*Please don't code files..they need to be opened for easier analysis. Thanks

OTL by OldTimer - Version 3.2.55.0 Folder = C:\Users\Glen\Desktop\Malware
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 3.22 Gb Available Physical Memory | 53.60% Memory free
12.21 Gb Paging File | 9.10 Gb Available in Paging File | 74.51% Paging File free
Paging file location(s): f:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 12.07 Gb Free Space | 5.18% Space Free | Partition Type: NTFS
Drive D: | 5.37 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 118.56 Gb Free Space | 12.73% Space Free | Partition Type: NTFS
Computer Name: GLENVISTA | User Name: Glen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012/07/30 21:43:07 | 000,162,816 | ---- | M] () -- C:\Users\Glen\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
PRC - [2012/07/30 21:38:18 | 000,896,400 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files (x86)\uTorrent\uTorrent.exe
PRC - [2012/07/30 20:59:38 | 000,597,504 | ---- | M] (OldTimer Tools) -- C:\Users\Glen\Desktop\Malware\OTL.exe
PRC - [2012/06/13 03:48:50 | 002,321,560 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe
PRC - [2012/06/09 19:56:08 | 000,334,488 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe
PRC - [2012/06/09 19:56:04 | 000,113,304 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
PRC - [2012/06/09 19:55:24 | 000,129,688 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
PRC - [2012/06/09 19:55:18 | 000,404,120 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe
PRC - [2012/06/09 18:30:12 | 000,539,288 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe
PRC - [2012/05/24 14:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Glen\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2012/05/14 11:28:22 | 006,149,120 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files (x86)\Free Download Manager\fdm.exe
PRC - [2012/04/05 05:12:34 | 002,587,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
PRC - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2012/07/30 21:44:07 | 000,056,224 | ---- | M] () -- \\?\C:\Users\Glen\AppData\Roaming\uTorrent\VirusGuard\avxdisk.dll
MOD - [2012/07/30 21:43:07 | 000,162,816 | ---- | M] () -- C:\Users\Glen\AppData\Roaming\uTorrent\VirusGuard\BitTorrentAntivirus.exe
[color=#E56717]========== Win32 Services (SafeList) ==========[/color]
SRV:
64bit: - [2011/10/31 05:49:32 | 000,301,720 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV:
64bit: - [2011/09/27 15:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:
64bit: - [2009/04/11 12:25:24 | 000,062,976 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nfsclnt.exe -- (NfsClnt)
SRV:
64bit: - [2008/07/29 13:20:28 | 004,737,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90)
SRV:
64bit: - [2008/01/20 22:51:10 | 000,521,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ntmssvc.dll -- (NtmsSvc)
SRV:
64bit: - [2008/01/20 22:50:23 | 000,195,584 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:
64bit: - [2008/01/20 22:46:39 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/07/30 17:54:04 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/19 11:58:10 | 000,529,232 | ---- | M] (Valve Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/06/17 13:40:56 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/06/13 03:48:50 | 002,321,560 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgfws.exe -- (avgfws)
SRV - [2012/06/09 19:56:08 | 000,334,488 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP)
SRV - [2012/06/09 19:56:04 | 000,113,304 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe -- (VMAuthdService)
SRV - [2012/06/09 19:55:18 | 000,404,120 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service)
SRV - [2012/06/09 18:30:12 | 000,539,288 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe -- (VMUSBArbService)
SRV - [2012/06/05 15:17:44 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/03/19 07:38:46 | 002,666,880 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/02/29 20:02:00 | 002,348,352 | ---- | M] (NVIDIA Corporation) [Auto | Stopped] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2012/02/29 13:26:46 | 000,382,272 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2012/02/14 04:53:38 | 000,193,288 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe -- (avgwd)
SRV - [2012/01/05 11:42:34 | 000,075,624 | ---- | M] (Alcohol Soft Development Team) [Disabled | Stopped] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\AxAutoMntSrv.exe -- (AxAutoMntSrv)
SRV - [2011/09/06 02:33:56 | 003,547,648 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\SlySoft\Game Jackal v4\Server.exe -- (GJService)
SRV - [2011/08/07 08:40:00 | 003,804,120 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2011/06/22 23:49:10 | 000,075,136 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2010/08/19 13:57:14 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2010/06/25 13:07:20 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\WinPcap\rpcapd.exe -- (rpcapd)
SRV - [2010/03/18 14:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/12/23 17:34:20 | 000,370,688 | ---- | M] (StarWind Software) [On_Demand | Stopped] -- C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe -- (StarWindServiceAE)
