CHR - homepage:
http://easy-google-search.blogspot.com/
CHR - default_search_provider: Conduit (Enabled)
CHR - default_search_provider: search_url =
http://search.conduit.com/Results.aspx?q={searchTerms}&SearchSource=49&ctid=CT2402945
CHR - default_search_provider: suggest_url =
http://search.conduit.com/,
CHR - homepage:
http://easy-google-search.blogspot.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Leon\AppData\Local\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Leon\AppData\Local\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_270.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Leon\AppData\Local\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Leon\AppData\Local\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpjidcokcfencofcmondgimdoobddnoe\2.3.15.509_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.290.11 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U29 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npdivx32.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw_1165635.dll
CHR - Extension: YouTube = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Facebook Colour Changer = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpllmoilcakpgbeodibeifcfnndoheam\1.3.1_0\
CHR - Extension: Pandora to Spotify Playlist Converter = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgkmfkggcmoclhipfkabaemflflellek\0.4.1_0\
CHR - Extension: Google Search = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: PandoraControl Beta = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\dckjilenognecmpjjpeckgekikdpchli\0.2.3_0\
CHR - Extension: FB Photo Zoom = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi\1.1206.11.1_0\
CHR - Extension: Facebook Background Changer = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\emnlfbokmiehpnhgdjlmedakkchfldmj\3.0.18_0\
CHR - Extension: Pandora = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: AdBlock = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.41_0\
CHR - Extension: Last.fm Scrobbler = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhinaapppaileiechjoiifaancjggfjm\1.9_0\
CHR - Extension: Weather Window by WeatherBug = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\1.0.12_0\
CHR - Extension: Command & Conquer Tiberium Alliances = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeopgjojikeoiidmfaejkifhgjoooe\1.0.6_0\
CHR - Extension: Typing Test - KeyHero = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm\1.4.0_0\
CHR - Extension: FVD Video Downloader = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfmhcpmkbdkbgbmkjoiopeeegenkdikp\1.2.9_0\
CHR - Extension: Fieldrunners = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkpikhjbfbffdblahfidklcohlaeabak\1.0.0.5_0\
CHR - Extension: 3D Solar System Web = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdaaepplopehigjgkolniddiadbbkphd\0.32_0\
CHR - Extension: DSL speedtest = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj\1.1_0\
CHR - Extension: 3Dnator! = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nhgjpfdjhlimkkdgnecbgnefdafbcncc\1.0.12_0\
CHR - Extension: Play (Grooveshark\u2122, Google Music\u2122, Pandora\u2122) = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ocimhajpehjmepnegklahceceebnened\2.3_0\
CHR - Extension: iCloud Dashboard 2 = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojmdhklabgbnnkkilmkcfcemdhognifc\2.0.4.1_0\
CHR - Extension: iCloud = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjfjiepcafjlmaopmmdfcmdjldjfhlki\1.0.0_0\
CHR - Extension: Gmail = C:\Users\Leon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/08/23 16:17:04 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Lexmark Printable Web) - {D2C5E510-BE6D-42CC-9F61-E4F939078474} - C:\Program Files\Lexmark Printable Web\bho.dll ()
O2 - BHO: (ChromeFrame BHO) - {ECB3C477-1A0A-44BD-BB57-78F9EFE34FA7} - C:\Program Files (x86)\Google\Chrome Frame\Application\21.0.1180.83\npchrome_frame.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [AccuWeatherWidget] C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] j:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Monitor] C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe (LeapFrog Enterprises, Inc.)
O4 - HKLM..\Run: [WRSVC] C:\Program Files\Webroot\WRSA.exe (Webroot)
O4 - HKCU..\Run: [DAEMON Tools Pro Agent] C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe (DT Soft Ltd)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [Plex Media Server] C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe (Plex, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O4 - Startup: C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_25156082.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDevMgrUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSetTaskbar = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDeletePrinter = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDFSTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogoff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoEncryptOnMove = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoRunasInstallPrompt = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoHardwareTab = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuSubFolders = 0
O8:
64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:
64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533}
https://oas.support.microsoft.com/ActiveX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {362C56AA-6E4F-40C7-A0B5-85501DBDAD77}
http://I.dell.com/images/global/js/scanner/SysProExe.cab (Scanner.SysScanner)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.5.1.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{367D4C99-2C77-4799-A525-C75D9930EBE0}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\cozi - No CLSID value found
O18:
64bit: - Protocol\Handler\gcf - No CLSID value found
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\cozi {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll (Cozi Group, Inc.)
