okay i did the scan this is the otl txt.
OTL logfile created on: 10/15/2009 4:58:59 PM - Run 1
OTL by OldTimer - Version 3.0.21.0 Folder = C:\Users\Richard\Downloads
64bit-Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18828)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.42 Gb Available Physical Memory | 60.52% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 149.05 Gb Total Space | 61.18 Gb Free Space | 41.05% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RICHARD-PC
Current User Name: Richard
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2009/10/15 16:56:15 | 00,521,216 | ---- | M] (OldTimer Tools) -- C:\Users\Richard\Downloads\OTL.exe
PRC - [2009/09/21 16:36:12 | 00,305,440 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\iTunes\iTunesHelper.exe
PRC - [2009/09/16 09:10:12 | 03,634,024 | ---- | M] (AOL LLC) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2009/09/12 13:32:35 | 00,908,280 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2009/09/11 07:24:32 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2009/08/01 17:14:12 | 00,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\Java\jre6\bin\jusched.exe
PRC - [2009/07/14 12:28:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/07/10 13:59:22 | 00,195,072 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2009/07/06 15:04:00 | 01,611,152 | ---- | M] (Philips) -- C:\Philips\GoGear VIBE Device Manager\GoGear_Vibe_DeviceManager.exe
PRC - [2009/02/06 17:02:14 | 00,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2009/09/11 07:33:20 | 00,023,296 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv [On_Demand | Stopped])
SRV:
64bit: - [2009/09/11 07:24:32 | 00,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn [Auto | Running])
SRV:
64bit: - [2009/04/11 00:11:28 | 00,252,928 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\umrdp.dll -- (UmRdpService [On_Demand | Stopped])
SRV:
64bit: - [2009/04/11 00:11:16 | 00,604,672 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cscsvc.dll -- (CscService [Auto | Running])
SRV:
64bit: - [2009/04/11 00:11:06 | 01,149,440 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wbengine.exe -- (wbengine [On_Demand | Stopped])
SRV:
64bit: - [2008/01/20 19:51:24 | 01,216,000 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Running])
SRV:
64bit: - [2008/01/20 19:50:23 | 00,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt [On_Demand | Stopped])
SRV:
64bit: - [2008/01/20 19:47:07 | 00,689,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\fxssvc.exe -- (Fax [On_Demand | Stopped])
SRV:
64bit: - [2008/01/20 19:46:39 | 00,383,544 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2009/10/13 14:43:16 | 00,316,664 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service [On_Demand | Stopped])
SRV - [2009/09/25 18:56:48 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe -- (gupdate1ca3e4ca093b9e8 [Auto | Stopped])
SRV - [2009/09/21 16:36:16 | 00,660,256 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\iPod\bin\iPodService.exe -- (iPod Service [On_Demand | Running])
SRV - [2009/08/28 19:42:54 | 00,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2009/07/14 12:28:00 | 00,239,648 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service [Auto | Running])
SRV - [2009/05/20 01:50:20 | 02,772,302 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\GameMon.des -- (npggsvc [On_Demand | Stopped])
SRV - [2009/04/10 23:28:24 | 00,592,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\netlogon.dll -- (Netlogon [On_Demand | Stopped])
SRV - [2009/03/29 21:42:16 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2009/03/29 21:39:56 | 00,089,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_64 [On_Demand | Stopped])
SRV - [2009/02/18 11:40:06 | 00,042,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2009/02/18 11:39:12 | 00,857,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/02/06 17:02:14 | 00,109,056 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/11/04 01:06:28 | 00,441,712 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2008/10/25 11:44:08 | 00,065,888 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe -- (Microsoft Office Groove Audit Service [On_Demand | Stopped])
SRV - [2008/01/20 19:50:39 | 00,344,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2008/01/20 19:50:39 | 00,153,600 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 08:03:44 | 00,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2006/11/02 06:34:14 | 00,000,000 | ---D | M] -- C:\Windows\SysWow64\Msdtc -- (MSDTC [Unknown | Stopped])
SRV - [2006/11/02 02:46:05 | 00,018,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\keyiso.dll -- (KeyIso [On_Demand | Running])
SRV - [2006/11/01 23:35:15 | 00,060,994 | ---- | M] () -- C:\Windows\SysWow64\Wbem\vds.mof -- (vds [On_Demand | Stopped])
SRV - [2006/11/01 23:35:15 | 00,055,846 | ---- | M] () -- C:\Windows\SysWow64\Wbem\vss.mof -- (VSS [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2009/09/11 07:27:10 | 00,044,944 | ---- | M] (ESET) -- C:\Windows\SysNative\DRIVERS\epfwwfp.sys -- (epfwwfp [Auto | Running])
DRV:
64bit: - [2009/09/11 07:27:04 | 00,168,544 | ---- | M] (ESET) -- C:\Windows\SysNative\DRIVERS\epfw.sys -- (epfw [Auto | Running])
DRV:
64bit: - [2009/09/11 07:23:52 | 00,136,584 | ---- | M] (ESET) -- C:\Windows\SysNative\DRIVERS\ehdrv.sys -- (ehdrv [System | Running])
DRV:
64bit: - [2009/09/11 07:17:20 | 00,144,824 | ---- | M] (ESET) -- C:\Windows\SysNative\DRIVERS\eamon.sys -- (eamon [Auto | Running])
DRV:
64bit: - [2009/06/19 09:10:40 | 00,033,608 | ---- | M] (ESET) -- C:\Windows\SysNative\DRIVERS\Epfwndis.sys -- (Epfwndis [On_Demand | Running])
DRV:
64bit: - [2009/05/18 14:17:08 | 00,034,152 | ---- | M] (GEAR Software Inc.) -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV:
64bit: - [2009/04/11 00:15:32 | 00,160,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DRIVERS\fvevol.sys -- (fvevol [Boot | Running])
DRV:
64bit: - [2009/04/10 22:39:36 | 00,098,944 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\usbaudio.sys -- (usbaudio [On_Demand | Stopped])
DRV:
64bit: - [2009/04/10 21:56:26 | 00,460,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\csc.sys -- (CSC [System | Running])
DRV:
64bit: - [2008/01/20 19:46:34 | 00,046,080 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb [On_Demand | Stopped])
DRV:
64bit: - [2007/06/25 05:37:14 | 00,108,032 | ---- | M] (Realtek Corporation ) -- C:\Windows\SysNative\DRIVERS\Rtlh64.sys -- (RTL8169 [On_Demand | Running])
DRV:
64bit: - [2007/05/03 08:11:46 | 00,244,736 | ---- | M] (Marvell Semiconductor, Inc) -- C:\Windows\SysNative\DRIVERS\MRVW13C.sys -- (MRV6X64P [On_Demand | Running])
DRV:
64bit: - [2006/11/01 22:28:10 | 00,273,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\HdAudio.sys -- (HdAudAddService [On_Demand | Stopped])
DRV - [2009/07/23 16:07:35 | 00,024,072 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\Windows\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2009/07/23 15:29:28 | 00,000,000 | ---D | M] -- C:\Windows\CSC -- (CSC [System | Running])
DRV - [2008/08/12 17:08:04 | 00,143,872 | ---- | M] () -- C:\Windows\SysWOW64\drivers\archlp.sys -- (archlp [System | Running])
DRV - [2006/09/18 14:36:40 | 00,003,066 | ---- | M] () -- C:\Windows\SysWow64\Wbem\tcpip.mof -- (Tcpip [System | Running])
DRV - [2006/09/18 14:35:23 | 00,001,088 | ---- | M] () -- C:\Windows\SysWow64\Wbem\mpsdrv.mof -- (mpsdrv [On_Demand | Running])
DRV - [2005/01/02 14:43:08 | 00,004,682 | ---- | M] (INCA Internet Co., Ltd.) -- C:\Windows\SysWow64\npptNT2.sys -- (NPPTNT2 [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 8F 52 A4 04 82 23 CA 01 [binary data]
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\Windows\SysWOW64\dvmurl.dll (DeviceVM Inc.)
