10/08 21:29:46 | 000,000,000 | ---D | M]
[2012/09/22 14:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Extensions
[2009/01/31 22:45:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Extensions\
mozswing@mozswing.org
[2012/09/22 14:37:29 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\extensions
[2012/05/31 13:55:18 | 000,000,000 | ---D | M] (Bloody Red) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\extensions\{2458abc0-f443-11dd-87af-0800200c9a66}
[2012/07/09 22:05:22 | 000,000,000 | ---D | M] (FT DeepDark) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\extensions\{77d2ed30-4cd2-11e0-b8af-0800200c9a66}
[2012/07/09 21:08:40 | 000,319,802 | ---- | M] () (No name found) -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\extensions\
firefox@facebook.com.xpi
[2012/07/03 21:14:54 | 000,002,299 | ---- | M] () -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\searchplugins\askcom.xml
[2012/09/22 14:28:35 | 000,002,515 | ---- | M] () -- C:\Users\Stephen D. Rains\AppData\Roaming\Mozilla\Firefox\Profiles\fkndfmis.default\searchplugins\Search_Results.xml
[2012/09/22 14:37:24 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/22 11:15:13 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011/08/09 14:34:52 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/08/17 11:21:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\SAVEVID TOOLBAR\DATAMNGR\FIREFOXEXTENSION
[2009/06/25 03:01:09 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/08/12 01:57:31 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/14 08:41:12 | 000,002,506 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\BearShareWebSearch.xml
[2011/08/11 23:16:35 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/22 14:28:35 | 000,002,515 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
O1 HOSTS File: ([2012/10/18 22:03:02 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - No CLSID value found.
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (FLockObj Class) - {97F4988F-6D68-4abc-9F18-7B5AAFFDACE4} - C:\Program Files\GiliSoft\File Lock Pro\FolderLockPlugin.dll ()
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Conime] C:\Windows\System32\conime.exe (Microsoft Corporation)
O4 - HKLM..\Run: [EKAiO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\EKAiO2MUI.exe (Eastman Kodak Company)
O4 - HKLM..\Run: [Garmin Lifetime Updater] C:\Program Files\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PCMService] C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-2555096432-530049489-2058458779-1000..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O4 - Startup: C:\Users\Stephen D. Rains\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoThumbnailCache = 1
O7 - HKU\S-1-5-21-2555096432-530049489-2058458779-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 10.7.2)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/4.0.3.0/GarminAxControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{542293BC-CD09-473B-A7AF-22B90951B04D}: DhcpNameServer = 10.0.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\514\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Stephen D. Rains\Pictures\Wallpaper\boondock.jpg
O24 - Desktop BackupWallPaper: C:\Users\Stephen D. Rains\Pictures\Wallpaper\boondock.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/06/18 17:12:18 | 000,000,088 | ---- | M] () - I:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/10/18 22:35:28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Stephen D. Rains\Desktop\OTL.exe
[2012/10/18 22:03:05 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/10/18 21:58:23 | 000,000,000 | ---D | C] -- C:\Users\Stephen D. Rains\AppData\Local\temp
[2012/10/18 21:58:19 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/10/18 21:43:14 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/10/18 21:43:14 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/10/18 21:43:14 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/10/18 21:43:07 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/10/18 21:43:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/18 21:42:24 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/10/18 21:33:03 | 004,984,103 | R--- | C] (Swearware) -- C:\Users\Stephen D. Rains\Desktop\ComboFix.exe
[2012/10/15 21:14:49 | 000,000,000 | ---D | C] -- C:\Users\Stephen D. Rains\{5ba16cdb-c405-4d72-bcdc-1174ab014368}
[2012/10/14 15:17:39 | 000,000,000 | ---D | C] -- C:\FRST
[2012/10/10 15:52:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/10/10 15:50:05 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/10/10 15:49:42 | 000,000,000 | ---D | C] -- C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/09/22 14:47:20 | 000,000,000 | ---D | C] -- C:\Users\Stephen D. Rains\AppData\Local\Ilivid Player
[2012/09/22 14:28:37 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2011/07/01 13:09:29 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Stephen D. Rains\AppData\Roaming\pcouffin.sys
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/10/18 22:50:12 | 000,606,136 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/10/18 22:50:12 | 000,105,044 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/10/18 22:43:09 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/10/18 22:43:08 | 000,003,744 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/10/18 22:43:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/10/18 22:35:16 | 000,000,000 | ---- | M] () -- C:\Windows\FileLock.bin
[2012/10/18 22:03:02 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/10/18 07:20:38 | 004,984,103 | R--- | M] (Swearware) -- C:\Users\Stephen D. Rains\Desktop\ComboFix.exe
[2012/10/17 09:25:19 | 000,199,680 | ---- | M] () -- C:\Users\Stephen D. Rains\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/10/15 21:12:25 | 000,022,729 | ---- | M] () -- C:\newkey
[2012/10/15 21:12:25 | 000,022,729 | ---- | M] () -- C:\newfile.enc
[2012/10/14 14:51:10 | 000,455,904 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/10/08 21:49:35 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/09/28 10:47:18 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Stephen D. Rains\Desktop\OTL.exe
[2012/09/22 14:50:25 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd98f3206bc120.job
