========== Chrome ==========
CHR - homepage:
http://www.google.ca/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.ca/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\20.0.1132.57\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Randy\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Randy\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Randy\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Comrade Plugin (Enabled) = C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - Extension: YouTube = C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\Randy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/26 19:53:57 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files (x86)\Hotspot Shield\HssIE\HssIE_64.dll (AnchorFree Inc.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {09EC805C-CB2E-4D53-B0D3-A75A428B81C7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKCU..\Run: [HydraVisionDesktopManager] C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 28
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_02-windows-i586.cab (Java Plug-in 1.6.0_02)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{934035AC-0B00-40B9-9B51-7F30B5531143}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B7ED1B21-9A9A-4F84-87B3-9B124247E07A}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\klogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/26 21:36:20 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/26 20:31:25 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2012/07/26 20:31:17 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/26 19:59:13 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/26 19:54:02 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/07/26 19:12:12 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/26 19:12:12 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/26 19:12:12 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/26 19:12:03 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/26 19:11:38 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/26 19:07:55 | 004,719,912 | R--- | C] (Swearware) -- C:\Users\Randy\Desktop\ComboFix.exe
[2012/07/25 10:48:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Alwil Software
[2012/07/25 10:48:34 | 000,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2012/07/20 14:56:12 | 000,000,000 | ---D | C] -- C:\Users\Randy\AppData\Local\Nero_AG
[2012/07/20 14:55:35 | 000,000,000 | ---D | C] -- C:\Users\Randy\AppData\Local\Nero
[2012/07/18 21:58:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.1
[2012/07/18 21:58:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cheat Engine 6.1
[2012/07/14 15:51:09 | 000,000,000 | ---D | C] -- C:\Users\Randy\AppData\Roaming\ImTOO
[2012/07/14 15:51:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImTOO
[2012/07/14 15:50:46 | 000,000,000 | ---D | C] -- C:\ProgramData\ImTOO
[2012/07/14 15:50:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ImTOO
[2012/07/14 14:10:07 | 000,000,000 | ---D | C] -- C:\ProgramData\boost_interprocess
[2012/07/14 14:10:04 | 000,000,000 | ---D | C] -- C:\ProgramData\43A7
[2012/07/14 14:09:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iMesh Applications
[2012/07/14 14:09:07 | 000,000,000 | ---D | C] -- C:\Users\Randy\AppData\Local\PackageAware
[2012/07/09 17:51:57 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2012/07/09 17:51:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2012/07/09 17:51:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2012/06/27 22:17:31 | 000,000,000 | ---D | C] -- C:\Users\Randy\AppData\Local\Facebook
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/26 20:31:25 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Randy\Desktop\OTL.exe
[2012/07/26 20:31:18 | 000,001,116 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/26 20:29:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/26 20:22:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001UA.job
[2012/07/26 19:59:20 | 002,655,666 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/26 19:59:20 | 001,111,428 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/26 19:59:20 | 000,006,426 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/26 19:58:57 | 000,014,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 19:58:57 | 000,014,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/26 19:53:57 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/26 19:53:50 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/26 19:53:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/26 19:53:39 | 536,195,071 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/26 19:41:30 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001Core.job
[2012/07/26 19:27:21 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001UA.job
[2012/07/26 19:22:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001Core.job
