 2 edits | Sorry it's taken so long i did a system restore and problem seemingly went away so i didn't want to waste anyone's time further but it seems to have resurfaced again. so I'm going to go through all the steps this time to make sure it is gone instead of just trying to rollback my pc.
MBAM log:
Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org
Database version: 7950
Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005
10/15/2011 2:29:30 AM mbam-log-2011-10-15 (02-29-30).txt
Scan type: Full scan (C:\|D:\|E:\|) Objects scanned: 436784 Time elapsed: 1 hour(s), 31 minute(s), 45 second(s)
Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: (No malicious items detected)
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: (No malicious items detected)
OTL.txt -------------
OTL logfile created on: 10/15/2011 2:33:18 AM - Run 1 OTL by OldTimer - Version 3.2.30.0 Folder = C:\Users\John\Desktop Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation Internet Explorer (Version = 7.0.6002.18005) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 1.73 Gb Available Physical Memory | 57.83% Memory free 6.20 Gb Paging File | 4.95 Gb Available in Paging File | 79.75% Paging File free Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files Drive C: | 729.22 Gb Total Space | 389.55 Gb Free Space | 53.42% Space Free | Partition Type: NTFS Drive D: | 2.00 Gb Total Space | 1.98 Gb Free Space | 98.82% Space Free | Partition Type: FAT Drive E: | 200.30 Gb Total Space | 196.35 Gb Free Space | 98.03% Space Free | Partition Type: NTFS
Computer Name: JOHN-NEWPC | User Name: John | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2011/10/15 01:12:01 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe PRC - [2011/09/23 06:31:50 | 002,404,704 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgtray.exe PRC - [2011/09/21 19:53:12 | 000,973,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgemcx.exe PRC - [2011/09/13 06:32:40 | 001,227,616 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgnsx.exe PRC - [2011/09/12 06:23:46 | 005,265,248 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe PRC - [2011/09/08 20:53:26 | 000,743,264 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgrsx.exe PRC - [2011/08/15 06:21:40 | 000,337,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgcsrvx.exe PRC - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe PRC - [2010/12/30 18:59:56 | 000,957,840 | ---- | M] (Razer USA Ltd) -- C:\Program Files\Razer\Naga Epic\NagaEpicSysTray.exe PRC - [2010/09/25 17:57:53 | 002,969,496 | ---- | M] () -- C:\Program Files\Pando Networks\Media Booster\PMB.exe PRC - [2010/09/17 22:14:22 | 000,460,144 | ---- | M] () -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe PRC - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe PRC - [2010/07/09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe PRC - [2010/05/14 11:44:46 | 000,501,480 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Common Files\Java\Java Update\jucheck.exe PRC - [2010/01/15 05:49:20 | 000,255,536 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe PRC - [2009/04/10 23:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe PRC - [2007/03/06 12:38:28 | 000,090,112 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe PRC - [2007/03/06 12:37:30 | 000,303,104 | ---- | M] (SigmaTel, Inc.) -- C:\Windows\sttray.exe PRC - [2006/10/20 17:23:38 | 000,118,784 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2011/03/15 07:13:46 | 004,254,560 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF MOD - [2010/09/25 17:57:53 | 002,969,496 | ---- | M] () -- C:\Program Files\Pando Networks\Media Booster\PMB.exe MOD - [2010/03/24 21:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll MOD - [2010/03/15 11:28:22 | 000,141,824 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV - [2011/09/12 06:23:46 | 005,265,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\AVGIDSAgent.exe -- (AVGIDSAgent) SRV - [2011/08/02 06:09:08 | 000,192,776 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG2012\avgwdsvc.exe -- (avgwd) SRV - [2010/09/17 22:14:22 | 000,460,144 | ---- | M] () [Auto | Running] -- C:\Program Files\Flip Video\FlipShare\FlipShareService.exe -- (FlipShare Service) SRV - [2010/08/23 20:21:40 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service\IntuitUpdateService.exe -- (IntuitUpdateService) SRV - [2010/07/09 16:09:52 | 000,248,936 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service) SRV - [2010/03/25 10:25:22 | 030,969,208 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service) SRV - [2010/01/15 05:49:20 | 000,227,232 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe -- (McComponentHostService) SRV - [2009/07/16 17:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service) SRV - [2008/01/19 00:38:24 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend) SRV - [2007/03/06 12:38:28 | 000,090,112 | ---- | M] (SigmaTel, Inc.) [Auto | Running] -- C:\Program Files\SigmaTel\C-Major Audio\WDM\stacsv.exe -- (STacSV)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - [2011/09/13 06:30:10 | 000,032,592 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86) DRV - [2011/08/08 06:08:58 | 000,040,016 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\System32\drivers\avgmfx86.sys -- (Avgmfx86) DRV - [2011/07/11 01:14:38 | 000,295,248 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgtdix.sys -- (Avgtdix) DRV - [2011/07/11 01:14:02 | 000,024,272 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter) DRV - [2011/07/11 01:14:02 | 000,016,720 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSShim.sys -- (AVGIDSShim) DRV - [2011/07/11 01:14:00 | 000,023,120 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH) DRV - [2011/07/11 01:13:58 | 000,134,736 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver) DRV - [2011/07/11 01:13:46 | 000,229,840 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\System32\drivers\avgldx86.sys -- (Avgldx86) DRV - [2010/12/16 10:23:14 | 000,103,424 | ---- | M] (Razer USA Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\RzSynapse.sys -- (RzSynapse) DRV - [2010/07/09 15:37:00 | 011,008,040 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm) DRV - [2009/03/18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi) DRV - [2007/08/09 18:12:30 | 000,110,624 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\nvstor32.sys -- (nvstor32) DRV - [2007/03/06 12:38:52 | 000,323,584 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 3D 80 59 14 B3 25 82 4D 80 6D AC 6C 4C B2 87 A5 [binary data] IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.startup.homepage: "google.com" FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22 FF - prefs.js..extensions.enabledItems: {1E73965B-8B48-48be-9C8D-68B920ABC1C4}:12.0.0.1829 FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.22.1 FF - prefs.js..extensions.enabledItems: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}:5.3.0.7550 FF - prefs.js..extensions.enabledItems: {d722b51d-adb1-4ed0-a3d2-18ae69f26932}:1.0 FF - prefs.js..extensions.enabledItems: {8dbb41a2-a1a2-4779-9702-42f0b0dd7e85}:1.0 FF - prefs.js..extensions.enabledItems: {dae5d5c7-c375-42ad-b720-5b117a71f2e9}:1.0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll () FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\John\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\John\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.) FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files\AVG\AVG2012\Firefox4\ [2011/10/13 00:28:17 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/09/28 08:30:43 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/09/28 08:30:44 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.8\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/03/26 00:30:23 | 000,000,000 | ---D | M] FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 3.1.8\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\avgthb@avg.com: C:\Program Files\AVG\AVG2012\Thunderbird\ [2011/10/13 00:28:17 | 000,000,000 | ---D | M]
[2011/03/02 09:26:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Extensions [2011/03/02 09:26:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6} [2011/10/15 01:51:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions [2010/09/11 01:54:45 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2011/06/29 08:36:05 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055} [2011/04/27 08:29:24 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}(72) [2011/10/11 19:41:08 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{8dbb41a2-a1a2-4779-9702-42f0b0dd7e85} [2011/09/20 04:33:56 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{d722b51d-adb1-4ed0-a3d2-18ae69f26932} [2011/10/15 00:39:46 | 000,000,000 | ---D | M] (XUL Cache) -- C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\tx8aecv3.default\extensions\{dae5d5c7-c375-42ad-b720-5b117a71f2e9} [2011/10/15 02:12:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011/08/07 23:05:33 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} [2010/10/20 08:30:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} [2011/10/13 00:28:17 | 000,000,000 | ---D | M] (AVG Safe Search) -- C:\PROGRAM FILES\AVG\AVG2012\FIREFOX4 [2010/10/20 08:30:15 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[color=#E56717]========== Chrome ==========[/color]
CHR - default_search_provider: Google (Enabled) CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms} CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms} CHR - plugin: Shockwave Flash (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\Application\14.0.835.186\gcswf32.dll CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll CHR - plugin: Java(TM) Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer CHR - plugin: Native Client (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\Application\14.0.835.186\ppGoogleNaClPluginChrome.dll CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\Application\14.0.835.186\pdf.dll CHR - plugin: Skype Toolbars (Enabled) = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7280_0\npSkypeChromePlugin.dll CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll CHR - plugin: Google Update (Enabled) = C:\Users\John\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll CHR - plugin: Default Plug-in (Enabled) = default_plugin CHR - Extension: AVG Safe Search = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.1829_0\ CHR - Extension: Skype Extension = C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7280_0\
O1 HOSTS File: ([2011/09/20 05:17:07 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: ::1 localhost O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.) O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.) O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation) O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.) O4 - HKLM..\Run: [Razer Naga Driver] C:\Program Files\Razer\Naga Epic\NagaEpicSysTray.exe (Razer USA Ltd) O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Windows\sttray.exe (SigmaTel, Inc.) O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation) O4 - HKCU..\Run: [EPSON Stylus CX4800 Series] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_FATIADA.EXE (SEIKO EPSON CORPORATION) O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe () O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation) O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0 O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation) O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation) O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O13 - gopher Prefix: missing O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_22) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} »platformdl.adobe.com/NOS/getPlus···6/gp.cab (Reg Error: Key error.) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{248C0332-2C2E-4F58-AE76-018863005377}: DhcpNameServer = 192.168.1.254 O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Users\John\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O24 - Desktop BackupWallPaper: C:\Users\John\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2007/10/28 20:10:54 | 000,001,046 | ---- | M] () - D:\AUTOEXEC.UP -- [ FAT ] O32 - AutoRun File - [2008/01/03 12:44:24 | 000,001,046 | ---- | M] () - D:\autoexec.bat -- [ FAT ] O33 - MountPoints2\{9cbb9388-bc9f-11df-b97e-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{9cbb9388-bc9f-11df-b97e-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Installer.exe O33 - MountPoints2\{b334386c-1b50-11e0-9930-001aa0e43832}\Shell\AutoRun\command - "" = J:\Setup_FlipShare.exe O33 - MountPoints2\{b334386c-1b50-11e0-9930-001aa0e43832}\Shell\Setup FlipShare\command - "" = J:\Setup_FlipShare.exe O34 - HKLM BootExecute: (autocheck autochk *) O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart) O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %*
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2011/10/15 01:26:59 | 000,000,000 | ---D | C] -- C:\Users\John\Desktop\scan results [2011/10/15 01:11:59 | 000,583,168 | ---- | C] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe [2011/10/15 01:09:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hitman Pro 3.5 [2011/10/15 01:09:14 | 000,000,000 | ---D | C] -- C:\Program Files\Hitman Pro 3.5 [2011/10/15 01:08:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Hitman Pro [2011/10/15 00:57:09 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\Malwarebytes [2011/10/15 00:56:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2011/10/15 00:56:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2011/10/15 00:56:54 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys [2011/10/15 00:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2011/10/15 00:56:54 | 000,000,000 | ---D | C] -- C:\Program Files\MALWAREBYTES ANTI-MALWARE [2011/10/15 00:50:29 | 000,446,464 | ---- | C] (OldTimer Tools) -- C:\Users\John\Desktop\TFC.exe [2011/10/12 09:14:59 | 000,000,000 | ---D | C] -- C:\A7FD0A197DD46BE9EF88DB43D8D8F5CD [2011/10/12 09:10:09 | 000,000,000 | ---D | C] -- C:\588EED39D62B3C9AE6 [2011/10/11 19:05:03 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Local\Mumble [2011/09/27 23:34:28 | 000,000,000 | ---D | C] -- C:\Users\John\Documents\Diablo III [2011/09/27 18:56:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III Beta [2011/09/27 18:56:03 | 000,000,000 | ---D | C] -- C:\Program Files\Diablo III Beta [2011/09/27 18:55:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Battle.net [2011/09/27 18:54:24 | 029,903,576 | ---- | C] (Blizzard Entertainment) -- C:\Users\John\Diablo-III-Beta-enUS-Setup.exe [2011/09/27 08:59:08 | 000,000,000 | ---D | C] -- C:\Users\John\riotsGamesLogs [2011/09/25 01:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2012 [2011/09/25 01:11:51 | 000,000,000 | ---D | C] -- C:\Users\John\AppData\Roaming\AVG2012 [2011/09/25 01:11:28 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012 [2011/09/20 09:22:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo II [2011/09/20 09:09:26 | 002,678,868 | ---- | C] (Blizzard Entertainment) -- C:\Users\John\Downloader_Diablo2_Lord_of_Destruction_enUS.exe [2011/09/20 09:04:59 | 002,764,855 | ---- | C] (Blizzard Entertainment) -- C:\Users\John\Downloader_Diablo2_enUS.exe
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2011/10/15 02:35:00 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2317141556-767997521-738446607-1000UA.job [2011/10/15 01:37:08 | 000,023,624 | ---- | M] () -- C:\Windows\System32\drivers\hitmanpro35.sys [2011/10/15 01:12:34 | 000,879,028 | ---- | M] () -- C:\Users\John\Desktop\SecurityCheck.exe [2011/10/15 01:12:01 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\OTL.exe [2011/10/15 01:09:16 | 000,001,785 | ---- | M] () -- C:\Users\Public\Desktop\Hitman Pro 3.5.lnk [2011/10/15 00:56:57 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/10/15 00:54:21 | 000,055,637 | ---- | M] () -- C:\ProgramData\nvModes.dat [2011/10/15 00:54:20 | 000,055,637 | ---- | M] () -- C:\ProgramData\nvModes.001 [2011/10/15 00:54:05 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 [2011/10/15 00:54:05 | 000,003,792 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 [2011/10/15 00:54:02 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2011/10/15 00:53:58 | 3218,448,384 | -HS- | M] () -- C:\hiberfil.sys [2011/10/15 00:50:30 | 000,446,464 | ---- | M] (OldTimer Tools) -- C:\Users\John\Desktop\TFC.exe [2011/10/15 00:35:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2317141556-767997521-738446607-1000Core.job [2011/10/14 22:06:19 | 106,577,993 | ---- | M] () -- C:\Windows\System32\drivers\AVG\incavi.avm [2011/10/13 00:42:42 | 000,000,842 | ---- | M] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011/10/12 08:36:48 | 000,007,916 | ---- | M] () -- C:\Users\John\AppData\Local\d3d9caps.dat [2011/09/27 19:56:31 | 000,000,789 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk [2011/09/27 18:56:12 | 000,001,007 | ---- | M] () -- C:\Users\Public\Desktop\Diablo III Beta.lnk [2011/09/27 18:54:54 | 029,903,576 | ---- | M] (Blizzard Entertainment) -- C:\Users\John\Diablo-III-Beta-enUS-Setup.exe [2011/09/27 18:52:46 | 000,404,640 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl [2011/09/26 22:40:50 | 000,355,025 | ---- | M] () -- C:\Windows\System32\drivers\AVG\iavichjg.avm [2011/09/21 08:29:01 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk [2011/09/20 19:35:47 | 000,002,037 | ---- | M] () -- C:\Users\John\Desktop\Google Chrome.lnk [2011/09/20 19:35:47 | 000,001,999 | ---- | M] () -- C:\Users\John\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2011/09/20 09:26:14 | 000,000,928 | ---- | M] () -- C:\Users\Public\Desktop\Diablo II - Lord of Destruction.lnk [2011/09/20 09:09:27 | 002,678,868 | ---- | M] (Blizzard Entertainment) -- C:\Users\John\Downloader_Diablo2_Lord_of_Destruction_enUS.exe [2011/09/20 09:05:02 | 002,764,855 | ---- | M] (Blizzard Entertainment) -- C:\Users\John\Downloader_Diablo2_enUS.exe
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2011/10/15 01:12:30 | 000,879,028 | ---- | C] () -- C:\Users\John\Desktop\SecurityCheck.exe [2011/10/15 01:09:16 | 000,023,624 | ---- | C] () -- C:\Windows\System32\drivers\hitmanpro35.sys [2011/10/15 01:09:16 | 000,001,785 | ---- | C] () -- C:\Users\Public\Desktop\Hitman Pro 3.5.lnk [2011/10/15 00:56:57 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk [2011/09/27 18:56:03 | 000,001,007 | ---- | C] () -- C:\Users\Public\Desktop\Diablo III Beta.lnk [2011/09/25 01:12:53 | 000,000,842 | ---- | C] () -- C:\Users\Public\Desktop\AVG 2012.lnk [2011/09/20 09:22:31 | 000,000,928 | ---- | C] () -- C:\Users\Public\Desktop\Diablo II - Lord of Destruction.lnk [2010/12/19 09:33:15 | 000,002,048 | ---- | C] () -- C:\Users\John\AppData\Roaming\A&I Book Creator Prefs [2010/11/25 02:24:16 | 000,168,600 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat [2010/11/03 01:44:13 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat [2010/10/11 10:45:48 | 000,073,220 | ---- | C] () -- C:\Windows\System32\EPPICPrinterDB.dat [2010/10/11 10:45:48 | 000,031,053 | ---- | C] () -- C:\Windows\System32\EPPICPattern131.dat [2010/10/11 10:45:48 | 000,029,114 | ---- | C] () -- C:\Windows\System32\EPPICPattern1.dat [2010/10/11 10:45:48 | 000,027,417 | ---- | C] () -- C:\Windows\System32\EPPICPattern121.dat [2010/10/11 10:45:48 | 000,021,021 | ---- | C] () -- C:\Windows\System32\EPPICPattern3.dat [2010/10/11 10:45:48 | 000,015,670 | ---- | C] () -- C:\Windows\System32\EPPICPattern5.dat [2010/10/11 10:45:48 | 000,013,280 | ---- | C] () -- C:\Windows\System32\EPPICPattern2.dat [2010/10/11 10:45:48 | 000,010,673 | ---- | C] () -- C:\Windows\System32\EPPICPattern4.dat [2010/10/11 10:45:48 | 000,004,943 | ---- | C] () -- C:\Windows\System32\EPPICPattern6.dat [2010/10/11 10:45:48 | 000,001,140 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_PT.dat [2010/10/11 10:45:48 | 000,001,140 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_BP.dat [2010/10/11 10:45:48 | 000,001,137 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_ES.dat [2010/10/11 10:45:48 | 000,001,130 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_FR.dat [2010/10/11 10:45:48 | 000,001,130 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_CF.dat [2010/10/11 10:45:48 | 000,001,104 | ---- | C] () -- C:\Windows\System32\EPPICPresetData_EN.dat [2010/10/11 10:45:48 | 000,000,097 | ---- | C] () -- C:\Windows\System32\PICSDK.ini [2010/09/11 02:24:34 | 000,006,656 | ---- | C] () -- C:\Windows\System32\stacutil.dll [2010/09/10 19:09:13 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll [2010/09/10 19:09:13 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin [2010/09/10 04:36:14 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin [2010/09/10 03:25:45 | 000,055,637 | ---- | C] () -- C:\ProgramData\nvModes.001 [2010/09/10 03:12:49 | 000,055,637 | ---- | C] () -- C:\ProgramData\nvModes.dat [2010/09/09 23:22:00 | 000,014,848 | ---- | C] () -- C:\Users\John\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/09/09 23:17:46 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat [2010/09/09 23:01:45 | 000,007,916 | ---- | C] () -- C:\Users\John\AppData\Local\d3d9caps.dat [2009/07/08 18:03:02 | 000,058,880 | ---- | C] () -- C:\Windows\System32\bdmpegv.dll [2006/11/02 05:57:28 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat [2006/11/02 05:47:37 | 000,383,368 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT [2006/11/02 05:35:32 | 000,005,632 | ---- | C] () -- C:\Windows\System32\sysprepMCE.dll [2006/11/02 03:33:01 | 000,607,168 | ---- | C] () -- C:\Windows\System32\perfh009.dat [2006/11/02 03:33:01 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat [2006/11/02 03:33:01 | 000,104,808 | ---- | C] () -- C:\Windows\System32\perfc009.dat [2006/11/02 03:33:01 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat [2006/11/02 03:23:21 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat [2006/11/02 01:58:30 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin [2006/11/02 01:19:00 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT [2006/11/02 00:40:29 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini [2006/11/02 00:25:31 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[color=#E56717]========== LOP Check ==========[/color]
[2011/10/13 00:28:24 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\.BitTornado [2010/12/19 09:28:56 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\A&I Book Creator [2011/08/16 00:12:52 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Audacity [2011/09/25 01:11:51 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\AVG2012 [2011/09/19 22:31:10 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Dropbox [2011/06/17 17:51:02 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\EPSON [2010/09/11 02:04:51 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Helios [2010/09/29 02:39:31 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\LolClient [2011/10/12 04:21:14 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Mumble [2011/08/23 22:32:11 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Octoshape [2011/05/14 04:03:34 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\RIFT [2011/10/13 08:52:11 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Spotify [2011/03/02 09:26:44 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Thunderbird [2011/02/15 00:15:21 | 000,000,000 | ---D | M] -- C:\Users\John\AppData\Roaming\Wizards of the Coast [2011/10/15 00:52:50 | 000,032,598 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color] |