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\S-1-5-21-2007572775-1956699559-2467264984-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\S-1-5-21-2007572775-1956699559-2467264984-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "swagbucks.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "
http://www.google.co...om/webhp?hl=en"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}:6.0.15
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.6
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: bloodfire@example.com:3.5
FF - prefs.js..extensions.enabledItems: {241aae70-0022-11de-87af-0800200c9a66}:3.5.2.08.11.09
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/07/23 18:01:17 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B728AB94-9BC7-49b7-B76A-422BB31B2FD0}: C:\Program Files (x86)\ArcSoft\Media Converter for Philips\Internet Video Downloader\Plugin_FireFox [2009/10/04 23:04:53 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2009/09/16 20:37:47 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2009/10/09 19:47:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
[2009/07/23 18:02:03 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Extensions
[2009/07/23 18:02:03 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/10/15 02:06:28 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions
[2009/07/23 18:03:00 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/24 15:44:18 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\{241aae70-0022-11de-87af-0800200c9a66}
[2009/07/23 18:03:01 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2009/08/12 20:52:03 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/08/01 17:17:32 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/07/23 23:42:11 | 00,000,000 | ---D | M] -- C:\Users\Richard\AppData\Roaming\mozilla\Firefox\Profiles\rqxpncr4.default\extensions\bloodfire@example.com
[2009/10/10 11:46:42 | 00,001,183 | ---- | M] () -- C:\Users\Richard\AppData\Roaming\Mozilla\FireFox\Profiles\rqxpncr4.default\searchplugins\swagbuckscom.xml
[2009/10/15 02:06:28 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions
[2009/09/12 13:32:37 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/08/01 17:14:38 | 00,000,000 | ---D | M] -- C:\Program Files (x86)\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
[2009/09/12 13:32:35 | 00,023,544 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2009/09/12 13:32:35 | 00,137,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2007/04/10 17:21:08 | 00,163,256 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll
[2009/08/01 17:14:12 | 00,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeploytk.dll
[2009/07/07 14:20:42 | 00,061,440 | ---- | M] (AOL LLC) -- C:\Program Files (x86)\mozilla firefox\plugins\npdnu.dll
[2009/07/07 14:20:42 | 00,065,536 | ---- | M] (AOL LLC) -- C:\Program Files (x86)\mozilla firefox\plugins\npdnupdater2.dll
[2009/09/12 13:32:36 | 00,065,016 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2006/10/26 20:12:16 | 00,016,192 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll
[2009/09/16 20:37:47 | 00,159,744 | ---- | M] (Apple Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll
[2007/04/16 10:07:12 | 00,180,293 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npViewpoint.dll
[2009/07/15 11:10:00 | 00,001,394 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom.xml
[2009/07/15 11:10:00 | 00,002,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2009/07/15 11:10:00 | 00,001,534 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2009/07/15 11:10:00 | 00,002,344 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay.xml
[2009/07/15 11:10:00 | 00,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2009/07/15 11:10:00 | 00,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2009/07/15 11:10:00 | 00,000,792 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (50 bytes) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IEPlugin Class) - {11222041-111B-46E3-BD29-EFB2449479B1} - C:\Program Files (x86)\ArcSoft\Media Converter for Philips\Internet Video Downloader\ArcURLRecord.dll (ArcSoft, Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O4:
64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [Skytel] C:\Windows\Skytel.exe (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [GrooveMonitor] C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe (Microsoft Corporation)
O4 - HKLM..\Run: [iTunesHelper] C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [QuickTime Task] C:\Program Files (x86)\QuickTime\QTTask.exe (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.DLL (Microsoft Corporation)
O4 - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL LLC)
O4 - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000..\Run: [Steam] c:\program files (x86)\steam\steam.exe (Valve Corporation)
O4 - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: ForceActiveDesktopOn = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2007572775-1956699559-2467264984-1000\..Trusted Domains: 25 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files (x86)\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18:
64bit: - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (MrvGINA.dll) - File not found
O22:
64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\SysWow64\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
64bit: O35 - comfile [open] -- "%1" %* File not found
64bit: O35 - exefile [open] -- "%1" %* File not found
O35 - comfile [open] -- "%1" %* File not found
O35 - exefile [open] -- "%1" %* File not found
========== Files/Folders - Created Within 30 Days ==========
[2009/09/23 06:37:06 | 00,000,000 | ---D | C] -- C:\ProgramData\{0DD0EEEE-2A7C-411C-9243-1AE62F445FC3}
[2009/09/27 10:17:15 | 00,000,000 | ---D | C] -- C:\ProgramData\AIM
[2009/09/16 20:37:14 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple
[2009/09/16 20:37:32 | 00,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2009/09/23 06:55:57 | 00,000,000 | -H-D | C] -- C:\ProgramData\ArcSoft
[2009/10/03 23:54:35 | 00,000,000 | ---D | C] -- C:\ProgramData\SiteAdvisor
[2009/10/05 20:22:17 | 00,000,000 | ---D | C] -- C:\ProgramData\Sony
[2009/10/01 00:37:10 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\.minecraft
[2009/09/16 20:39:12 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Apple Computer
[2009/09/23 06:56:07 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\ArcSoft
[2009/10/07 20:10:45 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Auslogics
[2009/10/09 16:26:19 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Download Manager
[2009/10/13 20:59:59 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\ESET
[2009/10/05 20:29:07 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Publish Providers
[2009/10/05 20:28:56 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Sony
[2009/10/04 10:28:44 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Roaming\Uniblue
[2009/09/27 10:17:15 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\AIM
[2009/09/16 20:37:15 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\Apple
[2009/09/16 20:39:12 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\Apple Computer
[2009/09/23 06:56:08 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\ArcSoft
[2009/10/13 20:17:05 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\ESET
[2009/09/25 18:56:48 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\Google
[2009/10/05 20:28:56 | 00,000,000 | ---D | C] -- C:\Users\Richard\AppData\Local\Sony
[2009/09/16 20:37:22 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2009/09/23 06:55:38 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ArcSoft
[2009/10/04 09:53:05 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Software Update Utility
[2009/10/04 09:53:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AIM
[2009/09/16 20:37:14 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2009/10/04 22:08:55 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ArcSoft
[2009/09/23 20:56:55 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2009/09/23 21:26:55 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\AVS4YOU
[2009/09/16 20:37:58 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2009/09/25 18:56:47 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\DivX
[2009/10/11 11:09:19 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2009/10/04 21:02:46 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\FrostWire
[2009/09/25 18:56:48 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Google
[2009/09/23 06:37:07 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\iPod
[2009/09/23 06:37:06 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2009/10/15 03:11:52 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
[2009/09/16 20:37:33 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2009/10/03 23:54:30 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\SiteAdvisor
[2009/10/05 20:22:08 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Sony
[2009/10/05 20:21:03 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Sony Setup
[2009/10/07 17:03:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2009/10/05 20:22:20 | 00,000,000 | ---D | C] -- C:\Program Files (x86)\Vstplugins
[2009/09/23 06:34:26 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/10/13 20:58:48 | 00,000,000 | ---D | C] -- C:\Program Files\ESET
[2009/09/23 06:37:06 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/10/04 11:09:16 | 00,000,000 | ---D | C] -- C:\Program Files\Recuva
[2009/10/15 14:51:09 | 00,000,000 | ---D | C] -- C:\b76cfdaca25c7e14f4313e1cf6046542
[2009/10/15 03:12:49 | 00,033,792 | ---- | C] (Panda Security, S.L.) -- C:\Windows\SysNative\drivers\pavboot64.sys
[2009/10/15 02:55:13 | 00,000,000 | ---D | C] -- C:\_OTS
[2009/10/11 11:11:38 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/10/05 20:28:56 | 00,000,000 | ---D | C] -- C:\Users\Richard\Documents\Vegas Movie Studio PE 9.0 Projects
[2009/10/04 22:08:55 | 00,393,216 | ---- | C] (Sample Corporation) -- C:\Windows\SysWow64\MSLUP60.dll
[2009/10/04 22:08:55 | 00,249,856 | ---- | C] (Sample Corporation) -- C:\Windows\SysWow64\MSLURT.dll
[2009/10/04 22:08:55 | 00,061,440 | ---- | C] (ArcSoft Inc.) -- C:\Windows\SysWow64\MMCEDT.exe
[2009/10/04 10:17:38 | 00,000,000 | ---D | C] -- C:\Users\Richard\Documents\MediaConverter
[2009/09/25 19:00:58 | 00,000,000 | ---D | C] -- C:\Users\Richard\Documents\Downloads
[2009/09/23 07:37:29 | 00,000,000 | ---D | C] -- C:\Windows\Replay Converter 3
[2009/09/23 07:03:08 | 00,000,000 | ---D | C] -- C:\Users\Richard\Documents\Media Converter for Philips
[2009/09/23 06:53:35 | 00,000,000 | ---D | C] -- C:\Philips
[2009/09/23 06:52:56 | 00,000,000 | ---D | C] -- C:\temp
[2009/09/23 06:37:35 | 00,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
========== Files - Modified Within 30 Days ==========
[2009/10/15 16:48:03 | 00,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/10/15 16:48:03 | 00,003,760 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/10/15 16:16:00 | 00,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/10/15 14:48:57 | 00,035,085 | ---- | M] () -- C:\ProgramData\nvModes.001
[2009/10/15 14:48:15 | 00,000,438 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{12D2AAC3-713A-447E-8DC7-4B4DEE477597}.job
[2009/10/15 14:48:04 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/10/15 03:02:52 | 00,694,964 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2009/10/15 03:02:52 | 00,598,350 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2009/10/15 03:02:52 | 00,101,988 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2009/10/15 02:57:10 | 00,035,085 | ---- | M] () -- C:\ProgramData\nvModes.dat
[2009/10/15 02:57:00 | 00,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/10/15 02:56:39 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/10/15 02:55:42 | 02,680,246 | -H-- | M] () -- C:\Users\Richard\AppData\Local\IconCache.db
[2009/10/14 22:13:23 | 00,031,744 | ---- | M] () -- C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/13 20:17:19 | 00,002,025 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2009/10/13 19:56:10 | 00,100,272 | ---- | M] () -- C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/10/13 19:54:17 | 00,371,440 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2009/10/13 19:42:25 | 00,000,219 | ---- | M] () -- C:\Windows\win.ini
