OTL logfile created on: 31/10/2010 16:10:42 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Mads\Documents\Downloads\Programs
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.05 Gb Total Space | 119.62 Gb Free Space | 42.11% Space Free | Partition Type: NTFS
Computer Name: MADS-VAIO | User Name: Mads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/10/31 16:03:47 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mads\My Documents\Downloads\Programs\OTL.exe
PRC - [2010/10/13 00:11:42 | 004,258,136 | —- | M] (AOL Inc.) – C:\Program Files (x86)\AIM\aim.exe
PRC - [2010/09/27 09:40:10 | 003,804,912 | —- | M] (easy-hideip.com) – C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe
PRC - [2010/07/06 16:03:00 | 000,173,352 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/06 03:04:24 | 000,310,224 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
PRC - [2010/01/25 21:12:36 | 003,179,952 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2010/01/04 16:08:46 | 000,151,552 | —- | M] (ShaPlus Software) – C:\Program Files (x86)\ShaPlus Bandwidth Meter\ShaPlus Bandwidth Meter.exe
PRC - [2009/12/23 22:34:20 | 000,370,688 | —- | M] (StarWind Software) – C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
PRC - [2009/12/14 21:06:24 | 002,320,920 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2009/12/14 21:06:08 | 000,268,824 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2009/11/21 00:25:24 | 000,013,336 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2009/11/21 00:25:22 | 000,284,696 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2009/11/09 04:17:50 | 000,180,224 | —- | M] (PowerISO Computing, Inc.) – C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
PRC - [2009/10/15 10:51:51 | 000,263,600 | —- | M] (Tonec Inc.) – C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2009/09/25 19:57:38 | 000,245,248 | —- | M] () – C:\Program Files (x86)\AutoHotkey\AutoHotkey.exe
PRC - [2005/07/15 22:48:33 | 000,479,232 | —- | M] (Google Inc.) – C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe
========== Modules (SafeList) ==========
MOD - [2010/10/31 16:03:47 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Users\Mads\My Documents\Downloads\Programs\OTL.exe
MOD - [2010/08/21 06:21:32 | 001,680,896 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - File not found [On_Demand | Stopped] – C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper64.exe – (VcmXmlIfHelper)
SRV:
64bit: - [2010/09/30 16:51:32 | 000,036,160 | —- | M] (TuneUp Software) [Auto | Running] – C:\Windows\SysNative\uxtuneup.dll – (UxTuneUp)
SRV:
64bit: - [2010/08/08 16:57:08 | 000,099,048 | —- | M] (SANDBOXIE L.T.D) [Auto | Running] – C:\Program Files\Sandboxie\SbieSvc.exe – (SbieSvc)
SRV:
64bit: - [2010/03/25 22:48:42 | 000,017,424 | —- | M] (Microsoft Corporation) [Auto | Running] – c:\Program Files\Microsoft Security Essentials\MsMpEng.exe – (MsMpSvc)
SRV:
64bit: - [2009/11/30 20:51:18 | 000,571,248 | —- | M] (Sony Corporation) [On_Demand | Running] – C:\Program Files\Sony\VAIO Power Management\SPMService.exe – (VAIO Power Management)
SRV:
64bit: - [2009/11/25 20:06:06 | 000,821,760 | —- | M] (Sony Corporation) [Auto | Running] – C:\Program Files\Sony\VAIO Smart Network\VSNService.exe – (VSNService)
SRV:
64bit: - [2009/09/04 22:35:12 | 000,873,248 | —- | M] (Broadcom Corporation.) [Auto | Running] – C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe – (btwdins)
SRV:
64bit: - [2009/07/14 02:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/10/18 10:34:06 | 000,607,040 | —- | M] (TuneUp Software) [On_Demand | Stopped] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpDefragService.exe – (TuneUp.Defrag)
SRV - [2010/09/30 16:56:12 | 001,403,200 | —- | M] (TuneUp Software) [Auto | Running] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesService64.exe – (TuneUp.UtilitiesSvc)
SRV - [2010/09/30 16:51:26 | 000,030,016 | —- | M] (TuneUp Software) [Auto | Running] – C:\Windows\SysWOW64\uxtuneup.dll – (UxTuneUp)
SRV - [2010/09/29 19:02:11 | 002,950,744 | —- | M] () [Auto | Running] – C:/Program Files (x86)/Common Files/Akamai/netsession_win_062a651.dll – (Akamai)
