OTL logfile created on: 12/13/11 11:38:11 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Robin\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: M/dd/yy
8.00 Gb Total Physical Memory | 6.07 Gb Available Physical Memory | 75.93% Memory free
10.00 Gb Paging File | 8.06 Gb Available in Paging File | 80.67% Paging File free
Paging file location(s): c:\pagefile.sys 2048 4096 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 583.02 Gb Total Space | 211.79 Gb Free Space | 36.33% Space Free | Partition Type: NTFS
Drive D: | 13.15 Gb Total Space | 1.80 Gb Free Space | 13.66% Space Free | Partition Type: NTFS
Computer Name: [redacted] | User Name: Robin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Robin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil11e_ActiveX.exe (Adobe Systems, Inc.)
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
PRC - C:\Program Files (x86)\Ant.com\IE add-on\AntMaintainer.exe (Ant.com)
PRC - C:\Program Files (x86)\IObit\Advanced Spyware Remover\ASRsrv.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
PRC - c:\Program Files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe (CyberLink Corp.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:
64bit: - (MatSvc) -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV:
64bit: - (NisSrv) -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:
64bit: - (MsMpSvc) -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:
64bit: - (SbieSvc) -- C:\Program Files\Sandboxie\SbieSvc.exe (tzuk)
SRV:
64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:
64bit: - (PDEngine) -- C:\Program Files\Raxco\PerfectDisk10\PDEngine.exe (Raxco Software, Inc.)
SRV:
64bit: - (PDAgent) -- C:\Program Files\Raxco\PerfectDisk10\PDAgent.exe (Raxco Software, Inc.)
SRV:
64bit: - (AgereModemAudio) -- C:\Program Files\LSI SoftModem\agr64svc.exe (LSI Corporation)
SRV:
64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (nvUpdatusService) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (WDSC) -- C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSC.exe ()
SRV - (WDFME) -- C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDFME\WDFME.exe ()
SRV - (CLKMSVC10_9EC60124) -- C:\Program Files (x86)\Cyberlink\PowerDVD9\NavFilter\kmsvc.exe (CyberLink)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (ASRservice) -- C:\Program Files (x86)\IObit\Advanced Spyware Remover\ASRsrv.exe (IObit)
SRV - (Fabs) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe (MAGIX AG)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (UpdateCenterService) -- C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (nTuneService) -- C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (FirebirdServerMAGIXInstance) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe (MAGIX®)
SRV - (PSI_SVC_2) -- c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (dvdfab) -- C:\Windows\SysNative\drivers\dvdfab.sys (Fengtao Software Inc.)
DRV:
64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:
64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:
64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (NisDrv) -- C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (Uim_IM) -- C:\Windows\SysNative\drivers\Uim_IMx64.sys (Paragon)
DRV:
64bit: - (UimBus) -- C:\Windows\SysNative\drivers\uimx64.sys (Windows (R) 2000 DDK provider)
DRV:
64bit: - (hotcore3) -- C:\Windows\SysNative\drivers\hotcore3.sys (Paragon Software Group)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (SbieDrv) -- C:\Program Files\Sandboxie\SbieDrv.sys (tzuk)
DRV:
64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:
64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:
64bit: - (L6UX1) -- C:\Windows\SysNative\drivers\L6UX164.sys (Line 6)
DRV:
64bit: - (pcouffin) -- C:\Windows\SysNative\drivers\pcouffin.sys (VSO Software)
DRV:
64bit: - (AgereSoftModem) -- C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corporation)
DRV:
64bit: - (AnyDVD) -- C:\Windows\SysNative\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV:
64bit: - (ElbyCDIO) -- C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:
64bit: - (DefragFS) -- C:\Windows\SysNative\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV:
64bit: - (NVNET) -- C:\Windows\SysNative\drivers\nvmf6264.sys (NVIDIA Corporation)
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (L6TPortGX) -- C:\Windows\SysNative\drivers\L6TPortGX64.sys (Line 6)
DRV:
64bit: - (NVENETFD) -- C:\Windows\SysNative\drivers\nvm62x64.sys (NVIDIA Corporation)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (cpuz132) -- C:\Windows\SysNative\drivers\cpuz132_x64.sys (Windows (R) Codename Longhorn DDK provider)
DRV:
64bit: - (L6PODX3) -- C:\Windows\SysNative\drivers\L6PODX364.sys (Line 6)
DRV:
64bit: - (WDC_SAM) -- C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV - (AnyDVD) -- C:\Windows\SysWOW64\drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (NVR0FLASHDev) -- C:\Windows\nvflsh64.sys (NVIDIA Corp.)
DRV - (NVR0Dev) -- C:\Windows\nvoclk64.sys (NVIDIA Corp.)
DRV - (speedfan) -- C:\Windows\SysWOW64\speedfan.sys (Windows (R) Server 2003 DDK provider)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_ca&c=91&bd=Pavilion&pf=cndt
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
IE - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "Startpage (SSL)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.ca/"
FF - prefs.js..extensions.enabledItems:
[redacted]:2.3.0
FF - prefs.js..extensions.enabledItems:
[redacted]:2.0.5
FF - prefs.js..extensions.enabledItems: {D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}:0.9.8
FF - prefs.js..extensions.enabledItems: {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8.6
FF - prefs.js..extensions.enabledItems:
[redacted]:2.0.2
FF - prefs.js..extensions.enabledItems: {8FFE139B-90A7-4460-A972-9D2738997F6D}:1.6.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems:
[redacted]:3.6.4
FF - prefs.js..extensions.enabledItems:
[redacted]:1.3.1
FF - prefs.js..extensions.enabledItems:
[redacted]:3.6.4
FF - prefs.js..keyword.URL: "http://search.avg.com/route/?d=4b6526ae&v=6.010.006.004&i=23&tp=ab&iy=&ychte=ca&lng=en-GB&q="
FF - prefs.js..network.proxy.type: 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Robin\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Robin\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/28 15:50:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/09 06:18:58 | 000,000,000 | ---D | M]
[2010/07/15 23:53:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Extensions
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (IE Tab) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (QuickPageZoom) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{8FFE139B-90A7-4460-A972-9D2738997F6D}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (Aero Fox) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{d9b25e30-c1cf-11de-8a39-0800200c9a66}
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (Ant Video Downloader) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\[redacted]
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] ("CyberSearch") -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\[redacted]
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (Foxdie for Firefox) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\[redacted]
[2011/12/07 04:50:26 | 000,000,000 | ---D | M] (GoogleTube) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\[redacted]
[2010/07/15 23:53:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{d9b25e30-c1cf-11de-8a39-0800200c9a66}\chrome\mac\browser\extensions
[2010/07/15 23:53:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{d9b25e30-c1cf-11de-8a39-0800200c9a66}\chrome\mac\mozapps\extensions
[2010/07/15 23:53:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{d9b25e30-c1cf-11de-8a39-0800200c9a66}\chrome\win\browser\extensions
[2010/07/15 23:53:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\extensions\{d9b25e30-c1cf-11de-8a39-0800200c9a66}\chrome\win\mozapps\extensions
[2011/11/11 16:36:31 | 000,002,325 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\searchplugins\startpage-ssl.xml
[2011/12/08 20:22:16 | 000,005,457 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\Mozilla\Firefox\Profiles\t64xcrhc.default\searchplugins\startpage.xml
[2011/11/28 15:50:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/20 20:53:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
() (No name found) -- C:\USERS\ROBIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\T64XCRHC.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\ROBIN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\T64XCRHC.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
[2011/11/28 15:50:44 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2009/11/06 10:37:19 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npCouponPrinter.dll
[2011/09/20 20:52:56 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2009/11/06 10:37:20 | 000,091,552 | ---- | M] (Coupons, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npMozCouponPrinter.dll
[2011/10/09 02:46:17 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/10/09 02:46:17 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/10/09 02:46:17 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/10/09 02:46:17 | 000,001,180 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/10/09 02:46:17 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google ()
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
O1 HOSTS File: ([2011/12/07 22:30:08 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Ant.com browser helper (video detector)) - {346FDE31-DFF9-418A-90C8-BA31DC9FF2EF} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll (Ant.com)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Ant.com Download Toolbar) - {2E924F4F-67F0-4BD8-9560-49F468E843D2} - C:\Program Files (x86)\Ant.com\IE add-on\AntToolbar.dll (Ant.com)
O3:
64bit: - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3:
64bit: - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\..\Toolbar\WebBrowser: (Ant.com Download Toolbar) - {2E924F4F-67F0-4BD8-9560-49F468E843D2} - C:\Program Files (x86)\Ant.com\IE add-on\AntToolbar.dll (Ant.com)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [KBD] C:\Program Files (x86)\Hewlett-Packard\KBD\KbdStub.exe (Microsoft)
O4 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (tzuk)
O4 - HKU\S-1-5-21-488319240-1603442040-3962435957-1003..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun File not found
O4:
64bit: - HKLM..\RunOnce: [PCDrProfiler] C:\Program Files\PC-Doctor for Windows\RunProfiler.exe (PC-Doctor, Inc.)
O4 - HKU\S-1-5-21-488319240-1603442040-3962435957-1003..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RAVCpl64.exe - Shortcut.lnk = C:\Program Files (x86)\Realtek\Audio\Drivers\Vista64\RAVCpl64.exe (Realtek Semiconductor)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 1
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveTrack = 1
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O7 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Zoom Into - C:\Program Files (x86)\zoomintoIE\image.htm ()
O8 - Extra context menu item: Zoom Into - C:\Program Files (x86)\zoomintoIE\image.htm ()
O9 - Extra Button: Download videos by Ant.com - {70AF6C9F-0818-4cf7-924A-BBDBB24211D3} - C:\Program Files (x86)\Ant.com\IE add-on\Download.dll (Ant.com)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O15 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\..Trusted Domains: line6.net ([]* in Trusted sites)
O15 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\..Trusted Ranges: Range1979 ([http] in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} http://www.musicnotes.com/download/mnviewer.cab (Musicnotes Viewer)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6770.cab (Windows Live Safety Center Base Module)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection2.cab (GMNRev Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_27-windows-i586.cab (Java Plug-in 1.6.0_27)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/s ... wflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{37C06628-9292-4122-8AF0-B6BBD25AA72C}: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\belarc - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper:
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-488319240-1603442040-3962435957-1000\...com [@ = ComFile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2011/12/13 11:31:54 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Robin\Desktop\OTL.exe
[2011/12/12 02:27:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Debugging Tools for Windows (x64)
[2011/12/12 02:27:38 | 000,000,000 | ---D | C] -- C:\WinDDK
[2011/12/12 01:39:29 | 004,425,880 | ---- | C] (Innovative Solutions ) -- C:\Users\Robin\Desktop\drivermax.exe
[2011/12/12 01:09:41 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\ElevatedDiagnostics
[2011/12/12 00:20:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
[2011/12/12 00:16:23 | 000,137,536 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvshext.dll
[2011/12/12 00:16:22 | 010,406,208 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcpl.dll
[2011/12/12 00:16:22 | 005,067,584 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvsvc64.dll
[2011/12/12 00:16:22 | 000,837,952 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\easyupdatusapiu64.dll
[2011/12/12 00:16:22 | 000,222,528 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvmctray.dll
[2011/12/12 00:12:54 | 001,452,648 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdagenco6420102.dll
[2011/12/12 00:12:54 | 000,174,184 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\drivers\nvhda64v.sys
[2011/12/12 00:12:54 | 000,029,288 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvhdap64.dll
[2011/12/12 00:12:49 | 008,791,360 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvwgf2umx.dll
[2011/12/12 00:12:49 | 007,041,856 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvwgf2um.dll
[2011/12/12 00:12:49 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/12/12 00:12:49 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/12/12 00:12:48 | 024,796,992 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcompiler.dll
[2011/12/12 00:12:48 | 024,742,720 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvoglv64.dll
[2011/12/12 00:12:48 | 018,871,616 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvoglv32.dll
[2011/12/12 00:12:48 | 017,248,576 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcompiler.dll
[2011/12/12 00:12:48 | 015,693,120 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvd3dumx.dll
[2011/12/12 00:12:48 | 013,205,312 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvd3dum.dll
[2011/12/12 00:12:48 | 007,581,504 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuda.dll
[2011/12/12 00:12:48 | 005,578,560 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuda.dll
[2011/12/12 00:12:48 | 002,808,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvapi64.dll
[2011/12/12 00:12:48 | 002,542,912 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvid.dll
[2011/12/12 00:12:48 | 002,458,432 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvapi.dll
[2011/12/12 00:12:48 | 002,401,088 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvid.dll
[2011/12/12 00:12:48 | 002,232,128 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvcuvenc.dll
[2011/12/12 00:12:48 | 002,099,520 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysWow64\nvcuvenc.dll
[2011/12/12 00:07:15 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\NVIDIA Corporation
[2011/12/11 23:04:58 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\directx
[2011/12/11 22:35:38 | 001,533,248 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvdispco64.dll
[2011/12/11 22:35:38 | 001,454,400 | ---- | C] (NVIDIA Corporation) -- C:\Windows\SysNative\nvgenco64.dll
[2011/12/11 16:34:08 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{745527A5-28F0-4E35-8F12-7A441032FA8C}
[2011/12/11 16:33:57 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{11692236-B597-432A-B574-148B1F106410}
[2011/12/11 03:14:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis
[2011/12/11 03:14:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trend Micro
[2011/12/09 05:45:54 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\IObit
[2011/12/09 05:22:02 | 000,000,000 | ---D | C] -- C:\41f7dcba618342895cab
[2011/12/08 20:07:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2011/12/08 20:06:59 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2011/12/08 00:35:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\DeepBurner Pro
[2011/12/07 22:31:25 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/12/07 22:29:27 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/12/07 22:28:28 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/12/07 22:20:59 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/12/07 22:20:59 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/12/07 22:20:59 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/12/07 22:20:56 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/12/07 22:17:42 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/12/07 21:47:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\SUPERAntiSpyware.com
[2011/12/07 21:24:36 | 004,331,784 | R--- | C] (Swearware) -- C:\Users\Robin\Desktop\ComboFix.exe
[2011/12/07 18:34:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2011/12/07 03:33:37 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/12/07 03:33:34 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/12/07 00:06:40 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2011/12/07 00:06:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Advanced Spyware Remover
[2011/12/06 23:49:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/12/04 10:13:09 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{0C600D9C-D585-43A4-BBBB-FA17E2B37F44}
[2011/12/04 10:12:59 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{1C8E0A02-2C5B-4D85-973D-BA2A2907EFF1}
[2011/12/01 13:43:19 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\robynn825699552
[2011/11/30 17:41:53 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\01-CRA-Info+Forms
[2011/11/29 23:15:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\$60 COST EACH
[2011/11/29 23:08:28 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\10 Bags=$490+$55=$544+$31=$576
[2011/11/28 17:28:53 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\1-IE-Help and Info
[2011/11/28 17:15:40 | 000,000,000 | ---D | C] -- C:\Users\Robin\CyberLink
[2011/11/28 17:12:37 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\zoominto
[2011/11/28 17:12:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\zoomintoIE
[2011/11/28 17:12:33 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Zoominto IePlugin
[2011/11/28 16:17:56 | 000,000,000 | R--D | C] -- C:\Users\Robin\pentadactyl
[2011/11/28 13:48:30 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\S7H0W4
[2011/11/27 12:24:08 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\selling5699552stuff
[2011/11/27 12:24:08 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\[redacted]
[2011/11/25 19:59:22 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{CE91FB52-1138-455D-AB9A-AC16E01CE8E6}
[2011/11/25 19:59:11 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{03E44292-4352-4868-B221-9A2AFABDA503}
[2011/11/24 19:16:46 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\1-Saskatoon Country Western Music Association
[2011/11/22 18:44:15 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{A800477D-372E-42B5-AF06-4B8ADFC0C755}
[2011/11/22 18:44:03 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Local\{1546113B-3CE4-4339-8BCB-F83682801DAD}
[2011/11/20 00:11:01 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\1-Metis-Info
[2011/11/19 15:12:10 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\01-Banking-Credit Card & Credit-Info
[2011/11/18 02:49:31 | 000,000,000 | ---D | C] -- C:\Users\Robin\.gimp-2.6
[2011/11/18 00:10:02 | 000,000,000 | ---D | C] -- C:\Users\Robin\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/11/17 22:02:55 | 000,000,000 | ---D | C] -- C:\ProgramData\regid.1986-12.com.adobe
[2011/11/17 22:02:26 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011/11/17 21:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011/11/17 21:58:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2011/11/17 21:58:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe Media Player
[2011/11/17 14:28:55 | 000,000,000 | ---D | C] -- C:\Users\Robin\Desktop\TAKE LEARNERS TEST!!!
[2011/11/14 23:30:55 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\01-Kijiji-Stuff
[2011/11/13 21:50:47 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\VSOBlurayConverter
[2011/11/13 21:33:11 | 000,000,000 | ---D | C] -- C:\Users\Robin\Documents\DVDFab Passkey
[2011/11/13 21:29:09 | 000,079,232 | ---- | C] (Fengtao Software Inc.) -- C:\Windows\SysNative\drivers\dvdfab.sys
[2011/11/13 21:29:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DVDFab Passkey
[2011/11/13 20:52:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
[2011/11/13 20:52:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SlySoft
[2011/11/13 20:43:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
[2010/01/30 21:06:32 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Robin\AppData\Roaming\pcouffin.sys
[2009/10/11 19:26:40 | 000,405,504 | ---- | C] (Waves Audio Ltd.) -- C:\Program Files (x86)\Vocal_WaveShell-VST 1.1.dll
[2009/10/11 19:26:35 | 000,442,368 | ---- | C] (Waves Audio Ltd.) -- C:\Program Files (x86)\WaveShell-DX 5.7.dll
[2009/10/11 19:26:24 | 000,417,792 | ---- | C] (Waves Audio Ltd) -- C:\Program Files (x86)\WaveShell-VST 5.2.dll
[2009/10/11 19:26:19 | 000,098,304 | ---- | C] (Waves Audio Ltd) -- C:\Program Files (x86)\WaveShell-VST 5.0.dll
[2009/10/11 19:26:14 | 000,557,056 | ---- | C] (Waves Audio Ltd.) -- C:\Program Files (x86)\WaveShell-VST 5.7.dll
[2009/10/11 19:26:09 | 000,405,504 | ---- | C] (Waves Audio Ltd.) -- C:\Program Files (x86)\WaveShell-VST 5.5.dll
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Robin\*.tmp files -> C:\Users\Robin\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Robin\AppData\Local\*.tmp files -> C:\Users\Robin\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/13 11:31:55 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Robin\Desktop\OTL.exe
[2011/12/13 11:18:29 | 000,006,416 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/13 11:18:29 | 000,006,416 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/13 11:11:01 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-488319240-1603442040-3962435957-1000UA.job
[2011/12/13 11:09:20 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/12/13 04:06:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/12/13 01:30:02 | 000,001,854 | ---- | M] () -- C:\Users\Robin\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/12 22:49:57 | 000,198,656 | ---- | M] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/12/12 20:11:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-488319240-1603442040-3962435957-1000Core.job
[2011/12/12 17:25:08 | 005,075,296 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/12/12 12:47:12 | 000,000,850 | ---- | M] () -- C:\Users\Robin\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/12 03:04:02 | 000,000,042 | ---- | M] () -- C:\Windows\SysNative\1323680642.lock
[2011/12/12 02:42:05 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\windbg.exe
[2011/12/12 02:41:11 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\cd
[2011/12/12 01:39:32 | 004,425,880 | ---- | M] (Innovative Solutions ) -- C:\Users\Robin\Desktop\drivermax.exe
[2011/12/12 00:12:15 | 000,001,996 | ---- | M] () -- C:\Windows\Sandboxie.ini
[2011/12/11 20:41:06 | 000,007,616 | ---- | M] () -- C:\Users\Robin\AppData\Local\resmon.resmoncfg
[2011/12/11 03:48:40 | 000,001,598 | ---- | M] () -- C:\Users\Robin\Desktop\Hijack.exe - Shortcut.lnk
[2011/12/10 23:24:56 | 000,000,065 | ---- | M] () -- C:\Windows\SysNative\1323581096.lock
[2011/12/10 23:24:32 | 000,000,068 | ---- | M] () -- C:\Windows\SysNative\1323581072.lock
[2011/12/10 23:13:16 | 000,000,067 | ---- | M] () -- C:\Windows\SysNative\1323580396.lock
[2011/12/10 23:12:39 | 000,000,067 | ---- | M] () -- C:\Windows\SysNative\1323580359.lock
[2011/12/10 23:10:46 | 000,000,064 | ---- | M] () -- C:\Windows\SysNative\1323580246.lock
[2011/12/10 23:10:25 | 000,000,194 | ---- | M] () -- C:\Windows\SysNative\1323580223.lock
[2011/12/08 23:11:02 | 000,196,608 | ---- | M] () -- C:\Windows\ocsetup_install_optionalfeatures.exe.etl
[2011/12/08 13:12:21 | 000,001,908 | ---- | M] () -- C:\Windows\diagwrn.xml
[2011/12/08 13:12:21 | 000,001,908 | ---- | M] () -- C:\Windows\diagerr.xml
[2011/12/07 22:30:08 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/12/07 18:07:04 | 004,331,784 | R--- | M] (Swearware) -- C:\Users\Robin\Desktop\ComboFix.exe
[2011/12/07 15:02:56 | 000,684,297 | ---- | M] () -- C:\Users\Robin\Desktop\unhide.exe
[2011/12/06 23:00:26 | 000,754,176 | ---- | M] () -- C:\Users\Robin\Desktop\RogueKiller.exe
[2011/12/04 11:06:50 | 000,081,183 | ---- | M] () -- C:\Users\Robin\Desktop\01-Black With Red Bows Corset-EBAY-$64.JPG
[2011/12/02 21:48:02 | 014,857,716 | ---- | M] () -- C:\Users\Robin\Desktop\Fox_On_The_Run_-Sweet.mp4
[2011/12/01 14:01:09 | 000,000,456 | ---- | M] () -- C:\Windows\tasks\PCDRScheduledMaintenance.job
[2011/11/29 10:53:15 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/28 15:51:53 | 000,001,905 | ---- | M] () -- C:\Users\Robin\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2011/11/28 09:44:49 | 000,000,000 | ---- | M] () -- C:\Users\Robin\AppData\Local\{A68F38EA-0815-4D70-8EAA-EEE3F4F36F8F}
[2011/11/22 19:20:27 | 000,002,219 | ---- | M] () -- C:\Users\Robin\.recently-used.xbel
[2011/11/18 02:42:14 | 000,001,456 | ---- | M] () -- C:\Users\Robin\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/11/13 20:55:16 | 000,000,040 | -HS- | M] () -- C:\ProgramData\.zreglib
[2011/11/13 20:43:25 | 000,082,816 | ---- | M] (VSO Software) -- C:\Users\Robin\AppData\Roaming\pcouffin.sys
[2011/11/13 20:43:25 | 000,007,859 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\pcouffin.cat
[2011/11/13 20:43:25 | 000,001,167 | ---- | M] () -- C:\Users\Robin\AppData\Roaming\pcouffin.inf
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Users\Robin\*.tmp files -> C:\Users\Robin\*.tmp -> ]
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Robin\AppData\Local\*.tmp files -> C:\Users\Robin\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/12 19:19:42 | 000,754,176 | ---- | C] () -- C:\Users\Robin\Desktop\RogueKiller.exe
[2011/12/12 12:47:12 | 000,000,850 | ---- | C] () -- C:\Users\Robin\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/12/12 12:46:23 | 000,001,854 | ---- | C] () -- C:\Users\Robin\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/12/12 03:04:02 | 000,000,042 | ---- | C] () -- C:\Windows\SysNative\1323680642.lock
[2011/12/12 02:42:05 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\windbg.exe
[2011/12/12 02:41:11 | 000,000,000 | ---- | C] () -- C:\Windows\SysNative\cd
[2011/12/11 03:48:40 | 000,001,598 | ---- | C] () -- C:\Users\Robin\Desktop\Hijack.exe - Shortcut.lnk
[2011/12/10 23:32:32 | 000,007,616 | ---- | C] () -- C:\Users\Robin\AppData\Local\resmon.resmoncfg
[2011/12/10 23:24:56 | 000,000,065 | ---- | C] () -- C:\Windows\SysNative\1323581096.lock
[2011/12/10 23:24:32 | 000,000,068 | ---- | C] () -- C:\Windows\SysNative\1323581072.lock
[2011/12/10 23:13:16 | 000,000,067 | ---- | C] () -- C:\Windows\SysNative\1323580396.lock
[2011/12/10 23:12:39 | 000,000,067 | ---- | C] () -- C:\Windows\SysNative\1323580359.lock
[2011/12/10 23:10:46 | 000,000,064 | ---- | C] () -- C:\Windows\SysNative\1323580246.lock
[2011/12/10 23:10:23 | 000,000,194 | ---- | C] () -- C:\Windows\SysNative\1323580223.lock
[2011/12/10 16:28:53 | 000,684,297 | ---- | C] () -- C:\Users\Robin\Desktop\unhide.exe
[2011/12/10 16:28:33 | 001,008,092 | ---- | C] () -- C:\Users\Robin\Desktop\iExplore.exe
[2011/12/10 16:28:22 | 001,008,092 | ---- | C] () -- C:\Users\Robin\Desktop\rkill.exe
[2011/12/08 23:10:41 | 000,196,608 | ---- | C] () -- C:\Windows\ocsetup_install_optionalfeatures.exe.etl
[2011/12/07 23:19:03 | 000,014,726 | ---- | C] () -- C:\Users\Robin\Desktop\Taskbar-Shortcut Icons.JPG
[2011/12/07 23:19:03 | 000,009,804 | ---- | C] () -- C:\Users\Robin\Desktop\Taskbar-Apps Currently Running-NOT MANY.JPG
[2011/12/07 22:32:11 | 000,006,416 | ---- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/07 22:32:11 | 000,006,416 | ---- | C] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/07 22:20:59 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/12/07 22:20:59 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/12/07 22:20:59 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/12/07 22:20:59 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/12/07 22:20:59 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/12/04 11:13:28 | 000,081,183 | ---- | C] () -- C:\Users\Robin\Desktop\01-Black With Red Bows Corset-EBAY-$64.JPG
[2011/12/02 21:47:11 | 014,857,716 | ---- | C] () -- C:\Users\Robin\Desktop\Fox_On_The_Run_-Sweet.mp4
[2011/11/28 09:44:49 | 000,000,000 | ---- | C] () -- C:\Users\Robin\AppData\Local\{A68F38EA-0815-4D70-8EAA-EEE3F4F36F8F}
[2011/11/22 19:20:27 | 000,002,219 | ---- | C] () -- C:\Users\Robin\.recently-used.xbel
[2011/11/18 02:42:14 | 000,001,456 | ---- | C] () -- C:\Users\Robin\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/11/17 16:20:23 | 091,121,388 | ---- | C] () -- C:\Users\Robin\Desktop\The Jack [Live].wav
[2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/10/09 17:27:11 | 002,469,760 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2011/10/09 17:27:11 | 000,019,840 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2011/10/09 17:27:10 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2011/10/09 17:27:10 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2011/10/09 17:27:10 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2011/09/30 15:59:21 | 000,000,578 | ---- | C] () -- C:\Windows\hpomdl36.dat.temp
[2011/09/22 15:36:20 | 000,001,996 | ---- | C] () -- C:\Windows\Sandboxie.ini
[2011/01/28 20:44:36 | 000,000,377 | ---- | C] () -- C:\Windows\lgfwup.ini
[2011/01/27 17:12:30 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2011/01/11 00:28:11 | 000,000,258 | ---- | C] () -- C:\ProgramData\tmaster8.net
[2010/12/19 22:41:44 | 000,734,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/09/23 21:04:44 | 000,000,000 | ---- | C] () -- C:\Users\Robin\AppData\Local\prvlcl.dat
[2010/09/13 19:43:27 | 000,023,127 | ---- | C] () -- C:\Windows\hpqins15.dat.temp
[2010/09/02 01:33:54 | 000,015,360 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2010/09/02 01:32:52 | 000,058,368 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2010/08/10 16:06:02 | 000,000,016 | ---- | C] () -- C:\Windows\SysWow64\msvcsv60.dll
[2010/08/10 16:06:02 | 000,000,016 | ---- | C] () -- C:\Windows\msocreg32.dat
[2010/07/16 16:19:53 | 000,000,088 | RHS- | C] () -- C:\ProgramData\19C2AC9A03.sys
[2010/07/16 16:19:52 | 000,005,018 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2010/07/05 16:40:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/06/14 22:21:12 | 000,237,568 | R--- | C] () -- C:\Windows\SysWow64\qtmlClient.dll
[2010/06/14 22:21:12 | 000,002,145 | ---- | C] () -- C:\Windows\Graffiti5.2Pin.ini
[2010/04/29 09:37:26 | 000,002,137 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/04/15 14:54:46 | 000,023,336 | ---- | C] () -- C:\Windows\hpqins15.dat
[2010/02/04 23:31:22 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\Iyvu9_32.dll
[2010/02/04 23:28:03 | 000,000,012 | ---- | C] () -- C:\Windows\Ulead32.ini
[2010/01/30 21:06:32 | 000,007,859 | ---- | C] () -- C:\Users\Robin\AppData\Roaming\pcouffin.cat
[2010/01/30 21:06:32 | 000,001,167 | ---- | C] () -- C:\Users\Robin\AppData\Roaming\pcouffin.inf
[2010/01/27 20:01:22 | 000,085,504 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/01/27 15:51:20 | 000,198,656 | ---- | C] () -- C:\Users\Robin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/12/15 15:24:30 | 000,129,024 | ---- | C] () -- C:\Windows\SysWow64\AVERM.dll
[2009/12/15 15:24:30 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2009/10/16 12:27:30 | 000,000,486 | ---- | C] () -- C:\Users\Robin\AppData\Roaming\wklnhst.dat
[2009/10/10 22:38:21 | 000,118,784 | ---- | C] () -- C:\Windows\dsdxirmv.exe
[2009/10/08 22:41:50 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2009/08/16 10:08:36 | 000,178,176 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009/07/13 20:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 20:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 18:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 17:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 15:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 15:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/05/29 15:52:26 | 000,204,800 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 15:47:06 | 000,881,664 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2009/03/03 15:39:02 | 000,327,680 | ---- | C] () -- C:\Windows\SysWow64\pythoncom25.dll
[2009/03/03 15:39:02 | 000,102,400 | ---- | C] () -- C:\Windows\SysWow64\pywintypes25.dll
[2008/02/08 17:13:44 | 000,319,488 | ---- | C] () -- C:\Windows\SysWow64\LS3Renderer.dll
[2007/04/27 09:43:58 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll
[2007/04/18 23:07:00 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\mgxasio2.dll
[2007/01/26 02:04:12 | 000,138,752 | ---- | C] () -- C:\Windows\SysWow64\mase32.dll
[2007/01/26 02:04:12 | 000,027,648 | ---- | C] () -- C:\Windows\SysWow64\ma32.dll
[2006/11/02 09:10:16 | 000,080,912 | ---- | C] () -- C:\Windows\SysWow64\sherlock2.exe
[2005/02/03 01:50:28 | 000,004,224 | ---- | C] () -- C:\Windows\SysWow64\StarOpen.sys
[1980/01/01 01:01:01 | 000,000,000 | ---- | C] () -- C:\Windows\bootstat.dat
========== Alternate Data Streams ==========
@Alternate Data Stream - 500 bytes -> C:\ProgramData\Temp:05EE1EEF
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:CF778051
< End of report >