Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 7622
Windows 6.1.7601 Service Pack 1
Internet Explorer 8.0.7601.17514
11/29/2011 3:50:40 PM
mbam-log-2011-11-29 (15-50-40).txt
Scan type: Quick scan
Objects scanned: 179543
Time elapsed: 1 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL logfile created on: 11/29/2011 4:24:34 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Colin Ahern\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.93 Gb Total Physical Memory | 6.66 Gb Available Physical Memory | 84.08% Memory free
15.85 Gb Paging File | 14.51 Gb Available in Paging File | 91.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 174.66 Gb Total Space | 37.48 Gb Free Space | 21.46% Space Free | Partition Type: NTFS
Drive D: | 504.44 Gb Total Space | 443.92 Gb Free Space | 88.00% Space Free | Partition Type: NTFS
Drive E: | 5.10 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 74.50 Gb Total Space | 29.65 Gb Free Space | 39.80% Space Free | Partition Type: FAT32
Computer Name: CERBERUS | User Name: Colin Ahern | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Colin Ahern\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Windows\AsScrPro.exe (ASUS)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ASUS)
========== Modules (No Company Name) ==========
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (avast! Web Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:
64bit: - (avast! Mail Scanner) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:
64bit: - (avast! Antivirus) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:
64bit: - (AFBAgent) -- C:\Windows\SysNative\FBAgent.exe (ASUSTeK Computer Inc.)
SRV:
64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel(R) Corporation)
SRV:
64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (PnkBstrB) -- C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (Stereo Service) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (sftvsa) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ATKGFNEXSrv) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS)
SRV - (UNS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel(R) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (ASLDRService) -- C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (NVHDA) -- C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:
64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:
64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:
64bit: - (FLxHCIc) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIc.sys (Fresco Logic)
DRV:
64bit: - (FLxHCIh) Fresco Logic xHCI (USB3) -- C:\Windows\SysNative\drivers\FLxHCIh.sys (Fresco Logic)
DRV:
64bit: - (Sftvol) -- C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftredir) -- C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftplay) -- C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:
64bit: - (Sftfs) -- C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:
64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:
64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:
64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:
64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:
64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:
64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:
64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:
64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:
64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:
64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:
64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:
64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:
64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV:
64bit: - (btusbflt) -- C:\Windows\SysNative\drivers\btusbflt.sys (Broadcom Corporation.)
DRV:
64bit: - (MBfilt) -- C:\Windows\SysNative\drivers\MBfilt64.sys (Creative Technology Ltd.)
DRV:
64bit: - (HECIx64) Intel(R) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:
64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) -- C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:
64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (SiSGbeLH) -- C:\Windows\SysNative\drivers\SiSG664.sys (Silicon Integrated Systems Corp.)
DRV:
64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:
64bit: - (MTsensor) -- C:\Windows\SysNative\drivers\ATK64AMD.sys (ASUS)
DRV:
64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:
64bit: - (WimFltr) -- C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (HWiNFO32) -- C:\Program Files (x86)\HWiNFO32\HWiNFO64A.SYS (REALiX(tm))
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (ASMMAP64) -- C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys (ASUS)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://asus.msn.com
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://asus.msn.com
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3205341673-3714787834-18347199-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://asus.msn.com
IE - HKU\S-1-5-21-3205341673-3714787834-18347199-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://asus.msn.com
IE - HKU\S-1-5-21-3205341673-3714787834-18347199-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3205341673-3714787834-18347199-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "hotmail.com"
FF - prefs.js..extensions.enabledItems: {c0c9a2c7-2e5c-4447-bc53-97718bc91e1b}:3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170633FE}:0.4.5.15
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.1
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.10
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.86
FF - prefs.js..network.proxy.type: 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Colin Ahern\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\BYOND: C:\Program Files (x86)\BYOND\bin\npbyond.dll (BYOND)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/10 17:37:17 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/07/23 14:29:01 | 000,000,000 | ---D | M]
[2010/11/23 22:58:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Colin Ahern\AppData\Roaming\Mozilla\Extensions
[2011/11/12 11:38:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Colin Ahern\AppData\Roaming\Mozilla\Firefox\Profiles\b3yqkken.default\extensions