SRV - [2010/07/06 16:03:00 | 000,173,352 | —- | M] (TeamViewer GmbH) [Auto | Running] – C:\Program Files (x86)\TeamViewer\Version5\TeamViewer_Service.exe – (TeamViewer5)
SRV - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/02 14:07:52 | 000,655,624 | —- | M] (Acresso Software Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/03/18 10:19:26 | 000,113,152 | —- | M] (ArcSoft Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe – (ACDaemon)
SRV - [2010/02/19 12:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/12/23 22:34:20 | 000,370,688 | —- | M] (StarWind Software) [Auto | Running] – C:\Program Files (x86)\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)
SRV - [2009/12/14 21:06:24 | 002,320,920 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe – (UNS) Intel®
SRV - [2009/12/14 21:06:08 | 000,268,824 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe – (LMS) Intel®
SRV - [2009/11/21 00:25:24 | 000,013,336 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe – (IAStorDataMgrSvc) Intel®
SRV - [2009/10/20 19:19:48 | 000,117,264 | —- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WinPcap\rpcapd.exe – (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009/06/17 10:18:42 | 006,582,912 | —- | M] () [On_Demand | Stopped] – c:\wamp\bin\mysql\mysql5.1.36\bin\mysqld.exe – (wampmysqld)
SRV - [2009/06/10 22:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/12/10 00:10:14 | 000,024,636 | —- | M] (Apache Software Foundation) [On_Demand | Stopped] – c:\wamp\bin\apache\apache2.2.11\bin\httpd.exe – (wampapache)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2010/08/08 17:03:24 | 000,143,464 | —- | M] (SANDBOXIE L.T.D) [Kernel | On_Demand | Running] – C:\Program Files\Sandboxie\SbieDrv.sys – (SbieDrv)
DRV:
64bit: - [2010/06/23 03:47:58 | 000,037,888 | —- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\taphss.sys – (taphss)
DRV:
64bit: - [2010/04/19 19:47:42 | 000,050,688 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\usbaapl64.sys – (USBAAPL64)
DRV:
64bit: - [2010/04/08 13:35:34 | 000,021,184 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\CPen.sys – (CPen)
DRV:
64bit: - [2010/03/15 00:22:32 | 000,834,544 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\sptd.sys – (sptd)
DRV:
64bit: - [2009/12/24 21:06:08 | 006,106,624 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\atikmdag.sys – (atikmdag)
DRV:
64bit: - [2009/12/16 21:03:59 | 000,244,736 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\IntcDAud.sys – (IntcDAud) Intel®
DRV:
64bit: - [2009/12/16 21:03:04 | 007,778,176 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\igdkmd64.sys – (igfx)
DRV:
64bit: - [2009/12/14 21:06:07 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\HECIx64.sys – (HECIx64) Intel®
DRV:
64bit: - [2009/11/21 00:09:48 | 000,537,112 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\iaStor.sys – (iaStor)
DRV:
64bit: - [2009/11/18 05:30:44 | 000,021,160 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwrchid.sys – (btwrchid)
DRV:
64bit: - [2009/11/18 05:30:32 | 000,132,648 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwavdt.sys – (btwavdt)
DRV:
64bit: - [2009/11/18 05:30:32 | 000,098,344 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwaudio.sys – (btwaudio)
DRV:
64bit: - [2009/11/18 05:30:21 | 000,052,264 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btusbflt.sys – (btusbflt)
DRV:
64bit: - [2009/11/18 05:23:46 | 000,035,104 | —- | M] (Broadcom Corporation.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\btwl2cap.sys – (btwl2cap)
DRV:
64bit: - [2009/11/13 21:08:21 | 000,151,936 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Impcd.sys – (Impcd)
DRV:
64bit: - [2009/11/12 21:16:19 | 000,395,264 | —- | M] () [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\yk62x64.sys – (yukonw7)
DRV:
64bit: - [2009/11/12 21:06:44 | 001,542,656 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\athrx.sys – (athr)
DRV:
64bit: - [2009/11/06 21:27:30 | 000,093,696 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\rimssne64.sys – (rimspci)
DRV:
64bit: - [2009/11/04 10:59:59 | 000,253,488 | —- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Apfiltr.sys – (ApfiltrService)
DRV:
