Hi Sweet Tech,
The sick PC seems to be running fairly well.
followed the steps, all was fine, except that when uninstalling Java (6.31) it said "could not uninstall" however it did remove the listing from Programs and Features I believe that at least part of the infection was a Java exploit, since I saw a Java window open briefly when the attack first occurred (as stated in original post) .
I rebooted and installed JRE 7 as directed with no issues on the install.
Also, Windows Update is prompting, but seems to have no history of older updates (although there are many) .
Please see logs below.
Thanks,
Jess
OTL Fix Log
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\JCP\Music Projects\Apps\MELODYNE 3 SETUP\H2O.rar moved successfully.
File\Folder C:\Users\JCP\Music Projects\Apps\MELODYNE 3 SETUP\H2O.rar not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: JCP
->Temp folder emptied: 54581958 bytes
->Temporary Internet Files folder emptied: 53737698 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 9918260 bytes
->Apple Safari cache emptied: 15532032 bytes
->Opera cache emptied: 1708264 bytes
->Flash cache emptied: 611 bytes
User: Public
->Temp folder emptied: 0 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 443837 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 11526192 bytes
Total Files Cleaned = 141.00 mb
[EMPTYFLASH]
User: All Users
User: Default
User: Default User
User: JCP
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.31.0 log created on 02212012_014251
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
OTL Scan Log
OTL logfile created on: 21/02/2012 01:47:43 - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\JCP\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.09 Gb Available Physical Memory | 54.66% Memory free
4.00 Gb Paging File | 3.05 Gb Available in Paging File | 76.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.66 Gb Total Space | 131.23 Gb Free Space | 28.18% Space Free | Partition Type: NTFS
Drive D: | 4.36 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive Y: | 465.65 Gb Total Space | 249.73 Gb Free Space | 53.63% Space Free | Partition Type: NTFS
Computer Name: JCP-PC | User Name: JCP | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/02/14 21:37:03 | 000,136,584 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\ramaint.exe
PRC - [2012/02/14 21:36:49 | 000,374,152 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe
PRC - [2012/02/07 15:18:02 | 001,422,664 | ---- | M] (RockMelt, Inc.) -- C:\Users\JCP\AppData\Local\RockMelt\Application\rockmelt.exe
PRC - [2012/02/04 12:28:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\JCP\Desktop\OTL.exe
PRC - [2011/05/25 12:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\JCP\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/02/24 21:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/23 13:32:47 | 000,136,336 | ---- | M] (RockMelt Inc.) -- C:\Users\JCP\AppData\Local\RockMelt\Update\1.2.189.1\RockMeltCrashHandler.exe
PRC - [2010/11/20 04:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/08 12:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeIn.exe
PRC - [2010/10/08 14:15:40 | 000,167,936 | ---- | M] (Mediafour Corporation) -- C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe
PRC - [2010/10/08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) -- C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe
PRC - [2010/01/08 15:42:42 | 000,285,744 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2009/11/20 15:18:24 | 000,188,712 | ---- | M] () -- C:\Program Files\MOTU\Audio\MFWAKeys.exe
PRC - [2009/11/15 11:59:11 | 000,158,752 | ---- | M] (Applian Technologies, Inc.) -- C:\Program Files\Freecorder\FLVSrvc.exe
PRC - [2009/07/29 14:28:40 | 000,252,424 | ---- | M] (Avid Technology, Inc.) -- C:\Windows\System32\MAFWTray.exe
PRC - [2009/06/18 15:41:50 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
PRC - [2009/01/13 11:28:48 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
PRC - [2008/08/11 12:41:00 | 000,063,048 | ---- | M] (LogMeIn, Inc.) -- C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
PRC - [2008/04/23 02:08:13 | 000,483,328 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
PRC - [2008/04/15 02:40:39 | 000,032,256 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
========== Modules (No Company Name) ==========
MOD - [2012/02/07 15:17:37 | 000,494,408 | ---- | M] () -- C:\Users\JCP\AppData\Local\RockMelt\Application\0.9.72.698\ppgooglenaclpluginchrome.dll
MOD - [2012/02/07 15:17:33 | 000,219,152 | ---- | M] () -- C:\Users\JCP\AppData\Local\RockMelt\Application\0.9.72.698\avformat-53.dll
MOD - [2012/02/07 15:17:33 | 000,142,328 | ---- | M] () -- C:\Users\JCP\AppData\Local\RockMelt\Application\0.9.72.698\avutil-51.dll
MOD - [2012/02/07 15:17:32 | 001,633,288 | ---- | M] () -- C:\Users\JCP\AppData\Local\RockMelt\Application\0.9.72.698\avcodec-53.dll
MOD - [2011/06/24 21:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 21:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2009/11/20 15:18:24 | 000,188,712 | ---- | M] () -- C:\Program Files\MOTU\Audio\MFWAKeys.exe
MOD - [2009/06/22 00:26:00 | 000,305,664 | ---- | M] () -- C:\Program Files\TeraCopy\TeraCopyExt.dll
MOD - [2009/04/27 12:55:12 | 000,678,400 | ---- | M] () -- C:\Program Files\IZArc\IZArcCM.dll
MOD - [2009/03/11 13:41:42 | 000,049,152 | ---- | M] () -- C:\Program Files\OxelonMedia\menuext.dll
========== Win32 Services (SafeList) ==========
SRV - [2012/02/14 21:37:03 | 000,136,584 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\RaMaint.exe -- (LMIMaint)
SRV - [2012/02/14 21:36:49 | 000,374,152 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LMIGuardianSvc.exe -- (LMIGuardianSvc)
SRV - [2010/11/08 12:04:18 | 000,390,528 | ---- | M] (LogMeIn, Inc.) [Auto | Running] -- C:\Program Files\LogMeIn\x86\LogMeIn.exe -- (LogMeIn)
SRV - [2010/10/08 12:11:50 | 000,131,584 | ---- | M] (Mediafour Corporation) [Auto | Running] -- C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exe -- (MacDrive8Service)
SRV - [2010/02/24 19:16:03 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/01/08 16:31:04 | 000,057,640 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
SRV - [2010/01/08 15:42:42 | 000,285,744 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2009/07/13 17:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 17:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/06/18 15:41:50 | 000,647,216 | ---- | M] (Cisco Systems, Inc.) [Auto | Stopped] -- C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe -- (nmservice)
SRV - [2009/04/29 03:21:04 | 000,410,624 | ---- | M] (Conexant Systems, Inc.) [Auto | Running] -- C:\Windows\System32\XAudio32.dll -- (HsfXAudioService)
SRV - [2009/01/13 11:28:48 | 001,528,608 | ---- | M] (Cisco Systems, Inc.) [Auto | Running] -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe -- (CVPND)
========== Driver Services (SafeList) ==========
DRV - [2012/02/14 21:36:49 | 000,083,360 | ---- | M] (LogMeIn, Inc.) [File_System | Disabled | Stopped] -- C:\Windows\System32\LMIRfsClientNP.dll -- (LMIRfsClientNP)
DRV - [2011/02/10 01:23:19 | 000,231,248 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\System32\drivers\truecrypt.sys -- (truecrypt)
DRV - [2010/11/20 02:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 01:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/10/07 15:36:04 | 000,234,160 | ---- | M] (Mediafour Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\MDFSYSNT.SYS -- (MDFSYSNT)
DRV - [2010/07/01 16:52:18 | 000,044,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dc3d.sys -- (dc3d)
DRV - [2010/05/12 14:51:34 | 000,029,792 | ---- | M] (Mediafour Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\MDPMGRNT.SYS -- (MDPMGRNT)
DRV - [2010/05/12 14:42:50 | 000,057,800 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\CBDisk.sys -- (CBDisk)
DRV - [2010/04/14 00:01:48 | 000,045,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\btusbflt.sys -- (btusbflt)
DRV - [2010/01/08 15:42:40 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2009/11/20 15:18:50 | 000,023,600 | ---- | M] (Mark of the Unicorn) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\motubus.sys -- (motubus)
DRV - [2009/11/20 15:18:44 | 000,026,160 | ---- | M] (Mark of the Unicorn) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MFWAMIDI.sys -- (mfwamidi)
DRV - [2009/11/20 15:18:38 | 000,464,944 | ---- | M] (Mark of the Unicorn) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\motufwa.sys -- (MotuFWA)
DRV - [2009/11/20 15:18:34 | 000,069,680 | ---- | M] (Mark of the Unicorn) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mfwawave.sys -- (mfwawave)
DRV - [2009/11/17 22:40:20 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) [Kernel | System | Running] -- C:\Windows\System32\drivers\pssdk42.sys -- (PSSDK42)
DRV - [2009/10/03 05:02:06 | 009,905,096 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2009/09/23 09:41:58 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2009/08/28 19:42:44 | 000,017,408 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netaapl.sys -- (Netaapl)
DRV - [2009/07/29 14:28:18 | 000,192,392 | ---- | M] (Avid Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mafw.sys -- (MAFW)
DRV - [2009/07/13 14:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2009/05/13 14:47:44 | 000,026,416 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\purendis.sys -- (purendis)
DRV - [2009/05/13 14:47:44 | 000,024,880 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\pnarp.sys -- (pnarp)
DRV - [2009/04/29 03:20:56 | 000,008,704 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\XAudio32.sys -- (XAudio)
DRV - [2009/01/13 11:27:36 | 000,306,812 | ---- | M] (Cisco Systems, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\CVPNDRVA.sys -- (CVPNDRVA)
DRV - [2008/08/28 17:17:38 | 000,131,856 | ---- | M] (Deterministic Networks, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dne2000.sys -- (DNE)
DRV - [2008/08/11 12:41:00 | 000,047,640 | ---- | M] (LogMeIn, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\LMIRfsDriver.sys -- (LMIRfsDriver)
DRV - [2008/08/11 12:41:00 | 000,012,856 | ---- | M] (LogMeIn, Inc.) [Kernel | Auto | Running] -- C:\Program Files\LogMeIn\x86\rainfo.sys -- (LMIInfo)
DRV - [2008/03/04 02:32:00 | 000,188,416 | ---- | M] (Conexant Systems Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\CHDRT32.sys -- (CnxtHdAudService)
DRV - [2007/07/11 02:30:22 | 000,007,168 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqRemHid.sys -- (HpqRemHid)
DRV - [2007/06/18 17:12:04 | 000,016,768 | ---- | M] (Hewlett-Packard Development Company, L.P.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HpqKbFiltr.sys -- (HpqKbFiltr)
DRV - [2007/05/21 16:04:16 | 000,029,696 | ---- | M] (Cristalink Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SeratoUsb.sys -- (SeratoUsb)
DRV - [2007/01/18 19:28:02 | 000,005,275 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2006/11/14 17:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2005/12/22 17:02:22 | 000,051,840 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2005/11/16 20:28:32 | 000,028,928 | ---- | M] (REDC) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\rimmptsk.sys -- (rimmptsk)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://secure.logmeinrescue.com/CA-EN/TechConsole/Console.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ca
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = F0 85 E2 AE F3 5B CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: {22AA42EA-508C-4b90-9BDA-836A848B6492}:2.0
FF - prefs.js..extensions.enabledItems: {B042753D-F57E-4e8e-A01B-7379A6D4CEFB}:1.03
FF - prefs.js..extensions.enabledItems: en-CA@dictionaries.addons.mozilla.org:1.1.4
FF - prefs.js..extensions.enabledItems: {C3A8BC35-ADF4-46c9-B81E-69BF809BF681}:1.30
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:3.9.4
FF - prefs.js..extensions.enabledItems: {fce36c1e-58d8-498a-b2a5-66ad1cedebbb}:0.76
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.6.4
FF - prefs.js..extensions.enabledItems: {a7c6cf7f-112c-4500-a7ea-39801a327e5f}:1.0.6
FF - prefs.js..extensions.enabledItems: {fffe0eac-3819-4561-8aa9-178a68450d4f}:1.9
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.3.1
FF - prefs.js..extensions.enabledItems: LogMeInClient@logmein.com:1.0.0.464
FF - prefs.js..extensions.enabledItems: TechnicianConsole@logmeinrescue.com:6.1.0.617
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.2
FF - prefs.js..extensions.enabledItems: youtube2mp3@mondayx.de:1.0.4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.5: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\JCP\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\JCP\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\JCP\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\JCP\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@us-w1.rockmelt.com/RockMelt Update;version=8: C:\Users\JCP\AppData\Local\RockMelt\Update\1.2.189.1\npRockMeltOneClick8.dll (RockMelt Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files\Google\Google Gears\Firefox\ [2010/03/06 21:58:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/02/21 01:30:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/21 01:40:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/10/14 00:14:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2009/11/02 12:22:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JCP\AppData\Roaming\Mozilla\Extensions
[2009/11/02 12:22:59 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JCP\AppData\Roaming\Mozilla\Extensions\postbox@postbox-inc.com
[2009/11/02 12:11:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions
[2009/11/02 12:11:00 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2009/11/02 12:11:01 | 000,000,000 | ---D | M] ("ColorfulTabs") -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (BaseCode) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{22AA42EA-508C-4b90-9BDA-836A848B6492}
[2009/11/02 12:11:00 | 000,000,000 | ---D | M] (FireFTP) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (BitComet Download Helper) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2009/11/02 12:11:04 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (CLPicView) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{C3A8BC35-ADF4-46c9-B81E-69BF809BF681}
[2009/11/02 12:11:01 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(38)
[2009/11/02 12:11:01 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(36)
[2009/11/02 12:11:04 | 000,000,000 | ---D | M] (CustomizeGoogle) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{fce36c1e-58d8-498a-b2a5-66ad1cedebbb}
[2009/11/02 12:11:00 | 000,000,000 | ---D | M] (firefusk) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\{fffe0eac-3819-4561-8aa9-178a68450d4f}
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (Canadian English Dictionary) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\en-CA@dictionaries.addons.mozilla.org
[2009/11/02 12:11:03 | 000,000,000 | ---D | M] (Email This! Bookmarklet Extension) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\gmailthis@lazyrussian(35).com
[2009/11/02 12:11:00 | 000,000,000 | ---D | M] (Email This! Bookmarklet Extension) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\gmailthis@lazyrussian(88).com
[2009/11/02 12:11:05 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\LogMeInClient@logmein.com
[2009/11/02 12:11:02 | 000,000,000 | ---D | M] (LogMeIn, Inc. Rescue Technician Console) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\TechnicianConsole@logmeinrescue.com
[2009/11/02 12:11:04 | 000,000,000 | ---D | M] (YouTube to MP3) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\extensions\youtube2mp3@mondayx.de
[2012/02/21 01:31:51 | 000,000,000 | ---D | M] (No name found) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions
[2010/03/30 08:54:06 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2012/02/21 01:31:26 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2010/12/30 14:00:55 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010/04/01 10:34:06 | 000,000,000 | ---D | M] (BaseCode) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{22AA42EA-508C-4b90-9BDA-836A848B6492}
[2011/04/08 15:54:10 | 000,000,000 | ---D | M] (Firefox Sync) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{340c2bbc-ce74-4362-90b5-7c26312808ef}
[2012/02/21 01:31:48 | 000,000,000 | ---D | M] (FEBE) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{4BBDD651-70CF-4821-84F8-2B918CF89CA3}
[2010/01/22 11:38:39 | 000,000,000 | ---D | M] (CacheViewer) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{71328583-3CA7-4809-B4BA-570A85818FBB}
[2011/11/13 18:16:52 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2009/11/02 12:11:31 | 000,000,000 | ---D | M] (CLPicView) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{C3A8BC35-ADF4-46c9-B81E-69BF809BF681}
[2009/11/02 12:11:32 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}(38)
[2009/11/02 12:11:30 | 000,000,000 | ---D | M] (DownThemAll!) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}(36)
[2011/06/15 17:49:32 | 000,000,000 | ---D | M] (firefusk) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\{fffe0eac-3819-4561-8aa9-178a68450d4f}
[2012/02/21 01:31:43 | 000,000,000 | ---D | M] (Canadian English Dictionary) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\en-CA@dictionaries.addons.mozilla.org
[2011/08/11 09:45:42 | 000,000,000 | ---D | M] (Firebug) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\firebug@software.joehewitt.com
[2009/11/02 12:11:32 | 000,000,000 | ---D | M] (Email This! Bookmarklet Extension) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\gmailthis@lazyrussian(35).com
[2009/11/02 12:11:29 | 000,000,000 | ---D | M] (Email This! Bookmarklet Extension) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\gmailthis@lazyrussian(88).com
[2010/09/03 12:42:47 | 000,000,000 | ---D | M] (Email This! Bookmarklet Extension) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\gmailthis@lazyrussian.com
[2011/11/13 18:16:55 | 000,000,000 | ---D | M] (Hypem.com: The Hype Machine Track Downloader) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\hypem@downloader.com
[2011/03/28 08:59:10 | 000,000,000 | ---D | M] (LogMeIn, Inc. Remote Access Plugin) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\LogMeInClient@logmein.com
[2011/06/16 20:15:46 | 000,000,000 | ---D | M] (LogMeIn, Inc. Rescue Technician Console) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\TechnicianConsole@logmeinrescue.com
[2011/10/01 14:21:52 | 000,000,000 | ---D | M] (YouTube to MP3) -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\yobjue9n.JCP\extensions\youtube2mp3@mondayx.de
[2009/03/20 23:18:14 | 000,000,853 | ---- | M] () -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\searchplugins\delicious-tag.xml
[2008/06/19 15:00:00 | 000,001,108 | ---- | M] () -- C:\Users\JCP\AppData\Roaming\Mozilla\Firefox\Profiles\d4brfg0l.default\searchplugins\wikipedia-en.xml
[2012/02/21 01:30:33 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
File not found (No name found) -- C:\PROGRAM FILES\MOZILLA FIREFOX\EXTENSIONS\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{02450954-CDD9-410F-B1DA-DB804E18C671}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{1A2D0EC4-75F5-4C91-89C4-3656F6E44B68}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{22AA42EA-508C-4B90-9BDA-836A848B6492}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{A7C6CF7F-112C-4500-A7EA-39801A327E5F}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{B042753D-F57E-4E8E-A01B-7379A6D4CEFB}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{B9DB16A4-6EDC-47EC-A1F4-B86292ED211D}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{C3A8BC35-ADF4-46C9-B81E-69BF809BF681}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{FCE36C1E-58D8-498A-B2A5-66AD1CEDEBBB}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\{FFFE0EAC-3819-4561-8AA9-178A68450D4F}
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\EN-CA@DICTIONARIES.ADDONS.MOZILLA.ORG
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\LOGMEINCLIENT@LOGMEIN.COM
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\TECHNICIANCONSOLE@LOGMEINRESCUE.COM
File not found (No name found) -- C:\USERS\JCP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TDGSLU8L.DEFAULT\EXTENSIONS\YOUTUBE2MP3@MONDAYX.DE
[2012/02/16 06:40:42 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/07/17 00:40:12 | 000,704,512 | ---- | M] (BitComet) -- C:\Program Files\mozilla firefox\plugins\npBitCometAgent.dll
[2012/02/16 02:42:53 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/02/16 02:42:53 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
O1 HOSTS File: ([2012/02/17 01:10:55 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll (Conduit Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Google Gears Helper) - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Program Files\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 7.0] C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] C:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Getting started with MacDrive 8] C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe (Mediafour Corporation)
O4 - HKLM..\Run: [LogMeIn GUI] C:\Program Files\LogMeIn\x86\LogMeInSystray.exe (LogMeIn, Inc.)
O4 - HKLM..\Run: [MacDrive 8 application] C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe (Mediafour Corporation)
O4 - HKLM..\Run: [M-Audio Taskbar Icon] C:\Windows\System32\MAFWTray.exe (Avid Technology, Inc.)
O4 - HKLM..\Run: [nmctxth] C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe (Cisco Systems, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKCU..\Run: [RockMelt Update] C:\Users\JCP\AppData\Local\RockMelt\Update\RockMeltUpdate.exe (RockMelt Inc.)
O4 - Startup: C:\Users\JCP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\JCP\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra 'Tools' menuitem : &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - C:\Program Files\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: logmeinrescue.com ([secure] https in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.microsoft.com/sites/production/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {254AA86E-5655-4518-AA87-185D7CC41801}
https://secure.logmeinrescue.com/US/TechConsole/x86/RescueControl.cab (LogMeIn Rescue Technician Console)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9}
https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 75.153.176.9 75.153.176.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2EB444EB-F81B-4F35-8579-18C2975F41EB}: NameServer = 10.97.72.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3CA9B515-890D-4F69-9A27-66DB8F109C85}: DhcpNameServer = 64.71.255.198 207.181.101.5
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9AB4E4CD-F55D-433A-9BE0-10904D6441CD}: DhcpNameServer = 192.168.1.1 75.153.176.9 75.153.176.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EC87EDB3-054B-41B0-B59D-3C2597542738}: DhcpNameServer = 64.71.255.198 207.181.101.5
O18 - Protocol\Handler\pure-go {4746C79A-2042-4332-8650-48966E44ABA8} - C:\Program Files\Common Files\Pure Networks Shared\Platform\puresp4.dll (Cisco Systems, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 13:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
========== Files/Folders - Created Within 30 Days ==========
[2012/02/21 01:41:05 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/02/21 01:40:30 | 000,637,848 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012/02/21 01:40:30 | 000,224,136 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/02/21 01:40:30 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/02/21 01:40:30 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/02/21 01:29:48 | 015,792,320 | ---- | C] (Mozilla) -- C:\Users\JCP\Desktop\Firefox Setup 10.0.2.exe
[2012/02/21 01:23:28 | 020,320,648 | ---- | C] (Oracle Corporation) -- C:\Users\JCP\Desktop\jre-7u3-windows-i586.exe
[2012/02/21 01:21:21 | 000,910,112 | ---- | C] (Sun Microsystems, Inc.) -- C:\Users\JCP\Desktop\chromeinstall-6u31.exe
[2012/02/19 18:53:25 | 002,322,184 | ---- | C] (ESET) -- C:\Users\JCP\Desktop\esetsmartinstaller_enu.exe
[2012/02/19 17:24:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/02/19 17:24:55 | 000,020,464 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/02/19 17:24:55 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/02/19 17:17:14 | 002,060,336 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\JCP\Desktop\tdsskiller.exe
[2012/02/19 15:35:21 | 004,729,344 | ---- | C] (AVAST Software) -- C:\Users\JCP\Desktop\aswMBR.exe
[2012/02/17 01:16:42 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/02/17 01:08:41 | 000,000,000 | ---D | C] -- C:\Users\JCP\AppData\Local\temp
[2012/02/16 13:21:06 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/02/16 11:28:31 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/16 11:28:31 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/16 11:28:31 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/16 11:28:22 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/02/16 11:27:01 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/16 11:19:50 | 000,000,000 | ---D | C] -- C:\found.000
[2012/02/16 11:08:13 | 004,406,022 | R--- | C] (Swearware) -- C:\Users\JCP\Desktop\ComboFix.exe
[2012/02/05 14:13:01 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/02/04 12:28:22 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\JCP\Desktop\OTL.exe
[2012/02/02 10:40:31 | 000,100,864 | ---- | C] (GMER) -- C:\uwldypow.sys
[2012/02/02 10:35:15 | 000,607,260 | R--- | C] (Swearware) -- C:\Users\JCP\Desktop\dds.scr
[2012/02/01 00:38:32 | 000,000,000 | ---D | C] -- C:\Users\JCP\Desktop\bootkit_remover
[2012/01/30 21:24:48 | 000,000,000 | ---D | C] -- C:\Users\JCP\AppData\Roaming\Malwarebytes
[2012/01/30 21:24:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/30 21:05:31 | 009,502,424 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\JCP\Desktop\mbam-setup-1.60.1.1000.exe
========== Files - Modified Within 30 Days ==========
[2012/02/21 01:51:33 | 000,664,780 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/02/21 01:51:33 | 000,129,574 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/02/21 01:51:24 | 000,017,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/21 01:51:23 | 000,017,648 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/21 01:44:42 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/02/21 01:44:11 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/21 01:44:00 | 1609,814,016 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/21 01:40:12 | 000,224,136 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaws.exe
[2012/02/21 01:40:12 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\javaw.exe
[2012/02/21 01:40:12 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\java.exe
[2012/02/21 01:40:11 | 000,637,848 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\npdeployJava1.dll
[2012/02/21 01:40:11 | 000,567,696 | ---- | M] (Oracle Corporation) -- C:\Windows\System32\deployJava1.dll
[2012/02/21 01:37:01 | 000,000,920 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-4208267705-815321249-1981094610-1000UA.job
[2012/02/21 01:32:00 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/02/21 01:30:34 | 000,001,990 | ---- | M] () -- C:\Users\JCP\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2012/02/21 01:30:34 | 000,001,088 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/02/21 01:30:11 | 015,792,320 | ---- | M] (Mozilla) -- C:\Users\JCP\Desktop\Firefox Setup 10.0.2.exe
[2012/02/21 01:23:41 | 020,320,648 | ---- | M] (Oracle Corporation) -- C:\Users\JCP\Desktop\jre-7u3-windows-i586.exe
[2012/02/21 01:21:22 | 000,910,112 | ---- | M] (Sun Microsystems, Inc.) -- C:\Users\JCP\Desktop\chromeinstall-6u31.exe
[2012/02/21 01:19:01 | 000,000,900 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4208267705-815321249-1981094610-1000UA.job
[2012/02/21 01:18:43 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-4208267705-815321249-1981094610-1000Core.job
[2012/02/19 21:58:37 | 000,000,499 | ---- | M] () -- C:\Users\JCP\Desktop\aswMBR3.lnk
[2012/02/19 21:51:39 | 000,879,700 | ---- | M] () -- C:\Users\JCP\Desktop\SecurityCheck (2).exe
[2012/02/19 21:07:03 | 000,000,848 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4208267705-815321249-1981094610-1000Core.job
[2012/02/19 18:53:33 | 002,322,184 | ---- | M] (ESET) -- C:\Users\JCP\Desktop\esetsmartinstaller_enu.exe
[2012/02/19 17:24:56 | 000,001,067 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/19 17:17:24 | 002,060,336 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\JCP\Desktop\tdsskiller.exe
[2012/02/19 17:17:00 | 000,000,512 | ---- | M] () -- C:\Users\JCP\Desktop\MBR.dat
[2012/02/19 15:35:59 | 004,729,344 | ---- | M] (AVAST Software) -- C:\Users\JCP\Desktop\aswMBR.exe
[2012/02/17 01:10:55 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/02/16 11:08:29 | 004,406,022 | R--- | M] (Swearware) -- C:\Users\JCP\Desktop\ComboFix.exe
[2012/02/14 21:36:49 | 000,087,424 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIinit.dll
[2012/02/14 21:36:49 | 000,083,360 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIRfsClientNP.dll
[2012/02/14 21:36:49 | 000,030,592 | ---- | M] (LogMeIn, Inc.) -- C:\Windows\System32\LMIport.dll
[2012/02/05 14:09:53 | 243,559,124 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/02/04 12:28:25 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\JCP\Desktop\OTL.exe
[2012/02/02 10:40:31 | 000,100,864 | ---- | M] (GMER) -- C:\uwldypow.sys
[2012/02/02 10:39:44 | 000,302,592 | ---- | M] () -- C:\Users\JCP\Desktop\q39yht1d.exe
[2012/02/02 10:35:17 | 000,607,260 | R--- | M] (Swearware) -- C:\Users\JCP\Desktop\dds.scr
[2012/02/02 10:29:35 | 000,050,477 | ---- | M] () -- C:\Users\JCP\Desktop\Defogger.exe
[2012/02/01 00:30:13 | 000,303,059 | ---- | M] () -- C:\Users\JCP\Desktop\ListParts.exe
[2012/02/01 00:25:11 | 000,044,607 | ---- | M] () -- C:\Users\JCP\Desktop\bootkit_remover.zip
[2012/01/30 21:07:10 | 000,869,194 | ---- | M] () -- C:\Users\JCP\Desktop\SecurityCheck (1).exe
[2012/01/30 21:05:37 | 009,502,424 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\JCP\Desktop\mbam-setup-1.60.1.1000.exe
[2012/01/30 21:04:47 | 000,869,194 | ---- | M] () -- C:\Users\JCP\Desktop\SecurityCheck.exe
========== Files Created - No Company Name ==========
[2012/02/21 01:30:34 | 000,001,100 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/02/19 21:51:35 | 000,879,700 | ---- | C] () -- C:\Users\JCP\Desktop\SecurityCheck (2).exe
[2012/02/19 17:24:56 | 000,001,067 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/02/19 17:17:00 | 000,000,499 | ---- | C] () -- C:\Users\JCP\Desktop\aswMBR3.lnk
[2012/02/16 11:28:31 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/16 11:28:31 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/16 11:28:31 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/16 11:28:31 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/16 11:28:31 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/02/14 22:45:16 | 000,000,512 | ---- | C] () -- C:\Users\JCP\Desktop\MBR.dat
[2012/02/02 10:39:42 | 000,302,592 | ---- | C] () -- C:\Users\JCP\Desktop\q39yht1d.exe
[2012/02/02 10:29:34 | 000,050,477 | ---- | C] () -- C:\Users\JCP\Desktop\Defogger.exe
[2012/02/01 00:30:12 | 000,303,059 | ---- | C] () -- C:\Users\JCP\Desktop\ListParts.exe
[2012/02/01 00:25:11 | 000,044,607 | ---- | C] () -- C:\Users\JCP\Desktop\bootkit_remover.zip
[2012/01/30 21:07:10 | 000,869,194 | ---- | C] () -- C:\Users\JCP\Desktop\SecurityCheck (1).exe
[2012/01/30 21:04:46 | 000,869,194 | ---- | C] () -- C:\Users\JCP\Desktop\SecurityCheck.exe
[2011/05/29 11:58:58 | 000,000,000 | ---- | C] () -- C:\Users\JCP\AppData\Local\{33F0A466-CC6F-431B-B10A-7CEAF8815BF0}
[2010/10/19 11:31:43 | 000,031,802 | ---- | C] () -- C:\Users\JCP\AppData\Roaming\UserTile.png
[2010/09/23 22:48:30 | 000,484,352 | ---- | C] () -- C:\Windows\System32\lame_enc.dll
[2010/08/11 13:31:20 | 000,008,704 | ---- | C] () -- C:\Users\JCP\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/17 22:31:10 | 000,819,200 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2010/04/17 22:31:10 | 000,180,224 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2010/04/08 14:51:10 | 000,322,720 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/01/25 11:58:06 | 000,462,848 | ---- | C] () -- C:\Windows\System32\ractrlkeyhook.dll
[2009/12/25 13:51:05 | 000,000,256 | ---- | C] () -- C:\Windows\System32\pool.bin
[2009/12/19 22:32:27 | 000,000,056 | ---- | C] () -- C:\Users\JCP\AppData\Roaming\MOTU FireWire SMPTE Prefs.prefs
[2009/12/07 15:58:14 | 000,905,290 | ---- | C] () -- C:\Windows\System32\libmmd.dll
[2009/12/07 15:53:18 | 000,129,024 | ---- | C] () -- C:\Windows\UNWISE.EXE
[2009/12/07 11:48:44 | 000,510,976 | ---- | C] () -- C:\Windows\System32\synsoacc.dll
[2009/11/09 17:08:31 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2009/11/03 09:42:56 | 000,172,032 | ---- | C] () -- C:\Windows\System32\secsnmp.dll
[2009/11/03 09:42:56 | 000,026,624 | ---- | C] () -- C:\Windows\System32\ssh1ml3.dll
[2009/11/02 23:10:00 | 000,087,552 | ---- | C] () -- C:\Windows\System32\cpwmon2k.dll
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\Windows\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\Windows\System32\OGAEXEC.exe
[2009/07/13 20:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 20:33:53 | 002,252,736 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 18:05:48 | 000,664,780 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 18:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 18:05:48 | 000,129,574 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 18:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 18:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 18:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 15:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 15:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 15:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 13:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/01/13 11:28:56 | 000,197,408 | ---- | C] () -- C:\Windows\System32\vpnapi.dll
[2006/03/09 16:58:00 | 001,060,424 | ---- | C] () -- C:\Windows\System32\WdfCoInstaller01000.dll
[2005/05/06 19:06:00 | 000,016,480 | ---- | C] () -- C:\Windows\System32\rixdicon.dll
[1998/10/10 23:07:38 | 000,088,576 | ---- | C] () -- C:\Windows\System32\Iticheck.dll
========== Custom Scans ==========
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2012/02/16 06:40:42 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2012/02/16 06:40:42 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2012/02/16 06:40:42 | 000,834,840 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2012/02/16 06:40:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2012/02/16 06:40:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2012/02/16 06:40:41 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ShowIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --show-icons [2012/02/14 21:03:37 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\HideIconsCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --hide-icons [2012/02/14 21:03:37 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\InstallInfo\\ReinstallCommand: "C:\Program Files\Google\Chrome\Application\chrome.exe" --make-default-browser [2012/02/14 21:03:37 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Google Chrome\shell\open\command\\: "C:\Program Files\Google\Chrome\Application\chrome.exe" [2012/02/14 21:03:37 | 001,049,072 | ---- | M] (Google Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: "C:\Windows\System32\ie4uinit.exe" -show [2011/04/06 09:42:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: "C:\Windows\System32\ie4uinit.exe" -reinstall [2011/04/06 09:42:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: "C:\Windows\System32\ie4uinit.exe" -hide [2011/04/06 09:42:32 | 000,074,240 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\naom\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" -extoff [2011/04/06 09:42:33 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2011/04/06 09:42:33 | 000,748,336 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Opera\Opera.exe" /HideIconsCommand [2009/11/20 19:01:18 | 000,832,296 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Opera\Opera.exe" /ShowIconsCommand [2009/11/20 19:01:18 | 000,832,296 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Opera\Opera.exe" /ReInstallBrowser [2009/11/20 19:01:18 | 000,832,296 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Opera.exe\shell\open\command\\: "C:\Program Files\Opera\Opera.exe" [2009/11/20 19:01:18 | 000,832,296 | ---- | M] (Opera Software)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\RockMelt\InstallInfo\\ShowIconsCommand: "C:\Users\JCP\AppData\Local\RockMelt\Application\rockmelt.exe" --show-icons [2012/02/07 15:18:02 | 001,422,664 | ---- | M] (RockMelt, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\RockMelt\InstallInfo\\HideIconsCommand: "C:\Users\JCP\AppData\Local\RockMelt\Application\rockmelt.exe" --hide-icons [2012/02/07 15:18:02 | 001,422,664 | ---- | M] (RockMelt, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\RockMelt\InstallInfo\\ReinstallCommand: "C:\Users\JCP\AppData\Local\RockMelt\Application\rockmelt.exe" --make-default-browser [2012/02/07 15:18:02 | 001,422,664 | ---- | M] (RockMelt, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\RockMelt\shell\open\command\\: "C:\Users\JCP\AppData\Local\RockMelt\Application\rockmelt.exe" [2012/02/07 15:18:02 | 001,422,664 | ---- | M] (RockMelt, Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011/07/05 19:04:50 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011/07/05 19:04:50 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011/07/05 19:04:50 | 002,388,848 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011/07/05 19:04:50 | 002,388,848 | ---- | M] (Apple Inc.)
< %systemroot%\*. /rp /s >
< MD5 for: CVPNDRVA.SYS >
[2009/01/13 11:27:36 | 000,306,812 | ---- | M] (Cisco Systems, Inc.) MD5=F4A38E478D71CF609B9A11C46BF1CAFE -- C:\Windows\System32\drivers\CVPNDRVA.sys
< MD5 for: NETAAPL.SYS >
[2011/05/10 07:06:14 | 000,018,432 | ---- | M] (Apple Inc.) MD5=1352E1648213551923A0A822E441553C -- C:\Program Files\Common Files\Apple\Mobile Device Support\NetDrivers\netaapl.sys
[2011/05/10 07:06:14 | 000,018,432 | ---- | M] (Apple Inc.) MD5=1352E1648213551923A0A822E441553C -- C:\Windows\System32\DriverStore\FileRepository\netaapl.inf_x86_neutral_b1e5350f88598904\netaapl.sys
[2009/08/28 19:42:44 | 000,017,408 | ---- | M] (Apple Inc.) MD5=29C45722E20572B6440B57E3359E73EE -- C:\Windows\System32\drivers\netaapl.sys
< MD5 for: USBAAPL.SYS >
[2011/05/10 07:06:08 | 000,042,496 | ---- | M] (Apple, Inc.) MD5=83CAFCB53201BBAC04D822F32438E244 -- C:\Program Files\Common Files\Apple\Mobile Device Support\Drivers\usbaapl.sys
[2011/05/10 07:06:08 | 000,042,496 | ---- | M] (Apple, Inc.) MD5=83CAFCB53201BBAC04D822F32438E244 -- C:\Windows\System32\DriverStore\FileRepository\usbaapl.inf_x86_neutral_1e34817a8e80d76d\usbaapl.sys
[2011/02/18 16:36:58 | 000,041,984 | ---- | M] (Apple, Inc.) MD5=D4FB6ECC60A428564BA8768B0E23C0FC -- C:\Windows\System32\drivers\usbaapl.sys
< %USERPROFILE%\AppData\Local\Google\Chrome\User Data\*.* /s >
[2012/01/20 00:43:48 | 000,000,000 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\First Run
[2012/01/20 00:44:55 | 000,000,000 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Archived History
[2012/01/20 00:44:55 | 000,000,512 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Archived History-journal
[2012/01/20 00:44:36 | 000,000,063 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Current Session
[2012/01/20 00:44:36 | 000,016,384 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Favicons
[2012/01/20 00:44:36 | 000,000,512 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Favicons-journal
[2012/01/20 00:44:35 | 000,086,016 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\History
[2012/01/20 00:44:35 | 000,000,011 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\History Provider Cache
[2010/11/30 22:01:00 | 000,000,287 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Preferences
[2012/01/20 00:44:55 | 000,000,000 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Top Sites
[2012/01/20 00:44:55 | 000,000,512 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Top Sites-journal
[2012/01/20 00:44:36 | 000,073,728 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Web Data
[2012/01/20 00:44:36 | 000,001,024 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal
[2012/01/20 00:44:35 | 000,000,000 | ---- | M] () -- C:\Users\JCP\AppData\Local\Google\Chrome\User Data\Default\User StyleSheets\Custom.css
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
< End of report >