SRV - [2009/04/11 12:24:52 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV:
64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\AudioCoder x64\SysInfoX64.sys -- (CrystalSysInfo)
DRV:
64bit: - [2012/06/09 19:56:52 | 000,068,760 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86)
DRV:
64bit: - [2012/06/09 19:56:40 | 000,081,048 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci)
DRV:
64bit: - [2012/06/09 19:54:56 | 000,031,896 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd)
DRV:
64bit: - [2012/06/09 19:54:50 | 000,030,360 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif)
DRV:
64bit: - [2012/06/09 18:30:08 | 000,038,552 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon)
DRV:
64bit: - [2012/06/09 16:06:56 | 000,045,104 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\DRIVERS\vmnetbridge.sys -- (VMnetBridge)
DRV:
64bit: - [2012/06/09 16:06:56 | 000,020,016 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\vmnetadapter.sys -- (VMnetAdapter)
DRV:
64bit: - [2012/05/22 14:26:10 | 000,147,288 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\VBoxNetAdp.sys -- (VBoxNetAdp)
DRV:
64bit: - [2012/04/19 04:50:26 | 000,028,480 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\Windows\SysNative\DRIVERS\avgidsha.sys -- (AVGIDSHA)
DRV:
64bit: - [2012/04/15 15:35:48 | 000,560,184 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\sptd.sys -- (sptd)
DRV:
64bit: - [2012/03/19 05:17:26 | 000,383,808 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avgtdia.sys -- (Avgtdia)
DRV:
64bit: - [2012/02/29 09:52:46 | 000,016,384 | ---- | M] (Microsoft Corporation) [Recognizer | System | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2012/02/22 05:25:32 | 000,289,872 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avgldx64.sys -- (Avgldx64)
DRV:
64bit: - [2012/01/31 04:46:48 | 000,036,944 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\DRIVERS\avgrkx64.sys -- (Avgrkx64)
DRV:
64bit: - [2011/12/23 13:32:14 | 000,047,696 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\DRIVERS\avgmfx64.sys -- (Avgmfx64)
DRV:
64bit: - [2011/12/15 13:29:42 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\tap0901.sys -- (tap0901)
DRV:
64bit: - [2011/10/31 05:50:12 | 000,013,464 | ---- | M] (Paramount Software UK Ltd) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PSVolAcc.sys -- (PSVolAcc)
DRV:
64bit: - [2011/10/31 05:49:46 | 000,040,600 | ---- | M] (Macrium Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\psmounter.sys -- (PSMounter)
DRV:
64bit: - [2011/09/06 02:28:48 | 000,059,512 | ---- | M] (SlySoft Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\maploml.sys -- (MaplomL)
DRV:
64bit: - [2011/09/06 02:28:32 | 000,034,936 | ---- | M] (SlySoft Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\maplom.sys -- (Maplom)
DRV:
64bit: - [2011/09/02 02:30:24 | 000,076,056 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LEqdUsb.Sys -- (LEqdUsb)
DRV:
64bit: - [2011/09/02 02:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LHidFilt.Sys -- (LHidFilt)
DRV:
64bit: - [2011/09/02 02:30:24 | 000,015,128 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\LHidEqd.Sys -- (LHidEqd)
DRV:
64bit: - [2011/07/17 00:25:35 | 000,017,224 | ---- | M] () [Kernel | On_Demand | Unknown] -- C:\Windows\SysNative\Drivers\Dbgv.sys -- (Dbgv)
DRV:
64bit: - [2011/05/23 01:03:28 | 000,048,992 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\DRIVERS\avgfwd6a.sys -- (Avgfwfd)
DRV:
64bit: - [2011/03/04 15:44:12 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\Drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:
64bit: - [2010/11/06 22:24:34 | 000,024,176 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files\PeerBlock\pbfilter.sys -- (pbfilter)
DRV:
64bit: - [2010/08/24 13:29:32 | 000,057,936 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LMouFilt.Sys -- (LMouFilt)
DRV:
64bit: - [2010/08/24 13:28:24 | 000,030,800 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\L8042Kbd.sys -- (L8042Kbd)
DRV:
64bit: - [2010/08/10 19:56:48 | 000,029,696 | ---- | M] (Leaf Networks) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\leafnets.sys -- (leafnets)
DRV:
64bit: - [2010/07/01 13:11:24 | 000,012,352 | ---- | M] () [Kernel | "Start" not found. | Unknown] -- C:\Program Files\Unlocker\UnlockerDriver5.sys -- (UnlockerDriver5)
DRV:
64bit: - [2010/06/25 13:07:26 | 000,035,344 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:
64bit: - [2009/09/30 20:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:
64bit: - [2009/08/05 15:18:32 | 000,057,856 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\L1E60x64.sys -- (L1E)
DRV:
64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2009/04/11 12:25:24 | 000,252,416 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\nfsrdr.sys -- (NfsRdr)
DRV:
64bit: - [2009/04/11 12:25:24 | 000,089,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rpcxdr.sys -- (RpcXdr)
DRV:
64bit: - [2009/04/08 15:28:46 | 000,068,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\xusb21.sys -- (xusb21)
DRV:
64bit: - [2009/02/24 19:35:44 | 000,255,552 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\mcdbus.sys -- (mcdbus)
DRV:
64bit: - [2008/01/20 22:46:34 | 000,903,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\xnacc.sys -- (xnacc)
DRV:
64bit: - [2008/01/20 22:46:34 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\avc.sys -- (Avc)
DRV:
64bit: - [2008/01/20 22:46:34 | 000,017,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\avcstrm.sys -- (AVCSTRM)
DRV:
64bit: - [2008/01/20 22:46:08 | 000,056,448 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\mstape.sys -- (MSTAPE)
DRV:
64bit: - [2008/01/20 22:46:06 | 000,054,840 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:
64bit: - [2008/01/20 22:46:05 | 000,058,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\61883.sys -- (61883)
DRV:
64bit: - [2008/01/20 22:46:01 | 000,061,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\msdv.sys -- (MSDV)
DRV:
64bit: - [2006/11/01 00:23:42 | 000,015,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\ASACPI.sys -- (MTsensor)
DRV - [2010/08/19 13:56:38 | 000,032,816 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »
www.bing.com/search?q={searchTer···M=IE8SRCIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = »
www.bing.com/search?q={searchTer···M=IE8SRCIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = »
www.msn.com/?ocid=iehpIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 33 F6 F9 57 C5 6D CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {F6E0DF0B-58AB-4992-8A9C-B8209D80BBB5}
IE - HKCU\..\SearchScopes\{F6E0DF0B-58AB-4992-8A9C-B8209D80BBB5}: "URL" = »
www.google.com/search?q={searchT···coding?}IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "about:blank"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: support@lastpass.com:1.72.0
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.3.0.7280
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:4.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.1: C:\Windows\system32\npDeployJava1.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.1: C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker\bin\npFFApi.dll File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.2: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\WOW64\TrustChecker
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fiddlerhook@fiddler2.com: C:\Program Files (x86)\Fiddler2\FiddlerHook [2012/07/02 00:57:18 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/07/25 09:04:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/23 12:39:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/23 12:39:20 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/23 12:39:20 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/06/23 12:39:20 | 000,000,000 | ---D | M]
[2010/11/21 16:29:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Glen\AppData\Roaming\Mozilla\Extensions
[2012/07/30 20:58:53 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\scx7yf13.default\extensions
[2012/07/08 15:10:21 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\scx7yf13.default\extensions\support@lastpass.com
[2012/01/17 17:53:18 | 000,002,281 | ---- | M] () -- C:\Users\Glen\AppData\Roaming\Mozilla\Firefox\Profiles\scx7yf13.default\searchplugins\s-amazon.xml
[2011/11/08 16:46:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/07/25 09:04:42 | 000,000,000 | ---D | M] (AVG Do Not Track) -- C:\PROGRAM FILES (X86)\AVG\AVG2012\FIREFOX\DONOTTRACK
[2012/07/02 00:57:18 | 000,000,000 | ---D | M] (FiddlerHook) -- C:\PROGRAM FILES (X86)\FIDDLER2\FIDDLERHOOK
[2012/06/17 13:38:54 | 000,000,000 | ---D | M] (Free Download Manager plugin) -- C:\PROGRAM FILES (X86)\FREE DOWNLOAD MANAGER\FIREFOX\EXTENSION
[2012/07/30 20:58:53 | 000,195,889 | ---- | M] () (No name found) -- C:\USERS\GLEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SCX7YF13.DEFAULT\EXTENSIONS\{37FA1426-B82D-11DB-8314-0800200C9A66}.XPI
[2012/02/06 22:05:50 | 000,007,240 | ---- | M] () (No name found) -- C:\USERS\GLEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\SCX7YF13.DEFAULT\EXTENSIONS\YOUTUBE-COMMENT-SNOB@EFINKE.COM.XPI
[2010/11/22 22:32:48 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/06/17 13:40:56 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/04 00:29:57 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012/06/06 23:56:28 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/06/06 23:56:28 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2011/01/27 16:00:57 | 000,001,211 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O2:
64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:
64bit: - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)
O2:
64bit: - BHO: (LastPass Vault) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll ()
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (LastPass Vault) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPToolbar.dll ()
O2 - BHO: (Free Download Manager) - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files (x86)\Free Download Manager\iefdm2.dll (FreeDownloadManager.ORG)
O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll ()
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [vmware-tray] C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (VMware, Inc.)