64bit: - [2009/10/20 19:19:54 | 000,047,632 | —- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\npf.sys – (NPF)
DRV:
64bit: - [2009/09/15 21:09:08 | 000,075,776 | —- | M] (REDC) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\risdsne64.sys – (risdsnpe)
DRV:
64bit: - [2009/08/19 21:09:21 | 000,011,392 | —- | M] (Sony Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SFEP.sys – (SFEP)
DRV:
64bit: - [2009/07/14 02:52:21 | 000,106,576 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2009/07/14 02:52:21 | 000,028,752 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2009/07/14 02:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/14 02:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/14 02:47:48 | 000,077,888 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2009/07/14 02:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/07/14 00:31:10 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:
64bit: - [2009/06/10 21:38:56 | 000,000,308 | —- | M] () [File_System | On_Demand | Running] – C:\Windows\SysNative\wbem\ntfs.mof – (Ntfs)
DRV:
64bit: - [2009/06/10 21:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 21:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 21:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 21:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2009/05/18 12:17:08 | 000,034,152 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:
64bit: - [2008/03/13 08:46:00 | 000,027,136 | —- | M] (ManyCam LLC.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\ManyCam_x64.sys – (ManyCam)
DRV - [2010/02/24 13:41:50 | 000,011,856 | —- | M] (TuneUp Software) [Kernel | On_Demand | Running] – C:\Program Files (x86)\TuneUp Utilities 2010\TuneUpUtilitiesDriver64.sys – (TuneUpUtilitiesDrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.google.com/ig/redirectdomain?br…C&bmod;=EU01
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.danskebank.dk/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:6.9.1
FF - prefs.js..extensions.enabledItems: [removed]:1.6.1
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/09/29 14:51:36 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/10/31 00:45:08 | 000,000,000 | —D | M]
[2010/03/12 19:09:46 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Extensions
[2010/10/31 11:13:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions
[2010/09/18 21:42:47 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/08/14 13:08:23 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/09/16 17:30:37 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/10/31 11:13:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\extensions\[removed]
[2010/06/08 10:28:50 | 000,000,929 | —- | M] () – C:\Users\Mads\AppData\Roaming\Mozilla\Firefox\Profiles\rg6lgvnn.default\searchplugins\conduit.xml
[2010/03/14 23:23:19 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/03/14 23:23:19 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/29 14:51:30 | 000,001,525 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\amazon-co-uk.xml
[2010/09/29 14:51:30 | 000,001,178 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\wikipedia-da.xml
[2010/09/29 14:51:30 | 000,001,102 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\yahoo-dk.xml
O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Tonec Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [MSSE] c:\Program Files\Microsoft Security Essentials\msseces.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files (x86)\Google\Gmail Notifier\gnotify.exe (Google Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files (x86)\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)
O4 - HKLM..\Run: [ShaPlus Bandwidth Meter] File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Hide IP Easy] C:\Program Files (x86)\HideIPEasy\HideIPEasy.exe (easy-hideip.com)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - Startup: C:\Users\Mads\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Itunes_script.ahk ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:
64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:
64bit: - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8:
64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O9:
64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:
64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth; Device… - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375}
https://netbank.danskebank.dk/html/activex/…B/e-Safekey.cab (e-Safekey)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab (Minesweeper Flags Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18:
64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20 - Winlogon\Notify\VESWinlogon: DllName - VESWinlogon.dll - C:\Windows\SysWow64\VESWinlogon.dll (Sony Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{19515331-c367-11df-bd57-0024bebab327}\Shell - "" = AutoRun
O33 - MountPoints2\{19515331-c367-11df-bd57-0024bebab327}\Shell\AutoRun\command - "" = J:\Startme.exe – File not found
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autoplay.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:
64bit: UxTuneUp - C:\Windows\SysNative\uxtuneup.dll (TuneUp Software)
Drivers32:
64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.vorbis - C:\Windows\SysWow64\vorbis.acm (HMS
http://hp.vector.co.jp/authors/VA012897/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/10/31 11:22:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2010/10/31 00:45:33 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\acccore
[2010/10/31 00:45:31 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\AOL
[2010/10/31 00:45:31 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\AIM
[2010/10/31 00:45:26 | 000,000,000 | —D | C] – C:\ProgramData\AIM
[2010/10/31 00:45:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Software Update Utility
[2010/10/31 00:45:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIM
[2010/10/31 00:45:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\AOL
[2010/10/29 10:15:30 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\faktura assasins creed_files
[2010/10/27 21:43:53 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/10/27 15:43:53 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\Adobe Flash Professional CS5
[2010/10/26 22:19:08 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\Unity
[2010/10/26 22:16:33 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\Electronic Arts
[2010/10/26 18:19:30 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\ElevatedDiagnostics
[2010/10/24 18:38:50 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\film
[2010/10/24 17:18:00 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\HideIPEasy
[2010/10/24 17:18:00 | 000,000,000 | —D | C] – C:\ProgramData\HideIPEasy
[2010/10/24 17:17:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\HideIPEasy
[2010/10/24 16:28:28 | 000,061,440 | —- | C] (MagTek,Inc.) – C:\Windows\SysWow64\MTUSBHIDSwipe.ocx
[2010/10/24 16:28:27 | 000,000,000 | —D | C] – C:\Windows\SigPlus
[2010/10/20 02:08:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2010/10/20 02:05:27 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/10/18 10:34:19 | 000,034,624 | —- | C] (TuneUp Software) – C:\Windows\SysNative\TURegOpt.exe
[2010/10/18 10:34:12 | 000,036,160 | —- | C] (TuneUp Software) – C:\Windows\SysNative\uxtuneup.dll
[2010/10/18 10:34:12 | 000,030,016 | —- | C] (TuneUp Software) – C:\Windows\SysWow64\uxtuneup.dll
[2010/10/18 10:34:12 | 000,025,920 | —- | C] (TuneUp Software) – C:\Windows\SysNative\authuitu.dll
[2010/10/18 10:34:12 | 000,021,312 | —- | C] (TuneUp Software) – C:\Windows\SysWow64\authuitu.dll
[2010/10/18 10:33:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\TuneUp Utilities 2010
[2010/10/18 10:13:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Antimalware
[2010/10/18 10:13:14 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Essentials
[2010/10/16 13:48:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Fusion
[2010/10/16 00:09:57 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\PlayStation 3
[2010/10/16 00:09:29 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Roaming\Nero
[2010/10/16 00:09:25 | 000,000,000 | —D | C] – C:\Users\Mads\AppData\Local\Nero
[2010/10/16 00:04:23 | 000,000,000 | —D | C] – C:\ProgramData\Nero
[2010/10/16 00:04:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Nero
[2010/10/16 00:02:07 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\Nero MediaHome 4 Essentials
[2010/10/15 23:51:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\ShaPlus Bandwidth Meter
[2010/10/15 23:50:56 | 000,000,000 | —D | C] – C:\Users\Mads\Desktop\11w
[2010/10/12 10:12:24 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ordbog
[2010/10/03 13:16:33 | 000,000,000 | —D | C] – C:\Users\Mads\.oces
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/10/31 15:48:14 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/10/31 11:43:54 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 11:43:54 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/10/31 11:22:44 | 000,002,971 | —- | M] () – C:\Users\Mads\Desktop\HiJackThis.lnk
[2010/10/31 00:45:31 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2010/10/31 00:45:26 | 000,001,941 | —- | M] () – C:\Users\Mads\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2010/10/31 00:45:25 | 000,001,917 | —- | M] () – C:\Users\Public\Desktop\AIM.lnk
[2010/10/30 20:59:30 | 2955,485,184 | -HS- | M] () – C:\hiberfil.sys
[2010/10/29 10:38:09 | 000,727,362 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/10/29 10:38:09 | 000,615,958 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/10/29 10:38:09 | 000,107,594 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/10/29 10:30:58 | 000,011,811 | —- | M] () – C:\Users\Mads\Desktop\Kildelæsning.docx
[2010/10/29 10:30:58 | 000,000,162 | -H– | M] () – C:\Users\Mads\Desktop\~$ldelæsning.docx
[2010/10/29 10:15:31 | 000,041,849 | —- | M] () – C:\Users\Mads\Desktop\faktura assasins creed.htm
[2010/10/24 17:17:56 | 000,001,035 | —- | M] () – C:\Users\Public\Desktop\Hide IP Easy.lnk
[2010/10/24 16:29:19 | 000,000,981 | —- | M] () – C:\Users\Mads\Desktop\SigCard1Client.lnk
[2010/10/18 10:34:05 | 000,002,181 | —- | M] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2010/10/18 10:34:05 | 000,002,163 | —- | M] () – C:\Users\Public\Desktop\TuneUp Utilities.lnk
[2010/10/18 10:13:15 | 000,001,023 | —- | M] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/16 13:48:25 | 000,001,150 | —- | M] () – C:\Users\Mads\Desktop\FUSION WOL.lnk
[2010/10/13 02:19:43 | 003,118,320 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/10/07 11:40:13 | 000,000,000 | —- | M] () – C:\Users\Mads\temp.dat
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/10/31 11:22:44 | 000,002,971 | —- | C] () – C:\Users\Mads\Desktop\HiJackThis.lnk
[2010/10/31 00:45:26 | 000,001,941 | —- | C] () – C:\Users\Mads\Application Data\Microsoft\Internet Explorer\Quick Launch\AIM.lnk
[2010/10/31 00:45:25 | 000,001,917 | —- | C] () – C:\Users\Public\Desktop\AIM.lnk
[2010/10/31 00:44:50 | 000,000,362 | -H– | C] () – C:\IPH.PH
[2010/10/29 10:30:58 | 000,011,811 | —- | C] () – C:\Users\Mads\Desktop\Kildelæsning.docx
[2010/10/29 10:30:58 | 000,000,162 | -H– | C] () – C:\Users\Mads\Desktop\~$ldelæsning.docx
[2010/10/29 10:15:30 | 000,041,849 | —- | C] () – C:\Users\Mads\Desktop\faktura assasins creed.htm
[2010/10/27 19:54:40 | 000,173,535 | —- | C] () – C:\Users\Mads\Desktop\Super.High.Me.2007.DVDRip.XviD-NODLABS.srt
[2010/10/27 19:52:01 | 733,888,512 | —- | C] () – C:\Users\Mads\Desktop\Super.High.Me.2007.DVDRip.XviD-NODLABS.avi
[2010/10/24 17:17:56 | 000,001,035 | —- | C] () – C:\Users\Public\Desktop\Hide IP Easy.lnk
[2010/10/24 16:29:19 | 000,000,981 | —- | C] () – C:\Users\Mads\Desktop\SigCard1Client.lnk
[2010/10/18 10:34:05 | 000,002,181 | —- | C] () – C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2010/10/18 10:34:05 | 000,002,163 | —- | C] () – C:\Users\Public\Desktop\TuneUp Utilities.lnk
[2010/10/18 10:13:15 | 000,001,023 | —- | C] () – C:\Users\Public\Desktop\Microsoft Security Essentials.lnk
[2010/10/16 13:48:25 | 000,001,150 | —- | C] () – C:\Users\Mads\Desktop\FUSION WOL.lnk
[2010/10/03 13:16:34 | 000,000,000 | —- | C] () – C:\Users\Mads\temp.dat
[2010/10/02 15:33:31 | 482,878,739 | —- | C] () – C:\Users\Mads\Desktop\Half.Baked.1998.m720p.ManO.mkv
[2010/09/29 13:35:40 | 000,230,752 | —- | C] () – C:\Windows\patchw32.dll
[2010/09/29 13:35:40 | 000,118,176 | —- | C] () – C:\Windows\patchw.dll
[2010/09/19 00:36:49 | 000,000,090 | —- | C] () – C:\Windows\WININIT.INI
[2010/09/18 21:23:43 | 000,001,282 | —- | C] () – C:\Windows\Sandboxie.ini
[2010/09/01 10:26:29 | 000,000,132 | —- | C] () – C:\Users\Mads\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/07/27 23:25:02 | 000,000,092 | —- | C] () – C:\Users\Mads\AppData\Local\fusioncache.dat
[2010/03/17 08:04:31 | 000,735,290 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/03/16 13:19:54 | 000,000,207 | —- | C] () – C:\Windows\Ic32.ini
[2010/03/15 00:45:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/14 16:50:09 | 000,000,000 | —- | C] () – C:\Users\Mads\AppData\Roaming\chrtmp
[2009/12/26 01:43:03 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2009/12/26 01:43:03 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2009/10/20 19:19:30 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2009/07/14 00:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2007/04/27 09:43:58 | 000,120,200 | —- | C] () – C:\Windows\SysWow64\DLLDEV32i.dll
========== LOP Check ==========
[2010/10/31 00:47:39 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\acccore
[2010/09/03 11:43:19 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\C Technologies
[2010/10/30 21:00:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\DMCache
[2010/10/26 22:16:33 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Electronic Arts
[2010/10/24 17:18:00 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\HideIPEasy
[2010/09/29 13:37:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\IDM
[2010/07/21 02:02:56 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Leadertech
[2010/09/01 09:09:52 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\MAGIX
[2010/05/08 18:35:29 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\ManyCam
[2010/04/15 09:02:55 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\OpenCandy
[2010/09/19 00:34:22 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\phpDesigner
[2010/04/13 07:42:47 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\Red Kawa
[2010/08/14 20:20:46 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\TeamViewer
[2010/04/04 21:48:21 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\The Creative Assembly
[2010/09/18 21:31:13 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\TuneUp Software
[2010/09/19 13:07:42 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\uTorrent
[2010/03/15 12:34:25 | 000,000,000 | —D | M] – C:\Users\Mads\AppData\Roaming\VitySoft
[2010/08/23 14:19:59 | 000,032,656 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/09 14:44:29 | 000,608,256 | —- | M] () – C:\blackra1n.exe
[2010/04/09 14:57:36 | 000,000,000 | —- | M] () – C:\blackra1n.log
[2010/10/30 20:59:30 | 2955,485,184 | -HS- | M] () – C:\hiberfil.sys
[2010/10/31 00:45:31 | 000,000,362 | -H– | M] () – C:\IPH.PH
[2000/10/30 12:04:06 | 000,045,936 | —- | M] (LEAD Technologies, Inc.) – C:\ltvdd10w.drv
[2010/01/23 06:03:59 | 000,305,864 | —- | M] () – C:\lv.log
[2010/10/30 20:59:35 | 3940,651,008 | -HS- | M] () – C:\pagefile.sys
[2000/10/30 12:04:08 | 000,029,184 | —- | M] (Blue Sky Software) – C:\Popup.ocx
[2010/01/23 06:00:19 | 000,002,269 | —- | M] () – C:\RHDSetup.log
[2010/01/23 06:03:54 | 000,000,073 | -H– | M] () – C:\splash.idx
[2009/12/15 12:53:48 | 000,003,872 | -H– | M] () – C:\version
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 31/10/2010 16:10:42 - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Users\Mads\Documents\Downloads\Programs
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: Denmark | Language: DAN | Date Format: dd-MM-yyyy
4.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 61.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 284.05 Gb Total Space | 119.62 Gb Free Space | 42.11% Space Free | Partition Type: NTFS
Computer Name: MADS-VAIO | User Name: Mads | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url [@ = InternetShortcut] – C:\Windows\System32\ieframe.DLL (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{26A24AE4-039D-4CA4-87B4-2F86416016FF}" = Java™ 6 Update 16 (64-bit)
"{328CC232-CFDC-468B-A214-2E21300E4CB5}" = Apple Mobile Device Support
"{6522F10D-3EB1-4FF4-8758-ABFB227CD8B5}" = Microsoft Antimalware Service DA-DK Language Pack