O18 - Protocol\Handler\gcf {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - C:\Program Files (x86)\Google\Chrome Frame\Application\21.0.1180.83\npchrome_frame.dll (Google Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\615\G2AWinLogon_x64.dll) - C:\Program Files (x86)\Citrix\GoToAssist\615\g2awinlogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O29:
64bit: - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29:
64bit: - HKLM SecurityProviders - (digest.dll) - File not found
O29:
64bit: - HKLM SecurityProviders - (msnsspc.dll) - File not found
O29 - HKLM SecurityProviders - (msapsspc.dll) - File not found
O29 - HKLM SecurityProviders - (digest.dll) - File not found
O29 - HKLM SecurityProviders - (msnsspc.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (Partizan)
O34 - HKLM BootExecute: (ootExecute settings...)
O34 - HKLM BootExecute: (ount)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/23 16:27:29 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/22 21:53:17 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/22 21:53:17 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/22 21:53:17 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/22 21:53:11 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/22 21:53:03 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/22 21:52:39 | 004,736,524 | R--- | C] (Swearware) -- C:\Users\Leon\Desktop\ComboFix_2.exe
[2012/08/22 12:32:34 | 000,000,000 | ---D | C] -- C:\Users\Leon\Desktop\Virus removal help
[2012/08/22 09:00:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2012/08/21 05:38:56 | 000,000,000 | ---D | C] -- C:\Reg help
[2012/08/19 18:07:52 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Local\Ubisoft Game Launcher
[2012/08/19 18:07:50 | 000,000,000 | ---D | C] -- C:\Users\Leon\Documents\Settlers7
[2012/08/19 18:05:57 | 000,000,000 | ---D | C] -- C:\Users\Leon\Desktop\New Folder (3)
[2012/08/18 04:02:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/18 04:02:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/18 03:58:23 | 000,039,184 | ---- | C] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012/08/18 03:56:10 | 000,000,000 | ---D | C] -- C:\ProgramData\RegRun
[2012/08/18 01:30:09 | 000,000,000 | ---D | C] -- C:\Users\Leon\Desktop\Warrior
[2012/08/17 05:29:45 | 000,000,000 | ---D | C] -- C:\BackSys
[2012/08/17 04:05:10 | 000,039,184 | ---- | C] (Greatis Software) -- C:\Windows\SysWow64\Partizan.exe
[2012/08/17 04:05:10 | 000,035,816 | ---- | C] (Greatis Software) -- C:\Windows\SysWow64\drivers\Partizan.sys
[2012/08/17 04:05:08 | 000,000,000 | ---D | C] -- C:\Users\Leon\Documents\RegRun2
[2012/08/17 04:05:07 | 000,012,800 | ---- | C] (Greatis Software, LLC.) -- C:\Windows\SysWow64\drivers\UnHackMeDrv.sys
[2012/08/17 04:05:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
[2012/08/17 04:05:07 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\regruninfo
[2012/08/17 04:05:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UnHackMe
[2012/08/16 00:30:31 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2012/08/16 00:27:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Oberon Media
[2012/08/15 08:01:07 | 000,000,000 | ---D | C] -- C:\GameHouse Games
[2012/08/14 10:03:45 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\Pogo Games
[2012/08/14 09:31:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PogoDGC
[2012/08/14 09:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\PogoDGC
[2012/08/14 09:28:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pogo Games
[2012/08/14 09:28:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Pogo Games
[2012/08/14 09:01:32 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gutterball Golden Pin Bowling
[2012/08/14 09:01:24 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Gutterball Golden Pin Bowling
[2012/08/13 10:37:28 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Local\CRE
[2012/08/13 09:50:35 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\TuneUpMedia
[2012/08/13 09:50:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Trymedia
[2012/08/13 09:50:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameHouse
[2012/08/13 09:50:01 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\OpenCandy
[2012/08/11 08:39:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
[2012/08/09 21:07:21 | 000,000,000 | ---D | C] -- C:\Users\Leon\Documents\THE SETTLERS - Rise of an Empire
[2012/08/09 21:00:10 | 000,000,000 | ---D | C] -- C:\ProgramData\Media Center Programs
[2012/08/09 19:09:26 | 000,000,000 | ---D | C] -- C:\Ubisoft
[2012/08/09 19:08:36 | 000,000,000 | ---D | C] -- C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
[2012/08/09 18:59:25 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2012/08/01 21:18:06 | 000,102,832 | ---- | C] (Webroot) -- C:\Windows\SysNative\WRusr.dll
[2012/08/01 21:18:05 | 000,149,688 | ---- | C] (Webroot) -- C:\Windows\SysWow64\WRusr.dll
[2012/08/01 21:18:05 | 000,110,096 | ---- | C] (Webroot) -- C:\Windows\SysNative\drivers\WRkrn.sys
[2012/08/01 21:18:04 | 000,000,000 | ---D | C] -- C:\Program Files\Webroot
[2012/08/01 21:17:59 | 000,000,000 | ---D | C] -- C:\ProgramData\WRData
[2012/07/27 16:31:43 | 000,701,499 | ---- | C] (CheatHappens) -- C:\Users\Leon\Desktop\sr3-bud11dy.exe
[2012/07/26 15:41:38 | 000,000,000 | ---D | C] -- C:\Users\Leon\Desktop\Fair
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/08/24 03:41:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3191922543-261891716-3115826397-1000UA.job
[2012/08/24 03:38:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/24 03:38:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/24 03:29:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/23 16:35:17 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/23 16:35:17 | 000,021,296 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/23 16:27:15 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/23 16:25:54 | 1059,942,398 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/23 16:17:04 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/08/23 16:16:46 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/08/23 06:41:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3191922543-261891716-3115826397-1000Core.job
[2012/08/22 21:52:33 | 004,736,524 | R--- | M] (Swearware) -- C:\Users\Leon\Desktop\ComboFix_2.exe
[2012/08/22 09:00:00 | 000,001,008 | ---- | M] () -- C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_25156082.lnk
[2012/08/22 08:58:50 | 000,000,512 | ---- | M] () -- C:\Users\Leon\Documents\MBR.dat
[2012/08/21 18:50:22 | 000,849,724 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/08/21 18:50:22 | 000,708,206 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/08/21 18:50:22 | 000,142,788 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/08/21 17:41:39 | 000,002,447 | ---- | M] () -- C:\Users\Leon\Desktop\Google Chrome.lnk
[2012/08/21 15:40:12 | 000,001,981 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/21 06:05:33 | 000,088,480 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012/08/21 06:05:33 | 000,046,400 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012/08/21 04:53:29 | 000,149,688 | ---- | M] (Webroot) -- C:\Windows\SysWow64\WRusr.dll
[2012/08/21 04:53:29 | 000,110,096 | ---- | M] (Webroot) -- C:\Windows\SysNative\drivers\WRkrn.sys
[2012/08/21 04:53:29 | 000,102,832 | ---- | M] (Webroot) -- C:\Windows\SysNative\WRusr.dll
[2012/08/18 04:03:06 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/18 04:02:55 | 000,863,382 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/08/18 03:58:23 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\SysNative\Partizan.exe
[2012/08/18 01:37:10 | 000,000,537 | -H-- | M] () -- C:\regrun.war
[2012/08/17 04:05:10 | 000,039,184 | ---- | M] (Greatis Software) -- C:\Windows\SysWow64\Partizan.exe
[2012/08/17 04:05:10 | 000,035,816 | ---- | M] (Greatis Software) -- C:\Windows\SysWow64\drivers\Partizan.sys
[2012/08/17 04:05:09 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\CONFIG.NT
[2012/08/17 04:05:09 | 000,000,002 | RHS- | M] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012/08/17 04:05:07 | 000,000,905 | ---- | M] () -- C:\Users\Leon\Desktop\UnHackMe.lnk
[2012/08/16 00:30:31 | 000,002,130 | ---- | M] () -- C:\Users\Leon\Desktop\Way To Go! Bowling.lnk
[2012/08/16 00:30:31 | 000,001,142 | ---- | M] () -- C:\Users\Leon\Desktop\Pogo Games.lnk
[2012/08/14 09:31:21 | 000,002,030 | ---- | M] () -- C:\Users\Public\Desktop\Way To Go Bowling.lnk
[2012/08/14 09:28:12 | 000,001,880 | ---- | M] () -- C:\Users\Leon\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Pogo Games.lnk
[2012/08/14 09:28:12 | 000,001,856 | ---- | M] () -- C:\Users\Public\Desktop\Play Pogo Games.lnk
[2012/08/14 09:01:32 | 000,002,050 | ---- | M] () -- C:\Users\Leon\Desktop\Gutterball Golden Pin Bowling.lnk
[2012/08/13 09:50:04 | 000,000,143 | ---- | M] () -- C:\Users\Leon\Desktop\More Games at GameHouse.com.url
[2012/08/13 08:07:51 | 000,001,866 | ---- | M] () -- C:\Users\Leon\Desktop\Rocket Bowl.lnk
[2012/08/11 08:29:39 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/08/09 21:07:09 | 000,000,760 | ---- | M] () -- C:\Users\Leon\Desktop\THE SETTLERS - Rise of an Empire - Shortcut.lnk
[2012/08/09 19:08:36 | 000,000,334 | ---- | M] () -- C:\Users\Leon\Desktop\Ghost Recon Online (NCSA-Live).appref-ms
[2012/08/09 14:04:58 | 000,291,904 | ---- | M] () -- C:\Users\Leon\Desktop\set6-bud11dy.exe