O4 - HKCU..\Run: [Free Download Manager] C:\Program Files (x86)\Free Download Manager\fdm.exe (FreeDownloadManager.ORG)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation)
O4 - Startup: C:\Users\Glen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Glen\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoChangeStartMenu = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoClose = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O8:
64bit: - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8:
64bit: - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8:
64bit: - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8:
64bit: - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8:
64bit: - Extra context menu item: LastPass - file://C:\Users\Glen\AppData\LocalLow\LastPass\context.html?cmd=lastpass File not found
O8:
64bit: - Extra context menu item: LastPass Fill Forms - file://C:\Users\Glen\AppData\LocalLow\LastPass\context.html?cmd=fillforms File not found
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files (x86)\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: LastPass - file://C:\Users\Glen\AppData\LocalLow\LastPass\context.html?cmd=lastpass File not found
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Users\Glen\AppData\LocalLow\LastPass\context.html?cmd=fillforms File not found
O9:
64bit: - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll ()
O9:
64bit: - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll ()
O9:
64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9:
64bit: - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Eric Lawrence)
O9:
64bit: - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll ()
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPToolbar.dll ()
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files (x86)\Fiddler2\Fiddler.exe (Eric Lawrence)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\x64\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} »
support.asus.com/select/asusTek_···trl3.cab (asusTek_sysctrl Class)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} »
download.microsoft.com/download/···trol.cab (Windows Genuine Advantage Validation Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{33921D60-5DCA-45F8-B8B5-2D4636D4C750}: NameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O27:
64bit: - HKLM IFEO\taskmgr.exe: Debugger - C:\WINDOWS\PROCEXP.EXE (Sysinternals - www.sysinternals.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/16 06:51:33 | 000,054,544 | R--- | M] (Electronic Arts) - D:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2009/09/21 15:58:35 | 000,000,049 | R--- | M] () - D:\Autorun.inf -- [ UDF ]
O33 - MountPoints2\{0c71f140-12b5-11e1-8067-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{0c71f140-12b5-11e1-8067-806e6f6e6963}\Shell\AutoRun\command - "" = G:\RunGame.exe
O33 - MountPoints2\{1058922b-12ab-11e0-b8cb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1058922b-12ab-11e0-b8cb-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe -- [2009/10/16 06:51:33 | 000,054,544 | R--- | M] (Electronic Arts)
O33 - MountPoints2\{1058922c-12ab-11e0-b8cb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1058922c-12ab-11e0-b8cb-806e6f6e6963}\Shell\AutoRun\command - "" = E:\CDSAMPLE\AUTORUN\AUTORUN.EXE
O33 - MountPoints2\{127b5719-d987-11e0-8b53-005056c00001}\Shell - "" = AutoRun
O33 - MountPoints2\{127b5719-d987-11e0-8b53-005056c00001}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\{1633801e-f5a9-11df-90a1-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{1633801e-f5a9-11df-90a1-806e6f6e6963}\Shell\AutoRun\command - "" = G:\setup.exe
O33 - MountPoints2\{25b3c640-9788-11e0-ba6c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{25b3c640-9788-11e0-ba6c-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Autorun.exe
O33 - MountPoints2\{34d3504b-f5af-11df-b602-0019dbe74e00}\Shell - "" = AutoRun
O33 - MountPoints2\{34d3504b-f5af-11df-b602-0019dbe74e00}\Shell\AutoRun\command - "" = E:\Setup\rsrc\Autorun.exe
O33 - MountPoints2\{34d3504b-f5af-11df-b602-0019dbe74e00}\Shell\dinstall\command - "" = E:\Directx\dxsetup.exe
O33 - MountPoints2\{bde3acca-1a82-11e0-916a-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{bde3acca-1a82-11e0-916a-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Autorun.exe -- [2009/10/16 06:51:33 | 000,054,544 | R--- | M] (Electronic Arts)
O33 - MountPoints2\{e54f0e30-049c-11e0-b507-0019dbe74e00}\Shell - "" = AutoRun
O33 - MountPoints2\{e54f0e30-049c-11e0-b507-0019dbe74e00}\Shell\AutoRun\command - "" = H:\Autorun.exe
O33 - MountPoints2\{e54f0e30-049c-11e0-b507-0019dbe74e00}\Shell\dinstall\command - "" = Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/07/30 21:38:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/07/30 21:37:43 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\uTorrent
