OTL logfile created on: 8/17/2012 9:25:57 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Clinic 123\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.17 Gb Available Physical Memory | 58.37% Memory free
4.00 Gb Paging File | 3.19 Gb Available in Paging File | 79.82% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 73.14 Gb Total Space | 29.72 Gb Free Space | 40.63% Space Free | Partition Type: NTFS
Drive D: | 196.29 Gb Total Space | 29.52 Gb Free Space | 15.04% Space Free | Partition Type: NTFS
Drive E: | 196.23 Gb Total Space | 26.93 Gb Free Space | 13.73% Space Free | Partition Type: NTFS
Drive F: | 15.01 Gb Total Space | 8.16 Gb Free Space | 54.39% Space Free | Partition Type: NTFS
Drive G: | 44.68 Gb Total Space | 23.67 Gb Free Space | 52.97% Space Free | Partition Type: NTFS
Drive I: | 44.68 Gb Total Space | 33.87 Gb Free Space | 75.79% Space Free | Partition Type: NTFS
Drive J: | 44.66 Gb Total Space | 9.88 Gb Free Space | 22.12% Space Free | Partition Type: NTFS
Computer Name: CLINIC123-PC | User Name: Clinic 123 | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/17 00:42:50 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Clinic 123\Desktop\OTL.exe
PRC - [2012/02/02 14:31:08 | 002,668,864 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
PRC - [2009/07/14 05:44:20 | 002,613,248 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/07/02 15:03:28 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Stopped] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2010/08/26 06:27:04 | 000,176,128 | ---- | M] (AMD) [Auto | Stopped] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2010/08/12 14:18:40 | 000,033,584 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Stopped] -- C:\Program Files\ESET\ESET Smart Security\ekrn.exe -- (ekrn)
SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/12/24 02:04:20 | 000,370,688 | ---- | M] (StarWind Software) [Auto | Stopped] -- C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009/07/14 05:46:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 05:46:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 05:45:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/01/29 20:24:44 | 000,102,400 | ---- | M] (PacketVideo) [On_Demand | Stopped] -- C:\Program Files\Nokia\Nokia Home Media Server\Media Server\twonkymedia.exe -- (TwonkyMedia)
SRV - [2008/11/11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\Nokia\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2007/03/18 13:36:36 | 001,327,104 | ---- | M] (Macrovision Corporation) [Auto | Stopped] -- C:\OrCAD\license_manager\lmgrd.exe -- (Cadence License Manager)
SRV - [2006/07/25 18:28:16 | 000,200,704 | ---- | M] (National Instruments, Inc.) [Auto | Stopped] -- C:\Program Files\National Instruments\Shared\Security\nidmsrv.exe -- (NIDomainService)
SRV - [2006/07/25 18:28:10 | 000,057,344 | ---- | M] (National Instruments, Inc.) [Auto | Stopped] -- C:\Windows\System32\lktsrv.exe -- (lkTimeSync)
SRV - [2006/07/25 18:28:02 | 000,045,056 | ---- | M] (National Instruments, Inc.) [Auto | Stopped] -- C:\Windows\System32\lkads.exe -- (lkClassAds)
SRV - [2006/06/27 20:55:28 | 001,007,616 | ---- | M] (Macrovision Corporation) [On_Demand | Stopped] -- C:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe -- (NILM License Manager)
SRV - [2006/06/19 15:01:52 | 000,688,190 | ---- | M] (National Instruments, Inc.) [Auto | Stopped] -- C:\Windows\System32\lkcitdl.exe -- (LkCitadelServer)
SRV - [2006/02/06 17:46:42 | 000,049,152 | ---- | M] (National Instruments Corp.) [Auto | Stopped] -- C:\Windows\System32\nisvcloc.exe -- (niSvcLoc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\CLINIC~1\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2012/04/23 15:56:26 | 000,096,056 | ---- | M] (Tonec Inc.) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2012/03/31 12:40:14 | 000,242,240 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV - [2011/07/02 12:22:12 | 000,278,728 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\atksgt.sys -- (atksgt)
DRV - [2011/07/02 12:22:11 | 000,025,416 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2011/05/06 16:20:57 | 000,011,264 | ---- | M] (Windows (R) Win 7 DDK provider) [File_System | Boot | Running] -- C:\Windows\System32\drivers\fmsg.sys -- (fmsg)
DRV - [2011/04/26 16:58:44 | 000,145,920 | ---- | M] (ITE ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\IT9135BDA.sys -- (IT9135BDA)
DRV - [2010/11/09 15:35:30 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\cpuz135_x32.sys -- (cpuz135)
DRV - [2010/08/26 08:06:28 | 006,380,032 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2010/08/26 05:50:36 | 000,221,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2010/07/29 13:31:26 | 000,136,632 | ---- | M] (ESET) [File_System | Auto | Stopped] -- C:\Windows\System32\drivers\eamonm.sys -- (eamonm)
DRV - [2010/07/29 13:31:26 | 000,134,512 | ---- | M] (ESET) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\epfw.sys -- (epfw)
DRV - [2010/07/29 13:31:26 | 000,115,008 | ---- | M] (ESET) [Kernel | System | Stopped] -- C:\Windows\System32\drivers\ehdrv.sys -- (ehdrv)
DRV - [2010/07/29 13:31:26 | 000,041,336 | ---- | M] (ESET) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\epfwwfp.sys -- (epfwwfp)
DRV - [2010/07/29 13:31:26 | 000,032,608 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\epfwndis.sys -- (Epfwndis)
DRV - [2010/07/15 17:17:36 | 000,101,904 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2010/01/29 11:40:04 | 000,082,320 | ---- | M] (EZB Systems, Inc.) [File_System | System | Stopped] -- C:\Program Files\UltraISO\drivers\ISODrive.sys -- (ISODrive)
DRV - [2009/12/21 20:00:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (TEAM)
DRV - [2009/12/21 20:00:30 | 000,043,520 | ---- | M] (Realtek Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtTeam60.sys -- (RTTEAMPT)
DRV - [2009/07/20 06:56:40 | 000,027,648 | ---- | M] (Realtek ) [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\RtNdPt60.sys -- (RtNdPt60)
DRV - [2009/07/14 05:49:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2009/07/14 05:49:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2009/07/14 05:49:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2009/07/14 04:21:11 | 000,034,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2009/07/14 03:58:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2009/07/14 03:58:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2009/07/14 02:32:46 | 001,096,704 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/09/15 07:56:34 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2008/09/15 07:56:24 | 000,022,016 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2008/09/15 07:56:24 | 000,017,664 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2008/09/15 07:56:24 | 000,008,064 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/12/03 06:49:42 | 000,019,968 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtVlan60.sys -- (VLAN)
DRV - [2007/12/03 06:49:42 | 000,019,968 | ---- | M] (Windows (R) Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RtVlan60.sys -- (RTVLANPT)
DRV - [2007/04/09 09:50:34 | 000,009,600 | ---- | M] (Waytech Development, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\UsbFltr.sys -- (UsbFltr)
DRV - [2006/11/10 15:05:00 | 000,018,688 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
DRV - [2006/07/27 11:00:00 | 000,004,096 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\cvintdrv.sys -- (cvintdrv)
DRV - [1998/07/22 13:44:26 | 000,064,512 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\System32\drivers\SENTINEL.SYS -- (Sentinel)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = EE 49 09 57 53 7C CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "
www.google.com"
FF - prefs.js..network.proxy.ftp: "localhost"
FF - prefs.js..network.proxy.ftp_port: 8080
FF - prefs.js..network.proxy.http: "localhost"
FF - prefs.js..network.proxy.http_port: 8080
FF - prefs.js..network.proxy.socks: "localhost"
FF - prefs.js..network.proxy.socks_port: 1080
FF - prefs.js..network.proxy.ssl: "localhost"
FF - prefs.js..network.proxy.ssl_port: 8080
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/03/25 21:49:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\
eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2011/06/01 23:15:42 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
mozilla_cc@internetdownloadmanager.com: C:\Users\Clinic 123\AppData\Roaming\IDM\idmmzcc5 [2012/07/28 14:15:12 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\
mozilla_cc@internetdownloadmanager.com: C:\Users\Clinic 123\AppData\Roaming\IDM\idmmzcc5 [2012/07/28 14:15:12 | 000,000,000 | ---D | M]
[2012/03/25 21:52:20 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clinic 123\AppData\Roaming\mozilla\Extensions
[2012/07/26 14:59:17 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Clinic 123\AppData\Roaming\mozilla\Firefox\Profiles\2yxm0cjs.default\extensions
[2012/03/25 21:49:18 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/07/28 14:15:12 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\CLINIC 123\APPDATA\ROAMING\IDM\IDMMZCC5
[2012/07/26 14:59:17 | 000,324,289 | ---- | M] () (No name found) -- C:\USERS\CLINIC 123\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2YXM0CJS.DEFAULT\EXTENSIONS\{F759CA51-3A91-4DD1-AE78-9DB5EEE9EBF0}.XPI
[2011/11/21 08:34:51 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/11/21 05:34:05 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/21 05:34:05 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Clinic 123\AppData\Local\Google\Chrome\Application\16.0.912.63\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Clinic 123\AppData\Local\Google\Chrome\Application\16.0.912.63\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Clinic 123\AppData\Local\Google\Chrome\Application\16.0.912.63\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java(TM) Platform SE 7 U3 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Clinic 123\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2_0\
CHR - Extension: Google Search = C:\Users\Clinic 123\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.14_0\
CHR - Extension: Gmail = C:\Users\Clinic 123\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\6.1.3_0\
O1 HOSTS File: ([2012/08/16 14:09:50 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [hpbdfawep] C:\Program Files\HP\Dfawep\bin\hpbdfawep.exe ()
O4 - HKLM..\Run: [HPUsageTracking] C:\Program Files\HP\HP UT\bin\hppusg.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToolBoxFX] C:\Program Files\HP\ToolBoxFX\bin\HPTLBXFX.exe (HP)
O4 - HKCU..\Run: [GoldenDict] C:\Program Files\GoldenDict\GoldenDict.exe (GoldenDict)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9FBDE429-3DB3-46F4-A9A6-04E8B6F905A7}: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/05/10 21:06:02 | 000,000,024 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/17 00:42:18 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Clinic 123\Desktop\OTL.exe
[2012/08/16 14:13:38 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/16 13:48:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/16 13:48:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/16 13:48:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/16 13:47:37 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/16 13:37:56 | 004,731,953 | R--- | C] (Swearware) -- C:\Users\Clinic 123\Desktop\ComboFix.exe
[2012/08/16 12:10:19 | 000,000,000 | ---D | C] -- C:\FRST
[2012/08/15 19:19:56 | 000,000,000 | ---D | C] -- C:\ProgramData\SysDll
[2012/08/15 19:19:55 | 000,000,000 | ---D | C] -- C:\ProgramData\SysDir
[2012/08/15 19:17:42 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\Desktop\The.Best.Keylogger.3.53.Build.1009._MihanDownload.com
[2012/08/15 16:03:57 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\Desktop\RK_Quarantine
[2012/08/15 00:45:13 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\Clinic 123\Desktop\dds.com
[2012/08/11 13:38:44 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Clinic 123\Desktop\aswMBR.exe
[2012/08/11 12:48:03 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\AppData\Roaming\Malwarebytes
[2012/08/11 12:47:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/11 12:47:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/11 12:47:06 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/08/11 12:47:06 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/08/10 12:34:07 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/10 11:37:04 | 002,136,664 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Clinic 123\Desktop\tdsskiller.exe
[2012/08/09 13:55:13 | 000,000,000 | ---D | C] -- C:\Windows\System32\DBBK
[2012/08/03 18:35:01 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%
[2012/07/27 19:33:51 | 000,000,000 | ---D | C] -- C:\Program Files\Throttle
[2012/07/27 18:58:37 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Your Freedom
[2012/07/27 18:58:20 | 000,000,000 | ---D | C] -- C:\Program Files\Your Freedom
[2012/07/26 15:05:16 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\Desktop\newstext.aspx_files
[2012/07/21 20:01:28 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\temp
[2012/07/21 20:01:13 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer
[2012/07/21 19:53:43 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\Desktop\Remote Desktop Limitation
[2012/07/19 14:37:58 | 000,000,000 | ---D | C] -- C:\Users\Clinic 123\AppData\Local\Programs
========== Files - Modified Within 30 Days ==========
[2012/08/17 21:24:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/17 21:24:13 | 1610,260,480 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/17 20:29:00 | 000,024,805 | ---- | M] () -- C:\Windows\deff1.dat
[2012/08/17 19:17:01 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\HP WEP.job
[2012/08/17 16:48:57 | 000,106,626 | ---- | M] () -- C:\Users\Clinic 123\Desktop\list index out of bounds.jpg
[2012/08/17 13:10:39 | 000,670,648 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/17 13:10:39 | 000,124,646 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/17 13:10:02 | 000,014,192 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 13:10:02 | 000,014,192 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/17 04:50:09 | 042,164,986 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi
[2012/08/17 04:39:29 | 010,707,706 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.003
[2012/08/17 04:34:56 | 015,728,640 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.002
[2012/08/17 00:42:50 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Clinic 123\Desktop\OTL.exe
[2012/08/16 17:45:34 | 011,131,285 | ---- | M] () -- C:\Users\Clinic 123\Desktop\DVBViewer.Pro.v4.5.0.0.MULTILINGUAL.REPACK-CRD.rar
[2012/08/16 14:09:50 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/08/16 13:39:37 | 004,731,953 | R--- | M] (Swearware) -- C:\Users\Clinic 123\Desktop\ComboFix.exe
[2012/08/15 20:22:06 | 000,001,472 | ---- | M] () -- C:\Users\Clinic 123\Desktop\iexplore.exe - Shortcut.lnk
[2012/08/15 19:19:42 | 000,001,725 | ---- | M] () -- C:\Users\Clinic 123\Desktop\SysDir.lnk
[2012/08/15 16:10:24 | 000,000,512 | ---- | M] () -- C:\Users\Clinic 123\Desktop\MBR.dat
[2012/08/15 16:03:02 | 001,558,528 | ---- | M] () -- C:\Users\Clinic 123\Desktop\RogueKiller.exe
[2012/08/15 01:43:41 | 015,728,640 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.001
[2012/08/15 00:46:04 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\Clinic 123\Desktop\dds.com
[2012/08/14 14:14:55 | 000,302,592 | ---- | M] () -- C:\Users\Clinic 123\Desktop\yo6e5e1h.exe
