Is it possible that an add-on is causing the issue?
Edit: Is it safe to remove Combofix now?
Here's the log:
OTL logfile created on: 30/10/2011 8:53:36 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Matt\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.99 Gb Total Physical Memory | 5.86 Gb Available Physical Memory | 73.27% Memory free
15.98 Gb Paging File | 13.33 Gb Available in Paging File | 83.38% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 685.18 Gb Total Space | 337.68 Gb Free Space | 49.28% Space Free | Partition Type: NTFS
Drive D: | 13.31 Gb Total Space | 1.83 Gb Free Space | 13.71% Space Free | Partition Type: NTFS
Computer Name: MATT-PC | User Name: Matt | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Matt\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
PRC - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Audio and Video programs\WinTV\TVServer\CaptureGenPCI.exe (Hauppauge Computer Works)
PRC - C:\Audio and Video programs\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
PRC - C:\Audio and Video programs\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonServer.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonClient.exe ()
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe ()
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
PRC - C:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\2cesy0m7.default\extensions\{a8864317-e18b-4292-99d9-e6e65ab905d3}\components\RadioWMPCoreGecko7.dll ()
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll ()
MOD - C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\fedf1ba58dced4f0b3f8c457648ceed9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()
MOD - C:\Audio and Video programs\WinTV\TVServer\HauppaugeTVServerps.dll ()
MOD - C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (MSCamSvc) -- C:\Program Files\Microsoft LifeCam\MSCamS64.exe (Microsoft Corporation)
SRV:
64bit: - (mfefire) -- C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.)
SRV:
64bit: - (McShield) -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:
64bit: - (mfevtp) -- C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV:
64bit: - (McODS) -- C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:
64bit: - (MSK80Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McProxy) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McOobeSv) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McNASvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McNaiAnn) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (mcmscsvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McMPFSvc) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (McAfee SiteAdvisor Service) -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (HauppaugeTVServer) -- C:\Audio and Video programs\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
SRV - (AMD_RAIDXpert) -- C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
SRV - (HPBtnSrv) -- C:\Program Files (x86)\Hewlett-Packard\HP Easy Backup\HPBtnSrv.exe ()
SRV - (WcesComm) -- C:\Windows\WindowsMobile\wcescomm.dll (Microsoft Corporation)
SRV - (RapiMgr) -- C:\Windows\WindowsMobile\rapimgr.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:
64bit: - (atksgt) -- C:\Windows\SysNative\drivers\atksgt.sys ()
DRV:
64bit: - (lirsgt) -- C:\Windows\SysNative\drivers\lirsgt.sys ()
DRV:
64bit: - (MSHUSBVideo) -- C:\Windows\SysNative\drivers\nx6000.sys (Microsoft Corporation)
DRV:
64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:
64bit: - (mfefirek) -- C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:
64bit: - (mfewfpk) -- C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:
64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:
64bit: - (mfeapfk) -- C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:
64bit: - (mferkdet) -- C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:
64bit: - (mfenlfk) -- C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:
64bit: - (cfwids) -- C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (ScreamBAudioSvc) -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\HCW85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (HCW85BDA) -- C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:
64bit: - (ahcix64s) -- C:\Windows\SysNative\drivers\ahcix64s.sys (Advanced Micro Devices, Inc)
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (RTL8169) -- C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation )
DRV:
64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=91&bd=Pavilion&pf=cndt
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.runescape.com/
IE - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.startup.homepage: "http://www.startrekonline.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: YouTubeAutoReplay@arikv.com:2.5
FF - prefs.js..extensions.enabledItems: {a8864317-e18b-4292-99d9-e6e65ab905d3}:3.6.0.10
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.9.5
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:5.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {4ED1F68A-5463-4931-9384-8FFF5ED91D92}:3.4.0
FF - prefs.js..keyword.URL: "chrome://browser-region/locale/region.properties"
FF - prefs.js..keyword.enabled: false
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Audio and Video programs\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Matt\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2011/09/27 01:13:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/22 21:48:05 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/26 23:32:08 | 000,000,000 | ---D | M]
[2010/02/04 22:22:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matt\AppData\Roaming\Mozilla\Extensions
[2011/10/30 20:45:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\2cesy0m7.default\extensions
[2011/04/13 13:09:41 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\2cesy0m7.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/09/28 15:57:58 | 000,000,000 | ---D | M] (RuneScape Community Toolbar) -- C:\Users\Matt\AppData\Roaming\Mozilla\Firefox\Profiles\2cesy0m7.default\extensions\{a8864317-e18b-4292-99d9-e6e65ab905d3}
[2011/10/22 21:48:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/09/05 01:17:44 | 000,000,000 | ---D | M] (Skype extension for Firefox) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/06/29 04:02:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/29 05:20:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/10/26 00:38:37 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2010/12/26 01:51:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/26 21:39:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/06/25 17:39:11 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/29 02:53:40 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2010/10/13 22:28:54 | 000,024,376 | ---- | M] (McAfee, Inc.) -- C:\Program Files (x86)\mozilla firefox\components\Scriptff.dll
[2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/07/11 17:48:12 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll
[2011/09/28 20:26:50 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/03/30 15:08:28 | 000,002,027 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
O1 HOSTS File: ([2011/10/29 23:56:12 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho64.dll ()
O2:
64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110327193126.dll (McAfee, Inc.)