[2012/07/30 20:23:08 | 000,000,000 | ---D | C] -- C:\Users\Glen\Desktop\Malware
[2012/07/30 18:14:49 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\Malwarebytes
[2012/07/30 18:14:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/30 18:14:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/30 18:14:42 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/30 18:14:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/30 14:21:01 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\JDeveloper
[2012/07/30 09:52:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeraCopy
[2012/07/30 09:52:53 | 000,000,000 | ---D | C] -- C:\Program Files\TeraCopy
[2012/07/30 09:52:32 | 000,000,000 | ---D | C] -- C:\jdeveloper
[2012/07/25 13:00:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenVPN
[2012/07/25 09:05:54 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\AVG2012
[2012/07/25 09:05:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2012/07/25 09:05:28 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\drivers\AVG
[2012/07/25 09:04:35 | 000,000,000 | -H-D | C] -- C:\$AVG
[2012/07/25 09:04:34 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\AVG
[2012/07/25 09:04:33 | 000,000,000 | ---D | C] -- C:\ProgramData\AVG2012
[2012/07/25 09:03:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVG
[2012/07/25 09:00:43 | 000,000,000 | -H-D | C] -- C:\ProgramData\Common Files
[2012/07/25 09:00:43 | 000,000,000 | ---D | C] -- C:\ProgramData\MFAData
[2012/07/25 08:42:49 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Electronic Arts
[2012/07/24 19:29:41 | 000,000,000 | ---D | C] -- C:\Users\Glen\Documents\Expresso Projects
[2012/07/24 19:29:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ultrapico
[2012/07/24 19:29:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Expresso
[2012/07/24 09:30:11 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Local\SMS
[2012/07/24 09:28:14 | 000,000,000 | ---D | C] -- C:\Users\Glen\Documents\CARS
[2012/07/21 18:33:31 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FAKEFACTORY CM11
[2012/07/17 18:36:12 | 000,000,000 | ---D | C] -- C:\Users\Glen\winamp_visual
[2012/07/16 09:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Xilisoft
[2012/07/15 16:03:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2012/07/15 16:02:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPER © - by eRightSoft
[2012/07/15 16:02:32 | 000,216,064 | RHS- | C] (MONOGRAM Multimedia, s.r.o.) -- C:\Windows\SysWow64\nbDX.dll
[2012/07/15 16:02:32 | 000,163,328 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\flvDX.dll
[2012/07/15 16:02:32 | 000,092,672 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLVorbisDec.ax
[2012/07/15 16:02:32 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSSplitter.ax
[2012/07/15 16:02:32 | 000,090,112 | RHS- | C] (-) -- C:\Windows\SysWow64\TTADSDecoder.ax
[2012/07/15 16:02:32 | 000,067,584 | RHS- | C] (RadLight, LLC) -- C:\Windows\SysWow64\RLTheoraDec.ax
[2012/07/15 16:02:32 | 000,031,232 | RHS- | C] (Hans Mayerl) -- C:\Windows\SysWow64\msfDX.dll
[2012/07/15 16:02:31 | 000,186,880 | RHS- | C] (RadLight) -- C:\Windows\SysWow64\RLOgg.ax
[2012/07/15 16:02:31 | 000,161,792 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\RealMediaDX.ax
[2012/07/15 16:02:29 | 000,179,200 | RHS- | C] (Gabest) -- C:\Windows\SysWow64\DiracSplitter.ax
[2012/07/15 16:02:29 | 000,123,904 | RHS- | C] (CoreCodec) -- C:\Windows\SysWow64\AVCDX.ax
[2012/07/14 18:24:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Traffic Simulator Configuration Tool
[2012/07/14 18:24:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Network Addon Mod
[2012/07/14 16:04:58 | 000,000,000 | ---D | C] -- C:\Users\Glen\.grasp_settings
[2012/07/14 15:50:09 | 000,955,800 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\npDeployJava1.dll
[2012/07/14 15:50:09 | 000,268,680 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaws.exe
[2012/07/14 15:49:45 | 000,189,424 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2012/07/14 15:49:45 | 000,188,912 | ---- | C] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2012/07/14 15:47:10 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/07/14 09:35:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis
[2012/07/14 09:34:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Maxis
