MSB146
Topic Starter
Hi, Zonealarm detects this trojan and although it treats it, the detection keeps appearing whenever I restart my computer. I would appreciate any help.
OTL logfile created on: 16/03/2013 7:32:11 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\John Niarhos\My Documents\My Download Files
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.00 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.07% Memory free
4.83 Gb Paging File | 3.54 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 97.98 Gb Free Space | 52.59% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS
Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\John Niarhos\My Documents\My Download Files\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
PRC - C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\TrueSuite Access Manager\PwdBank.exe (Arachnoid Biometrics Identification Group)
PRC - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
PRC - C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\024c898ad1ccfde466d033c0a08d0564\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7ee03714420b252415b952d40ef59e4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e143370f0583abe015d8e3d2d536185e\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ba12e418b906593b7c9c18f971f36bf9\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d7a2248a76f0e94d56c92c5bf96f5175\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\96b7a0136e9e72e8f4eb0230c20766d2\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7782f356a838c403b4a8e9c80df5a577\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\fde\fde_api.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\crsrpt.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mtdsdk.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\resources\mbzaenu.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\WINDOWS\system32\qcap.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\tsd32.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Applet\TouchPad_ONOFF.dll ()
MOD - C:\WINDOWS\system32\TosCommAPI.dll ()
========== Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (nosGetPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TODDSrv) – C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FingerprintServer) – C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (SSNDIS5) – System32\Drivers\SSNDIS5.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MagicTune) – system32\drivers\MTiCtwl.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (IntcHdmiAddService) – system32\drivers\IntcHdmi.sys File not found
DRV - (ialm) – system32\DRIVERS\igxpmp32.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (Vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (KL1) – C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (NETw5x32) – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (ATSWPDRV) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AlfaFF) – C:\WINDOWS\system32\drivers\AlfaFF.sys (Alfa Corporation)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (UVCFTR) – C:\WINDOWS\system32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (FwLnk) – C:\WINDOWS\system32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdudf) – C:\WINDOWS\system32\drivers\tdudf.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\WINDOWS\system32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (trudf) – C:\WINDOWS\system32\drivers\trudf.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2645238
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.autosport.com/"
FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: %7B9AA46F4F-4DC7-4c06-97AF-5035170634FE%7D:5.2
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0043-ABCDEFFEDCBA%7D:6.0.43
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.5.9rc3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.2
FF - prefs.js..extensions.enabledItems: {5C655500-E712-41e7-9349-CE462F844B19}:0.9
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/04/26 08:38:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/27 21:12:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/27 21:12:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 13:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 13:35:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/12/01 11:27:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/02/22 11:39:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions
[2009/12/30 17:24:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions\[removed]
[2013/03/13 10:55:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions
[2011/02/24 09:07:44 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/26 08:38:18 | 000,000,000 | —D | M] (ZoneAlarm Security Community Toolbar) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
[2013/01/31 08:46:37 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/02/26 09:34:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/11/10 13:29:30 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/19 20:49:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/19 00:17:58 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/19 00:23:54 | 000,000,000 | —D | M] (ImTranslator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2011/02/19 00:16:47 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/19 20:50:09 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012/10/28 08:50:51 | 000,060,290 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\[removed]
[2013/03/13 10:55:29 | 000,532,010 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/02/22 08:05:14 | 000,115,869 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}
[2013/03/08 13:35:39 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/12/27 21:08:39 | 000,124,056 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/08/29 11:47:03 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/20 12:34:07 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
O1 HOSTS File: ([2013/03/16 06:37:07 | 000,000,147 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Toolbar) - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PwdBank] C:\Program Files\TrueSuite Access Manager\PwdBank.exe (Arachnoid Biometrics Identification Group)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_43)
O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5D1F8053-B3F4-4593-8E92-AA0AFDB16D2F}: DhcpNameServer = 10.1.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ATFUS: DllName - (C:\WINDOWS\system32\FpWinLogonNp.dll) - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/26 12:46:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/03/16 06:55:49 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Niarhos\Recent
[2013/03/08 13:35:12 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/03/07 10:24:50 | 000,262,560 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/03/07 10:24:50 | 000,174,496 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/03/07 10:24:50 | 000,174,496 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/03/06 11:42:28 | 000,094,112 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/02/21 10:23:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2013/02/21 10:23:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/16 07:42:30 | 000,000,147 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\HOSTS
[2013/03/16 07:14:17 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:48 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:47 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:42 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/03/16 07:12:48 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/16 07:12:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/03/16 07:10:37 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/16 07:09:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/03/16 06:54:03 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/16 06:42:09 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/03/15 17:11:00 | 000,001,026 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3058550478-1113504122-141126719-1005UA.job
[2013/03/15 11:11:00 | 000,001,004 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3058550478-1113504122-141126719-1005Core.job
