OTL logfile created on: 8/12/2012 10:10:50 PM - Run 1
OTL by OldTimer - Version 3.2.56.0 Folder = C:\Users\Computer\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.75 Gb Total Physical Memory | 1.72 Gb Available Physical Memory | 62.77% Memory free
5.73 Gb Paging File | 4.73 Gb Available in Paging File | 82.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 198.76 Gb Total Space | 62.69 Gb Free Space | 31.54% Space Free | Partition Type: NTFS
Drive D: | 34.13 Gb Total Space | 24.98 Gb Free Space | 73.20% Space Free | Partition Type: NTFS
Computer Name: COMPUTER-PC | User Name: Computer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/08/12 22:07:45 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Computer\Desktop\OTL.exe
PRC - [2012/05/12 04:03:41 | 000,351,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_2_202_235_ActiveX.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2010/12/14 17:12:12 | 000,956,416 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2009/06/04 17:41:22 | 000,451,904 | ---- | M] () -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe
PRC - [2009/04/11 01:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/02/12 14:19:52 | 000,723,496 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/14 11:33:04 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 11:31:48 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 11:26:06 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 04:02:38 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/05/12 04:16:18 | 000,998,400 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\f3d4d5fe5ab848fbfcf91a49960dc8ae\System.Management.ni.dll
MOD - [2012/05/12 04:13:04 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/12 04:12:51 | 000,627,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\b6d83a652c94b32fc8f99a6df0acd7f4\System.Transactions.ni.dll
MOD - [2012/05/12 04:12:46 | 000,627,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4b5eaa70d2900b98ccf6fd9915f34d69\System.EnterpriseServices.ni.dll
MOD - [2012/05/12 04:12:46 | 000,280,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\4b5eaa70d2900b98ccf6fd9915f34d69\System.EnterpriseServices.Wrapper.dll
MOD - [2012/05/12 04:11:48 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/12 04:07:39 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/12 04:04:52 | 006,621,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\bfdd10e0a0aacf46bac557ffc5d55ba5\System.Data.ni.dll
MOD - [2012/05/12 04:04:28 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/12 04:02:20 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/12 04:02:12 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/12 04:01:13 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2010/12/14 16:51:52 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2010/12/14 16:51:50 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2010/12/14 16:51:44 | 000,200,704 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libpcre.dll
MOD - [2009/04/11 01:28:21 | 000,368,640 | ---- | M] () -- C:\Windows\System32\msjetoledb40.dll
MOD - [2009/04/10 21:04:15 | 000,113,664 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
MOD - [2009/03/29 23:42:19 | 000,261,632 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/29 23:42:17 | 002,933,760 | ---- | M] () -- C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2008/09/30 18:56:06 | 000,032,768 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Content.XmlSerializers.dll
MOD - [2008/09/30 18:52:02 | 000,007,168 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\RemotingClient.dll
MOD - [2008/09/30 18:52:00 | 000,057,344 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\Pillars\PCAlerts\PCAlertsPillar.dll
MOD - [2008/09/30 18:51:52 | 000,118,784 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\ECLibrary.dll
MOD - [2008/09/30 18:51:52 | 000,010,240 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingClients.dll
MOD - [2008/09/30 18:51:36 | 000,040,960 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingServer.dll
MOD - [2008/09/30 18:51:36 | 000,028,672 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingMessages.dll
MOD - [2008/09/30 18:51:36 | 000,005,632 | ---- | M] () -- C:\Program Files\Hewlett-Packard\HP Advisor\MessagingInterface.dll
MOD - [2008/09/23 20:21:22 | 000,066,856 | ---- | M] () -- C:\Program Files\HP\QuickPlay\Kernel\common\MCEMediaStatus.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (MpsSvc)
SRV - File not found [On_Demand | Stopped] -- -- (BFE)
SRV - [2012/07/18 19:10:39 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/06/06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/03/18 11:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/06/04 17:41:22 | 000,451,904 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service)
SRV - [2008/10/06 11:54:52 | 000,365,952 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/09/18 11:57:32 | 003,093,872 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2008/01/20 21:23:32 | 000,272,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/06/15 12:57:42 | 000,145,504 | ---- | M] (B.H.A Corporation) [On_Demand | Stopped] -- C:\Windows\System32\bgsvcgen.exe -- (bgsvcgen)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2010/10/29 16:11:08 | 000,197,224 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 13:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2009/07/23 21:01:00 | 009,791,072 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/06/01 14:51:54 | 000,030,088 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\point32k.sys -- (Point32)