[2012/08/05 14:13:29 | 000,003,584 | ---- | M] () -- C:\Users\Leon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/05 03:37:34 | 000,000,821 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/27 09:30:44 | 000,701,499 | ---- | M] (CheatHappens) -- C:\Users\Leon\Desktop\sr3-bud11dy.exe
[2012/07/27 03:51:35 | 000,095,338 | ---- | M] () -- C:\Users\Leon\Documents\LSutton_Resume.pdf
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/08/22 21:53:17 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/22 21:53:17 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/22 21:53:17 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/22 21:53:17 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/22 21:53:17 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/08/22 09:00:00 | 000,001,008 | ---- | C] () -- C:\Users\Leon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\_uninst_25156082.lnk
[2012/08/22 08:58:50 | 000,000,512 | ---- | C] () -- C:\Users\Leon\Documents\MBR.dat
[2012/08/21 16:15:00 | 000,002,944 | ---- | C] () -- C:\Windows\SKLANG.INI
[2012/08/18 04:02:57 | 000,001,917 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/17 05:27:29 | 000,000,537 | -H-- | C] () -- C:\regrun.war
[2012/08/17 04:05:09 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\CONFIG.NT
[2012/08/17 04:05:09 | 000,000,002 | RHS- | C] () -- C:\Windows\SysWow64\AUTOEXEC.NT
[2012/08/17 04:05:07 | 000,000,905 | ---- | C] () -- C:\Users\Leon\Desktop\UnHackMe.lnk
[2012/08/16 00:30:31 | 000,002,130 | ---- | C] () -- C:\Users\Leon\Desktop\Way To Go! Bowling.lnk
[2012/08/16 00:30:31 | 000,001,142 | ---- | C] () -- C:\Users\Leon\Desktop\Pogo Games.lnk
[2012/08/14 09:31:21 | 000,002,030 | ---- | C] () -- C:\Users\Public\Desktop\Way To Go Bowling.lnk
[2012/08/14 09:28:12 | 000,001,880 | ---- | C] () -- C:\Users\Leon\Application Data\Microsoft\Internet Explorer\Quick Launch\Play Pogo Games.lnk
[2012/08/14 09:28:12 | 000,001,856 | ---- | C] () -- C:\Users\Public\Desktop\Play Pogo Games.lnk
[2012/08/14 09:01:32 | 000,002,050 | ---- | C] () -- C:\Users\Leon\Desktop\Gutterball Golden Pin Bowling.lnk
[2012/08/13 09:50:04 | 000,000,143 | ---- | C] () -- C:\Users\Leon\Desktop\More Games at GameHouse.com.url
[2012/08/09 21:07:09 | 000,000,760 | ---- | C] () -- C:\Users\Leon\Desktop\THE SETTLERS - Rise of an Empire - Shortcut.lnk
[2012/08/09 21:05:58 | 000,291,904 | ---- | C] () -- C:\Users\Leon\Desktop\set6-bud11dy.exe
[2012/08/09 21:00:04 | 000,088,480 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2012/08/09 21:00:04 | 000,046,400 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2012/08/09 19:08:36 | 000,000,334 | ---- | C] () -- C:\Users\Leon\Desktop\Ghost Recon Online (NCSA-Live).appref-ms
[2012/08/08 18:05:57 | 000,001,981 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/05 14:09:10 | 000,003,584 | ---- | C] () -- C:\Users\Leon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/27 05:39:12 | 000,000,110 | ---- | C] () -- C:\Users\Leon\Desktop\More Trainers @ GameCopyWorld.url
[2012/07/27 03:51:35 | 000,095,338 | ---- | C] () -- C:\Users\Leon\Documents\LSutton_Resume.pdf
[2012/07/14 15:31:57 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012/06/13 20:47:04 | 000,000,068 | ---- | C] () -- C:\Windows\spwdr.INI
[2012/06/13 20:46:20 | 000,000,077 | ---- | C] () -- C:\Windows\Crypkey.ini
[2012/06/13 20:46:17 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
[2012/06/13 20:46:17 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2012/06/13 20:46:17 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
[2012/06/13 20:46:15 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\StellarProfile.dll
[2012/05/15 02:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/02/26 12:42:39 | 000,000,319 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2012/01/16 04:17:01 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/01/16 04:17:01 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2012/01/09 19:17:50 | 000,000,600 | ---- | C] () -- C:\Users\Leon\AppData\Roaming\winscp.rnd
[2011/11/25 19:33:02 | 001,036,288 | ---- | C] () -- C:\Windows\SysWow64\lxdudrs.dll
[2011/11/25 19:33:02 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\lxducaps.dll
[2011/11/25 19:33:02 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\lxducnv4.dll
[2011/11/25 19:32:47 | 001,069,056 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduserv.dll
[2011/11/25 19:32:47 | 000,860,160 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduusb1.dll
[2011/11/25 19:32:47 | 000,651,264 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdupmui.dll
[2011/11/25 19:32:47 | 000,577,536 | ---- | C] ( ) -- C:\Windows\SysWow64\lxdulmpm.dll
[2011/11/25 19:32:47 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\LXDUinst.dll