[2013/03/14 11:44:19 | 000,000,803 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2013/03/14 11:42:29 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/03/14 11:42:29 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/03/06 11:42:00 | 000,094,112 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/03/06 11:41:58 | 000,262,560 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/03/06 11:41:58 | 000,174,496 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/03/06 11:41:58 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/03/06 11:41:57 | 000,861,088 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/03/06 11:41:57 | 000,782,240 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/03/06 11:41:57 | 000,174,496 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/03/05 14:44:07 | 000,688,069 | —- | M] () – C:\Documents and Settings\John Niarhos\My Documents\J & B Niarhos 2012.13.BC4
[2013/02/21 10:23:27 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/05 14:44:05 | 000,688,069 | —- | C] () – C:\Documents and Settings\John Niarhos\My Documents\J & B Niarhos 2012.13.BC4
[2013/02/21 10:23:27 | 000,001,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/05/07 21:39:48 | 001,142,238 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3058550478-1113504122-141126719-1005-0.dat
[2012/05/02 23:51:03 | 000,416,342 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/02 11:29:02 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2012/05/02 11:29:02 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2012/05/02 11:29:02 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2012/05/02 11:29:02 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2012/05/02 11:29:02 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2012/05/02 11:29:02 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2012/05/02 11:29:02 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2012/05/02 11:29:02 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2012/05/02 11:29:02 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2012/05/02 11:29:02 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2012/05/02 11:29:02 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2012/05/02 11:29:02 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2012/05/02 11:29:02 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2012/05/02 11:29:02 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2012/05/02 11:29:02 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2012/05/02 11:29:02 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2012/05/02 11:29:02 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2012/05/02 11:29:02 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2012/05/02 11:29:02 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2012/02/15 15:54:48 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/09/13 22:34:53 | 000,000,697 | —- | C] () – C:\Documents and Settings\John Niarhos\PCTuneUp.config
[2010/12/13 17:25:23 | 000,638,486 | —- | C] () – C:\Documents and Settings\John Niarhos\J & B Niarhos 2010.11.BC4
[2010/10/22 16:54:05 | 000,001,057 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\vso_ts_preview.xml
[2009/05/04 12:28:55 | 000,015,872 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2008/06/26 12:57:40 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2013/02/06 21:18:44 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 22:40:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 22:30:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/08/04 15:45:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2013/01/29 20:05:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/05/02 12:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BlazeVideo
[2009/11/11 10:12:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cadsoft
[2009/03/09 20:46:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/12/27 22:05:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonEPP
[2012/12/27 22:06:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2012/12/27 22:05:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2012/12/27 21:45:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJETV
[2012/12/27 22:02:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJFAX
[2013/01/03 15:13:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2012/12/27 22:27:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSDU
[2012/12/27 21:59:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJWSpt
[2011/09/05 17:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/12/07 16:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2009/02/02 11:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/06 13:01:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2012/05/02 12:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2012/04/28 00:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Quark
[2012/06/15 19:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/09/28 16:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009/06/11 15:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/22 21:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/30 17:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/10/22 17:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2012/04/27 19:10:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2011/02/20 16:09:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/06 15:45:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/09 10:54:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/17 17:51:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/23 21:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/02/05 14:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ABIG
[2010/09/28 16:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\AnvSoft
[2012/04/28 00:25:40 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Aquafadas
[2013/01/03 15:13:38 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Canon
[2010/05/26 14:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\CheckPoint
[2009/11/05 10:52:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ColorSchemer
[2010/10/22 16:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\InterVideo
[2011/02/22 21:35:30 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\KeePass
[2009/04/08 21:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\LimeWire
[2011/09/05 17:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\MailFrontier
[2010/09/28 16:15:48 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\OpenCandy
[2011/05/26 17:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Opera
[2012/06/16 15:03:55 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\PDAppFlex
[2012/04/28 00:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Quark
[2009/06/11 15:11:56 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ScanSoft
[2009/11/04 11:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\SmartDraw
[2012/06/16 15:04:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/11/22 21:27:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Thunderbird
[2009/12/30 17:24:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\TomTom
[2008/06/26 13:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\toshiba
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Uniblue
[2012/01/28 11:00:41 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Vso
[2011/03/06 13:46:51 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2008/04/14 22:30:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:\WINDOWS\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/14 22:30:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/30 02:12:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe
< MD5 for: EXPLORER.HTM >
[2011/03/07 13:43:30 | 000,002,057 | —- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Documents and Settings\All Users\Application Data\ATI\ACE\Help\en-US\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SC_ >
[2008/04/14 22:30:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2008/04/14 22:30:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2008/04/14 22:30:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:\WINDOWS\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2008/04/14 22:30:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\Help\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2008/04/14 22:30:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:\WINDOWS\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/04/14 22:30:00 | 000,093,184 | -HS- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2008/04/30 02:12:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe
< MD5 for: IEXPLORE.EXE.LNK >
[2011/05/03 10:30:35 | 000,000,903 | —- | M] () MD5=9A86C62F4DC106C0FA23BA0CA691F7DD – C:\Documents and Settings\John Niarhos\Desktop\IEXPLORE.EXE.lnk
< MD5 for: IEXPLORE.HL_ >
[2008/04/14 22:30:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2008/04/14 22:30:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2008/04/14 22:30:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES._ >
[2008/04/14 22:30:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._