[2012/08/12 17:21:02 | 000,000,116 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/08/11 13:40:59 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Clinic 123\Desktop\aswMBR.exe
[2012/08/11 12:47:08 | 000,001,072 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:42:56 | 000,058,654 | ---- | M] () -- C:\Users\Clinic 123\Desktop\rrr.jpg
[2012/08/10 14:40:35 | 000,169,700 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Untitldded.jpg
[2012/08/10 11:38:03 | 002,136,664 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Clinic 123\Desktop\tdsskiller.exe
[2012/08/09 14:39:30 | 000,378,274 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Untiwwwtled.jpg
[2012/08/09 05:48:29 | 013,548,027 | ---- | M] () -- C:\Users\Clinic 123\Desktop\The.Best.Keylogger.3.53.Build.1009._MihanDownload.com.rar
[2012/08/07 13:55:11 | 000,045,046 | ---- | M] () -- C:\Users\Clinic 123\Desktop\68073514757564361027.jpg
[2012/08/05 13:57:21 | 000,033,372 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Payment Gateway-Result Page.mht
[2012/08/04 20:09:06 | 001,174,564 | ---- | M] () -- C:\Users\Clinic 123\Desktop\2011 World Wrestling Championships - Wikipedia, the free encyclopedia.mht
[2012/08/03 16:14:38 | 000,407,872 | ---- | M] () -- C:\Users\Clinic 123\Desktop\iexplore.exe
[2012/08/03 16:13:04 | 000,407,872 | ---- | M] () -- C:\Users\Clinic 123\Desktop\pkiller.exe
[2012/08/03 15:59:07 | 001,144,963 | ---- | M] () -- C:\Users\Clinic 123\Desktop\ProcessExplorer.zip
[2012/07/30 14:41:19 | 003,590,834 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Muse - Survival.mp3
[2012/07/26 15:05:16 | 000,112,405 | ---- | M] () -- C:\Users\Clinic 123\Desktop\newstext.aspx.htm
[2012/07/25 20:38:51 | 000,037,101 | ---- | M] () -- C:\Users\Clinic 123\Desktop\sudoku.jpg
[2012/07/25 00:58:08 | 005,221,440 | ---- | M] () -- C:\Users\Clinic 123\Desktop\simorgh.mp3
[2012/07/23 13:11:58 | 003,314,315 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Django Unchained OST - Hit That Jive.mp3
[2012/07/23 13:10:41 | 002,817,359 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Django Unchained OST - Ain't no grave (Johnny Cash).mp3
[2012/07/23 12:49:39 | 007,184,042 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Chelsea 1-1 PSG_Kooora.com.avi
[2012/07/22 13:38:20 | 011,626,496 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Inter_2-1_Milan_Yaghoub2000.avi
[2012/07/22 13:10:33 | 013,068,288 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Inter_1-1_Milan_Yaghoub2000.avi
[2012/07/21 20:02:24 | 000,779,887 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Team_Viewer_Learn_Mihandownload.com.rar
[2012/07/21 20:01:24 | 000,001,125 | ---- | M] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/07/21 20:00:10 | 004,660,082 | ---- | M] () -- C:\Users\Clinic 123\Desktop\TeamViewer.7.0.13852.Final_mihandownload.com.rar
[2012/07/21 19:48:27 | 000,000,000 | -H-- | M] () -- C:\Users\Clinic 123\Documents\Default.rdp
[2012/07/21 18:30:34 | 001,130,052 | ---- | M] () -- C:\Users\Clinic 123\Desktop\TehranMusic.zip
[2012/07/21 14:12:57 | 007,629,893 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Seattle Sounders 0-2 Chelsea.KoooRa.CoM.wmv
[2012/07/21 05:08:34 | 000,002,304 | ---- | M] () -- C:\Users\Clinic 123\Desktop\Google Chrome.lnk
[2012/07/19 14:36:25 | 000,858,655 | ---- | M] () -- C:\Users\Clinic 123\Desktop\36498273492.rar
[2012/07/19 14:24:19 | 000,051,504 | -HS- | M] () -- C:\Users\Clinic 123\Desktop\Folder.jpg
[2012/07/19 14:24:19 | 000,009,690 | -HS- | M] () -- C:\Users\Clinic 123\Desktop\AlbumArtSmall.jpg
========== Files Created - No Company Name ==========
[2012/08/17 16:48:57 | 000,106,626 | ---- | C] () -- C:\Users\Clinic 123\Desktop\list index out of bounds.jpg
[2012/08/17 13:15:18 | 000,000,326 | ---- | C] () -- C:\Windows\tasks\HP WEP.job
[2012/08/17 04:50:06 | 042,164,986 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi
[2012/08/16 17:42:27 | 011,131,285 | ---- | C] () -- C:\Users\Clinic 123\Desktop\DVBViewer.Pro.v4.5.0.0.MULTILINGUAL.REPACK-CRD.rar
[2012/08/16 13:48:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/16 13:48:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/16 13:48:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/16 13:48:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/16 13:48:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/08/15 20:22:06 | 000,001,472 | ---- | C] () -- C:\Users\Clinic 123\Desktop\iexplore.exe - Shortcut.lnk
[2012/08/15 19:19:42 | 000,001,725 | ---- | C] () -- C:\Users\Clinic 123\Desktop\SysDir.lnk
[2012/08/15 16:10:24 | 000,000,512 | ---- | C] () -- C:\Users\Clinic 123\Desktop\MBR.dat
[2012/08/15 16:02:03 | 001,558,528 | ---- | C] () -- C:\Users\Clinic 123\Desktop\RogueKiller.exe
[2012/08/15 01:10:27 | 010,707,706 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.003
[2012/08/15 01:10:21 | 015,728,640 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.002
[2012/08/15 01:10:13 | 015,728,640 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Ehsan+Hadadi-'s+Trophy1.avi.001
[2012/08/14 14:14:08 | 000,302,592 | ---- | C] () -- C:\Users\Clinic 123\Desktop\yo6e5e1h.exe
[2012/08/11 12:47:08 | 000,001,072 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/10 14:42:55 | 000,058,654 | ---- | C] () -- C:\Users\Clinic 123\Desktop\rrr.jpg
[2012/08/10 14:40:35 | 000,169,700 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Untitldded.jpg
[2012/08/09 14:39:30 | 000,378,274 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Untiwwwtled.jpg
[2012/08/07 13:55:09 | 000,045,046 | ---- | C] () -- C:\Users\Clinic 123\Desktop\68073514757564361027.jpg
[2012/08/05 13:57:18 | 000,033,372 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Payment Gateway-Result Page.mht
[2012/08/04 20:09:00 | 001,174,564 | ---- | C] () -- C:\Users\Clinic 123\Desktop\2011 World Wrestling Championships - Wikipedia, the free encyclopedia.mht
[2012/08/03 16:14:33 | 000,407,872 | ---- | C] () -- C:\Users\Clinic 123\Desktop\iexplore.exe
[2012/08/03 16:12:49 | 000,407,872 | ---- | C] () -- C:\Users\Clinic 123\Desktop\pkiller.exe
[2012/08/03 16:00:17 | 000,072,268 | ---- | C] () -- C:\Users\Clinic 123\Desktop\procexp.chm
[2012/08/03 15:59:03 | 001,144,963 | ---- | C] () -- C:\Users\Clinic 123\Desktop\ProcessExplorer.zip
[2012/07/30 14:40:31 | 003,590,834 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Muse - Survival.mp3
[2012/07/27 16:48:15 | 013,548,027 | ---- | C] () -- C:\Users\Clinic 123\Desktop\The.Best.Keylogger.3.53.Build.1009._MihanDownload.com.rar
[2012/07/26 15:05:16 | 000,112,405 | ---- | C] () -- C:\Users\Clinic 123\Desktop\newstext.aspx.htm
[2012/07/25 20:38:49 | 000,037,101 | ---- | C] () -- C:\Users\Clinic 123\Desktop\sudoku.jpg
[2012/07/25 00:56:38 | 005,221,440 | ---- | C] () -- C:\Users\Clinic 123\Desktop\simorgh.mp3
[2012/07/23 13:10:58 | 003,314,315 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Django Unchained OST - Hit That Jive.mp3
[2012/07/23 13:09:56 | 002,817,359 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Django Unchained OST - Ain't no grave (Johnny Cash).mp3
[2012/07/23 12:47:43 | 007,184,042 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Chelsea 1-1 PSG_Kooora.com.avi
[2012/07/22 13:35:18 | 011,626,496 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Inter_2-1_Milan_Yaghoub2000.avi
[2012/07/22 13:07:00 | 013,068,288 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Inter_1-1_Milan_Yaghoub2000.avi
[2012/07/21 20:02:03 | 000,779,887 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Team_Viewer_Learn_Mihandownload.com.rar
[2012/07/21 20:01:24 | 000,001,137 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012/07/21 20:01:24 | 000,001,125 | ---- | C] () -- C:\Users\Public\Desktop\TeamViewer 7.lnk
[2012/07/21 19:59:00 | 004,660,082 | ---- | C] () -- C:\Users\Clinic 123\Desktop\TeamViewer.7.0.13852.Final_mihandownload.com.rar
