OTL produced only one report that I can see. I ran it twice to see if I missed something, but still only this report.
OTL logfile created on: 2/24/2013 7:33:36 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Documents and Settings\Wester\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.73% Memory free
3.84 Gb Paging File | 2.91 Gb Available in Paging File | 75.85% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.46 Gb Total Space | 25.44 Gb Free Space | 34.17% Space Free | Partition Type: NTFS
Computer Name: OWNER-71B831874 | User Name: Wester | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/02/24 19:01:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Wester\Desktop\OTL.exe
PRC - [2013/01/31 10:38:54 | 003,289,208 | ---- | M] (Skype Technologies S.A.) -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe
PRC - [2012/10/30 14:50:59 | 004,297,136 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2012/10/30 14:50:59 | 000,044,808 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2012/09/26 15:12:33 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
PRC - [2012/09/11 18:40:30 | 000,296,096 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2011/05/27 14:57:30 | 000,562,592 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
PRC - [2011/05/27 14:57:28 | 002,015,136 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
PRC - [2011/05/27 14:57:26 | 007,025,568 | ---- | M] (Affinegy, Inc.) -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
PRC - [2011/01/12 18:01:28 | 006,129,496 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Vid HD\Vid.exe
PRC - [2010/05/07 17:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
PRC - [2010/05/07 17:43:52 | 000,651,096 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2010/05/07 17:35:22 | 000,165,208 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2010/05/07 17:34:58 | 000,168,792 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2008/04/13 16:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2013/02/24 13:35:02 | 002,063,360 | ---- | M] () -- C:\Program Files\Alwil Software\Avast5\defs\13022401\algo.dll
MOD - [2011/05/27 14:57:32 | 000,022,944 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinServicePS.dll
MOD - [2011/05/27 14:08:56 | 000,660,480 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
MOD - [2011/01/12 17:57:34 | 000,751,616 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\vpxmd.dll
MOD - [2011/01/12 17:55:28 | 000,027,472 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\SDL.dll
MOD - [2010/11/12 08:23:44 | 000,330,584 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2010/11/09 18:45:18 | 000,181,592 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\SharedBin\LvApi11.dll
MOD - [2010/08/22 20:01:36 | 007,187,456 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\QtGui4.dll
MOD - [2010/08/22 20:01:08 | 000,325,632 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\QtXml4.dll
MOD - [2010/08/22 20:01:06 | 001,954,304 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\QtCore4.dll
MOD - [2010/08/22 20:01:06 | 000,847,360 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\QtNetwork4.dll
MOD - [2010/08/22 19:32:34 | 000,119,808 | ---- | M] () -- C:\Program Files\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll
MOD - [2010/05/07 17:43:52 | 000,651,096 | ---- | M] () -- C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2010/05/07 17:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010/05/07 17:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010/05/07 17:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010/05/07 17:36:20 | 000,921,944 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QtNetwork4.dll
MOD - [2010/05/07 17:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010/05/07 17:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2010/05/07 17:34:58 | 000,168,792 | ---- | M] () -- C:\Program Files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2009/04/22 13:53:56 | 000,969,040 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtNetwork4.dll
MOD - [2009/04/09 15:04:56 | 002,141,008 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtCore4.dll
MOD - [2009/03/03 14:18:08 | 000,138,064 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll
MOD - [2009/03/03 14:18:06 | 000,035,152 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\plugins\imageformats\qico4.dll
MOD - [2009/03/03 14:18:06 | 000,029,008 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\plugins\imageformats\qgif4.dll
MOD - [2009/03/03 14:17:46 | 011,311,952 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtWebKit4.dll
MOD - [2009/03/03 14:17:46 | 000,363,856 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtXml4.dll
MOD - [2009/03/03 14:17:44 | 000,200,016 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtSql4.dll
MOD - [2009/03/03 14:17:40 | 000,475,472 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtOpenGL4.dll
MOD - [2009/03/03 14:17:38 | 007,704,400 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\QtGui4.dll
MOD - [2009/03/03 14:17:32 | 000,291,664 | ---- | M] () -- C:\Program Files\Logitech\Vid HD\phonon4.dll