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/10/18 21:43:14 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/10/18 21:43:14 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/10/18 21:43:14 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/10/18 21:43:14 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/10/18 21:43:14 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/10/15 21:12:25 | 000,022,729 | ---- | C] () -- C:\newkey
[2012/10/15 21:12:25 | 000,022,729 | ---- | C] () -- C:\newfile.enc
[2012/10/15 20:36:32 | 000,773,882 | ---- | C] () -- C:\Windows\System32\oem7.inf
[2012/09/22 14:50:25 | 000,000,882 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore1cd98f3206bc120.job
[2012/06/23 13:23:49 | 000,000,218 | ---- | C] () -- C:\Users\Stephen D. Rains\.recently-used.xbel
[2011/12/09 19:52:00 | 000,000,146 | ---- | C] () -- C:\Windows\WININIT.INI
[2011/09/30 07:41:19 | 000,000,000 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Local\{B7D38FCC-F155-40E3-8B6C-0E82865BEC06}
[2011/08/10 11:24:21 | 000,000,746 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\AtomicAlarmClock.ini
[2011/08/10 10:41:36 | 000,000,759 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\ClockTraySkins.ini
[2011/08/05 14:35:30 | 000,001,056 | ---- | C] () -- C:\Windows\System32\EKaio2WiaCoInst.ini
[2011/08/04 21:20:05 | 000,000,000 | ---- | C] () -- C:\Windows\FileLock.bin
[2011/07/01 13:09:29 | 000,007,887 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\pcouffin.cat
[2011/07/01 13:09:29 | 000,001,144 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\pcouffin.inf
[2010/12/09 09:46:26 | 000,000,384 | ---- | C] () -- C:\Users\Stephen D. Rains\Documents - Shortcut.lnk
[2010/11/16 15:54:20 | 000,002,560 | ---- | C] () -- C:\Windows\_MSRSTRT.EXE
[2010/09/10 07:51:38 | 000,000,990 | -HS- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\systemfl.$dk
[2009/06/24 18:35:10 | 000,008,248 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Local\en.ini
[2009/03/03 16:04:44 | 000,001,122 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Roaming\wklnhst.dat
[2009/02/16 23:18:07 | 000,005,972 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Local\d3d9caps.dat
[2009/01/31 01:39:50 | 000,199,680 | ---- | C] () -- C:\Users\Stephen D. Rains\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2006/11/02 08:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 13:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/11 02:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 02:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2009/02/20 10:12:32 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\LimeWire
[2012/07/14 08:36:10 | 000,000,000 | ---D | M] -- C:\Users\Guest\AppData\Roaming\Western Digital
[2011/08/10 11:59:18 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Active Alarm Clock
[2012/05/15 10:11:38 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Audacity
[2011/12/07 00:00:24 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\avidemux
[2011/06/06 12:55:05 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/02/07 05:45:51 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\deluge
[2010/12/07 12:19:15 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Digiarty
[2010/09/07 11:58:36 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\DriverFinder
[2009/07/14 07:19:45 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\F-Secure
[2011/09/23 13:01:35 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\FaceOffMax
[2012/08/06 08:44:42 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\FixCleaner
[2011/08/03 13:21:11 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\FreeAudioPack
[2011/08/04 16:37:17 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\FreeCDRipper
[2011/03/29 12:47:10 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\FrostWire
[2011/11/24 10:27:34 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Garmin
[2012/07/05 13:04:05 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\GetRightToGo
[2011/08/05 07:28:48 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Gili File Lock
[2012/06/23 13:16:22 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\griffith
[2012/02/13 08:57:10 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\gtk-2.0
[2011/02/20 09:42:25 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\HandBrake
[2011/08/09 13:33:45 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\HotMP3Downloader
[2011/08/10 16:17:40 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\IObit
[2010/11/16 16:41:04 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\LimeWireTurbo
[2011/09/08 08:42:51 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\MP3Rocket
[2011/03/10 05:13:59 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\MusicNet
[2011/10/22 11:43:58 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\OpenOffice.org
[2009/03/13 08:55:15 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Panda Security
[2010/12/17 07:30:59 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\PCDr
[2010/12/09 08:26:15 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\RegistryOptimizerFree
[2010/07/05 21:12:19 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Smith Micro
[2011/08/02 09:52:07 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Temp
[2009/03/03 16:04:45 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Template
[2011/07/07 13:00:24 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\TuneUp Software
[2011/08/09 13:36:28 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\URSoft
[2012/10/18 22:54:44 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\uTorrent
[2011/01/26 18:39:28 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Video DVD Maker FREE
[2012/08/09 17:18:05 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Vso
[2011/11/30 14:47:52 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Western Digital
[2012/06/27 09:37:10 | 000,000,000 | ---D | M] -- C:\Users\Stephen D. Rains\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 209 bytes -> C:\ProgramData\TEMP:CB0AACC9
@Alternate Data Stream - 157 bytes -> C:\ProgramData\TEMP:1CE11B51
< End of report >