[2012/07/21 19:48:27 | 000,000,000 | -H-- | C] () -- C:\Users\Clinic 123\Documents\Default.rdp
[2012/07/21 18:30:20 | 001,130,052 | ---- | C] () -- C:\Users\Clinic 123\Desktop\TehranMusic.zip
[2012/07/21 14:10:55 | 007,629,893 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Seattle Sounders 0-2 Chelsea.KoooRa.CoM.wmv
[2012/07/21 05:08:34 | 000,002,304 | ---- | C] () -- C:\Users\Clinic 123\Desktop\Google Chrome.lnk
[2012/07/19 14:35:46 | 000,858,655 | ---- | C] () -- C:\Users\Clinic 123\Desktop\36498273492.rar
[2012/07/19 14:24:19 | 000,051,504 | -HS- | C] () -- C:\Users\Clinic 123\Desktop\Folder.jpg
[2012/07/19 14:24:19 | 000,009,690 | -HS- | C] () -- C:\Users\Clinic 123\Desktop\AlbumArtSmall.jpg
[2012/06/05 23:37:41 | 000,004,096 | -H-- | C] () -- C:\Users\Clinic 123\AppData\Local\keyfile3.drm
[2012/04/06 15:11:38 | 000,251,904 | ---- | C] () -- C:\Windows\System32\orant71.dll
[2012/04/06 15:11:37 | 000,018,944 | ---- | C] ( ) -- C:\Windows\System32\implode.dll
[2012/04/06 15:00:27 | 000,000,000 | ---- | C] () -- C:\Windows\splash.INI
[2011/09/26 22:14:50 | 000,156,593 | ---- | C] () -- C:\Windows\hppins09.dat.temp
[2011/09/26 22:14:50 | 000,003,425 | ---- | C] () -- C:\Windows\hppmdl09.dat.temp
[2011/09/26 21:31:36 | 000,157,073 | ---- | C] () -- C:\Windows\System32\hppins09.dat
[2011/09/26 21:31:36 | 000,156,720 | ---- | C] () -- C:\Windows\hppins09.dat
[2011/09/16 09:35:08 | 000,000,252 | ---- | C] () -- C:\Windows\System32\AF15IRTBL.bin
[2011/09/15 15:27:53 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2011/09/15 15:27:48 | 000,650,752 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/09/15 15:27:48 | 000,243,200 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/09/15 15:27:47 | 000,074,752 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/09/02 19:12:24 | 000,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll
[2011/08/22 02:32:03 | 000,000,374 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/08/22 02:18:38 | 000,903,168 | ---- | C] () -- C:\Windows\System32\mitmdl30.dll
[2011/08/22 02:18:38 | 000,110,080 | ---- | C] () -- C:\Windows\System32\lfpng60n.dll
[2011/08/22 02:18:38 | 000,046,080 | ---- | C] () -- C:\Windows\System32\lftif60n.dll
[2011/08/22 02:18:38 | 000,020,480 | ---- | C] () -- C:\Windows\System32\lfpsd60n.dll
[2011/08/22 02:18:38 | 000,019,968 | ---- | C] () -- C:\Windows\System32\lftga60n.dll
[2011/08/22 02:18:38 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwpg60n.dll
[2011/08/22 02:18:38 | 000,019,456 | ---- | C] () -- C:\Windows\System32\lfwmf60n.dll
[2011/08/22 02:18:37 | 000,176,128 | ---- | C] () -- C:\Windows\System32\lffax60n.dll
[2011/08/22 02:18:37 | 000,141,824 | ---- | C] () -- C:\Windows\System32\lfcmp60n.dll
[2011/08/22 02:18:37 | 000,023,552 | ---- | C] () -- C:\Windows\System32\lfpcx60n.dll
[2011/08/22 02:18:37 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfpct60n.dll
[2011/08/22 02:18:37 | 000,022,528 | ---- | C] () -- C:\Windows\System32\lfeps60n.dll
[2011/08/22 02:18:37 | 000,022,016 | ---- | C] () -- C:\Windows\System32\lfbmp60n.dll
[2011/08/22 02:18:37 | 000,018,432 | ---- | C] () -- C:\Windows\System32\lfmsp60n.dll
[2011/08/22 02:18:37 | 000,017,920 | ---- | C] () -- C:\Windows\System32\lfmac60n.dll
[2011/08/17 13:27:31 | 000,034,308 | ---- | C] () -- C:\Windows\System32\BASSMOD.dll
[2011/07/02 12:22:12 | 000,278,728 | ---- | C] () -- C:\Windows\System32\drivers\atksgt.sys
[2011/07/02 12:22:11 | 000,025,416 | ---- | C] () -- C:\Windows\System32\drivers\lirsgt.sys
[2011/06/07 11:34:50 | 000,000,116 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/06/06 19:36:37 | 000,073,471 | ---- | C] () -- C:\Windows\hpqins16.dat
[2011/05/27 10:59:43 | 000,000,146 | ---- | C] () -- C:\Windows\capture.INI
[2011/05/27 10:54:28 | 000,064,512 | ---- | C] () -- C:\Windows\System32\drivers\SENTINEL.SYS
[2011/05/27 10:54:28 | 000,017,408 | ---- | C] () -- C:\Windows\System32\RNBOVDD.DLL
