OTL logfile created on: 2/6/2012 3:02:28 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Derek\Desktop\fix
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 4.37 Gb Available Physical Memory | 54.62% Memory free
16.00 Gb Paging File | 12.17 Gb Available in Paging File | 76.04% Paging File free
Paging file location(s): i:\pagefile.sys 8192 12000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 171.72 Gb Total Space | 90.19 Gb Free Space | 52.52% Space Free | Partition Type: NTFS
Drive E: | 759.69 Gb Total Space | 426.89 Gb Free Space | 56.19% Space Free | Partition Type: NTFS
Drive H: | 3.78 Gb Total Space | 0.01 Gb Free Space | 0.15% Space Free | Partition Type: FAT32
Drive I: | 12.04 Gb Total Space | 3.96 Gb Free Space | 32.85% Space Free | Partition Type: NTFS
Drive J: | 453.71 Gb Total Space | 64.03 Gb Free Space | 14.11% Space Free | Partition Type: NTFS
Computer Name: DEREK-PC | User Name: Derek | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Derek\Desktop\fix\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
PRC - C:\Program Files (x86)\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
PRC - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Messaging)
PRC - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files (x86)\Input Director\InputDirector.exe (Imperative Software Pty Ltd)
PRC - C:\Program Files (x86)\Input Director\InputDirectorClipboardHelper.exe (Imperative Software Pty Ltd)
PRC - C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
PRC - C:\Windows\winsxs\wow64_microsoft-windows-sidebar_31bf3856ad364e35_6.1.7601.17514_none_37575b7e71a86712\sidebar.exe (Microsoft Corporation)
PRC - C:\Windows\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Creative\Console Launcher\ConsoLCu.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Creative\ShareDLL\CADI\NotiMan.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll ()
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\avutil-51.dll ()
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\avformat-53.dll ()
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\avcodec-53.dll ()
MOD - C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\gcswf32.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\dd759df05fad8dc6d3404e8e02b40819\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\mozjs.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldap32v60.dll ()
MOD - C:\Program Files (x86)\Mozilla Thunderbird\nsldappr32v60.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\6f2de1cb69aef1946760a70f355a3075\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll ()
MOD - C:\Users\Derek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.3.gadget\GetCoreTempInfoNET.dll ()
MOD - C:\Users\Derek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.3.gadget\SystemInfo.dll ()
MOD - C:\Users\Derek\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.3.gadget\CoreTempReader.dll ()
MOD - C:\Windows\SysWOW64\APOMngr.DLL ()
MOD - C:\Windows\SysWOW64\CmdRtr.DLL ()
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Macrovision Europe Ltd.)
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (SbieSvc) -- C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (PnkBstrB) -- C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (MediaMall Server) -- C:\Program Files (x86)\MediaMall\MediaMallServer.exe (MediaMall Technologies, Inc.)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (InputDirector) -- C:\Program Files (x86)\Input Director\IDWinService.exe ()
SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (PDFProFiltSrvPP) -- C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe (Nuance Communications, Inc.)
SRV - (PassThru Service) -- C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (YammmSvc) -- C:\Program Files (x86)\Yammm\YammmSvc.exe (Mikinho)
SRV - (IDVistaService) -- C:\Program Files (x86)\Input Director\IDVistaService.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (CTAudSvcService) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (NILM License Manager) -- C:\Program Files (x86)\National Instruments\Shared\License Manager\Bin\lmgrd.exe (Macrovision Corporation)
SRV - (NIDomainService) -- C:\Program Files (x86)\National Instruments\Shared\Security\nidmsrv.exe (National Instruments Corporation)
SRV - (lkClassAds) -- C:\Windows\SysWOW64\lkads.exe (National Instruments Corporation)
SRV - (lkTimeSync) -- C:\Windows\SysWOW64\lktsrv.exe (National Instruments Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (niSvcLoc) -- C:\Windows\SysWOW64\nisvcloc.exe (National Instruments Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (LkCitadelServer) -- C:\Windows\SysWOW64\lkcitdl.exe (National Instruments, Inc.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (SbieDrv) -- C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:
64bit: - (Lbd) -- C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:
64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:
64bit: - (epmntdrv) -- C:\Windows\SysNative\epmntdrv.sys ()
DRV:
64bit: - (EuGdiDrv) -- C:\Windows\SysNative\EuGdiDrv.sys ()
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (RdpVideoMiniport) -- C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:
64bit: - (BazisVirtualCDBus) -- C:\Windows\SysNative\drivers\BazisVirtualCDBus.sys (SysProgs.org)
DRV:
64bit: - (prwntdrv) -- C:\Windows\SysNative\prwntdrv.sys ()
DRV:
64bit: - (htcnprot) -- C:\Windows\SysNative\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV:
64bit: - (ha20x2k) -- C:\Windows\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:
64bit: - (emupia) -- C:\Windows\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctsfm2k) -- C:\Windows\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctprxy2k) -- C:\Windows\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ossrv) -- C:\Windows\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:
64bit: - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:
64bit: - (ctac32k) -- C:\Windows\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:
64bit: - (CTEXFIFX.SYS) -- C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:
64bit: - (CTEXFIFX) -- C:\Windows\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:
64bit: - (CTHWIUT.SYS) -- C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:
64bit: - (CTHWIUT) -- C:\Windows\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:
64bit: - (CT20XUT.SYS) -- C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:
64bit: - (CT20XUT) -- C:\Windows\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:
64bit: - (msvad_simple) -- C:\Windows\SysNative\drivers\povrtdev.sys (MediaMall Technologies, Inc.)
DRV:
64bit: - (HTCAND64) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:
64bit: - (androidusb) -- C:\Windows\SysNative\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV:
64bit: - (VIAHdAudAddService) -- C:\Windows\SysNative\drivers\viahduaa.sys (VIA Technologies, Inc.)
DRV:
64bit: - (TIEHDUSB) -- C:\Windows\SysNative\drivers\tiehdusb.sys (Texas Instruments)
DRV:
64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (WSDPrintDevice) -- C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:
64bit: - (StillCam) -- C:\Windows\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:
64bit: - (irda) -- C:\Windows\SysNative\drivers\irda.sys (Microsoft Corporation)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek Corporation )
DRV:
64bit: - (irsir) -- C:\Windows\SysNative\drivers\irsir.sys (Microsoft Corporation)
DRV - (epmntdrv) -- C:\Windows\SysWOW64\epmntdrv.sys ()
DRV - (EuGdiDrv) -- C:\Windows\SysWOW64\EuGdiDrv.sys ()
DRV - (speedfan) -- C:\Windows\SysWOW64\speedfan.sys (Almico Software)
DRV - (prwntdrv) -- C:\Windows\SysWOW64\prwntdrv.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (atillk64) -- E:\Apps+Programs\LowLevel\atillk64.sys (ATI Technologies Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 2A 23 65 A8 46 09 CC 01 [binary data]
IE - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Derek\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Derek\AppData\Local\Google\Update\1.3.21.99\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3C5F0F00-683D-4847-89C8-E7AF64FD1CFB}: C:\Program Files (x86)\RelevantKnowledge
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2012/01/11 16:44:16 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/31 23:13:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/01/31 23:13:53 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2011/10/04 23:10:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins
[2011/05/02 22:15:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Derek\AppData\Roaming\Mozilla\Extensions
[2011/05/02 22:15:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Derek\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/02/02 17:15:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0absop31.default\extensions
[2011/12/24 12:05:04 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0absop31.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/01/26 17:01:24 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0absop31.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/02/02 17:15:58 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0absop31.default\extensions\support@lastpass.com
[2012/02/02 17:15:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\dhlgvm7e.Derek2\extensions
[2012/01/28 18:32:38 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\dhlgvm7e.Derek2\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/01/28 18:32:38 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\dhlgvm7e.Derek2\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2012/02/02 17:15:58 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\dhlgvm7e.Derek2\extensions\support@lastpass.com
[2012/02/02 17:15:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\wjwr6dn7.Fresh\extensions
[2012/02/02 17:15:58 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\wjwr6dn7.Fresh\extensions\support@lastpass.com
[2011/02/01 18:05:08 | 000,002,333 | ---- | M] () -- C:\Users\Derek\AppData\Roaming\Mozilla\Firefox\Profiles\0absop31.default\searchplugins\askcom.xml
[2011/11/08 22:00:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\DEREK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0ABSOP31.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\DEREK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0ABSOP31.DEFAULT\EXTENSIONS\MOVABLEAPPBUTTON@MERCI.CHAO.XPI
() (No name found) -- C:\USERS\DEREK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0ABSOP31.DEFAULT\EXTENSIONS\OMNIBAR@AJITK.COM.XPI
() (No name found) -- C:\USERS\DEREK\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\0ABSOP31.DEFAULT\EXTENSIONS\PERSONALTITLEBAR@MOZTW.ORG.XPI
[2011/12/25 01:28:16 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2008/12/10 14:49:34 | 000,023,040 | ---- | M] (National Instruments) -- C:\Program Files (x86)\mozilla firefox\plugins\nplv86win32.dll
[2009/10/07 16:11:28 | 000,025,088 | ---- | M] (National Instruments) -- C:\Program Files (x86)\mozilla firefox\plugins\nplv90win32.dll
[2011/12/01 16:37:49 | 000,005,142 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\arccosine.xml
[2011/09/28 00:30:59 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/08 22:00:04 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Derek\AppData\Local\Google\Chrome\Application\16.0.912.77\pdf.dll
CHR - plugin: Java Platform SE 7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\new_plugin\npjp2.dll
CHR - plugin: MSN\u00AE Toolbar (Enabled) = C:\Program Files (x86)\MSN Toolbar\Platform\4.0.0357.1\npwinext.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Derek\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: YouTube = C:\Users\Derek\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.3_0\
CHR - Extension: Google Search = C:\Users\Derek\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.16_0\
CHR - Extension: LastPass = C:\Users\Derek\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.90.1_0\
CHR - Extension: Gmail = C:\Users\Derek\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/02/06 01:18:04 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (LastPass Browser Helper Object) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O2:
64bit: - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (LastPass Browser Helper Object) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O3 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001..\Run: [InputDirector] C:\Program Files (x86)\Input Director\InputDirector.exe (Imperative Software Pty Ltd)
O4 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001..\Run: [PlayOn] C:\Program Files (x86)\MediaMall\PlayOn.exe (MediaMall Technologies, Inc.)
O4 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001..\Run: [Sidebar] C:\Windows\winsxs\wow64_microsoft-windows-sidebar_31bf3856ad364e35_6.1.7601.17514_none_37575b7e71a86712\sidebar.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
O4 - Startup: C:\Users\Laptop\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
O4 - Startup: C:\Users\Mcx1-DEREK-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
O4 - Startup: C:\Users\Mcx1-DEREK-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk = C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3658522930-349798691-2258556366-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass File not found
O8:
64bit: - Extra context menu item: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: LastPass - file://C:\Program Files (x86)\LastPass\context.html?cmd=lastpass File not found
O8 - Extra context menu item: LastPass Fill Forms - file://C:\Program Files (x86)\LastPass\context.html?cmd=fillforms File not found
O9:
64bit: - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O9:
64bit: - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O9:
64bit: - Extra Button: Encarta Search - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - Reg Error: Key error. File not found
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 10.0.0)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.7.0)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 192.168.254.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F77DF858-C71A-42A2-A8FB-B51A4E81AA24}: DhcpNameServer = 8.8.8.8 192.168.254.254
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O22:
64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/02/06 01:19:54 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/02/06 01:12:35 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/02/06 01:12:35 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/02/06 01:12:35 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/02/06 01:12:32 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/02/06 01:12:29 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/02/06 01:08:10 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\Sunbelt Software
[2012/02/06 00:20:58 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\Apps
[2012/02/06 00:16:01 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\fix
[2012/02/05 17:07:28 | 000,055,384 | ---- | C] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/02/05 17:00:50 | 000,069,376 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2012/02/05 17:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2012/02/05 17:00:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2012/02/05 17:00:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2012/02/05 15:56:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2012/02/05 15:56:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2012/02/05 15:56:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2012/02/05 15:48:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2012/02/05 15:48:55 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/02/05 05:18:07 | 000,000,000 | -H-D | C] -- C:\Users\Derek\Desktop\.picasaoriginals
[2012/02/02 17:15:57 | 014,522,912 | ---- | C] (LastPass) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2012/02/02 17:15:54 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
[2012/02/02 17:15:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
[2012/02/02 17:15:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LastPass
[2012/02/02 15:11:47 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\My PaperPort Documents
[2012/02/02 15:10:44 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\OfficeDrop
[2012/02/02 15:10:19 | 000,000,000 | ---D | C] -- C:\Program Files\Nuance
[2012/02/02 15:09:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Zeon
[2012/02/02 15:08:57 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Zeon
[2012/02/02 15:08:56 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Nuance
[2012/02/02 15:08:42 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\.oit
[2012/02/02 15:08:40 | 000,000,000 | ---D | C] -- C:\ProgramData\ScanSoft
[2012/02/02 15:08:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PaperPort 14
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\ScanSoft Shared
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\Windows\PIXTRAN
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Nuance
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nuance
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\MyWebPages
[2012/02/02 15:08:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Macrovision
[2012/02/01 16:57:18 | 000,000,000 | ---D | C] -- C:\Windows\twain_32
[2012/02/01 16:20:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ixia
[2012/02/01 16:20:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IxiaInstallerCache
[2012/02/01 01:31:52 | 000,000,000 | ---D | C] -- C:\Windows\Hewlett-Packard
[2012/02/01 01:29:12 | 000,000,000 | R--D | C] -- C:\Users\Derek\Documents\Scanned Documents
[2012/02/01 01:29:11 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\Fax
[2012/02/01 01:27:00 | 000,000,000 | ---D | C] -- C:\ProgramData\SSScanAppDataDir
[2012/02/01 01:26:54 | 000,000,000 | ---D | C] -- C:\ProgramData\MSScanAppDataDir
[2012/01/31 23:02:33 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Yahoo!
[2012/01/31 23:02:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Yahoo!
[2012/01/31 23:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
[2012/01/31 23:00:32 | 000,000,000 | ---D | C] -- C:\Program Files\HP
[2012/01/31 22:30:03 | 000,000,000 | ---D | C] -- C:\Users\Derek\0absop31.default
[2012/01/30 12:03:49 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\MigWiz
[2012/01/29 15:38:23 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\More Productivity
[2012/01/29 15:33:07 | 000,000,000 | R--D | C] -- C:\Users\Derek\Desktop\More Apps
[2012/01/29 15:31:04 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\More Managment
[2012/01/29 15:12:47 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\MusicBrainz
[2012/01/29 15:11:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MusicBrainz Picard
[2012/01/28 22:33:47 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\SolidWorks Downloads
[2012/01/28 22:33:47 | 000,000,000 | ---D | C] -- C:\Windows\SolidWorks
[2012/01/28 22:33:46 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\SolidWorks
[2012/01/28 20:10:47 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\Orzeszek
[2012/01/28 18:57:19 | 000,000,000 | R--D | C] -- C:\Sandbox
[2012/01/28 18:56:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sandboxie
[2012/01/28 18:56:22 | 000,000,000 | ---D | C] -- C:\Program Files\Sandboxie
[2012/01/28 18:13:40 | 000,000,000 | R--D | C] -- C:\Users\Derek\Searches
[2012/01/28 17:16:21 | 000,000,000 | R--D | C] -- C:\Users\Derek\Favorites
[2012/01/28 15:32:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/28 15:32:16 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/01/28 15:32:15 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/01/28 15:32:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2012/01/28 15:31:22 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/01/28 15:31:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2012/01/28 14:37:57 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/01/28 14:37:53 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/01/28 14:37:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/01/28 14:37:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/01/25 15:48:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASRock Utility
[2012/01/25 15:48:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ASRock Utility
[2012/01/22 16:10:17 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/01/22 16:10:17 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Adobe Mini Bridge CS5.1
[2012/01/22 15:45:22 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/20 11:50:58 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\Mobiola Video Files
[2012/01/20 11:50:58 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\Mobiola Image Files
[2012/01/20 11:50:58 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\Mobiola Audio Files
[2012/01/20 11:50:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mobiola Web Camera for S60
[2012/01/18 00:52:50 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\eagle
[2012/01/18 00:43:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EAGLE Layout Editor 6.1.0
[2012/01/18 00:38:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EAGLE-6.1.0
[2012/01/18 00:38:25 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\CadSoft
[2012/01/17 12:18:56 | 000,000,000 | ---D | C] -- C:\ProgramData\FLEXnet
[2012/01/17 12:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Macrovision Shared
[2012/01/17 12:13:54 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Autodesk Shared
[2012/01/17 12:13:54 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Autodesk
[2012/01/17 12:13:54 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\Autodesk
[2012/01/17 12:13:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Autodesk
[2012/01/17 12:13:54 | 000,000,000 | ---D | C] -- C:\Program Files\AutoCAD 2010
[2012/01/17 12:12:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
[2012/01/17 12:12:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Autodesk Shared
[2012/01/17 12:12:26 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Autodesk
[2012/01/17 11:58:37 | 000,304,128 | ---- | C] (InstallShield Software Corporation) -- C:\Windows\IsUninst.exe
[2012/01/17 11:55:34 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2012/01/17 11:55:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2012/01/17 11:47:51 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\National Instruments
[2012/01/17 11:42:03 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Google
[2012/01/17 11:42:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Google
[2012/01/17 11:41:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google SketchUp 8
[2012/01/17 03:52:55 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\National Instruments
[2012/01/17 03:52:55 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\National Instruments
[2012/01/17 03:50:38 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HI-TECH Software
[2012/01/17 03:50:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HI-TECH Software
[2012/01/17 03:49:37 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\National Instruments
[2012/01/17 03:49:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\National Instruments
[2012/01/17 03:48:42 | 000,000,000 | ---D | C] -- C:\Program Files\National Instruments
[2012/01/17 03:48:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Merge Modules
[2012/01/17 03:48:27 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\cvirte
[2012/01/17 03:48:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\National Instruments
[2012/01/17 03:46:45 | 000,000,000 | ---D | C] -- C:\ProgramData\National Instruments
[2012/01/17 02:49:01 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\MATLAB
[2012/01/16 18:30:07 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\My Scans
[2012/01/16 16:11:40 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\CCC
[2012/01/16 16:11:26 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Documents
[2012/01/12 18:07:27 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Differential Equations
[2012/01/12 18:06:28 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Circuit Analysys
[2012/01/12 18:06:19 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Engineering Statics
[2012/01/12 18:06:14 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Social Problems
[2012/01/12 18:05:43 | 000,000,000 | ---D | C] -- C:\Users\Derek\Desktop\Physics
[2012/01/12 13:39:40 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/01/12 13:39:40 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2012/01/12 13:39:40 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2012/01/12 13:39:40 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/01/12 13:39:40 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/01/12 13:39:40 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/01/11 19:18:05 | 000,000,000 | ---D | C] -- C:\Users\Derek\.VirtualBox
[2012/01/11 19:17:12 | 000,000,000 | ---D | C] -- C:\Program Files\Oracle
[2012/01/11 19:00:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Input Director
[2012/01/11 19:00:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Input Director
[2012/01/11 12:49:50 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2012/01/11 12:49:50 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2012/01/11 12:49:50 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012/01/11 12:49:50 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012/01/11 12:49:43 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012/01/11 12:49:38 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012/01/11 12:49:38 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2012/01/10 01:41:20 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\My Photos
[2012/01/10 01:41:20 | 000,000,000 | ---D | C] -- C:\Users\Derek\Documents\My Documents
[2012/01/09 23:55:23 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2012/01/09 23:54:20 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Local\Htc
[2012/01/09 23:53:46 | 000,000,000 | ---D | C] -- C:\Users\Derek\AppData\Roaming\HTC
[2012/01/09 23:53:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HTC Sync
[2012/01/09 23:52:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe AIR
[2012/01/09 22:20:25 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spirent Communications
[2012/01/09 17:10:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hewlett-Packard Company
[2010/05/05 18:59:10 | 000,060,928 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2010/05/05 18:38:18 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
[5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/02/06 14:58:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3658522930-349798691-2258556366-1001UA.job
[2012/02/06 14:37:05 | 000,016,848 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 14:37:05 | 000,016,848 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/02/06 01:18:04 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/02/06 00:19:01 | 000,000,000 | ---- | M] () -- C:\Users\Derek\defogger_reenable
[2012/02/05 23:04:45 | 000,000,132 | ---- | M] () -- C:\Users\Derek\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/05 22:36:59 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/02/05 22:36:57 | 2146,910,207 | -HS- | M] () -- C:\hiberfil.sys
[2012/02/05 22:36:20 | 000,062,476 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000000-00001102-00000005-00311102}.rfx
[2012/02/05 22:36:20 | 000,062,476 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000001-00000000-00000000-00001102-00000005-00311102}.rfx
[2012/02/05 22:36:20 | 000,000,788 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000001-00000000-00000000-00001102-00000005-00311102}.rfx
[2012/02/05 22:28:42 | 000,004,164 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2012/02/05 21:02:58 | 000,013,824 | ---- | M] () -- C:\Users\Derek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/02/05 17:07:28 | 000,055,384 | ---- | M] (Sunbelt Software) -- C:\Windows\SysNative\drivers\SBREDrv.sys
[2012/02/05 17:07:24 | 000,016,432 | ---- | M] () -- C:\Windows\SysNative\lsdelete.exe
[2012/02/05 15:58:02 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3658522930-349798691-2258556366-1001Core.job
[2012/02/05 15:56:33 | 000,001,300 | ---- | M] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/02/05 15:56:33 | 000,001,276 | ---- | M] () -- C:\Users\Derek\Desktop\Spybot - Search & Destroy.lnk
[2012/02/05 15:48:55 | 000,002,975 | ---- | M] () -- C:\Users\Derek\Desktop\HiJackThis.lnk
[2012/02/04 16:59:43 | 000,786,330 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/04 16:59:43 | 000,669,072 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/02/04 16:59:43 | 000,125,258 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/02/04 16:59:39 | 000,786,330 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/02/04 16:34:24 | 000,001,150 | ---- | M] () -- C:\Users\Derek\Desktop\Mozilla Firefox.lnk
[2012/02/02 20:32:14 | 000,002,034 | -H-- | M] () -- C:\Users\Derek\Documents\Default.rdp
[2012/02/02 20:16:49 | 000,001,655 | ---- | M] () -- C:\Users\Derek\Desktop\DEREK LAPTOP-HP.lnk
[2012/02/02 17:16:16 | 014,522,912 | ---- | M] (LastPass) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2012/02/02 17:16:16 | 000,001,192 | ---- | M] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\My LastPass Vault.lnk
[2012/02/02 17:15:54 | 000,001,192 | ---- | M] () -- C:\Users\Public\Desktop\My LastPass Vault.lnk
[2012/02/02 16:25:07 | 005,088,456 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/02/02 15:08:35 | 000,002,090 | ---- | M] () -- C:\Users\Public\Desktop\PaperPort.lnk
[2012/02/01 18:38:04 | 000,000,432 | RHS- | M] () -- C:\Users\Derek\ntuser.pol
[2012/02/01 17:33:16 | 000,024,680 | ---- | M] () -- C:\Users\Derek\Documents\Hewlett-Packard bkp.reg
[2012/01/31 21:35:10 | 000,000,840 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/29 20:33:34 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/01/29 20:33:27 | 000,189,248 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012/01/29 20:33:25 | 000,075,136 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/01/29 15:42:43 | 000,002,305 | ---- | M] () -- C:\Users\Derek\Desktop\Laptop User.lnk
[2012/01/29 15:28:21 | 000,000,732 | ---- | M] () -- C:\Users\Derek\Desktop\Apps + Programs.lnk
[2012/01/29 15:21:59 | 000,000,738 | ---- | M] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/01/29 15:14:52 | 000,000,584 | ---- | M] () -- C:\Users\Derek\Desktop\Steam.lnk
[2012/01/29 15:12:58 | 000,001,189 | ---- | M] () -- C:\Users\Derek\Desktop\MusicBrainz Picard.lnk
[2012/01/28 19:34:29 | 000,000,774 | ---- | M] () -- C:\Users\Derek\Desktop\My Music.lnk
[2012/01/28 18:56:22 | 000,000,914 | ---- | M] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2012/01/28 16:59:24 | 000,001,021 | ---- | M] () -- C:\Users\Derek\Desktop\Derek.lnk
[2012/01/28 15:32:36 | 000,001,801 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/25 01:22:50 | 000,000,362 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/01/24 22:08:19 | 000,007,600 | ---- | M] () -- C:\Users\Derek\AppData\Local\resmon.resmoncfg
[2012/01/24 11:53:21 | 000,002,417 | ---- | M] () -- C:\Users\Derek\Desktop\Google Chrome.lnk
[2012/01/23 20:28:05 | 000,013,441 | ---- | M] () -- C:\Users\Derek\Desktop\Desktops.lnk
[2012/01/23 19:01:23 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2012/01/23 19:01:23 | 000,001,080 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2012/01/22 15:45:59 | 000,251,376 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/01/19 21:58:05 | 000,000,132 | ---- | M] () -- C:\Users\Derek\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2012/01/18 00:52:41 | 000,001,129 | ---- | M] () -- C:\Users\Derek\Desktop\EAGLE 6.1.0.lnk
[2012/01/17 12:14:18 | 000,001,919 | ---- | M] () -- C:\Users\Public\Desktop\AutoCAD 2010 - English.lnk
[2012/01/17 12:12:28 | 000,002,172 | ---- | M] () -- C:\Users\Public\Desktop\Autodesk Design Review.lnk
[2012/01/17 11:58:48 | 000,001,111 | ---- | M] () -- C:\Users\Derek\Desktop\Adobe Photoshop.lnk
[2012/01/17 11:45:02 | 000,001,272 | ---- | M] () -- C:\Users\Derek\Desktop\Snipping Tool.lnk
[2012/01/17 11:41:49 | 000,002,043 | ---- | M] () -- C:\Users\Public\Desktop\Google SketchUp 8.lnk
[2012/01/17 11:12:10 | 000,005,460 | ---- | M] () -- C:\Users\Derek\Desktop\Videos & Pictures.lnk
[2012/01/17 11:08:59 | 000,000,500 | ---- | M] () -- C:\Users\Derek\Desktop\Storage (E).lnk
[2012/01/17 11:08:22 | 000,007,438 | ---- | M] () -- C:\Users\Derek\Desktop\My Pictures.lnk
[2012/01/17 11:07:43 | 000,001,227 | ---- | M] () -- C:\Users\Derek\Desktop\My Documents.lnk
[2012/01/17 11:07:33 | 000,000,906 | ---- | M] () -- C:\Users\Derek\Desktop\Downloads (2).lnk
[2012/01/17 03:52:50 | 000,002,184 | ---- | M] () -- C:\Users\Derek\Desktop\Ultiboard 11.0.lnk
[2012/01/17 03:52:48 | 000,002,181 | ---- | M] () -- C:\Users\Derek\Desktop\Multisim 11.0.lnk
[2012/01/11 19:00:07 | 000,001,092 | ---- | M] () -- C:\Users\Public\Desktop\Input Director.lnk
[2012/01/11 16:44:22 | 000,002,044 | ---- | M] () -- C:\Users\Public\Desktop\Acrobat X Pro.lnk
[2012/01/11 16:42:53 | 000,002,114 | ---- | M] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Thunderbird.lnk
[2012/01/09 23:29:01 | 000,000,000 | -H-- | M] () -- C:\Windows\SysNative\drivers\Msft_Kernel_androidusb_01009.Wdf
[5 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/02/06 01:12:35 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/02/06 01:12:35 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/02/06 01:12:35 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/02/06 01:12:35 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/02/06 01:12:35 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/02/06 00:19:01 | 000,000,000 | ---- | C] () -- C:\Users\Derek\defogger_reenable
[2012/02/05 19:34:34 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2012/02/05 15:56:33 | 000,001,300 | ---- | C] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2012/02/05 15:56:33 | 000,001,276 | ---- | C] () -- C:\Users\Derek\Desktop\Spybot - Search & Destroy.lnk
[2012/02/05 15:48:55 | 000,002,975 | ---- | C] () -- C:\Users\Derek\Desktop\HiJackThis.lnk
[2012/02/04 16:34:24 | 000,001,150 | ---- | C] () -- C:\Users\Derek\Desktop\Mozilla Firefox.lnk
[2012/02/02 17:15:57 | 000,001,192 | ---- | C] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\My LastPass Vault.lnk
[2012/02/02 17:15:54 | 000,001,192 | ---- | C] () -- C:\Users\Public\Desktop\My LastPass Vault.lnk
[2012/02/02 15:08:35 | 000,002,090 | ---- | C] () -- C:\Users\Public\Desktop\PaperPort.lnk
[2012/02/01 17:33:16 | 000,024,680 | ---- | C] () -- C:\Users\Derek\Documents\Hewlett-Packard bkp.reg
[2012/01/29 15:42:43 | 000,002,305 | ---- | C] () -- C:\Users\Derek\Desktop\Laptop User.lnk
[2012/01/29 15:42:24 | 000,001,655 | ---- | C] () -- C:\Users\Derek\Desktop\DEREK LAPTOP-HP.lnk
[2012/01/29 15:28:21 | 000,000,732 | ---- | C] () -- C:\Users\Derek\Desktop\Apps + Programs.lnk
[2012/01/29 15:21:59 | 000,000,738 | ---- | C] () -- C:\Users\Public\Desktop\Origin.lnk
[2012/01/29 15:14:52 | 000,000,584 | ---- | C] () -- C:\Users\Derek\Desktop\Steam.lnk
[2012/01/29 15:12:58 | 000,001,189 | ---- | C] () -- C:\Users\Derek\Desktop\MusicBrainz Picard.lnk
[2012/01/29 15:11:20 | 000,001,189 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicBrainz Picard.lnk
[2012/01/28 19:34:29 | 000,000,774 | ---- | C] () -- C:\Users\Derek\Desktop\My Music.lnk
[2012/01/28 18:56:37 | 000,000,914 | ---- | C] () -- C:\Users\Derek\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnk
[2012/01/28 18:56:35 | 000,004,164 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2012/01/28 16:59:24 | 000,001,021 | ---- | C] () -- C:\Users\Derek\Desktop\Derek.lnk
[2012/01/28 15:32:36 | 000,001,801 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/23 20:28:05 | 000,013,441 | ---- | C] () -- C:\Users\Derek\Desktop\Desktops.lnk
[2012/01/22 15:45:59 | 000,251,376 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/01/19 22:18:20 | 000,000,132 | ---- | C] () -- C:\Users\Derek\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/01/19 21:58:05 | 000,000,132 | ---- | C] () -- C:\Users\Derek\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2012/01/18 00:52:41 | 000,001,129 | ---- | C] () -- C:\Users\Derek\Desktop\EAGLE 6.1.0.lnk
[2012/01/17 12:14:18 | 000,001,919 | ---- | C] () -- C:\Users\Public\Desktop\AutoCAD 2010 - English.lnk
[2012/01/17 12:12:28 | 000,002,172 | ---- | C] () -- C:\Users\Public\Desktop\Autodesk Design Review.lnk
[2012/01/17 11:58:48 | 000,001,111 | ---- | C] () -- C:\Users\Derek\Desktop\Adobe Photoshop.lnk
[2012/01/17 11:56:46 | 000,001,111 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1 (64 Bit).lnk
[2012/01/17 11:56:25 | 000,001,241 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.1.lnk
[2012/01/17 11:55:12 | 000,001,203 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.1.lnk
[2012/01/17 11:54:56 | 000,001,296 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.5.lnk
[2012/01/17 11:53:38 | 000,001,397 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.5.lnk
[2012/01/17 11:53:30 | 000,001,569 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.5.lnk
[2012/01/17 11:53:06 | 000,001,015 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/01/17 11:45:02 | 000,001,272 | ---- | C] () -- C:\Users\Derek\Desktop\Snipping Tool.lnk
[2012/01/17 11:41:49 | 000,002,043 | ---- | C] () -- C:\Users\Public\Desktop\Google SketchUp 8.lnk
[2012/01/17 11:12:10 | 000,005,460 | ---- | C] () -- C:\Users\Derek\Desktop\Videos & Pictures.lnk
[2012/01/17 11:08:59 | 000,000,500 | ---- | C] () -- C:\Users\Derek\Desktop\Storage (E).lnk
[2012/01/17 11:08:22 | 000,007,438 | ---- | C] () -- C:\Users\Derek\Desktop\My Pictures.lnk
[2012/01/17 11:07:43 | 000,001,227 | ---- | C] () -- C:\Users\Derek\Desktop\My Documents.lnk
[2012/01/17 11:07:33 | 000,000,906 | ---- | C] () -- C:\Users\Derek\Desktop\Downloads (2).lnk
[2012/01/17 03:52:50 | 000,002,184 | ---- | C] () -- C:\Users\Derek\Desktop\Ultiboard 11.0.lnk
[2012/01/17 03:52:48 | 000,002,181 | ---- | C] () -- C:\Users\Derek\Desktop\Multisim 11.0.lnk
[2012/01/16 18:18:47 | 000,207,087 | ---- | C] () -- C:\Windows\hpoins46.dat.temp
[2012/01/16 18:18:47 | 000,000,601 | ---- | C] () -- C:\Windows\hpomdl46.dat.temp
[2012/01/11 19:00:07 | 000,001,092 | ---- | C] () -- C:\Users\Public\Desktop\Input Director.lnk
[2012/01/11 16:44:22 | 000,002,044 | ---- | C] () -- C:\Users\Public\Desktop\Acrobat X Pro.lnk
[2012/01/09 23:29:01 | 000,000,000 | -H-- | C] () -- C:\Windows\SysNative\drivers\Msft_Kernel_androidusb_01009.Wdf
[2011/12/15 19:31:32 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/12/15 17:56:22 | 000,000,362 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/12/05 22:04:00 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/12/05 22:03:52 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/12/05 20:35:10 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2011/12/05 20:35:10 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/11/07 14:03:39 | 000,189,248 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/11/07 14:03:38 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/30 13:29:17 | 000,000,940 | ---- | C] () -- C:\Windows\lightworks.ini
[2011/10/25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/10/13 14:30:24 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2011/09/12 16:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/20 00:42:46 | 002,469,248 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2011/08/20 00:42:46 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2011/08/20 00:42:46 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2011/08/20 00:42:46 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2011/08/20 00:42:46 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2011/08/13 14:39:25 | 000,013,824 | ---- | C] () -- C:\Users\Derek\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/13 13:13:10 | 000,034,326 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2011/06/12 18:49:00 | 000,007,600 | ---- | C] () -- C:\Users\Derek\AppData\Local\resmon.resmoncfg
[2011/05/16 17:00:55 | 000,002,048 | ---- | C] () -- C:\Windows\SysWow64\winver.exe
[2011/05/03 01:10:01 | 000,786,330 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/02 23:47:38 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/05/02 22:37:50 | 000,098,696 | ---- | C] () -- C:\Windows\SysWow64\setupprwdrv03.exe
[2011/05/02 22:37:50 | 000,013,704 | ---- | C] () -- C:\Windows\SysWow64\prwntdrv.sys
[2011/05/02 22:36:26 | 000,148,480 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2011/05/02 22:36:26 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2011/05/02 22:09:21 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2010/05/05 19:37:52 | 000,021,204 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2010/05/05 19:37:50 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2010/05/05 18:56:46 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL
[2010/05/05 18:46:30 | 000,321,512 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2010/05/05 18:46:30 | 000,056,509 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2010/05/05 18:38:22 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2009/07/13 23:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 20:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/07/06 12:47:08 | 000,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:8EFFFE8D
@Alternate Data Stream - 160 bytes -> C:\ProgramData\TEMP:9D1B94FD
@Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:FD9CE1F3
@Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:890CC2F3
< End of report >