O2:
64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (McAfee Phishing Filter) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\Program Files\McAfee\MSK\mskapbho.dll ()
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110327193126.dll (McAfee, Inc.)
O2 - BHO: (Skype add-on for Internet Explorer) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (Microsoft Live Search Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3:
64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Microsoft Live Search Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files (x86)\MSN\Toolbar\3.0.0541.0\msneshellx.dll (Microsoft Corp.)
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe (Hewlett-Packard)
O4:
64bit: - HKLM..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Health Check Scheduler] c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe (Hewlett-Packard)
O4 - HKLM..\Run: [HP Remote Solution] C:\Program Files (x86)\Hewlett-Packard\HP Remote Solution\HP_Remote_Solution.exe ()
O4 - HKLM..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKLM..\Run: [LifeCam] C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Users\Matt\Downloads\PowerColor HD5750\Catalyst\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] c:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDIRShortCut] c:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePSTShortCut] c:\Program Files (x86)\CyberLink\CyberLink DVD Suite Deluxe\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKU\S-1-5-21-3941653321-956662587-3663273246-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKU\S-1-5-21-3941653321-956662587-3663273246-1000..\Run: [Steam] C:\Games\Steam\steam.exe (Valve Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKU\S-1-5-21-3941653321-956662587-3663273246-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {36299202-09EF-4ABF-ADB9-47C599DBE778}
https://www.hpwindows7upgrade.arvato.com/north_america/Endcustomer/HPProdDetect.cab (HP Product Detection Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.226.51.46 209.226.51.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{39968C27-287A-45EB-9CF5-405132056AC3}: DhcpNameServer = 209.226.51.46 209.226.51.10
O18:
64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\Users\Matt\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Matt\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/30 20:51:30 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Matt\Desktop\OTL.exe
[2011/10/30 20:02:07 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{D1FC0D4F-E00E-4E0E-8EFD-14F4CAE072A7}
[2011/10/30 20:01:56 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{BCD8F9CA-525B-46B5-ABF7-8B2E6DB24ADB}
[2011/10/30 17:51:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2011/10/29 23:56:29 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2011/10/29 22:16:48 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/10/29 22:16:48 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/10/29 22:16:48 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/10/29 22:16:43 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/10/29 22:16:31 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/10/29 21:53:29 | 004,278,104 | R--- | C] (Swearware) -- C:\Users\Matt\Desktop\ComboFix.exe
[2011/10/29 21:12:30 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{D38664A3-E39D-4689-8C17-9C46F5556308}
[2011/10/29 21:12:19 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{2AB283AC-0E5E-4DE8-BD12-14E44A0C4F34}
[2011/10/29 03:24:54 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{A6E06778-B3EF-4E46-A55D-8D32173CF299}
[2011/10/29 03:24:43 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{61EE83BD-DCEC-47CC-B558-C0C5537D7614}
[2011/10/28 15:24:15 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B37334B3-D64D-415C-B266-F78D617176E3}
[2011/10/28 15:24:02 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{F0F87D74-6DC9-4980-A732-654DE5938E23}
[2011/10/28 03:23:34 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{3E440285-298D-4763-A16A-B45DC01ADA89}
[2011/10/27 15:23:02 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{3479FAEB-5E76-410E-B3CF-36265FDCA3EE}
[2011/10/27 15:22:47 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{C717845E-FC58-47D8-A6B4-8D3D0EFB3F4C}
[2011/10/26 16:11:04 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{357FAF4A-10FE-4905-91EB-3D987BF3301D}
[2011/10/26 16:10:52 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{8257D57C-ABD3-4AD6-9F3E-6695F5289E57}
[2011/10/26 03:28:25 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{600A37D2-08C5-4AC5-94BA-96ED02205991}
[2011/10/26 03:28:14 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{78C2A276-F8AA-4FC4-8351-B2DD1D8DE383}
[2011/10/25 21:48:52 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Roaming\Disney Interactive Studios
[2011/10/25 15:27:45 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E1341920-196D-49BA-A1AF-59A3D83E6B6E}
[2011/10/25 15:27:33 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{AE05FF53-6BF7-4FD9-BF50-C332F89FB252}
[2011/10/25 03:24:28 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{47F60337-EBEB-4927-AE80-55FB7F20AD8D}
[2011/10/24 15:24:03 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{6D6D3B18-0262-4A74-A400-1CD73C559C5E}
[2011/10/24 15:23:50 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{08C0D8A3-C224-406F-A771-7A565EF7166F}
[2011/10/23 16:04:45 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B3CBF8E7-E087-4C33-B9DA-16168D2BC0CF}
[2011/10/23 16:04:33 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E004C5DB-1E21-4267-904E-69A5622A42F7}
[2011/10/23 02:35:27 | 000,000,000 | ---D | C] -- C:\Users\Matt\Desktop\adware
[2011/10/23 01:33:38 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/10/22 21:57:07 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Roaming\Malwarebytes
[2011/10/22 21:56:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/22 21:56:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/10/22 21:56:38 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/10/22 21:56:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/22 21:19:32 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{578C534B-3BFB-4C2B-9100-32FCDF0E81A4}
[2011/10/22 21:19:21 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{57C5F6BA-1F25-4A2C-9123-1A43B0552458}
[2011/10/22 01:38:53 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{1C47D9D9-CA83-4097-9DB1-F3AB88E1CFD2}
[2011/10/22 01:38:42 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B9BBDFE2-F2E3-4AEA-B070-828F63329F5A}
[2011/10/21 23:07:47 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\Fallout3
[2011/10/21 13:38:15 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{16EF0C59-5C4F-47BB-AA41-F33BA5AF63F9}
[2011/10/21 13:38:04 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B3DBAE6D-56A9-4CAB-9195-A9306A74200D}
[2011/10/21 01:37:38 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{29B1695B-0133-45B4-AF14-8B58B6D518F7}
[2011/10/20 13:37:13 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E420C3B5-05FD-4928-88E5-E049C4CC3D25}
[2011/10/20 13:37:01 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{AE87C397-186E-490F-9521-FF5F56FE2754}
[2011/10/19 15:54:47 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{D00C1B5C-CB03-4A42-8FD3-038A3E00C08D}
[2011/10/19 15:54:36 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{49954C21-F7B7-48B8-B9D1-A810A9F8EBFA}
[2011/10/19 02:01:01 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{81378572-E11B-4C4A-A140-F11E283DDBC1}
[2011/10/19 02:00:50 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{EB7F9244-101E-4BCD-8335-9A72A8D68A84}
[2011/10/18 14:00:14 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{9C12630A-2BD3-4DBC-907A-65C010817C5F}
[2011/10/18 14:00:00 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{EEC83AD5-E0E1-4318-B8C1-95FCDFE404D3}
[2011/10/18 01:59:32 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{0C3301D5-523B-4297-B45B-C7235465E40F}
[2011/10/18 01:59:21 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{5471246C-F497-49B9-94F9-AAAB65E7E8BD}
[2011/10/17 13:58:50 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{F9303786-2A46-4AE5-A32C-4D5D589E2F52}
[2011/10/17 13:58:39 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{436B1AB9-8007-44FE-A763-D2BCC79507E9}
[2011/10/16 15:40:59 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{2A903310-30C4-4CDE-BF64-BAC8B2C5E26A}
[2011/10/16 15:40:47 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{4096BD02-5FE3-4F11-AA88-BCFBC938B581}
[2011/10/16 02:15:30 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Roaming\.minecraft
[2011/10/16 01:28:08 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B079618C-82C3-498E-9D7A-0E9C3ECF3620}
[2011/10/15 13:27:41 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{AC248DE6-A5DD-4C1D-B866-B2A864A288D5}
[2011/10/15 13:27:28 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{6229058F-481B-4D14-BBCA-B3EABF2CCE09}
[2011/10/15 01:19:33 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{382E6DFC-B4A1-4410-903F-EA6D87A86E8E}
[2011/10/15 01:19:22 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{6E532250-A33D-4B0C-B304-C4C21E2E1951}
[2011/10/14 13:18:55 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{0A9025F0-5332-4E34-8DEE-DE2992D9A94E}
[2011/10/14 13:18:43 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{BE97BD9B-7FE1-44CE-AC52-54A52BD29F24}
[2011/10/13 15:53:50 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B476259B-C1D5-47CE-9D0B-7E6738C2D6B8}
[2011/10/13 15:53:37 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E7D89C8C-29AC-4027-B38B-21EECEE4E6C5}
[2011/10/13 02:46:54 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{3D4E13DB-71EF-400D-98A3-3813618C23FE}
[2011/10/13 02:46:44 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{009496E4-CAF8-40B0-A375-5A7C0CC59A6D}
[2011/10/12 14:46:17 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{8A6EE519-D01E-4EE9-8DA3-A4B3DED03B81}
[2011/10/12 14:46:04 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B51D6007-B11B-4C51-A65C-A105EAFAB126}
[2011/10/12 01:10:21 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B105D075-0EE9-42EB-9666-20391FBDC8A0}
[2011/10/12 01:10:10 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{3C30536B-303A-4033-82B1-78CAC69666A8}
[2011/10/11 13:09:44 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{FFD71169-5870-41CC-8E1A-8DFBEAF90180}
[2011/10/11 13:09:33 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{43F3C4E7-9EF8-4B27-8908-35BD50D8D16C}
[2011/10/11 01:09:08 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{97F5E2AA-0C7E-4FB1-B45E-60957EB4C02F}
[2011/10/11 00:25:05 | 000,000,000 | ---D | C] -- C:\Users\Matt\Desktop\Anoying Orange
[2011/10/10 13:08:44 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{6ABACDE2-46CB-40FC-BA1D-54BD2FCDD522}
[2011/10/10 13:08:33 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{03AD3048-FEED-4670-9BA3-5B1D16EA80F9}
[2011/10/10 00:12:12 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{C3221F5C-DF15-48E4-978B-E4374434602A}
[2011/10/10 00:12:01 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{D26F753A-D965-4D87-AB12-313F49F7CB0B}
[2011/10/09 12:11:34 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{8D30D00A-C959-481F-9CEC-F0DBD4AFCC79}
[2011/10/09 12:11:21 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{2C558A16-656B-407C-BC1E-A7212829EBCB}
[2011/10/08 15:42:24 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{635B1BCE-93E2-40DA-A0D1-4CC52AC3AD0A}
[2011/10/08 15:42:10 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{F8F537EC-E0F7-43B1-B603-69A5B0ABE31F}
[2011/10/07 15:40:18 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{61D88D6D-80B9-45FE-AF3B-424616565FBC}
[2011/10/07 15:40:07 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E495EE00-226D-4F12-B9B2-8C199520DBFF}
[2011/10/06 21:06:41 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{0AF335A4-001E-45C9-A7C0-92F5F8250D06}
[2011/10/06 21:06:30 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{897F3118-39E8-4DA8-B19C-D79901DA7082}
[2011/10/05 14:46:58 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{BFEEEC05-A08F-4F6D-A7D9-F95F8F971D22}
[2011/10/05 14:46:44 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{23D5BDA2-3683-4B68-A1CD-7013CEB61610}
[2011/10/04 14:37:37 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{5BE688D6-E00F-495E-957D-A319EDE629A2}
[2011/10/04 14:37:24 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{08A7C272-54DE-48A3-BE4A-A81A380AE295}
[2011/10/03 17:44:12 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{7577A4E6-474D-4CB0-8BC3-642082079757}
[2011/10/03 17:44:00 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{A0F6D1B3-523E-4BB6-B1F9-8ED3FA1C69E3}
[2011/10/02 14:37:04 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{FCC69C40-4270-418F-90F6-5696095074C8}
[2011/10/02 14:36:52 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{E9879DAE-EF49-4653-98E0-A7F7D184B3B2}
[2011/10/01 15:32:24 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B15AFEB3-DD85-4292-A052-EDEC2FC31F32}
[2011/10/01 15:32:11 | 000,000,000 | ---D | C] -- C:\Users\Matt\AppData\Local\{B97A31E6-4815-473D-B28C-9E214DFF43C0}
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Matt\AppData\Local\*.tmp files -> C:\Users\Matt\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/30 20:51:35 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Matt\Desktop\OTL.exe
[2011/10/30 20:26:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/30 19:58:11 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/30 17:57:18 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/10/30 17:57:18 | 000,010,896 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/10/30 17:51:59 | 000,001,830 | ---- | M] () -- C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2011/10/30 17:49:31 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/10/30 17:49:17 | 2141,253,631 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/30 02:59:33 | 000,000,032 | ---- | M] () -- C:\Users\Matt\jagex_cl_runescape_LIVE.dat
[2011/10/30 00:55:16 | 000,001,169 | ---- | M] () -- C:\Users\Matt\Desktop\FUEL - Shortcut.lnk
[2011/10/29 23:56:12 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/10/29 21:53:36 | 004,278,104 | R--- | M] (Swearware) -- C:\Users\Matt\Desktop\ComboFix.exe
[2011/10/29 21:51:54 | 000,727,362 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/29 21:51:54 | 000,627,974 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/10/29 21:51:54 | 000,111,414 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/10/27 01:09:05 | 000,000,230 | ---- | M] () -- C:\Users\Matt\Desktop\SPORE™ Galactic Adventures.lnk
[2011/10/27 01:05:27 | 000,000,137 | ---- | M] () -- C:\Windows\disney.ini
[2011/10/25 21:08:18 | 000,001,345 | ---- | M] () -- C:\Users\Matt\Desktop\Fallout3 - Shortcut.lnk
[2011/10/25 15:39:28 | 000,000,129 | ---- | M] () -- C:\Users\Matt\jagex_runescape_preferences2.dat
[2011/10/25 15:39:02 | 000,000,046 | ---- | M] () -- C:\Users\Matt\jagex_runescape_preferences.dat
[2011/10/23 01:33:44 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/22 21:56:42 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/22 21:48:11 | 000,001,140 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/22 21:46:07 | 000,235,433 | ---- | M] () -- C:\Users\Matt\Desktop\bookmarks-2011-10-22.json
[2011/10/22 00:51:31 | 000,007,597 | ---- | M] () -- C:\Users\Matt\AppData\Local\resmon.resmoncfg
[2011/10/16 21:20:00 | 000,000,207 | ---- | M] () -- C:\Users\Matt\Desktop\Mount & Blade Warband.url
[2011/10/15 14:33:48 | 005,292,054 | ---- | M] () -- C:\Users\Matt\Desktop\Taja.bmp
[2011/10/13 17:30:17 | 000,001,524 | ---- | M] () -- C:\Users\Matt\.recently-used.xbel
[2011/10/13 16:57:02 | 010,269,781 | ---- | M] () -- C:\Users\Matt\Desktop\The Doctor Forever.mp4
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Matt\AppData\Local\*.tmp files -> C:\Users\Matt\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/10/30 00:55:16 | 000,001,169 | ---- | C] () -- C:\Users\Matt\Desktop\FUEL - Shortcut.lnk
[2011/10/29 22:16:48 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/10/29 22:16:48 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/10/29 22:16:48 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/10/29 22:16:48 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/10/29 22:16:48 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/10/27 01:09:05 | 000,000,230 | ---- | C] () -- C:\Users\Matt\Desktop\SPORE™ Galactic Adventures.lnk
[2011/10/25 21:37:09 | 000,000,137 | ---- | C] () -- C:\Windows\disney.ini
[2011/10/25 15:39:00 | 000,000,032 | ---- | C] () -- C:\Users\Matt\jagex_cl_runescape_LIVE.dat
[2011/10/22 21:56:42 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/22 21:48:11 | 000,001,152 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2011/10/22 21:48:11 | 000,001,140 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/10/22 21:46:05 | 000,235,433 | ---- | C] () -- C:\Users\Matt\Desktop\bookmarks-2011-10-22.json
[2011/10/21 23:54:36 | 000,001,345 | ---- | C] () -- C:\Users\Matt\Desktop\Fallout3 - Shortcut.lnk
[2011/10/16 21:20:00 | 000,000,207 | ---- | C] () -- C:\Users\Matt\Desktop\Mount & Blade Warband.url
[2011/10/13 17:30:17 | 000,001,524 | ---- | C] () -- C:\Users\Matt\.recently-used.xbel
[2011/10/13 16:56:04 | 010,269,781 | ---- | C] () -- C:\Users\Matt\Desktop\The Doctor Forever.mp4
[2011/09/17 15:14:35 | 000,004,096 | ---- | C] () -- C:\Windows\ndridev.dll
[2011/07/31 16:19:57 | 000,000,000 | ---- | C] () -- C:\Users\Matt\AppData\Local\{70F8A395-B2B1-4D0C-B2F2-1227468FBEC6}
[2011/07/31 16:19:34 | 000,000,000 | ---- | C] () -- C:\Users\Matt\AppData\Local\{D782D29B-9322-4513-B93F-E24EA554DD4A}
[2011/06/12 21:54:44 | 000,734,870 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/04/23 21:00:21 | 000,679,770 | ---- | C] () -- C:\Windows\unins000.exe
[2011/04/23 21:00:21 | 000,044,141 | ---- | C] () -- C:\Windows\unins000.dat
[2011/04/12 00:44:11 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2011/04/12 00:44:11 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2011/04/12 00:44:11 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/09/05 01:22:16 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/08/20 01:12:05 | 000,003,584 | ---- | C] () -- C:\Users\Matt\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/31 01:15:06 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2010/02/26 19:47:18 | 000,000,305 | ---- | C] () -- C:\Windows\game.ini
[2010/02/14 03:36:25 | 000,000,000 | ---- | C] () -- C:\Users\Matt\AppData\Roaming\wklnhst.dat
[2010/02/12 03:39:20 | 000,121,460 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.JPG
[2010/02/12 03:39:20 | 000,121,460 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.4
[2010/02/12 03:38:55 | 000,122,164 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.3
[2010/02/12 03:38:54 | 000,120,176 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.2
[2010/02/12 03:38:52 | 000,120,976 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.1
[2010/02/12 03:38:50 | 000,118,106 | ---- | C] () -- C:\Users\Matt\AppData\Local\tmpTHUNDER HORSE AND SANHICAN-A 8.0
[2010/02/06 22:47:11 | 000,007,597 | ---- | C] () -- C:\Users\Matt\AppData\Local\resmon.resmoncfg
[2010/02/04 22:56:53 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/02/04 18:18:14 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2010/01/29 21:14:50 | 000,000,248 | ---- | C] () -- C:\Windows\HCWBlast.ini
[2010/01/27 18:59:47 | 000,033,169 | ---- | C] () -- C:\Windows\Irremote.ini
[2010/01/27 18:59:21 | 000,000,209 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2010/01/27 18:59:21 | 000,000,135 | ---- | C] () -- C:\Windows\ODBC.INI
[2010/01/27 18:58:58 | 000,142,337 | ---- | C] () -- C:\Windows\SysWow64\Wait.exe
[2010/01/27 18:55:11 | 000,003,936 | ---- | C] () -- C:\Windows\HCWPNP.INI
[2010/01/24 16:21:06 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/14 01:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/03/16 01:47:28 | 000,122,880 | ---- | C] () -- C:\Windows\SysWow64\WinMsgBalloonServer.exe
[2009/03/16 01:47:24 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\WinMsgBalloonClient.exe
[2009/03/10 12:08:29 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll
[2009/03/10 12:08:29 | 000,102,400 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll
[2009/03/05 20:00:36 | 000,532,480 | ---- | C] () -- C:\Windows\SysWow64\libxml2.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007/07/23 09:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007/07/23 09:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2001/10/12 10:58:20 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\mr310exd.dll
[2001/10/12 10:57:18 | 000,036,864 | ---- | C] () -- C:\Windows\SysWow64\mr310exv.dll
[2000/12/07 10:13:58 | 000,015,164 | ---- | C] () -- C:\Windows\Mr310twv.ini
========== Alternate Data Streams ==========
@Alternate Data Stream - 149 bytes -> C:\ProgramData\Temp:8CE646EE
< End of report >
This post has been edited by Usko_Detra: 30 October 2011 - 08:45 PM