[2009/10/12 21:45:07 | 00,077,824 | ---- | M] () -- C:\Users\Richard\Desktop\Research and explain the XYZ Affair between the U.doc
[2009/10/12 08:48:54 | 00,041,984 | ---- | M] () -- C:\Users\Richard\Desktop\XYZ Affair home cheat.doc
[2009/10/11 11:09:21 | 00,000,763 | ---- | M] () -- C:\Users\Richard\Desktop\NTREGOPT.lnk
[2009/10/11 11:09:21 | 00,000,744 | ---- | M] () -- C:\Users\Richard\Desktop\ERUNT.lnk
[2009/10/09 16:30:52 | 00,708,868 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/10/07 17:03:20 | 00,001,928 | ---- | M] () -- C:\Users\Richard\Desktop\HijackThis.lnk
[2009/10/05 20:22:24 | 00,001,998 | ---- | M] () -- C:\Users\Public\Desktop\Vegas Movie Studio Platinum 9.0.lnk
[2009/10/04 23:05:00 | 00,002,206 | ---- | M] () -- C:\Users\Public\Desktop\Internet Video Downloader.lnk
[2009/10/04 23:05:00 | 00,002,071 | ---- | M] () -- C:\Users\Public\Desktop\Media Converter for Philips.lnk
[2009/10/04 23:03:11 | 00,000,921 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk
[2009/10/04 23:03:11 | 00,000,887 | ---- | M] () -- C:\Users\Public\Desktop\Philips GoGear VIBE Device Manager.lnk
[2009/10/04 22:09:53 | 00,001,848 | ---- | M] () -- C:\Users\Public\Desktop\TotalMedia Theatre.lnk
[2009/10/04 21:03:00 | 00,001,046 | ---- | M] () -- C:\Users\Richard\Desktop\FrostWire 4.18.3.lnk
[2009/10/04 11:09:17 | 00,001,606 | ---- | M] () -- C:\Users\Richard\Desktop\Recuva.lnk
[2009/10/04 09:53:39 | 00,001,072 | -H-- | M] () -- C:\IPH.PH
[2009/10/04 09:53:30 | 00,001,752 | ---- | M] () -- C:\Users\Public\Desktop\AIM.lnk
[2009/10/03 22:24:33 | 00,001,724 | ---- | M] () -- C:\Users\Richard\Desktop\CCleaner.lnk
[2009/10/01 20:42:31 | 00,001,792 | ---- | M] () -- C:\Users\Richard\Desktop\Left 4 Dead.lnk
[2009/09/27 23:12:22 | 00,014,646 | ---- | M] () -- C:\Windows\SysNative\nvdisp.nvu
[2009/09/27 18:22:50 | 00,253,738 | ---- | M] () -- C:\Windows\SysNative\NvApps.xml
[2009/09/27 18:22:50 | 00,068,587 | ---- | M] () -- C:\Windows\SysNative\NvwsApps.xml
[2009/09/23 21:27:24 | 00,001,128 | ---- | M] () -- C:\Users\Richard\Desktop\AVS4YOU Software Navigator.lnk
[2009/09/23 21:27:05 | 00,001,079 | ---- | M] () -- C:\Users\Richard\Desktop\AVS Video Converter 6.lnk
[2009/09/23 06:38:10 | 00,001,804 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/09/22 21:43:39 | 00,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2009/09/21 22:30:21 | 06,273,536 | ---- | M] () -- C:\Users\Richard\Documents\Richs power point2.ppt
[2009/09/21 01:46:06 | 00,373,089 | ---- | M] () -- C:\Users\Richard\Documents\Scribble words.docx
[2009/09/20 00:05:44 | 00,004,096 | -H-- | M] () -- C:\Users\Richard\AppData\Local\keyfile3.drm
[2009/09/18 00:13:00 | 00,010,412 | ---- | M] () -- C:\Users\Richard\Documents\Profane.docx
[2009/09/16 20:37:41 | 00,001,756 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/09/15 23:43:42 | 00,012,404 | ---- | M] () -- C:\Users\Richard\Documents\Mzxamyx123.docx
========== Files - No Company Name ==========
[2009/10/12 20:15:51 | 00,077,824 | ---- | C] () -- C:\Users\Richard\Desktop\Research and explain the XYZ Affair between the U.doc
[2009/10/12 20:15:39 | 00,041,984 | ---- | C] () -- C:\Users\Richard\Desktop\XYZ Affair home cheat.doc
[2009/10/11 11:09:21 | 00,000,763 | ---- | C] () -- C:\Users\Richard\Desktop\NTREGOPT.lnk
[2009/10/11 11:09:21 | 00,000,744 | ---- | C] () -- C:\Users\Richard\Desktop\ERUNT.lnk
[2009/10/09 16:30:52 | 00,708,868 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/10/07 17:03:20 | 00,001,928 | ---- | C] () -- C:\Users\Richard\Desktop\HijackThis.lnk
[2009/10/05 20:22:24 | 00,001,998 | ---- | C] () -- C:\Users\Public\Desktop\Vegas Movie Studio Platinum 9.0.lnk
[2009/10/04 22:09:53 | 00,001,848 | ---- | C] () -- C:\Users\Public\Desktop\TotalMedia Theatre.lnk
[2009/10/04 22:09:47 | 00,143,872 | ---- | C] () -- C:\Windows\SysWow64\drivers\ArcHlp.sys
[2009/10/04 11:09:17 | 00,001,606 | ---- | C] () -- C:\Users\Richard\Desktop\Recuva.lnk