< MD5 for: SERVICES.CFG >
[2012/12/19 00:58:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EX_ >
[2008/04/14 22:30:00 | 000,049,959 | —- | M] () MD5=EE4885163C0C0729A3C5F1416A6E5F48 – C:\WINDOWS\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2009/02/06 21:36:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 22:30:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 21:41:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 21:41:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2009/03/24 14:03:54 | 000,001,613 | —- | M] () MD5=7EEA346F3C26EE5505704F81EE5A2844 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MS_ >
[2008/04/14 22:30:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2008/04/14 22:30:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.PNG >
[2012/07/17 12:09:28 | 000,000,863 | —- | M] () MD5=D1216C0F5D2A014C4F6CD31E49F02A29 – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}\chrome\skin\services.png
[2011/02/19 20:49:35 | 000,000,863 | —- | M] () MD5=D1216C0F5D2A014C4F6CD31E49F02A29 – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}\chrome\skin\services.png
< MD5 for: SERVICES.SBS >
[2011/03/01 10:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.EX_ >
[2008/04/14 22:30:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:\WINDOWS\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 22:30:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 23:47:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/09/08 15:11:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/09 17:54:33 | 000,000,450 | —- | M] () – C:\InstallHelper.log
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:30:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:30:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/03/16 07:12:25 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/12/05 06:32:37 | 000,002,215 | —- | M] () – C:\rollback.ini
[2008/06/26 13:44:44 | 000,000,086 | —- | M] () – C:\setup.log
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/06/26 12:46:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/22 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD94.DLL
[2007/10/29 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD98.DLL
[2011/11/03 05:00:00 | 000,029,184 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDAZ.DLL
[2002/09/30 06:30:00 | 000,013,824 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDya.DLL
[2007/05/22 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP94.DLL
[2007/10/29 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP98.DLL
[2011/11/03 05:00:00 | 000,084,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPAZ.DLL
[2002/09/30 06:30:00 | 000,046,080 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPya.DLL
[2008/07/06 22:36:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 21:20:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2004/12/08 18:34:46 | 000,045,056 | —- | M] (TOSHIBA) – C:\WINDOWS\cfdemo.scr
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/01/04 23:29:02 | 000,001,762 | -H– | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/06/26 05:36:16 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/06/26 05:36:16 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/06/26 05:36:15 | 000,925,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/26 12:47:08 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/02 09:45:43 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/06/26 12:53:07 | 000,000,079 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/04/17 11:32:31 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\John Niarhos\Desktop\ATF_Cleaner.exe
[2009/04/17 11:36:51 | 002,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\John Niarhos\Desktop\mbam-setup.exe
[2011/03/06 14:39:18 | 000,057,344 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\SMP2250.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-03-13 10:16:01
========== Files - Unicode (All) ==========
[2012/10/15 10:21:37 | 000,087,552 | —- | M] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
[2009/02/17 11:52:35 | 000,087,552 | —- | C] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >
OTL logfile created on: 16/03/2013 7:32:11 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\John Niarhos\My Documents\My Download Files
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000C09 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.00 Gb Total Physical Memory | 1.95 Gb Available Physical Memory | 65.07% Memory free
4.83 Gb Paging File | 3.54 Gb Available in Paging File | 73.27% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 186.31 Gb Total Space | 97.98 Gb Free Space | 52.59% Space Free | Partition Type: NTFS
Drive D: | 186.31 Gb Total Space | 185.93 Gb Free Space | 99.80% Space Free | Partition Type: NTFS
Computer Name: YOUR-6D410B054D | User Name: John Niarhos | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\John Niarhos\My Documents\My Download Files\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Secunia\PSI\psia.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
PRC - C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
PRC - C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
PRC - C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\TrueSuite Access Manager\PwdBank.exe (Arachnoid Biometrics Identification Group)
PRC - C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
PRC - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
PRC - C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosA2dp.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHSP.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtHid.exe (TOSHIBA CORPORATION.)
PRC - C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
PRC - C:\WINDOWS\system32\TPSMain.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\TPSBattM.exe (TOSHIBA Corporation)
PRC - C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe (Nuance Communications, Inc.)
PRC - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
PRC - C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
========== Modules (No Company Name) ==========
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\024c898ad1ccfde466d033c0a08d0564\Microsoft.VisualBasic.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\d7ee03714420b252415b952d40ef59e4\System.ServiceProcess.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\e143370f0583abe015d8e3d2d536185e\System.Web.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ba12e418b906593b7c9c18f971f36bf9\System.Windows.Forms.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d7a2248a76f0e94d56c92c5bf96f5175\System.Runtime.Remoting.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\96b7a0136e9e72e8f4eb0230c20766d2\System.Configuration.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\fe025743210c22bea2f009e1612c38bf\System.Xml.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\7782f356a838c403b4a8e9c80df5a577\System.Drawing.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\aeac298c43c77d8860db8e7634d9f2eb\System.ni.dll ()
MOD - C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\eab2340ead8e1a84bdf1a87868659979\mscorlib.ni.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\fde\fde_api.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\crsrpt.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\MlfHook.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mtdsdk.dll ()
MOD - C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\resources\mbzaenu.dll ()
MOD - C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
MOD - C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe ()
MOD - C:\WINDOWS\system32\qcap.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\tsd32.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Applet\TouchPad_ONOFF.dll ()
MOD - C:\WINDOWS\system32\TosCommAPI.dll ()
========== Services (SafeList) ==========
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE.EXE (SUPERAntiSpyware.com)
SRV - (MBAMService) – C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (Secunia PSI Agent) – C:\Program Files\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files\Secunia\PSI\sua.exe (Secunia)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (WDFME) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (WDSC) – C:\Program Files\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDDMService) – C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe (WDC)
SRV - (nosGetPlusHelper) – C:\Program Files\NOS\bin\getPlus_Helper_3004.dll (NOS Microsystems Ltd.)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (TAPPSRV) – C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe (TOSHIBA Corp.)
SRV - (TOSHIBA Bluetooth Service) – C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe (TOSHIBA CORPORATION)
SRV - (TODDSrv) – C:\WINDOWS\system32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (FingerprintServer) – C:\WINDOWS\system32\FpLogonServ.exe (AuthenTec,Inc)
SRV - (AgereModemAudio) – C:\WINDOWS\system32\agrsmsvc.exe (Agere Systems)
SRV - (CFSvcs) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (SSNDIS5) – System32\Drivers\SSNDIS5.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (MagicTune) – system32\drivers\MTiCtwl.sys File not found
DRV - (lbrtfdc) – File not found
DRV - (IntcHdmiAddService) – system32\drivers\IntcHdmi.sys File not found
DRV - (ialm) – system32\DRIVERS\igxpmp32.sys File not found
DRV - (i2omgmt) – File not found
DRV - (Changer) – File not found
DRV - (MBAMProtector) – C:\WINDOWS\system32\drivers\mbam.sys (Malwarebytes Corporation)
DRV - (Vsdatant) – C:\WINDOWS\system32\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (icsak) – C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys (Check Point Software Technologies)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (KL1) – C:\WINDOWS\system32\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV - (kl2) – C:\WINDOWS\system32\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV - (KLIF) – C:\WINDOWS\system32\drivers\klif.sys (Kaspersky Lab)
DRV - (PSI) – C:\WINDOWS\system32\drivers\psi_mf.sys (Secunia)
DRV - (fssfltr) – C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (NETw5x32) – C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation)
DRV - (ATSWPDRV) – C:\WINDOWS\system32\drivers\ATSwpDrv.sys (AuthenTec, Inc.)
DRV - (tosrfbd) – C:\WINDOWS\system32\drivers\tosrfbd.sys (TOSHIBA CORPORATION)
DRV - (IntcAzAudAddService) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (tosporte) – C:\WINDOWS\system32\drivers\tosporte.sys (TOSHIBA Corporation)
DRV - (Tosrfhid) – C:\WINDOWS\system32\drivers\Tosrfhid.sys (TOSHIBA Corporation.)
DRV - (AlfaFF) – C:\WINDOWS\system32\drivers\AlfaFF.sys (Alfa Corporation)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtHDMI.sys (Realtek Semiconductor Corp.)
DRV - (rimmptsk) – C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC)
DRV - (TosRfSnd) – C:\WINDOWS\system32\drivers\TosRfSnd.sys (TOSHIBA Corporation)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (UVCFTR) – C:\WINDOWS\system32\drivers\UVCFTR_S.SYS (Chicony Electronics Co., Ltd.)
DRV - (tosrfbnp) – C:\WINDOWS\system32\drivers\tosrfbnp.sys (TOSHIBA Corporation)
DRV - (Tosrfusb) – C:\WINDOWS\system32\drivers\tosrfusb.sys (TOSHIBA CORPORATION)
DRV - (Tosrfcom) – C:\WINDOWS\system32\drivers\tosrfcom.sys (TOSHIBA Corporation)
DRV - (rismxdp) – C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC)
DRV - (rimsptsk) – C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC)
DRV - (FwLnk) – C:\WINDOWS\system32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (tdudf) – C:\WINDOWS\system32\drivers\tdudf.sys (TOSHIBA Corporation)
DRV - (tdcmdpst) – C:\WINDOWS\system32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (trudf) – C:\WINDOWS\system32\drivers\trudf.sys (TOSHIBA Corporation)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (tosrfec) – C:\WINDOWS\system32\drivers\tosrfec.sys (TOSHIBA Corporation)
DRV - (tosrfnds) – C:\WINDOWS\system32\drivers\tosrfnds.sys (TOSHIBA Corporation.)
DRV - (Netdevio) – C:\WINDOWS\system32\drivers\Netdevio.sys (TOSHIBA Corporation.)
DRV - (FTSER2K) – C:\WINDOWS\system32\drivers\ftser2k.sys (FTDI Ltd.)
DRV - (FTDIBUS) – C:\WINDOWS\system32\drivers\ftdibus.sys (FTDI Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\..\URLSearchHook: {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2645238
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.autosport.com/"
FF - prefs.js..extensions.enabledAddons: translator%40zoli.bod:2.1.0.3
FF - prefs.js..extensions.enabledAddons: %7Ba0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7%7D:20130129
FF - prefs.js..extensions.enabledAddons: %7B9AA46F4F-4DC7-4c06-97AF-5035170634FE%7D:5.2
FF - prefs.js..extensions.enabledAddons: %7Bb9db16a4-6edc-47ec-a1f4-b86292ed211d%7D:4.9.14
FF - prefs.js..extensions.enabledAddons: %7BCAFEEFAC-0016-0000-0043-ABCDEFFEDCBA%7D:6.0.43
FF - prefs.js..extensions.enabledAddons: %7B73a6fe31-595d-460b-a920-fcc0f8843232%7D:2.6.5.9rc3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - prefs.js..extensions.enabledItems: {ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}:2.7.2
FF - prefs.js..extensions.enabledItems: {5C655500-E712-41e7-9349-CE462F844B19}:0.9
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20110704
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.0: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.6.14: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.0.282: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2012/04/26 08:38:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{34712C68-7391-4c47-94F3-8F88D49AD632}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2012/12/27 21:12:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2012/12/27 21:12:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/03/08 13:35:40 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/03/08 13:35:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/12/01 11:27:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 8.0\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2011/02/22 11:39:01 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions
[2009/12/30 17:24:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\Extensions\[removed]
[2013/03/13 10:55:29 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions
[2011/02/24 09:07:44 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/04/26 08:38:18 | 000,000,000 | —D | M] (ZoneAlarm Security Community Toolbar) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{91da5e8a-3318-4f8c-b67e-5964de3ab546}
[2013/01/31 08:46:37 | 000,000,000 | —D | M] (WOT) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2013/02/26 09:34:32 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/11/10 13:29:30 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2011/02/19 20:49:43 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions
[2011/02/19 00:25:17 | 000,000,000 | —D | M] (Quick Translator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{5C655500-E712-41e7-9349-CE462F844B19}
[2011/02/19 00:17:58 | 000,000,000 | —D | M] (NoScript) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2011/02/19 00:23:54 | 000,000,000 | —D | M] (ImTranslator) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}
[2011/02/19 00:16:47 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/19 20:50:09 | 000,000,000 | —D | M] (FoxLingo) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}
[2012/10/28 08:50:51 | 000,060,290 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\[removed]
[2013/03/13 10:55:29 | 000,532,010 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi
[2013/02/22 08:05:14 | 000,115,869 | —- | M] () (No name found) – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/03/08 13:35:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA}
[2013/03/08 13:35:39 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/12/27 21:08:39 | 000,124,056 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/08/29 11:47:03 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/20 12:34:07 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
O1 HOSTS File: ([2013/03/16 06:37:07 | 000,000,147 | —- | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Toolbar) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Toolbar) - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - C:\Program Files\ZoneAlarm_Security\prxtbZon2.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\Alcmtr.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [Camera Assistant Software] C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe (Chicony)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe ()
O4 - HKLM..\Run: [FingerPrintNotifer] C:\Program Files\TrueSuite Access Manager\FpNotifier.exe (AuthenTec, Inc)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [ITSecMng] C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\ItSecMng.exe ( TOSHIBA CORPORATION)
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [OpwareSE4] C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PwdBank] C:\Program Files\TrueSuite Access Manager\PwdBank.exe (Arachnoid Biometrics Identification Group)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [THotkey] C:\Program Files\TOSHIBA\TOSHIBA Applet\THotkey.exe (TOSHIBA)
O4 - HKLM..\Run: [TPSMain] C:\WINDOWS\System32\TPSMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [UsbMonitor] C:\Program Files\TrueSuite Access Manager\usbnotify.exe ()
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [FileHippo.com] C:\Program Files\FileHippo.com\UpdateChecker.exe (FileHippo.com)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - HKCU..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe (TOSHIBA)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth Manager.lnk = C:\Program Files\TOSHIBA\Bluetooth Toshiba Stack\TosBtMng.exe (TOSHIBA CORPORATION.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Secunia PSI Tray.lnk = C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: internet ([]about in Internet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0043-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_43)
O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_17)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.1.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5D1F8053-B3F4-4593-8E92-AA0AFDB16D2F}: DhcpNameServer = 10.1.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\ATFUS: DllName - (C:\WINDOWS\system32\FpWinLogonNp.dll) - C:\WINDOWS\system32\FpWinlogonNp.dll (AuthenTec,Inc)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\John Niarhos\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/26 12:46:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/03/16 06:55:49 | 000,000,000 | RH-D | C] – C:\Documents and Settings\John Niarhos\Recent
[2013/03/08 13:35:12 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/03/07 10:24:50 | 000,262,560 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/03/07 10:24:50 | 000,174,496 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/03/07 10:24:50 | 000,174,496 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/03/06 11:42:28 | 000,094,112 | —- | C] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/02/21 10:23:27 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2013/02/21 10:23:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/03/16 07:42:30 | 000,000,147 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\HOSTS
[2013/03/16 07:14:17 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:48 | 000,000,292 | —- | M] () – C:\WINDOWS\tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:47 | 000,000,300 | —- | M] () – C:\WINDOWS\tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3058550478-1113504122-141126719-1005.job
[2013/03/16 07:13:42 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2013/03/16 07:12:48 | 000,000,894 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2013/03/16 07:12:31 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2013/03/16 07:10:37 | 000,000,795 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes Anti-Malware.lnk
[2013/03/16 07:09:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/03/16 06:54:03 | 000,000,898 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2013/03/16 06:42:09 | 000,000,693 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2013/03/15 17:11:00 | 000,001,026 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3058550478-1113504122-141126719-1005UA.job
[2013/03/15 11:11:00 | 000,001,004 | —- | M] () – C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-3058550478-1113504122-141126719-1005Core.job
[2013/03/14 11:44:19 | 000,000,803 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Microsoft Office Outlook.lnk
[2013/03/14 11:42:29 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerApp.exe
[2013/03/14 11:42:29 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2013/03/06 11:42:00 | 000,094,112 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\WindowsAccessBridge.dll
[2013/03/06 11:41:58 | 000,262,560 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaws.exe
[2013/03/06 11:41:58 | 000,174,496 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javaw.exe
[2013/03/06 11:41:58 | 000,143,872 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\javacpl.cpl
[2013/03/06 11:41:57 | 000,861,088 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\npdeployJava1.dll
[2013/03/06 11:41:57 | 000,782,240 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\deployJava1.dll
[2013/03/06 11:41:57 | 000,174,496 | —- | M] (Oracle Corporation) – C:\WINDOWS\System32\java.exe
[2013/03/05 14:44:07 | 000,688,069 | —- | M] () – C:\Documents and Settings\John Niarhos\My Documents\J & B Niarhos 2012.13.BC4
[2013/02/21 10:23:27 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/03/05 14:44:05 | 000,688,069 | —- | C] () – C:\Documents and Settings\John Niarhos\My Documents\J & B Niarhos 2012.13.BC4
[2013/02/21 10:23:27 | 000,001,878 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2012/05/07 21:39:48 | 001,142,238 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-3058550478-1113504122-141126719-1005-0.dat
[2012/05/02 23:51:03 | 000,416,342 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2012/05/02 11:29:02 | 000,111,932 | —- | C] () – C:\WINDOWS\System32\EPPICPrinterDB.dat
[2012/05/02 11:29:02 | 000,031,053 | —- | C] () – C:\WINDOWS\System32\EPPICPattern131.dat
[2012/05/02 11:29:02 | 000,027,417 | —- | C] () – C:\WINDOWS\System32\EPPICPattern121.dat
[2012/05/02 11:29:02 | 000,026,154 | —- | C] () – C:\WINDOWS\System32\EPPICPattern1.dat
[2012/05/02 11:29:02 | 000,024,903 | —- | C] () – C:\WINDOWS\System32\EPPICPattern3.dat
[2012/05/02 11:29:02 | 000,021,390 | —- | C] () – C:\WINDOWS\System32\EPPICPattern5.dat
[2012/05/02 11:29:02 | 000,020,148 | —- | C] () – C:\WINDOWS\System32\EPPICPattern2.dat
[2012/05/02 11:29:02 | 000,011,811 | —- | C] () – C:\WINDOWS\System32\EPPICPattern4.dat
[2012/05/02 11:29:02 | 000,004,943 | —- | C] () – C:\WINDOWS\System32\EPPICPattern6.dat
[2012/05/02 11:29:02 | 000,001,146 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_DU.dat
[2012/05/02 11:29:02 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2012/05/02 11:29:02 | 000,001,139 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2012/05/02 11:29:02 | 000,001,136 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2012/05/02 11:29:02 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2012/05/02 11:29:02 | 000,001,129 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2012/05/02 11:29:02 | 000,001,120 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_IT.dat
[2012/05/02 11:29:02 | 000,001,107 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_GE.dat
[2012/05/02 11:29:02 | 000,001,104 | —- | C] () – C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2012/05/02 11:29:02 | 000,000,097 | —- | C] () – C:\WINDOWS\System32\PICSDK.ini
[2012/02/15 15:54:48 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/09/13 22:34:53 | 000,000,697 | —- | C] () – C:\Documents and Settings\John Niarhos\PCTuneUp.config
[2010/12/13 17:25:23 | 000,638,486 | —- | C] () – C:\Documents and Settings\John Niarhos\J & B Niarhos 2010.11.BC4
[2010/10/22 16:54:05 | 000,001,057 | —- | C] () – C:\Documents and Settings\John Niarhos\Application Data\vso_ts_preview.xml
[2009/05/04 12:28:55 | 000,015,872 | —- | C] () – C:\Documents and Settings\John Niarhos\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2008/06/26 12:57:40 | 000,000,227 | RHS- | M] () – C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll – [2013/02/06 21:18:44 | 001,510,400 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\fastprox.dll – [2009/02/09 22:40:48 | 000,473,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = C:\WINDOWS\system32\wbem\wbemess.dll – [2008/04/14 22:30:00 | 000,273,920 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2011/08/04 15:45:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\!SASCORE
[2013/01/29 20:05:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\188F1432-103A-4ffb-80F1-36B633C5C9E1
[2012/05/02 12:28:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BlazeVideo
[2009/11/11 10:12:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Cadsoft
[2009/03/09 20:46:15 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2012/12/27 22:05:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonEPP
[2012/12/27 22:06:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEGV
[2012/12/27 22:05:20 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX2
[2012/12/27 21:45:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJETV
[2012/12/27 22:02:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJFAX
[2013/01/03 15:13:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2012/12/27 22:27:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJSDU
[2012/12/27 21:59:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJWSpt
[2011/09/05 17:08:55 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\CheckPoint
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DriverScanner
[2009/12/07 16:05:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Kaspersky SDK
[2009/02/02 11:28:01 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MailFrontier
[2009/03/06 13:01:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSScanAppDataDir
[2012/05/02 12:34:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panasonic
[2012/04/28 00:18:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Quark
[2012/06/15 19:52:13 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2010/09/28 16:16:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ReviverSoft
[2009/06/11 15:11:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/22 21:00:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/30 17:24:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2010/10/22 17:57:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2012/04/27 19:10:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Western Digital
[2011/02/20 16:09:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WinZip
[2009/04/06 15:45:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010/04/09 10:54:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/01/17 17:51:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009/04/23 21:19:32 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/02/05 14:46:04 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ABIG
[2010/09/28 16:15:39 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\AnvSoft
[2012/04/28 00:25:40 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Aquafadas
[2013/01/03 15:13:38 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Canon
[2010/05/26 14:53:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\CheckPoint
[2009/11/05 10:52:50 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ColorSchemer
[2010/10/22 16:35:58 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\InterVideo
[2011/02/22 21:35:30 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\KeePass
[2009/04/08 21:39:28 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\LimeWire
[2011/09/05 17:49:45 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\MailFrontier
[2010/09/28 16:15:48 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\OpenCandy
[2011/05/26 17:21:35 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Opera
[2012/06/16 15:03:55 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\PDAppFlex
[2012/04/28 00:24:17 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Quark
[2009/06/11 15:11:56 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\ScanSoft
[2009/11/04 11:04:02 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\SmartDraw
[2012/06/16 15:04:08 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/11/22 21:27:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Thunderbird
[2009/12/30 17:24:10 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\TomTom
[2008/06/26 13:47:22 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\toshiba
[2009/07/12 14:11:54 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Uniblue
[2012/01/28 11:00:41 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\Vso
[2011/03/06 13:46:51 | 000,000,000 | —D | M] – C:\Documents and Settings\John Niarhos\Application Data\WinBatch
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EX_ >
[2008/04/14 22:30:00 | 000,356,615 | —- | M] () MD5=D7B59A7EC9CB1429FDCEC84A22228555 – C:\WINDOWS\I386\EXPLORER.EX_
< MD5 for: EXPLORER.EXE >
[2008/04/14 22:30:00 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/30 02:12:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\explorer.exe
< MD5 for: EXPLORER.HTM >
[2011/03/07 13:43:30 | 000,002,057 | —- | M] () MD5=0768146E197314BF50A1E3E5E89892F1 – C:\Documents and Settings\All Users\Application Data\ATI\ACE\Help\en-US\wwhelp\wwhimpl\java\html\explorer.htm
< MD5 for: EXPLORER.SC_ >
[2008/04/14 22:30:00 | 000,000,181 | —- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 – C:\WINDOWS\I386\EXPLORER.SC_
< MD5 for: EXPLORER.SCF >
[2008/04/14 22:30:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINDOWS\explorer.scf
< MD5 for: IEXPLORE.CH_ >
[2008/04/14 22:30:00 | 000,199,077 | —- | M] () MD5=1D662719AB9BB40BA7526B3973D3F626 – C:\WINDOWS\I386\IEXPLORE.CH_
< MD5 for: IEXPLORE.CHM >
[2008/04/14 22:30:00 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINDOWS\Help\iexplore.chm
< MD5 for: IEXPLORE.EX_ >
[2008/04/14 22:30:00 | 000,037,887 | —- | M] () MD5=2B46169148FFD81CAE84572CD32BDF86 – C:\WINDOWS\I386\IEXPLORE.EX_
< MD5 for: IEXPLORE.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2008/04/14 22:30:00 | 000,093,184 | -HS- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\Program Files\Internet Explorer\IEXPLORE.EXE
[2008/04/30 02:12:08 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\iexplore.exe
< MD5 for: IEXPLORE.EXE.LNK >
[2011/05/03 10:30:35 | 000,000,903 | —- | M] () MD5=9A86C62F4DC106C0FA23BA0CA691F7DD – C:\Documents and Settings\John Niarhos\Desktop\IEXPLORE.EXE.lnk
< MD5 for: IEXPLORE.HL_ >
[2008/04/14 22:30:00 | 000,059,881 | —- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 – C:\WINDOWS\I386\IEXPLORE.HL_