MOD - [2008/04/13 16:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2008/04/13 16:11:51 | 000,059,904 | ---- | M] () -- C:\WINDOWS\system32\devenum.dll
MOD - [2003/03/09 12:31:04 | 000,561,152 | ---- | M] () -- C:\Program Files\Hewlett-Packard\Digital Imaging\{7C8BB31C-E09E-4c7d-BBF1-45E33B467FE1}\Drivers\Scanner\hpotscl.dll
========== Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- %SystemRoot%\System32\appmgmts.dll -- (AppMgmt)
SRV - [2013/02/16 09:38:36 | 000,251,248 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2013/01/31 10:38:54 | 003,289,208 | ---- | M] (Skype Technologies S.A.) [Auto | Running] -- C:\Documents and Settings\All Users\Application Data\Skype\Toolbars\Skype C2C Service\c2c_service.exe -- (Skype C2C Service)
SRV - [2013/01/08 12:55:20 | 000,161,536 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/10/30 14:50:59 | 000,044,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2012/09/26 15:12:33 | 000,116,608 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE.EXE -- (!SASCORE)
SRV - [2011/05/27 14:57:30 | 000,562,592 | ---- | M] (Affinegy, Inc.) [Auto | Running] -- C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe -- (AffinegyService)
SRV - [2010/05/07 17:47:32 | 000,162,648 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2003/03/09 12:31:02 | 000,065,795 | R--- | M] (HP) [On_Demand | Stopped] -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Wester\LOCALS~1\Temp\cpuz134\cpuz134_x32.sys -- (cpuz134)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Wester\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys -- (cpuz132)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Wester\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\AFGMp50.sys -- (AFGMp50)
DRV - [2012/10/30 14:51:58 | 000,738,504 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2012/10/30 14:51:58 | 000,361,032 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/10/30 14:51:58 | 000,054,232 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2012/10/30 14:51:58 | 000,035,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2012/10/30 14:51:57 | 000,097,608 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2012/10/30 14:51:56 | 000,025,256 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2012/10/30 14:51:56 | 000,021,256 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/09/08 13:35:59 | 000,067,664 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2011/09/08 13:35:59 | 000,012,880 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2011/01/03 20:04:42 | 000,195,424 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6)
DRV - [2010/11/09 18:49:50 | 004,323,040 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC)
DRV - [2010/11/09 18:48:12 | 000,283,744 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvrs.sys -- (LVRS)
DRV - [2010/11/07 16:26:16 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/08/25 14:45:28 | 000,395,464 | ---- | M] (Paragon) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\Uim_IM.sys -- (Uim_IM)
DRV - [2010/08/25 14:45:28 | 000,037,080 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Stopped] -- C:\WINDOWS\system32\drivers\UimBus.sys -- (UimBus)
DRV - [2010/08/22 20:01:54 | 000,027,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AFGSp50.sys -- (AFGSp50)
DRV - [2010/05/07 17:43:30 | 000,025,824 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2009/12/30 10:20:56 | 000,027,064 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\revoflt.sys -- (Revoflt)
DRV - [2008/02/27 12:49:00 | 000,003,840 | ---- | M] () [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\BANTExt.sys -- (BANTExt)
DRV - [2007/05/02 15:21:22 | 004,403,712 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService)
DRV - [2004/10/07 17:16:04 | 000,035,840 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.sisqtel.net/
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{30CFB165-2CF1-7712-E58F-3A8DBE9E3CFA}: "URL" = http://www.incredimail-start.com/s/?q={searchTerms}&iesrc=IE-SearchBox&site=Bing&cfg=2-428-0-2mvZP
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{4C88943D-6D33-44E1-A4AA-8513CDF0FD70}: "URL" = http://www.amazon.com/gp/bit/amazonserp/ref=bit_f_abba_serp_ie_us_display?ie=UTF8&ie=UTF8&tag=abba-serp-us-ie-20&tagbase=abba&query={searchTerms}
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{8AAAD4E0-BC8D-4D5D-9BB1-84FFA75BE92F}: "URL" = http://www.mysearchresults.com/search?&c=2652&t=03&q={searchTerms}
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{A7074310-4059-46BB-976E-7A06E7573070}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7GZAZ_en
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\SearchScopes\{D591FBDA-7BFF-4C48-85EF-4189AC549A0C}: "URL" = http://www.google.com/search?q={searchTerms}&rlz=1I7GZAZ_en
IE - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}: C:\Program Files\Wajam\Firefox\{5a95a9e0-59dd-4314-bd84-4d18ca83a0e2}.xpi
[2010/11/06 12:46:42 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Extensions
[2010/01/09 06:21:50 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2013/02/24 19:06:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions
[2013/02/21 19:43:31 | 000,000,000 | ---D | M] ("Coupon Companion Plugin") -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]
