OTL logfile created on: 05/07/2012 12:02:32 AM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\becky\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
1.99 Gb Total Physical Memory | 0.81 Gb Available Physical Memory | 40.88% Memory free
4.21 Gb Paging File | 2.68 Gb Available in Paging File | 63.59% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.04 Gb Total Space | 145.67 Gb Free Space | 50.57% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.27 Gb Free Space | 62.65% Space Free | Partition Type: NTFS
Drive E: | 5.55 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 122.03 Mb Total Space | 1.36 Mb Free Space | 1.12% Space Free | Partition Type: FAT32
Computer Name: BECKY-PC | User Name: becky | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - C:\Users\becky\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_11_3_300_257_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
PRC - C:\Windows\System32\UTSCSI.EXE ()
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\Cisco Systems\Cisco Valet Connector\CiscoAdapterSvc.exe (Cisco Consumer Products LLC)
PRC - C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
PRC - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Windows\System32\lxczcoms.exe ( )
PRC - C:\Windows\system\w98eject.exe (Sigmatel)
PRC - C:\Windows\V0230Mon.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ========== MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Win32 Services (SafeList) ========== SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter File not found
SRV - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Skype C2C Service) -- C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (SkypeUpdate) -- C:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore.exe (SUPERAntiSpyware.com)
SRV - (UTSCSI) -- C:\Windows\System32\UTSCSI.EXE ()
SRV - (iWinTrusted) -- C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (RaAutoInstSrv_AM10) -- C:\Program Files\Cisco Systems\Cisco Valet Connector\CiscoAdapterSvc.exe (Cisco Consumer Products LLC)
SRV - (IJPLMSVC) -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe ()
SRV - (TeamViewer5) -- C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (YahooAUService) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) -- C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (lxcz_device) -- C:\Windows\System32\lxczcoms.exe ( )
SRV - (DSBrokerService) -- C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ========== DRV - (catchme) -- C:\Users\becky\AppData\Local\Temp\catchme.sys File not found
DRV - (aswMBR) -- C:\Users\becky\AppData\Local\Temp\aswMBR.sys File not found
DRV - (aswTdi) -- C:\Windows\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSnx) -- C:\Windows\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) -- C:\Windows\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswMonFlt) -- C:\Windows\System32\drivers\aswMonFlt.sys (AVAST Software)
DRV - (aswRdr) -- C:\Windows\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswFsBlk) -- C:\Windows\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (AM10) -- C:\Windows\System32\drivers\am10va.sys (Ralink Technology Corp.)
DRV - (PID_0928) Logitech QuickCam Express(PID_0928) -- C:\Windows\System32\drivers\LV561AV.SYS (Logitech Inc.)
DRV - (mr97310c) -- C:\Windows\System32\drivers\mr97310c.sys (Mars Semiconductor Corp.)
DRV - (V0230VID) -- C:\Windows\System32\drivers\V0230VID.sys (Creative Technology Ltd.)
DRV - (e1express) Intel® -- C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (dsunidrv) -- C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (R300) -- C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (DSproct) -- C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (V0230Vfx) -- C:\Windows\System32\drivers\V0230Vfx.sys (EyePower Games Pte. Ltd.)
DRV - (ASPI32) -- C:\Windows\System32\drivers\ASPI32.SYS (Adaptec)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.gboxapp.com/IE - HKLM\..\SearchScopes,DefaultScope = {AA74FE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRCIE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7DACAIE - HKLM\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://search.gboxapp.com/?q={searchTerms}IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.mywinnipeg.com/IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes,DefaultScope = {36377DD7-B3EB-42f5-986F-680BAF59BA9D}
IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRCIE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{080FBDF6-B230-4e4d-A4E7-7C7A56D7BABC}: "URL" =
http://searchservice.myspace.com/index.cfm?fuseaction=sitesearch.results&qry={searchTerms}&type=Web&orig=IMC-IEDSIE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?client=ie&tb=IMB&o=15781&src=crm&q={searchTerms}&locale=en_USIE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{1CB20BF0-BBAE-40A7-93F4-6435FF3D0411}: "URL" =
http://www.crawler.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=60196IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{36377DD7-B3EB-42f5-986F-680BAF59BA9D}: "URL" =
http://start.iplay.com/searchresults.aspx?o=chrome&q={searchTerms}IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" =
http://www.google.com/search?q={searchTerms}&rlz=1I7DDCA_en-GB&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{8E02D41C-5924-4816-9490-33CCD28BEB72}: "URL" =
http://search.yahoo.com/search?ei=ISO-8859-1&fr=vmn&type=egames&q={searchTerms}IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{AA74FE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" =
http://search.gboxapp.com/?q={searchTerms}IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" =
http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{BB622412-7DB8-4AFD-B084-E5065BAE464B}: "URL" =
http://search.imgag.com/?appid=kwapp&c=&sbs=2&sc=2&f=web&vernum=1.0&uid=&did=%7bBB622412-7DB8-4AFD-B084-E5065BAE464B%7d&component=&q={searchTerms}IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{C04B7D22-5AEC-4561-8F49-27F6269208F6}: "URL" =
http://toolbar.inbox.com/search/dispatcher.aspx?tp=bs&qkw={searchTerms}&tbid=80154&lng=enIE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" =
http://mystart.incredimail.com/mb6?search={searchTerms}&loc=search_box_im2_test_v2IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}: "URL" =
http://search.yahoo.com/search?p={searchTerms}&fr=chr-rogIE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\SearchScopes\Bing: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&mkt=en-CA&FORM=IE0001IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\becky\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\becky\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\becky\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\becky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{FFB96CC1-7EB3-449D-B827-DB661701C6BB}: C:\Program Files\CheckPoint\ZAForceField\TrustChecker
[2010/06/21 15:41:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\becky\AppData\Roaming\Mozilla\Extensions
[2010/11/01 14:47:25 | 000,000,000 | ---D | M] (No name found) -- C:\Users\becky\AppData\Roaming\Mozilla\Firefox\extensions
[2010/11/01 14:47:25 | 000,000,000 | ---D | M] (XfireXO Toolbar) -- C:\Users\becky\AppData\Roaming\Mozilla\Firefox\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\becky\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\becky\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\becky\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.220.4 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U22 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\becky\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\becky\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - plugin: Google Update (Enabled) = C:\Users\becky\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: YouTube = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: avast! WebRep = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1451_0\
CHR - Extension: avast! WebRep = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1456_0\
CHR - Extension: Skype Click to Call = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10297_0\
CHR - Extension: Gmail = C:\Users\becky\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/04 11:55:31 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (eGames Toolbar) - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\Program Files\egamestoolbar\egamestoolbar.dll ( )
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (&Google) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (eGames Toolbar) - {4E7BD74F-2B8D-469E-85B2-BC27FE9AAE2E} - C:\Program Files\egamestoolbar\egamestoolbar.dll ( )
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [dellsupportcenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask .exe" -atboottime File not found
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [V0230Mon.exe] C:\Windows\V0230Mon.exe (Creative Technology Ltd.)
O4 - HKU\.DEFAULT..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe ()
O4 - HKU\S-1-5-18..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe ()
O4 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe (Electronic Arts)
O4 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000..\Run: [Facebook Update] C:\Users\becky\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\becky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RollerCoaster Tycoon 3 Registration.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4053380413-3599652072-2352306657-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Morpheus Music\RazaWebHook.dll/3000 File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/Beach%20Party%20Craze/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1}
https://www.battlefieldheroes.com/static/updater/BFHUpdater_5.0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC}
http://panda-plugin.disney.go.com/plugin/win32/p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 1.7.0_05)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_05-windows-i586.cab (Java Plug-in 10.5.0)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/Beach%20Party%20Craze/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D}
http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.3.1.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C6B67A9A-260D-4704-AABC-2E312ACBAE1B}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E293DC91-DDF9-4FDC-8747-97BC79A65185}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL) - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Users\becky\Pictures\Alexis\034.JPG
O24 - Desktop BackupWallPaper: C:\Users\becky\Pictures\Alexis\034.JPG
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/07/08 01:09:23 | 000,000,000 | R--D | M] - E:\AutoRun -- [ UDF ]
O32 - AutoRun File - [2009/07/08 01:17:56 | 000,703,552 | R--- | M] (Electronic Arts Inc.) - E:\AutoRun.exe -- [ UDF ]
O32 - AutoRun File - [2009/07/08 01:17:57 | 000,711,744 | R--- | M] (Electronic Arts Inc.) - E:\AutoRunGUI.dll -- [ UDF ]
O32 - AutoRun File - [2009/07/08 01:17:51 | 000,000,164 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2010/05/29 15:15:10 | 000,000,224 | -H-- | M] () - F:\autorun.inf -- [ FAT32 ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ========== [2012/07/05 00:01:09 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\becky\Desktop\OTL.exe
[2012/07/04 18:45:30 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\becky\Desktop\aswMBR.exe
[2012/07/04 18:41:12 | 002,135,640 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\becky\Desktop\TDSSKiller.exe
[2012/07/04 13:17:06 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{5CE09212-9A14-4BAC-BE40-4C7A2A528A37}
[2012/07/04 13:16:54 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{7136CDCB-8CC4-4FAF-9224-995803B55FEC}
[2012/07/04 12:01:18 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/07/04 11:59:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/04 11:59:24 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/04 11:59:24 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\temp
[2012/07/04 11:36:38 | 000,000,000 | ---D | C] -- C:\ComboFix
[2012/07/04 11:35:41 | 004,571,084 | R--- | C] (Swearware) -- C:\Users\becky\Desktop\ComboFix.exe
[2012/07/03 18:14:01 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\becky\Desktop\dds.scr
[2012/07/02 10:32:49 | 000,426,184 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/07/02 10:32:48 | 000,070,344 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/07/01 14:40:18 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine
[2012/07/01 01:30:42 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{5DF6C488-F68A-4F7C-8503-8386AD7A3A8E}
[2012/07/01 01:30:25 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{5F22A333-45DE-46B0-92EE-0E663DA2B70A}
[2012/06/30 10:48:08 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{7B743901-5A87-4573-AE45-0AECFDC24753}
[2012/06/30 10:47:56 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{347D4982-47F2-4769-9788-71B27612FDEA}
[2012/06/29 22:47:11 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{F45C090C-A81A-48EB-8572-4BA549AEEEF7}
[2012/06/29 22:46:33 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{0B9A79B6-C9C4-4F47-8EA0-B74965066160}
[2012/06/29 11:36:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/06/29 11:35:46 | 000,227,824 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/06/29 11:35:37 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/06/29 11:35:37 | 000,174,064 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/06/29 11:29:11 | 000,772,592 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/06/29 10:46:00 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{67BF6E9F-9062-415A-A003-96CA7E12533E}
[2012/06/29 10:45:43 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{C35F07B7-179F-4B93-B7A2-C4EEAEF4FBD6}
[2012/06/28 10:53:52 | 000,000,000 | ---D | C] -- C:\Users\becky\Desktop\tdsskiller
[2012/06/28 10:42:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/06/28 10:42:29 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012/06/27 09:18:00 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{C95C19DB-33C9-4D8F-A7CA-877B6FFE48BC}
[2012/06/27 09:17:44 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{05BAF087-3E9B-47D7-BA62-D2D3A5738B0D}
[2012/06/26 12:35:35 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{8705BCEB-6F74-4BB5-AFBA-A187560026FD}
[2012/06/26 12:35:03 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{C17C6719-9563-4246-9AEA-87D1BE5B23E5}
[2012/06/26 12:09:08 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Roaming\SUPERAntiSpyware.com
[2012/06/26 12:08:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2012/06/26 12:08:44 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2012/06/25 13:23:06 | 000,000,000 | ---D | C] -- C:\ProgramData\n7-89-o9-3r-4t-r9
[2012/06/25 13:11:27 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Roaming\GameHouse
[2012/06/25 11:57:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/25 11:57:23 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/06/25 01:57:07 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{D568273B-1BDC-40F7-91A0-A232D462A789}
[2012/06/25 01:57:04 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{5A87911F-1B29-4D02-B184-B03F1DED1A45}
[2012/06/24 13:55:06 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{25A63652-0E65-493E-AFF9-6BA76BC31FA6}
[2012/06/24 13:54:22 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{038D0B34-5CAF-4622-9916-F18D309B7ADF}
[2012/06/22 14:45:53 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{99452DFA-AD69-4E99-B5D1-25EEA73CDF8F}
[2012/06/22 14:44:29 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{50F5462C-E61E-4741-853E-19F071A82F13}
[2012/06/21 22:47:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/21 22:46:13 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\Windows\System32\GEARAspi.dll
[2012/06/21 22:44:18 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/06/21 22:44:15 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/06/21 22:44:15 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012/06/21 22:42:04 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2012/06/21 22:38:27 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/06/19 16:08:22 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{F1735578-0705-4699-BF75-ECE9F97A4C16}
[2012/06/19 16:08:10 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{4E07F7DD-9DC3-4CEE-A14A-720B98A5AFE1}
[2012/06/19 14:52:35 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\RealDetectives
[2012/06/19 14:52:35 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Roaming\FreezeTag
[2012/06/19 09:29:37 | 002,422,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2012/06/19 09:29:37 | 000,045,080 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups2.dll
[2012/06/19 09:28:58 | 000,577,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2012/06/19 09:28:58 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2012/06/19 09:28:58 | 000,035,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wups.dll
[2012/06/19 09:28:39 | 000,171,904 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2012/06/19 09:28:39 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2012/06/18 12:12:18 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{78D4DB8D-A791-42E9-974F-AA4B86C52661}
[2012/06/18 00:11:18 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{A61872EF-3CBF-423B-BA7E-7BCD49B802E2}
[2012/06/17 12:11:02 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{BD1D5539-19F6-40E0-A5D4-89CC50F5BAC5}
[2012/06/16 15:36:52 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{9773EC00-4F32-486A-A299-AB5E13746B88}
[2012/06/15 21:27:24 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{A3CE5A7C-B5B1-4ECF-95AC-451521C82FD8}
[2012/06/14 10:24:46 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{06633143-330D-4A5E-856C-30D73FADBFBD}
[2012/06/14 10:24:43 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{35E40B91-2289-4E6A-8F94-64C84BE7BDEF}
[2012/06/14 03:03:20 | 002,382,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2012/06/14 03:03:16 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2012/06/14 03:03:16 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieUnatt.exe
[2012/06/14 03:03:14 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2012/06/14 03:03:12 | 001,800,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2012/06/14 03:03:12 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2012/06/14 03:03:09 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2012/06/13 18:38:43 | 002,045,440 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2012/06/13 14:30:21 | 000,000,000 | ---D | C] -- C:\ProgramData\PuzzlesByJoe
[2012/06/12 18:52:28 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{7AC653A9-8921-43AD-87D7-C730BC2C9637}
[2012/06/12 18:51:09 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{EBFCEB08-9F96-45A1-85CD-6C0C49504ED7}
[2012/06/11 07:15:55 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{9CFF2485-2EC3-45D6-A170-D1B62E67AD3D}
[2012/06/11 07:15:34 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{DFE83C4A-3F82-4E04-8694-EE8B1CFAC9B8}
[2012/06/10 18:49:46 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{6F5A6FE2-165F-4581-A8DB-C3941F0FB87A}
[2012/06/10 18:48:01 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{89A76269-BC25-4CEE-81E5-3E0BB78E5957}
[2012/06/10 06:18:13 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{66AE9566-0B34-46C9-B9CC-391E2BDB7700}
[2012/06/10 06:18:10 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{DD993C84-FD28-4EF7-B3AB-ADFE832E4A86}
[2012/06/09 18:15:33 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{4A477EE5-F866-4466-AC65-472FCCDAB388}
[2012/06/09 18:13:04 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{242F75DB-89B3-4EE7-8417-92B468010D70}
[2012/06/09 15:32:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/06/09 15:32:37 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2012/06/08 19:46:45 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2012/06/07 07:58:06 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{7DF5DF4B-2F36-454B-A956-1C54E558B1E9}
[2012/06/07 07:58:04 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{0D66EE56-32E5-4761-82B3-17F75BAB54FE}
[2012/06/06 19:57:20 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{020DF096-C40C-42AA-BC1F-BEDDBE17BBAB}
[2012/06/06 19:57:12 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{057E13FC-8719-4ABE-AC3C-8B3E2AA3DB91}
[2012/06/06 15:04:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Fugazo
[2012/06/05 23:32:17 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{136EF814-2FF9-4777-A907-D56D540B3EC1}
[2012/06/05 23:31:11 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Local\{2ADFDF56-91C9-4185-B4C8-1B707D041679}
[2012/06/05 17:40:59 | 000,000,000 | ---D | C] -- C:\Users\becky\AppData\Roaming\Cat's Eye Games
========== Files - Modified Within 30 Days ========== [2012/07/05 00:01:14 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\becky\Desktop\OTL.exe
[2012/07/04 23:42:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000UA.job
[2012/07/04 23:17:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/04 22:48:56 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/04 22:48:56 | 000,003,568 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/04 22:28:04 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000UA.job
[2012/07/04 19:42:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000Core.job
[2012/07/04 19:30:50 | 000,000,512 | ---- | M] () -- C:\Users\becky\Desktop\MBR.dat
[2012/07/04 19:28:09 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000Core.job
[2012/07/04 18:47:55 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\becky\Desktop\aswMBR.exe
[2012/07/04 18:41:38 | 002,135,640 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\becky\Desktop\TDSSKiller.exe
[2012/07/04 14:48:35 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/04 14:19:39 | 000,000,506 | ---- | M] () -- C:\Windows\tasks\SystemToolsDailyTest.job
[2012/07/04 12:03:26 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2012/07/04 11:55:31 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/07/04 11:35:51 | 004,571,084 | R--- | M] (Swearware) -- C:\Users\becky\Desktop\ComboFix.exe
[2012/07/04 11:19:10 | 000,881,475 | ---- | M] () -- C:\Users\becky\Desktop\SecurityCheck.exe
[2012/07/03 19:58:15 | 000,024,576 | ---- | M] () -- C:\Users\becky\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/07/03 18:21:50 | 000,302,592 | ---- | M] () -- C:\Users\becky\Desktop\7cp3wrtk.exe
[2012/07/03 18:14:03 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\becky\Desktop\dds.scr
[2012/07/03 18:11:01 | 000,000,000 | ---- | M] () -- C:\Users\becky\defogger_reenable
[2012/07/03 11:21:54 | 000,054,232 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2012/07/03 11:21:53 | 000,721,000 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2012/07/03 11:21:53 | 000,353,688 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2012/07/03 11:21:53 | 000,057,656 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2012/07/03 11:21:53 | 000,035,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2012/07/03 11:21:53 | 000,021,256 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2012/07/03 11:21:32 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/07/03 11:21:28 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2012/07/02 10:32:49 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/07/02 10:32:49 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/06/29 22:51:38 | 000,000,192 | ---- | M] () -- C:\Users\becky\Desktop\Google+.url
[2012/06/29 22:51:25 | 000,000,213 | ---- | M] () -- C:\Users\becky\Desktop\ui=2&view=bsp&ver=ohhl4rw8mbn4.url
[2012/06/29 14:04:31 | 000,000,680 | ---- | M] () -- C:\Users\becky\AppData\Local\d3d9caps.dat
[2012/06/29 11:35:22 | 000,772,592 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npDeployJava1.dll
[2012/06/29 11:35:22 | 000,687,600 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012/06/29 11:35:22 | 000,227,824 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/06/29 11:35:22 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/06/29 11:35:22 | 000,174,064 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/06/27 09:14:24 | 000,000,564 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[2012/06/26 12:08:52 | 000,001,802 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/06/25 13:11:31 | 000,000,971 | ---- | M] () -- C:\Users\Public\Desktop\Doggie Dash.lnk
[2012/06/25 13:11:31 | 000,000,122 | ---- | M] () -- C:\Users\Public\Desktop\More Games at GameHouse.com.url
[2012/06/25 11:57:26 | 000,000,908 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/21 22:47:11 | 000,001,666 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/19 17:07:04 | 000,002,293 | ---- | M] () -- C:\Users\Public\Desktop\The Sims™ 2 University Life Collection.lnk
[2012/06/19 17:07:04 | 000,001,218 | ---- | M] () -- C:\Users\Public\Desktop\www.thesims3.com.lnk
[2012/06/16 15:37:55 | 000,612,902 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/16 15:37:55 | 000,110,212 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/14 04:03:08 | 000,324,200 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/06/13 14:21:57 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\Clutter II He Said, She Said.lnk
[2012/06/08 15:20:09 | 000,000,198 | ---- | M] () -- C:\Users\becky\Desktop\Play Free Online Games Pogo.com®.url
========== Files Created - No Company Name ========== [2012/07/04 18:58:01 | 000,000,512 | ---- | C] () -- C:\Users\becky\Desktop\MBR.dat
[2012/07/04 11:19:09 | 000,881,475 | ---- | C] () -- C:\Users\becky\Desktop\SecurityCheck.exe
[2012/07/03 18:21:50 | 000,302,592 | ---- | C] () -- C:\Users\becky\Desktop\7cp3wrtk.exe
[2012/07/03 18:11:01 | 000,000,000 | ---- | C] () -- C:\Users\becky\defogger_reenable
[2012/07/02 10:32:56 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/29 22:51:38 | 000,000,192 | ---- | C] () -- C:\Users\becky\Desktop\Google+.url
[2012/06/29 22:51:25 | 000,000,213 | ---- | C] () -- C:\Users\becky\Desktop\ui=2&view=bsp&ver=ohhl4rw8mbn4.url
[2012/06/26 12:08:52 | 000,001,802 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2012/06/25 13:11:31 | 000,000,971 | ---- | C] () -- C:\Users\Public\Desktop\Doggie Dash.lnk
[2012/06/25 13:11:31 | 000,000,122 | ---- | C] () -- C:\Users\Public\Desktop\More Games at GameHouse.com.url
[2012/06/25 11:57:26 | 000,000,908 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/21 22:47:11 | 000,001,666 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/19 17:07:03 | 000,002,293 | ---- | C] () -- C:\Users\Public\Desktop\The Sims™ 2 University Life Collection.lnk
[2012/06/13 14:21:57 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\Clutter II He Said, She Said.lnk
[2012/06/08 19:37:22 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000UA.job
[2012/06/08 19:37:08 | 000,000,856 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4053380413-3599652072-2352306657-1000Core.job
[2012/06/08 15:20:09 | 000,000,198 | ---- | C] () -- C:\Users\becky\Desktop\Play Free Online Games Pogo.com®.url
[2012/06/04 10:14:28 | 000,003,716 | ---- | C] () -- C:\Windows\System32\drivers\V0230FwH.bin
[2012/06/04 10:14:28 | 000,003,716 | ---- | C] () -- C:\Windows\System32\drivers\V0230FwF.bin
[2012/02/24 22:29:27 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012/01/06 20:26:34 | 000,001,103 | ---- | C] () -- C:\Users\becky\Recent Items - Shortcut.lnk
[2011/06/28 10:35:32 | 000,045,056 | ---- | C] () -- C:\Windows\System32\UTSCSI.EXE
[2011/05/08 08:24:19 | 001,372,841 | ---- | C] () -- C:\Users\becky\AppData\Roaming\UserTile.png
[2010/12/27 16:10:16 | 000,024,576 | ---- | C] () -- C:\Users\becky\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/22 21:47:56 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2010/12/22 21:47:56 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2010/12/22 21:47:56 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2010/12/22 21:47:56 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2010/12/22 21:47:56 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2010/12/21 21:00:22 | 000,000,552 | ---- | C] () -- C:\Users\becky\AppData\Local\d3d8caps.dat
[2010/12/21 18:34:16 | 000,000,112 | ---- | C] () -- C:\ProgramData\UMdsyGU7.dat
[2010/12/15 15:55:03 | 000,000,680 | ---- | C] () -- C:\Users\becky\AppData\Local\d3d9caps.dat
[2010/11/20 09:51:01 | 000,138,184 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/11/20 09:51:01 | 000,138,056 | ---- | C] () -- C:\Users\becky\AppData\Roaming\PnkBstrK.sys
[2010/11/20 09:50:48 | 000,215,016 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/11/20 09:50:39 | 002,427,248 | ---- | C] () -- C:\Windows\System32\pbsvc_heroes.exe
[2010/11/20 09:50:39 | 000,075,064 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010/08/06 22:58:04 | 000,056,320 | ---- | C] () -- C:\Windows\System32\iyvu9_32.dll
[2010/07/01 14:43:29 | 000,000,373 | ---- | C] () -- C:\Users\becky\Documents - Shortcut.lnk
[2010/06/21 23:14:59 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/03/20 14:05:25 | 000,000,924 | ---- | C] () -- C:\Users\becky\AppData\Roaming\wklnhst.dat
========== Alternate Data Streams ========== @Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\Slingo Supreme Documents:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\SightSpeed Recordings:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\PassionFruit Games:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\MySpaceIM Pics:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\My Received Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\My Projects:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\Morpheus Music:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\ForceField Shared Files:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Documents\Call of Atlantis:Roxio EMC Stream
@Alternate Data Stream - 76 bytes -> C:\Users\becky\Desktop\messengers:Roxio EMC Stream
@Alternate Data Stream - 152 bytes -> C:\ProgramData\TEMP:273A8657
@Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:A99C1C81
@Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:DF2C953B
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:FC70A22A
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:3DB251F0
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:08660BC0
@Alternate Data Stream - 144 bytes -> C:\ProgramData\TEMP:6A37FCC3
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:F2B0ABCC
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:EBDA021F
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:78B923B2
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:4A2289A6
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:F24AD862
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:9F222B60
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:389C1BAE
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:1AC2B366
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:0FC57F99
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:F71B881A
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:7198E1D2
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:F00A953B
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:05F547A9
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:7E239580
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:14AD1C14
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:CE63AEF4
@Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:2966D3A0
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:EF258AD5
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:E7BA7168
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:A93A1878
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:4A966CC2
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:3C6E4889
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:FCD3A761
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:FF8F1AE3
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E36F5B57
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:A43443E9
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:24386795
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:07A0D262
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:72830084
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:B6C1A5F4
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:3FF2B6F1
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:09B77012
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:FDFD169D
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:EA21CA80
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:05F9CFF2
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:80D975A5
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:0B7C7BAE
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:F8B49EF2
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:C8033E19
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:AA2A4FE5
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6638AEDF
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A798AA1A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:0824CCE8
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:50E7393E
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:81D77061
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:04826ECB
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D1D657D4
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:AED4FFF5
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:2A6BF249
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:F76441C8
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ED9B661E
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3B3A35EC
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:40464012
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:1F0F3115
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F10C2DA8
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:7D371AB2
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:8E5EA40F
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:23FA878E
< End of report >