[2012/07/11 09:27:37 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2012/07/11 09:27:37 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2012/07/11 09:27:35 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2012/07/11 09:27:35 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2012/07/11 09:27:34 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2012/07/11 09:27:34 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2012/07/11 09:27:34 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2012/07/11 09:27:34 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2012/07/11 09:27:33 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2012/07/11 09:27:32 | 002,311,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2012/07/11 09:27:32 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2012/07/11 09:27:31 | 000,818,688 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2012/07/11 09:27:31 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2012/07/11 09:17:25 | 000,254,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ncrypt.dll
[2012/07/08 10:20:03 | 014,690,376 | ---- | C] (LastPass) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2012/07/08 10:19:44 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
[2012/07/08 10:19:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
[2012/07/08 10:19:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LastPass
[2012/07/04 14:54:48 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\vlc
[2012/07/04 14:53:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/07/03 23:50:36 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Roaming\SpyStudio
[2012/07/03 23:50:32 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Local\Nektra
[2012/07/03 12:49:40 | 000,000,000 | ---D | C] -- C:\Users\Glen\AppData\Local\rohitab.com
[2012/07/03 12:49:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\rohitab.com
[2012/07/03 12:48:47 | 000,000,000 | ---D | C] -- C:\Program Files\rohitab.com
[2012/07/02 00:57:33 | 000,000,000 | ---D | C] -- C:\Users\Glen\Documents\Fiddler2
[2012/07/02 00:57:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Fiddler2
[2012/07/01 16:06:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\CE Remote Tools
[6 C:\Users\Glen\AppData\Local\*.tmp files -> C:\Users\Glen\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/07/30 21:52:23 | 000,008,560 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/30 21:52:23 | 000,008,560 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/30 21:38:18 | 000,000,792 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/07/30 21:26:24 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/30 20:23:44 | 000,000,592 | ---- | M] () -- C:\Users\Glen\Desktop\JDeveloper.lnk
[2012/07/30 20:10:28 | 000,017,558 | ---- | M] () -- C:\Users\Glen\AppData\Local\recently-used.xbel
[2012/07/30 19:00:32 | 102,599,076 | ---- | M] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/07/30 18:14:43 | 000,000,958 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/30 17:54:03 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/07/30 17:54:03 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/07/30 17:52:22 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/29 14:20:32 | 004,941,696 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/29 14:08:20 | 000,001,251 | ---- | M] () -- C:\CoreTemp.ini
[2012/07/28 23:00:55 | 000,241,152 | ---- | M] () -- C:\Users\Glen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/25 09:05:28 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/07/25 09:05:28 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/07/25 09:05:28 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/07/25 08:59:39 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/07/25 08:58:50 | 000,693,008 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/25 08:58:50 | 000,138,660 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/24 12:29:48 | 000,000,352 | ---- | M] () -- C:\Users\Glen\AppData\Roaming\Network Meter_Settings.ini
[2012/07/20 19:44:59 | 000,000,600 | ---- | M] () -- C:\Users\Glen\AppData\Local\PUTTY.RND
[2012/07/20 11:23:36 | 000,834,070 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/18 19:21:18 | 000,001,961 | ---- | M] () -- C:\Users\Glen\Documents\ax_files.xml
[2012/07/14 15:49:30 | 000,189,424 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\javaw.exe
[2012/07/14 15:49:29 | 000,188,912 | ---- | M] (Oracle Corporation) -- C:\Windows\SysNative\java.exe
[2012/07/14 09:35:35 | 000,002,006 | ---- | M] () -- C:\Users\Glen\Desktop\SimCity 4 Deluxe.lnk
[2012/07/14 09:34:19 | 000,000,741 | ---- | M] () -- C:\Windows\eReg.dat
[2012/07/13 17:01:17 | 000,000,780 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/07/12 13:35:38 | 000,000,880 | ---- | M] () -- C:\Users\Public\Desktop\foobar2000.lnk
[2012/07/08 15:10:27 | 014,690,376 | ---- | M] (LastPass) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2012/07/08 00:43:20 | 000,000,003 | ---- | M] () -- C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/07/04 14:53:50 | 000,000,911 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/07/04 12:42:57 | 000,682,898 | ---- | M] () -- C:\Users\Glen\Documents\TrainzAPIScanning.xml
[2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/02 00:37:47 | 000,104,864 | ---- | M] () -- C:\Users\Glen\Documents\AuranRequest.xml
[2012/07/01 00:16:08 | 000,000,918 | ---- | M] () -- C:\Users\Public\Desktop\Buzz.lnk
[6 C:\Users\Glen\AppData\Local\*.tmp files -> C:\Users\Glen\AppData\Local\*.tmp -> ]
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/07/30 21:38:18 | 000,000,792 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/07/30 20:23:44 | 000,000,592 | ---- | C] () -- C:\Users\Glen\Desktop\JDeveloper.lnk
[2012/07/30 20:10:28 | 000,017,558 | ---- | C] () -- C:\Users\Glen\AppData\Local\recently-used.xbel
[2012/07/30 19:00:32 | 102,599,076 | ---- | C] () -- C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/07/30 18:14:43 | 000,000,958 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/07/29 14:19:47 | 004,941,696 | ---- | C] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/25 09:05:28 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\incavi.avm
[2012/07/25 09:05:28 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavifw.avm
[2012/07/25 09:05:28 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\drivers\AVG\iavichjw.avm
[2012/07/15 16:02:32 | 000,121,344 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.ax
[2012/07/15 16:02:32 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll
[2012/07/15 16:02:31 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\RLMPCDec.ax
[2012/07/15 16:02:31 | 000,070,656 | RHS- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2012/07/15 16:02:31 | 000,051,712 | RHS- | C] () -- C:\Windows\SysWow64\RLSpeexDec.ax
[2012/07/15 16:02:30 | 000,195,584 | RHS- | C] () -- C:\Windows\SysWow64\MatroskaDX.ax
[2012/07/15 16:02:30 | 000,120,832 | RHS- | C] () -- C:\Windows\SysWow64\MPCDx.ax
[2012/07/15 16:02:30 | 000,097,280 | RHS- | C] () -- C:\Windows\SysWow64\FLACDX.ax
[2012/07/15 16:02:29 | 000,227,328 | RHS- | C] () -- C:\Windows\SysWow64\ac3DX.ax
[2012/07/15 16:02:29 | 000,175,104 | RHS- | C] () -- C:\Windows\SysWow64\CoreAAC.ax
[2012/07/15 16:02:29 | 000,081,920 | RHS- | C] () -- C:\Windows\SysWow64\aac_parser.ax
[2012/07/14 09:35:34 | 000,002,006 | ---- | C] () -- C:\Users\Glen\Desktop\SimCity 4 Deluxe.lnk
[2012/07/08 00:43:20 | 000,000,003 | ---- | C] () -- C:\Windows\SysNative\HRUPPROG.DIE.NOW
[2012/07/04 14:53:50 | 000,000,911 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/07/04 11:45:17 | 000,682,898 | ---- | C] () -- C:\Users\Glen\Documents\TrainzAPIScanning.xml
[2012/07/02 00:57:18 | 000,001,737 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fiddler2.lnk
[2012/07/02 00:37:47 | 000,104,864 | ---- | C] () -- C:\Users\Glen\Documents\AuranRequest.xml
[2012/06/26 23:32:15 | 000,197,621 | ---- | C] () -- C:\Users\Glen\AppData\Local\census.cache
[2012/06/26 23:31:54 | 000,163,126 | ---- | C] () -- C:\Users\Glen\AppData\Local\ars.cache
[2012/06/26 23:18:16 | 000,000,036 | ---- | C] () -- C:\Users\Glen\AppData\Local\housecall.guid.cache
[2012/06/15 20:17:24 | 000,042,432 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012/06/06 18:35:37 | 000,000,741 | ---- | C] () -- C:\Windows\eReg.dat
[2012/02/29 13:26:56 | 000,416,064 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/01/13 14:37:09 | 000,056,320 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll
[2011/11/25 13:29:32 | 000,000,410 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\hexplorer.dat
[2011/11/25 13:29:32 | 000,000,004 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\mclip.dat
[2011/11/19 21:42:50 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2011/11/19 21:42:50 | 000,013,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2011/10/27 17:27:01 | 000,000,600 | ---- | C] () -- C:\Users\Glen\AppData\Local\PUTTY.RND
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/08/20 18:29:05 | 000,039,894 | ---- | C] () -- C:\ProgramData\HKCU.reg
[2011/07/29 04:08:25 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll
[2011/07/28 23:02:04 | 000,000,033 | ---- | C] () -- C:\Windows\Caligari.ini
[2011/07/02 00:19:00 | 000,000,352 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\Network Meter_Settings.ini
[2011/06/22 23:49:11 | 000,281,656 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/06/22 23:49:10 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/06/12 11:28:21 | 000,000,035 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011/06/03 18:33:06 | 000,024,226 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\UserTile.png
[2011/05/26 15:47:07 | 000,000,339 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\Drives Meter_Settings.ini
[2011/04/18 16:23:48 | 000,000,011 | ---- | C] () -- C:\Users\Glen\Plugins.ini
[2011/04/16 11:45:52 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/04/06 23:19:24 | 000,001,356 | ---- | C] () -- C:\Users\Glen\AppData\Local\d3d9caps.dat
[2011/01/07 14:53:20 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2010/12/12 15:42:33 | 000,000,533 | ---- | C] () -- C:\Windows\Tcsofla.INI
[2010/12/12 01:45:32 | 000,000,172 | ---- | C] () -- C:\Users\Glen\AppData\Local\rahistory.xml
[2010/12/10 22:36:10 | 000,000,600 | ---- | C] () -- C:\Windows\Rtcw.INI
[2010/12/10 18:02:08 | 000,000,160 | ---- | C] () -- C:\Windows\wininit.ini
[2010/12/03 18:33:34 | 000,848,122 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/11/23 16:18:01 | 000,241,152 | ---- | C] () -- C:\Users\Glen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/21 14:09:59 | 000,000,363 | ---- | C] () -- C:\Users\Glen\AppData\Roaming\GPU Monitor_Settings.ini
[2010/11/21 13:25:15 | 000,000,552 | ---- | C] () -- C:\Users\Glen\AppData\Local\d3d8caps.dat
[2010/11/21 13:04:34 | 000,001,460 | ---- | C] () -- C:\Users\Glen\AppData\Local\d3d9caps64.dat
[color=#E56717]========== LOP Check ==========[/color]
[2012/06/17 13:44:54 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\.minecraft
[2010/12/11 23:49:06 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Armagetron
[2012/07/25 21:04:00 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Audacity
[2011/05/03 18:08:08 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Auslogics
[2012/07/25 09:05:54 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\AVG2012
[2011/07/29 04:41:11 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Blender Foundation
[2011/08/11 01:00:05 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Broad Intelligence
[2012/04/21 17:06:43 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/03/27 17:00:33 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\CheckPoint
[2011/12/01 19:18:05 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/08/10 15:18:51 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\DAEMON Tools Lite
[2012/07/30 21:21:58 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Dropbox
[2012/05/11 14:07:14 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\EurekaLog
[2012/07/23 22:08:18 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\FileZilla
[2012/07/30 20:56:09 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\foobar2000
[2012/07/30 22:00:30 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Free Download Manager
[2012/01/18 18:06:26 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\gtk-2.0
[2012/06/30 19:48:37 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Hex-Rays
[2011/05/10 01:05:34 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\ImgBurn
[2012/07/30 14:21:01 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\JDeveloper
[2011/04/18 16:16:46 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Jeskola
[2010/11/21 16:48:24 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Leadertech
[2011/05/31 21:11:17 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\MPEG Streamclip
[2012/02/12 20:02:02 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Mumble
[2012/07/30 16:53:50 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Notepad++
[2011/12/01 19:20:41 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\PACE Anti-Piracy
[2011/06/03 18:33:05 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\PeerNetworking
[2011/05/02 23:56:13 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\PilotEdit
[2011/07/05 11:02:43 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Polac
[2012/06/24 15:36:47 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Process Hacker 2
[2011/04/21 21:30:40 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Publish Providers
[2011/04/21 21:30:15 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Sony
[2012/07/03 23:50:36 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\SpyStudio
[2011/12/01 19:29:42 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/12/13 17:18:08 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Subversion
[2011/07/05 11:08:27 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\SumatraPDF
[2012/06/07 18:05:08 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\TeamViewer
[2012/07/29 14:00:48 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\TeraCopy
[2012/07/24 09:37:18 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\TS3Client
[2012/07/30 22:00:35 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\uTorrent
[2012/02/25 18:54:20 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\Wireshark
[2010/12/27 14:41:30 | 000,000,000 | ---D | M] -- C:\Users\Glen\AppData\Roaming\X-Chat 2
[2012/07/30 17:50:13 | 000,032,558 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 1283 bytes -> C:\Users\Glen\AppData\Local\OV83tPpmIzoIa:Kt4K1hRGbwtriOYAADw
@Alternate Data Stream - 1262 bytes -> C:\Users\Glen\AppData\Local\Temp:ukeFErMOdkH9eij4t72WHGfdZ
@Alternate Data Stream - 1136 bytes -> C:\Users\Glen\AppData\Local\Temp:hhVURVFe6k4oXYI55ylONxKrj8P
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~