[2013/02/16 09:37:41 | 000,000,000 | ---D | M] (Delta Toolbar) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]
[2013/02/16 09:37:28 | 000,000,000 | ---D | M] (GetSavin) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\getsavin@jetpack
[2011/12/26 20:19:26 | 000,000,000 | ---D | M] (EpicPlay Games) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]
[2013/02/21 19:03:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]\chrome
[2013/02/21 19:03:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]\defaults
[2013/02/21 19:03:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]\locale
[2013/02/21 19:03:10 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]\skin
[2013/02/21 19:03:09 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]\chrome\content\extensionCode
[2012/12/31 17:46:08 | 000,216,743 | ---- | M] () (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]
[2012/07/31 03:59:18 | 000,221,380 | ---- | M] () (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\
[email protected]
[2013/01/01 11:35:14 | 000,555,412 | ---- | M] () (No name found) -- C:\Documents and Settings\Wester\Application Data\Mozilla\Firefox\Profiles\lotgrs3i.default\extensions\{3fe6b000-fd7d-a4e4-edda-ef3dc5c7f32c}.xpi
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\WESTER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LOTGRS3I.DEFAULT\EXTENSIONS\39FFXTBR@MAPSGALAXY_39.COM
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\WESTER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LOTGRS3I.DEFAULT\EXTENSIONS\
[email protected]
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\WESTER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LOTGRS3I.DEFAULT\EXTENSIONS\
[email protected]
File not found (No name found) -- C:\DOCUMENTS AND SETTINGS\WESTER\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\LOTGRS3I.DEFAULT\EXTENSIONS\
[email protected]
========== Chrome ==========
O1 HOSTS File: ([2013/02/24 07:05:54 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.)
O2 - BHO: (SocialRibbons LP5) - {CBF3FDCA-6104-1864-D931-D737D2BFC202} - C:\Program Files\SocialRibbons LP5\Toolbar.dll ()
O2 - BHO: (SimpleAdblock Class) - {FFCB3198-32F3-4E8B-9539-4324694ED664} - C:\Program Files\Common Files\Simple Adblock\SimpleAdblock.dll File not found
O3 - HKLM\..\Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe (Affinegy, Inc.)
O4 - HKLM..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [Nikon Message Center 2] C:\Program Files\Nikon\Nikon Message Center 2\NkMC2.exe (Nikon Corporation)
O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Real\RealPlayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004..\Run: [GoogleChromeAutoLaunch_68C5A8428529928452A60A8F37F8FE9D] C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004..\Run: [Logitech Vid] C:\Program Files\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.)
O4 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O15 - HKU\S-1-5-21-1960408961-1801674531-725345543-1004\..Trusted Domains: netflix.com ([]* in Trusted sites)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
http://qtinstall.apple.com/qtactivex/qtplugin.cab (QuickTime Object)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8}
http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/downl...-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E3F1348-4370-4BBE-A67A-CC7ED824CA85}
http://download.microsoft.com/downl...75-4d5b-a6dd-9c4bc923683e/Selfhelpcontrol.cab (Microsoft Genuine Advantage Self Support Tool)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1352645896906 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0EB5D392-0969-4012-A619-931FF8F7F152}: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Wester\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Wester\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/08 18:38:23 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/02/24 19:20:28 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERUNT
[2013/02/24 19:19:39 | 000,000,000 | ---D | C] -- C:\JRT
[2013/02/24 19:18:50 | 000,547,439 | ---- | C] (Oleg N. Scherbakov) -- C:\Documents and Settings\Wester\Desktop\JRT.exe
[2013/02/24 19:18:39 | 000,547,439 | ---- | C] (Oleg N. Scherbakov) -- C:\Documents and Settings\Wester\Desktop\JRTasd.exe
[2013/02/24 18:52:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Wester\Desktop\OTLaaa.exe
[2013/02/24 12:41:43 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2013/02/24 11:47:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2013/02/24 06:48:37 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Wester\Recent
[2013/02/23 21:03:36 | 000,000,000 | ---D | C] -- C:\found.000
[2013/02/23 20:24:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Start Menu\Programs\Revo Uninstaller
[2013/02/23 19:49:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Start Menu\Programs\HiJackThis
[2013/02/23 19:38:05 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2013/02/23 19:23:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Max Uninstaller
[2013/02/23 19:23:23 | 000,000,000 | ---D | C] -- C:\Program Files\Max Uninstaller
[2013/02/23 08:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Application Data\ElevatedDiagnostics