[2009/10/04 09:53:30 | 00,001,752 | ---- | C] () -- C:\Users\Public\Desktop\AIM.lnk
[2009/10/01 20:42:31 | 00,001,792 | ---- | C] () -- C:\Users\Richard\Desktop\Left 4 Dead.lnk
[2009/09/27 23:12:22 | 00,014,646 | ---- | C] () -- C:\Windows\SysNative\nvdisp.nvu
[2009/09/27 18:22:50 | 00,253,738 | ---- | C] () -- C:\Windows\SysNative\NvApps.xml
[2009/09/27 18:22:50 | 00,068,587 | ---- | C] () -- C:\Windows\SysNative\NvwsApps.xml
[2009/09/25 19:11:22 | 00,000,898 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2009/09/25 19:11:21 | 00,000,894 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2009/09/25 18:58:23 | 00,002,025 | ---- | C] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2009/09/25 07:28:05 | 00,001,046 | ---- | C] () -- C:\Users\Richard\Desktop\FrostWire 4.18.3.lnk
[2009/09/23 21:27:24 | 00,001,128 | ---- | C] () -- C:\Users\Richard\Desktop\AVS4YOU Software Navigator.lnk
[2009/09/23 21:27:05 | 00,001,079 | ---- | C] () -- C:\Users\Richard\Desktop\AVS Video Converter 6.lnk
[2009/09/23 07:44:36 | 00,020,318 | ---- | C] () -- C:\Users\Richard\AppData\Roaming\ReplayConverterLog.log
[2009/09/23 06:56:55 | 00,000,006 | -HS- | C] () -- C:\Users\Richard\AppData\Roaming\desktop.ini
[2009/09/23 06:56:55 | 00,000,006 | -HS- | C] () -- C:\Users\Richard\AppData\Local\desktop.ini
[2009/09/23 06:56:01 | 00,002,206 | ---- | C] () -- C:\Users\Public\Desktop\Internet Video Downloader.lnk
[2009/09/23 06:56:01 | 00,002,071 | ---- | C] () -- C:\Users\Public\Desktop\Media Converter for Philips.lnk
[2009/09/23 06:53:35 | 00,000,921 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Philips GoGear VIBE Device Manager.lnk
[2009/09/23 06:53:35 | 00,000,887 | ---- | C] () -- C:\Users\Public\Desktop\Philips GoGear VIBE Device Manager.lnk
[2009/09/23 06:38:10 | 00,001,804 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2009/09/22 21:43:39 | 00,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2009/09/21 15:53:42 | 06,273,536 | ---- | C] () -- C:\Users\Richard\Documents\Richs power point2.ppt
[2009/09/21 01:46:02 | 00,373,089 | ---- | C] () -- C:\Users\Richard\Documents\Scribble words.docx
[2009/09/20 00:05:44 | 00,004,096 | -H-- | C] () -- C:\Users\Richard\AppData\Local\keyfile3.drm
[2009/09/18 00:12:59 | 00,010,412 | ---- | C] () -- C:\Users\Richard\Documents\Profane.docx
[2009/09/16 20:37:41 | 00,001,756 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2009/09/15 23:43:42 | 00,012,404 | ---- | C] () -- C:\Users\Richard\Documents\Mzxamyx123.docx
[2009/08/31 13:54:26 | 00,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/08/25 17:59:41 | 00,000,552 | ---- | C] () -- C:\Users\Richard\AppData\Local\d3d8caps.dat
[2009/08/05 20:52:07 | 00,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/08/05 20:51:41 | 00,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/08/05 10:53:43 | 00,024,088 | ---- | C] () -- C:\Users\Richard\AppData\Roaming\UserTile.png
[2009/07/29 16:20:33 | 00,000,418 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/07/24 02:23:04 | 00,031,744 | ---- | C] () -- C:\Users\Richard\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/07/23 18:26:45 | 00,035,085 | ---- | C] () -- C:\ProgramData\nvModes.001
[2009/07/23 18:26:43 | 00,035,085 | ---- | C] () -- C:\ProgramData\nvModes.dat
[2009/07/23 18:25:30 | 02,680,246 | -H-- | C] () -- C:\Users\Richard\AppData\Local\IconCache.db
[2009/07/23 18:21:02 | 00,000,732 | ---- | C] () -- C:\Users\Richard\AppData\Local\d3d9caps64.dat
[2009/07/23 15:57:36 | 00,000,010 | ---- | C] () -- C:\Windows\GSetup.ini
[2009/07/23 15:53:46 | 00,100,272 | ---- | C] () -- C:\Users\Richard\AppData\Local\GDIPFONTCACHEV1.DAT
[2008/01/20 19:49:10 | 00,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2006/11/02 08:24:55 | 00,000,174 | -HS- | C] () -- C:\Program Files\desktop.ini
[2006/11/02 08:24:55 | 00,000,174 | -HS- | C] () -- C:\Program Files (x86)\desktop.ini
[2006/11/02 05:34:27 | 00,000,219 | ---- | C] () -- C:\Windows\win.ini
[2006/11/02 05:34:27 | 00,000,219 | ---- | C] () -- C:\Windows\system.ini
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:5C321E34
< End of report >