DRV - [2009/04/29 08:46:54 | 000,015,872 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2008/12/20 03:01:46 | 001,093,120 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/10/03 03:39:28 | 000,222,208 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008/08/21 23:49:58 | 000,008,320 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgpfl.sys -- (motccgpfl)
DRV - [2008/08/21 23:49:22 | 000,018,688 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motccgp.sys -- (motccgp)
DRV - [2008/05/09 14:17:32 | 000,043,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2008/04/24 17:51:46 | 000,014,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/01/20 21:23:20 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2007/10/17 18:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/06/18 20:18:26 | 000,023,680 | ---- | M] (Motorola) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motmodem.sys -- (motmodem)
DRV - [2006/02/20 19:17:40 | 000,033,408 | ---- | M] (B.H.A Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\cdrbsdrv.sys -- (cdrbsdrv)
DRV - [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\afc.sys -- (Afc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cnnb
IE - HKLM\..\SearchScopes,DefaultScope = {C0A1EA64-7765-46B6-8F39-05EA8ECAD073}
IE - HKLM\..\SearchScopes\{C0A1EA64-7765-46B6-8F39-05EA8ECAD073}: "URL" =
http://search.live.com/results.aspx?q={searchTerms}&FORM=HPNTDF
IE - HKLM\..\SearchScopes\{FCEBD5DB-1C30-4EE7-8C22-5C3C0F98C672}: "URL" =
http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ie
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ie
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ie
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\SearchScopes,DefaultScope = {C0A1EA64-7765-46B6-8F39-05EA8ECAD073}
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={sear
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\SearchScopes\{9D32EF93-BF7D-4DF0-8734-0D6015B2D0A9}: "URL" =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\SearchScopes\{C0A1EA64-7765-46B6-8F39-05EA8ECAD073}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=HPNTDF&pc=HPNTDF&src=IE-SearchBox
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\SearchScopes\{FCEBD5DB-1C30-4EE7-8C22-5C3C0F98C672}: "URL" =
http://www.ask.com/web?q={searchTerms}&l=dis&o=uscql
IE - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "
http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
moveplayer@movenetworks.com:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.3.37: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.3.37: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.3.37: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Computer\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Users\Computer\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Computer\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Computer\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/04/24 22:15:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 19:10:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/24 22:15:30 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\
moveplayer@movenetworks.com: C:\Users\Computer\AppData\Roaming\Move Networks [2010/01/09 17:03:02 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/18 19:10:40 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/24 22:15:30 | 000,000,000 | ---D | M]
[2007/09/02 06:00:47 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Computer\AppData\Roaming\Mozilla\Extensions
[2012/05/02 17:36:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Computer\AppData\Roaming\Mozilla\Firefox\Profiles\uw85skps.default\extensions
[2012/05/19 15:27:22 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/01/09 17:03:02 | 000,000,000 | ---D | M] (Move Media Player) -- C:\USERS\COMPUTER\APPDATA\ROAMING\MOVE NETWORKS
[2012/07/18 19:10:40 | 000,136,672 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/22 23:41:00 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/06/20 20:30:27 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/06/20 20:30:27 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
http://www.google.com/
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
http://www.google.com/
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Computer\AppData\Local\Google\Chrome\Application\21.0.1180.60\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Computer\AppData\Local\Google\Chrome\Application\21.0.1180.60\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Computer\AppData\Local\Google\Chrome\Application\21.0.1180.60\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Computer\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.310.5 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
CHR - plugin: Java(TM) Platform SE 6 U31 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprpjplug.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\nprjplug.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Computer\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Users\Computer\AppData\Roaming\Move Networks\plugins\npqmp071505000011.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Total Defense Anti-Phishing Toolbar = C:\Users\Computer\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpdpkkpdlooddakbebmkeeegehfjdnih\2.0.0.430_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Computer\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
O1 HOSTS File: ([2012/08/12 20:56:05 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\Toolbar\WebBrowser: (no name) - {0123B506-0AD9-43AA-B0CF-916C122AD4C5} - No CLSID value found.
O3 - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..\Toolbar\WebBrowser: (no name) - {724D43A0-0D85-11D4-9908-00400523E39A} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll File not found
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files\Evernote\Evernote3.5\enbar.dll File not found
O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
O15 - HKU\S-1-5-21-3482958328-679290281-1852491039-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {070DC617-E3B7-468B-A29C-D4E84FAE938C}
http://utilities.pcpitstop.com/pctuneup2/controls/pctuneup.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {A3256902-51FA-45A0-8A97-FC1143C169D9}
http://support.microsoft.com/mats/DiagWebControl.cab (Diagnostics ActiveX WebControl)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3B351C87-BD5F-4C94-970A-CD76AFED29C9}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Computer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Computer\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/08/12 22:06:57 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\Computer\Desktop\OTL.exe
[2012/08/12 21:33:18 | 000,000,000 | ---D | C] -- C:\FRST
[2012/08/12 21:03:31 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/08/12 20:56:19 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/12 20:39:47 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/08/12 20:39:47 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/08/12 20:39:47 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/08/12 20:39:43 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/08/12 20:23:56 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/08/12 20:23:29 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/08/12 19:48:11 | 004,729,547 | R--- | C] (Swearware) -- C:\Users\Computer\Desktop\ComboFix.exe
[2012/08/11 16:47:37 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/09 20:46:03 | 000,000,000 | ---D | C] -- C:\Users\Computer\AppData\Roaming\Malwarebytes
[2012/08/09 20:45:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/09 20:45:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/09 20:45:39 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/08/09 20:45:39 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/07/29 14:34:36 | 000,000,000 | ---D | C] -- C:\Users\Computer\Desktop\Voices of Songbirds_ Set 1
[2012/07/29 14:34:36 | 000,000,000 | ---D | C] -- C:\Users\Computer\Desktop\__MACOSX
========== Files - Modified Within 30 Days ==========
[2012/08/12 22:07:45 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\Computer\Desktop\OTL.exe
[2012/08/12 22:06:00 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/12 21:21:00 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3482958328-679290281-1852491039-1000UA.job
[2012/08/12 21:08:29 | 000,000,246 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2012/08/12 21:08:26 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/12 21:08:25 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/12 21:08:24 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/12 21:08:14 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/08/12 21:08:10 | 2951,106,560 | -HS- | M] () -- C:\hiberfil.sys
[2012/08/12 21:06:23 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/08/12 20:56:05 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/08/12 20:02:24 | 000,082,780 | ---- | M] () -- C:\Windows\System32\drivers\KmxAgent.asc
[2012/08/12 19:48:12 | 004,729,547 | R--- | M] (Swearware) -- C:\Users\Computer\Desktop\ComboFix.exe
[2012/08/11 17:25:03 | 000,007,808 | ---- | M] () -- C:\Users\Computer\AppData\Local\d3d9caps.dat
[2012/08/11 16:52:25 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/08/11 16:47:52 | 000,606,802 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/08/11 16:47:52 | 000,105,370 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/08/09 13:27:16 | 000,002,019 | ---- | M] () -- C:\Users\Computer\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/08 12:21:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3482958328-679290281-1852491039-1000Core.job
[2012/08/03 13:19:14 | 000,187,904 | ---- | M] () -- C:\Users\Computer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/02 13:04:05 | 289,880,008 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/08/02 07:00:12 | 003,554,057 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8723.JPG
[2012/08/02 07:00:04 | 003,212,343 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8722.JPG
[2012/08/02 06:59:52 | 004,310,747 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8721.JPG
[2012/08/02 06:59:44 | 002,994,250 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8720.JPG
[2012/08/02 06:59:30 | 004,368,768 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8719.JPG
[2012/08/02 06:59:20 | 003,201,167 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8718.JPG
[2012/08/02 06:59:16 | 004,411,634 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8717.JPG
[2012/08/02 06:59:02 | 003,938,755 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8716.JPG
[2012/08/02 06:58:48 | 003,549,463 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8715.JPG
[2012/08/02 06:58:40 | 003,879,332 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8714.JPG
[2012/08/02 06:58:26 | 003,364,133 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8713.JPG
[2012/08/02 06:58:16 | 003,229,159 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8712.JPG
[2012/08/02 06:58:06 | 003,689,266 | ---- | M] () -- C:\Users\Computer\Desktop\IMG_8711.JPG
[2012/07/29 18:02:11 | 001,038,662 | ---- | M] () -- C:\Users\Computer\Desktop\unknown plant.jpg
[2012/07/29 15:49:48 | 005,546,434 | ---- | M] () -- C:\Users\Computer\Desktop\P1060379.JPG
[2012/07/29 15:48:44 | 005,586,054 | ---- | M] () -- C:\Users\Computer\Desktop\P1060377.JPG
[2012/07/28 13:59:48 | 000,762,086 | ---- | M] () -- C:\Users\Computer\Desktop\P1060304_2.jpg
[2012/07/22 12:51:56 | 005,965,128 | ---- | M] () -- C:\Users\Computer\Desktop\P1060304.JPG
[2012/07/20 19:51:44 | 003,628,338 | ---- | M] () -- C:\Users\Computer\Desktop\P1060267.JPG
========== Files Created - No Company Name ==========
[2012/08/12 20:39:47 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/08/12 20:39:47 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/08/12 20:39:47 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/08/12 20:39:47 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/08/12 20:39:47 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/08/11 18:25:31 | 2951,106,560 | -HS- | C] () -- C:\hiberfil.sys
[2012/08/11 16:52:25 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/08/11 16:48:04 | 000,001,826 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/02 19:59:00 | 004,411,634 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8717.JPG
[2012/08/02 19:59:00 | 003,938,755 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8716.JPG
[2012/08/02 19:59:00 | 003,879,332 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8714.JPG
[2012/08/02 19:59:00 | 003,689,266 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8711.JPG
[2012/08/02 19:59:00 | 003,554,057 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8723.JPG
[2012/08/02 19:59:00 | 003,549,463 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8715.JPG
[2012/08/02 19:59:00 | 003,364,133 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8713.JPG
[2012/08/02 19:59:00 | 003,229,159 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8712.JPG
[2012/08/02 19:59:00 | 003,201,167 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8718.JPG
[2012/08/02 19:58:59 | 004,368,768 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8719.JPG
[2012/08/02 19:58:59 | 004,310,747 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8721.JPG
[2012/08/02 19:58:59 | 003,212,343 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8722.JPG
[2012/08/02 19:58:59 | 002,994,250 | ---- | C] () -- C:\Users\Computer\Desktop\IMG_8720.JPG
[2012/07/29 18:01:57 | 001,038,662 | ---- | C] () -- C:\Users\Computer\Desktop\unknown plant.jpg
[2012/07/29 17:18:01 | 005,546,434 | ---- | C] () -- C:\Users\Computer\Desktop\P1060379.JPG
[2012/07/29 17:17:48 | 005,586,054 | ---- | C] () -- C:\Users\Computer\Desktop\P1060377.JPG
[2012/07/28 13:59:44 | 000,762,086 | ---- | C] () -- C:\Users\Computer\Desktop\P1060304_2.jpg
[2012/07/28 13:37:48 | 005,965,128 | ---- | C] () -- C:\Users\Computer\Desktop\P1060304.JPG
[2012/07/20 23:22:55 | 003,628,338 | ---- | C] () -- C:\Users\Computer\Desktop\P1060267.JPG
[2011/03/17 19:57:18 | 000,339,968 | ---- | C] () -- C:\Windows\System32\ZSHP2600.EXE
[2011/01/11 22:43:17 | 000,000,585 | ---- | C] () -- C:\Users\Computer\AppData\Local\cookies.ini
[2010/09/24 00:41:52 | 000,125,952 | ---- | C] () -- C:\Windows\System32\ZLhp2600.DLL
[2010/09/21 22:52:06 | 000,006,112 | ---- | C] () -- C:\Windows\System32\cdenable.sys
[2010/09/19 23:20:23 | 000,028,672 | ---- | C] () -- C:\Windows\System32\qttask.exe
[2010/06/28 19:08:53 | 000,000,000 | ---- | C] () -- C:\Users\Computer\AppData\Roaming\wklnhst.dat
[2010/01/22 10:08:50 | 000,007,808 | ---- | C] () -- C:\Users\Computer\AppData\Local\d3d9caps.dat