[2011/11/10 17:37:35 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Colin Ahern\AppData\Roaming\Mozilla\Firefox\Profiles\b3yqkken.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010/11/28 00:40:58 | 000,002,057 | ---- | M] () -- C:\Users\Colin Ahern\AppData\Roaming\Mozilla\Firefox\Profiles\b3yqkken.default\searchplugins\youtube-video-search.xml
[2011/11/10 17:37:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/02/12 13:13:45 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
() (No name found) -- C:\USERS\COLIN AHERN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3YQKKEN.DEFAULT\EXTENSIONS\{9AA46F4F-4DC7-4C06-97AF-5035170633FE}.XPI
() (No name found) -- C:\USERS\COLIN AHERN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3YQKKEN.DEFAULT\EXTENSIONS\{C0C9A2C7-2E5C-4447-BC53-97718BC91E1B}.XPI
() (No name found) -- C:\USERS\COLIN AHERN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3YQKKEN.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\COLIN AHERN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\B3YQKKEN.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
[2011/11/10 17:37:17 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2008/07/08 13:07:06 | 000,040,960 | ---- | M] (BYOND) -- C:\Program Files (x86)\mozilla firefox\plugins\npbyond.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/05/06 06:55:12 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/11/10 17:37:17 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:
64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2:
64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:
64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg64.dll (Google Inc.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:
64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3205341673-3714787834-18347199-1000..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer Networking Limited)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3205341673-3714787834-18347199-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 172.16.42.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{22C60620-3693-4DB7-B6D7-FD16290C125A}: DhcpNameServer = 172.16.42.1
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/10/06 07:01:16 | 000,000,044 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O33 - MountPoints2\{155ab4dd-cc45-11df-b102-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{155ab4dd-cc45-11df-b102-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe -- [2011/10/06 07:01:18 | 000,355,920 | R--- | M] (Valve Corporation)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/29 15:48:38 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\Malwarebytes
[2011/11/29 15:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/29 15:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/29 15:48:04 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/29 15:48:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/29 06:09:43 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Colin Ahern\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/29 06:09:43 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Colin Ahern\Desktop\OTL.exe
[2011/11/29 06:09:42 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\Colin Ahern\Desktop\aswMBR.exe
[2011/11/26 09:28:40 | 000,000,000 | ---D | C] -- C:\Windows\Options
[2011/11/26 09:28:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Atheros
[2011/11/26 09:28:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Atheros
[2011/11/26 09:28:06 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\Desktop\atheros_v9.2.0.105
[2011/11/25 22:35:24 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\Intel
[2011/11/25 22:34:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
[2011/11/25 22:34:10 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Intel
[2011/11/25 22:34:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Intel
[2011/11/25 22:34:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cisco
[2011/11/25 22:33:15 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\Desktop\WiFi_Intel_1000_Win7_64_Z132030
[2011/11/19 07:32:54 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/19 07:32:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ERUNT
[2011/11/19 07:32:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ERUNT
[2011/11/15 20:57:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO32
[2011/11/15 20:57:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HWiNFO32
[2011/11/12 22:32:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\E9F4B
[2011/11/12 22:32:40 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\2C6E9
[2011/11/12 22:32:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LP
[2011/11/12 22:32:32 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\l333pmmG5aQJdW8
[2011/11/12 22:32:26 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\QqqhhYXwwkV
[2011/11/12 22:32:25 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\KnnnGG4amH6sJ7E
[2011/11/12 22:32:18 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\lzzOONyyxA0vSib
[2011/11/12 22:32:17 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Roaming\dEEKK8gRRZhY
[2011/11/12 20:28:45 | 000,000,000 | ---D | C] -- C:\Users\Colin Ahern\AppData\Local\Skyrim
[1 C:\Users\Colin Ahern\AppData\Local\*.tmp files -> C:\Users\Colin Ahern\AppData\Local\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/29 16:19:25 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 16:19:25 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/29 16:12:11 | 000,045,056 | ---- | M] () -- C:\Windows\SysNative\acovcnt.exe
[2011/11/29 16:11:51 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/29 16:11:46 | 2087,997,439 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/29 15:48:07 | 000,001,111 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/29 15:47:43 | 000,000,512 | ---- | M] () -- C:\Users\Colin Ahern\Desktop\MBR.dat
[2011/11/29 06:08:08 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Colin Ahern\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/29 06:07:56 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Colin Ahern\Desktop\OTL.exe
[2011/11/29 06:07:42 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\Colin Ahern\Desktop\aswMBR.exe
[2011/11/28 18:31:49 | 001,233,600 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/28 18:31:49 | 000,331,648 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/28 18:31:49 | 000,006,616 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/25 22:18:58 | 050,049,747 | ---- | M] () -- C:\Users\Colin Ahern\Desktop\WiFi_Intel_1000_Win7_64_Z132030.zip
[2011/11/19 07:32:23 | 000,000,907 | ---- | M] () -- C:\Users\Colin Ahern\Desktop\ERUNT.lnk
[2011/11/16 19:17:09 | 000,001,823 | ---- | M] () -- C:\Users\Colin Ahern\Desktop\TESV.exe - Shortcut.lnk
[2011/11/11 16:02:54 | 000,000,606 | ---- | M] () -- C:\Users\Public\Desktop\World of Warcraft.lnk
[2011/11/11 10:21:22 | 000,275,352 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/10 17:37:38 | 000,002,050 | ---- | M] () -- C:\Users\Colin Ahern\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[1 C:\Users\Colin Ahern\AppData\Local\*.tmp files -> C:\Users\Colin Ahern\AppData\Local\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/29 15:48:07 | 000,001,111 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/29 15:47:43 | 000,000,512 | ---- | C] () -- C:\Users\Colin Ahern\Desktop\MBR.dat
[2011/11/25 22:33:09 | 050,049,747 | ---- | C] () -- C:\Users\Colin Ahern\Desktop\WiFi_Intel_1000_Win7_64_Z132030.zip
[2011/11/19 07:32:23 | 000,000,907 | ---- | C] () -- C:\Users\Colin Ahern\Desktop\ERUNT.lnk
[2011/11/16 19:17:09 | 000,001,823 | ---- | C] () -- C:\Users\Colin Ahern\Desktop\TESV.exe - Shortcut.lnk
[2011/07/04 00:32:18 | 000,003,584 | ---- | C] () -- C:\Users\Colin Ahern\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/28 01:35:00 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011/06/11 02:35:42 | 000,000,268 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/05/20 21:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/05/09 19:49:41 | 002,434,856 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/02/12 13:23:46 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2011/02/01 19:22:26 | 000,000,000 | ---- | C] () -- C:\Windows\McHmm.INI
[2011/01/21 22:15:12 | 000,215,128 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/01/21 22:15:11 | 000,669,184 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/01/21 22:15:11 | 000,075,064 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2010/12/26 07:59:33 | 000,006,598 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/09/29 20:02:01 | 000,001,200 | ---- | C] () -- C:\Windows\THXCfg_SP_APOIM.ini
[2010/09/29 20:02:01 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_HP_APOIM.ini
[2010/09/29 20:02:01 | 000,001,099 | ---- | C] () -- C:\Windows\THXCfg_APOIM.ini
[2010/09/29 20:01:59 | 000,181,760 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2010/09/29 20:01:59 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2010/09/29 19:30:38 | 000,131,368 | ---- | C] () -- C:\ProgramData\FullRemove.exe
[2010/02/08 23:07:38 | 000,020,480 | ---- | C] () -- C:\Windows\OOBEPlayer.exe
[2010/02/08 23:07:38 | 000,000,269 | ---- | C] () -- C:\Windows\OOBEPlayer.ini
[2009/10/25 19:38:22 | 000,000,176 | ---- | C] () -- C:\Windows\explorer.exe.config
[2009/07/28 21:20:40 | 000,000,010 | ---- | C] () -- C:\Windows\SysWow64\ABLKSR.ini
[2009/07/13 21:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 18:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 18:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 16:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 15:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 13:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 13:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/05/18 19:39:57 | 000,015,497 | ---- | C] () -- C:\Windows\snp2uvc.ini
[2005/08/30 00:00:00 | 000,781,312 | ---- | C] () -- C:\Windows\SysWow64\RGSS102J.dll
[2005/08/30 00:00:00 | 000,778,752 | ---- | C] () -- C:\Windows\SysWow64\RGSS102E.dll
[2005/08/30 00:00:00 | 000,771,584 | ---- | C] () -- C:\Windows\SysWow64\RGSS100J.dll
[2005/04/04 07:59:00 | 000,017,920 | ---- | C] () -- C:\Windows\SysWow64\implode.dll
[1997/06/13 16:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\iyvu9_32.dll
========== LOP Check ==========
[2011/10/17 21:24:01 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\.minecraft
[2011/11/12 11:28:03 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\.purple
[2011/11/12 22:32:40 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\2C6E9
[2011/09/10 23:13:25 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Amazon
[2011/03/14 19:26:17 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\AtomZombieDemoData
[2011/10/27 19:25:57 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Bioshock
[2011/11/29 06:04:34 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\BitTorrent
[2011/11/12 22:32:17 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\dEEKK8gRRZhY
[2011/09/09 19:50:37 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\gtk-2.0
[2011/11/28 18:07:05 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\IrfanView
[2011/03/14 20:33:38 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Kalypso Media
[2011/11/12 22:32:25 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\KnnnGG4amH6sJ7E
[2011/11/12 22:32:32 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\l333pmmG5aQJdW8
[2011/11/12 22:32:18 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\lzzOONyyxA0vSib
[2010/12/13 18:33:37 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Notepad++
[2011/11/12 22:32:26 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\QqqhhYXwwkV
[2011/05/26 10:42:57 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\RIFT
[2011/11/15 22:24:57 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\SoftGrid Client
[2011/09/30 21:02:55 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\SplitMediaLabs
[2011/01/16 21:44:48 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\SystemRequirementsLab
[2010/12/26 08:00:38 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\TP
[2011/03/05 22:07:58 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Ubisoft
[2011/03/20 20:29:56 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\Unity
[2011/03/21 21:42:35 | 000,000,000 | ---D | M] -- C:\Users\Colin Ahern\AppData\Roaming\WinterVoicesDemo
[2011/11/17 18:00:09 | 000,032,564 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >
There you have it in all it's glory.