[2013/02/23 08:07:20 | 000,000,000 | ---D | C] -- C:\MATS
[2013/02/23 08:04:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Windows PowerShell 1.0
[2013/02/23 08:04:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\windowspowershell
[2013/02/23 06:55:37 | 005,034,320 | R--- | C] (Swearware) -- C:\Documents and Settings\Wester\Desktop\ComboFix.exe
[2013/02/22 22:13:43 | 000,000,000 | ---D | C] -- C:\Program Files\ Online Backup
[2013/02/22 18:11:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Application Data\PriceGong(2)
[2013/02/22 10:00:09 | 000,000,000 | ---D | C] -- C:\AI_RecycleBin
[2013/02/21 19:44:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ESET
[2013/02/21 19:25:08 | 000,000,000 | ---D | C] -- C:\avast! sandbox(2)
[2013/02/21 05:59:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\My Documents\mbar
[2013/02/17 19:39:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Local Settings\Application Data\ESET
[2013/02/17 19:31:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\ESET
[2013/02/16 09:37:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Wester\Local Settings\Application Data\getsavin
========== Files - Modified Within 30 Days ==========
[2013/02/24 19:18:53 | 000,547,439 | ---- | M] (Oleg N. Scherbakov) -- C:\Documents and Settings\Wester\Desktop\JRT.exe
[2013/02/24 19:18:41 | 000,547,439 | ---- | M] (Oleg N. Scherbakov) -- C:\Documents and Settings\Wester\Desktop\JRTasd.exe
[2013/02/24 19:07:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2013/02/24 19:07:45 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2013/02/24 19:05:18 | 000,594,019 | ---- | M] () -- C:\Documents and Settings\Wester\Desktop\aaa.exe
[2013/02/24 19:01:35 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Wester\Desktop\OTL.exe
[2013/02/24 18:52:20 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Wester\Desktop\OTLaaa.exe
[2013/02/24 18:48:14 | 000,000,326 | ---- | M] () -- C:\WINDOWS\reimage.ini
[2013/02/24 18:38:49 | 000,000,488 | ---- | M] () -- C:\hpfr5550.xml
[2013/02/24 18:37:25 | 000,002,515 | ---- | M] () -- C:\Documents and Settings\Wester\Desktop\Microsoft Office Word 2007 (2).lnk
[2013/02/24 17:32:52 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2013/02/24 17:31:19 | 000,000,020 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2013/02/24 07:05:54 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2013/02/23 20:12:14 | 000,694,288 | ---- | M] () -- C:\Documents and Settings\Wester\Desktop\HiJackThis.zip
[2013/02/23 06:56:45 | 005,034,320 | R--- | M] (Swearware) -- C:\Documents and Settings\Wester\Desktop\ComboFix.exe
[2013/02/22 22:20:35 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2013/02/22 20:04:48 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2013/02/21 19:48:58 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2013/02/21 19:48:58 | 000,000,318 | -H-- | M] () -- C:\WINDOWS\tasks\avast! Emergency Update.job
[2013/02/17 18:00:09 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\Wester\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/02/16 09:38:37 | 000,000,830 | ---- | M] () -- C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2013/02/13 17:55:10 | 000,348,992 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2013/02/13 07:28:12 | 000,436,664 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2013/02/13 07:28:12 | 000,069,116 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2013/02/11 11:56:02 | 000,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1ce0891d19a575a.job
[2013/02/02 19:51:34 | 001,101,824 | ---- | M] () -- C:\Documents and Settings\Wester\My Documents\RECIPES11.accdb
[2013/02/02 19:51:10 | 001,101,824 | ---- | M] () -- C:\Documents and Settings\Wester\My Documents\RECIPES12.accdb
========== Files Created - No Company Name ==========
[2013/02/24 19:05:18 | 000,594,019 | ---- | C] () -- C:\Documents and Settings\Wester\Desktop\aaa.exe
[2013/02/23 20:12:12 | 000,694,288 | ---- | C] () -- C:\Documents and Settings\Wester\Desktop\HiJackThis.zip
[2013/02/12 14:25:33 | 000,002,347 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader XI.lnk
[2013/02/11 11:56:02 | 000,000,882 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore1ce0891d19a575a.job
[2012/12/26 10:43:35 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ViewNX2.INI
[2012/12/26 10:33:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Core Data Application
[2012/12/26 10:33:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Wester\Application Data\Configure Folder Actions
[2012/12/26 10:33:49 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLes.DAT
[2012/12/26 10:33:49 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\DirectoryService
[2012/12/26 10:32:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\CustomDataViews
[2012/12/26 10:32:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Contextual Menu Items
[2012/12/26 10:32:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Wester\Application Data\Console
[2012/12/26 10:32:49 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Wester\Application Data\Conditionals
[2012/12/26 10:32:49 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLev.DAT
[2012/12/26 10:32:49 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLet.DAT
[2012/12/26 10:32:49 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Distortion
[2012/12/26 10:32:20 | 000,000,268 | RH-- | C] () -- C:\Documents and Settings\Wester\Application Data\Devices
[2012/12/26 10:32:20 | 000,000,020 | -H-- | C] () -- C:\Documents and Settings\All Users\Application Data\PKP_DLeo.DAT
[2012/12/26 10:32:20 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Flange Saw
[2012/12/26 10:32:20 | 000,000,012 | RH-- | C] () -- C:\Documents and Settings\All Users\Application Data\Digital Light
[2011/12/10 17:17:38 | 000,001,170 | ---- | C] () -- C:\WINDOWS\checkip.dat
[2011/12/10 17:17:32 | 000,001,170 | ---- | C] () -- C:\WINDOWS\dhstatus.dat
[2011/12/10 17:13:07 | 000,000,894 | ---- | C] () -- C:\WINDOWS\ipconfig.dat
[2011/10/20 18:59:37 | 000,645,632 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2011/10/20 18:59:37 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2011/09/09 18:59:04 | 000,000,272 | ---- | C] () -- C:\Documents and Settings\Wester\Application Data\.backup.dm
[2011/09/09 06:53:43 | 000,042,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\EUBKMON.sys
[2011/08/04 14:37:37 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat
[2011/03/13 17:20:36 | 000,070,656 | ---- | C] () -- C:\Documents and Settings\Wester\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/04/28 07:36:02 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2009/12/19 14:40:25 | 000,004,986 | ---- | C] () -- C:\Documents and Settings\Wester\Application Data\wklnhst.dat
========== ZeroAccess Check ==========
[2010/10/05 12:47:40 | 000,000,227 | RHS- | M] () -- C:\WINDOWS\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shdocvw.dll -- [2008/04/13 16:12:05 | 001,499,136 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/02/09 04:10:48 | 000,473,600 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2008/04/13 16:12:08 | 000,273,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2012/03/25 12:14:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Affinegy
[2010/10/19 05:59:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2012/02/24 16:09:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/04/14 17:56:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Belkin
[2012/12/26 10:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\EnterNHelp
[2013/02/17 19:31:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2009/12/13 20:32:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FileCure
[2009/11/15 17:41:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IM
[2009/11/15 17:41:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IncrediMail
[2010/11/09 20:11:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\launcher
[2011/01/03 20:04:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Medtronic
[2012/12/26 13:35:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nikon
[2013/01/12 16:22:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Oberon Media
[2009/11/25 15:56:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Paragon
[2010/03/27 13:05:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2010/12/22 16:24:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Photo Notifier and Animation Creator
[2010/06/16 18:30:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PhotoMail
[2009/11/10 10:30:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sierra
[2011/04/10 14:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SpeedyPC
[2012/12/26 10:33:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ultima_T15
[2010/02/28 19:55:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2011/08/15 20:52:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42}
[2010/01/01 15:38:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/07/19 18:00:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\AMICAS
[2011/08/04 14:38:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\CheckPoint
[2013/02/23 08:08:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\ElevatedDiagnostics
[2011/08/19 19:01:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\GlarySoft
[2009/11/11 15:19:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\ieSpell
[2011/03/13 16:27:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Leadertech
[2012/12/26 10:40:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Nikon
[2013/01/12 16:22:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Oberon Media
[2013/02/22 18:14:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\PriceGong(2)
[2011/03/23 12:14:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Sierra
[2012/12/12 16:12:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Simple Adblock
[2009/12/19 14:40:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Template
[2010/01/09 06:21:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\Thunderbird
[2013/01/12 15:50:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\VideoBuzz
[2010/10/05 12:46:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\WeatherBug
[2010/02/13 13:29:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Wester\Application Data\WildTangent
========== Purity Check ==========
< End of report >