computerwannabe
Topic Starter
My subscription to Norton ran out a month or so ago. Instead of paying I activated Windows defender. It didn't take long to get infected. I have run MBAM scans, I have run Norton Power Eraser, I have downloaded and installed avast and run their scan, but nothing has found any infection or removed the problem. I have also run JRT and ATF cleaner. I also manually emptied out cookies, but as soon as I refresh the home page or restart firefox the same batch of cookies are right back again.
The problem: Redirecting when I click on any link. Those annoying lines in every page I go to that pop up a window when I mouse over them. And an annoying popup in the lower left corner of the screen every time I go to any page. Oh, and a constant reminder to update flash player. It happens when I am on random pages and will take me away from the page I have been on for a minute or so to a site to 'take care of the problem'.
Here is the OTL logfile:
OTL logfile created on: 5/29/2013 12:16:25 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\jtmeserole\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 61.10% Memory free
5.96 Gb Paging File | 4.87 Gb Available in Paging File | 81.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 135.71 Gb Free Space | 47.32% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.09% Space Free | Partition Type: NTFS
Drive E: | 1.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Users\jtmeserole\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\NCH Software\ExpressZip\ezcm.dll ()
========== Services (SafeList) ==========
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV - (NSM) – C:\Program Files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (RosettaStoneDaemon) – C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\JTMESE~1\AppData\Local\Temp\catchme.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (ccSet_NSM) – C:\Windows\System32\drivers\NSM\0206000.02B\ccSetx86.sys (Symantec Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (Power Software Ltd)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (speedfan) – C:\Windows\System32\speedfan.sys (Almico Software)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\System32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (giveio) – C:\Windows\System32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPDTDF
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {C4E9144D-8269-4F50-B1BE-371B8170CF5A}
IE - HKCU\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{C4E9144D-8269-4F50-B1BE-371B8170CF5A}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Search By ZoneAlarm"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/en/"
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: hOUiT7au%40i0ixSKgctyasBk.com:11
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.43\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/25 22:30:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013/05/25 23:04:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/24 14:07:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/24 14:06:57 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
[2011/11/09 11:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2013/05/25 23:21:11 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2012/09/11 13:55:36 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/27 15:16:06 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2013/03/24 13:46:03 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2013/05/25 23:21:06 | 000,000,000 | —D | M] (zonealarm.com) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 15:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/04/23 18:38:59 | 000,234,665 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/08/23 22:57:12 | 000,074,961 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2013/04/30 10:10:31 | 000,003,259 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/07/19 20:56:57 | 000,310,942 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/12/17 12:34:28 | 000,222,578 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi
[2013/02/19 19:19:26 | 000,685,671 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
[2013/01/23 05:46:58 | 000,007,919 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]\content\Abine\chrome\content\ff\view_expiry.js
[2011/05/03 11:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2013/05/25 22:58:46 | 000,001,488 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\zonealarm.xml
[2013/05/24 14:07:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/24 14:07:05 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/08/14 10:09:55 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2012/06/18 17:44:09 | 000,003,749 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:in
s
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://isearch.avg.com/?cid={9BC737C8-EB9C…mp;d=2012-06-18 17:44:13&v;=11.1.0.7&sap;=hp
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.1.36_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Disabled) = C:\Program Files\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPSibelius.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Earth Plugin (Disabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U11 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windstream Service Agent (Enabled) = C:\Program Files\Windstream\Service Agent\nprpspa.dll
CHR - plugin: iTunes Application Detector (Disabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: SOE Web Installer (Disabled) = C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll
CHR - plugin: Java Deployment Toolkit 7.0.110.21 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Bejeweled = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: YouTube = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: WebFilter Pro - The best filtering addon! = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejgfoklefkbjadjcgjmnhfbdfjolojnn\0.19.6.12_0\
CHR - Extension: Stylish = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.1_0\
CHR - Extension: XKit = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd\7.0.2_0\
CHR - Extension: avast! Online Security = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.6_0\
CHR - Extension: The Great Grass Sea Theme = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpghdlkjginnphhfpdccobkbncldkgmc\1.0_0\
CHR - Extension: Love Smoke = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0\
CHR - Extension: Typing Test - KeyHero = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm\1.4.0_0\
CHR - Extension: Sketchpad = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkllajgbhondgjjnhmmgbjndmogapinp\1.0.0.4_0\
CHR - Extension: Radialpoint SPD Extension = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj\1.0_0\
CHR - Extension: TumTaster = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanfbkacbckngfcklahdgfagjlghfbgm\0.4.9_0\
CHR - Extension: Tumblr Savior = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefddkjnflmjbclpnnoegglmmdfkidip\0.4.5_0\
CHR - Extension: Gmail = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2013/01/17 22:07:58 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC2E7865-5ADB-466A-9527-0EFA9B7FF184}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/03/30 14:43:00 | 002,843,492 | R— | M] (Teaching Textbooks ) - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/04/01 23:21:00 | 000,000,031 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 14 Days ==========
[2013/05/25 23:04:57 | 000,000,000 | —D | C] – C:\Users\jtmeserole\Documents\ForceField Shared Files
[2013/05/25 23:04:52 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\CheckPoint
[2013/05/25 23:02:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2013/05/25 23:00:54 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/05/25 22:58:43 | 000,000,000 | —D | C] – C:\Program Files\Check Point Software Technologies LTD
[2013/05/25 22:58:37 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Check Point Software Technologies LTD
[2013/05/25 22:58:33 | 000,000,000 | —D | C] – C:\Program Files\CheckPoint
[2013/05/25 22:57:34 | 000,000,000 | —D | C] – C:\ProgramData\CheckPoint
[2013/05/25 22:30:36 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/05/25 22:30:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/05/25 22:30:35 | 000,765,736 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/05/25 22:30:35 | 000,368,944 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/05/25 22:30:35 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/05/25 22:30:35 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/05/25 22:30:34 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/05/25 22:30:34 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/05/25 22:29:52 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/05/25 22:28:58 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/05/25 20:11:04 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/05/25 19:31:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/05/25 19:30:56 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/05/25 19:30:56 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/05/25 19:30:56 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/05/24 14:06:55 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/20 08:13:58 | 000,000,000 | —D | C] – C:\ProgramData\Wild Tangent
[2013/05/20 08:00:19 | 000,000,000 | —D | C] – C:\Program Files\WildTangent Games
[2013/05/16 01:15:29 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/05/16 01:00:46 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/05/16 01:00:46 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/05/16 01:00:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/05/16 01:00:46 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/05/16 01:00:45 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/05/16 01:00:45 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/05/16 01:00:44 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/26 10:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
========== Files - Modified Within 14 Days ==========
[2013/05/29 12:17:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/29 12:08:15 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/29 11:52:35 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/29 11:52:35 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/29 11:16:40 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/28 13:53:32 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2013/05/28 13:52:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/26 18:56:46 | 000,604,946 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/05/26 18:56:46 | 000,104,388 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/05/25 23:07:43 | 000,417,507 | —- | M] () – C:\Windows\System32\drivers\vsconfig.xml
[2013/05/25 23:02:40 | 000,000,639 | —- | M] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2013/05/25 22:30:36 | 000,001,795 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/05/25 22:30:34 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/05/22 11:29:50 | 000,001,853 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/20 10:44:48 | 000,070,144 | —- | M] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/20 08:00:35 | 000,002,274 | —- | M] () – C:\Users\jtmeserole\Application Data\Microsoft\Internet Explorer\Quick Launch\WildTangent Games App - hp.lnk
[2013/05/20 08:00:34 | 000,002,242 | —- | M] () – C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
[2013/05/16 08:38:16 | 000,381,240 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013/05/25 23:05:00 | 000,417,507 | —- | C] () – C:\Windows\System32\drivers\vsconfig.xml
[2013/05/25 23:02:40 | 000,000,639 | —- | C] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2013/05/25 22:30:36 | 000,001,795 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/05/25 22:30:35 | 000,174,664 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/05/25 22:30:35 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/05/20 08:00:32 | 000,002,274 | —- | C] () – C:\Users\jtmeserole\Application Data\Microsoft\Internet Explorer\Quick Launch\WildTangent Games App - hp.lnk
[2013/05/20 08:00:32 | 000,002,242 | —- | C] () – C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
[2013/03/27 11:33:33 | 000,069,632 | —- | C] () – C:\Windows\System32\MobOlExt.dll
[2013/01/17 21:54:27 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/17 21:54:27 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/17 21:54:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/17 21:54:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/17 21:54:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/29 15:48:10 | 000,035,328 | —- | C] () – C:\Users\jtmeserole\01074461.XLT
[2012/09/04 20:29:20 | 000,019,456 | —- | C] () – C:\Users\jtmeserole\01026644.xlt
[2012/08/28 08:43:51 | 000,003,632 | —- | C] () – C:\Users\jtmeserole\profiles.xml
[2012/02/29 10:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 10:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2012/01/25 14:38:22 | 000,000,043 | —- | C] () – C:\Users\jtmeserole\Food Storage Planner-Path
[2011/08/20 16:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/17 18:30:51 | 000,000,115 | —- | C] () – C:\Users\jtmeserole\webct_upload_applet.properties
[2011/08/12 13:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 01:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/02/12 22:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/14 10:35:04 | 000,000,632 | RHS- | C] () – C:\Users\jtmeserole\ntuser.pol
[2010/09/25 19:46:40 | 000,070,144 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/22 23:41:23 | 000,029,262 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 13:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/04/29 13:56:06 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.minecraft
[2011/09/23 11:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 20:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/09/01 19:32:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Anuman
[2012/09/22 21:08:08 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2012/08/08 09:16:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Boolat Games
[2011/09/29 16:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2013/05/25 22:58:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Check Point Software Technologies LTD
[2013/05/25 23:04:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\CheckPoint
[2011/05/30 17:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2012/08/13 21:26:06 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\EuroTalk
[2011/04/10 14:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2013/02/06 18:04:41 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 21:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 18:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2013/03/12 13:35:30 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 17:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 13:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2013/01/13 22:14:05 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Meridian93
[2011/03/01 11:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 17:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 18:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 12:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 14:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2012/08/18 08:56:49 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Peace Craft
[2012/05/03 20:05:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2013/01/14 16:43:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Playrix Entertainment
[2013/05/25 18:09:40 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/11/21 14:53:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/10/06 18:04:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\redsn0w
[2012/08/22 20:19:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Sandlot Games
[2012/02/27 16:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 11:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 11:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2013/04/10 14:24:59 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/08/22 20:06:25 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SulusGames
[2012/03/08 13:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 21:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 23:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 18:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 18:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/10/01 13:19:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 15:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2013/05/20 08:00:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 21:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 20:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[1995/04/25 02:00:00 | 000,969,792 | —- | M] () MD5=182749693EF4B3BE232EAC23BC68A448 – C:\HISTORY\EXPLORER.EXE
[2009/05/18 15:45:17 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/05/18 15:45:16 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/05/18 15:45:16 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/05/18 15:45:16 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: EXPLORER.EXE.3164.DMP >
[2013/01/17 21:48:36 | 003,469,158 | —- | M] () MD5=922F306FBA3C8D838F683FB1C74F171C – C:\Users\jtmeserole\AppData\Local\CrashDumps\explorer.exe.3164.dmp
< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/05/28 14:01:41 | 000,169,548 | —- | M] () MD5=8AFDBD786D27AB62500E213E26EA90E5 – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf
< MD5 for: EXPLORER.HLP >
[1995/04/25 02:00:00 | 000,571,344 | —- | M] () MD5=78B5A9803EBA4EA7CE1CCEEE76F5543E – C:\HISTORY\EXPLORER.HLP
< MD5 for: EXPLORER.INI >
[2012/03/09 12:21:51 | 000,000,467 | —- | M] () MD5=05C10B448D97CCD55D08AD8583583DEA – C:\HISTORY\EXPLORER.INI
< MD5 for: IEXPLORE.BAT >
[2013/01/04 15:58:30 | 000,031,067 | —- | M] () MD5=709A62B22C7BA09D875F765341E0FFFC – C:\JRT\iexplore.bat
< MD5 for: IEXPLORE.EXE >
[2012/05/17 18:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 06:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/05/18 15:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/05/18 15:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\ERDNT\cache\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2011/09/30 18:49:11 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2009/05/18 15:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2009/05/18 15:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2009/05/18 15:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2011/11/03 02:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2013/02/21 23:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2013/04/04 17:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/04/04 17:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_586ab855ebd8e83a\iexplore.exe
[2013/02/21 23:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2010/09/08 01:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/05/18 15:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 06:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2009/05/18 15:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2011/12/15 02:36:29 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=54EF418BD99720658CCE24210799BD1A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23286_none_12841eca4925008b\iexplore.exe
[2010/11/02 01:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 21:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2009/05/18 15:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2010/06/26 01:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 02:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2011/05/28 02:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2010/06/28 11:33:13 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=867D06F3C473F65921F5EDF35866FF14 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
[2012/02/20 04:02:12 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 02:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2009/05/18 15:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 02:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/05/18 15:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_58f1544304f93bff\iexplore.exe
[2011/12/15 01:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19190_none_11e9b0573014e4a8\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 16:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/06/28 11:19:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6D7D54B736056991109F169737592C7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
[2010/12/18 01:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2013/04/04 16:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_58e9853504fea3f5\iexplore.exe
[2011/02/22 01:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2011/11/03 01:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/08 01:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/05/18 15:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_58728763ebd38044\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2011/05/28 01:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/26 01:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/05/18 15:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 07:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2012/02/20 04:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/02/20 04:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui
< MD5 for: SERVICES >
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
< MD5 for: SERVICES.DAT >
[2013/01/23 17:22:39 | 000,001,494 | —- | M] () MD5=82F6D657C1FF1C56102204E254445825 – C:\JRT\services.dat
< MD5 for: SERVICES.EXE >
[2008/01/20 21:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\ERDNT\cache\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
< MD5 for: SERVICES.LNK >
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof
< MD5 for: SERVICES.MSC >
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc
< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/01/20 21:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 07:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2013/05/29 12:02:51 | 000,035,160 | —- | M] () MD5=0D36FE4A17D0C601487A8393A31106C8 – C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf
< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 15:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2013/01/25 11:35:49 | 000,013,623 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 12:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/05/28 13:52:26 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2012/09/04 07:55:42 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_04.09.2012_07.55.37_log.txt
[2012/09/11 15:51:23 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.09.2012_15.51.20_log.txt
[2013/05/25 18:43:38 | 000,069,442 | —- | M] () – C:\TDSSKiller.2.5.15.0_25.05.2013_18.43.05_log.txt
[2013/05/25 18:44:12 | 000,069,442 | —- | M] () – C:\TDSSKiller.2.5.15.0_25.05.2013_18.43.48_log.txt
[2013/01/14 14:06:33 | 000,259,570 | —- | M] () – C:\TDSSKiller.2.8.15.0_14.01.2013_13.01.19_log.txt
[2013/05/25 18:46:35 | 000,133,342 | —- | M] () – C:\TDSSKiller.2.8.15.0_25.05.2013_18.46.05_log.txt
[2012/09/04 07:57:29 | 000,132,120 | —- | M] () – C:\TDSSKiller.2.8.8.0_04.09.2012_07.56.29_log.txt
[2012/09/11 15:53:29 | 000,132,458 | —- | M] () – C:\TDSSKiller.2.8.8.0_11.09.2012_15.52.06_log.txt
[2009/05/18 15:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 07:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 12:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 12:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2013/05/09 03:58:37 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/05/20 08:00:33 | 000,000,434 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/08/20 15:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2013/01/25 11:19:27 | 005,026,656 | R— | M] (Swearware) – C:\Users\jtmeserole\Desktop\ComboFix.exe
[2012/11/22 13:09:15 | 000,866,592 | —- | M] () – C:\Users\jtmeserole\Desktop\Norton_Removal_Tool.exe
[2013/01/22 22:22:25 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\jtmeserole\Desktop\OTL.exe
[2013/01/14 14:00:32 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 10:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-05-28 13:23:35
========== Alternate Data Streams ==========
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:9CF728A6
< End of report >
The problem: Redirecting when I click on any link. Those annoying lines in every page I go to that pop up a window when I mouse over them. And an annoying popup in the lower left corner of the screen every time I go to any page. Oh, and a constant reminder to update flash player. It happens when I am on random pages and will take me away from the page I have been on for a minute or so to a site to 'take care of the problem'.
Here is the OTL logfile:
OTL logfile created on: 5/29/2013 12:16:25 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\jtmeserole\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.87 Gb Total Physical Memory | 1.76 Gb Available Physical Memory | 61.10% Memory free
5.96 Gb Paging File | 4.87 Gb Available in Paging File | 81.77% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 286.80 Gb Total Space | 135.71 Gb Free Space | 47.32% Space Free | Partition Type: NTFS
Drive D: | 11.28 Gb Total Space | 1.59 Gb Free Space | 14.09% Space Free | Partition Type: NTFS
Drive E: | 1.12 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: JTMESEROLE-PC | User Name: jtmeserole | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 14 Days
========== Processes (SafeList) ==========
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
PRC - C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
PRC - C:\Users\jtmeserole\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
PRC - C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
PRC - C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
PRC - C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
PRC - C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
PRC - C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\NCH Software\ExpressZip\ezcm.dll ()
========== Services (SafeList) ==========
SRV - (sftlist) – C:\Program Files\Microsoft Application Virtualization Client\sftlist.exe File not found
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (vsmon) – C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe (Check Point Software Technologies LTD)
SRV - (IswSvc) – C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe (Check Point Software Technologies)
SRV - (NSM) – C:\Program Files\Norton Family\Engine\2.6.0.43\ccSvcHst.exe (Symantec Corporation)
SRV - (Norton PC Checkup Application Launcher) – C:\Program Files\Norton PC Checkup 3.0\SymcPCCULaunchSvc.exe (Symantec Corporation)
SRV - (SkypeUpdate) – C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (ServicepointService) – C:\Program Files\Windstream\Service Agent\ServicepointService.exe (Radialpoint SafeCare Inc.)
SRV - (sftvsa) – C:\Program Files\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (UMVPFSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (PCCUJobMgr) – C:\Program Files\Norton PC Checkup\Engine\2.0.12.27\ccSvcHst.exe (Symantec Corporation)
SRV - (HsdService) – C:\Program Files\Windstream\Diagnostic Tools\HsdService.exe (Windstream)
SRV - (RosettaStoneDaemon) – C:\Program Files\RosettaStoneLtdServices\RosettaStoneDaemon.exe (Rosetta Stone Ltd.)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (AgereModemAudio) – C:\Program Files\LSI SoftModem\agrsmsvc.exe (LSI Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (NwlnkFwd) – system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) – system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) – system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) – C:\Users\JTMESE~1\AppData\Local\Temp\catchme.sys File not found
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswVmm) – C:\Windows\System32\drivers\aswVmm.sys ()
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswRvrt) – C:\Windows\System32\drivers\aswRvrt.sys ()
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (AswRdr) – C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Vsdatant) – C:\Windows\System32\drivers\vsdatant.sys (Check Point Software Technologies LTD)
DRV - (ISWKL) – C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys (Check Point Software Technologies)
DRV - (ccSet_NSM) – C:\Windows\System32\drivers\NSM\0206000.02B\ccSetx86.sys (Symantec Corporation)
DRV - (SCDEmu) – C:\Windows\System32\drivers\scdemu.sys (Power Software Ltd)
DRV - (Sftvol) – C:\Windows\System32\drivers\Sftvollh.sys (Microsoft Corporation)
DRV - (Sftredir) – C:\Windows\System32\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV - (Sftplay) – C:\Windows\System32\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV - (Sftfs) – C:\Windows\System32\drivers\Sftfslh.sys (Microsoft Corporation)
DRV - (LVUVC) – C:\Windows\System32\drivers\lvuvc.sys (Logitech Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (speedfan) – C:\Windows\System32\speedfan.sys (Almico Software)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corporation)
DRV - (USBCCID) – C:\Windows\System32\drivers\usbccid.sys (Microsoft Corporation)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (ElRawDisk) – C:\Windows\System32\drivers\rsdrv.sys (EldoS Corporation)
DRV - (nvrd32) – C:\Windows\System32\drivers\nvrd32.sys (NVIDIA Corporation)
DRV - (nvstor32) – C:\Windows\System32\drivers\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (MHIKEY10) – C:\Windows\System32\drivers\MHIKEY10.sys (Generic USB smartcard reader)
DRV - (nvsmu) – C:\Windows\System32\drivers\nvsmu.sys (NVIDIA Corporation)
DRV - (irsir) – C:\Windows\System32\drivers\irsir.sys (Microsoft Corporation)
DRV - (dsiarhwprog) – C:\Windows\System32\drivers\dsiarhwprog.sys (Thesycon GmbH, Germany)
DRV - (sscdserd) – C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (giveio) – C:\Windows\System32\giveio.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633ee93-d776-472f-a0ff-e1416b8b2e3a}
IE - HKLM\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://search.live.com/results.aspx?q={sea…amp;FORM=HPDTDF
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 98 7D 03 02 CE 6E E2 4D 9F 26 81 EE 65 AF 76 3D [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {C4E9144D-8269-4F50-B1BE-371B8170CF5A}
IE - HKCU\..\SearchScopes\{7EC2F961-F9C4-4F23-8885-C882FF51F8B2}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{C4E9144D-8269-4F50-B1BE-371B8170CF5A}: "URL" = http://www.google.com/search?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "www.google.com"
FF - prefs.js..browser.search.defaulturl: "Bing"
FF - prefs.js..browser.search.order.1: "Search By ZoneAlarm"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.ldsscripturemastery.net/en/"
FF - prefs.js..extensions.enabledAddons: %7Be001c731-5e37-4538-a5cb-8168736a2360%7D:0.9.9.119
FF - prefs.js..extensions.enabledAddons: hOUiT7au%40i0ixSKgctyasBk.com:11
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:21.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: [removed]:5.0.1
FF - prefs.js..extensions.enabledItems: [removed]:2.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems: {2D3F3651-74B9-4795-BDEC-6DA2F431CB62}:4.6
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:[removed]
FF - prefs.js..extensions.enabledItems: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115}:2.1.0.51
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@checkpoint.com/FFApi: C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\npFFApi.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Musicnotes.com/Musicnotes Viewer,version=1.18.9: C:\Program Files\Musicnotes\npmusicn.dll (Musicnotes, Inc.)
FF - HKLM\Software\MozillaPlugins\@radialpoint.com/SPA,version=1: C:\Program Files\Windstream\Service Agent\nprpspa.dll (Windstream)
FF - HKLM\Software\MozillaPlugins\@Sibelius.com/Scorch Plugin,version=6.2.0.88: C:\Program Files\Musicnotes\npsibelius.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6D5C8FC4-DE46-41bf-9092-93F0F78E9115}: C:\ProgramData\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.6.0.43\coFFFw\
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/05/25 22:30:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker [2013/05/25 23:04:46 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/05/24 14:07:05 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 21.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/24 14:06:57 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/03/28 10:30:49 | 000,000,000 | —D | M]
[2011/11/09 11:14:59 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Extensions
[2013/05/25 23:21:11 | 000,000,000 | —D | M] (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions
[2012/09/11 13:55:36 | 000,000,000 | —D | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2010/09/27 21:35:19 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/06/27 15:16:06 | 000,000,000 | —D | M] (Bitdefender QuickScan) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2013/03/24 13:46:03 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2013/05/25 23:21:06 | 000,000,000 | —D | M] (zonealarm.com) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2010/09/20 15:59:14 | 000,000,000 | —D | M] (KidZui) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/04/23 18:38:59 | 000,234,665 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/08/23 22:57:12 | 000,074,961 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2013/04/30 10:10:31 | 000,003,259 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2011/07/19 20:56:57 | 000,310,942 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]
[2012/12/17 12:34:28 | 000,222,578 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.xpi
[2013/02/19 19:19:26 | 000,685,671 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{ef4e370e-d9f0-4e00-b93e-a4f274cfdd5a}.xpi
[2013/01/23 05:46:58 | 000,007,919 | —- | M] () (No name found) – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\[removed]\content\Abine\chrome\content\ff\view_expiry.js
[2011/05/03 11:52:57 | 000,002,469 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\safesearch.xml
[2013/05/25 22:58:46 | 000,001,488 | —- | M] () – C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\searchplugins\zonealarm.xml
[2013/05/24 14:07:05 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\browser\extensions
[2013/05/24 14:07:05 | 000,000,000 | —D | M] (Default) – C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2012/08/14 10:09:55 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2010/03/31 11:09:22 | 010,437,264 | —- | M] (PDFTron Systems Inc.) – C:\Program Files\mozilla firefox\plugins\PDFNetC.dll
[2010/04/08 13:36:02 | 000,107,760 | —- | M] () – C:\Program Files\mozilla firefox\plugins\ScorchPDFWrapper.dll
[2012/06/18 17:44:09 | 000,003,749 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:in
s
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://isearch.avg.com/?cid={9BC737C8-EB9C…mp;d=2012-06-18 17:44:13&v;=11.1.0.7&sap;=hp
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Disabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\27.0.1453.94\pdf.dll
CHR - plugin: Norton Identity Safe (Enabled) = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.2.1.36_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Disabled) = C:\Program Files\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: CouponNetwork Coupon Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPcol400.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: ScorchPlugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPSibelius.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MI1933~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Earth Plugin (Disabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U11 (Enabled) = C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Musicnotes (Enabled) = C:\Program Files\Musicnotes\npmusicn.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windstream Service Agent (Enabled) = C:\Program Files\Windstream\Service Agent\nprpspa.dll
CHR - plugin: iTunes Application Detector (Disabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\jtmeserole\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: SOE Web Installer (Disabled) = C:\Users\jtmeserole\AppData\Roaming\Mozilla\Firefox\Profiles\tkucy2ap.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll
CHR - plugin: Java Deployment Toolkit 7.0.110.21 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Bejeweled = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: YouTube = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: WebFilter Pro - The best filtering addon! = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejgfoklefkbjadjcgjmnhfbdfjolojnn\0.19.6.12_0\
CHR - Extension: Stylish = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.1_0\
CHR - Extension: XKit = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpfgeeomkfdefkckijiabdbogjkdaecd\7.0.2_0\
CHR - Extension: avast! Online Security = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.6_0\
CHR - Extension: The Great Grass Sea Theme = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpghdlkjginnphhfpdccobkbncldkgmc\1.0_0\
CHR - Extension: Love Smoke = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0\
CHR - Extension: Typing Test - KeyHero = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkcieoaeooeidmpaopkpjpjfakidlabm\1.4.0_0\
CHR - Extension: Sketchpad = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lkllajgbhondgjjnhmmgbjndmogapinp\1.0.0.4_0\
CHR - Extension: Radialpoint SPD Extension = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmmhpfbhngkongobaoibpmnijjokabmj\1.0_0\
CHR - Extension: TumTaster = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\nanfbkacbckngfcklahdgfagjlghfbgm\0.4.9_0\
CHR - Extension: Tumblr Savior = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\oefddkjnflmjbclpnnoegglmmdfkidip\0.4.5_0\
CHR - Extension: Gmail = C:\Users\jtmeserole\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1\
O1 HOSTS File: ([2013/01/17 22:07:58 | 000,000,027 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (ZoneAlarm Security Engine Registrar) - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (ZoneAlarm Security Engine) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\Trustchecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DiagnosticTools.exe] C:\Program Files\Windstream\Diagnostic Tools\DiagnosticTools.exe (Windstream)
O4 - HKLM..\Run: [ISW] C:\Program Files\CheckPoint\ZAForceField\ForceField.exe (Check Point Software Technologies)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Windstream Service Agent.exe] C:\Program Files\Windstream\Service Agent\Windstream Service Agent.exe (Windstream)
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm] C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe (Check Point Software Technologies LTD)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Download all with Free Download Manager - C:\Program Files\Free Download Manager\dlall.htm ()
O8 - Extra context menu item: Download selected with Free Download Manager - C:\Program Files\Free Download Manager\dlselected.htm ()
O8 - Extra context menu item: Download video with Free Download Manager - C:\Program Files\Free Download Manager\dlfvideo.htm ()
O8 - Extra context menu item: Download with Free Download Manager - C:\Program Files\Free Download Manager\dllink.htm ()
O8 - Extra context menu item: E&xport; to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd; to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked; Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop.com/betapit/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {4B54A9DE-EF1C-4EBE-A328-7C28EA3B433A} http://quickscan.bitdefender.com/qsax/qsax.cab (BitDefender QuickScan Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitdefender.com/resources/…can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DC2E7865-5ADB-466A-9527-0EFA9B7FF184}: DhcpNameServer = 192.168.254.254
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\jtmeserole\AppData\Roaming\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2010/03/30 14:43:00 | 002,843,492 | R— | M] (Teaching Textbooks ) - E:\Autorun.exe – [ CDFS ]
O32 - AutoRun File - [2010/04/01 23:21:00 | 000,000,031 | R— | M] () - E:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.i420 - C:\Windows\System32\lvcodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 14 Days ==========
[2013/05/25 23:04:57 | 000,000,000 | —D | C] – C:\Users\jtmeserole\Documents\ForceField Shared Files
[2013/05/25 23:04:52 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\CheckPoint
[2013/05/25 23:02:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Check Point
[2013/05/25 23:00:54 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\netio.sys
[2013/05/25 22:58:43 | 000,000,000 | —D | C] – C:\Program Files\Check Point Software Technologies LTD
[2013/05/25 22:58:37 | 000,000,000 | —D | C] – C:\Users\jtmeserole\AppData\Roaming\Check Point Software Technologies LTD
[2013/05/25 22:58:33 | 000,000,000 | —D | C] – C:\Program Files\CheckPoint
[2013/05/25 22:57:34 | 000,000,000 | —D | C] – C:\ProgramData\CheckPoint
[2013/05/25 22:30:36 | 000,029,816 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2013/05/25 22:30:36 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2013/05/25 22:30:35 | 000,765,736 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSnx.sys
[2013/05/25 22:30:35 | 000,368,944 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswSP.sys
[2013/05/25 22:30:35 | 000,056,080 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswTdi.sys
[2013/05/25 22:30:35 | 000,049,760 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswRdr.sys
[2013/05/25 22:30:34 | 000,229,648 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2013/05/25 22:30:34 | 000,066,336 | —- | C] (AVAST Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2013/05/25 22:29:52 | 000,041,664 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2013/05/25 22:28:58 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2013/05/25 20:11:04 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2013/05/25 19:31:11 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2013/05/25 19:30:56 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\javaw.exe
[2013/05/25 19:30:56 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\System32\java.exe
[2013/05/25 19:30:56 | 000,094,112 | —- | C] (Oracle Corporation) – C:\Windows\System32\WindowsAccessBridge.dll
[2013/05/24 14:06:55 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/05/20 08:13:58 | 000,000,000 | —D | C] – C:\ProgramData\Wild Tangent
[2013/05/20 08:00:19 | 000,000,000 | —D | C] – C:\Program Files\WildTangent Games
[2013/05/16 01:15:29 | 002,382,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2013/05/16 01:00:46 | 000,607,744 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2013/05/16 01:00:46 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2013/05/16 01:00:46 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieUnatt.exe
[2013/05/16 01:00:46 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2013/05/16 01:00:45 | 001,800,704 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript9.dll
[2013/05/16 01:00:45 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2013/05/16 01:00:44 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\System32\inetcpl.cpl
[2012/03/26 10:22:17 | 035,113,704 | —- | C] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
========== Files - Modified Within 14 Days ==========
[2013/05/29 12:17:00 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/29 12:08:15 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/29 11:52:35 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/29 11:52:35 | 000,003,616 | —- | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/29 11:16:40 | 000,000,890 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/28 13:53:32 | 000,065,536 | —- | M] () – C:\Windows\System32\Ikeext.etl
[2013/05/28 13:52:33 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/05/26 18:56:46 | 000,604,946 | —- | M] () – C:\Windows\System32\perfh009.dat
[2013/05/26 18:56:46 | 000,104,388 | —- | M] () – C:\Windows\System32\perfc009.dat
[2013/05/25 23:07:43 | 000,417,507 | —- | M] () – C:\Windows\System32\drivers\vsconfig.xml
[2013/05/25 23:02:40 | 000,000,639 | —- | M] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2013/05/25 22:30:36 | 000,001,795 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/05/25 22:30:34 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2013/05/22 11:29:50 | 000,001,853 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2013/05/20 10:44:48 | 000,070,144 | —- | M] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/20 08:00:35 | 000,002,274 | —- | M] () – C:\Users\jtmeserole\Application Data\Microsoft\Internet Explorer\Quick Launch\WildTangent Games App - hp.lnk
[2013/05/20 08:00:34 | 000,002,242 | —- | M] () – C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
[2013/05/16 08:38:16 | 000,381,240 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2013/05/25 23:05:00 | 000,417,507 | —- | C] () – C:\Windows\System32\drivers\vsconfig.xml
[2013/05/25 23:02:40 | 000,000,639 | —- | C] () – C:\Users\Public\Desktop\ZoneAlarm Security.lnk
[2013/05/25 22:30:36 | 000,001,795 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2013/05/25 22:30:35 | 000,174,664 | —- | C] () – C:\Windows\System32\drivers\aswVmm.sys
[2013/05/25 22:30:35 | 000,049,376 | —- | C] () – C:\Windows\System32\drivers\aswRvrt.sys
[2013/05/20 08:00:32 | 000,002,274 | —- | C] () – C:\Users\jtmeserole\Application Data\Microsoft\Internet Explorer\Quick Launch\WildTangent Games App - hp.lnk
[2013/05/20 08:00:32 | 000,002,242 | —- | C] () – C:\Users\Public\Desktop\WildTangent Games App - hp.lnk
[2013/03/27 11:33:33 | 000,069,632 | —- | C] () – C:\Windows\System32\MobOlExt.dll
[2013/01/17 21:54:27 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2013/01/17 21:54:27 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2013/01/17 21:54:27 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2013/01/17 21:54:27 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2013/01/17 21:54:27 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/29 15:48:10 | 000,035,328 | —- | C] () – C:\Users\jtmeserole\01074461.XLT
[2012/09/04 20:29:20 | 000,019,456 | —- | C] () – C:\Users\jtmeserole\01026644.xlt
[2012/08/28 08:43:51 | 000,003,632 | —- | C] () – C:\Users\jtmeserole\profiles.xml
[2012/02/29 10:51:38 | 000,000,022 | —- | C] () – C:\Windows\WinInit.Ini
[2012/02/29 10:51:28 | 000,168,207 | —- | C] () – C:\Windows\System32\Unstall.exe
[2012/01/25 14:38:22 | 000,000,043 | —- | C] () – C:\Users\jtmeserole\Food Storage Planner-Path
[2011/08/20 16:04:22 | 000,150,004 | —- | C] () – C:\Windows\System32\mlfcache.dat
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\System32\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\System32\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\System32\LogiDPPApp.exe
[2011/08/17 18:30:51 | 000,000,115 | —- | C] () – C:\Users\jtmeserole\webct_upload_applet.properties
[2011/08/12 13:20:14 | 000,015,896 | —- | C] () – C:\Windows\System32\drivers\iKeyLFT2.dll
[2011/07/26 01:48:54 | 000,028,418 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/02/12 22:26:46 | 000,000,048 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/10/14 10:35:04 | 000,000,632 | RHS- | C] () – C:\Users\jtmeserole\ntuser.pol
[2010/09/25 19:46:40 | 000,070,144 | —- | C] () – C:\Users\jtmeserole\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/22 23:41:23 | 000,029,262 | —- | C] () – C:\Users\jtmeserole\AppData\Roaming\wklnhst.dat
[2010/09/20 13:18:13 | 000,001,356 | —- | C] () – C:\Users\jtmeserole\AppData\Local\d3d9caps.dat
========== ZeroAccess Check ==========
[2006/11/02 07:54:22 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/04/11 01:28:25 | 000,347,648 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2013/04/29 13:56:06 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.minecraft
[2011/09/23 11:48:03 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\.t4k_common
[2011/03/02 20:50:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\2monkeys
[2012/09/01 19:32:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Anuman
[2012/09/22 21:08:08 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Audacity
[2012/08/08 09:16:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Boolat Games
[2011/09/29 16:30:47 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Catalina Marketing Corp
[2013/05/25 22:58:37 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Check Point Software Technologies LTD
[2013/05/25 23:04:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\CheckPoint
[2011/05/30 17:30:34 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Chessmaster Challenge
[2012/08/13 21:26:06 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\EuroTalk
[2011/04/10 14:35:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Farm Mania 2.1
[2013/02/06 18:04:41 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Free Download Manager
[2011/01/24 21:48:39 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\freshgames
[2011/09/07 18:15:19 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Guitar Pro 6
[2013/03/12 13:35:30 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\KidZui
[2011/12/11 17:31:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Leadertech
[2011/03/03 13:06:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Mean Hamster
[2013/01/13 22:14:05 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Meridian93
[2011/03/01 11:52:31 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MSNInstaller
[2010/10/15 17:58:10 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusE
[2010/11/05 18:54:16 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\MusicNet
[2011/02/12 12:24:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\NCH Swift Sound
[2010/12/15 14:38:17 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Oberon Games
[2012/08/18 08:56:49 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Peace Craft
[2012/05/03 20:05:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\PlayFirst
[2013/01/14 16:43:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Playrix Entertainment
[2013/05/25 18:09:40 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\QuickScan
[2012/11/21 14:53:54 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Radialpoint
[2012/10/06 18:04:46 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\redsn0w
[2012/08/22 20:19:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Sandlot Games
[2012/02/27 16:38:58 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\School Zone Preferences
[2010/10/19 11:23:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Skunk Studios
[2012/02/28 11:30:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SoftGrid Client
[2013/04/10 14:24:59 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Stellarium
[2012/08/22 20:06:25 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\SulusGames
[2012/03/08 13:16:04 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Super-Cow
[2011/01/25 21:26:00 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Supermarket Mania 2
[2010/09/22 23:41:24 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Template
[2011/09/30 18:21:20 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Tific
[2012/03/01 18:12:26 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\TP
[2012/10/01 13:19:09 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\tuxmath
[2010/09/27 15:17:15 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Unity
[2013/05/20 08:00:52 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\WildTangent
[2012/01/17 21:37:53 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\Windstream
[2010/10/15 20:20:28 | 000,000,000 | —D | M] – C:\Users\jtmeserole\AppData\Roaming\YoudaGames
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.EXE >
[1995/04/25 02:00:00 | 000,969,792 | —- | M] () MD5=182749693EF4B3BE232EAC23BC68A448 – C:\HISTORY\EXPLORER.EXE
[2009/05/18 15:45:17 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2009/05/18 15:45:16 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2009/05/18 15:45:16 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\ERDNT\cache\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\explorer.exe
[2009/04/11 01:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2009/05/18 15:45:16 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2008/01/20 21:24:24 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe
< MD5 for: EXPLORER.EXE.3164.DMP >
[2013/01/17 21:48:36 | 003,469,158 | —- | M] () MD5=922F306FBA3C8D838F683FB1C74F171C – C:\Users\jtmeserole\AppData\Local\CrashDumps\explorer.exe.3164.dmp
< MD5 for: EXPLORER.EXE.MUI >
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\en-US\explorer.exe.mui
[2006/11/02 07:41:18 | 000,036,864 | —- | M] (Microsoft Corporation) MD5=192DD053B43250E264383CDC3D564A18 – C:\Windows\winsxs\x86_microsoft-windows-explorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_03bbc52176b6ba20\explorer.exe.mui
< MD5 for: EXPLORER.EXE-7A3328DA.PF >
[2013/05/28 14:01:41 | 000,169,548 | —- | M] () MD5=8AFDBD786D27AB62500E213E26EA90E5 – C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf
< MD5 for: EXPLORER.HLP >
[1995/04/25 02:00:00 | 000,571,344 | —- | M] () MD5=78B5A9803EBA4EA7CE1CCEEE76F5543E – C:\HISTORY\EXPLORER.HLP
< MD5 for: EXPLORER.INI >
[2012/03/09 12:21:51 | 000,000,467 | —- | M] () MD5=05C10B448D97CCD55D08AD8583583DEA – C:\HISTORY\EXPLORER.INI
< MD5 for: IEXPLORE.BAT >
[2013/01/04 15:58:30 | 000,031,067 | —- | M] () MD5=709A62B22C7BA09D875F765341E0FFFC – C:\JRT\iexplore.bat
< MD5 for: IEXPLORE.EXE >
[2012/05/17 18:21:54 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16446_none_5898f8e3ebb5c47b\iexplore.exe
[2011/07/23 06:02:27 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=04D1DC458C723B291179F8449ACC281D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19120_none_12355fcb2fdc2111\iexplore.exe
[2009/05/18 15:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=07ED775D6DB4BFA96D7CFB09EB228418 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16681_none_2d26424d1d17e8b7\iexplore.exe
[2009/05/18 15:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=0844F5B9CB3BB85A917D347EF1565B6C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16809_none_2d84c7c91ccfce35\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\ERDNT\cache\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16457_none_588f2941ebbcf9c3\iexplore.exe
[2011/09/30 18:49:11 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=0E1695AD4C30E72D68170F01B4818A80 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23250_none_129e8cd2491214ae\iexplore.exe
[2009/05/18 15:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=157F8DE991396C536820D7FA5C8DCF7D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16711_none_2d71f3a71cdf2247\iexplore.exe
[2009/05/18 15:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=182CAF7403705ACCB51211A761080B8F – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20777_none_2dc0b0c03628049a\iexplore.exe
[2009/05/18 15:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=19403B64906C9EAC627E3C10847B0FDA – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16757_none_2d4cb5b31cfa2a15\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16450_none_5888273bebc34862\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20551_none_5912c45104e00183\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16455_none_588d28adebbec715\iexplore.exe
[2011/11/03 02:33:09 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=2A268DF89913A0E927091077878EDB3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23266_none_1299bea24914c8a9\iexplore.exe
[2009/04/11 01:27:44 | 000,636,080 | —- | M] (Microsoft Corporation) MD5=2C5168C856455CC43C4B4E1CC1920001 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6002.18005_none_314d791517204c15\iexplore.exe
[2013/02/21 23:10:00 | 000,757,376 | —- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16476_none_5878891febce184e\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16447_none_5899f92debb4ddd2\iexplore.exe
[2013/04/04 17:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Program Files\Internet Explorer\iexplore.exe
[2013/04/04 17:47:49 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16483_none_586ab855ebd8e83a\iexplore.exe
[2013/02/21 23:10:31 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20586_none_58f755ff04f3d409\iexplore.exe
[2010/09/08 01:26:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4A719476A6393B1DCACFEB4F3AC6599C – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23067_none_129abb204913e7b2\iexplore.exe
[2009/05/18 15:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=4CBA2F58668F2D5F3259CBE73E227F25 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20937_none_2debf43c36078f24\iexplore.exe
[2011/07/23 06:42:34 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=4D08A4234D645EFCB30605CC0BFA87F4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23216_none_12cfce3e48ec3cf4\iexplore.exe
[2009/05/18 15:35:44 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=4DBD95312B1C96C5285D38F1D748CD4D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20868_none_2dcc82dc361eff27\iexplore.exe
[2011/12/15 02:36:29 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=54EF418BD99720658CCE24210799BD1A – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23286_none_12841eca4925008b\iexplore.exe
[2010/11/02 01:03:13 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=5AB037B17F8A87D052F5A88E0D29A3C8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18999_none_11f2d8e9300c984e\iexplore.exe
[2008/01/20 21:23:50 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=5B92133D3E7FB2644677686305E29E81 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18000_none_2f62000919fe80c9\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20557_none_5918c60d04da998d\iexplore.exe
[2009/05/18 15:40:03 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=6655B851D9EEF7C83395EE52D551B448 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20927_none_2df6c42835ff7333\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16464_none_58815877ebc7c9af\iexplore.exe
[2010/06/26 01:06:48 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7420BE0E7D3D1320054F7ACA0594953D – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18943_none_1222e6c92fe9748f\iexplore.exe
[2010/12/18 02:19:44 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7852371DA9EFBC17B645558E23780EAC – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23111_none_12cacae648f0c11a\iexplore.exe
[2011/09/30 18:07:49 | 000,638,216 | —- | M] (Microsoft Corporation) MD5=7ACBBC85FCE4989B533220FC3B291633 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19154_none_1218f12f2ff0da40\iexplore.exe
[2011/05/28 02:09:20 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=7EE10C5413AD7ED1AF9E8FAE1B58FC3E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23181_none_127f1b72492984b1\iexplore.exe
[2010/06/28 11:33:13 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=867D06F3C473F65921F5EDF35866FF14 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.22720_none_2fd60860332c475f\iexplore.exe
[2012/02/20 04:02:12 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16421_none_58a99749ebaa0de6\iexplore.exe
[2010/11/02 02:13:47 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=92A17B0A89D14815AACC62CD190B6CE3 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23091_none_127449a04931a37b\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16448_none_589af977ebb3f729\iexplore.exe
[2009/05/18 15:29:17 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9437CA21CD48C9B6BFD6F5AC0143D251 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16643_none_2d5382911cf5aba1\iexplore.exe
[2011/02/22 02:18:28 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=9CE5543464432CA73134F170FA2BF823 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23143_none_12ac5bb64907479b\iexplore.exe
[2009/05/18 15:30:20 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=9F1427F203CA078005C9943800929640 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20823_none_2df2c11a360310b0\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20580_none_58f1544304f93bff\iexplore.exe
[2011/12/15 01:22:33 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=AB18B8902C06954F8DFBAC5C6DC7E1E8 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19190_none_11e9b0573014e4a8\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2009/03/08 16:09:24 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18702_none_124d22632fc9f126\iexplore.exe
[2010/06/28 11:19:40 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B6D7D54B736056991109F169737592C7 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6001.18498_none_2f08baa51a403b96\iexplore.exe
[2010/12/18 01:28:35 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=B988D7F127B94BD5BF8356FE81B985C4 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19019_none_1249306b2fcbec08\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20553_none_5914c4e504de3431\iexplore.exe
[2013/04/04 16:55:02 | 000,757,360 | —- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20593_none_58e9853504fea3f5\iexplore.exe
[2011/02/22 01:21:12 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=C1D36A2CBE0CEC4DF593DB1288CF586E – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19048_none_1227c05d2fe52684\iexplore.exe
[2011/11/03 01:23:19 | 000,638,240 | —- | M] (Microsoft Corporation) MD5=CCDB0B2D1F2E016966B1DB1097E24842 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19170_none_11ff502f3004acc6\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20562_none_5908f4af04e736cb\iexplore.exe
[2010/09/08 01:02:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=D5A730DFDEAE005373E62BC2A866E3BB – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.18975_none_120477992ffffb10\iexplore.exe
[2009/05/18 15:43:57 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=D762642A109433EEDCD332B0A9511137 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.16764_none_2d3ee4e91d04fa01\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.16470_none_58728763ebd38044\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20554_none_5915c52f04dd4d88\iexplore.exe
[2011/05/28 01:09:21 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=ED65737D70FDEAC29F738E77D2496EE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.19088_none_11fc80ad30059648\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20573_none_58ff250d04ee6c13\iexplore.exe
[2010/06/26 01:52:42 | 000,638,232 | —- | M] (Microsoft Corporation) MD5=F05B3A2C6CB319DD1377AD566CF5ECE5 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_8.0.6001.23040_none_12a958f24909fe6f\iexplore.exe
[2009/05/18 15:49:59 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=F0B1CA517977BA2FF6DA33F1B966C488 – C:\Windows\winsxs\x86_microsoft-windows-ie-internetexplorer_31bf3856ad364e35_6.0.6000.20996_none_2daa146a36391d73\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\x86_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.1.8112.20565_none_590bf58d04e482d0\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2006/11/02 07:41:15 | 000,016,384 | —- | M] (Microsoft Corporation) MD5=3CCDDDBC49DEACA370F39A9F0E146A1B – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_6.0.6000.16386_en-us_3b55b11a57da5590\iexplore.exe.mui
[2012/02/20 04:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/02/20 04:02:13 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\x86_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.1.8112.16421_en-us_52562cc123574ecd\iexplore.exe.mui
[2009/03/08 16:27:11 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Windows\winsxs\x86_microsoft-windows-i..texplorer.resources_31bf3856ad364e35_8.0.6001.18702_en-us_207795706a90d6c1\iexplore.exe.mui
< MD5 for: SERVICES >
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\System32\drivers\etc\services
[2006/09/18 16:41:30 | 000,017,244 | —- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 – C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services
< MD5 for: SERVICES.DAT >
[2013/01/23 17:22:39 | 000,001,494 | —- | M] () MD5=82F6D657C1FF1C56102204E254445825 – C:\JRT\services.dat
< MD5 for: SERVICES.EXE >
[2008/01/20 21:24:48 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\ERDNT\cache\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\System32\services.exe
[2009/04/11 01:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 07:40:53 | 000,017,920 | —- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C – C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui
< MD5 for: SERVICES.LNK >
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2008/01/20 21:42:58 | 000,001,688 | —- | M] () MD5=C50AE46E57C3F3FB61A3B3A1E5D9C412 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\System32\wbem\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/18 16:46:11 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof
< MD5 for: SERVICES.MSC >
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\en-US\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\System32\services.msc
[2006/11/02 07:41:29 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/18 16:29:40 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc
< MD5 for: WINLOGON.EXE >
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\ERDNT\cache\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\System32\winlogon.exe
[2009/04/11 01:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/01/20 21:24:49 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\System32\en-US\winlogon.exe.mui
[2008/01/20 21:25:40 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=26AC28BF50DC112BAA794A83E08588F0 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6001.18000_en-us_caf8918b0416723a\winlogon.exe.mui
[2006/11/02 07:40:50 | 000,028,672 | —- | M] (Microsoft Corporation) MD5=A1D2856F3EC3C86EBBF1442B0245A8B3 – C:\Windows\winsxs\x86_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.0.6000.16386_en-us_c8c1cf8f072b6166\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-8163EECC.PF >
[2013/05/29 12:02:51 | 000,035,160 | —- | M] () MD5=0D36FE4A17D0C601487A8393A31106C8 – C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf
< MD5 for: WINLOGON.MOF >
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\System32\wbem\winlogon.mof
[2006/09/18 16:41:56 | 000,002,794 | —- | M] () MD5=545C578F290B9CDD280966939935B9EA – C:\Windows\winsxs\x86_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.0.6000.16386_none_7e0207d478fccc94\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2009/05/18 15:28:11 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2013/01/25 11:35:49 | 000,013,623 | —- | M] () – C:\ComboFix.txt
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2011/09/07 12:57:44 | 000,000,000 | —- | M] () – C:\FileRecovery.log
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2012/02/28 13:03:39 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2013/05/28 13:52:26 | 3399,237,632 | -HS- | M] () – C:\pagefile.sys
[2012/09/04 07:55:42 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_04.09.2012_07.55.37_log.txt
[2012/09/11 15:51:23 | 000,000,414 | —- | M] () – C:\TDSSKiller.2.5.15.0_11.09.2012_15.51.20_log.txt
[2013/05/25 18:43:38 | 000,069,442 | —- | M] () – C:\TDSSKiller.2.5.15.0_25.05.2013_18.43.05_log.txt
[2013/05/25 18:44:12 | 000,069,442 | —- | M] () – C:\TDSSKiller.2.5.15.0_25.05.2013_18.43.48_log.txt
[2013/01/14 14:06:33 | 000,259,570 | —- | M] () – C:\TDSSKiller.2.8.15.0_14.01.2013_13.01.19_log.txt
[2013/05/25 18:46:35 | 000,133,342 | —- | M] () – C:\TDSSKiller.2.8.15.0_25.05.2013_18.46.05_log.txt
[2012/09/04 07:57:29 | 000,132,120 | —- | M] () – C:\TDSSKiller.2.8.8.0_04.09.2012_07.56.29_log.txt
[2012/09/11 15:53:29 | 000,132,458 | —- | M] () – C:\TDSSKiller.2.8.8.0_11.09.2012_15.52.06_log.txt
[2009/05/18 15:31:49 | 000,000,349 | —- | M] () – C:\updatedatfix.log
[2008/08/26 07:37:52 | 000,000,458 | —- | M] () – C:\Windows Sidebar
< %systemroot%\Fonts\*.com >
[2006/11/02 07:37:12 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 07:37:12 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 07:37:12 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2010/12/21 12:24:56 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:37:34 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/04/20 12:23:48 | 000,315,904 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\hpfpp70w.dll
[2008/01/20 21:23:14 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2006/11/02 07:35:48 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2006/10/26 20:56:12 | 000,033,104 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2013/05/09 03:58:37 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 21:43:21 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2008/01/20 22:14:18 | 016,846,848 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2008/01/20 22:14:08 | 000,106,496 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2008/01/20 22:14:18 | 000,020,480 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/05/20 08:00:33 | 000,000,434 | -HS- | M] () – C:\Users\jtmeserole\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/08/20 15:55:47 | 000,050,688 | —- | M] (Atribune.org) – C:\Users\jtmeserole\Desktop\ATF_Cleaner.exe
[2013/01/25 11:19:27 | 005,026,656 | R— | M] (Swearware) – C:\Users\jtmeserole\Desktop\ComboFix.exe
[2012/11/22 13:09:15 | 000,866,592 | —- | M] () – C:\Users\jtmeserole\Desktop\Norton_Removal_Tool.exe
[2013/01/22 22:22:25 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\jtmeserole\Desktop\OTL.exe
[2013/01/14 14:00:32 | 002,213,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\jtmeserole\Desktop\TDSSKiller.exe
< %PROGRAMFILES%\Common Files\*.* >
[2012/03/26 10:22:17 | 035,113,704 | —- | M] (Microsoft Corporation) – C:\Program Files\Common Files\directx_9c_redist.exe
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2013-05-28 13:23:35
========== Alternate Data Streams ==========
@Alternate Data Stream - 207 bytes -> C:\ProgramData\Temp:10D98D98
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:A1D3FEF0
@Alternate Data Stream - 206 bytes -> C:\ProgramData\Temp:1663E41B
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:9CF728A6
< End of report >