[2012/07/26 19:07:58 | 004,719,912 | R--- | M] (Swearware) -- C:\Users\Randy\Desktop\ComboFix.exe
[2012/07/25 10:48:47 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/07/20 14:56:20 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[6 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/26 20:31:18 | 000,001,116 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/26 19:12:12 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/26 19:12:12 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/26 19:12:12 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/26 19:12:12 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/26 19:12:12 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/06/27 22:17:46 | 000,000,928 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001UA.job
[2012/06/27 22:17:45 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001Core.job
[2012/02/16 23:41:26 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2012/02/14 23:05:16 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2012/02/14 22:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/02/14 22:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/12/17 02:15:57 | 000,000,028 | ---- | C] () -- C:\Windows\v2d.INI
[2011/12/12 22:13:30 | 000,000,248 | ---- | C] () -- C:\Windows\SysWow64\secustat.dat
[2011/12/12 22:11:18 | 000,000,305 | ---- | C] () -- C:\Windows\SysWow64\secushr.dat
[2011/12/12 21:54:28 | 000,000,025 | ---- | C] () -- C:\Windows\libem.INI
[2011/10/27 20:25:18 | 000,073,220 | ---- | C] () -- C:\Windows\SysWow64\EPPICPrinterDB.dat
[2011/10/27 20:25:18 | 000,031,053 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern131.dat
[2011/10/27 20:25:18 | 000,029,114 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern1.dat
[2011/10/27 20:25:18 | 000,027,417 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern121.dat
[2011/10/27 20:25:18 | 000,021,021 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern3.dat
[2011/10/27 20:25:18 | 000,015,670 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern5.dat
[2011/10/27 20:25:18 | 000,013,280 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern2.dat
[2011/10/27 20:25:18 | 000,010,673 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern4.dat
[2011/10/27 20:25:18 | 000,004,943 | ---- | C] () -- C:\Windows\SysWow64\EPPICPattern6.dat
[2011/10/27 20:25:18 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2011/10/27 20:25:18 | 000,001,140 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2011/10/27 20:25:18 | 000,001,137 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2011/10/27 20:25:18 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2011/10/27 20:25:18 | 000,001,130 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2011/10/27 20:25:18 | 000,001,104 | ---- | C] () -- C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2011/10/27 20:25:18 | 000,000,097 | ---- | C] () -- C:\Windows\SysWow64\PICSDK.ini
[2011/10/27 20:23:27 | 000,000,079 | ---- | C] () -- C:\Windows\EWF325.ini
[2011/10/25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/08/23 15:38:06 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2011/08/22 18:43:33 | 000,045,568 | ---- | C] () -- C:\Users\Randy\AppData\Roaming\DiabloIIMapHack v1.3.exe
[2011/08/19 13:24:19 | 000,154,112 | ---- | C] () -- C:\Windows\SysWow64\WSContextMenu.dll
[2011/08/10 15:17:21 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2011/07/25 14:06:40 | 000,004,670 | ---- | C] () -- C:\Users\Randy\swap.xml
[2011/07/25 14:06:38 | 000,017,380 | ---- | C] () -- C:\Users\Randy\ims_radios.xml
[2011/03/03 12:20:19 | 000,044,544 | ---- | C] () -- C:\Windows\SysWow64\GIF89.DLL
[2011/02/27 03:37:22 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/15 11:47:22 | 000,000,024 | ---- | C] () -- C:\Windows\SysWow64\sysogg.dll
[2011/02/15 11:46:01 | 000,484,352 | ---- | C] () -- C:\Windows\SysWow64\lame_enc.dll
[2011/01/02 12:28:38 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/01/02 12:28:30 | 000,103,736 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2010/12/24 15:35:43 | 000,000,122 | ---- | C] () -- C:\Windows\WA.INI
[2010/12/09 12:11:05 | 000,230,752 | ---- | C] () -- C:\Windows\patchw32.dll
[2010/12/09 12:11:05 | 000,118,176 | ---- | C] () -- C:\Windows\patchw.dll
[2010/12/03 02:52:16 | 000,000,000 | ---- | C] () -- C:\Windows\eDrawingOfficeAutomator.INI
[2010/10/25 02:12:43 | 000,153,600 | ---- | C] () -- C:\Windows\SysWow64\WS_ATLMovie.dll
[2010/09/27 20:05:44 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2010/09/27 20:05:44 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\statistics.dat
[2010/09/27 20:05:44 | 000,000,039 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2010/09/27 15:53:58 | 000,001,324 | ---- | C] () -- C:\Windows\ntbackup.ini
[2010/09/27 14:46:27 | 000,034,296 | ---- | C] () -- C:\Windows\SysWow64\drivers\mbamcatchme.sys
[2010/09/27 14:46:27 | 000,015,864 | ---- | C] () -- C:\Windows\SysWow64\drivers\mbam.sys