[2009/08/03 22:06:38 | 000,788,274 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2008/12/09 06:51:17 | 000,000,246 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2007/09/01 23:30:39 | 000,187,904 | ---- | C] () -- C:\Users\Computer\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/09/01 04:41:24 | 000,788,274 | ---- | C] () -- C:\ProgramData\nvModes.001
========== LOP Check ==========
[2010/01/09 20:11:59 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\.BitTornado
[2011/01/11 22:42:38 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Acapela Group
[2011/08/28 20:34:42 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Alawar
[2010/06/27 18:56:26 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Anabel
[2010/03/07 15:46:46 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Artogon
[2011/01/19 01:35:11 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Big Fish Games
[2011/03/21 22:55:57 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Boomzap
[2012/01/28 21:06:24 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\calibre
[2011/09/24 21:48:53 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\casanova
[2011/09/01 00:43:15 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Casual Arts
[2011/07/03 20:59:15 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Colibri Games
[2010/05/24 19:20:59 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/02 21:39:05 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Crown
[2011/08/21 16:52:47 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Dekovir
[2011/12/18 22:08:29 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\DivoGames
[2010/12/26 17:57:53 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\EleFun Games
[2010/12/27 22:00:07 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\ERS Game Studios
[2010/05/31 19:35:21 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Facebook
[2010/06/26 19:22:17 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Fugazo
[2011/01/01 18:36:20 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\GameMill Entertainment
[2010/04/08 14:13:02 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\GetRightToGo
[2011/01/17 18:23:27 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\LittleGamesCompany
[2011/07/05 22:38:27 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Mutant Arcade
[2010/10/31 15:20:37 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\muvee Technologies
[2011/03/19 17:11:45 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Namco
[2010/06/15 22:49:11 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\OpenOffice.org
[2011/07/04 23:15:13 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Orneon
[2010/04/04 12:27:55 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Panasonic
[2011/11/26 23:23:07 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Phantasmat_bf_ce1
[2011/12/19 21:47:19 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\PlayFirst
[2010/05/31 14:42:51 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Playrix Entertainment
[2010/03/03 22:05:47 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Silverback Productions
[2012/06/04 13:17:07 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\SkyGoblin
[2010/11/08 13:52:37 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\StudyMinder
[2011/08/16 19:09:00 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\Teyon
[2011/11/11 22:46:59 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\TrickySoftware
[2010/04/23 23:03:36 | 000,000,000 | ---D | M] -- C:\Users\Computer\AppData\Roaming\WildTangent
[2012/08/12 21:06:23 | 000,032,642 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:3E06C78F
@Alternate Data Stream - 213 bytes -> C:\ProgramData\Temp:E2CFA9CD
@Alternate Data Stream - 195 bytes -> C:\ProgramData\Temp:8E5EA40F
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:7BFAAE70
@Alternate Data Stream - 134 bytes -> C:\ProgramData\Temp:2AE74FF9
@Alternate Data Stream - 128 bytes -> C:\ProgramData\Temp:953CB9E9
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:E5B07840
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:7DC5D762
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:6F221BA1
@Alternate Data Stream - 124 bytes -> C:\ProgramData\Temp:0785072C
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:902C848D
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp

746CE5A
@Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:064877B6
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp

B4C77AD
@Alternate Data Stream - 114 bytes -> C:\ProgramData\Temp:569CEE83
< End of report >