[2011/11/25 19:32:47 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduinpa.dll
[2011/11/25 19:32:47 | 000,339,968 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduiesc.dll
[2011/11/25 19:32:47 | 000,335,872 | ---- | C] () -- C:\Windows\SysWow64\lxducomx.dll
[2011/11/25 19:32:46 | 000,761,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxducomc.dll
[2011/11/25 19:32:46 | 000,684,032 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduhbn3.dll
[2011/11/25 19:32:46 | 000,589,824 | ---- | C] ( ) -- C:\Windows\SysWow64\lxducoms.exe
[2011/11/25 19:32:46 | 000,376,832 | ---- | C] ( ) -- C:\Windows\SysWow64\lxducomm.dll
[2011/11/25 19:32:46 | 000,364,544 | ---- | C] ( ) -- C:\Windows\SysWow64\lxducfg.exe
[2011/11/25 19:32:46 | 000,323,584 | ---- | C] ( ) -- C:\Windows\SysWow64\lxduih.exe
[2011/10/25 22:21:48 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/10/25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/10/25 21:38:38 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/10/25 21:38:38 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/09/12 18:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/31 15:23:49 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/08/31 13:42:10 | 000,001,264 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2011/08/31 13:42:10 | 000,001,247 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2011/08/31 13:42:10 | 000,001,247 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2011/08/31 13:42:07 | 000,177,664 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011/08/31 13:42:07 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/02/10 12:10:51 | 000,863,382 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
========== LOP Check ==========
[2012/05/26 17:01:43 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Acronis
[2012/01/16 04:24:56 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Babylon
[2012/02/05 19:44:59 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\calibre
[2012/07/16 21:53:22 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/07/17 20:38:55 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2012/03/13 02:24:29 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Command and Conquer 4
[2011/11/21 05:32:21 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\DAEMON Tools Pro
[2012/08/23 15:56:34 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\DMCache
[2011/11/22 20:46:55 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Fanda Games
[2011/11/20 06:22:38 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Fingertapps
[2012/05/02 08:42:09 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\HideIPEasy
[2012/08/17 04:44:03 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\IDM
[2011/11/20 06:22:19 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Leadertech
[2011/12/06 10:41:38 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Lexmark Productivity Studio
[2012/08/13 09:50:03 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\OpenCandy
[2012/02/20 11:01:51 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Origin
[2011/11/20 15:03:17 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\PCDr
[2012/08/14 10:03:45 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Pogo Games
[2012/02/26 08:33:18 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\redsn0w
[2012/03/23 19:47:05 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Rovio
[2012/05/27 00:35:46 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Seas0nPass
[2012/01/24 19:16:00 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Sierra Entertainment
[2012/04/09 18:05:10 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\SystemRequirementsLab
[2011/12/03 07:35:53 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Thinstall
[2012/04/11 19:16:17 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\TomTom
[2012/08/13 21:25:01 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\TuneUpMedia
[2011/11/27 05:32:39 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Ubisoft
[2012/08/24 04:00:56 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\uTorrent
[2012/01/02 10:10:11 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\wargaming.net
[2011/12/23 15:42:57 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\WindSolutions
[2012/04/08 07:22:23 | 000,000,000 | ---D | M] -- C:\Users\Leon\AppData\Roaming\Wondershare Video Converter Ultimate
[2012/08/11 08:29:39 | 000,000,564 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 01:08:49 | 000,029,678 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/08/23 16:16:46 | 000,000,506 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 187 bytes -> C:\ProgramData\Temp:2D0C22DC
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp

32974C3
< End of report >