IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&form=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{2F3A1C9A-B38B-4B23-9E3D-A047B6C52C2E}: "URL" =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" =
http://search.ask.com/web?q={searchterms}&l=dis&o=HPNTDF
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=HPNTDF
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" =
http://en.wikipedia.org/wiki/Special:Search?search={searchTerms}
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" =
http://rover.ebay.com/rover/1/711-30572-11896-2/4?mpre=http://shop.ebay.com/?_nkw={searchTerms}
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&fr=chr-atty
IE - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://yahoo.com/"
FF - prefs.js..network.proxy.type: 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: C:\Program Files (x86)\Common Files\Motive\npMotive.dll (Alcatel-Lucent)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/02/05 16:29:29 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/06/30 11:25:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/24 16:59:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/11 11:51:37 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/24 16:59:50 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/11 11:51:37 | 000,000,000 | ---D | M]
[2012/01/08 11:22:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taira\AppData\Roaming\Mozilla\Extensions
[2012/06/12 09:30:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Taira\AppData\Roaming\Mozilla\Firefox\Profiles\tc846fhp.default\extensions
[2012/06/08 20:57:30 | 000,000,000 | ---D | M] (ADDICT-THING) -- C:\Users\Taira\AppData\Roaming\Mozilla\Firefox\Profiles\tc846fhp.default\extensions\
4fd2aa9f34015@4fd2aa9f3404e.info
[2012/02/22 20:31:56 | 000,001,976 | ---- | M] () -- C:\Users\Taira\AppData\Roaming\Mozilla\Firefox\Profiles\tc846fhp.default\searchplugins\duckduckgo.xml
[2012/03/10 12:53:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/01/22 19:16:04 | 000,000,000 | ---D | M] (TrueSuite Website Logon) -- C:\Program Files (x86)\Mozilla Firefox\extensions\
websitelogon@truesuite.com
[2012/06/30 11:25:24 | 000,000,000 | ---D | M] (McAfee ScriptScan for Firefox) -- C:\PROGRAM FILES (X86)\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/02/05 16:29:29 | 000,000,000 | ---D | M] (McAfee SiteAdvisor) -- C:\PROGRAM FILES (X86)\MCAFEE\SITEADVISOR
[2012/05/16 01:49:03 | 000,550,833 | ---- | M] () (No name found) -- C:\USERS\TAIRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TC846FHP.DEFAULT\EXTENSIONS\
DIVXWEBPLAYER@DIVX.COM.XPI
[2012/03/04 02:08:38 | 000,003,326 | ---- | M] () (No name found) -- C:\USERS\TAIRA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TC846FHP.DEFAULT\EXTENSIONS\
LOJIRZUUKD@LOJIRZUUKD.ORG.XPI
[2012/06/25 00:00:45 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/25 00:00:39 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/25 00:00:39 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2012/07/29 16:31:59 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120630095920.dll (McAfee, Inc.)
O2:
64bit: - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\x64\IEBHO.dll (HP)
O2:
64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20120630095920.dll (McAfee, Inc.)
O2 - BHO: (TrueSuite Website Log On) - {8590886E-EC8C-43C1-A32C-E4C2B0B6395B} - C:\Program Files (x86)\HP SimplePass 2011\IEBHO.dll (HP)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:
64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O4:
64bit: - HKLM..\Run: [ATT-SST_McciTrayApp] C:\Program Files\ATT-SST\McciTrayApp.exe (Alcatel-Lucent)
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Easybits Recovery] C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe (EasyBits Software AS)
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O15 - HKU\S-1-5-21-2656346458-3139568991-3301255850-1001\..Trusted Domains: $talisma_url$ ([]https in Trusted sites)
O16:
64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:
64bit: - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F31B9B1F-2C1D-419C-B5A2-A59F786AF7BE}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {E54729E8-BB3D-4270-9D49-7389EA579090} - C:\Windows\SysWOW64\ezUPBHook.dll (EasyBits Software Corp.)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/29 18:36:18 | 000,597,504 | ---- | C] (OldTimer Tools) -- C:\Users\Taira\Desktop\OTL.exe
[2012/07/29 17:07:21 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/29 17:03:24 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/29 16:13:22 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/29 16:13:22 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/29 16:13:22 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/29 15:46:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/29 15:45:54 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/29 15:30:37 | 004,721,417 | R--- | C] (Swearware) -- C:\Users\Taira\Desktop\ComboFix.exe
[2012/07/29 14:02:07 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/29 10:48:49 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{76A23F35-4A30-4CE4-BAB9-0F157D10E262}
[2012/07/29 10:48:38 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{48C5A5C5-A3AB-4F80-AF17-C6C6EE6ECABE}
[2012/07/29 00:41:33 | 000,000,000 | ---D | C] -- C:\Users\Taira\Desktop\TechSpot Virus Removal
[2012/07/28 21:31:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2012/07/28 21:31:45 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2012/07/28 21:30:42 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2012/07/28 19:04:53 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{A4940A8E-2711-449A-8903-4941999B4E2B}
[2012/07/28 19:04:09 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{D000321E-8BD3-40D3-9CF6-495EF0F2879B}
[2012/07/28 18:58:33 | 000,000,000 | ---D | C] -- C:\Windows\Sun
[2012/07/28 17:47:20 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{15CC67DC-FB83-44C4-8AA9-6BCAF33B0EC1}
[2012/07/28 12:45:24 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{4E4E0A16-F97A-4559-8E62-76AAD05E6B57}
[2012/07/26 13:58:15 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{62C94753-DC54-4852-AB43-AA985887687B}
[2012/07/25 13:35:31 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{65F2DE56-3D3B-49DA-8A45-1F8DBC4E95D7}
[2012/07/25 13:33:32 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{53F2F0FF-11E8-4B5B-B1AF-DB3EB09CB4C9}
[2012/07/24 14:44:34 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{3179DAE1-E77D-4AA6-B925-02417D08CE22}
[2012/07/24 14:44:02 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{E23616D5-C32F-40DD-9B01-7BEAF8A1E477}
[2012/07/24 08:48:04 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{EF1AC17F-D0FA-49B7-84A3-F87ECF96DDEC}
[2012/07/23 13:26:18 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{CB8C3BDD-E75B-4270-BE74-756FD8045950}
[2012/07/23 13:25:44 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{1B929CFF-49C1-4BED-8581-2455777DBE58}
[2012/07/22 13:34:13 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{C13F083B-3388-4110-BCF7-0185231DACFA}
[2012/07/21 09:58:56 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{183172E4-375E-47DF-B6FC-AE863CBA4DDA}
[2012/07/21 09:58:18 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{5C3CF144-28AB-4FB5-B7E1-0F8711B52F68}
[2012/07/20 14:02:13 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{588B2AB4-EFF6-404B-8AE4-45F8A29C2898}
[2012/07/19 13:44:18 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{041599DF-2EE4-4076-BD14-0A7F0B49D38F}
[2012/07/19 13:44:05 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{51E92146-CD34-41EE-ACDB-BA5941515F0A}
[2012/07/18 14:44:27 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{95236D71-D65B-4BB3-A13B-36FA0CEFB238}
[2012/07/18 14:43:57 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{4C692467-FB30-4764-A2E1-2FCAAE8F8FFB}
[2012/07/17 13:48:55 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{FC4D5D0C-78AD-4D14-9C26-D2FB61D76862}
[2012/07/17 13:48:45 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{1B4D8F32-14B1-496E-A88C-153822C27CE1}
[2012/07/15 17:32:08 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{F22FCA23-26A7-48A9-BFC1-142F05DAC788}
[2012/07/15 17:31:57 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{820BEF59-16EF-490D-8B47-FE6864BB607A}
[2012/07/13 14:36:54 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{84F7081A-73F8-4D0F-9B31-DE4A48E751E8}
[2012/07/13 14:36:32 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{AFC38C3D-4CF4-401C-9877-AD1A1862BAA6}
[2012/07/12 14:54:28 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{D91CC259-5E45-4483-A977-8D418634022C}
[2012/07/12 14:54:15 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{3454F60B-5390-4B36-9543-19CC9B90AFBE}
[2012/07/12 00:22:01 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{58414253-BA82-4AA6-AD1A-91001C22726E}
[2012/07/12 00:21:48 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{7DC959C8-EE96-452E-8F53-081900C1F540}
[2012/07/11 12:21:13 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{6427BFC6-8037-4D78-B083-A8E8EC270F54}
[2012/07/11 12:21:00 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{25BCD5BC-6808-4499-872B-927F7233E705}
[2012/07/10 23:55:51 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{6C8EBF9E-0BD2-417C-A0B3-D8F82C23A1D5}
[2012/07/10 23:55:39 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{24CE51A7-BE7A-48E6-A13E-49B56D5A781E}
[2012/07/09 22:11:33 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{D9FE6D65-70AA-4D35-9D40-FB73E56ADE93}
[2012/07/09 10:11:01 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{3BA09435-60F0-49BE-B779-D5A598E6457E}
[2012/07/09 10:10:49 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{DF4D4863-0C5D-4DB6-8FD2-9FF915E7D830}
[2012/07/08 12:36:05 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{BA92F027-5D38-4A7A-9701-AD7C02A08FC0}
[2012/07/08 12:35:33 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{C934DF11-FAC2-4037-BEEF-B3B44FB92192}
[2012/07/08 01:47:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-NFB Reading Technology
[2012/07/08 01:47:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eReaders and Document Viewers
[2012/07/08 01:46:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\K-NFB Reading Technology Inc
[2012/07/08 01:43:33 | 000,000,000 | ---D | C] -- C:\Program Files\PlayReady
[2012/07/08 01:42:27 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\Downloaded Installations
[2012/07/08 01:40:21 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\Kjs.AppLife.Update
[2012/07/07 23:36:44 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{398D0035-8FC7-4D3B-B71D-7D85FB59B416}
[2012/07/07 23:36:31 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{00CFBFD9-4A2D-4F00-87F1-74EDD67FFD2F}
[2012/07/07 11:15:42 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{FE3C6527-EBB3-4E62-883A-0BD43A76BD13}
[2012/07/06 23:04:10 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{E22D88B4-6610-488D-AE81-C9CB0D62DF39}
[2012/07/06 23:03:58 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{F27A37E8-890E-4438-A67C-CDFAC0E5BA32}
[2012/07/06 10:28:22 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{5160A866-CA8F-459C-9898-1493ACFB63BA}
[2012/07/06 10:28:03 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{A0B922D7-95B6-4700-A8E7-3D704EFAF055}
[2012/07/05 11:51:02 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{428BA977-2232-4995-ACC4-D463D9FB5C2D}
[2012/07/05 11:50:51 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{E826FB15-35B3-4E3B-9F62-F4F37883D639}
[2012/07/04 23:50:22 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{DF1A1604-81F5-43AE-A092-2219462FB5FA}
[2012/07/03 11:37:30 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{8CBB8B5F-5751-4921-B83B-00128D72EFDC}
[2012/07/02 11:16:55 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{4DC8CE57-7F0B-43E4-BB6B-F4C2F7F32CE4}
[2012/07/02 11:16:38 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{9BD77E3F-486C-498C-9582-84F150DB84FC}
[2012/06/30 09:51:47 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{E9F1933B-4E57-49D3-B947-F46CDC26A54E}
[2012/06/29 20:16:39 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{22418411-9CAB-442C-A7DB-D12350324F43}
[2012/06/29 20:16:30 | 000,000,000 | ---D | C] -- C:\Users\Taira\AppData\Local\{ACE271F0-E226-4C5A-8B4A-7A6ABE60CEE9}
[13 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/29 18:36:20 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Taira\Desktop\OTL.exe
[2012/07/29 18:35:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/29 18:17:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/29 17:14:40 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/29 17:14:40 | 000,032,064 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/29 17:13:50 | 002,973,148 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/29 17:13:50 | 000,992,010 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/29 17:13:50 | 000,006,212 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/29 17:10:12 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Security Center.lnk
[2012/07/29 17:06:37 | 2801,979,392 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/29 16:31:59 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/29 15:30:38 | 004,721,417 | R--- | M] (Swearware) -- C:\Users\Taira\Desktop\ComboFix.exe
[2012/07/28 21:47:03 | 000,001,897 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2012/07/28 21:37:49 | 000,003,736 | ---- | M] () -- C:\Windows\SysNative\.crusader
[2012/07/25 18:02:57 | 000,000,342 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForBABIILUV$.job
[2012/07/25 14:00:37 | 000,342,368 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/25 13:48:14 | 000,000,129 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2012/07/24 17:08:28 | 000,001,073 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/08 01:47:28 | 000,002,067 | ---- | M] () -- C:\Users\Public\Desktop\Blio eBooks.lnk
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/06/30 15:18:55 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForTaira.job
[13 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/29 16:13:22 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/29 16:13:22 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/29 16:13:22 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/29 16:13:22 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/29 16:13:22 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/28 21:37:49 | 000,003,736 | ---- | C] () -- C:\Windows\SysNative\.crusader
[2012/07/28 21:31:45 | 000,001,897 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2012/07/25 13:48:14 | 000,000,129 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2012/07/24 17:08:28 | 000,001,073 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/08 01:47:28 | 000,002,067 | ---- | C] () -- C:\Users\Public\Desktop\Blio eBooks.lnk
[2012/02/19 21:36:58 | 000,413,696 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtinpa.dll
[2012/02/19 21:36:58 | 000,397,312 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtiesc.dll
[2012/02/19 21:36:58 | 000,323,584 | ---- | C] ( ) -- C:\Windows\SysWow64\DLBThcp.dll
[2012/02/19 21:36:58 | 000,274,432 | ---- | C] () -- C:\Windows\SysWow64\DLBTinst.dll
[2012/02/19 21:36:58 | 000,135,168 | ---- | C] () -- C:\Windows\SysWow64\dlbtjswr.dll
[2012/02/19 21:36:58 | 000,106,496 | ---- | C] () -- C:\Windows\SysWow64\dlbtinsr.dll
[2012/02/19 21:36:58 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\dlbtcur.dll
[2012/02/19 21:36:57 | 000,643,072 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtpmui.dll
[2012/02/19 21:36:57 | 000,434,176 | ---- | C] () -- C:\Windows\SysWow64\dlbtutil.dll
[2012/02/19 21:36:57 | 000,176,128 | ---- | C] () -- C:\Windows\SysWow64\dlbtinsb.dll
[2012/02/19 21:36:57 | 000,159,744 | ---- | C] () -- C:\Windows\SysWow64\dlbtins.dll
[2012/02/19 21:36:56 | 001,224,704 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtserv.dll
[2012/02/19 21:36:56 | 000,995,328 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtusb1.dll
[2012/02/19 21:36:56 | 000,163,840 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtprox.dll
[2012/02/19 21:36:56 | 000,086,016 | ---- | C] () -- C:\Windows\SysWow64\dlbtcub.dll
[2012/02/19 21:36:56 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\dlbtcu.dll
[2012/02/19 21:36:55 | 000,696,320 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbthbn3.dll
[2012/02/19 21:36:55 | 000,585,728 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtlmpm.dll
[2012/02/19 21:36:55 | 000,386,544 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtih.exe
[2012/02/19 21:36:55 | 000,181,744 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtppls.exe
[2012/02/19 21:36:55 | 000,094,208 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtpplc.dll
[2012/02/19 21:36:54 | 000,684,032 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtcomc.dll
[2012/02/19 21:36:54 | 000,538,096 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtcoms.exe
[2012/02/19 21:36:54 | 000,421,888 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtcomm.dll
[2012/02/19 21:36:54 | 000,382,448 | ---- | C] ( ) -- C:\Windows\SysWow64\dlbtcfg.exe
[2012/02/19 21:36:53 | 000,069,632 | ---- | C] () -- C:\Windows\SysWow64\DLBTcfg.dll
[2012/02/03 19:28:02 | 000,002,048 | -HS- | C] () -- C:\Windows\SysWOW64\config\systemprofile\AppData\Local\{a6a1f5d1-9b89-34a1-1fa5-e81abdda6d59}\@
[2012/02/03 19:28:02 | 000,002,048 | -HS- | C] () -- C:\Windows\System32\config\systemprofile\AppData\Local\{a6a1f5d1-9b89-34a1-1fa5-e81abdda6d59}\@
[2011/12/03 17:54:41 | 000,000,632 | RHS- | C] () -- C:\Users\Taira\ntuser.pol
[2011/10/22 07:46:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/10/22 07:43:39 | 000,014,051 | ---- | C] () -- C:\Windows\SysWow64\RaCoInst.dat
[2011/10/22 07:39:51 | 000,006,344 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/22 07:27:51 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/08/29 20:40:04 | 000,000,068 | ---- | C] () -- C:\Windows\SysWow64\ezdigsgn.dat
[2011/03/21 21:56:22 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/03/17 18:51:46 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/03/03 23:04:58 | 000,007,736 | ---- | C] () -- C:\Windows\hpDSTRES.DLL
[2010/12/16 21:26:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
========== LOP Check ==========
[2012/05/14 00:26:34 | 000,000,000 | ---D | M] -- C:\Users\Amonte\AppData\Roaming\Synaptics
[2011/11/29 23:09:16 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\Blio
[2012/03/04 02:08:38 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\Flood Light Games
[2011/12/13 21:26:16 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\funkitron
[2012/07/28 17:42:30 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\SoftGrid Client
[2011/11/28 21:36:44 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\Synaptics
[2011/12/06 13:13:33 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\Tific
[2012/01/08 11:28:14 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\TP
[2011/12/25 20:40:24 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\WildTangentv1002
[2012/05/06 22:27:56 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\Windows Live Writer
[2011/12/11 19:23:37 | 000,000,000 | ---D | M] -- C:\Users\Taira\AppData\Roaming\_MDLogs
[2012/07/28 17:45:10 | 000,032,640 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >