Thank you very much, Maurice! My computer is running faster, and I haven't been redirected yet (at least this morning)! I did have some questions: Could this have infected my other PC via my wireless network? Is there a way to prevent this happening again (especially since Trend Micro doesn't even have Happili in its virus database)? Is Chrome more prone to this than IE? I wonder if it's a coincidence that I got this right after installing Chrome.
Thanks again - I know you're doing this as a volunteer, and I appreciate it. Here are the logs:
OTL logfile created on: 5/3/2012 4:26:52 AM - Run 2
OTL by OldTimer - Version 3.2.42.2 Folder = C:\Users\Raisa\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19222)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.99 Gb Total Physical Memory | 1.42 Gb Available Physical Memory | 47.32% Memory free
6.21 Gb Paging File | 4.61 Gb Available in Paging File | 74.27% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.29 Gb Total Space | 203.82 Gb Free Space | 70.70% Space Free | Partition Type: NTFS
Drive D: | 9.77 Gb Total Space | 4.52 Gb Free Space | 46.24% Space Free | Partition Type: NTFS
Computer Name: LAPTOP | User Name: Raisa | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\Raisa\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
PRC - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
PRC - C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
PRC - C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
PRC - C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApntEx.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.)
PRC - C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
PRC - C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
========== Modules (No Company Name) ========== MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\48302596a8c8f2ab396b3be518dbd800\System.Web.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\09b9cd1c630210237b5b46d9943e1946\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\61759b9905aed9a87347d04b5fad046b\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\5c3bfd69e0c268baff0d169e11a6a784\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7fd6c62196829d1e2dce5a253145d51a\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d9f0f1dc8cbdb81f1ba122d77a6ab710\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\c50133cb67d7c013fa31e1ffb942060b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\bcb66dbad2b45d05235b37a02f737eb5\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3106.38542__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3106.38494__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3106.38558__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3106.38756__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3106.38533__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3106.38664__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3106.38517__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3106.38798__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3106.38714__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3106.38724__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3106.38795__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3106.38805__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3106.38731__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3106.38510__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3106.38723__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3106.38795__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3106.38668__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3106.38573__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.3106.38519__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3106.38746__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3106.38565__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3106.38689__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3106.38667__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3106.38578__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3106.38687__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Dashboard\2.0.3106.38657__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3106.38706__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3106.38666__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3106.38579__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3106.38665__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3106.38667__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3106.38704__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3091.17968__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3091.17961__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3091.17980__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3091.18004__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3091.17978__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3091.18004__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3091.17957__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3091.17970__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3091.18001__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3091.17954__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3091.17956__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3091.18035__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.3091.17981__90ba9c70f846762e\DEM.OS.I0602.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3091.17970__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3091.17968__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3091.17961__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3091.17977__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.3091.17980__90ba9c70f846762e\DEM.OS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3091.17981__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3091.17967__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3091.17987__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3091.17982__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3091.17993__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3091.17992__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3091.17990__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3091.17990__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3091.17990__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3091.17992__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3091.17976__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3091.18001__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3091.17988__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3091.17982__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3091.17979__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3091.17991__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3091.17983__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.3091.17977__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3091.17968__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3106.38822__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Implementation\2.0.3106.38837__90ba9c70f846762e\LOCALIZATION.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3106.38526__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3106.38785__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3106.38782__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3106.38488__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3106.38485__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3091.17979__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3091.17961__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3091.17965__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3091.17978__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3091.17977__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3091.17977__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\LOCALIZATION.Foundation.Private\2.0.3091.17963__90ba9c70f846762e\LOCALIZATION.Foundation.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AxInterop.WBOCXLib\1.0.0.0__90ba9c70f846762e\AxInterop.WBOCXLib.dll ()
MOD - C:\Windows\assembly\GAC\Interop.WBOCXLib\1.0.0.0__90ba9c70f846762e\Interop.WBOCXLib.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3106.38485__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3106.38503__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.3106.38486__90ba9c70f846762e\ATIDEMOS.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.3106.38482__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.3106.38484__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3091.17970__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3106.38784__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3091.17993__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\Windows\System32\bcmwlrmt.dll ()
MOD - C:\Windows\System32\atitmmxx.dll ()
========== Win32 Services (SafeList) ========== SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Akamai) -- c:\program files\common files\akamai/netsession_win_6c825ce.dll ()
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (GoToAssist) -- C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (BBSvc) -- C:\Program Files\Microsoft\BingBar\BBSvc.EXE (Microsoft Corporation.)
SRV - (SeaPort) -- C:\Program Files\Microsoft\BingBar\SeaPort.EXE (Microsoft Corporation)
SRV - (SfCtlCom) -- C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe ()
SRV - (TmProxy) -- C:\Program Files\Trend Micro\Internet Security\TmProxy.exe ()
SRV - (TmPfw) -- C:\Program Files\Trend Micro\Internet Security\TmPfw.exe ()
SRV - (TMBMServer) -- C:\Program Files\Trend Micro\BM\TMBMSRV.exe ()
SRV - (STacSV) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\stacsv.exe (IDT, Inc.)
SRV - (AESTFilters) -- C:\Windows\System32\DriverStore\FileRepository\stwrt.inf_f6ef8056\AEstSrv.exe (Andrea Electronics Corporation)
SRV - (Creative Labs Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe (Creative Labs)
SRV - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (DockLoginService) -- C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (MSSQL$SONY_MEDIAMGR) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe (Microsoft Corporation)
SRV - (SQLAgent$SONY_MEDIAMGR) -- C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE (Microsoft Corporation)
========== Driver Services (SafeList) ========== DRV - (NwlnkFwd) -- system32\DRIVERS\nwlnkfwd.sys File not found
DRV - (NwlnkFlt) -- system32\DRIVERS\nwlnkflt.sys File not found
DRV - (IpInIp) -- system32\DRIVERS\ipinip.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (MBAMSwissArmy) -- C:\Windows\System32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (PCDSRVC{E9D79540-57D5953E-06020101}_0) -- c:\Program Files\Dell Support Center\pcdsrvc.pkms (PC-Doctor, Inc.)
DRV - (tmxpflt) -- C:\Windows\System32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) -- C:\Windows\System32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) -- C:\Windows\System32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (tmactmon) -- C:\Windows\System32\DRIVERS\tmactmon.sys ()
DRV - (tmevtmgr) -- C:\Windows\System32\DRIVERS\tmevtmgr.sys ()
DRV - (tmcomm) -- C:\Windows\System32\DRIVERS\tmcomm.sys ()
DRV - (tmwfp) -- C:\Windows\System32\drivers\tmwfp.sys (Trend Micro Inc.)
DRV - (tmtdi) -- C:\Windows\System32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (tmlwf) -- C:\Windows\System32\drivers\tmlwf.sys (Trend Micro Inc.)
DRV - (itecir) -- C:\Windows\System32\drivers\itecir.sys (ITE Tech. Inc. )
DRV - (STHDA) -- C:\Windows\System32\drivers\stwrt.sys (IDT, Inc.)
DRV - (OA001Vid) -- C:\Windows\System32\drivers\OA001Vid.sys (Creative Technology Ltd.)
DRV - (OA001Ufd) -- C:\Windows\System32\drivers\OA001Ufd.sys (Creative Technology Ltd.)
DRV - (WinDriver6) -- C:\Windows\System32\drivers\windrvr6.sys (Jungo)
DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (BCM42RLY) -- C:\Windows\System32\drivers\bcm42rly.sys (Broadcom Corporation)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (atikmdag) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (ApfiltrService) -- C:\Windows\System32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (rismxdp) -- C:\Windows\System32\drivers\rixdptsk.sys (REDC)
DRV - (rimmptsk) -- C:\Windows\System32\drivers\rimmptsk.sys (REDC)
DRV - (rimsptsk) -- C:\Windows\System32\drivers\rimsptsk.sys (REDC)
DRV - (k57nd60x) Broadcom NetLink -- C:\Windows\System32\drivers\k57nd60x.sys (Broadcom Corporation)
DRV - (e1express) Intel® -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (SNP2STD) -- C:\Windows\System32\drivers\snp2sxp.sys ()
DRV - (sscdserd) SAMSUNG CDMA Modem Diagnostic Serial Port (WDM) -- C:\Windows\System32\drivers\sscdserd.sys (MCCI)
DRV - (sscdmdm) -- C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) -- C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) -- C:\Windows\System32\drivers\sscdbus.sys (MCCI)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" =
http://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&query={searchTerms}&invocationType=tb50-ie-aim-chromesbox-en-usIE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DKUS IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://news.google.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\..\SearchScopes,DefaultScope = {50E569B9-FC1A-46DD-9D42-9690FC5FDFA2}
IE - HKCU\..\SearchScopes\{0B4A10D1-FBD6-451d-BFDA-F03252B05984}: "URL" =
http://slirsredirect.search.aol.com/redirector/sredir?sredir=2706&query={searchTerms}&invocationType=tb50-ie-aim-chromesbox-en-usIE - HKCU\..\SearchScopes\{50E569B9-FC1A-46DD-9D42-9690FC5FDFA2}: "URL" =
http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8&rlz=1I7DLUS_enIE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DKUSIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=15.0.2.72: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=15.0.2.72: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.2.72: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=15.0.2.72: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Raisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2012/04/05 14:28:30 | 000,000,000 | ---D | M]
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files\Google\Chrome\Application\18.0.1025.168\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.8 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\ZoomBrowser EX\Program\NPCIG.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Raisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Raisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\Raisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Raisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Gmail = C:\Users\Raisa\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/04/29 20:12:59 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Bing Bar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Bing Bar) - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray.exe (IDT, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UfSeAgnt.exe] C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe ()
O4 - HKLM..\Run: [WPCUMI] C:\Windows\System32\wpcumi.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: UseDefaultTile = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLogOff = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableChangePassword = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableLockWorkstation = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O9 - Extra Button: Add to Wish List - {76c5fb99-dd0a-4186-9e75-65d1bf3da283} - C:\Program Files\Amazon\Add to Wish List IE Extension\run.htm ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\System32\wpclsp.dll (Microsoft Corporation)
O15 - HKCU\..Trusted Domains: sneent.com ([emr] https in Trusted sites)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}
https://carelink.minimed.com/plugin/jinstall-1_5_0_11-windows-i586.cab (Java Plug-in 1.5.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_11-windows-i586.cab (Java Plug-in 1.6.0_11)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C52ED867-66A2-44D8-B887-D42A31A5BCDD}: DhcpNameServer = 68.105.28.11 68.105.29.11 68.105.28.12
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files\Citrix\GoToAssist\615\G2AWinLogon.dll) - C:\Program Files\Citrix\GoToAssist\615\g2awinlogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O24 - Desktop WallPaper: C:\Users\Raisa\Pictures\plonsky pix\procrasination meter.jpg
O24 - Desktop BackupWallPaper: C:\Users\Raisa\Pictures\plonsky pix\procrasination meter.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Camera Monitor SD.lnk - C:\Program Files\PIXELA\Everio MediaBrowser\MBCameraMonitor.exe - (PIXELA CORPORATION)
MsConfig - StartUpFolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe - (Logitech, Inc.)
MsConfig - StartUpFolder: C:^Users^Raisa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.1.lnk - C:\Program Files\OpenOffice.org 3\program\quickstart.exe - ()
MsConfig - StartUpReg:
Adobe ARM - hkey= - key= - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
MsConfig - StartUpReg:
Akamai NetSession Interface - hkey= - key= - C:\Users\Raisa\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
MsConfig - StartUpReg:
CanonMyPrinter - hkey= - key= - C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
MsConfig - StartUpReg:
CanonSolutionMenu - hkey= - key= - C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
MsConfig - StartUpReg:
Creative MediaSource Go - hkey= - key= - C:\Program Files\Creative\MediaSource5\Go\CTCMSGoU.exe (Creative Technology Ltd)
MsConfig - StartUpReg:
CvtmapSnap - hkey= - key= - File not found
MsConfig - StartUpReg:
Dell Webcam Central - hkey= - key= - C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe (Creative Technology Ltd.)
MsConfig - StartUpReg:
ehTray.exe - hkey= - key= - C:\Windows\ehome\ehtray.exe (Microsoft Corporation)
MsConfig - StartUpReg:
Facebook Update - hkey= - key= - C:\Users\Raisa\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
MsConfig - StartUpReg:
fssui - hkey= - key= - C:\Program Files\Windows Live\Family Safety\fsui.exe (Microsoft Corporation)
MsConfig - StartUpReg:
IJNetworkScanUtility - hkey= - key= - C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (CANON INC.)
MsConfig - StartUpReg:
iTunesHelper - hkey= - key= - C:\Program Files\iTunes\iTunesHelper.exe (Apple Inc.)
MsConfig - StartUpReg:
Kernel and Hardware Abstraction Layer - hkey= - key= - C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
MsConfig - StartUpReg:
msnmsgr - hkey= - key= - C:\Program Files\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
MsConfig - StartUpReg:
OA001Cfg.exe - hkey= - key= - C:\Windows\OA001Cfg.exe (Creative Technology Ltd.)
MsConfig - StartUpReg:
OE - hkey= - key= - C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
MsConfig - StartUpReg:
PCMService - hkey= - key= - C:\Program Files\Dell\MediaDirect\PCMService.exe (CyberLink Corp.)
MsConfig - StartUpReg:
QuickTime Task - hkey= - key= - C:\Program Files\QuickTime\QTTask.exe (Apple Inc.)
MsConfig - StartUpReg:
SightSpeed - hkey= - key= - C:\Program Files\Dell Video Chat\DellVideoChat.exe (Dell Inc. and SightSpeed Inc.)
MsConfig - StartUpReg:
snp2std - hkey= - key= - C:\Windows\vsnp2std.exe (Sonix)
MsConfig - StartUpReg:
UpdReg - hkey= - key= - C:\Windows\Updreg.EXE (Creative Technology Ltd.)
MsConfig - StartUpReg:
Windows Defender - hkey= - key= - File not found
MsConfig - StartUpReg:
WMPNSCFG - hkey= - key= - C:\Program Files\Windows Media Player\wmpnscfg.exe (Microsoft Corporation)
MsConfig - StartUpReg:
WPCUMI - hkey= - key= - File not found
MsConfig - State: "startup" - 2
MsConfig - State: "services" - 2
SafeBootMin: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootMin: Base - Driver Group
SafeBootMin: Boot Bus Extender - Driver Group
SafeBootMin: Boot file system - Driver Group
SafeBootMin: File system - Driver Group
SafeBootMin: Filter - Driver Group
SafeBootMin: HelpSvc - Service
SafeBootMin: NTDS - File not found
SafeBootMin: PCI Configuration - Driver Group
SafeBootMin: PNP Filter - Driver Group
SafeBootMin: Primary disk - Driver Group
SafeBootMin: sacsvr - Service
SafeBootMin: SCSI Class - Driver Group
SafeBootMin: System Bus Extender - Driver Group
SafeBootMin: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootMin: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootMin: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootMin: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootMin: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootMin: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootMin: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootMin: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootMin: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootMin: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootMin: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootMin: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootMin: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootMin: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootMin: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootMin: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootMin: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootMin: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
SafeBootNet: AppMgmt - %SystemRoot%\System32\appmgmts.dll File not found
SafeBootNet: Base - Driver Group
SafeBootNet: Boot Bus Extender - Driver Group
SafeBootNet: Boot file system - Driver Group
SafeBootNet: File system - Driver Group
SafeBootNet: Filter - Driver Group
SafeBootNet: GoToAssist - C:\Program Files\Citrix\GoToAssist\615\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SafeBootNet: HelpSvc - Service
SafeBootNet: Messenger - Service
SafeBootNet: NDIS Wrapper - Driver Group
SafeBootNet: NetBIOSGroup - Driver Group
SafeBootNet: NetDDEGroup - Driver Group
SafeBootNet: Network - Driver Group
SafeBootNet: NetworkProvider - Driver Group
SafeBootNet: NTDS - File not found
SafeBootNet: PCI Configuration - Driver Group
SafeBootNet: PNP Filter - Driver Group
SafeBootNet: PNP_TDI - Driver Group
SafeBootNet: Primary disk - Driver Group
SafeBootNet: rdsessmgr - Service
SafeBootNet: sacsvr - Service
SafeBootNet: SCSI Class - Driver Group
SafeBootNet: Streams Drivers - Driver Group
SafeBootNet: System Bus Extender - Driver Group
SafeBootNet: TDI - Driver Group
SafeBootNet: WinDefend - C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SafeBootNet: WudfPf - Driver
SafeBootNet: WudfUsbccidDriver - Driver
SafeBootNet: {36FC9E60-C465-11CF-8056-444553540000} - Universal Serial Bus controllers
SafeBootNet: {4D36E965-E325-11CE-BFC1-08002BE10318} - CD-ROM Drive
SafeBootNet: {4D36E967-E325-11CE-BFC1-08002BE10318} - DiskDrive
SafeBootNet: {4D36E969-E325-11CE-BFC1-08002BE10318} - Standard floppy disk controller
SafeBootNet: {4D36E96A-E325-11CE-BFC1-08002BE10318} - Hdc
SafeBootNet: {4D36E96B-E325-11CE-BFC1-08002BE10318} - Keyboard
SafeBootNet: {4D36E96F-E325-11CE-BFC1-08002BE10318} - Mouse
SafeBootNet: {4D36E972-E325-11CE-BFC1-08002BE10318} - Net
SafeBootNet: {4D36E973-E325-11CE-BFC1-08002BE10318} - NetClient
SafeBootNet: {4D36E974-E325-11CE-BFC1-08002BE10318} - NetService
SafeBootNet: {4D36E975-E325-11CE-BFC1-08002BE10318} - NetTrans
SafeBootNet: {4D36E977-E325-11CE-BFC1-08002BE10318} - PCMCIA Adapters
SafeBootNet: {4D36E97B-E325-11CE-BFC1-08002BE10318} - SCSIAdapter
SafeBootNet: {4D36E97D-E325-11CE-BFC1-08002BE10318} - System
SafeBootNet: {4D36E980-E325-11CE-BFC1-08002BE10318} - Floppy disk drive
SafeBootNet: {50DD5230-BA8A-11D1-BF5D-0000F805F530} - Smart card readers
SafeBootNet: {533C5B84-EC70-11D2-9505-00C04F79DEAF} - Volume shadow copy
SafeBootNet: {6BDD1FC1-810F-11D0-BEC7-08002BE2092F} - IEEE 1394 Bus host controllers
SafeBootNet: {71A27CDD-812A-11D0-BEC7-08002BE2092F} - Volume
SafeBootNet: {745A17A0-74D3-11D0-B6FE-00A0C90F57DA} - Human Interface Devices
SafeBootNet: {D48179BE-EC20-11D1-B6B8-00C04FA372A7} - SBP2 IEEE 1394 Devices
SafeBootNet: {D94EE5D8-D189-4994-83D2-F68D7D41B0E6} - SecurityDevices
ActiveX: {08B0E5C0-4FCB-11CF-AAA5-00401C608500} - Java (Sun)
ActiveX: {2179C5D3-EBFF-11CF-B6FD-00AA00B4E220} -
ActiveX: {22d6f312-b0f6-11d0-94ab-0080c74c7e95} - Microsoft Windows Media Player 11.0
ActiveX: {2C7339CF-2B09-4501-B3F3-F3508C9228ED} - %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
ActiveX: {3af36230-a269-11d1-b5bf-0000f8051515} - Offline Browsing Pack
ActiveX: {44BBA840-CC51-11CF-AAFA-00AA00B6015C} - "%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOE
ActiveX: {44BBA848-CC51-11CF-AAFA-00AA00B6015C} -
ActiveX: {44BBA855-CC51-11CF-AAFA-00AA00B6015F} - DirectDrawEx
ActiveX: {45ea75a0-a269-11d1-b5bf-0000f8051515} - Internet Explorer Help
ActiveX: {4f645220-306d-11d2-995d-00c04f98bbc9} - Microsoft Windows Script 5.8
ActiveX: {5fd399c0-a70a-11d1-9948-00c04f98bbc9} - Internet Explorer Setup Tools
ActiveX: {630b1da0-b465-11d1-9948-00c04f98bbc9} - Browsing Enhancements
ActiveX: {6BF52A52-394A-11d3-B153-00C04F79FAA6} - Microsoft Windows Media Player
ActiveX: {6fab99d0-bab8-11d1-994a-00c04f98bbc9} - MSN Site Access
ActiveX: {7790769C-0471-11d2-AF11-00C04FA35D02} - Address Book 7
ActiveX: {7C028AF8-F614-47B3-82DA-BA94E41B1089} - .NET Framework
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4340} - regsvr32.exe /s /n /i:U shell32.dll
ActiveX: {89820200-ECBD-11cf-8B85-00AA005B4383} - C:\Windows\system32\ie4uinit.exe -BaseSettings
ActiveX: {89B4C1CD-B018-4511-B0A1-5476DBF70820} - C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,Install
ActiveX: {9381D8F2-0288-11D0-9501-00AA00B911A5} - Dynamic HTML Data Binding
ActiveX: {C9E9A340-D1F1-11D0-821E-444553540600} - Internet Explorer Core Fonts
ActiveX: {CDD7975E-60F8-41d5-8149-19E51D6F71D0} - Windows Movie Maker v2.1
ActiveX: {D27CDB6E-AE6D-11CF-96B8-444553540000} - Adobe Flash Player
ActiveX: {de5aed00-a4bf-11d1-9948-00c04f98bbc9} - HTML Help
ActiveX: {E92B03AB-B707-11d2-9CBD-0000F87A369E} - Active Directory Service Interface
ActiveX: >{22d6f312-b0f6-11d0-94ab-0080c74c7e95} - C:\Windows\system32\unregmp2.exe /ShowWMP
ActiveX: >{26923b43-4d38-484f-9b9e-de460746276c} - C:\Windows\system32\ie4uinit.exe -UserIconConfig
ActiveX: >{60B49E34-C7CC-11D0-8953-00A0C90347FF} - "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: VIDC.CFHD - C:\Windows\System32\cfhd.dll (CineForm Inc.)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
CLEARALLRESTOREPOINTS
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ========== [2012/05/02 22:06:13 | 000,040,776 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/05/02 22:06:08 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Roaming\Malwarebytes
[2012/05/02 22:05:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/05/02 22:05:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/05/02 22:05:47 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/05/02 22:05:47 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/05/02 21:44:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2012/05/02 21:44:41 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2012/05/02 21:36:49 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{F1D34425-489B-4D17-A69B-B0D47B867AF5}
[2012/05/02 21:36:29 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{1809CBAD-098A-49A9-9A7D-E85C63DFDA60}
[2012/05/02 06:45:32 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{F745CAF3-C5EA-4884-965C-E531599C2D70}
[2012/05/02 06:45:08 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{568193C9-A2E4-4CCE-91AB-00BD6E042C23}
[2012/05/01 21:58:14 | 000,000,000 | ---D | C] -- C:\Windows\Minidump
[2012/04/30 08:34:42 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{4520CDC5-1920-4AA2-89A2-E908C65C1628}
[2012/04/30 08:34:20 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{CFD1F31A-1879-4097-9BE8-F7AED4F5D798}
[2012/04/29 22:30:37 | 000,595,456 | ---- | C] (OldTimer Tools) -- C:\Users\Raisa\Desktop\OTL.exe
[2012/04/29 21:48:29 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012/04/29 21:48:29 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012/04/29 21:48:29 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012/04/29 20:41:27 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{FC460ED1-FE99-43D4-A155-2B7A4F1A315F}
[2012/04/29 20:41:06 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{060CE995-E820-4663-A385-5C124EBB6BF5}
[2012/04/29 20:21:05 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/04/29 20:21:04 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\temp
[2012/04/29 20:13:06 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2012/04/29 19:18:18 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/04/29 19:18:18 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/04/29 19:18:18 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/04/29 19:18:07 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/04/29 19:18:01 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/04/29 19:05:56 | 004,479,463 | R--- | C] (Swearware) -- C:\Users\Raisa\Desktop\ComboFix.exe
[2012/04/29 18:52:24 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{59588D29-E76C-4AE4-88F8-55EE5677D201}
[2012/04/29 18:52:02 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{0BCFB25C-F5D5-49D0-8CB1-872DFC0BC1D9}
[2012/04/29 16:50:23 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{1F383E8F-0AA5-4F5C-8F0A-8BABE9FDA407}
[2012/04/28 12:32:41 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{B8DC2105-1604-4DDF-BF2C-1F2707A01A0D}
[2012/04/28 12:32:08 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{E7E51456-4256-42EB-9171-822F973275B4}
[2012/04/26 14:41:04 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{EC287E2A-C0C0-43F2-BFA2-5F0AB090153C}
[2012/04/26 14:40:32 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{D73033B4-F1F4-4E49-8583-A167C0581B81}
[2012/04/22 10:58:49 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{5F585D4A-EFDD-4D90-AF25-222A517EDEBD}
[2012/04/22 10:58:28 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{E14C1AAC-6760-4A2E-BE54-1955B8816B36}
[2012/04/20 21:49:13 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{C9B9B6FA-E3CB-4300-BC6B-0455D8D01E49}
[2012/04/20 21:48:51 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{D81F8046-8052-4AFC-8FB8-E980E24B743A}
[2012/04/20 21:31:19 | 000,237,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2012/04/18 06:44:25 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{FCDA8597-4FC8-4E30-B6FD-FB5454BBDBB1}
[2012/04/18 06:43:41 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{AF3D802D-C5BA-4947-9F7D-AFF4891EE2FA}
[2012/04/17 19:49:28 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\America Online
[2012/04/17 19:48:22 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2012/04/12 07:14:27 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{CE5E1F48-D450-46A5-8EC2-EA46897FC09B}
[2012/04/12 07:14:07 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{7EC69160-2692-4801-A4FA-71852B15F1FB}
[2012/04/11 07:14:43 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{A6C4044F-0159-4368-BB14-1A8871C9E186}
[2012/04/11 07:14:23 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{6B3B2637-B96C-4061-AD45-99FDB23139A7}
[2012/04/10 23:10:01 | 000,105,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/04/10 23:10:01 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/04/10 23:09:59 | 001,469,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/04/10 23:09:59 | 000,602,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2012/04/10 23:09:58 | 000,611,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mstime.dll
[2012/04/10 23:09:58 | 000,387,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2012/04/10 23:09:58 | 000,385,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\html.iec
[2012/04/10 23:09:58 | 000,184,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iepeers.dll
[2012/04/10 23:09:58 | 000,164,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/04/10 23:09:58 | 000,109,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesysprep.dll
[2012/04/10 23:09:57 | 000,133,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/04/10 23:09:57 | 000,071,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iesetup.dll
[2012/04/10 23:09:56 | 000,174,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2012/04/10 23:09:56 | 000,055,808 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iernonce.dll
[2012/04/10 23:09:56 | 000,055,296 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedsbs.dll
[2012/04/10 23:09:56 | 000,043,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\licmgr10.dll
[2012/04/10 23:09:55 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/04/10 23:09:55 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeedssync.exe
[2012/04/08 22:04:42 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2012/04/08 22:04:34 | 000,106,496 | ---- | C] (Zenographics, Inc.) -- C:\Windows\System32\ZSPOOL.DLL
[2012/04/08 22:04:34 | 000,102,400 | ---- | C] (Zenographics, Inc.) -- C:\Windows\System32\ZLhp1018.DLL
[2012/04/08 22:04:34 | 000,061,440 | ---- | C] (Zenographics, Inc.) -- C:\Windows\System32\ZIMF.DLL
[2012/04/08 22:04:34 | 000,053,248 | ---- | C] (Zenographics, Inc.) -- C:\Windows\System32\ZTAG.DLL
[2012/04/08 08:28:05 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{A86DCF82-84BE-42E2-82DB-582962669A27}
[2012/04/08 08:27:23 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{9481B48C-7A9E-4650-A31C-E78881EEE6D9}
[2012/04/08 08:26:23 | 000,418,464 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/04/05 14:28:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2012/04/05 14:28:19 | 000,198,832 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012/04/05 14:28:07 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012/04/05 14:28:07 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012/04/05 14:28:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real
[2012/04/05 14:28:05 | 000,272,896 | ---- | C] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012/04/05 14:27:46 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2012/04/05 14:27:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Real
[2012/04/05 14:27:41 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Roaming\Real
[2012/04/05 13:36:34 | 000,000,000 | ---D | C] -- C:\Program Files\Dell Support Center
[2012/04/05 07:06:12 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{60B17262-2705-4363-91E1-09CCD3362510}
[2012/04/05 07:05:30 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{2EBA368E-7687-420E-AB0C-88DFCD8BD3D0}
[2012/04/03 20:36:12 | 000,000,000 | ---D | C] -- C:\Users\Raisa\AppData\Local\{5731207B-0B5E-405D-9560-5B6D8A496AE7}
========== Files - Modified Within 30 Days ========== [2012/05/03 04:27:00 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/05/03 04:24:13 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/05/03 04:24:13 | 000,003,616 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/05/03 04:22:59 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/05/03 02:29:59 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1219886524-1901542093-1859949695-1001UA.job
[2012/05/03 01:58:18 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1219886524-1901542093-1859949695-1000UA.job
[2012/05/02 22:57:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1219886524-1901542093-1859949695-1000Core.job
[2012/05/02 22:08:12 | 000,040,776 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2012/05/02 22:05:48 | 000,000,868 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/02 21:44:42 | 000,000,695 | ---- | M] () -- C:\Users\Raisa\Desktop\NTREGOPT.lnk
[2012/05/02 21:44:42 | 000,000,676 | ---- | M] () -- C:\Users\Raisa\Desktop\ERUNT.lnk
[2012/05/02 21:22:04 | 000,000,392 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{4D341C81-2780-4D34-B10C-8EC09BB0005B}.job
[2012/05/02 21:11:50 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/05/02 21:11:34 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/05/02 21:11:29 | 000,006,836 | ---- | M] () -- C:\Users\Raisa\AppData\Local\d3d9caps.dat
[2012/05/02 21:11:27 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1219886524-1901542093-1859949695-1001Core.job
[2012/05/02 21:11:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/05/01 22:05:28 | 000,000,632 | RHS- | M] () -- C:\Users\Raisa\ntuser.pol
[2012/05/01 22:05:09 | 000,613,828 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/05/01 22:05:08 | 000,109,534 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/05/01 21:58:11 | 3215,831,040 | -HS- | M] () -- C:\hiberfil.sys
[2012/05/01 21:58:08 | 322,190,590 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/05/01 20:45:30 | 000,001,933 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2012/04/29 22:30:55 | 000,595,456 | ---- | M] (OldTimer Tools) -- C:\Users\Raisa\Desktop\OTL.exe
[2012/04/29 21:47:43 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\deployJava1.dll
[2012/04/29 21:47:43 | 000,157,472 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaws.exe
[2012/04/29 21:47:43 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\javaw.exe
[2012/04/29 21:47:43 | 000,149,280 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\System32\java.exe
[2012/04/29 20:12:59 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/04/29 19:10:19 | 004,479,463 | R--- | M] (Swearware) -- C:\Users\Raisa\Desktop\ComboFix.exe
[2012/04/17 20:15:11 | 000,418,464 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/04/17 20:15:11 | 000,070,304 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/04/17 20:07:33 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/04/05 14:28:19 | 000,198,832 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\rmoc3260.dll
[2012/04/05 14:28:07 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5016.dll
[2012/04/05 14:28:07 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\Windows\System32\pndx5032.dll
[2012/04/05 14:28:06 | 000,272,896 | ---- | M] (Progressive Networks) -- C:\Windows\System32\pncrt.dll
[2012/04/04 15:56:40 | 000,022,344 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
========== Files Created - No Company Name ========== [2012/05/02 22:05:48 | 000,000,868 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/05/02 21:44:42 | 000,000,695 | ---- | C] () -- C:\Users\Raisa\Desktop\NTREGOPT.lnk
[2012/05/02 21:44:42 | 000,000,676 | ---- | C] () -- C:\Users\Raisa\Desktop\ERUNT.lnk
[2012/05/01 21:58:08 | 322,190,590 | ---- | C] () -- C:\Windows\MEMORY.DMP
[2012/04/29 19:18:18 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/04/29 19:18:18 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/04/29 19:18:18 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/04/29 19:18:18 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/04/29 19:18:18 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/04/17 19:48:44 | 000,000,564 | ---- | C] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/04/17 19:48:35 | 000,000,506 | ---- | C] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/04/08 22:04:34 | 000,430,080 | ---- | C] () -- C:\Windows\System32\ZSHP1018.EXE
[2012/04/08 22:04:34 | 000,128,380 | ---- | C] () -- C:\Windows\System32\hp1018.img
[2012/04/08 22:04:34 | 000,010,632 | ---- | C] () -- C:\Windows\System32\ZSHP1018.CHM
[2012/04/08 08:26:27 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2010/12/18 11:34:04 | 000,000,010 | ---- | C] () -- C:\Windows\WININIT.INI
========== Custom Scans ========== < %ALLUSERSPROFILE%\Application Data\*. > < %ALLUSERSPROFILE%\Application Data\*.exe /s > < %ALLUSERSPROFILE%\Application Data\*.dll /s > < c:\users\Raisa\AppData\Local\*.dll /s >[2011/11/17 07:52:22 | 000,292,352 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\chs.dll
[2011/11/17 07:52:28 | 000,292,352 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\cht.dll
[2011/11/17 07:52:34 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\csy.dll
[2011/11/17 07:52:40 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\dan.dll
[2011/11/17 07:52:46 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\deu.dll
[2011/11/17 07:52:52 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\esp.dll
[2011/11/17 07:52:58 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\fin.dll
[2011/11/17 07:53:04 | 000,293,888 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\fra.dll
[2011/11/17 07:53:10 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\ita.dll
[2011/11/17 07:53:16 | 000,292,864 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\jpn.dll
[2011/11/17 07:53:22 | 000,292,352 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\kor.dll
[2011/11/17 07:53:28 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\nld.dll
[2011/11/17 07:53:34 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\nor.dll
[2011/11/17 07:53:40 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\plk.dll
[2011/11/17 07:53:46 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\ptb.dll
[2011/11/17 07:53:52 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\ptg.dll
[2011/11/17 07:53:58 | 000,293,888 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\rus.dll
[2011/11/17 07:54:04 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\sve.dll
[2011/11/17 07:54:11 | 000,293,376 | ---- | M] () -- c:\users\Raisa\AppData\Local\Akamai\Languages\trk.dll
[2011/12/15 22:32:10 | 000,020,480 | ---- | M] (Citrix Online) -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\AssistCustomer.dll
[2011/12/15 22:32:09 | 000,006,656 | ---- | M] (Citrix Online) -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\ClassicStarter.dll
[2011/12/15 22:31:26 | 000,003,584 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\FinderHelper.dll
[2011/12/15 22:32:10 | 000,008,192 | ---- | M] (Citrix Online) -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\HelperStarter.dll
[2011/12/15 23:01:18 | 000,003,584 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_0b3e9c346e6aaa9f\en\AppCore.Resources.Dll
[2009/01/18 20:18:18 | 000,006,656 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_e22532eaebc1d077\AssistCustomer.dll
[2009/01/18 20:18:17 | 000,005,632 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_e22532eaebc1d077\ClassicStarter.dll
[2009/01/18 20:18:13 | 000,003,584 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_e22532eaebc1d077\FinderHelper.dll
[2009/01/18 20:18:18 | 000,007,168 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_e22532eaebc1d077\HelperStarter.dll
[2009/01/18 20:18:17 | 000,002,560 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_e22532eaebc1d077\en\AppCore.Resources.Dll
[2011/12/15 22:31:26 | 000,003,584 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_none_fccbcdb47a5c7ed5\FinderHelper.dll
[2009/01/18 20:18:13 | 000,003,584 | ---- | M] () -- c:\users\Raisa\AppData\Local\Apps\2.0\LNQMETTP.W3B\XL79LOTH.BJH\citr..rter_1f7b1ea3a3243e4a_0001.0000_none_fd7a111279d20a20\FinderHelper.dll
[2011/07/17 14:30:37 | 000,024,576 | ---- | M] () -- c:\users\Raisa\AppData\Local\assembly\dl3\RLVZE39A.2QM\RKDGYBJJ.RCJ\1ffdae17\80f0f91a_56fec901\SelectPrinterControl.DLL
[2011/04/28 23:34:37 | 000,159,744 | ---- | M] () -- c:\users\Raisa\AppData\Local\assembly\dl3\RLVZE39A.2QM\RKDGYBJJ.RCJ\6959faa7\80855ac3_53fec901\PatientChart.DLL
[2011/07/13 22:52:18 | 000,686,912 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdate.dll
[2011/07/13 22:52:18 | 000,025,920 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ar.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bg.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_bn.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ca.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_cs.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_da.dll
[2011/07/13 22:52:18 | 000,029,504 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_de.dll
[2011/07/13 22:52:18 | 000,030,016 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_el.dll
[2011/07/13 22:52:18 | 000,026,944 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en-GB.dll
[2011/07/13 22:52:18 | 000,026,944 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_en.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es-419.dll
[2011/07/13 22:52:18 | 000,029,504 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_es.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_et.dll
[2011/07/13 22:52:18 | 000,026,432 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fa.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fi.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fil.dll
[2011/07/13 22:52:18 | 000,029,504 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_fr.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_gu.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hi.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hr.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_hu.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_id.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_is.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_it.dll
[2011/07/13 22:52:18 | 000,024,896 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_iw.dll
[2011/07/13 22:52:18 | 000,023,360 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ja.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_kn.dll
[2011/07/13 22:52:18 | 000,023,360 | ---- | M] (Facebook Inc) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ko.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] („Google Inc.“) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lt.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_lv.dll
[2011/07/13 22:52:18 | 000,030,528 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ml.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_mr.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ms.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_nl.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_no.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_or.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pl.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-BR.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_pt-PT.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ro.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ru.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sk.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sl.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sr.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_sv.dll
[2011/07/13 22:52:18 | 000,028,992 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ta.dll
[2011/07/13 22:52:18 | 000,028,480 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_te.dll
[2011/07/13 22:52:18 | 000,026,432 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_th.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_tr.dll
[2011/07/13 22:52:18 | 000,027,968 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_uk.dll
[2011/07/13 22:52:18 | 000,027,456 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_ur.dll
[2011/07/13 22:52:18 | 000,026,944 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_vi.dll
[2011/07/13 22:52:18 | 000,021,312 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-CN.dll
[2011/07/13 22:52:18 | 000,021,312 | ---- | M] (Facebook Inc.) -- c:\users\Raisa\AppData\Local\Facebook\Update\1.2.203.0\goopdateres_zh-TW.dll
[2012/03/15 22:33:08 | 001,075,560 | ---- | M] (Skype Limited) -- c:\users\Raisa\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
[2012/04/01 12:41:11 | 000,100,864 | ---- | M] () -- c:\users\Raisa\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.0.1\libEGL.dll
[2012/04/01 12:41:11 | 004,052,480 | ---- | M] () -- c:\users\Raisa\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.0.1\libGLESv2.dll
[2012/05/02 21:12:09 | 000,100,864 | ---- | M] () -- c:\users\Raisa\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.0.2\libEGL.dll
[2012/05/02 21:12:08 | 004,050,944 | ---- | M] () -- c:\users\Raisa\AppData\Local\Google\Chrome\User Data\SwiftShader\1.0.0.2\libGLESv2.dll
[2010/09/22 14:19:34 | 000,335,112 | ---- | M] (Microsoft Corp.) -- c:\users\Raisa\AppData\Local\Microsoft\Toolbar\Applications\appmgr.dll
[2010/09/21 17:04:22 | 001,128,712 | ---- | M] (Microsoft Corporation) -- c:\users\Raisa\AppData\Local\Microsoft\Toolbar\Applications\bingrewardsclient.dll
[2010/09/22 14:19:34 | 000,096,520 | ---- | M] (Microsoft Corp.) -- c:\users\Raisa\AppData\Local\Microsoft\Toolbar\Applications\scextension.dll
[2010/09/22 14:19:34 | 000,131,336 | ---- | M] (Microsoft Corp.) -- c:\users\Raisa\AppData\Local\Microsoft\Toolbar\Applications\searchappextension.dll
[2010/09/22 14:19:34 | 000,461,576 | ---- | M] (Microsoft Corp.) -- c:\users\Raisa\AppData\Local\Microsoft\Toolbar\Applications\wlextension.dll
[2012/04/18 06:44:23 | 000,828,264 | ---- | M] (Microsoft Corporation) -- c:\users\Raisa\AppData\Local\Microsoft\Windows Live\Installer\Catalog\wlupdate.15.4.120.0.dll
[2009/01/28 09:45:38 | 000,315,392 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\.jagex_cache_32\runescape\jogl.dll
[2009/01/28 09:45:38 | 000,020,480 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\.jagex_cache_32\runescape\jogl_awt.dll
[2009/01/28 12:00:09 | 000,315,392 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\Desktop\.jagex_cache_32\runescape\jogl.dll
[2009/01/28 12:00:09 | 000,020,480 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\Desktop\.jagex_cache_32\runescape\jogl_awt.dll
[2009/02/03 21:23:14 | 000,045,056 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\Medtronic\ddmsDTWSerialPort.dll
[2009/02/03 21:24:00 | 000,081,920 | ---- | M] () -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\Medtronic\ddmsDTWusb\ComLink2\Jungo 8.1.1\cl2_jni_wrapper.dll
[2009/02/03 21:24:00 | 000,337,320 | ---- | M] (Microsoft Corporation) -- c:\users\Raisa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Raisa\Medtronic\ddmsDTWusb\ComLink2\Jungo 8.1.1\difxapi.dll
[2011/08/09 09:57:00 | 000,521,632 | ---- | M] (Solid State Networks) -- c:\users\Raisa\AppData\Local\Solid State Networks\Host.c6ebf1cbfe6d743040ca235767a3012e0bc027e7\downloader.dll
[2011/08/09 09:56:00 | 000,166,816 | ---- | M] (Solid State Networks) -- c:\users\Raisa\AppData\Local\Solid State Networks\Host.c6ebf1cbfe6d743040ca235767a3012e0bc027e7\launcher.dll
[2011/11/09 22:31:30 | 000,176,128 | ---- | M] () -- c:\users\Raisa\AppData\Local\usrMainVdm\CvtmapSnap.dll
< %APPDATA%\*. >[2010/01/08 18:51:11 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\acccore
[2011/10/13 07:31:40 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Adobe
[2009/09/26 16:55:22 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Apple Computer
[2008/12/26 08:46:16 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\ATI
[2010/02/10 19:02:25 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Audacity
[2011/01/29 16:01:20 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Canon
[2012/01/01 12:32:06 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Creative
[2010/08/20 07:04:03 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\CyberLink
[2011/12/15 00:04:01 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Dell
[2008/12/27 14:33:43 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Google
[2008/12/26 08:45:41 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Identities
[2009/01/05 23:09:17 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\InstallShield
[2011/12/13 22:08:33 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\iolo
[2009/01/05 23:11:35 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Logitech
[2010/01/18 00:02:22 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Macromedia
[2012/05/02 22:06:08 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Malwarebytes
[2010/01/24 23:02:22 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\MechCAD
[2006/11/02 08:37:34 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Media Center Programs
[2011/10/13 07:31:40 | 000,000,000 | --SD | M] -- C:\Users\Raisa\AppData\Roaming\Microsoft
[2010/02/11 19:14:23 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\NCH Swift Sound
[2010/05/28 21:48:15 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\ooVoo Details
[2010/05/28 21:45:02 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\oovooinstaller
[2009/05/19 21:37:31 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\OpenOffice.org
[2011/12/14 23:44:02 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\PCDr
[2012/04/05 14:29:49 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Real
[2010/01/18 09:29:19 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Reallusion
[2010/02/04 11:34:13 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Roxio
[2012/03/09 22:32:59 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Skype
[2012/03/09 22:32:47 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\skypePM
[2009/11/11 12:32:32 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Sony
[2009/01/18 21:10:02 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Template
[2011/09/05 15:17:38 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\Windows Live Writer
[2011/06/25 22:44:12 | 000,000,000 | ---D | M] -- C:\Users\Raisa\AppData\Roaming\ZoomBrowser EX
< %APPDATA%\*.exe /s >[2009/12/12 19:44:05 | 000,000,947 | ---- | M] () -- C:\Users\Raisa\AppData\Roaming\DataSafeDotNet.exe
[2012/04/05 13:32:09 | 051,401,720 | ---- | M] (Dell Inc) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Binaries\full_dsc_5907_29_32_01.exe
[2012/04/17 19:39:00 | 051,406,040 | ---- | M] (Dell Inc) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Binaries\full_dsc_5907_39_32_02.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\0e3b2450-6bd5-49fc-bb76-7f70eb6a4a5b\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\16145453-1ba4-4da3-aa87-aad54baf93c0\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\2196d5f8-34b1-44fa-91aa-35b31ef59bd3\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\28ed709d-b08d-469d-9100-10ac7758cd21\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\2dcc814b-7e30-441f-8aa3-6ba32d0caef6\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\41a29fa7-41e6-44dd-8663-7c0af1719a34\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\448f6f57-06b4-4a05-9a36-cedd90347eab\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\454fb028-58b3-4ec4-a5a2-884be6eea5ae\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\4e0f45b1-216f-4d45-b430-70f799baefe5\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\5469a0b0-a60e-4d7d-a14d-eadd802252b4\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\6574b534-2cb6-418e-a0c5-94a0501308f5\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\7885a178-c9a6-416d-afe0-e271aef5b000\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\7bad201d-9ee8-4106-b2bd-a1f5fe6ac180\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\8394a1cf-19b9-4f2b-9a07-a95cf202d296\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\8582cec0-69fb-45b8-9cd5-eb08db3e2516\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\992df247-5404-4233-a367-7de293da9a71\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\a866792c-3a9b-4a43-bfce-11daa79e406e\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\c27a2e5b-3f48-410c-a4e4-b8005634ed21\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\e249b553-f238-4d24-8768-e9090f9fadb8\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\ec72f24c-2a61-489b-9cc6-5a2212d0db6d\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\ecc02a18-549a-4628-be28-8c8c08d568e8\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\ee978553-ddca-40b8-9d78-5d6018f3c6b5\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\f3322622-d3e7-41a8-aa3c-d9aebb9079a2\appupdaterrules_dell\AddCertificate.exe
[2012/03/23 12:35:30 | 000,016,976 | ---- | M] (PC-Doctor, Inc.) -- C:\Users\Raisa\AppData\Roaming\PCDr\Update\Rules\fbb7bdbd-6362-4eb9-bbfb-8b43076642a6\appupdaterrules_dell\AddCertificate.exe
< %SYSTEMDRIVE%\*.exe > < c:|Fun4IM;true;true;true; /FP > < c:|Bandoo;true;true;true; /FP > < c:|Searchn;true;true;true; /FP > < c:|Searchq;true;true;true; /FP > < c:|datamngr;true;true;true; /FP > < c:|iLivid;true;true;true; /FP > < c:|whitesmoke;true;true;true; /FP > < %USERPROFILE%\..|smtmp;true;true;true /FP > < %systemroot%\*. /mp /s > ========== Alternate Data Streams ========== @Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0051.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0050.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0049.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0047.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0046.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0045.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0044.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0043.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0042.avi:TOC.WMV
@Alternate Data Stream - 64 bytes -> C:\Users\Raisa\Documents\clip0041.avi:TOC.WMV
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.05.02.09
Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 8.0.6001.19222
Raisa :: LAPTOP [administrator]
5/2/2012 10:08:46 PM
mbam-log-2012-05-02 (22-08-46).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 400908
Time elapsed: 2 hour(s), 11 minute(s), 39 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)