< MD5 for: IEXPLORE.HLP >
[2008/04/14 22:30:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINDOWS\Help\iexplore.hlp
< MD5 for: SERVICES >
[2008/04/14 22:30:00 | 000,007,116 | —- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A – C:\WINDOWS\system32\drivers\etc\services
< MD5 for: SERVICES._ >
[2008/04/14 22:30:00 | 000,001,989 | —- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 – C:\WINDOWS\I386\SERVICES._
< MD5 for: SERVICES.CFG >
[2012/12/19 00:58:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EX_ >
[2008/04/14 22:30:00 | 000,049,959 | —- | M] () MD5=EE4885163C0C0729A3C5F1416A6E5F48 – C:\WINDOWS\I386\SERVICES.EX_
< MD5 for: SERVICES.EXE >
[2009/02/06 21:36:24 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=020CEAAEDC8EB655B6506B8C70D53BB6 – C:\WINDOWS\$hf_mig$\KB956572\SP3QFE\services.exe
[2008/04/14 22:30:00 | 000,108,544 | —- | M] (Microsoft Corporation) MD5=0E776ED5F7CC9F94299E70461B7B8185 – C:\WINDOWS\$NtUninstallKB956572$\services.exe
[2009/02/06 21:41:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\dllcache\services.exe
[2009/02/06 21:41:05 | 000,110,592 | —- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 – C:\WINDOWS\system32\services.exe
< MD5 for: SERVICES.LNK >
[2009/03/24 14:03:54 | 000,001,613 | —- | M] () MD5=7EEA346F3C26EE5505704F81EE5A2844 – C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\Services.lnk
< MD5 for: SERVICES.MS_ >
[2008/04/14 22:30:00 | 000,003,649 | —- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 – C:\WINDOWS\I386\SERVICES.MS_
< MD5 for: SERVICES.MSC >
[2008/04/14 22:30:00 | 000,033,464 | —- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 – C:\WINDOWS\system32\services.msc
< MD5 for: SERVICES.PNG >
[2012/07/17 12:09:28 | 000,000,863 | —- | M] () MD5=D1216C0F5D2A014C4F6CD31E49F02A29 – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\gbf4isav.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}\chrome\skin\services.png
[2011/02/19 20:49:35 | 000,000,863 | —- | M] () MD5=D1216C0F5D2A014C4F6CD31E49F02A29 – C:\Documents and Settings\John Niarhos\Application Data\Mozilla\firefox\profiles\rkgwx65o.default\extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66}\chrome\skin\services.png
< MD5 for: SERVICES.SBS >
[2011/03/01 10:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files\Spybot - Search & Destroy\Includes\Services.sbs
< MD5 for: WINLOGON.EX_ >
[2008/04/14 22:30:00 | 000,265,069 | —- | M] () MD5=063EF1A46C58A731F78AE5AF47070D65 – C:\WINDOWS\I386\WINLOGON.EX_
< MD5 for: WINLOGON.EXE >
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/04/14 22:30:00 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe
[2008/07/01 23:47:12 | 000,090,624 | —- | M] () MD5=FBB39A4487E11F64DCFFD36AEC2D2216 – C:\Program Files\CheckPoint\ZAForceField\Heuristics\winlogon.exe
< %SYSTEMDRIVE%\*.* >
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012/09/08 15:11:09 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008/06/26 12:46:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2009/07/09 17:54:33 | 000,000,450 | —- | M] () – C:\InstallHelper.log
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/06/26 12:46:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/04/14 22:30:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/04/14 22:30:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2013/03/16 07:12:25 | 2145,386,496 | -HS- | M] () – C:\pagefile.sys
[2009/12/05 06:32:37 | 000,002,215 | —- | M] () – C:\rollback.ini
[2008/06/26 13:44:44 | 000,000,086 | —- | M] () – C:\setup.log
< %systemroot%\Fonts\*.com >
[2006/04/18 16:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2008/06/26 12:46:11 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2007/05/22 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD94.DLL
[2007/10/29 06:30:00 | 000,027,136 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD98.DLL
[2011/11/03 05:00:00 | 000,029,184 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDAZ.DLL
[2002/09/30 06:30:00 | 000,013,824 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPDya.DLL
[2007/05/22 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP94.DLL
[2007/10/29 06:30:00 | 000,069,632 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP98.DLL
[2011/11/03 05:00:00 | 000,084,992 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPAZ.DLL
[2002/09/30 06:30:00 | 000,046,080 | R— | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPPya.DLL
[2008/07/06 22:36:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/04/09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008/07/06 21:20:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2004/12/08 18:34:46 | 000,045,056 | —- | M] (TOSHIBA) – C:\WINDOWS\cfdemo.scr
[2010/04/17 00:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WLXPGSS.SCR
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/01/04 23:29:02 | 000,001,762 | -H– | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/06/26 05:36:16 | 000,094,208 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2008/06/26 05:36:16 | 001,089,536 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2008/06/26 05:36:15 | 000,925,696 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2008/06/26 12:47:08 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2009/02/02 09:45:43 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008/06/26 12:53:07 | 000,000,079 | —- | M] () – C:\Documents and Settings\John Niarhos\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2009/04/17 11:32:31 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\John Niarhos\Desktop\ATF_Cleaner.exe
[2009/04/17 11:36:51 | 002,967,800 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\John Niarhos\Desktop\mbam-setup.exe
[2011/03/06 14:39:18 | 000,057,344 | —- | M] () – C:\Documents and Settings\John Niarhos\Desktop\SMP2250.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-03-13 10:16:01
========== Files - Unicode (All) ==========
[2012/10/15 10:21:37 | 000,087,552 | —- | M] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
[2009/02/17 11:52:35 | 000,087,552 | —- | C] ()(C:\Documents and Settings\John Niarhos\My Documents\????? ????.doc) – C:\Documents and Settings\John Niarhos\My Documents\コカコーラ ヨーヨー.doc
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >