Here it is:
OTL logfile created on: 11/1/2011 2:22:38 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\robert\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.25 Gb Total Physical Memory | 4.42 Gb Available Physical Memory | 60.97% Memory free
14.50 Gb Paging File | 11.29 Gb Available in Paging File | 77.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 225.99 Gb Total Space | 148.93 Gb Free Space | 65.90% Space Free | Partition Type: NTFS
Drive D: | 5.89 Gb Total Space | 0.59 Gb Free Space | 10.00% Space Free | Partition Type: NTFS
Drive J: | 931.51 Gb Total Space | 765.07 Gb Free Space | 82.13% Space Free | Partition Type: NTFS
Drive P: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive Q: | 183.17 Gb Total Space | 58.98 Gb Free Space | 32.20% Space Free | Partition Type: NTFS
Drive R: | 261.16 Gb Total Space | 79.94 Gb Free Space | 30.61% Space Free | Partition Type: NTFS
Drive S: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive T: | 261.16 Gb Total Space | 79.94 Gb Free Space | 30.61% Space Free | Partition Type: NTFS
Drive U: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive V: | 558.75 Gb Total Space | 29.89 Gb Free Space | 5.35% Space Free | Partition Type: NTFS
Drive W: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive X: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive Y: | 927.44 Gb Total Space | 887.80 Gb Free Space | 95.73% Space Free | Partition Type: NTFS
Drive Z: | 261.16 Gb Total Space | 79.94 Gb Free Space | 30.61% Space Free | Partition Type: NTFS
Computer Name: RMSSTAT005 | User Name: robert | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\robert\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Plantronics\PlantronicsURE\PlantronicsBatteryStatus.exe (Plantronics, Inc.)
PRC - C:\Program Files (x86)\Plantronics\PlantronicsURE\PlantronicsURE.exe (Plantronics, Inc.)
PRC - C:\Program Files (x86)\YoWindow\yowindow.exe (Repkasoft)
PRC - C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe (N-able Technologies)
PRC - C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\AgentMaint.exe (N-able Technologies)
PRC - C:\Users\robert\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\IIS Express\iisexpress.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Ditto\Ditto.exe ()
PRC - C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Lync\UcMapi.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Shoreline Communications\ShoreWare Client\ShoreTel.exe (ShoreTel Inc.)
PRC - C:\Program Files (x86)\Shoreline Communications\ShoreWare Client\CSISCMGR.exe (ShoreTel, Inc.)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\ProtectionUtilSurrogate.exe (Symantec Corporation)
PRC - C:\ProgramData\FLEXnet\Connect\11\agent.exe (Flexera Software, Inc.)
PRC - C:\Program Files (x86)\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
PRC - C:\Program Files (x86)\Microsoft MapPoint Europe 2010\StreetsOlkShim.exe (Microsoft)
PRC - C:\Program Files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe (Iomega Corporation)
PRC - C:\Program Files (x86)\UltraVNC\winvnc.exe (UltraVNC)
PRC - C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
PRC - C:\Windows\SysWOW64\WinMsgBalloonServer.exe ()
PRC - C:\Windows\SysWOW64\WinMsgBalloonClient.exe ()
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
PRC - C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PlantronicsURE\58b47cfa84473cd7d5f9d6a103783867\PlantronicsURE.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PlantronicsBatteryS#\9a78e6fb736e15fc134f1ef6ec6ca627\PlantronicsBatteryStatus.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Wind#\b4556112287eda96265d7ec1232aceac\Plantronics.UC.WindowsMediaPlayer.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Skype\9fb2d6c2178df61592c3285b39693d99\Plantronics.UC.Skype.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Webe#\dc753302163da87d39052aa28d04c680\Plantronics.UC.WebexConnect.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Offi#\c87eedbcceb0fc6f443a0bdd5b281dec\Plantronics.UC.OfficeCommunicator.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Sess#\f599c51d45cb1596cb2787e94bff2d1c\Plantronics.UC.SessionService.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Shor#\52abe1973f654ead35672528d9e77800\Plantronics.UC.ShoreTel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.CSFC#\5173afef77eb5e3efdb1016db20c06cf\Plantronics.UC.CSFClient.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.iTun#\acba0ab7f4d21e3a10e102f50cecbefc\Plantronics.UC.iTunes.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.CSF\67efd9cef73890c662fe8cf903c70c0f\Plantronics.UC.CSF.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.TAPI\aa2d6617f8ccc1eac89f34fdd0bfe2fd\Plantronics.UC.TAPI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Cisco\b0f87257ce97815b4814571db877ef6b\Plantronics.UC.Cisco.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avay#\ed7b7b3c9623a04199cd3e5ffea721a9\Plantronics.UC.AvayaSoftphone.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avay#\14b9961fb69c7b5b6c6564c35404a4f9\Plantronics.UC.AvayaIPAgent.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Comm#\a14890ad8a6a9953aa58ee2b0158ead2\Plantronics.UC.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.UC.Avaya\3d417f2a7a9cf89521568c3c030007a8\Plantronics.UC.Avaya.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.License#\90bb1e08b2b27fb64bf05464030f9ad9\Plantronics.License.Manager.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.FlexNet#\793de4a6232faf2f544c7f3548447e7b\Plantronics.FlexNet.Adapter.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.License#\7965d955f47a9548d6aa4c5ec65cfcb5\Plantronics.License.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.Device.#\1f247575394c70f742ad3372531fec46\Plantronics.Device.Common.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.Globali#\f3c42ed80100e60d8ed32dc81f40fd0c\Plantronics.Globalization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.Device.#\9f1f6a2825cdf33da481bcc14a025cf8\Plantronics.Device.Hid.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.Utility\4e8d7ab59b31264100c4ecebf6f372d3\Plantronics.Utility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Plantronics.Config\92c0daa61c104dacdeb82328df5eee45\Plantronics.Config.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\log4net\e24b02f0752ac1bbac8cceebfa329c80\log4net.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.SKYPE4COMLib\165a8ad55a60ce99006b18a170615ccc\Interop.SKYPE4COMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\HtmlAgilityPack\d5f6594957a4b8754eed0844b0e32ace\HtmlAgilityPack.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.FNCClient11#\2fdf524b4c4c0a796c2af4acddbe5364\Interop.FNCClient11Lib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.Communicato#\6e4a43bcf8da94eaa64d7b36cd5f2dcb\Interop.CommunicatorAPI.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Interop.CiscoInterf#\ba79aef68c09b89e2364220eafb72bf5\Interop.CiscoInterface.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Atapi\00fcc9a281f7848e4e0cd2b545383d9a\Atapi.ni.dll ()
MOD - C:\Program Files (x86)\Ditto\Ditto.exe ()
MOD - C:\Program Files (x86)\Ditto\focus.dll ()
MOD - C:\Program Files (x86)\Ditto\sqlite3.dll ()
MOD - C:\Program Files (x86)\Ditto\zlib1.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMSkin\0a5e5b648b75dee958933bcb7abaa4d3\PCMSkin.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\EAEXCTRLLib\e6530f4ea9434d3d9dc53eb41a4fe7bf\EAEXCTRLLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Outlook\2f65bd951f3a968fd4fb69c85ef5b1a0\Outlook.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\AxInterop.SHDocVw\24d5a76235a5252daa6a6e6ef151a8b0\AxInterop.SHDocVw.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\STVideo\b62c69e4dc04de8bb5a0404a236c2eed\STVideo.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMLib\9830b93c41bc36b49c50286064833c34\PCMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMControls\a7c35b68db12116c3066425582bc2fcf\PCMControls.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMIMLib\b19a818e9c6a72dd847ac990fe659999\PCMIMLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMUtils\719d76429eba0a4ecaeae87ad55040d2\PCMUtils.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\EMMgcpAxNET\51dd172a6ea35f6379327bec3f5ac8ab\EMMgcpAxNET.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMBasics\9fac3e02ee16fa18f2f817310275e5ed\PCMBasics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PCMTrace\5a0809323152a9946b92a456513371ee\PCMTrace.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraVert#\903c34387d4040b83305919d5436ac46\DevExpress.XtraVerticalGrid.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraGrid#\8e8473db921e3968e5ccae14265a4b3c\DevExpress.XtraGrid.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraEdit#\74c1a2b5973849dcc9a1a29c5df71596\DevExpress.XtraEditors.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.XtraBars#\e7dd4d4b6cfef9cc3074235879691656\DevExpress.XtraBars.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\STUIControls\79d9dc1949e93d750b9bb0c120125cf8\STUIControls.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Data.v9.1\50d4971c3e1624de130cf4446ac8290b\DevExpress.Data.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DevExpress.Utils.v9#\764b3b900865af128a4f295b7250c79b\DevExpress.Utils.v9.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\ShoreTel\caf2cab0d0422f9c9e3185e1dee82a23\ShoreTel.ni.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\2ce20cdf50b09576d2cbebefeeb74598\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2e2e31c87004468796d3defa1a1df011\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\aadfdc0e7d9181a98d667a52c3c35601\System.Configuration.ni.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\c0f61f9b73571f26b6e0e0757bc5f460\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Design\d802dc9d6af9beb0a7c59259e6997ca0\System.Design.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\7f457271e765b5d72f081942b829469c\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ead6be8b410d56b5576b10e56af2c180\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\003d2d74243cab7e412d36416bbf0a3d\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5dd9f783008543df3e642ff1e99de4e8\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5ba3bf5367fc012300c6566f20cb7f54\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\8c1770d45c63cf5c462eeb945ef9aa5d\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AcroTray.DEU ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\AcroTray.FRA ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\sqlite.dll ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:
64bit: - (TlntSvr) -- C:\Windows\SysNative\tlntsvr.exe (Microsoft Corporation)
SRV:
64bit: - (BrcmMgmtAgent) -- C:\Program Files\Broadcom\MgmtAgent\BrcmMgmtAgent.exe (Broadcom Corporation)
SRV - (Akamai) -- c:\Program Files (x86)\Common Files\Akamai\netsession_win_807ba95.dll ()
SRV - (LMIMaint) -- C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (RSMWebServer) -- C:\Program Files (x86)\N-able Technologies\NRM\RSMWinService.exe ()
SRV - (Windows Agent Service) -- C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe (N-able Technologies)
SRV - (Windows Agent Maintenance Service) -- C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\AgentMaint.exe (N-able Technologies)
SRV - (winrdp_service) -- C:\Program Files (x86)\N-able Technologies\NRM\UltraVNCServer\winrdp.exe (WCCS)
SRV - (GoToAssist Express Customer) -- C:\Program Files (x86)\Citrix\GoToAssist Express Customer\290\g2ax_service.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (LogMeIn) -- C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (ccSetMgr) -- C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) -- C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SNAC) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\SNAC64.EXE (Symantec Corporation)
SRV - (SmcService) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus) -- C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SupportSoft RemoteAssist) -- C:\Program Files (x86)\Common Files\supportsoft\bin\ssrc.exe (SupportSoft, Inc.)
SRV - (LiveUpdate) -- C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (uvnc_service) -- C:\Program Files (x86)\UltraVNC\WinVNC.exe (UltraVNC)
SRV - (pdfcDispatcher) -- C:\Program Files (x86)\PDF Complete\pdfsvc.exe (PDF Complete Inc)
SRV - (RoxMediaDB10) -- C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (AMD_RAIDXpert) -- C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe (AMD)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (LMIRfsClientNP) -- C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:
64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (LMIRfsDriver) -- C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:
64bit: - (lmimirr) -- C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:
64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:
64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\srtspx64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSPL) -- C:\Windows\SysNative\drivers\srtspl64.sys (Symantec Corporation)
DRV:
64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\srtsp64.sys (Symantec Corporation)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (ahcix64s) -- C:\Windows\SysNative\drivers\ahcix64s.sys (Advanced Micro Devices, Inc)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (TPM) -- C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:
64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (Blfp) -- C:\Windows\SysNative\drivers\basp.sys (Broadcom Corporation)
DRV:
64bit: - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV:
64bit: - (USBModem) -- C:\Windows\SysNative\drivers\lgx64modem.sys (LG Electronics Inc.)
DRV:
64bit: - (UsbDiag) -- C:\Windows\SysNative\drivers\lgx64diag.sys (LG Electronics Inc.)
DRV:
64bit: - (usbbus) -- C:\Windows\SysNative\drivers\lgx64bus.sys (LG Electronics Inc.)
DRV - (NAVEX15) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111031.034\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Symantec\Definitions\VirusDefs\20111031.034\ENG64.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (LMIInfo) -- C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - (SRTSPX) -- C:\Windows\SysWOW64\drivers\srtspx64.sys (Symantec Corporation)
DRV - (SRTSPL) -- C:\Windows\SysWOW64\drivers\srtspl64.sys (Symantec Corporation)
DRV - (SRTSP) -- C:\Windows\SysWOW64\drivers\srtsp64.sys (Symantec Corporation)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-796845957-117609710-1801674531-2638\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://sql07:8000/UI/Home.aspx
IE - HKU\S-1-5-21-796845957-117609710-1801674531-2638\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/DownloadManager,version=1.1: C:\Windows\ [2011/10/31 08:51:34 | 000,000,000 | ---D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\webdialer@shoretel.com: C:\Program Files (x86)\ShoreTel\Web Dialer\webdialer [2010/12/17 10:42:09 | 000,000,000 | ---D | M]
[2010/10/22 02:24:26 | 000,032,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
O1 HOSTS File: ([2011/10/31 08:48:14 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ccApp] C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Iomega Home Storage Manager] C:\Program Files (x86)\Iomega\Home Storage Manager\Iomega Discovery.exe (Iomega Corporation)
O4 - HKLM..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe (PDF Complete Inc)
O4 - HKLM..\Run: [PlantronicsBatteryStatus.exe] C:\Program Files (x86)\Plantronics\PlantronicsURE\PlantronicsBatteryStatus.exe (Plantronics, Inc.)
O4 - HKLM..\Run: [PlantronicsURE.exe] C:\Program Files (x86)\Plantronics\PlantronicsURE\PlantronicsURE.exe (Plantronics, Inc.)
O4 - HKLM..\Run: [RightFAX Print-to-Fax Driver] C:\Program Files (x86)\RightFax\Client\FAXCTRL.exe (Captaris, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-796845957-117609710-1801674531-2638..\Run: [Ditto] C:\Program Files (x86)\Ditto\Ditto.exe ()
O4 - HKU\S-1-5-21-796845957-117609710-1801674531-2638..\Run: [ShoreTel Personal Call Manager] C:\Program Files (x86)\Shoreline Communications\ShoreWare Client\ShoreTel.exe (ShoreTel Inc.)
O4 - Startup: C:\Users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\robert\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Excalibur RSS Reader.appref-ms ()
O4 - Startup: C:\Users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\YoWindow.lnk = C:\Program Files (x86)\YoWindow\yowindow.exe (Repkasoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideFastUserSwitching = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = [binary data]
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: &ShoreTel Web Dialer - C:\Program Files (x86)\ShoreTel\Web Dialer\MakeACall.htm ()
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O8 - Extra context menu item: &ShoreTel Web Dialer - C:\Program Files (x86)\ShoreTel\Web Dialer\MakeACall.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office14\EXCEL.EXE/3000 File not found
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: factorybrands.net ([locks] http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: fmpilot.com ([anf] http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: fmpilot.com ([www] http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: servicechannel.com ([www4] http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: sql07 ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: sql08 ([]http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Domains: workoasis.com ([nmfm] http in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Ranges: Range1 ([http] in Trusted sites)
O15 - HKU\S-1-5-21-796845957-117609710-1801674531-2638\..Trusted Ranges: Range2 ([http] in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control)
O16 - DPF: {08D390AE-5101-4701-A89F-6C6DADCCC402}
http://photos.msn.com/resources/neutral/controls/MsnPPick.cab?10,0,910,0 (MSN Photo Select Tool)
O16 - DPF: {0D221D00-A6ED-477C-8A91-41F3B660A832}
http://dnr.wi.gov/WasteMgmt/wm/WMExternal/Reserved.ReportViewerWebControl.axd?Mode=true&ReportID=99b6f24451e34fb7b98ed7c0bfffa47e&ControlID=895aa3177b534575b83442168afd0827&Culture=1033&UICulture=1033&ReportStack=1&OpType=PrintCab (RSClientPrint 2005 Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2670A42B-22E7-46E5-BCA9-BF50CF6A80D1}
http://dinosrest2.no-ip.biz:81/bvip_setup.cab (CAutoloadControl Object)
O16 - DPF: {41861299-EAB2-4DCC-986C-802AE12AC499}
http://sql08/ReportServer/Reserved.ReportViewerWebControl.axd?ExecutionID=mibfol55oesqg3mozqjmuprm&ControlID=abac4d5a6f3e4de3bf86a312dae3a802&Culture=1033&UICulture=9&ReportStack=1&OpType=PrintCab (RSClientPrint 2005 Class)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab (DLM Control)
O16 - DPF: {71D73A47-975F-11D1-AA77-00A0C98D86D4}
http://192.168.1.240/shorewaredirector/VoiceMessage.ocx (VoiceMessage Control)
O16 - DPF: {721700FE-7F0E-49C5-BDED-CA92B7CB1245}
http://65.44.139.2:9203/camclictrl.cab (Camera Stream Client Control Object)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {7ECB1A47-6647-4B2C-A8DA-675569C9FF15}
http://www.mpix.com/customer/uploading/scripts7/ImageUploader7.cab (Image Uploader Control)
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0}
https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab (DLC Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE}
https://msdn.vo.msecnd.net/pr/MSDownloadManager_en-US.cab?e=1624911450&h=257922df4d56ad0f5be36b0e4bfa8756 (Microsoft Download Manager ActiveX control)
O16 - DPF: {CAA6C3B6-662B-4D14-BB64-EADB88213BFE}
http://192.168.1.137/IPCamPluginTM.cab (IPCamPluginTMPT Control)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {DB9DE2A8-D1BA-472A-B1F8-39697899DEF7}
http://pagerman.kguard.org/HiDvrOcx.cab (HiDvrOcx Control)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://akamaicdn.webex.com/client/WBXclient-T27L10NSP28EP2-12243/webex/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O16 - DPF: {FE5B9F54-7764-4C01-89F0-4862601EE954}
http://photos.msn.com/resources/neutral/controls/DigWebX2.cab?10,0,910,0 (DigWebHelper Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.10
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = retail.local
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{33C8C3C2-DC0A-42CB-99F9-B74A2775F0F4}: DhcpNameServer = 192.168.1.10
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\GoToAssist Express Customer: DllName - (C:\Program Files (x86)\Citrix\GoToAssist Express Customer\290\g2ax_winlogonx64.dll) - C:\Program Files (x86)\Citrix\GoToAssist Express Customer\290\g2ax_winlogonx64.dll (Citrix Online, a division of Citrix Systems, Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/17 06:30:39 | 000,000,000 | ---D | M] - C:\AUTOUPGRADETEMP -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/01 14:21:31 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\robert\Desktop\OTL.exe
[2011/11/01 10:26:03 | 000,000,000 | ---D | C] -- C:\Users\robert\Desktop\1442
[2011/11/01 10:11:26 | 000,000,000 | ---D | C] -- C:\Users\robert\Desktop\Cover Project 2011
[2011/11/01 07:40:44 | 001,564,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\robert\Desktop\tdsskiller.exe
[2011/10/31 10:08:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\UltraVNC
[2011/10/31 10:06:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IIS Express
[2011/10/31 10:04:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\N-able Technologies
[2011/10/31 09:22:29 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/10/31 07:59:16 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/10/28 09:30:46 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\robert\Desktop\dds.com
[2011/10/28 07:36:58 | 000,000,000 | ---D | C] -- C:\Users\robert\AppData\Local\Adobe
[2011/10/27 16:46:27 | 000,050,688 | ---- | C] (Atribune.org) -- C:\Users\robert\Desktop\ATF-Cleaner.exe
[2011/10/27 12:34:41 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/10/27 09:31:08 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/10/27 09:31:07 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011/10/27 09:31:07 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/10/27 09:31:07 | 001,427,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011/10/27 09:31:07 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/10/27 09:31:07 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/10/27 09:31:07 | 000,434,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011/10/27 09:31:07 | 000,367,104 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011/10/27 09:31:07 | 000,267,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011/10/27 09:31:07 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/10/27 09:31:07 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/10/27 09:31:07 | 000,227,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011/10/27 09:31:07 | 000,222,208 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011/10/27 09:31:07 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011/10/27 09:31:07 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/10/27 09:31:07 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011/10/27 09:31:07 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011/10/27 09:31:07 | 000,163,840 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011/10/27 09:31:07 | 000,162,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011/10/27 09:31:07 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011/10/27 09:31:07 | 000,152,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011/10/27 09:31:07 | 000,150,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011/10/27 09:31:07 | 000,149,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011/10/27 09:31:07 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011/10/27 09:31:07 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011/10/27 09:31:07 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011/10/27 09:31:07 | 000,130,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011/10/27 09:31:07 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011/10/27 09:31:07 | 000,118,784 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011/10/27 09:31:07 | 000,114,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011/10/27 09:31:07 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011/10/27 09:31:07 | 000,110,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011/10/27 09:31:07 | 000,101,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011/10/27 09:31:07 | 000,091,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/10/27 09:31:07 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/10/27 09:31:07 | 000,086,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011/10/27 09:31:07 | 000,078,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011/10/27 09:31:07 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/10/27 09:31:07 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011/10/27 09:31:07 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011/10/27 09:31:07 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/10/27 09:31:07 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011/10/27 09:31:07 | 000,065,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011/10/27 09:31:07 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011/10/27 09:31:07 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011/10/27 09:31:07 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011/10/27 09:31:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011/10/27 09:31:07 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011/10/27 09:31:07 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011/10/27 09:31:07 | 000,023,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011/10/27 09:31:07 | 000,012,288 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011/10/27 09:31:07 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011/10/27 09:31:07 | 000,010,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011/10/27 09:31:06 | 003,695,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011/10/27 09:31:06 | 001,492,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011/10/27 09:31:06 | 000,697,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011/10/27 09:31:06 | 000,603,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011/10/27 09:31:06 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011/10/27 09:31:06 | 000,452,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011/10/27 09:31:06 | 000,448,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011/10/27 09:31:06 | 000,282,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011/10/27 09:31:06 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/10/27 09:31:06 | 000,165,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011/10/27 09:31:06 | 000,160,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011/10/27 09:31:06 | 000,103,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011/10/27 09:31:06 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/10/27 09:31:06 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011/10/27 09:31:06 | 000,085,504 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011/10/27 09:31:06 | 000,082,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011/10/27 09:31:06 | 000,076,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011/10/27 09:31:06 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011/10/27 09:31:06 | 000,030,720 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011/10/27 09:29:58 | 001,888,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2011/10/27 09:29:58 | 001,619,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2011/10/27 09:29:58 | 000,320,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011/10/27 09:29:58 | 000,265,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/10/27 09:29:58 | 000,197,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011/10/27 09:29:58 | 000,144,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/10/27 09:29:57 | 004,068,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2011/10/27 09:29:57 | 003,181,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2011/10/27 09:29:57 | 001,863,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/10/27 09:29:57 | 001,837,568 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/10/27 09:29:57 | 001,540,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/10/27 09:29:57 | 001,495,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/10/27 09:29:57 | 000,902,656 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/10/27 09:29:57 | 000,662,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/10/27 09:29:57 | 000,470,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/10/27 09:29:57 | 000,442,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/10/27 09:29:57 | 000,283,648 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/10/27 09:29:57 | 000,257,024 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2011/10/27 09:29:57 | 000,229,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/10/27 09:29:57 | 000,206,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2011/10/27 09:29:57 | 000,196,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2011/10/27 09:29:57 | 000,135,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/10/26 13:05:17 | 000,525,544 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2011/10/26 13:05:17 | 000,190,752 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2011/10/26 13:05:17 | 000,171,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2011/10/26 13:05:17 | 000,171,808 | ---- | C] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2011/10/26 13:05:04 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2011/10/26 13:04:46 | 017,197,344 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\robert\Desktop\jre-6u29-windows-x64.exe
[2011/10/26 09:24:45 | 001,564,464 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\robert\Desktop\iexplore.exe
[2011/10/26 08:39:49 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011/10/26 08:39:49 | 000,000,000 | ---D | C] -- C:\Users\robert\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/10/26 08:08:21 | 000,200,976 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/10/25 16:14:05 | 000,000,000 | ---D | C] -- C:\Users\robert\AppData\Roaming\Malwarebytes
[2011/10/25 16:14:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/25 16:14:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/10/25 16:13:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/10/25 16:13:44 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\robert\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/25 13:34:49 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/10/25 13:34:49 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/10/25 13:34:49 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/10/25 13:33:45 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/10/25 13:31:17 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/10/25 13:30:09 | 004,278,520 | R--- | C] (Swearware) -- C:\Users\robert\Desktop\ComboFix.exe
[2011/10/18 07:50:15 | 071,733,104 | ---- | C] (Apple Inc.) -- C:\Users\robert\Desktop\iTunes64Setup.exe
[2011/10/06 09:13:10 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Lync Server 2010
[2011/10/06 09:07:58 | 000,000,000 | ---D | C] -- C:\Users\robert\Desktop\BBW911
[2011/10/05 14:03:03 | 000,000,000 | ---D | C] -- C:\Users\robert\Desktop\Phone Ext_files
[2011/10/04 10:53:08 | 000,000,000 | ---D | C] -- C:\Users\robert\AppData\Roaming\webex
[2011/10/04 10:05:00 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2011/10/04 07:38:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Winamp
========== Files - Modified Within 30 Days ==========
[2011/11/01 14:21:33 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\robert\Desktop\OTL.exe
[2011/11/01 13:32:09 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/01 13:32:01 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/01 10:12:07 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 10:12:07 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/01 07:40:48 | 001,564,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\robert\Desktop\tdsskiller.exe
[2011/11/01 07:36:12 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/01 07:35:41 | 1543,024,639 | -HS- | M] () -- C:\hiberfil.sys
[2011/10/31 16:36:46 | 000,002,036 | ---- | M] () -- C:\Users\robert\Documents\Default.rdp
[2011/10/31 13:48:30 | 000,000,819 | ---- | M] () -- C:\Users\robert\Desktop\UltraVNC Viewer.lnk
[2011/10/31 10:05:49 | 000,000,862 | ---- | M] () -- C:\Windows\SysNative\termcap
[2011/10/31 10:05:24 | 000,000,708 | ---- | M] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2011/10/31 10:04:57 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\client.db
[2011/10/31 10:04:56 | 000,798,968 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/31 10:04:56 | 000,663,252 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/10/31 10:04:56 | 000,121,904 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/10/31 08:48:14 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/10/31 07:55:13 | 004,278,520 | R--- | M] (Swearware) -- C:\Users\robert\Desktop\ComboFix.exe
[2011/10/28 09:38:43 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\robert\Desktop\dds.com
[2011/10/27 17:44:32 | 000,050,688 | ---- | M] (Atribune.org) -- C:\Users\robert\Desktop\ATF-Cleaner.exe
[2011/10/27 16:47:13 | 000,782,218 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/10/27 12:21:57 | 000,000,737 | ---- | M] () -- C:\Users\robert\Desktop\VSS October 2011 - Shortcut.lnk
[2011/10/27 09:38:51 | 000,001,439 | ---- | M] () -- C:\Users\robert\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/10/27 09:31:08 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/10/27 09:31:07 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dat
[2011/10/27 09:31:07 | 002,309,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/10/27 09:31:07 | 001,427,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2011/10/27 09:31:07 | 000,818,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/10/27 09:31:07 | 000,716,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/10/27 09:31:07 | 000,434,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2011/10/27 09:31:07 | 000,367,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\html.iec
[2011/10/27 09:31:07 | 000,267,776 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieaksie.dll
[2011/10/27 09:31:07 | 000,248,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/10/27 09:31:07 | 000,231,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/10/27 09:31:07 | 000,227,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieaksie.dll
[2011/10/27 09:31:07 | 000,222,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msls31.dll
[2011/10/27 09:31:07 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2011/10/27 09:31:07 | 000,176,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/10/27 09:31:07 | 000,173,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2011/10/27 09:31:07 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakui.dll
[2011/10/27 09:31:07 | 000,163,840 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakui.dll
[2011/10/27 09:31:07 | 000,162,304 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2011/10/27 09:31:07 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieakeng.dll
[2011/10/27 09:31:07 | 000,152,064 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\wextract.exe
[2011/10/27 09:31:07 | 000,150,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iexpress.exe
[2011/10/27 09:31:07 | 000,149,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\occache.dll
[2011/10/27 09:31:07 | 000,145,920 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iepeers.dll
[2011/10/27 09:31:07 | 000,142,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2011/10/27 09:31:07 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\IEAdvpack.dll
[2011/10/27 09:31:07 | 000,130,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieakeng.dll
[2011/10/27 09:31:07 | 000,123,392 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\occache.dll
[2011/10/27 09:31:07 | 000,118,784 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iepeers.dll
[2011/10/27 09:31:07 | 000,114,176 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\admparse.dll
[2011/10/27 09:31:07 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesysprep.dll
[2011/10/27 09:31:07 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\IEAdvpack.dll
[2011/10/27 09:31:07 | 000,101,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\admparse.dll
[2011/10/27 09:31:07 | 000,091,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/10/27 09:31:07 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/10/27 09:31:07 | 000,086,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesysprep.dll
[2011/10/27 09:31:07 | 000,078,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inseng.dll
[2011/10/27 09:31:07 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/10/27 09:31:07 | 000,074,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2011/10/27 09:31:07 | 000,074,240 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ie4uinit.exe
[2011/10/27 09:31:07 | 000,072,822 | ---- | M] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/10/27 09:31:07 | 000,072,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/10/27 09:31:07 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\icardie.dll
[2011/10/27 09:31:07 | 000,065,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\pngfilt.dll
[2011/10/27 09:31:07 | 000,063,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\tdc.ocx
[2011/10/27 09:31:07 | 000,054,272 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\pngfilt.dll
[2011/10/27 09:31:07 | 000,049,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\imgutil.dll
[2011/10/27 09:31:07 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmler.dll
[2011/10/27 09:31:07 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmler.dll
[2011/10/27 09:31:07 | 000,031,744 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2011/10/27 09:31:07 | 000,023,552 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\licmgr10.dll
[2011/10/27 09:31:07 | 000,012,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshta.exe
[2011/10/27 09:31:07 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msfeedssync.exe
[2011/10/27 09:31:07 | 000,010,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeedssync.exe
[2011/10/27 09:31:06 | 003,695,416 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dat
[2011/10/27 09:31:06 | 001,492,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2011/10/27 09:31:06 | 000,697,344 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2011/10/27 09:31:06 | 000,603,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2011/10/27 09:31:06 | 000,534,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2011/10/27 09:31:06 | 000,452,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtmsft.dll
[2011/10/27 09:31:06 | 000,448,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\html.iec
[2011/10/27 09:31:06 | 000,282,112 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\dxtrans.dll
[2011/10/27 09:31:06 | 000,237,056 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/10/27 09:31:06 | 000,165,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iexpress.exe
[2011/10/27 09:31:06 | 000,160,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\wextract.exe
[2011/10/27 09:31:06 | 000,103,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inseng.dll
[2011/10/27 09:31:06 | 000,096,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/10/27 09:31:06 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2011/10/27 09:31:06 | 000,085,504 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2011/10/27 09:31:06 | 000,082,432 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\icardie.dll
[2011/10/27 09:31:06 | 000,076,800 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\tdc.ocx
[2011/10/27 09:31:06 | 000,072,822 | ---- | M] () -- C:\Windows\SysNative\ieuinit.inf
[2011/10/27 09:31:06 | 000,039,936 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2011/10/27 09:31:06 | 000,030,720 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\licmgr10.dll
[2011/10/27 09:29:58 | 001,888,256 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\WMVDECOD.DLL
[2011/10/27 09:29:58 | 001,619,456 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\WMVDECOD.DLL
[2011/10/27 09:29:58 | 000,320,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1core.dll
[2011/10/27 09:29:58 | 000,265,088 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/10/27 09:29:58 | 000,197,120 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10_1.dll
[2011/10/27 09:29:58 | 000,144,384 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\cdd.dll
[2011/10/27 09:29:57 | 004,068,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mf.dll
[2011/10/27 09:29:57 | 003,181,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mf.dll
[2011/10/27 09:29:57 | 001,863,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ExplorerFrame.dll
[2011/10/27 09:29:57 | 001,837,568 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2011/10/27 09:29:57 | 001,540,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\DWrite.dll
[2011/10/27 09:29:57 | 001,495,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ExplorerFrame.dll
[2011/10/27 09:29:57 | 000,902,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2011/10/27 09:29:57 | 000,662,528 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsPrint.dll
[2011/10/27 09:29:57 | 000,470,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsGdiConverter.dll
[2011/10/27 09:29:57 | 000,442,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsPrint.dll
[2011/10/27 09:29:57 | 000,283,648 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/10/27 09:29:57 | 000,257,024 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfreadwrite.dll
[2011/10/27 09:29:57 | 000,229,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\XpsRasterService.dll
[2011/10/27 09:29:57 | 000,206,848 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mfps.dll
[2011/10/27 09:29:57 | 000,196,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mfreadwrite.dll
[2011/10/27 09:29:57 | 000,135,168 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\XpsRasterService.dll
[2011/10/26 13:05:05 | 000,525,544 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\deployJava1.dll
[2011/10/26 13:05:05 | 000,190,752 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaws.exe
[2011/10/26 13:05:05 | 000,171,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\javaw.exe
[2011/10/26 13:05:05 | 000,171,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Windows\SysNative\java.exe
[2011/10/26 13:04:46 | 017,197,344 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\robert\Desktop\jre-6u29-windows-x64.exe
[2011/10/26 11:08:57 | 000,684,297 | ---- | M] () -- C:\Users\robert\Desktop\unhide.exe
[2011/10/26 09:24:46 | 001,564,464 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\robert\Desktop\iexplore.exe
[2011/10/26 09:20:02 | 001,008,092 | ---- | M] () -- C:\Users\robert\Desktop\uSeRiNiT.exe
[2011/10/26 08:39:49 | 000,002,981 | ---- | M] () -- C:\Users\robert\Desktop\HiJackThis.lnk
[2011/10/26 08:18:12 | 000,131,668 | ---- | M] () -- C:\Users\robert\AppData\Local\ars.cache
[2011/10/26 08:07:21 | 000,000,036 | ---- | M] () -- C:\Users\robert\AppData\Local\housecall.guid.cache
[2011/10/25 16:14:01 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 16:13:50 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\robert\Desktop\mbam-setup-1.51.2.1300.exe
[2011/10/25 13:24:23 | 000,000,683 | ---- | M] () -- C:\Users\robert\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/10/25 13:24:18 | 000,000,344 | ---- | M] () -- C:\ProgramData\1kAlMiG2Kb7FzP.bakk
[2011/10/24 13:34:31 | 000,000,203 | ---- | M] () -- C:\ProgramData\RmUserCfg.ini
[2011/10/24 13:34:31 | 000,000,026 | ---- | M] () -- C:\ProgramData\IpAndPort.fig
[2011/10/20 13:30:23 | 000,049,631 | ---- | M] () -- C:\Users\robert\Desktop\Floor Plan.pdf
[2011/10/20 13:29:44 | 000,063,836 | ---- | M] () -- C:\Users\robert\Desktop\Detail.pdf
[2011/10/18 07:50:15 | 071,733,104 | ---- | M] (Apple Inc.) -- C:\Users\robert\Desktop\iTunes64Setup.exe
[2011/10/18 07:38:22 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/14 15:54:53 | 004,015,494 | ---- | M] () -- C:\Users\robert\Desktop\Abercrombie Fuse (2).jpg
[2011/10/13 16:32:56 | 000,220,473 | ---- | M] () -- C:\Users\robert\Desktop\ceiling-tiles-an.pdf
[2011/10/12 07:36:45 | 000,000,408 | RHS- | M] () -- C:\Users\robert\ntuser.pol
[2011/10/07 13:35:33 | 008,229,626 | ---- | M] () -- C:\Users\robert\Desktop\Fixed Fee Plumbing 2001 - DC, MD, NC, NJ, VA and PA - Phase 2.zip
[2011/10/07 11:27:01 | 000,000,336 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForrobert.job
[2011/10/07 07:49:42 | 002,486,469 | ---- | M] () -- C:\Users\robert\Desktop\photo1.JPG
[2011/10/07 07:49:36 | 002,491,391 | ---- | M] () -- C:\Users\robert\Desktop\photo.JPG
[2011/10/07 07:37:35 | 000,087,456 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIRfsClientNP.dll
[2011/10/07 07:37:34 | 000,080,768 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIinit.dll
[2011/10/07 07:37:34 | 000,034,688 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\SysNative\LMIport.dll
[2011/10/06 12:46:34 | 000,030,720 | ---- | M] () -- C:\Users\robert\Desktop\iPhone4S.jpg
[2011/10/05 12:02:22 | 001,848,549 | ---- | M] () -- C:\Users\robert\Desktop\Van2.JPG
[2011/10/05 12:01:54 | 002,054,091 | ---- | M] () -- C:\Users\robert\Desktop\Van1.JPG
========== Files Created - No Company Name ==========
[2011/10/31 10:05:50 | 000,000,862 | ---- | C] () -- C:\Windows\SysNative\termcap
[2011/10/31 10:05:22 | 000,000,708 | ---- | C] () -- C:\Windows\SysWow64\InstallUtil.InstallLog
[2011/10/31 10:04:57 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\client.db
[2011/10/27 12:21:57 | 000,000,737 | ---- | C] () -- C:\Users\robert\Desktop\VSS October 2011 - Shortcut.lnk
[2011/10/27 09:31:07 | 000,072,822 | ---- | C] () -- C:\Windows\SysWow64\ieuinit.inf
[2011/10/27 09:31:06 | 000,072,822 | ---- | C] () -- C:\Windows\SysNative\ieuinit.inf
[2011/10/26 11:08:57 | 000,684,297 | ---- | C] () -- C:\Users\robert\Desktop\unhide.exe
[2011/10/26 09:20:01 | 001,008,092 | ---- | C] () -- C:\Users\robert\Desktop\uSeRiNiT.exe
[2011/10/26 08:39:49 | 000,002,981 | ---- | C] () -- C:\Users\robert\Desktop\HiJackThis.lnk
[2011/10/26 08:18:12 | 000,131,668 | ---- | C] () -- C:\Users\robert\AppData\Local\ars.cache
[2011/10/26 08:07:21 | 000,000,036 | ---- | C] () -- C:\Users\robert\AppData\Local\housecall.guid.cache
[2011/10/25 16:14:01 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/25 14:30:35 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011/10/25 14:30:34 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/10/25 14:30:33 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011/10/25 14:30:32 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/10/25 14:30:31 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/10/25 14:30:30 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011/10/25 14:30:29 | 000,002,737 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Streets & Trips 2011.lnk
[2011/10/25 14:30:28 | 000,002,741 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft MapPoint North America 2011.lnk
[2011/10/25 14:30:27 | 000,002,747 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft MapPoint Europe 2010.lnk
[2011/10/25 14:30:26 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/10/25 14:30:25 | 000,000,990 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn.lnk
[2011/10/25 14:30:24 | 000,001,924 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Install HP Power Manager.lnk
[2011/10/25 14:30:23 | 000,002,094 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Install ATI Catalyst Control Center with HydraVision.lnk
[2011/10/25 14:30:22 | 000,000,935 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FOX News Live.lnk
[2011/10/25 14:30:21 | 000,001,056 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity 1.3 Beta (Unicode).lnk
[2011/10/25 14:30:20 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/10/25 14:30:18 | 000,002,507 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 9 Standard.lnk
[2011/10/25 14:30:17 | 000,002,465 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 9.lnk
[2011/10/25 14:30:14 | 000,001,009 | ---- | C] () -- C:\Users\Public\Desktop\YoWindow.lnk
[2011/10/25 14:30:13 | 000,001,854 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/10/25 14:30:12 | 000,000,842 | ---- | C] () -- C:\Users\Public\Desktop\Speccy.lnk
[2011/10/25 14:30:11 | 000,002,252 | ---- | C] () -- C:\Users\Public\Desktop\ShoreTel Communicator.lnk
[2011/10/25 14:30:10 | 000,001,188 | ---- | C] () -- C:\Users\Public\Desktop\IPCam Surveillance Software.lnk
[2011/10/25 14:30:09 | 000,001,145 | ---- | C] () -- C:\Users\Public\Desktop\IPCam Admin Utility.lnk
[2011/10/25 14:30:08 | 000,000,923 | ---- | C] () -- C:\Users\Public\Desktop\FOX News Live.lnk
[2011/10/25 14:30:07 | 000,000,932 | ---- | C] () -- C:\Users\Public\Desktop\EPSON Scan.lnk
[2011/10/25 13:34:49 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/10/25 13:34:49 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/10/25 13:34:49 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/10/25 13:34:49 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/10/25 13:34:49 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/10/25 13:24:23 | 000,000,683 | ---- | C] () -- C:\Users\robert\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/10/25 13:24:18 | 000,000,344 | ---- | C] () -- C:\ProgramData\1kAlMiG2Kb7FzP.bakk
[2011/10/20 13:30:23 | 000,049,631 | ---- | C] () -- C:\Users\robert\Desktop\Floor Plan.pdf
[2011/10/20 13:29:44 | 000,063,836 | ---- | C] () -- C:\Users\robert\Desktop\Detail.pdf
[2011/10/14 15:54:41 | 004,015,494 | ---- | C] () -- C:\Users\robert\Desktop\Abercrombie Fuse (2).jpg
[2011/10/13 16:32:56 | 000,220,473 | ---- | C] () -- C:\Users\robert\Desktop\ceiling-tiles-an.pdf
[2011/10/07 13:35:27 | 008,229,626 | ---- | C] () -- C:\Users\robert\Desktop\Fixed Fee Plumbing 2001 - DC, MD, NC, NJ, VA and PA - Phase 2.zip
[2011/10/07 07:49:10 | 002,491,391 | ---- | C] () -- C:\Users\robert\Desktop\photo.JPG
[2011/10/07 07:49:10 | 002,486,469 | ---- | C] () -- C:\Users\robert\Desktop\photo1.JPG
[2011/10/06 12:46:34 | 000,030,720 | ---- | C] () -- C:\Users\robert\Desktop\iPhone4S.jpg
[2011/10/06 09:14:13 | 025,538,157 | ---- | C] () -- C:\Users\robert\Desktop\Lync_ITPro.chm
[2011/10/06 07:36:38 | 000,000,362 | ---- | C] () -- C:\Users\robert\Desktop\Excalibur RSS Reader.appref-ms
[2011/08/09 07:59:17 | 000,000,203 | ---- | C] () -- C:\ProgramData\RmUserCfg.ini
[2011/08/09 07:59:17 | 000,000,026 | ---- | C] () -- C:\ProgramData\IpAndPort.fig
[2011/04/08 10:18:57 | 000,005,120 | ---- | C] () -- C:\Users\robert\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/03/11 14:21:52 | 000,027,136 | ---- | C] () -- C:\Windows\SysWow64\HiDvrOcxESN.dll
[2011/03/11 14:21:50 | 000,026,624 | ---- | C] () -- C:\Windows\SysWow64\HiDvrOcxITA.dll
[2011/03/11 14:21:42 | 000,026,624 | ---- | C] () -- C:\Windows\SysWow64\HiDvrOcxBRG.dll
[2011/03/11 14:21:42 | 000,020,992 | ---- | C] () -- C:\Windows\SysWow64\HiDvrOcxJPN.dll
[2011/01/03 15:03:02 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/10/13 18:17:19 | 000,798,968 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/08/18 12:18:50 | 000,002,902 | ---- | C] () -- C:\ProgramData\LUUnInstall.LiveUpdate
[2010/03/24 15:22:32 | 000,009,046 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/03/24 12:44:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/01/25 13:58:06 | 000,462,848 | ---- | C] () -- C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/03/16 02:47:28 | 000,122,880 | ---- | C] () -- C:\Windows\SysWow64\WinMsgBalloonServer.exe
[2009/03/16 02:47:24 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\WinMsgBalloonClient.exe
[2009/03/05 21:00:36 | 000,532,480 | ---- | C] () -- C:\Windows\SysWow64\libxml2.dll
[2008/02/07 10:05:18 | 000,163,840 | ---- | C] () -- C:\Windows\SysWow64\hppatusg01.dll
< End of report >