part 2:
O1 HOSTS File: ([2012/07/09 18:15:44 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (RoboForm Toolbar Helper) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3:
64bit: - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (&RoboForm Toolbar) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files (x86)\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3:
64bit: - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\..\Toolbar\WebBrowser: (&RoboForm Toolbar) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files (x86)\Vuze_Remote\prxtbVuz0.dll (Conduit Ltd.)
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:
64bit: - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4:
64bit: - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [SSDMonitor] C:\Program Files (x86)\Common Files\PC Tools\sMonitor\SSDMonitor.exe (PC Tools)
O4 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
O4 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000..\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe (Apple Inc.)
O4 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000..\Run: [RoboForm] C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 0
O7 - HKU\S-1-5-21-791489813-3487081352-2665593224-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:
64bit: - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:
64bit: - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8:
64bit: - Extra context menu item: Show RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Show RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9:
64bit: - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:
64bit: - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:
64bit: - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:
64bit: - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:
64bit: - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9:
64bit: - Extra 'Tools' menuitem : Show RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform-x64.dll (Siber Systems Inc.)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Show Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra 'Tools' menuitem : Show RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BE1F96B0-21CD-464A-BE52-159E5443327E}: DhcpNameServer = 192.168.1.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/18 17:12:18 | 000,000,088 | ---- | M] () - E:\autorun.inf -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/09 20:44:08 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/08 18:06:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
[2012/07/07 21:35:53 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/07 21:35:53 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/07 21:35:53 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/07 21:29:38 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/07 21:29:33 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/07 19:58:21 | 000,000,000 | ---D | C] -- C:\Users\Greg\AppData\Roaming\SanDisk SecureAccess
[2012/07/07 19:56:23 | 000,000,000 | ---D | C] -- C:\Users\Greg\AppData\Local\Proxure
[2012/07/07 19:56:21 | 000,000,000 | ---D | C] -- C:\ProgramData\ClubSanDisk
[2012/07/07 00:48:54 | 000,000,000 | ---D | C] -- C:\ProgramData\U3
[2012/07/07 00:11:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/07 00:11:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/06 23:39:29 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012/07/06 23:39:29 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012/07/06 23:37:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/07/06 16:43:00 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/06 16:07:06 | 000,000,000 | ---D | C] -- C:\Users\Greg\AppData\Roaming\DriverCure
[2012/07/06 16:07:05 | 000,000,000 | ---D | C] -- C:\Users\Greg\AppData\Roaming\SpeedyPC Software
[2012/07/06 16:06:54 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
[2012/06/23 21:22:17 | 000,000,000 | ---D | C] -- C:\Users\Greg\AppData\Local\Macromedia
[2012/06/14 12:25:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/14 12:25:13 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/06/14 12:25:12 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/06/14 12:25:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/09 20:51:18 | 000,019,328 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/09 20:51:18 | 000,019,328 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/09 20:45:54 | 000,001,394 | ---- | M] () -- C:\Users\Greg\Desktop\OTL - Shortcut.lnk
[2012/07/09 20:44:08 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/09 20:44:05 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/09 20:43:54 | 3220,525,056 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/09 20:40:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/09 19:04:31 | 000,000,264 | ---- | M] () -- C:\Windows\tasks\RMSchedule.job
