OTL logfile created on: 11/25/2012 9:29:24 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Randall Bailey\Downloads
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.75 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 55.28% Memory free
5.71 Gb Paging File | 4.12 Gb Available in Paging File | 72.04% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 138.71 Gb Total Space | 53.57 Gb Free Space | 38.62% Space Free | Partition Type: NTFS
Drive D: | 10.33 Gb Total Space | 1.22 Gb Free Space | 11.79% Space Free | Partition Type: NTFS
Drive G: | 93.16 Gb Total Space | 57.14 Gb Free Space | 61.34% Space Free | Partition Type: NTFS
Computer Name: BARDICK-PC | User Name: Randall Bailey | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
[color=#E56717]========== Processes (SafeList) ==========[/color]
PRC - [2012/11/25 09:02:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Randall Bailey\Downloads\OTL.exe
PRC - [2012/11/23 13:59:36 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\Macromed\Flash\FlashUtil32_11_5_502_110_ActiveX.exe
PRC - [2012/10/02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/09/12 12:21:04 | 001,278,648 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee.com\Agent\mcagent.exe
PRC - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
PRC - [2012/08/31 13:00:52 | 000,078,704 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\Core\mchost.exe
PRC - [2012/08/13 10:57:02 | 010,376,704 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2012/08/13 10:57:02 | 010,368,512 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 15:09:30 | 000,166,320 | ---- | M] (McAfee, Inc.) -- C:\Windows\System32\mfevtps.exe
PRC - [2012/07/17 15:05:48 | 000,168,368 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mfefire.exe
PRC - [2012/07/17 15:03:46 | 000,200,816 | ---- | M] (McAfee, Inc.) -- C:\Program Files\Common Files\Mcafee\SystemCore\mcshield.exe
PRC - [2012/05/15 03:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/05/15 02:28:16 | 001,820,480 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2012/05/15 02:27:34 | 000,857,920 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2011/12/05 20:41:32 | 004,426,384 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
PRC - [2011/12/05 20:41:32 | 001,059,472 | R--- | M] (Carbonite, Inc.) -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe
PRC - [2011/11/02 02:00:44 | 000,090,448 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
PRC - [2010/02/04 01:28:02 | 000,025,256 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe
PRC - [2010/02/04 01:27:55 | 000,672,424 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
PRC - [2009/04/10 23:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/10/06 09:54:52 | 000,365,952 | ---- | M] () -- C:\Program Files\SMINST\BLService.exe
PRC - [2008/02/27 17:53:25 | 000,594,600 | ---- | M] ( ) -- C:\Windows\System32\lxdxcoms.exe
[color=#E56717]========== Modules (No Company Name) ==========[/color]
MOD - [2012/11/16 09:33:48 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7f15d0cb7e4f87f86e425d5ffe7e8280\System.Configuration.ni.dll
MOD - [2012/11/16 09:31:15 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\741164a3e36f879b9f9e3ff176465127\System.Xml.ni.dll
MOD - [2012/11/16 09:26:12 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\22e554f2c4da53c07e4815a24e2d50e2\System.Windows.Forms.ni.dll
MOD - [2012/11/16 09:25:33 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2c6cd37f29fc76d6c2ed6bbed202d82c\System.Drawing.ni.dll
MOD - [2012/11/16 09:23:21 | 007,976,960 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b2052acbbbba4f98585196872195e009\System.ni.dll
MOD - [2012/11/16 09:20:45 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7ad9c44df3b85848590e63f13fc59804\mscorlib.ni.dll
MOD - [2012/08/10 16:51:32 | 000,985,088 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2010/02/04 01:28:02 | 000,025,256 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmsdmon.exe
MOD - [2010/02/04 01:27:55 | 000,672,424 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe
MOD - [2010/02/04 01:05:09 | 000,081,920 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxcaps.dll
MOD - [2010/02/04 01:04:53 | 000,380,928 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxscw.dll
MOD - [2010/02/04 01:04:52 | 000,782,336 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxdrs.dll
MOD - [2010/02/04 00:52:39 | 000,589,824 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxdatr.dll
MOD - [2010/02/04 00:52:33 | 000,069,632 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\lxdxcnv4.dll
MOD - [2010/02/02 03:30:16 | 000,036,864 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.core.dll
MOD - [2010/02/02 03:30:16 | 000,028,672 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\app4r.monitor.common.dll
MOD - [2010/02/02 03:29:04 | 000,061,440 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.dll
MOD - [2007/11/22 03:55:48 | 000,011,776 | ---- | M] () -- C:\Program Files\Lexmark 3600-4600 Series\app4r.devmons.mcmdevmon.autoplayutil.dll
[color=#E56717]========== Services (SafeList) ==========[/color]