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8F790958-2107-48F2-88E0-B352A0C225AB}" = iTunes
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95C9C76F-ECF3-40FA-94F8-5DDFB6BAF40D}" = Microsoft Security Essentials
"{9E9D49A4-1DF4-4138-B7DB-5D87A893088E}" = WIDCOMM Bluetooth Software
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Alps Pointing-device for VAIO
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}" = Bonjour
"{E62A1F01-07B7-4541-A835-EE5B0BF064C2}" = Microsoft Antimalware
"3BA80AB4C7E9F8497C115C844953A3D4BEB84D21" = Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800)
"930E4792BDAEAFB62A9514EE7578775658A5D07C" = Windows Driver Package - Broadcom Bluetooth (09/09/2009 6.2.0.9405)
"CD890B33C151F0A9940A3982594354969B729745" = Windows Driver Package - C Technologies AB (CPen) Input Pen (02/22/2010 3.0.0.2)
"Defraggler" = Defraggler
"Microsoft Security Essentials" = Microsoft Security Essentials
"Sandboxie" = Sandboxie 3.47.04 (64-bit)
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}" = Microsoft Games for Windows - LIVE Redistributable
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"{0899D75A-C2FC-42EA-A702-5B9A5F24EAD5}" = VAIO Smart Network
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{121C477C-5B7B-44E3-B621-BDDB542AE8FD}" = TuneUp Utilities Language Pack (en-GB)
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16C315AA-1027-4530-92E1-C47CA832E330}" = Xara Designer Pro 6 Content Pack
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1D13459A-B743-46D8-B1D7-BECAC7ED4C17}" = Fists of Fu
"{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java™ 6 Update 17
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}" = Microsoft Games for Windows - LIVE
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{34DC654E-6E43-4BFA-9E00-6C16CFA7B9F0}" = VAIO Data Restore Tool
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{411F3ABA-2AB5-4799-AA19-6ADF0A8F7424}" = Adobe Setup
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4BE09A97-FEA8-4ACA-8684-C0F8CF418034}" = Fists of Fu
"{57B955CE-B5D3-495D-AF1B-FAEE0540BFEF}" = VAIO Data Restore Tool
"{5E22DF13-BF77-4E88-9BC1-8367FE35DE6F}" = C-Pen Core
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6E9EF98E-259E-416D-B5F8-0ABDB99942CE}" = Adobe Flash Player 10 ActiveX
"{70991E0A-1108-437E-BA7D-085702C670C0}" =
"{72042FA6-5609-489F-A8EA-3C2DD650F667}" = VAIO Control Center
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{803E4FA5-A940-4420-B89D-A8BC2E160247}" = VAIO Power Management
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{931FE23C-BB40-4C7A-A594-DB35908D8E83}" = VAIO Quick Web Access
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96D0B6C6-5A72-4B47-8583-A87E55F5FE81}" =
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DA53D22-D922-494C-B1D7-51CD9BCB9E4A}" = VAIO Hardware Diagnostics
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A63E7492-A0BC-4BB9-89A7-352965222380}" = VAIO Original Function Settings
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7C30414-2382-4086-B0D6-01A88ABA21C3}" = VAIO Gate
"{A7DA438C-2E43-4C20-BFDA-C1F4A6208558}" = Setting Utility Series
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.4
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support
"{B7546697-2A80-4256-A24B-1C33163F535B}" = VAIO Gate Default
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BC41C09D-FAA9-4346-9FE6-1E0017BC551A}" = Adobe Flash Player 10 Plugin
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{C066286F-E002-46C0-9DFD-2DCB9A2B7A99}_is1" = iLiberty+ 1.3.0 Build 113
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C7163400-6A4A-467E-A31B-3841C33F6F5D}" = Xara Designer Pro 6
"{C79312BD-3E76-4474-A10C-1435D1856A4B}" = Adobe Dreamweaver CS5
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CFC9F871-7C40-40B6-BE4A-B98A5B309716}" = Adobe Flash Professional CS5
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.3.22 Game
"{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}" = TuneUp Utilities
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{D7BF3B76-EEF9-4868-9B2B-42ABF60B279A}" = Microsoft_VC80_CRT_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DACFD753-491E-4BC4-95A0-A49D05475FF6}" = TI Interactive!