[2012/07/09 18:15:44 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/07 21:25:21 | 000,001,138 | ---- | M] () -- C:\Users\Greg\Desktop\ComboFix - Shortcut.lnk
[2012/07/07 19:57:14 | 000,000,288 | ---- | M] () -- C:\Users\Greg\AppData\Roaming\.backup.dm
[2012/07/07 19:53:23 | 000,779,266 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/07 19:53:23 | 000,660,280 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/07 19:53:23 | 000,121,208 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/07 00:43:53 | 000,001,143 | ---- | M] () -- C:\Users\Greg\Desktop\FRST64(1) - Shortcut.lnk
[2012/07/07 00:11:19 | 000,001,127 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/14 12:25:47 | 000,001,783 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/13 19:29:28 | 000,311,816 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/09 20:45:54 | 000,001,394 | ---- | C] () -- C:\Users\Greg\Desktop\OTL - Shortcut.lnk
[2012/07/07 21:35:53 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/07 21:35:53 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/07 21:35:53 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/07 21:35:53 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/07 21:35:53 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/07 21:25:21 | 000,001,138 | ---- | C] () -- C:\Users\Greg\Desktop\ComboFix - Shortcut.lnk
[2012/07/07 19:57:14 | 000,000,288 | ---- | C] () -- C:\Users\Greg\AppData\Roaming\.backup.dm
[2012/07/07 00:43:53 | 000,001,143 | ---- | C] () -- C:\Users\Greg\Desktop\FRST64(1) - Shortcut.lnk
[2012/07/07 00:11:19 | 000,001,127 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/14 12:25:47 | 000,001,783 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/03/05 17:16:57 | 000,012,800 | ---- | C] () -- C:\Users\Greg\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/25 15:00:18 | 000,772,990 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/17 17:51:46 | 000,003,929 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/01/25 15:48:56 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/11/10 03:45:32 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2010/11/10 03:45:30 | 010,871,128 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2010/11/10 03:45:20 | 000,316,248 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010/08/06 09:57:22 | 000,000,090 | ---- | C] () -- C:\Windows\SysWow64\ftm31.dat
[2009/11/20 11:23:19 | 000,000,167 | ---- | C] () -- C:\Users\Greg\Wolfe, Renee (US - Cleveland).vcf
[2009/11/20 11:23:19 | 000,000,162 | ---- | C] () -- C:\Users\Greg\Serrin Michael-Wolfe.vcf
[2009/11/20 11:23:19 | 000,000,157 | ---- | C] () -- C:\Users\Greg\LutherCopeland@aol_com.vcf
[2009/11/20 11:23:19 | 000,000,156 | ---- | C] () -- C:\Users\Greg\James Dom Dera, MD, FAAFP.vcf
[2009/11/20 11:23:19 | 000,000,154 | ---- | C] () -- C:\Users\Greg\mark@turftrimmers_com.vcf
[2009/11/20 11:23:19 | 000,000,150 | ---- | C] () -- C:\Users\Greg\Joseph A_ Laure III.vcf
[2009/11/20 11:23:19 | 000,000,150 | ---- | C] () -- C:\Users\Greg\Earl, Stephanie A_.vcf
[2009/11/20 11:23:19 | 000,000,150 | ---- | C] () -- C:\Users\Greg\Chris Bucci _Spida_.vcf
[2009/11/20 11:23:19 | 000,000,148 | ---- | C] () -- C:\Users\Greg\Jane Bissler.vcf
[2009/11/20 11:23:19 | 000,000,145 | ---- | C] () -- C:\Users\Greg\earl119@sssnet_com.vcf
[2009/11/20 11:23:19 | 000,000,143 | ---- | C] () -- C:\Users\Greg\Mollie MacDonald.vcf
[2009/11/20 11:23:19 | 000,000,142 | ---- | C] () -- C:\Users\Greg\Christopher Bucci.vcf
[2009/11/20 11:23:19 | 000,000,141 | ---- | C] () -- C:\Users\Greg\Stephen Moats.vcf
[2009/11/20 11:23:19 | 000,000,140 | ---- | C] () -- C:\Users\Greg\Chris & Christy.vcf
[2009/11/20 11:23:19 | 000,000,139 | ---- | C] () -- C:\Users\Greg\Jim Schelberg.vcf
[2009/11/20 11:23:19 | 000,000,138 | ---- | C] () -- C:\Users\Greg\Mary Higgins.vcf
[2009/11/20 11:23:19 | 000,000,137 | ---- | C] () -- C:\Users\Greg\stephan moats.vcf
[2009/11/20 11:23:19 | 000,000,137 | ---- | C] () -- C:\Users\Greg\Lori Stickler.vcf
[2009/11/20 11:23:19 | 000,000,137 | ---- | C] () -- C:\Users\Greg\Janine Laughlin.vcf
[2009/11/20 11:23:19 | 000,000,137 | ---- | C] () -- C:\Users\Greg\Erin Fenderbosch.vcf
[2009/11/20 11:23:19 | 000,000,137 | ---- | C] () -- C:\Users\Greg\Erin Fenderbosch (1).vcf
[2009/11/20 11:23:19 | 000,000,136 | ---- | C] () -- C:\Users\Greg\Dawn traver.vcf
[2009/11/20 11:23:19 | 000,000,136 | ---- | C] () -- C:\Users\Greg\Curt Strawder.vcf
[2009/11/20 11:23:19 | 000,000,136 | ---- | C] () -- C:\Users\Greg\Aikfan2@aol_com.vcf
[2009/11/20 11:23:19 | 000,000,135 | ---- | C] () -- C:\Users\Greg\Tracy Olds.vcf
[2009/11/20 11:23:19 | 000,000,135 | ---- | C] () -- C:\Users\Greg\David Kless.vcf
[2009/11/20 11:23:19 | 000,000,134 | ---- | C] () -- C:\Users\Greg\Angela Eckman.vcf
[2009/11/20 11:23:19 | 000,000,133 | ---- | C] () -- C:\Users\Greg\Earl, Marissa N.vcf
[2009/11/20 11:23:19 | 000,000,133 | ---- | C] () -- C:\Users\Greg\Chuck Moats.vcf
[2009/11/20 11:23:19 | 000,000,131 | ---- | C] () -- C:\Users\Greg\Tim Chafins.vcf
[2009/11/20 11:23:19 | 000,000,131 | ---- | C] () -- C:\Users\Greg\The Prowler.vcf
[2009/11/20 11:23:19 | 000,000,130 | ---- | C] () -- C:\Users\Greg\Jeff Barr.vcf
[2009/11/20 11:23:19 | 000,000,129 | ---- | C] () -- C:\Users\Greg\Amiee Bell.vcf
[2009/11/20 11:23:19 | 000,000,128 | ---- | C] () -- C:\Users\Greg\Joe Laure.vcf
[2009/11/20 11:23:19 | 000,000,128 | ---- | C] () -- C:\Users\Greg\Eric Wolfe.vcf
[2009/11/20 11:23:19 | 000,000,128 | ---- | C] () -- C:\Users\Greg\Bob Wolfe.vcf
[2009/11/20 11:23:19 | 000,000,127 | ---- | C] () -- C:\Users\Greg\Greg Wolfe.vcf
[2009/11/20 11:23:19 | 000,000,123 | ---- | C] () -- C:\Users\Greg\Kelli.vcf
[2009/11/20 11:23:19 | 000,000,123 | ---- | C] () -- C:\Users\Greg\Holly.vcf
[2009/11/20 11:23:19 | 000,000,122 | ---- | C] () -- C:\Users\Greg\wolfe39.vcf
[2009/11/20 11:23:19 | 000,000,122 | ---- | C] () -- C:\Users\Greg\Ott, Eric.vcf
[2009/11/20 11:23:19 | 000,000,122 | ---- | C] () -- C:\Users\Greg\Amy.vcf
[2009/11/20 11:23:19 | 000,000,121 | ---- | C] () -- C:\Users\Greg\Marvin.vcf
[2009/11/20 11:23:19 | 000,000,121 | ---- | C] () -- C:\Users\Greg\Kelly.vcf
[2009/11/20 11:23:19 | 000,000,119 | ---- | C] () -- C:\Users\Greg\Erika.vcf
[2009/11/20 11:23:19 | 000,000,117 | ---- | C] () -- C:\Users\Greg\Willy.vcf
[2009/11/20 11:23:19 | 000,000,115 | ---- | C] () -- C:\Users\Greg\Erin.vcf
[2009/11/20 11:23:19 | 000,000,114 | ---- | C] () -- C:\Users\Greg\PM.vcf
[2009/11/20 11:23:19 | 000,000,077 | ---- | C] () -- C:\Users\Greg\Greg.vcf
[2009/11/12 01:33:12 | 000,000,017 | ---- | C] () -- C:\Users\Greg\AppData\Local\resmon.resmoncfg
========== LOP Check ==========
[2010/12/19 11:53:24 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Avery
[2012/05/17 23:50:17 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Azureus
[2011/04/15 11:37:36 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\BodyMedia
[2012/05/18 20:43:12 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Canon
[2012/05/18 20:44:08 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Canon_Inc_IC
[2011/12/08 10:23:20 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Catalina Marketing Corp
[2011/09/08 09:49:00 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Downloaded Installations
[2012/07/06 16:07:06 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\DriverCure
[2009/11/06 00:52:13 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\ESET
[2011/09/08 09:54:33 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\FedEx
[2010/08/06 09:57:27 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Firetrust
[2011/06/28 21:14:45 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Forte
[2011/08/10 21:13:05 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\GARMIN
[2011/03/12 17:20:29 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\GoodSync
[2009/11/06 01:10:32 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Leadertech
[2010/08/06 10:04:18 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\MailWasherPro
[2010/04/06 11:10:03 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\pdf995
[2011/11/09 20:28:07 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Product_RM
[2011/12/04 10:46:08 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Registry Mechanic
[2012/07/07 19:58:21 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\SanDisk SecureAccess
[2010/01/23 15:31:45 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Sony
[2010/01/23 15:30:48 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Sony Setup
[2012/07/06 16:07:05 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\SpeedyPC Software
[2012/01/19 10:21:53 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\TaxCut
[2010/04/15 11:27:22 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Thunderbird
[2012/05/20 12:57:23 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Ulead Systems
[2012/02/22 18:38:32 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Unity
[2009/11/06 20:54:00 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Western Digital
[2009/11/06 20:54:01 | 000,000,000 | ---D | M] -- C:\Users\Greg\AppData\Roaming\Western DigitalTemp
[2012/07/09 19:04:31 | 000,000,264 | ---- | M] () -- C:\Windows\Tasks\RMSchedule.job
[2012/05/22 15:43:33 | 000,032,600 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP

1B5B4F1
< End of report >