[2011/05/26 17:49:20 | 000,688,443 | ---- | C] () -- C:\Windows\unins000.exe
[2011/05/26 17:49:20 | 000,002,393 | ---- | C] () -- C:\Windows\unins000.dat
[2011/05/24 20:17:24 | 000,002,158 | ---- | C] () -- C:\Windows\FONTSMRT.INI
[2011/05/24 20:17:06 | 000,000,415 | ---- | C] () -- C:\Windows\prntname.ini
[2011/05/24 20:16:51 | 000,000,076 | ---- | C] () -- C:\Windows\tmprn.ini
[2011/05/06 16:21:17 | 000,024,805 | ---- | C] () -- C:\Windows\deff1.dat
[2011/05/05 23:04:15 | 000,031,232 | ---- | C] () -- C:\Users\Clinic 123\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/05 22:53:20 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011/05/05 20:32:06 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/05/05 20:28:56 | 000,002,857 | ---- | C] () -- C:\Windows\System32\atipblag.dat
========== LOP Check ==========
[2011/08/19 15:05:26 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\Acapela Group
[2011/08/20 13:30:04 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\Babylon
[2011/05/08 14:16:46 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\COWON
[2012/03/31 12:42:03 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\DAEMON Tools Pro
[2011/09/15 16:04:22 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\DeepBurner
[2012/08/17 21:23:06 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\DMCache
[2011/05/11 21:04:45 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\ESET
[2012/08/17 21:17:47 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\GoldenDict
[2012/08/12 04:35:56 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\IDM
[2012/03/21 19:51:04 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\ImTOO
[2011/09/02 19:12:16 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\iolo
[2011/06/03 14:19:58 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\National Instruments
[2011/09/10 11:17:48 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\Nokia
[2011/09/10 11:30:32 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\Nseries
[2011/09/10 11:30:36 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\PC Suite
[2012/03/27 23:55:14 | 000,000,000 | ---D | M] -- C:\Users\Clinic 123\AppData\Roaming\Rovio
[2012/07/14 20:44:28 | 000,032,528 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/07/26 15:00:35 | 000,542,963 | ---- | M] ()(C:\Users\Clinic 123\Desktop\???? ??????? ????????? ??????.mht) -- C:\Users\Clinic 123\Desktop\جدول مسابقات ورزشكاران ايراني.mht
[2012/07/26 15:00:30 | 000,542,963 | ---- | C] ()(C:\Users\Clinic 123\Desktop\???? ??????? ????????? ??????.mht) -- C:\Users\Clinic 123\Desktop\جدول مسابقات ورزشكاران ايراني.mht
[2012/07/23 14:44:30 | 000,063,371 | ---- | M] ()(C:\Users\Clinic 123\Desktop\??????-?????-?????????-??????-??-????-?????-???.htm) -- C:\Users\Clinic 123\Desktop\برنامه-رقابت-ورزشکاران-ایرانی-در-لندن-چگونه-است.htm
[2012/07/23 14:44:27 | 000,000,000 | ---D | M](C:\Users\Clinic 123\Desktop\??????-?????-?????????-??????-??-????-?????-???_files) -- C:\Users\Clinic 123\Desktop\برنامه-رقابت-ورزشکاران-ایرانی-در-لندن-چگونه-است_files
[2012/07/23 14:44:25 | 000,063,371 | ---- | C] ()(C:\Users\Clinic 123\Desktop\??????-?????-?????????-??????-??-????-?????-???.htm) -- C:\Users\Clinic 123\Desktop\برنامه-رقابت-ورزشکاران-ایرانی-در-لندن-چگونه-است.htm
[2012/07/23 14:44:25 | 000,000,000 | ---D | C](C:\Users\Clinic 123\Desktop\??????-?????-?????????-??????-??-????-?????-???_files) -- C:\Users\Clinic 123\Desktop\برنامه-رقابت-ورزشکاران-ایرانی-در-لندن-چگونه-است_files
[2011/05/06 15:39:57 | 000,000,000 | ---D | M](C:\Users\Clinic 123\AppData\Local\???????_?????) -- C:\Users\Clinic 123\AppData\Local\حمیدرضا_محمدی
[2011/05/06 15:39:57 | 000,000,000 | ---D | M](C:\Users\Clinic 123\AppData\Local\???????_?????) -- C:\Users\Clinic 123\AppData\Local\حمیدرضا_محمدی
(C:\Users\Clinic 123\AppData\Local\???????_?????) -- C:\Users\Clinic 123\AppData\Local\حمیدرضا_محمدی
< End of report >