[2010/09/14 10:31:04 | 000,000,001 | ---- | C] () -- C:\Windows\SysWow64\SI.bin
[2010/09/09 17:39:02 | 000,065,536 | ---- | C] () -- C:\Windows\IFinst27.exe
[2010/09/01 12:12:43 | 1689,327,695 | ---- | C] () -- C:\Windows\SysWow64\RareROFull.exe
[2010/08/25 12:31:36 | 000,000,202 | ---- | C] () -- C:\Users\Randy\AppData\Roaming\default.rss
[2010/08/25 12:31:16 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2010/08/10 16:00:32 | 000,000,004 | ---- | C] () -- C:\Windows\info147.sys
[2010/07/30 02:18:04 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
========== LOP Check ==========
[2011/01/14 20:42:06 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Asguaard_Saves
[2012/04/13 16:03:53 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\asoftech
[2011/05/22 01:52:01 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Audacity
[2012/06/06 14:09:39 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\BitCometLite
[2011/12/12 22:13:30 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\BITS
[2010/07/17 17:46:09 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\BoneTown
[2010/12/15 03:48:12 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\BugTrap Console Test108
[2010/12/03 02:59:15 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\CB Model Pro
[2010/07/18 16:44:09 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\DAEMON Tools Lite
[2010/12/03 02:52:25 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\DassaultSystemes
[2012/04/23 19:15:33 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Easeware
[2010/12/03 02:52:25 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\EDrawings
[2011/12/28 00:07:25 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Epson
[2010/09/28 12:58:00 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\EyeballChatAvatars
[2010/09/28 13:53:13 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\EyeballChatUserData
[2012/06/09 14:29:14 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FirstColony
[2011/01/17 04:47:10 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FishinFortune
[2011/12/12 21:54:21 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FlashGet
[2012/04/23 19:46:06 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FlashGetBHO
[2012/02/22 00:49:21 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FOG Downloader
[2011/12/17 20:57:23 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\FreeBurner
[2012/07/23 20:01:41 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\GameRanger
[2010/12/24 15:39:13 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\GetRightToGo
[2011/05/21 02:17:53 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Hi-Rez Studios
[2010/09/02 11:58:02 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\ImgBurn
[2012/07/14 15:51:09 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\ImTOO
[2011/01/21 20:44:48 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Leadertech
[2010/07/22 21:52:54 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\LimeWire
[2010/11/12 20:45:23 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\LolClient
[2011/05/07 06:14:45 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\mkvtoolnix
[2011/11/04 22:13:01 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Mumble
[2010/12/11 13:12:10 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Need for Speed World
[2011/12/31 18:11:25 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\NPLUTO Corporation
[2012/03/28 17:16:00 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Opera
[2012/05/28 12:37:02 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\RIFT
[2011/11/12 18:06:14 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\SanDisk
[2011/01/27 02:59:51 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Secret of the Solstice
[2012/04/23 19:00:07 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\SystemRequirementsLab
[2011/10/01 02:55:50 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\TeamViewer
[2012/04/23 18:14:09 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\TS3Client
[2011/09/10 23:16:30 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Tunngle
[2010/10/22 20:33:22 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Utherverse
[2012/07/25 10:48:39 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\uTorrent
[2011/01/17 04:52:35 | 000,000,000 | ---D | M] -- C:\Users\Randy\AppData\Roaming\Voodoo
[2012/07/26 19:41:30 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001Core.job
[2012/07/26 19:27:21 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-300263774-3026266254-749598526-1001UA.job
[2012/07/26 13:01:40 | 000,032,600 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:6BF0805F
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:A3C2A225
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A9662AE0
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:75D366A3
< End of report >