"{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}" = ArcSoft WebCam Companion 3
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{EE18E5E3-9929-4A7C-AA08-E0AEC2FEA75C}" = Air Mouse Server
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Graphics Media Accelerator Driver
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1432614-6183-49E6-98E8-674485463CFE}" = VAIO Original Function Settings
"{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{FB77DB0C-6951-47B6-9D80-A0FDBEE0334C}" =
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe_3dcb365ab9e01871fb8c6f27b0ea079" = Adobe After Effects CS4
"AIM_7" = AIM 7
"Akamai" = Akamai NetSession Interface
"AutoHotkey" = AutoHotkey 1.0.48.05
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"ENTERPRISE" = Microsoft Office Enterprise 2007
"FUSION WOL_is1" = FUSION WOL v1.0
"Garena" = Garena 2010
"HideIPEasy" = Hide IP Easy
"InstallShield_{06F80017-8F98-4C94-B868-52358569FC32}" = Command & Conquer Generals
"InstallShield_{F3E9C243-122E-4D6B-ACC1-E1FEC02F6CA1}" = Command and ConquerTM Generals Zero Hour
"Internet Download Manager" = Internet Download Manager
"MAGIX_MSI_XtremePro6" = Xara Designer Pro 6
"Mozilla Firefox (3.6.10)" = Mozilla Firefox (3.6.10)
"OpenAL" = OpenAL
"PowerISO" = PowerISO
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"splashtop" = VAIO Quick Web Access
"TeamViewer 5" = TeamViewer 5
"Tekken 3" = Tekken 3
"Topaz SigCard1 MSR ActiveX" = Topaz SigCard1 MSR ActiveX
"TuneUp Utilities" = TuneUp Utilities
"uTorrent" = µTorrent
"VAIO Help and Support" =
"VAIO Premium Partners" = VAIO Premium Partners
"Videora iPod Converter" = Videora iPod Converter 5.04
"VLC Connection Utility_is1" = VLC Connection Utility 2.60
"VLC media player" = VLC media player 1.0.5
"WampServer 2_is1" = WampServer 2.0
"Warcraft III" = Warcraft III
"WinPcapInst" = WinPcap 4.1.1
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"EA SPORTS Game Face Browser Plugin" = EA SPORTS Game Face Browser Plugin 1.0.0.18
"UnityWebPlayer" = Unity Web Player
"Warcraft III" = Warcraft III: All Products
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 16/10/2010 12:56:39 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 5054
Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 6068
Error - 16/10/2010 12:56:40 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 6068
Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1076
Error - 17/10/2010 17:13:51 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1076
Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 39470780
Error - 18/10/2010 04:11:41 | Computer Name = Mads-VAIO | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 39470780
[ System Events ]
Error - 18/10/2010 04:55:46 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 10:54:29 on ?18-?10-?2010 was unexpected.
Error - 18/10/2010 04:55:59 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2
Error - 18/10/2010 05:11:13 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2
Error - 18/10/2010 05:34:18 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The TuneUp Theme Extension service failed to start due to the following
error: %%1083
Error - 18/10/2010 05:58:14 | Computer Name = Mads-VAIO | Source = volsnap | ID = 393230
Description = The shadow copies of volume C: were aborted because of an IO failure
on volume C:.
Error - 18/10/2010 09:28:16 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 15:26:56 on ?18-?10-?2010 was unexpected.
Error - 18/10/2010 09:28:25 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2
Error - 18/10/2010 09:48:41 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 15:47:05 on ?18-?10-?2010 was unexpected.
Error - 18/10/2010 09:48:41 | Computer Name = Mads-VAIO | Source = Service Control Manager | ID = 7000
Description = The MySQL service failed to start due to the following error: %%2
Error - 18/10/2010 10:25:17 | Computer Name = Mads-VAIO | Source = EventLog | ID = 6008
Description = The previous system shutdown at 16:01:28 on ?18-?10-?2010 was unexpected.
[ TuneUp Events ]
Error - 18/10/2010 14:33:40 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 18/10/2010 15:39:26 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
Error - 29/10/2010 07:09:21 | Computer Name = Mads-VAIO | Source = TuneUp.UtilitiesSvc | ID = 300
Description =
< End of report >
GMER 1.0.15.15477 -
http://www.gmer.net
Rootkit scan 2010-10-31 16:57:20
Windows 6.1.7600
Running: gmer.exe
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0c6076a27b49
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC7 0x8F 0xE7 0x53 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x25 0x7E 0x0D 0x57 …
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xB2 0x4E 0x41 0x35 …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0c6076a27b49 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@p0 C:\Program Files (x86)\Alcohol Soft\Alcohol 52\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04@ujdew 0xC7 0x8F 0xE7 0x53 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@a0 0x20 0x01 0x00 0x00 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001@ujdew 0x25 0x7E 0x0D 0x57 …
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04\00000001\jdgg40@ujdew 0xB2 0x4E 0x41 0x35 …
—- EOF - GMER 1.0.15 —-