SRV - [2012/10/24 10:50:38 | 000,115,168 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/10/19 16:14:08 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/10/02 12:13:44 | 003,064,000 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2012/09/10 17:44:06 | 000,279,048 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\McAfee\VirusScan\mcods.exe -- (McODS)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV - [2012/08/31 13:20:06 | 000,167,784 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV - [2012/07/27 13:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/17 15:09:30 | 000,166,320 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\System32\mfevtps.exe -- (mfevtp)
SRV - [2012/07/17 15:05:48 | 000,168,368 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV - [2012/07/17 15:03:46 | 000,200,816 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV - [2012/05/15 03:26:00 | 001,262,400 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2011/12/05 20:41:32 | 004,426,384 | R--- | M] (Carbonite, Inc. (www.carbonite.com)) [Auto | Running] -- C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe -- (CarboniteService)
SRV - [2011/08/25 17:53:00 | 000,013,672 | ---- | M] (Intuit Inc.) [Auto | Running] -- C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe -- (IntuitUpdateServiceV4)
SRV - [2008/11/09 13:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/06 09:54:52 | 000,365,952 | ---- | M] () [Auto | Running] -- C:\Program Files\SMINST\BLService.exe -- (Recovery Service for Windows)
SRV - [2008/02/27 17:53:25 | 000,594,600 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxdxcoms.exe -- (lxdx_device)
SRV - [2008/01/20 19:33:00 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (mfeavfk01)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - [2012/07/17 15:12:34 | 000,060,480 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\cfwids.sys -- (cfwids)
DRV - [2012/07/17 15:09:42 | 000,206,784 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\mfewfpk.sys -- (mfewfpk)
DRV - [2012/07/17 15:08:10 | 000,092,192 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mferkdet.sys -- (mferkdet)
DRV - [2012/07/17 15:07:00 | 000,554,048 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\mfehidk.sys -- (mfehidk)
DRV - [2012/07/17 15:05:58 | 000,360,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfefirek.sys -- (mfefirek)
DRV - [2012/07/17 15:05:38 | 000,061,912 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfebopk.sys -- (mfebopk)
DRV - [2012/07/17 15:05:18 | 000,230,224 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeavfk.sys -- (mfeavfk)
DRV - [2012/07/17 15:04:46 | 000,127,992 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mfeapfk.sys -- (mfeapfk)
DRV - [2012/05/15 03:26:00 | 011,354,944 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2012/04/20 16:40:44 | 000,146,872 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HipShieldK.sys -- (HipShieldK)
DRV - [2012/04/18 10:08:04 | 000,148,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvhda32v.sys -- (NVHDA)
DRV - [2011/02/14 02:42:36 | 000,020,864 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbdiag.sys -- (UsbDiag)
DRV - [2011/02/14 02:42:34 | 000,025,216 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbmodem.sys -- (USBModem)
DRV - [2011/02/14 02:42:32 | 000,013,056 | ---- | M] (LG Electronics Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\lgusbbus.sys -- (usbbus)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVNET)
DRV - [2010/08/12 12:07:50 | 000,292,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nvmfdx32.sys -- (NVENETFD)
DRV - [2010/03/12 18:22:18 | 000,081,920 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2008/10/03 03:39:28 | 000,222,208 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2008/04/27 11:07:44 | 000,909,824 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\athr.sys -- (athr)
DRV - [2008/04/24 15:51:46 | 000,014,848 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvsmu.sys -- (nvsmu)
DRV - [2008/01/20 19:32:45 | 002,225,664 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NETw3v32.sys -- (NETw3v32)
DRV - [2007/10/17 16:36:54 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)
DRV - [2007/06/18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
[color=#E56717]========== Internet Explorer ==========[/color]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = »
ie.redirect.hp.com/svs/rdr?TYPE=···&pf=cnnbIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »
ie.redirect.hp.com/svs/rdr?TYPE=···&pf=cnnbIE - HKLM\..\SearchScopes,DefaultScope = {36190541-0C04-4C0F-9F78-A70761A42B1B}
IE - HKLM\..\SearchScopes\{36190541-0C04-4C0F-9F78-A70761A42B1B}: "URL" = »
search.live.com/results.aspx?q={···M=HPNTDFIE - HKLM\..\SearchScopes\{44f44034-6036-4f06-9336-74ec4620edab}: "URL" = »
search.mywebsearch.com/mywebsear···chTerms}IE - HKLM\..\SearchScopes\{F71A5F20-2EEC-41AE-BE76-5CABF69A135E}: "URL" = »
www.ask.com/web?q={searchTerms}&···&o=uscqlIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = »
ie.redirect.hp.com/svs/rdr?TYPE=···&pf=cnnbIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = »
www.sparkpeople.com/myspark [Binary data over 200 bytes]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = »
www.myfoxphoenix.com/category/230135/newsIE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {DECA3892-BA8F-44b8-A993-A466AD694AE4}
IE - HKCU\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" = »
search.yahoo.com/search?p={searchTerms}IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[color=#E56717]========== FireFox ==========[/color]
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..extensions.enabledAddons: {6B6B6A0D-5922-4B4F-89BE-39E9799AE387}:6.3
FF - prefs.js..extensions.enabledAddons: {D19CA586-DD6C-4a0a-96F8-14644F340D60}:14.4.1
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.9.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.9.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~1\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MVT: C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nds.com/PCShowPlugin: C:\Users\Randall Bailey\AppData\Local\DIRECTV Player\npPCShowPlugin.dll (NDS)
FF - HKCU\Software\MozillaPlugins\@nds.com/PlayerPlugin: C:\Users\Randall Bailey\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Randall Bailey\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Randall Bailey\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Randall Bailey\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Randall Bailey\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Randall Bailey\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\NDS.com/PlayerPlugin: C:\Users\Randall Bailey\AppData\Local\DIRECTV Player\npPlayerPlugin.dll (NDS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files\McAfee\SiteAdvisor [2012/11/11 20:43:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files\Common Files\McAfee\SystemCore [2012/11/25 04:14:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/11/12 16:57:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 16.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/11/11 20:43:39 | 000,000,000 | ---D | M]
[2011/12/18 09:23:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Randall Bailey\AppData\Roaming\Mozilla\Extensions
[2012/11/21 12:59:13 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Randall Bailey\AppData\Roaming\Mozilla\Firefox\Profiles\ylg7woa7.default\extensions
[2012/11/12 16:09:38 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Randall Bailey\AppData\Roaming\Mozilla\Firefox\Profiles\ylg7woa7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/11/11 03:49:11 | 000,000,000 | ---D | M] (UPnPDescriptionDocument Class extension for Firefox) -- C:\Users\Randall Bailey\AppData\Roaming\Mozilla\Firefox\Profiles\ylg7woa7.default\extensions\{6B6B6A0D-5922-4B4F-89BE-39E9799AE387}
[2012/11/12 16:57:15 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/11/11 20:43:39 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/11/25 04:14:30 | 000,000,000 | ---D | M] (McAfee ScriptScan for Firefox) -- C:\PROGRAM FILES\COMMON FILES\MCAFEE\SYSTEMCORE
[2012/10/24 10:50:58 | 000,261,600 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/04/14 14:01:38 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files\mozilla firefox\components\Scriptff.dll
[2012/10/24 10:50:17 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/10/24 10:50:17 | 000,002,058 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[color=#E56717]========== Chrome ==========[/color]
CHR - homepage: »
www.google.com/CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: »
www.google.com/CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\22.0.1229.95\pdf.dll
CHR - plugin: Skype Click to Call (Enabled) = C:\Users\Randall Bailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\npSkypeChromePlugin.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Randall Bailey\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Randall Bailey\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 7 U9 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.90.5 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: McAfee SiteAdvisor (Enabled) = C:\Program Files\McAfee\SiteAdvisor\npmcffplg32.dll
CHR - plugin: McAfee Virtual Technician (Enabled) = C:\Program Files\McAfee\Supportability\MVT\npmvtplugin.dll
CHR - plugin: BlackBerry AppWorld (Enabled) = C:\Program Files\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: NDS PCShow Plugin (Enabled) = C:\Users\Randall Bailey\AppData\Local\DIRECTV Player\npPCShowPlugin.dll
CHR - plugin: PCShow Player Plugin (Enabled) = C:\Users\Randall Bailey\AppData\Local\DIRECTV Player\npPlayerPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Randall Bailey\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: BrowserPlus (from Yahoo!) v2.9.8 (Enabled) = C:\Users\Randall Bailey\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~1\mcafee\msc\npmcsn~1.dll
CHR - Extension: YouTube = C:\Users\Randall Bailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Randall Bailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Skype Click to Call = C:\Users\Randall Bailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.3.0.11079_0\
CHR - Extension: Gmail = C:\Users\Randall Bailey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2006/09/18 14:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\Mcafee\SystemCore\ScriptSn.20120624200152.dll (McAfee, Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (DCA BHO) - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Upromise\dca-bho.dll (Compete, Inc.)
O2 - BHO: (WOT Helper) - {C920E44A-7F78-4E64-BDD7-A57026E7FEB7} - C:\Program Files\WOT\WOT.dll ()
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Upromise TurboSaver) - {EDC0F17F-F4B7-47e4-B73E-887FAEB376FA} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (WOT) - {71576546-354D-41c9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Upromise TurboSaver) - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (WOT) - {71576546-354D-41C9-AAE8-31F2EC22BF0D} - C:\Program Files\WOT\WOT.dll ()
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [lxdxamon] C:\Program Files\Lexmark 3600-4600 Series\lxdxamon.exe ()
O4 - HKLM..\Run: [lxdxmon.exe] C:\Program Files\Lexmark 3600-4600 Series\lxdxmon.exe ()
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Randall Bailey\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - Startup: C:\Users\Randall Bailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 File not found
O9 - Extra Button: Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra 'Tools' menuitem : Upromise TurboSaver - {06E58E5E-F8CB-4049-991E-A41C03BD419E} - C:\Program Files\Upromise\upromisetoolbar.dll (Upromise, Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: directv.com ([www] https in Trusted sites)
O15 - HKCU\..Trusted Domains: fax.com ([secure] https in Trusted sites)
O15 - HKCU\..Trusted Domains: intuit.com ([ttlc] https in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O15 - HKCU\..Trusted Domains: srpnet.com ([myaccount] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{89F10C57-CF82-47A4-A2B5-684C2EA32BCA}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D892DBAB-43CA-4A32-AE2B-9845BE228544}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wot {C2A44D6B-CB9F-4663-88A6-DF2F26E4D952} - C:\Program Files\WOT\WOT.dll ()
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Randall Bailey\Pictures\Colorado\IMGA0390.JPG
O24 - Desktop BackupWallPaper: C:\Users\Randall Bailey\Pictures\Colorado\IMGA0390.JPG
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 14:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{735d1864-5bd5-11de-be58-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{735d1864-5bd5-11de-be58-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.EXE
O33 - MountPoints2\{86929e47-1754-11e1-89e4-001f167bac78}\Shell - "" = AutoRun
O33 - MountPoints2\{86929e47-1754-11e1-89e4-001f167bac78}\Shell\AutoRun\command - "" = G:\TAOPhotoTransfer.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/11/25 04:15:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/11/25 03:21:32 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\Randall Bailey\Desktop\TFC.exe
[2012/11/24 03:36:28 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{68CE577F-0842-4F83-97C1-89A87AAD2A34}
[2012/11/23 13:59:37 | 000,697,272 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/11/23 13:59:37 | 000,073,656 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/11/23 09:35:38 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Roaming\Malwarebytes
[2012/11/23 09:35:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/11/23 09:35:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/11/23 09:35:04 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/11/23 09:35:04 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/11/23 09:19:23 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/11/23 09:12:24 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2012/11/22 20:20:42 | 000,000,000 | ---D | C] -- C:\Program Files\SAMSUNG
[2012/11/22 20:19:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Samsung
[2012/11/22 19:47:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/11/22 09:08:16 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{40BF40AC-D74E-453D-A5CE-912615748D45}
[2012/11/21 18:22:41 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{84909EA9-C209-401D-9EA3-F32BB22FCF80}
[2012/11/20 05:16:18 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/11/19 19:02:52 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{0329BE1F-163A-4DDB-8687-9D6648F207D4}
[2012/11/18 18:25:56 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{D63123B9-44B0-4A43-A961-E36914AB257B}
[2012/11/18 06:25:29 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{F68B4FA1-2EB4-4AF6-94F6-1157480523E7}
[2012/11/17 13:09:48 | 000,821,736 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/11/17 13:09:48 | 000,246,760 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/11/17 13:09:18 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/11/17 13:09:18 | 000,174,056 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/11/17 13:09:18 | 000,093,672 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/11/17 09:09:58 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\Seven Zip
[2012/11/17 06:52:01 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Roaming\McAfee
[2012/11/16 04:40:45 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/11/16 04:40:42 | 000,607,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012/11/16 04:40:42 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/11/16 04:40:42 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/11/16 04:40:42 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/11/16 04:40:40 | 001,800,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/11/16 04:40:40 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/11/16 04:40:38 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/11/15 12:26:12 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\synceng.dll
[2012/11/15 12:25:18 | 002,047,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/11/11 03:53:04 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\Macromedia
[2012/11/11 03:50:39 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\Mozilla Firefox
[2012/11/10 05:38:53 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{B0BDCDD7-8B27-4255-86F0-7BDD58CBBFA6}
[2012/11/09 03:28:54 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{AC5A06D3-004E-4C7A-983F-46E0CFDFA13A}
[2012/11/08 17:37:55 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\Spotify
[2012/11/08 17:36:46 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Roaming\Spotify
[2012/11/08 03:36:39 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Roaming\WildTangent
[2012/11/08 03:36:00 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\BVRP Software
[2012/11/05 19:24:30 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2012/11/05 19:24:24 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Maintenance Service
[2012/11/05 17:08:24 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{47F513B7-0FAF-417B-A86F-BCAA38EB2494}
[2012/11/05 05:08:12 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{DDA3F7A5-6BB8-422A-B7DA-58BB3DF7B044}
[2012/11/04 17:08:00 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{38DD0FC4-EF83-4AED-B863-87F3EAED9F4A}
[2012/11/04 08:21:03 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\ABBYY
[2012/11/04 08:19:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ABBYY FineReader 6.0 Sprint
[2012/11/04 08:18:24 | 000,000,000 | ---D | C] -- C:\Program Files\Abbyy FineReader 6.0 Sprint
[2012/11/04 05:07:47 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{1C01B6E9-621B-4156-BFBD-686A3F2A956C}
[2012/11/03 17:07:34 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{CBB3D626-6D39-46BE-9BE3-9342CB4B3F0E}
[2012/11/03 05:07:22 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{3DCAB480-AAC2-4AC1-A888-C0135BD71E71}
[2012/11/02 17:06:54 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{DEA8A3F8-24AB-4D7C-BECB-8823708C7500}
[2012/11/02 03:57:20 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{F4AAC95F-73EA-4816-A459-AFC8F8F15604}
[2012/10/31 16:10:25 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{EBFDE835-0EB2-4846-B939-626293F5FD9B}
[2012/10/30 16:16:13 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{BA62C8EF-75A7-4BD0-AD5D-A5D2514BDF0D}
[2012/10/30 04:15:48 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{75C69AB7-6C69-4859-AC13-623448543046}
[2012/10/29 16:15:28 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{4855CBF8-FA22-449E-982E-1185A20715A4}
[2012/10/28 11:16:53 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Roaming\Skype
[2012/10/28 11:16:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/10/28 11:16:17 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2012/10/28 11:16:16 | 000,000,000 | R--D | C] -- C:\Program Files\Skype
[2012/10/28 11:16:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Skype
[2012/10/28 04:46:44 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{B86086CB-FD82-48AC-A208-4E33418CFB1C}
[2012/10/27 16:46:28 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{800D4EE6-47C6-4DF3-98EC-611B099B9AB7}
[2012/10/27 04:46:15 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{2ADD4C5B-9475-48D4-B8BB-ADEB97479A04}
[2012/10/26 16:46:02 | 000,000,000 | ---D | C] -- C:\Users\Randall Bailey\AppData\Local\{8FCC8198-6F6F-4E83-8D17-11E7377BDCD2}
[2011/11/16 07:58:28 | 000,940,544 | ---- | C] (Apache Software Foundation) -- C:\Users\Randall Bailey\AppData\Local\log4cxx.dll
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/11/25 09:32:05 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/25 09:30:44 | 000,000,944 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002UA.job
[2012/11/25 09:02:28 | 000,000,514 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.ics
[2012/11/25 08:49:06 | 000,000,964 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002UA.job
[2012/11/25 08:11:45 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/25 08:11:45 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/25 04:10:31 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/25 04:09:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/25 03:22:07 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\Randall Bailey\Desktop\TFC.exe
[2012/11/25 03:12:04 | 000,000,567 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\MBRCheck - Shortcut.lnk
[2012/11/24 16:30:19 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002Core.job
[2012/11/24 14:49:04 | 000,000,942 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002Core.job
[2012/11/24 06:54:23 | 000,640,658 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/11/24 06:54:23 | 000,118,878 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/11/23 13:59:37 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/11/23 13:59:37 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/11/23 09:35:17 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/23 09:32:44 | 000,000,577 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\tdsskiller - Shortcut.lnk
[2012/11/23 00:34:04 | 000,001,971 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/23 00:34:04 | 000,001,955 | ---- | M] () -- C:\Users\Randall Bailey\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/22 15:25:52 | 289,624,380 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/11/20 19:52:07 | 000,577,646 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\shawna license.pdf
[2012/11/20 19:42:01 | 001,697,444 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\megan wagy.pdf
[2012/11/18 09:19:21 | 000,001,028 | ---- | M] () -- C:\Users\Randall Bailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2012/11/17 13:08:18 | 000,093,672 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\WindowsAccessBridge.dll
[2012/11/17 13:08:11 | 000,246,760 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/11/17 13:08:11 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/11/17 13:08:11 | 000,174,056 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/11/17 13:08:10 | 000,821,736 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/11/17 13:08:09 | 000,746,984 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012/11/17 07:46:23 | 000,011,968 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\MVTHealthCheck_Deviation.html
[2012/11/17 06:52:00 | 000,001,929 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Virtual Technician.lnk
[2012/11/16 09:15:09 | 000,346,800 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/11/12 16:57:25 | 000,000,870 | ---- | M] () -- C:\Users\Randall Bailey\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/11/12 16:57:25 | 000,000,846 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/11/12 16:39:44 | 000,013,824 | ---- | M] () -- C:\Users\Randall Bailey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/10 17:04:27 | 000,000,680 | ---- | M] () -- C:\Users\Randall Bailey\AppData\Local\d3d9caps.dat
[2012/11/09 04:06:28 | 000,083,986 | ---- | M] () -- C:\Users\Randall Bailey\AppData\Local\{33090943-95A0-CABB-A565-2F2049631B24}.dat
[2012/11/05 19:31:03 | 001,192,082 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\11-5-2012 7;31;03 PM.PDF
[2012/11/05 19:26:44 | 001,147,321 | ---- | M] () -- C:\Users\Randall Bailey\Desktop\11-5-2012 7;26;44 PM.PDF
[2012/11/04 08:19:32 | 000,075,233 | ---- | M] () -- C:\Windows\System32\LexFiles.ulf
[2012/11/03 07:52:37 | 000,009,905 | ---- | M] () -- C:\Users\Randall Bailey\Documents\YARDSALE2.odg
[2012/11/03 07:39:06 | 000,013,523 | ---- | M] () -- C:\Users\Randall Bailey\Documents\YARDSALE.odg
[2012/10/28 11:16:17 | 000,001,878 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/10/27 16:05:08 | 000,224,565 | ---- | M] () -- C:\Users\Public\Documents\Jonathan's trip.xps
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/11/25 03:12:04 | 000,000,567 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\MBRCheck - Shortcut.lnk
[2012/11/23 09:35:17 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/23 09:32:44 | 000,000,577 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\tdsskiller - Shortcut.lnk
[2012/11/22 19:47:27 | 000,001,971 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/11/22 19:47:27 | 000,001,955 | ---- | C] () -- C:\Users\Randall Bailey\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/22 15:25:52 | 289,624,380 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/11/20 19:52:06 | 000,577,646 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\shawna license.pdf
[2012/11/20 19:41:59 | 001,697,444 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\megan wagy.pdf
[2012/11/18 09:19:21 | 000,001,028 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
[2012/11/17 07:46:23 | 000,011,968 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\MVTHealthCheck_Deviation.html
[2012/11/17 06:52:00 | 000,001,929 | ---- | C] () -- C:\Users\Public\Desktop\McAfee Virtual Technician.lnk
[2012/11/17 06:51:13 | 000,001,939 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Virtual Technician.lnk
[2012/11/09 04:06:28 | 000,083,986 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Local\{33090943-95A0-CABB-A565-2F2049631B24}.dat
[2012/11/05 19:31:07 | 001,192,082 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\11-5-2012 7;31;03 PM.PDF
[2012/11/05 19:27:08 | 001,147,321 | ---- | C] () -- C:\Users\Randall Bailey\Desktop\11-5-2012 7;26;44 PM.PDF
[2012/11/04 08:18:09 | 000,000,044 | ---- | C] () -- C:\Windows\System32\lxdxrwrd.ini
[2012/11/03 07:52:36 | 000,009,905 | ---- | C] () -- C:\Users\Randall Bailey\Documents\YARDSALE2.odg
[2012/11/03 07:22:48 | 000,013,523 | ---- | C] () -- C:\Users\Randall Bailey\Documents\YARDSALE.odg
[2012/10/29 16:25:17 | 000,000,944 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002UA.job
[2012/10/29 16:25:14 | 000,000,892 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2363605596-395245341-3206715689-1002Core.job
[2012/10/28 11:16:17 | 000,001,878 | ---- | C] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/10/27 16:05:07 | 000,224,565 | ---- | C] () -- C:\Users\Public\Documents\Jonathan's trip.xps
[2012/03/31 09:30:38 | 000,001,571 | ---- | C] () -- C:\Windows\Faxcpp1.ini
[2012/03/31 09:30:38 | 000,000,422 | ---- | C] () -- C:\Windows\Faxcpp.ini
[2012/03/31 09:29:07 | 000,040,960 | ---- | C] () -- C:\Windows\System32\Twscan32.dll
[2012/03/31 09:29:04 | 000,090,112 | ---- | C] () -- C:\Windows\System32\Tga32.dll
[2012/03/31 09:29:03 | 000,241,664 | ---- | C] () -- C:\Windows\System32\Image32.dll
[2012/03/31 09:29:03 | 000,122,880 | ---- | C] () -- C:\Windows\System32\Png32.dll
[2012/03/31 09:29:03 | 000,081,920 | ---- | C] () -- C:\Windows\System32\Pcx32.dll
[2012/03/17 07:19:30 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/03/17 07:19:30 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/02/08 04:17:01 | 000,052,167 | ---- | C] () -- C:\Users\Randall Bailey\Application for Copy of Birth Record.pdf
[2012/01/28 10:22:08 | 000,128,326 | ---- | C] () -- C:\Users\Randall Bailey\ACE - 2.pdf
[2012/01/01 07:14:56 | 000,000,120 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2011/12/29 12:11:03 | 000,000,944 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Roaming\wklnhst.dat
[2011/11/19 04:54:04 | 000,000,451 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
[2011/11/16 07:58:35 | 000,094,208 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Local\common_functions.dll
[2011/10/17 19:17:07 | 000,053,248 | ---- | C] () -- C:\Windows\System32\CommonDL.dll
[2011/10/17 19:17:06 | 000,002,413 | ---- | C] () -- C:\Windows\System32\lgAxconfig.ini
[2011/09/02 04:08:50 | 000,102,400 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Local\ie_runner_app.exe
[2011/08/22 06:24:38 | 000,000,680 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Local\d3d9caps.dat
[2011/07/18 01:40:10 | 000,030,547 | ---- | C] () -- C:\Users\Randall Bailey\UC232A_winxp.zip
[2011/07/17 07:27:39 | 000,013,824 | ---- | C] () -- C:\Users\Randall Bailey\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/07/17 06:43:26 | 000,438,272 | ---- | C] ( ) -- C:\Windows\System32\LXDXhcp.dll
[2011/07/17 06:43:26 | 000,348,160 | ---- | C] () -- C:\Windows\System32\LXDXinst.dll
[2011/07/16 10:25:36 | 000,053,248 | ---- | C] ( ) -- C:\Windows\System32\lxdxprox.dll
[2011/07/16 10:25:32 | 001,105,920 | ---- | C] ( ) -- C:\Windows\System32\lxdxserv.dll
[2011/07/16 10:25:31 | 000,647,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxpmui.dll
[2011/07/16 10:25:30 | 000,594,600 | ---- | C] ( ) -- C:\Windows\System32\lxdxcoms.exe
[2011/07/16 10:25:30 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\lxdxlmpm.dll
[2011/07/16 10:25:28 | 000,376,832 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomm.dll
[2011/07/16 10:25:23 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxdxinpa.dll
[2011/07/16 10:25:22 | 000,851,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxcomc.dll
[2011/07/16 10:25:22 | 000,339,968 | ---- | C] ( ) -- C:\Windows\System32\lxdxiesc.dll
[2011/07/16 10:25:21 | 000,843,776 | ---- | C] ( ) -- C:\Windows\System32\lxdxusb1.dll
[2011/07/16 10:25:21 | 000,663,552 | ---- | C] ( ) -- C:\Windows\System32\lxdxhbn3.dll
[2011/07/16 10:25:20 | 000,208,896 | ---- | C] () -- C:\Windows\System32\lxdxgrd.dll
[2011/07/16 10:25:19 | 000,365,224 | ---- | C] ( ) -- C:\Windows\System32\lxdxcfg.exe
[2011/07/16 10:25:19 | 000,320,168 | ---- | C] ( ) -- C:\Windows\System32\lxdxih.exe
[2011/07/16 10:25:19 | 000,040,960 | ---- | C] () -- C:\Windows\System32\lxdxvs.dll
[2011/07/15 17:45:03 | 000,782,336 | ---- | C] () -- C:\Windows\System32\lxdxdrs.dll
[2011/07/15 17:45:03 | 000,081,920 | ---- | C] () -- C:\Windows\System32\lxdxcaps.dll
[2011/07/15 17:45:03 | 000,069,632 | ---- | C] () -- C:\Windows\System32\lxdxcnv4.dll
[2011/05/08 06:50:47 | 000,050,493 | ---- | C] () -- C:\Users\Randall Bailey\Mother's Day card.jpg
[2011/05/01 16:00:35 | 005,454,111 | ---- | C] () -- C:\Users\Randall Bailey\owp04282011.mp3
[2011/03/06 07:38:55 | 000,559,824 | ---- | C] () -- C:\Users\Randall Bailey\Ford AX4S Transmission Problems.mht
[2010/08/28 15:02:57 | 000,669,199 | ---- | C] () -- C:\Users\Randall Bailey\fairfield.JPG
[2010/06/24 03:19:35 | 000,131,088 | ---- | C] () -- C:\Users\Randall Bailey\ttaxol2008.pdf
[2010/04/17 06:22:42 | 000,046,280 | ---- | C] () -- C:\Users\Randall Bailey\CHSdrama.jpg
[2010/04/11 09:19:20 | 000,156,812 | ---- | C] () -- C:\Users\Randall Bailey\AZgunlaw2009.pdf
[2010/04/03 07:16:57 | 000,331,340 | ---- | C] () -- C:\Users\Randall Bailey\ladmotie.jpg.jpg
[2010/02/22 14:54:35 | 000,307,535 | ---- | C] () -- C:\Users\Randall Bailey\goals and barriers.pdf
[2009/12/12 10:26:00 | 000,223,045 | ---- | C] () -- C:\Users\Randall Bailey\pi_abilify.pdf
[2009/11/01 13:26:08 | 001,360,858 | ---- | C] () -- C:\Users\Randall Bailey\Carbonite-3.230.zip
[2009/10/31 11:13:48 | 000,605,922 | ---- | C] () -- C:\Users\Randall Bailey\S9_UG.pdf
[2009/08/22 09:34:12 | 000,052,351 | ---- | C] () -- C:\Users\Randall Bailey\aerize.optimizer.manual.1.0.0.pdf
[2009/08/06 15:00:51 | 001,284,803 | ---- | C] () -- C:\Users\Randall Bailey\Car agreement.JPG
[2009/06/22 03:29:23 | 000,081,622 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/06/22 03:15:09 | 000,081,622 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/06/17 23:50:01 | 000,000,246 | ---- | C] () -- C:\ProgramData\hpqp.ini
[2009/05/15 10:59:17 | 005,697,705 | ---- | C] () -- C:\Users\Randall Bailey\2009_relocation.pdf
[2009/04/13 17:14:32 | 000,131,012 | ---- | C] () -- C:\Users\Randall Bailey\2008tax.pdf
[2009/03/24 07:52:50 | 000,084,693 | ---- | C] () -- C:\Users\Randall Bailey\autoinsurance.pdf
[2009/03/10 04:21:33 | 000,180,224 | ---- | C] () -- C:\Users\Randall Bailey\2009-03-07_rev_1252_compiled.zip
[2009/03/04 12:24:17 | 000,000,650 | ---- | C] () -- C:\Users\Randall Bailey\SHARED LEADERSHIP MARCH 4TH.rtf
[2009/01/24 05:50:25 | 002,939,836 | ---- | C] () -- C:\Users\Randall Bailey\Driver_install_instructions_1.pdf
[2009/01/01 13:43:37 | 000,012,657 | ---- | C] () -- C:\Users\Randall Bailey\Windowscontacts.csv
[2009/01/01 12:41:53 | 000,016,351 | ---- | C] () -- C:\Users\Randall Bailey\WLContacts.csv
[2008/12/22 18:36:50 | 000,017,819 | ---- | C] () -- C:\Users\Randall Bailey\address.csv
[2008/12/22 16:07:27 | 000,007,283 | ---- | C] () -- C:\Users\Randall Bailey\Yahoo.csv
[2008/12/19 15:39:34 | 006,737,032 | ---- | C] () -- C:\Users\Randall Bailey\transcript 12-19-2008p2.pdf
[2008/12/19 15:37:41 | 006,737,032 | ---- | C] () -- C:\Users\Randall Bailey\transcript 12-19-2008.pdf
[2008/12/16 10:37:10 | 001,031,195 | ---- | C] () -- C:\Users\Randall Bailey\U. S. Senate Report.pdf
[2008/11/26 19:40:25 | 003,622,912 | ---- | C] () -- C:\Users\Randall Bailey\UNIQUE Fotos.pps
[2008/10/04 07:19:24 | 000,033,286 | ---- | C] () -- C:\Users\Randall Bailey\Emergency Economic Stabilization Act of 2008.pdf
[2008/09/25 17:29:24 | 000,019,651 | ---- | C] () -- C:\Users\Randall Bailey\phone.csv
[2008/09/21 16:28:53 | 000,080,021 | ---- | C] () -- C:\Users\Randall Bailey\psychrometric chart.gif
[2008/08/28 15:13:04 | 000,102,994 | ---- | C] () -- C:\Users\Randall Bailey\sleep_diary.pdf
[2008/08/24 19:42:08 | 001,354,194 | ---- | C] () -- C:\Users\Randall Bailey\myCIGNAGuide.pdf
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2006/11/02 05:51:16 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 10:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 23:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 23:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[color=#E56717]========== LOP Check ==========[/color]
[2011/09/11 05:30:47 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Blackberry Desktop
[2012/10/14 07:30:31 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/04/22 06:22:19 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Funambol
[2011/07/22 03:47:41 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Lexmark Productivity Studio
[2011/08/04 12:05:49 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\OpenOffice.org
[2011/07/30 08:59:18 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Research In Motion
[2012/11/08 19:57:56 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Spotify
[2011/12/29 12:11:07 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Template
[2011/11/16 07:58:12 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\upromise
[2012/11/08 03:36:39 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\WildTangent
[2011/08/29 17:06:38 | 000,000,000 | ---D | M] -- C:\Users\Randall Bailey\AppData\Roaming\Windows Live Writer
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\Z06197VS AZ.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\taylor.wma:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\TaxReturn2008.pdf:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\RSI.PDF:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\NewTake1.wav:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\InfoTool.txt:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0311.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0310.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0309.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0308.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0307.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0306.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0305.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0304.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0303.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0302.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0301.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0300.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0299.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0298.JPG:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\Randall Bailey\Documents\IMGA0297.JPG:Roxio EMC Stream
@Alternate Data Stream - 1045 bytes -> C:\Users\Randall Bailey\Documents\Walmart_com Product Care Plan Confirmation.eml:OECustomProperty
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~