This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

www.juego.com/

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Suddenly when I use favorites in Firefox one of the tabs opens www.juego.com/
I cannot figure out where it is coming from.

OTL logfile created on: 09/14/2011 03:16:21 PM - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\silat\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

5.99 Gb Total Physical Memory | 2.97 Gb Available Physical Memory | 49.62% Memory free
11.98 Gb Paging File | 9.31 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 517.81 Gb Free Space | 86.86% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 416.36 Gb Free Space | 44.70% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 409.52 Gb Free Space | 43.96% Space Free | Partition Type: NTFS

Computer Name: BLACKHOLE | User Name: silat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\silat\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\SystemExplorer Portable\SystemExplorer.exe (Mister Group)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\VueSoft\VueMinder\VueMinder.exe (VueSoft)
PRC - C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Siber Systems)
PRC - C:\Program Files (x86)\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
PRC - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\Divvy.exe (Mizage LLC)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Returnil\RSS\rvsgui.exe (CJSC Returnil Software)
PRC - C:\Program Files (x86)\Returnil\RSS\rvsmon.exe (CJSC Returnil Software)
PRC - C:\Program Files (x86)\Zentimo\Zentimo.exe (Crystal Rich Ltd)
PRC - C:\Windows\SysWOW64\vsnapvss.exe (StorageCraft Technology Corporation)
PRC - C:\Program Files (x86)\StorageCraft\ShadowProtect\ShadowProtect.exe (StorageCraft Technology Corporation)
PRC - C:\Program Files (x86)\StorageCraft\ShadowProtect\ShadowProtectSvc.exe (StorageCraft Technology Corporation)
PRC - C:\Program Files (x86)\FastStoneCapture\FSCapture.exe (FastStone Soft)
PRC - C:\Program Files (x86)\Flashnote\Flashnote-portable.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
PRC - E:\Downloads 1\Internet Utilities\Networx\networx.exe (SoftPerfect Research)
PRC - C:\Program Files (x86)\Winstep\WsxService.exe (Winstep Software Technologies)
PRC - C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\Program Files (x86)\Kensington TrackballWorks\KTbWorks.exe (Kensington Computer Products Group)
PRC - C:\Program Files (x86)\Kensington TrackballWorks\KTbWorksS.exe (Kensington Computer Products Group)
PRC - C:\Program Files (x86)\WordWeb\wweb32.exe (WordWeb Software)
PRC - C:\Program Files (x86)\PowerStrip\PStrip.exe (EnTech Taiwan)
PRC - C:\Program Files (x86)\Conceptworld\NoteZilla\NoteZilla.exe (Conceptworld Corporation)
PRC - C:\Windows\SysWOW64\HsMgr.exe ()
PRC - C:\Program Files (x86)\RocketDock\RocketDock.exe ()
PRC - C:\Program Files (x86)\DeskPins\DeskPins.exe (Elias Fotinis)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\GAC\Microsoft.Office.Interop.Outlook\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Outlook.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\ICSharpCode.SharpZi#\43d6caf1a345c679d7e0bb6593646143\ICSharpCode.SharpZipLib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\SecurityManager.2005\a4bc79ba6bc4e451faf33da21509e209\SecurityManager.2005.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.A#\caed5d8c9f85e6304c75036849c0d8b2\Infragistics2.Win.AppStylistSupport.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\76bfbc0ce09ed692b2c23b615fa07ddf\Infragistics2.Win.UltraWinSpellChecker.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Client\ed342fc2eff721561c887982a1107a35\Google.GData.Client.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Google.GData.Calend#\30baa7d05cae39f297f6f22a38cd987b\Google.GData.Calendar.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\4d92715985b91ddd1e7cd6576f0f921c\Infragistics2.Win.UltraWinTree.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.S#\6793cb16ed8c337d994fd18497db2316\Infragistics2.Win.SupportDialogs.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\70adf9f685bbc3763bdf56927221662a\Infragistics2.Win.UltraWinDock.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\1824ede5bc9505375a9e04c6e398f564\Infragistics2.Win.UltraWinGrid.ExcelExport.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\DDay.iCal\1fd6fd0477f38bd6cab9b22dcad4e338\DDay.iCal.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\7f84291412836227e3a25348fc1b95b6\Infragistics2.Win.UltraWinDataSource.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Vuesoft.Application#\45fdbf5dc5b751287cfab27e9190f3f2\Vuesoft.Applications.Vueminder.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\protobuf-net\a1c7ee3e871073cecad973c6af40da51\protobuf-net.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\27568620173d28fec3a1a3c8bcc4c474\Infragistics2.Win.UltraWinListView.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\1d6872c9f618234de7fd538a6d783c3f\Infragistics2.Win.UltraWinGauge.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\b6be26537e4d830c1de646b6845e4cfa\Infragistics2.Win.UltraWinTabbedMdi.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\65b97db2e2ab494e3ed0f432d649abf7\Infragistics2.Win.UltraWinGrid.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\3cfdea79b9d11da22b65dd9bbf0cb649\Infragistics2.Win.UltraWinToolbars.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\3c4a2779672c20622188f357fd1b8b28\Infragistics2.Win.UltraWinTabControl.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\43f26d389d001b8853f35082c648b3fd\Infragistics2.Win.UltraWinStatusBar.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\ea26942967a9441cbcc841c1d2a1b672\Infragistics2.Win.UltraWinEditors.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.M#\512578f09249921041a3c236f621e124\Infragistics2.Win.Misc.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.U#\bdfd6911e2fe55dbedc97e2acf0bc194\Infragistics2.Win.UltraWinSchedule.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Win.v#\b124254efe037192dc38a6df948c2320\Infragistics2.Win.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Infragistics2.Share#\6e138560378916b4d4a98f384dfd785a\Infragistics2.Shared.v10.1.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Speech\b49029aa87036bc216f7ffe095d0e97c\System.Speech.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\dc851eb6cb72e5c1cd919af309a07023\WindowsFormsIntegration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\5914966008346d5e9341ba1f9d6d2760\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\6fe7fb2d0b04dbe5c8c5c7a62c0e2720\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\60aa01ac9637903f30ac346c55ce58bb\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\86f429e0a23238cf277d464bd0433d86\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\ad9c2f4737e1e07fa774af31a7d74235\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\462ca53f84ff85f159d5555d91a5e28d\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\69eae47315bb993ef0d3a92ddb0c8671\System.Runtime.Serialization.Formatters.Soap.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eba4ec48e3f7f16864c6d96f510fafd9\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\808e41877f992187276492aa2e55e909\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\cea5d9b8e3d6ff3bf3be32cf5fcbcd02\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\21cc2572fbb5a3a7e0ef085d7bf27eca\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\155679a9c8991cc33f90d6b27bac1977\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\0bddc91cbf37d143f08f6684b2919566\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\610374fef100556da252243e673ac64b\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\2e8bbdf2a971ffe1ba403c620989954c\CustomMarshalers.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Accessibility\5c6e1a094b1e65c69b528151cc19b1ee\Accessibility.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\23bc3936180ff789f44259a211dfc7fc\mscorlib.ni.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\divvywidgets.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\QtCore4.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\QtSql4.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\QtNetwork4.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\QtGui4.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\plugins\sqldrivers\qsqlite4.dll ()
MOD - C:\Users\silat\AppData\Local\Mizage LLC\Divvy\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Flashnote\Flashnote-portable.exe ()
MOD - C:\Program Files (x86)\Adobe\Acrobat 10.0\PDFMaker\Common\AdobePDFMakerX.dll ()
MOD - C:\Program Files (x86)\Flashnote\sqlite3.dll ()
MOD - E:\Downloads 1\Internet Utilities\Networx\sqlite.dll ()
MOD - C:\Program Files (x86)\RocketDock\Docklets\StackDocklet\StackDocklet.dll ()
MOD - C:\Program Files (x86)\WordWeb\WUCNT.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Windows\SysWOW64\HsMgr.exe ()
MOD - C:\Program Files (x86)\RocketDock\RocketDock.exe ()
MOD - C:\Program Files (x86)\RocketDock\RocketDock.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office12\OUTLCTL.DLL ()
MOD - C:\Program Files (x86)\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files (x86)\Conceptworld\NoteZilla\sqlite3.dll ()
MOD - C:\Program Files (x86)\Conceptworld\NoteZilla\zlib.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV:64bit: - (!SASCORE) – C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE (SUPERAntiSpyware.com)
SRV:64bit: - (LBTServ) – C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV:64bit: - (PDAgent) – C:\Program Files\Raxco\PerfectDisk\PDAgent.exe (Raxco Software, Inc.)
SRV:64bit: - (PDEngine) – C:\Program Files\Raxco\PerfectDisk\PDEngine.exe (Raxco Software, Inc.)
SRV:64bit: - (WinVNC4) – C:\Program Files\RealVNC\VNC4\WinVNC4.exe (RealVNC Ltd)
SRV:64bit: - (TurboBoost) – C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (SandraAgentSrv) – C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2010\RpcAgentSrv.exe (SiSoftware)
SRV - (TeamViewer6) – C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (RVSMONBL) – C:\Program Files (x86)\Returnil\RSS\rvsmon.exe (CJSC Returnil Software)
SRV - (ZentimoService) – C:\Program Files (x86)\Zentimo\ZentimoService.exe ()
SRV - (VSNAPVSS) – C:\Windows\SysWOW64\vsnapvss.exe (StorageCraft Technology Corporation)
SRV - (ShadowProtectSvc) – C:\Program Files (x86)\StorageCraft\ShadowProtect\ShadowProtectSvc.exe (StorageCraft Technology Corporation)
SRV - (CLHNServiceForPowerDVD) – C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\CLHNServiceForPowerDVD.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (CyberLink PowerDVD 11.0 Service) – C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSServer.exe (CyberLink)
SRV - (CyberLink PowerDVD 11.0 Monitor Service) – C:\Program Files (x86)\CyberLink\PowerDVD11\Common\MediaServer\CLMSMonitorService.exe (CyberLink)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator.exe (VMware, Inc.)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Winstep Xtreme Service) – C:\Program Files (x86)\Winstep\WsxService.exe (Winstep Software Technologies)
SRV - (nlsX86cc) – C:\Windows\SysWOW64\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (ufad-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-ufad.exe (VMware, Inc.)
SRV - (KTbWorksService) – C:\Program Files (x86)\Kensington TrackballWorks\KTbWorksS.exe (Kensington Computer Products Group)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files (x86)\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\drivers\aswRdr.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV:64bit: - (DbusAudio) – C:\Windows\SysNative\drivers\DbusAudio.sys (Windows ® Codename Longhorn DDK provider)
DRV:64bit: - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (rvsystem) – C:\Windows\SysNative\drivers\rvsystem.sys (CJSC Returnil Software)
DRV:64bit: - (sbmount) – C:\Windows\SysNative\drivers\sbmount.sys (StorageCraft Technology Corporation)
DRV:64bit: - (stcvsm) – C:\Windows\SysNative\drivers\stcvsm.sys (StorageCraft Technology Corporation)
DRV:64bit: - (rvsmonn) – C:\Windows\SysNative\drivers\rvsmonn2.sys (CJSC Returnil Software)
DRV:64bit: - (rvseng) – C:\Windows\SysNative\drivers\rvseng.sys (CJSC Returnil Software)
DRV:64bit: - (rvsmonf) – C:\Windows\SysNative\drivers\rvsmonf.sys (CJSC Returnil Software)
DRV:64bit: - (rvsmon) – C:\Windows\SysNative\drivers\rvsmon.sys (CJSC Returnil Software)
DRV:64bit: - (LHidFilt) – C:\Windows\SysNative\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LMouFilt) – C:\Windows\SysNative\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV:64bit: - (LVUVC64) Logitech HD Pro Webcam C910(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (CompFilter64) – C:\Windows\SysNative\drivers\lvbflt64.sys (Logitech Inc.)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (vmkbd) – C:\Windows\SysNative\drivers\VMkbd.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (vncmirror) – C:\Windows\SysNative\drivers\vncmirror.sys (RealVNC Ltd.)
DRV:64bit: - (ntcdrdrv) – C:\Windows\SysNative\drivers\ntcdrdrv.sys (NoteBurn Software)
DRV:64bit: - (DefragFS) – C:\Windows\SysNative\drivers\DefragFs.sys (Raxco Software, Inc.)
DRV:64bit: - (HMuKstE) – C:\Windows\SysNative\drivers\HMuKstE.sys (Dritek System Inc.)
DRV:64bit: - (ScreamBAudioSvc) – C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC)
DRV:64bit: - (Revoflt) – C:\Windows\SysNative\drivers\revoflt.sys (VS Revo Group)
DRV:64bit: - (TurboB) – C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies, Inc.)
DRV:64bit: - (cmudaxp) – C:\Windows\SysNative\drivers\cmudaxp.sys (C-Media Inc)
DRV:64bit: - (SANDRA) – C:\Program Files\SiSoftware\SiSoftware Sandra Professional Business 2010\WNt500x64\sandra.sys (SiSoftware)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (npusbio) – C:\Windows\SysNative\drivers\npusbio_x64.sys (Thesycon GmbH, Germany)
DRV:64bit: - (ATITool) – C:\Windows\SysNative\drivers\ATITool64.sys ()
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV:64bit: - (PStrip64) – C:\Windows\SysNative\drivers\pstrip64.sys ()
DRV - (ntk_PowerDVD) – C:\Program Files (x86)\CyberLink\PowerDVD11\Kernel\DMP\ntk_PowerDVD_64.sys (Cyberlink Corp.)
DRV - (PORTMON) – C:\Program Files (x86)\SystemInternalsUtilities\PORTMSYS.SYS (Systems Internals)
DRV - ({329F96B6-DF1E-4328-BFDA-39EA953C1312}) – C:\Program Files (x86)\CyberLink\PowerDVD11\Common\NavFilter\000.fcl (CyberLink Corp.)
DRV - (speedfan) – C:\Windows\SysWOW64\speedfan.sys (Almico Software)
DRV - (vstor2-ws60) – C:\Program Files (x86)\VMware\VMware Workstation\vstor2-ws60.sys (VMware, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Users\silat\Desktop\Temptemp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = E8 5C 51 CF F9 A1 CA 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.startup.homepage: "blank"
FF - prefs.js..keyword.URL: "http://search.newtabking.com/?t=1&q;="

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/18 02:06:29 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2011/04/18 02:06:29 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\silat\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\silat\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/05/07 02:44:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3ED591BC-7CC7-495B-A526-B2431356EDC1}: C:\Program Files (x86)\Ad Muncher\FirefoxExtension_2.0 [2011/09/08 22:00:28 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/09 12:30:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 6.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\SeaMonkey\Extensions\\{3ED591BC-7CC7-495B-A526-B2431356EDC1}: C:\Program Files (x86)\Ad Muncher\FirefoxExtension_2.0 [2011/09/08 22:00:28 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox [2011/08/21 10:15:45 | 000,000,000 | —D | M]

[2011/09/09 12:30:47 | 000,000,000 | —D | M] (No name found) – C:\Users\silat\AppData\Roaming\Mozilla\Extensions
[2011/09/14 02:41:44 | 000,000,000 | —D | M] (No name found) – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions
[2011/09/09 14:11:17 | 000,000,000 | —D | M] (Flagfox) – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011/09/09 13:38:50 | 000,000,000 | —D | M] (New Tab King) – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions\{FC5BAC7D-D696-4ba6-B913-CF8F000C33DF}
[2011/09/09 14:11:17 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions\[removed]
[2011/09/09 14:18:06 | 000,000,000 | —D | M] ("Xmarks") – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions\[removed]
[2011/09/10 01:26:01 | 000,000,000 | —D | M] (Reload Plus) – C:\Users\silat\AppData\Roaming\Mozilla\Firefox\Profiles\n2florzd.default\extensions\reloadplus@blackwind
[2011/09/09 12:30:34 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/08 22:00:28 | 000,000,000 | —D | M] (Ad Muncher Browser Extensions) – C:\PROGRAM FILES (X86)\AD MUNCHER\FIREFOXEXTENSION_2.0
[2011/08/21 10:15:45 | 000,000,000 | —D | M] (Roboform Toolbar for Firefox) – C:\PROGRAM FILES (X86)\SIBER SYSTEMS\AI ROBOFORM\FIREFOX
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{0545B830-F0AA-4D7E-8820-50A4629A56FE}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE30}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{166745B8-8D4A-4C86-9120-696DE51A77AA}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{24CEA704-946D-11DA-A72B-0800200C9A66}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{962E0D4D-6B89-4B73-AA72-DF03360DA12E}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{A95D8332-E4B4-6E7F-98AC-20B733364387}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{C4D362EC-1CFF-4CA0-9031-99A8FAD7995A}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{DC572301-7619-498C-A57D-39143191B318}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{DD3D7613-0246-469D-BC65-2A3CC1668ADC}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\{EDA7B1D7-F793-4E03-B074-E6F303317FB0}.XPI
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
() (No name found) – C:\USERS\SILAT\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\N2FLORZD.DEFAULT\EXTENSIONS\[removed]
[2011/09/02 23:01:45 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/09/02 16:25:59 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

O1 HOSTS File: ([2009/06/10 14:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files (x86)\Shareaza\RazaWebHook64.dll (Shareaza Development Team)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (Shareaza Web Download Hook) - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files (x86)\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O2 - BHO: (Reg Error: Value error.) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (no name) - {ACDF77A9-9EDA-407f-969F-B3BCBE3217D0} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (&Linkman;) - {5C9DCA26-CEC4-4280-A831-D622D4DBF113} - C:\Program Files (x86)\Linkman\LinkmanCom.dll (Outertech)
O3 - HKLM\..\Toolbar: (&RoboForm;) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm;) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O4 - HKLM..\Run: [Chameleon System Monitor] C:\Program Files (x86)\Common Files\Chameleon Manager\monitor.exe (NeoSoft Tools)
O4 - HKCU..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\spreview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 File not found
O4 - Startup: C:\Users\silat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Zentimo.exe.lnk = C:\Program Files (x86)\Zentimo\Zentimo.exe (Crystal Rich Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 124
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: DisallowRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\DisallowCpl: 1 =
O8:64bit: - Extra context menu item: &ieSpell; Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: >Search in Linkman - C:\Users\silat\Documents\Linkman\iescript_search.htm ()
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Add to Linkman - C:\Users\silat\Documents\Linkman\iescript_add.htm ()
O8:64bit: - Extra context menu item: Add to Linkman (all tabs) - C:\Users\silat\Documents\Linkman\iescript_addall.htm ()
O8:64bit: - Extra context menu item: Add to Linkman and Edit - C:\Users\silat\Documents\Linkman\iescript_edit.htm ()
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_frame File not found
O8:64bit: - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_image File not found
O8:64bit: - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_be_i…id=menu_ie_link File not found
O8:64bit: - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8:64bit: - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_be_i…menu_ie_exclude File not found
O8:64bit: - Extra context menu item: Download with &Shareaza; - C:\Program Files (x86)\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O8:64bit: - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8:64bit: - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8:64bit: - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8:64bit: - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8:64bit: - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_be_i…=menu_ie_report File not found
O8:64bit: - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8:64bit: - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8:64bit: - Extra context menu item: Show Linkman - C:\Users\silat\Documents\Linkman\iescript_show.htm ()
O8:64bit: - Extra context menu item: Zoom Into - C:\Program Files (x86)\zoomintoIE\image.htm ()
O8 - Extra context menu item: &ieSpell; Options - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: >Search in Linkman - C:\Users\silat\Documents\Linkman\iescript_search.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Add to Linkman - C:\Users\silat\Documents\Linkman\iescript_add.htm ()
O8 - Extra context menu item: Add to Linkman (all tabs) - C:\Users\silat\Documents\Linkman\iescript_addall.htm ()
O8 - Extra context menu item: Add to Linkman and Edit - C:\Users\silat\Documents\Linkman\iescript_edit.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Block frame with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_frame File not found
O8 - Extra context menu item: Block image with Ad Muncher - http://www.admuncher.com/request_will_be_i…d=menu_ie_image File not found
O8 - Extra context menu item: Block link with Ad Muncher - http://www.admuncher.com/request_will_be_i…id=menu_ie_link File not found
O8 - Extra context menu item: Check &Spelling; - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Customize Menu - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Don't filter page with Ad Muncher - http://www.admuncher.com/request_will_be_i…menu_ie_exclude File not found
O8 - Extra context menu item: Download with &Shareaza; - C:\Program Files (x86)\Shareaza\RazaWebHook32.dll (Shareaza Development Team)
O8 - Extra context menu item: Fill Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll (Google Inc.)
O8 - Extra context menu item: Lookup on Merriam Webster - C:\Program Files (x86)\ieSpell\Merriam Webster.HTM ()
O8 - Extra context menu item: Lookup on Wikipedia - C:\Program Files (x86)\ieSpell\wikipedia.HTM ()
O8 - Extra context menu item: Report page to the Ad Muncher developers - http://www.admuncher.com/request_will_be_i…=menu_ie_report File not found
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O8 - Extra context menu item: Show Linkman - C:\Users\silat\Documents\Linkman\iescript_show.htm ()
O8 - Extra context menu item: Zoom Into - C:\Program Files (x86)\zoomintoIE\image.htm ()
O9 - Extra Button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra 'Tools' menuitem : ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files (x86)\ieSpell\iespell.dll (Red Egg Software)
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Customize - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O9 - Extra 'Tools' menuitem : Customize Menu - {320AF880-6646-11D3-ABEE-C5DBF3571F4E} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {63F5866B-A7C5-40B4-9A89-0CCA99726C8D} https://secure.logmeinrescue.com/Customer/x…eDownloader.cab (LogMeIn Rescue Applet Downloader)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{451EC62D-E4BF-4226-9289-8026B4D97842}: DhcpNameServer = 192.168.25.2
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6502301C-ADD7-4257-BE49-8FD59C14D15F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E55665EF-B483-4CD4-8832-1E25012110B9}: DhcpNameServer = 192.168.40.1
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O20:64bit: - AppInit_DLLs: (acaptuser64.dll) - C:\Windows\SysNative\acaptuser64.dll (Adobe Systems, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\syswow64\userinit.exe) -c:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKCU Winlogon: Shell - (expstart.exe) -C:\Windows\expstart.exe ()
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {1984D045-52CF-49cd-DB77-08F378FEA4DB} - ObjectDockShellExt - C:\Program Files (x86)\Stardock\ObjectDockPlus2\ODMenu64.dll (Stardock)
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O22 - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysWOW64\DreamScene.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - Reg Error: Key error. File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lhacm - C:\Windows\SysWow64\lhacm.acm (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: VIDC.RTV1 - rtvcvfw32.dll File not found
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.VMnc - C:\Windows\SysWow64\vmnc.dll (VMware, Inc.)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\Windows\SysWOW64\xvidvfw.dll ()

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/14 15:11:00 | 000,581,632 | —- | C] (OldTimer Tools) – C:\Users\silat\Desktop\OTL.exe
[2011/09/11 22:46:39 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\vlc
[2011/09/11 22:43:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoLAN
[2011/09/09 12:30:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2011/09/08 22:00:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ad Muncher
[2011/09/08 22:00:21 | 000,000,000 | —D | C] – C:\ProgramData\Ad Muncher
[2011/09/08 22:00:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ad Muncher
[2011/09/08 01:31:31 | 000,000,000 | —D | C] – C:\Windows\SysNative\SPReview
[2011/09/06 22:29:38 | 000,024,408 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/09/06 22:29:37 | 000,301,912 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2011/09/06 22:29:35 | 000,058,200 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2011/09/06 22:29:35 | 000,042,328 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2011/09/06 22:29:34 | 000,601,944 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2011/09/06 22:29:32 | 000,254,400 | —- | C] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2011/09/06 22:29:32 | 000,065,368 | —- | C] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/09/06 22:29:23 | 000,199,304 | —- | C] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2011/09/06 22:29:23 | 000,041,184 | —- | C] (AVAST Software) – C:\Windows\avastSS.scr
[2011/09/06 22:29:18 | 000,000,000 | —D | C] – C:\ProgramData\AVAST Software
[2011/09/06 22:29:18 | 000,000,000 | —D | C] – C:\Program Files\AVAST Software
[2011/09/06 10:43:17 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2011/09/05 14:19:00 | 000,000,000 | —D | C] – C:\Users\silat\Documents\Xilisoft
[2011/09/05 14:18:03 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\Xilisoft
[2011/09/05 10:37:07 | 000,000,000 | —D | C] – C:\Users\silat\Documents\ScreenSteps Library
[2011/09/05 10:37:05 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\._LiveCode_
[2011/09/05 10:36:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\ScreenSteps 2
[2011/09/05 10:36:56 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\ScreenSteps
[2011/09/03 23:36:50 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\Nathanael Jones
[2011/09/03 23:36:49 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\Nathanael Jones
[2011/09/03 23:36:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Quick Key
[2011/09/03 23:36:28 | 000,000,000 | —D | C] – C:\Users\silat\Documents\Charsets
[2011/09/03 13:48:43 | 000,000,000 | —D | C] – C:\Users\silat\Documents\Rainmeter
[2011/09/03 13:48:43 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\Rainmeter
[2011/09/03 13:48:33 | 000,000,000 | —D | C] – C:\Program Files\Rainmeter
[2011/09/01 02:43:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\EfficientPIM
[2011/08/31 13:24:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\YaruReg
[2011/08/31 13:23:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Event Viewer Plus v 1.0
[2011/08/31 13:22:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Taskbar Color Effects
[2011/08/30 21:07:13 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\Stuf
[2011/08/30 21:07:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Stuf
[2011/08/28 15:52:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Xmarks
[2011/08/26 21:41:05 | 000,000,000 | —D | C] – C:\ProgramData\Vuesoft
[2011/08/26 21:41:04 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\VueSoft
[2011/08/26 21:40:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\VueSoft
[2011/08/26 21:36:34 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\PotPlayerMini64
[2011/08/26 21:36:34 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\Daum
[2011/08/26 21:34:11 | 000,000,000 | —D | C] – C:\Program Files\DAUM
[2011/08/26 21:30:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\The KMPlayer
[2011/08/25 13:14:27 | 000,704,000 | —- | C] (SUPERAdBlocker.com and SUPERAntiSpyware.com) – C:\Program Files\SUPERSampleSubmit.exe
[2011/08/24 17:15:44 | 000,000,000 | —D | C] – C:\Program Files\TrackWinstall
[2011/08/23 15:22:49 | 000,000,000 | —D | C] – C:\Users\silat\Documents\ASBware
[2011/08/23 15:22:49 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\ASBware
[2011/08/23 15:20:53 | 000,000,000 | —D | C] – C:\Users\silat\Documents\Audio Notetaker Recordings
[2011/08/23 15:19:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Sonocent
[2011/08/23 11:58:05 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\ESET
[2011/08/23 11:25:49 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/08/23 11:25:49 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/08/23 11:25:48 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/08/23 11:25:47 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/08/23 11:25:47 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/08/23 11:25:47 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/08/23 11:25:47 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/08/23 11:25:47 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/08/23 11:25:46 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/08/23 11:24:48 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2011/08/23 11:24:48 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2011/08/23 11:24:48 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2011/08/23 11:24:48 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/08/23 11:24:48 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/08/23 11:24:48 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/08/23 11:24:47 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2011/08/23 11:24:47 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2011/08/23 11:24:47 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/08/23 11:24:47 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2011/08/23 11:24:47 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/08/23 11:24:46 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/23 11:24:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/23 11:24:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/08/23 11:24:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/08/23 11:24:46 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/08/23 11:24:46 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/08/23 11:24:45 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/08/23 11:24:45 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/23 11:24:45 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/23 11:24:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/08/23 11:24:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/08/23 11:24:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/23 11:24:44 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/23 11:24:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/08/23 11:24:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/23 11:24:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/08/23 11:24:43 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/08/23 11:24:43 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/08/23 11:24:43 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/08/23 11:24:43 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/08/23 11:24:43 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/08/23 11:24:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/23 11:24:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/08/23 11:24:42 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/08/23 11:24:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/08/23 11:24:41 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/08/23 11:24:41 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/08/23 11:24:41 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/08/23 11:24:41 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/08/23 11:24:32 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2011/08/23 11:24:32 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2011/08/23 11:24:32 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2011/08/23 11:24:32 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2011/08/23 11:24:32 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2011/08/23 11:24:32 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2011/08/23 11:24:32 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2011/08/23 11:24:31 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2011/08/23 11:24:31 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2011/08/23 11:24:27 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/08/23 11:24:26 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/08/23 11:24:19 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/08/23 11:23:12 | 005,507,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/08/23 11:23:10 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/08/23 11:23:10 | 003,902,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/08/23 04:14:54 | 000,000,000 | —D | C] – C:\ProgramData\f-secure
[2011/08/23 00:30:58 | 001,050,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSJET35.DLL
[2011/08/23 00:30:58 | 000,415,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSREPL35.DLL
[2011/08/23 00:30:58 | 000,252,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSRD2X35.DLL
[2011/08/23 00:30:58 | 000,180,224 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\ijl11.dll
[2011/08/23 00:30:58 | 000,123,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSJINT35.DLL
[2011/08/23 00:30:58 | 000,089,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\VB5DB.DLL
[2011/08/23 00:30:58 | 000,024,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSJTER35.DLL
[2011/08/23 00:30:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\textBEAST3pro
[2011/08/23 00:30:57 | 000,000,000 | —D | C] – C:\ProgramData\ASBware
[2011/08/22 18:51:50 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\Panda Security
[2011/08/22 18:51:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Toolbar Cleaner
[2011/08/22 18:51:13 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\panda2_0dn
[2011/08/22 18:51:11 | 000,000,000 | —D | C] – C:\ProgramData\Panda Security URL Filtering
[2011/08/22 18:50:44 | 000,000,000 | —D | C] – C:\ProgramData\Panda Security
[2011/08/22 18:50:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Panda Security
[2011/08/21 20:23:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Ashampoo
[2011/08/20 13:55:30 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Roaming\TrackWinstall
[2011/08/20 13:53:58 | 000,000,000 | —D | C] – C:\Users\silat\Documents\PassMark
[2011/08/20 13:53:41 | 000,000,000 | —D | C] – C:\ProgramData\PassMark
[2011/08/20 13:53:41 | 000,000,000 | —D | C] – C:\Program Files\OSForensics
[2011/08/19 12:13:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\FileASSASSIN
[2011/08/19 01:29:10 | 000,000,000 | —D | C] – C:\Users\silat\AppData\Local\Mizage LLC
[2011/08/18 11:08:28 | 000,270,992 | —- | C] (BiniSoft.org) – C:\Windows\SysNative\wfc.exe
[2011/08/18 02:36:23 | 000,000,000 | —D | C] – C:\Users\silat\Documents\GroceryListGenerator
[2011/08/17 02:53:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Zentimo
[2011/04/22 05:25:47 | 000,669,696 | —- | C] (TheWindowsClub) – C:\Program Files (x86)\Taskbar Thumbnail Tweaker.exe
[2011/04/22 05:24:59 | 000,073,728 | —- | C] (door2windows) – C:\Program Files (x86)\Windows Taskbar Thumbnail Customizer.exe
[2006/05/17 12:19:00 | 000,273,920 | —- | C] (Datasoft Ltd.) – C:\Program Files\stripmail.exe
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\silat\Desktop\*.tmp files -> C:\Users\silat\Desktop\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/14 15:15:03 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/14 15:15:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-938881651-2139490446-1910908031-1001UA.job
[2011/09/14 15:11:02 | 000,581,632 | —- | M] (OldTimer Tools) – C:\Users\silat\Desktop\OTL.exe
[2011/09/14 11:07:00 | 000,000,510 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d2c7d1cc-e931-4951-a2b6-93d1ae5c03d5.job
[2011/09/14 09:28:25 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-938881651-2139490446-1910908031-1001Core.job
[2011/09/14 06:03:36 | 000,000,396 | —- | M] () – C:\Windows\tasks\GBM - New Backup Job-Full.job
[2011/09/13 21:15:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/12 16:45:16 | 000,021,394 | —- | M] () – C:\Users\silat\AppData\Roaming\PStrip.ini
[2011/09/12 16:45:16 | 000,021,394 | —- | M] () – C:\Users\silat\AppData\Roaming\PStrip.bak
[2011/09/12 12:15:47 | 000,013,488 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/12 12:15:47 | 000,013,488 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/12 12:08:24 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/12 12:08:21 | 529,932,287 | -HS- | M] () – C:\hiberfil.sys
[2011/09/12 12:07:25 | 000,022,339 | —- | M] () – C:\Users\silat\AppData\Roaming\PStrip.bk!
[2011/09/11 00:45:32 | 000,106,438 | —- | M] () – C:\Users\silat\Desktop\LMAO.jpg
[2011/09/09 12:25:50 | 002,374,902 | —- | M] () – C:\Users\silat\Desktop\bookmarks.html
[2011/09/09 09:08:19 | 000,022,339 | —- | M] () – C:\Users\silat\AppData\Roaming\PStrip.bko
[2011/09/09 09:08:10 | 000,001,037 | —- | M] () – C:\Users\silat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Zentimo.exe.lnk
[2011/09/08 22:55:06 | 000,007,038 | —- | M] () – C:\Windows\Sandboxie.ini
[2011/09/08 22:33:26 | 000,775,656 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/09/08 22:33:26 | 000,158,152 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/09/08 22:33:26 | 000,005,638 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/08 01:23:11 | 000,000,983 | —- | M] () – C:\Users\Public\Desktop\Beyond Compare 3.lnk
[2011/09/06 22:37:25 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2011/09/06 21:18:10 | 006,070,064 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/09/06 20:47:29 | 000,001,133 | —- | M] () – C:\Users\silat\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2011/09/06 13:45:29 | 000,199,304 | —- | M] (AVAST Software) – C:\Windows\SysWow64\aswBoot.exe
[2011/09/06 13:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2011/09/06 13:45:17 | 000,254,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2011/09/06 13:38:18 | 000,601,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2011/09/06 13:38:16 | 000,301,912 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2011/09/06 13:36:41 | 000,058,200 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2011/09/06 13:36:41 | 000,042,328 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr.sys
[2011/09/06 13:36:30 | 000,065,368 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/09/06 13:36:14 | 000,024,408 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/09/06 10:44:32 | 000,018,960 | —- | M] (Logitech, Inc.) – C:\Windows\SysNative\drivers\LNonPnP.sys
[2011/09/05 10:37:10 | 000,000,026 | -H– | M] () – C:\ProgramData\.6b14a35055fac291a0de744e5b9ee9ec.dat
[2011/09/03 23:29:52 | 000,001,197 | —- | M] () – C:\Users\silat\Desktop\CharacterMap.lnk
[2011/09/03 13:48:35 | 000,001,694 | —- | M] () – C:\Users\Public\Desktop\Rainmeter.lnk
[2011/09/01 03:31:47 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/08/24 02:28:27 | 000,000,412 | —- | M] () – C:\Users\silat\AppData\Roaming\All CPU Meter_Settings.ini
[2011/08/23 04:19:29 | 000,006,064 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/20 13:46:39 | 000,001,144 | —- | M] () – C:\Users\silat\Application Data\Microsoft\Internet Explorer\Quick Launch\Bring Notes On Top (NoteZilla).lnk
[2011/08/19 21:43:39 | 000,069,181 | —- | M] () – C:\Users\silat\Desktop\vlemmings.jpg
[2011/08/19 01:29:23 | 000,001,212 | —- | M] () – C:\Users\silat\Desktop\Divvy.lnk
[2011/08/18 11:08:28 | 000,270,992 | —- | M] (BiniSoft.org) – C:\Windows\SysNative\wfc.exe
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[3 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\silat\Desktop\*.tmp files -> C:\Users\silat\Desktop\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/11 00:45:32 | 000,106,438 | —- | C] () – C:\Users\silat\Desktop\LMAO.jpg
[2011/09/09 12:25:04 | 002,374,902 | —- | C] () – C:\Users\silat\Desktop\bookmarks.html
[2011/09/08 01:23:11 | 000,000,983 | —- | C] () – C:\Users\Public\Desktop\Beyond Compare 3.lnk
[2011/09/06 22:29:32 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\config.nt
[2011/09/05 10:37:10 | 000,000,026 | -H– | C] () – C:\ProgramData\.6b14a35055fac291a0de744e5b9ee9ec.dat
[2011/09/03 23:29:52 | 000,001,197 | —- | C] () – C:\Users\silat\Desktop\CharacterMap.lnk
[2011/09/03 13:48:35 | 000,001,694 | —- | C] () – C:\Users\Public\Desktop\Rainmeter.lnk
[2011/08/24 01:34:30 | 000,000,412 | —- | C] () – C:\Users\silat\AppData\Roaming\All CPU Meter_Settings.ini
[2011/08/20 13:46:39 | 000,001,144 | —- | C] () – C:\Users\silat\Application Data\Microsoft\Internet Explorer\Quick Launch\Bring Notes On Top (NoteZilla).lnk
[2011/08/19 21:43:38 | 000,069,181 | —- | C] () – C:\Users\silat\Desktop\vlemmings.jpg
[2011/08/19 16:17:12 | 000,001,037 | —- | C] () – C:\Users\silat\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Zentimo.exe.lnk
[2011/08/19 01:29:23 | 000,001,212 | —- | C] () – C:\Users\silat\Desktop\Divvy.lnk
[2011/07/31 01:26:24 | 000,000,051 | —- | C] () – C:\Windows\REGKEYNT.INI
[2011/07/28 23:31:44 | 000,001,291 | —- | C] () – C:\Windows\MultiTimer.ini
[2011/07/28 12:23:04 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\UFModDll.dll
[2011/07/27 09:38:46 | 000,002,593 | —- | C] () – C:\Users\silat\AppData\Roaming\com.living-e.timeEdition.plist
[2011/07/21 09:32:52 | 000,000,012 | —- | C] () – C:\ProgramData\ReminderNextRun
[2011/07/16 03:34:18 | 000,925,184 | —- | C] () – C:\Windows\expstart.exe
[2011/07/13 00:25:51 | 000,001,588 | —- | C] () – C:\Windows\debugrcfile.ini
[2011/07/13 00:25:49 | 000,061,440 | —- | C] () – C:\Windows\SysWow64\CIUtils.dll
[2011/07/11 02:09:38 | 000,003,584 | —- | C] () – C:\Users\silat\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/26 20:32:18 | 000,000,090 | —- | C] () – C:\Windows\SysWow64\ftm31.dat
[2011/06/01 16:07:02 | 000,000,130 | —- | C] () – C:\Users\silat\AppData\Roaming\artha.conf
[2011/05/30 22:45:01 | 000,000,136 | —- | C] () – C:\Windows\AoADVDRipper.INI
[2011/05/29 18:16:34 | 000,000,033 | —- | C] () – C:\Windows\DownloadStudioScheduleMonitor.INI
[2011/05/23 12:28:52 | 000,000,073 | —- | C] () – C:\Windows\EurekaLog.ini
[2011/05/18 11:35:11 | 000,000,000 | —- | C] () – C:\Users\silat\AppData\Local\{45004D72-1284-4590-95A6-B2D7F50D23B5}
[2011/05/18 11:11:44 | 000,000,000 | —- | C] () – C:\Users\silat\AppData\Local\{EF07F7B8-835B-4450-BFD2-DD073AC7591B}
[2011/05/12 15:15:16 | 000,000,058 | —- | C] () – C:\Windows\SysWow64\Anderson Hu_MobysaurusThesaurus_InstallInfo.dat
[2011/05/12 15:15:16 | 000,000,058 | —- | C] () – C:\Users\silat\AppData\Local\Anderson Hu_MobysaurusThesaurus_InstallInfo.dat
[2011/05/12 01:31:06 | 000,131,584 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall.exe
[2011/05/12 01:31:06 | 000,001,734 | —- | C] () – C:\Windows\SysWow64\SpoonUninstall-Mobysaurus Thesaurus.dat
[2011/05/10 21:52:35 | 000,209,630 | —- | C] () – C:\Windows\Screen Compass Uninstaller.exe
[2011/05/10 21:43:22 | 000,210,354 | —- | C] () – C:\Windows\Screen Protractor Uninstaller.exe
[2011/05/10 21:24:29 | 000,211,457 | —- | C] () – C:\Windows\Screen Calipers Uninstaller.exe
[2011/05/10 11:13:47 | 000,000,022 | -HS- | C] () – C:\Users\silat\AppData\Roaming\Sys2662.Config.Repository.bin
[2011/04/22 15:40:59 | 000,274,460 | —- | C] () – C:\Windows\Icon Converter Plus Uninstaller.exe
[2011/04/22 05:16:35 | 000,001,970 | —- | C] () – C:\Program Files (x86)\7 Taskbar Tweaker.lnk
[2011/04/20 14:25:41 | 000,000,179 | —- | C] () – C:\Windows\EQ3D.ini
[2011/04/14 15:42:08 | 000,000,000 | —- | C] () – C:\Windows\ColorConsole_Portable.INI
[2011/04/07 16:47:56 | 000,000,262 | —- | C] () – C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2011/04/07 13:00:01 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\cid_store.dat
[2011/04/07 12:17:03 | 000,000,625 | —- | C] () – C:\Windows\clipc.INI
[2011/03/31 22:07:02 | 010,877,272 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/03/31 22:07:02 | 000,102,744 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/03/31 22:06:56 | 000,331,608 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2010/05/20 16:34:28 | 000,120,832 | —- | C] () – C:\Program Files (x86)\Svchost Viewer.exe
[2010/02/17 20:59:20 | 000,000,000 | —- | C] () – C:\Windows\Infob.dat
[2010/02/17 20:59:20 | 000,000,000 | —- | C] () – C:\Windows\Infoa.dat
[2010/02/17 04:20:33 | 000,053,760 | —- | C] () – C:\Windows\SysWow64\zlib.dll
[2010/02/13 19:51:47 | 007,277,568 | —- | C] () – C:\Windows\SysWow64\3gpcore.dll
[2010/02/13 19:51:36 | 008,676,883 | —- | C] () – C:\Windows\SysWow64\NCMedia2.dll
[2010/02/13 19:51:36 | 000,819,200 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2010/02/13 19:51:36 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2010/02/07 23:44:22 | 010,977,280 | —- | C] () – C:\ProgramData\sandra.mda
[2010/02/06 12:24:32 | 000,077,312 | —- | C] () – C:\Windows\SysWow64\UNACEV2.DLL
[2010/02/03 23:36:03 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/02/02 01:38:07 | 000,022,339 | —- | C] () – C:\Users\silat\AppData\Roaming\PStrip.bko
[2010/02/01 10:17:32 | 000,022,339 | —- | C] () – C:\Users\silat\AppData\Roaming\PStrip.bk!
[2010/02/01 10:17:27 | 000,021,394 | —- | C] () – C:\Users\silat\AppData\Roaming\PStrip.bak
[2010/02/01 10:16:11 | 000,000,062 | —- | C] () – C:\Windows\wininit.ini
[2010/02/01 10:07:08 | 000,021,394 | —- | C] () – C:\Users\silat\AppData\Roaming\PStrip.ini
[2010/01/31 19:14:58 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/01/31 00:13:26 | 000,103,424 | —- | C] () – C:\Windows\SysWow64\DCLibrary_nat.dll
[2010/01/30 22:00:24 | 000,000,140 | —- | C] () – C:\Windows\ODBC.INI
[2010/01/30 20:12:09 | 000,006,064 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/01/30 16:45:19 | 000,007,038 | —- | C] () – C:\Windows\Sandboxie.ini
[2010/01/30 15:58:49 | 000,200,704 | —- | C] () – C:\Windows\SysWow64\HsMgr.exe
[2010/01/30 15:58:49 | 000,000,053 | —- | C] () – C:\Windows\SysWow64\cmasiop.ini
[2010/01/30 15:58:48 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\VmixP8.dll
[2010/01/30 15:58:47 | 000,039,973 | —- | C] () – C:\Windows\Cmicnfgp.ini.cfl
[2010/01/30 15:58:32 | 000,000,929 | —- | C] () – C:\Windows\Cmicnfgp.ini.imi
[2010/01/30 15:58:28 | 000,004,965 | —- | C] () – C:\Windows\Cmicnfgp.ini.cfg
[2010/01/30 15:58:27 | 000,000,558 | —- | C] () – C:\Windows\cmudaxp.ini
[2010/01/30 15:39:33 | 000,000,017 | —- | C] () – C:\Users\silat\AppData\Local\resmon.resmoncfg
[2009/10/20 11:19:30 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2009/07/13 22:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 19:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 19:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 17:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 14:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 14:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2008/09/20 18:06:21 | 000,000,108 | RHS- | C] () – C:\Windows\neoqaz2.dll
[2008/01/31 16:55:20 | 000,000,109 | —- | C] () – C:\Windows\SysWow64\OSENXPSUITE2005.INI
[2002/10/15 15:54:04 | 000,153,088 | —- | C] () – C:\Windows\SysWow64\unrar.dll

========== LOP Check ==========

[2011/06/25 15:14:36 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\.purple
[2011/04/22 05:16:35 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\7 Taskbar Tweaker
[2011/07/11 02:19:09 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ACD Systems
[2011/04/14 21:08:32 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\aicon
[2011/08/23 15:22:49 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ASBware
[2010/01/30 15:58:57 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ASUS
[2011/04/17 13:44:38 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Audacity
[2010/02/05 22:46:43 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Auto Mailer
[2011/04/20 14:59:29 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Axialis
[2010/02/16 13:57:25 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Bitmeter2
[2011/09/05 22:24:08 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\BitTorrent
[2011/05/11 11:48:55 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Blazing tools
[2011/04/20 01:39:15 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Blue Ridge Networks
[2011/08/07 12:04:24 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Breevy
[2011/05/29 22:01:36 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/19 21:35:37 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Chief Architect Premier X3
[2011/04/17 01:40:33 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ColorCop
[2011/08/14 14:08:55 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Conceptworld
[2011/04/30 13:54:00 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\DVDFab
[2011/07/10 04:39:47 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\EAC
[2011/06/25 14:17:36 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\enchant
[2011/05/09 23:33:26 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\EnergiekostenSchnellrechner
[2011/04/20 14:57:28 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Extensis
[2011/04/08 14:08:40 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Firetrust
[2011/04/07 06:22:50 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Flashnote
[2011/07/05 03:54:44 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\foobar2000
[2010/01/31 00:56:18 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Forte
[2010/02/18 14:26:30 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Foxit
[2011/07/23 02:28:19 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\FreeFixer
[2010/01/30 22:24:42 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Genie-Soft
[2011/07/04 02:08:17 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\GetRightToGo
[2011/04/26 12:50:21 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\GoodSync
[2011/05/01 21:22:39 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\GumNotes
[2011/05/30 04:15:07 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\HD Tune Pro
[2010/02/01 01:05:51 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Highresolution Enterprises
[2011/05/10 21:24:29 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Iconico
[2011/04/10 04:28:32 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ieSpell
[2011/04/15 13:08:49 | 000,000,000 | -H-D | M] – C:\Users\silat\AppData\Roaming\IFViewer
[2010/02/21 17:04:30 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ImgBurn
[2011/05/12 01:32:02 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ImmersEd
[2011/04/10 00:07:37 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\IrfanView
[2010/02/18 12:42:19 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\JAM Software
[2011/06/11 14:08:29 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Key Metric Software
[2011/07/08 13:28:57 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Kinook Software
[2011/05/31 14:47:29 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\KRKsoft
[2011/04/07 16:44:21 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Leadertech
[2010/02/17 14:09:05 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\LockHunter
[2011/07/18 04:08:31 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\MainType
[2011/04/07 12:18:57 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Maxthon2
[2011/07/27 10:48:47 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Maxthon3
[2011/05/01 01:55:19 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Mirillis
[2011/04/07 13:16:03 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\MxBoost
[2011/09/03 23:36:50 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Nathanael Jones
[2011/06/07 03:19:15 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\nemo
[2011/07/10 16:37:28 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\NeoSoftTools
[2011/05/29 23:01:07 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\onOne Software
[2011/08/22 18:51:50 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Panda Security
[2011/05/13 02:40:26 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\PDF Software
[2011/08/26 21:36:34 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\PotPlayerMini64
[2011/05/14 12:40:54 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Process Hacker 2
[2011/09/11 01:03:22 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ProcessLasso
[2011/09/03 13:49:44 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Rainmeter
[2010/02/09 01:19:47 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Returnil
[2011/04/17 01:20:59 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Screaming Bee
[2011/09/05 10:37:06 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\ScreenSteps
[2011/06/03 18:22:31 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Shareaza
[2010/02/19 16:06:39 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Six-Updater
[2011/04/13 10:38:26 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Sonocent
[2011/04/21 23:36:49 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Stardock
[2011/04/20 03:18:58 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Stellarium
[2011/08/14 23:16:37 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\stickies
[2011/05/17 11:36:23 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\SuperCat
[2011/07/26 20:19:22 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\TeamViewer
[2011/06/01 15:58:22 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\TheSage
[2011/07/30 11:56:11 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Thinstall
[2010/02/05 15:00:51 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Thunderbird
[2011/07/27 09:44:26 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\timeEdition
[2011/08/20 13:55:30 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\TrackWinstall
[2010/02/01 12:10:37 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Trillian
[2011/07/03 16:01:31 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\TS3Client
[2011/04/20 00:03:24 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\TweakNow PowerPack 2011
[2010/02/12 21:24:58 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\WeatherPulse
[2011/04/14 20:40:07 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Wieldraaijer
[2011/05/30 23:02:32 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\WinAVI
[2011/05/23 03:28:05 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\WordWeb
[2011/06/07 03:10:44 | 000,000,000 | -HSD | M] – C:\Users\silat\AppData\Roaming\wyUpdate AU
[2010/02/01 01:24:00 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\X-Setup Pro
[2011/09/05 14:18:39 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Xilisoft
[2010/02/07 21:24:13 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Xilisoft Corporation
[2011/04/09 20:15:23 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\XRayz
[2011/08/17 02:53:54 | 000,000,000 | —D | M] – C:\Users\silat\AppData\Roaming\Zentimo
[2011/09/14 06:03:36 | 000,000,396 | —- | M] () – C:\Windows\Tasks\GBM - New Backup Job-Full.job
[2011/05/28 22:37:56 | 000,032,580 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/09/14 11:07:00 | 000,000,510 | —- | M] () – C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task d2c7d1cc-e931-4951-a2b6-93d1ae5c03d5.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/07/15 18:13:19 | 000,001,024 | —- | M] () – C:\.rnd
[2009/07/13 18:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/04/17 01:32:33 | 000,000,279 | —- | M] () – C:\data
[2011/09/12 12:08:21 | 529,932,287 | -HS- | M] () – C:\hiberfil.sys
[2011/07/13 04:19:34 | 000,000,000 | —- | M] () – C:\JavaRa.log
[2011/09/12 12:08:21 | 2138,234,879 | -HS- | M] () – C:\pagefile.sys
[2010/02/13 00:00:02 | 000,000,096 | —- | M] () – C:\SendMail.url
[2011/05/08 23:59:35 | 000,000,077 | —- | M] () – C:\Show Desktop.scf
[2011/07/24 01:09:10 | 000,005,247 | —- | M] () – C:\tasklist.csv
[2011/04/07 05:24:44 | 000,032,256 | —- | M] () – C:\TRACK1.BAK
[2011/07/28 01:16:30 | 000,004,096 | -HS- | M] () – C:\VSM000.IDX

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/09/06 13:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2011/04/22 05:16:35 | 000,001,970 | —- | M] () – C:\Program Files (x86)\7 Taskbar Tweaker.lnk
[2011/06/14 18:46:43 | 000,000,300 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2011/04/22 06:01:01 | 000,270,398 | RHS- | M] () – C:\Program Files (x86)\desktop22.ico
[2011/06/14 18:46:43 | 000,370,070 | RHS- | M] () – C:\Program Files (x86)\desktop71.ico
[2010/05/20 16:34:28 | 000,120,832 | —- | M] () – C:\Program Files (x86)\Svchost Viewer.exe
[2010/03/08 07:30:26 | 000,669,696 | —- | M] (TheWindowsClub) – C:\Program Files (x86)\Taskbar Thumbnail Tweaker.exe
[2011/04/22 05:15:24 | 000,073,728 | —- | M] (door2windows) – C:\Program Files (x86)\Windows Taskbar Thumbnail Customizer.exe

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2009/07/13 22:01:14 | 000,000,442 | -HS- | M] () – C:\ProgramData\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/17 01:32:20 | 000,000,221 | -HS- | M] () – C:\Users\silat\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2011/06/03 17:24:12 | 000,003,677 | -H– | M] () – C:\Users\silat\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\setup.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/14 15:11:02 | 000,581,632 | —- | M] (OldTimer Tools) – C:\Users\silat\Desktop\OTL.exe
[2010/11/05 06:27:18 | 007,168,768 | —- | M] (TeamSpeak Systems GmbH) – C:\Users\silat\Desktop\ts3client_win32.exe
[2009/10/20 15:21:28 | 000,551,784 | —- | M] (Sysinternals - www.sysinternals.com) – C:\Users\silat\Desktop\ZoomIt.exe
[1 C:\Users\silat\Desktop\*.tmp files -> C:\Users\silat\Desktop\*.tmp -> ]

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 54 bytes -> C:\Users\silat\ntuser.ini:l_encryption_d
@Alternate Data Stream - 204 bytes -> C:\ProgramData\TEMP:618D0840
@Alternate Data Stream - 196 bytes -> C:\ProgramData\TEMP:BEC0D766
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:ED3F622D
@Alternate Data Stream - 16 bytes -> C:\Users\silat\Downloads:Shareaza.GUID
@Alternate Data Stream - 16 bytes -> C:\Users\silat\Desktop\Temptemp:Shareaza.GUID
@Alternate Data Stream - 156 bytes -> C:\ProgramData\TEMP:8CE646EE
@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:30FD0CBD
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:905844AA
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:63238B95
@Alternate Data Stream - 124 bytes -> C:\Users\silat\ntuser.ini:l_encryption_e
@Alternate Data Stream - 108 bytes -> C:\Windows:

< End of report >
OTL Extras logfile created on: 09/14/2011 03:16:21 PM - Run 1
OTL by OldTimer - Version 3.2.28.0 Folder = C:\Users\silat\Desktop
64bit- An unknown product (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: MM/dd/yyyy

5.99 Gb Total Physical Memory | 2.97 Gb Available Physical Memory | 49.62% Memory free
11.98 Gb Paging File | 9.31 Gb Available in Paging File | 77.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 596.17 Gb Total Space | 517.81 Gb Free Space | 86.86% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 416.36 Gb Free Space | 44.70% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 409.52 Gb Free Space | 43.96% Space Free | Partition Type: NTFS

Computer Name: BLACKHOLE | User Name: silat | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Flash Renamer] – "C:\Program Files (x86)\Flash Renamer 5.05\FlashRen.exe" "/p %1" (RL Vision)
Directory [open] – "C:\Program Files\zabkat\xplorer2\xplorer2_64.exe" /M "%1" (ZabKat)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [UnzipThemAll] – "C:\Program Files (x86)\UnzipThemAll\UnzipThemAll.exe" "%1" (Hervé Thouzard)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Flash Renamer] – "C:\Program Files (x86)\Flash Renamer 5.05\FlashRen.exe" "/p %1" (RL Vision)
Directory [open] – "C:\Program Files\zabkat\xplorer2\xplorer2_64.exe" /M "%1" (ZabKat)
Directory [runas] – cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [UnzipThemAll] – "C:\Program Files (x86)\UnzipThemAll\UnzipThemAll.exe" "%1" (Hervé Thouzard)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
"DefaultOutboundAction" = 1
"DefaultInboundAction" = 1
"DisableUnicastResponsesToMulticastBroadcast" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
"DefaultOutboundAction" = 1
"DefaultInboundAction" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
"DoNotAllowExceptions" = 0
"DefaultOutboundAction" = 1
"DefaultInboundAction" = 1

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.0.0 (r181)
"{0325FFA1-28D4-459A-A220-52FC5C00DB1D}" = True Launch Bar: Volume Control plugin
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{12297AC7-E154-493B-9701-479383649E13}" = True Launch Bar: Disable Windows Keys
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{14BAA831-33BF-4FA7-B9DD-A3E27CF51D13}" = True Launch Bar: Display Mode plugin
"{186FFBE2-E195-464F-9A55-D8879977DF73}" = True Launch Bar: Virtual Desktops plugin
"{1AE42C63-E904-43B0-AE88-26D8B041CFE5}" = True Launch Bar: Wireless Monitor plugin
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{299CC263-D4A2-4536-9874-9C9F75B2F475}_is1" = Genie Backup Manager Pro 8.0 (x64)
"{344A17D9-DE25-4E77-B089-E7F0A0AF2AE7}" = Microangelo On Display (x64)
"{3613F7D5-DCB3-4099-8C2F-05D9C71F1605}" = True Launch Bar: Key State plugin
"{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}" = Intel® Turbo Boost Technology Monitor
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{53019CE7-5137-4154-BFF0-E3D6B239442C}" = True Launch Bar: Startup Manager plugin
"{63BA5CB8-08AE-4CEB-AAA7-162B4E80A24C}" = TLB: CD Control plugin
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.3
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{73156824-D102-42A7-A92F-0B9C24517AE5}" = True Launch Bar: Media Control plugin
"{73C334B1-7D2B-4AF7-9A04-45F915C1E43A}" = True Launch Bar: Spacer plugin
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8C545F85-0C95-49CF-9897-592BFB787AC5}" = True Launch Bar: Calendar plugin
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{98B1A3B1-B86F-40D8-87DD-3FB62B4DB5AE}" = True Launch Bar: Add Or Remove Programs plugin
"{9939A1EC-0093-4964-BDB3-0994D60CBFFF}" = True Launch Bar: Select Color plugin
"{9DAB307E-531F-4992-AB30-6F1AD39E6CF9}" = Desktop Restore
"{A3A40A1E-8757-4E69-A3C2-C4B465263E58}" = True Launch Bar: Slide Show plugin
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{AC76BA86-1033-0000-0064-0003D0000004}" = Adobe Acrobat 9 Pro Extended 64-bit Add-On
"{B26B00DA-2E5D-4CF2-83C5-911198C0F009}" = GoodSync
"{B296DCFE-A8B8-44FF-B42D-DC86F848FCA0}" = True Launch Bar: Device Manager plugin
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 270.61
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 270.61
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 270.61
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 270.61
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B7607FC8-72AD-486D-B6B7-A402D5876309}" = PerfectDisk 11 Professional
"{B7CAD946-BC0D-48FC-B788-66B4C91D1BAC}" = TLB: System Monitor plugin
"{BD475B03-FA15-4F3D-90EB-78EA3C2CFDFB}_is1" = GIGATweaker
"{C3113E55-7BCB-4de3-8EBF-60E6CE6B2296}_is1" = SiSoftware Sandra Professional Business 2011.SP4c
"{C6F34AE0-0576-11d4-82FE-4491FCC00000}" = IconViewer
"{C74A84EC-7C5F-4C36-A4A6-381E516D643B}" = Microsoft IntelliPoint 7.0
"{C7C58093-FD90-4525-8F0F-BB997FC1DAF4}" = True Launch Bar: Net Monitor plugin
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9F9F1D9-B3F5-4D49-A04C-3CD5BD49BE8F}" = True Launch Bar: Moon Monitor plugin
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE63DE9D-2CBA-4B01-B3CF-FF06497403AD}" = Microangelo Toolset 6 (x64)
"{D237D67F-E77C-4D9E-AA66-8B7A821C215F}" = MFC RunTime files x64
"{D93AC9C8-B6CF-391E-BD2F-48AF4727476C}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30411
"{DC022CBF-9AA5-4757-BA5D-0B3D56DC71EB}" = True Launch Bar: Batch Run plugin
"{E62DC431-1B1F-486F-B6CB-0F53BC161E5B}" = True Launch Bar: Up Time plugin
"{EADB5474-B697-4ECA-A70D-64892805F29A}" = True Launch Bar: TLB Clock plugin
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FC712CA0-A945-11d4-A594-956F6349FC18}" = True Launch Bar
"{FC7B8731-C52D-4CE1-888F-C8999514C37D}" = True Launch Bar: Battery Monitor plugin
"3DB2Cursors" = 3D Blue 2 Animated Cursors
"Agent Ransack (64-bit)_is1" = Agent Ransack 2010 (64-bit)
"Better File Rename_is1" = Better File Rename 5.6
"ClipCache_is1" = ClipCache Pro 3.5.1
"C-Media Oxygen HD Audio Driver" = ASUS Xonar D1 Audio Driver
"EVGA E-LEET TUNING UTILITY_is1" = EVGA E-LEET TUNING UTILITY 1.08.8
"FileMenu Tools_is1" = FileMenu Tools
"LockHunter_is1" = LockHunter version 1.0 beta 3, 64 bit edition
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"NoteBurner_is1" = NoteBurner 2.35
"OSForensics_is1" = OSForensics Beta
"PotPlayer64" = Daum PotPlayer 1.5.29332 x64 Edition
"Process_Hacker2_is1" = Process Hacker 2.15
"RealVNC_is1" = VNC Enterprise Edition E4.6.1
"Registry Workshop" = Registry Workshop
"Revo Uninstaller Pro_is1" = Revo Uninstaller Pro 2.1.1
"Sandboxie" = Sandboxie 3.58 (64-bit)
"sp6" = Logitech SetPoint 6.30
"VNCMirror_is1" = VNC Mirror Driver 1.8.0
"VNCPrinter_is1" = VNC Printer Driver 1.7.0
"Windows Firewall Control" = Windows Firewall Control
"WinRAR archiver" = WinRAR 4.01 (64-bit)
"xplorer2p64" = xplorer² professional 64 bit

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"@icon sushi_is1" = @icon sushi 1.21
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{076B4237-0A24-466F-B5C2-6EE84FEF7C4D}" = Chief Architect Premier X3
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A2A435C-B6F6-4000-B21B-3478B9F8246E}" = Audio Notetaker 2.5
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0EE2BBFD-4AA3-4A27-85F7-9B92805D5138}" = Windows 7 Logon Background Changer
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{156732BC-6E6E-42A7-89C0-E26C97048953}_is1" = Start menu width 1.1.2
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83216018FF}" = Java™ 6 Update 26
"{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1" = ConvertHelper 2.2
"{2AEA17BA-FAB3-49D2-BB85-0669D14DC9BC}_is1" = Rainbow Folders
"{2B2AE80E-E813-4B4C-8418-C627D0A9E132}" = Audio Notetaker Viewer 2.3
"{2FB1052B-2F3D-48CE-A65D-006240516ECE}_is1" = Alternative Flash Player Auto-Updater
"{361000D5-6F06-43A2-8866-F982FFE4E70D}" = Aces High Pilot Stats
"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{4590D323-F7A7-4FD0-B133-956B40FFDD43}" = Xmarks for IE
"{48CABD59-C04D-4AE0-AB05-331787E336E6}" = EMET
"{49471DB8-7F3C-42DB-89C2-AC50FA0C5290}" = Camtasia Studio 7
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{569A1FAB-9304-4F8C-96C4-8ACDB701088C}" = MailWasherPro
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{6FAB7C8A-F677-41D9-8841-62D92B8002DA}" = Extensis Suitcase Fusion 3
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73E80655-FB3C-46F4-BE00-62D248BC490A}" = Visual C++ 2008 Runtime (x64)
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ULTIMATER_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ULTIMATER_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ULTIMATER_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00B2-0409-0000-0000000FF1CE}" = Microsoft Save as PDF or XPS Add-in for 2007 Microsoft Office programs
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_ULTIMATER_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ULTIMATER_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002E-0000-0000-0000000FF1CE}" = Microsoft Office Ultimate 2007
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{944FF102-3AC8-45CF-AAC3-1BB5C2D8DE0A}" = AHII Aircraft Performance
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{A0B0BCE9-2994-36F2-BE66-D23C884372E8}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
"{A11BEF13-58F5-41EE-93AF-C53715A4D83E}_is1" = Vector Clock Pro version 2.10
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3FF5CB2-FB35-4658-8751-9EDE1D65B3AA}" = VMware Workstation
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A7AEC0D9-ADD4-4D18-9FCE-065064E096A0}" = VueMinder Calendar Pro
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AA2EBBCC-4E3B-3442-865E-7BB3E9F45F0C}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AF42897D-4CB6-40AA-B78E-48B927E6A641}" = Returnil System Safe 2011
"{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}" = Google Earth
"{B6164988-AA55-4099-BB9C-EC058210DAD6}" = ImageManager
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C1C910A7-0B89-4260-8845-FE221D9285E8}_is1" = PC Chrono [removed]
"{C3854303-3B65-4254-AD91-46095BA97753}" = ZoomInto
"{C4C6BED7-B068-4C79-B486-5A3846318F6C}" = ShadowProtect Desktop
"{C6ACC864-52AE-44D9-8AAA-20C69AD43267}" = Microsoft Office Labs Search Commands
"{CB92C58B-7BDF-48E3-92E3-51768DCCA585}_is1" = EVGA OC Scanner 1.6.1
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}" = WinZip 12.0
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C0}" = WinZip 15.0
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Professional
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1725D54-279A-40C5-A70D-23C1785DB920}_is1" = AoA Audio Extractor Platinum
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D670F37A-5667-4AD0-A68F-D2343A278341}" = Quick Key
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA9B11CD-46C8-40AD-BC88-8507C64FA8B7}_is1" = Artha 1.0.2.0
"{DF29A0E2-DF76-4932-98A9-34B441F40486}" = Auction Sentry
"{E2C98732-F973-4985-A9C5-DC06178E16EE}" = Microsoft Mathematics Add-in (32-bit)
"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse
"{EAB17EF3-6B6A-4324-8585-E17976E7484C}" = ShadowProtect Desktop
"{EB5BA578-FF7F-3863-8E53-7A003222B7FC}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{EB6C11E5-449C-3BA3-9086-80B18BCFF947}" = Visual C++ 9.0 OpenMP (x86) WinSXS MSM
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"{FCADA4FF-142C-42A8-B73C-0A54A7F83345}" = Perfect Resize 7.0.1 Professional Edition
"{FF0CA85F-BB7D-475C-9836-BAF48AE712FD}_is1" = Liquid Story Binder XE version 4.93
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"8E94BAD3-BBE4-4C3A-BC8B-D07B4EEDEEEC_is1" = GumNotes version 1.3.1.740
"AC3Filter_is1" = AC3Filter 1.63b
"Aces High" = Aces High
"Ad Muncher" = Ad Muncher v4.92 Build 32700
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Afterburner" = MSI Afterburner 2.1.0
"AoA DVD Ripper_is1" = AoA DVD Ripper
"Ashampoo Snap 4_is1" = Ashampoo Snap 4 v.4.3.0
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Auto Mailer" = Auto Mailer
"avast" = avast! Free Antivirus
"avi.NET 3.4.0.0" = avi.NET 3.4.0.0
"AviSynth" = AviSynth 2.5
"BattlEye" = BattlEye Uninstall
"BeyondCompare3_is1" = Beyond Compare Version 3.3.1
"BitMeter" = BitMeter
"BitTorrent" = BitTorrent
"CamStudio" = CamStudio
"Celestia_is1" = Celestia 1.6.0
"Chameleon Startup Manager 3" = Chameleon Startup Manager 3.4.0.760
"Chameleon Task Manager 3" = Chameleon Task Manager 3.1.0.430
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Converber" = Converber 2.1.0
"CursorWorkshop" = Axialis CursorWorkshop 6.33
"DeskPins" = DeskPins (remove only)
"Digsby" = Digsby
"Directory Lister Pro_is1" = Directory Lister Pro v1.40
"DriverCleanerDotNET" = Driver Cleaner.NET
"DVD Shrink_is1" = DVD Shrink 3.2
"DVDFab 8 Qt_is1" = DVDFab 8.0.8.8 Beta (22/04/2011) Qt
"Energy Costs Calculator_is1" = Energy Costs Calculator 1.1.7
"EVEREST Ultimate Edition_is1" = EVEREST Ultimate Edition v5.30
"Exact Audio Copy" = Exact Audio Copy 1.0beta2
"Fences" = Fences
"Flash Renamer 5.05_is1" = Flash Renamer 5.05
"Flashnote" = Flashnote 3.6
"Flv Audio Video Extractor_is1" = Flv Audio Video Extractor 2.0
"FLV Player" = FLV Player 2.0 (build 25)
"FolderJump" = FolderJump Full 2.0.0.20
"foobar2000" = foobar2000 v1.1.6
"Forte Agent" = Forté Agent
"Fraps" = Fraps (remove only)
"FreeFixer0.58" = FreeFixer
"Freez 3GP Video Converter_is1" = Freez 3GP Video Converter 2.0
"Freez FLV to AVI/MPEG/WMV Converter v1.6_is1" = Freez FLV to AVI/MPEG/WMV Converter
"Freez Screen Video Capture v1.2_is1" = Freez Screen Video Capture v1.2
"GetDiz 3.0" = GetDiz 3.0
"GOM Player" = GOM Player
"HD Tune Pro_is1" = HD Tune Pro 4.60
"Icon Converter Plus" = Icon Converter Plus
"IconsExtract" = IconsExtract
"IconWorkshop " = Axialis IconWorkshop 6.52
"ieSpell" = ieSpell
"ImgBurn" = ImgBurn
"ImmersEd" = ImmersEd
"Impulse" = Impulse
"InstallShield_{F232C87C-6E92-4775-8210-DFE90B7777D9}" = CyberLink PowerDVD 11
"IrfanView" = IrfanView (remove only)
"jv16 PowerTools 2011" = jv16 PowerTools 2011
"KTbWorks" = Kensington TrackballWorks
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"Linkman" = Linkman Pro
"LinX" = LinX
"MainType2_is1" = MainType 2.1.1
"MainType3_is1" = High-Logic MainType 3.0
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.1.1800
"Maxthon2" = Maxthon2
"Maxthon3" = Maxthon 3
"Milkdrop Preset Pack" = Milkdrop Preset Pack
"Mobysaurus Thesaurus" = Mobysaurus Thesaurus
"MoffCalc2_is1" = Moffsoft Calculator 2
"Mozilla Firefox 6.0.2 (x86 en-US)" = Mozilla Firefox 6.0.2 (x86 en-US)
"NoIPDUC" = No-IP DUC
"NoteZilla_is1" = NoteZilla 7.0
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"ObjectDock Plus 2" = ObjectDock Plus 2
"OpenAL" = OpenAL
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"PFConfig" = PFConfig 1.0.296
"Picasa 3" = Picasa 3
"Pidgin" = Pidgin
"POP Peeper" = POP Peeper
"PowerCmd_is1" = PowerCmd 2.2
"PowerStrip 3 (remove only)" = PowerStrip 3 (remove only)
"Precision" = EVGA Precision 2.0.3
"PrintFolder Pro 3.3_is1" = PrintFolder Pro
"ProcessLasso" = Process Lasso
"QuicktimeAlt_is1" = QuickTime Alternative 3.1.1
"Rainlendar2" = Rainlendar2 (remove only)
"Rainmeter" = Rainmeter
"RealAlt_is1" = Real Alternative 2.0.1
"RecentX_is1" = RecentX 3.0
"Recomposit_is1" = Recomposit 2.1
"Recover My Files_is1" = Recover My Files
"ReNamer_is1" = ReNamer
"Rhymesaurus_is1" = Rhymesaurus (2.0.1)
"RocketDock_is1" = RocketDock 1.3.5
"RSS" = Returnil System Safe 2011
"Screen Calipers" = Screen Calipers
"Screen Compass" = Screen Compass
"Screen Protractor" = Screen Protractor
"ScreenSteps_is1" = ScreenSteps 2.9
"Security Task Manager" = Security Task Manager 1.8c
"Shareaza_is1" = Shareaza [removed]
"Sharp World Clock_is1" = Sharp World Clock 5.33
"Six Updater Suite" = Six Updater Suite
"Smart FLV Converter Pro_is1" = Smart FLV Converter Pro 3.0
"Smart Type Assistant 1.0" = Smart Type Assistant
"SpeedFan" = SpeedFan (remove only)
"Steam App 24960" = Battlefield: Bad Company 2
"Steam App 2780" = ARMA: Armed Assault
"Steam App 33900" = ARMA II
"Steam App 440" = Team Fortress 2
"Stellarium_is1" = Stellarium 0.10.6.1
"Stuf 2.06" = Stuf 2.06
"SyncBackSE_is1" = SyncBackSE
"Teamspeak 2 RC2_is1" = TeamSpeak 2 RC2
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"TeamViewer 6" = TeamViewer 6
"textBEAST Pro clipboard+_is1" = textBEAST Pro clipboard+ 3.0
"The KMPlayer" = The KMPlayer (remove only)
"Toolbar Cleaner" = Toolbar Cleaner 1.0
"Total Uninstall 5 RU-BOARD VERSION_is1" = Total Uninstall 5.9.2
"Total Uninstall 5_is1" = Total Uninstall 5.9.3
"Total Video Converter 3.61_is1" = Total Video Converter 3.60 100204
"TreeSize Professional_is1" = TreeSize Professional V5.5
"Trillian" = Trillian
"TweakNow PowerPack 2011 SP1_is1" = TweakNow PowerPack 2011 SP1
"TweakUAC_is1" = TweakUAC
"ULTIMATER" = Microsoft Office Ultimate 2007
"Unigine Heaven DX11 Benchmark 2.5_is1" = Unigine Heaven DX11 Benchmark 2.5 version 2.5
"Universal Extractor_is1" = Universal Extractor 1.6.1
"UnzipThemAll_is1" = UnzipThemAll 1.3
"Virtual Hypnotist" = Virtual Hypnotist 5.8
"vis_milk.dllWinamp" = MilkDrop for Winamp 2x (remove only)
"VLC media player" = VLC media player 1.1.11
"VMware_Workstation" = VMware Workstation
"VobSub" = VobSub v2.23 (Remove Only)
"Weather Pulse [removed]" = Weather Pulse [removed]
"Winamp" = Winamp
"WinAVI Video Converter 10.1_is1" = WinAVI Video Converter
"WinPcapInst" = WinPcap 4.1.1
"Winstep Xtreme_is1" = Winstep Xtreme 11.2
"WM Recorder 14" = WM Recorder 14
"WordWeb" = WordWeb Pro
"XdN Tweaker" = XdN Tweaker 0.9.2.6
"Xilisoft Audio Converter Pro" = Xilisoft Audio Converter Pro
"Xilisoft DVD Copy Express" = Xilisoft DVD Copy Express
"Xilisoft DVD Creator 6" = Xilisoft DVD Creator 6
"Xilisoft DVD Ripper Ultimate 6" = Xilisoft DVD Ripper Ultimate 6
"Xilisoft HD Video Converter 6" = Xilisoft HD Video Converter 6
"Xilisoft Video Converter Ultimate 6" = Xilisoft Video Converter Ultimate 6
"xqdcXSP_is1" = XQDC X-Setup Pro 9.2.100
"Xvid_is1" = Xvid 1.2.2 final uninstall
"yBook_is1" = yBook
"Zentimo PRO_is1" = Zentimo PRO 1.3
"ZhornStickies" = Stickies 7.1a

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"7 Taskbar Tweaker" = 7 Taskbar Tweaker v2.0
"AI RoboForm" = RoboForm 7-4-2
"Divvy" = Divvy
"Google Chrome" = Google Chrome
"Winamp Detect" = Winamp Detector Plug-in

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 09/11/2011 06:20:11 AM | Computer Name = Blackhole | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 09/11/2011 09:38:27 PM | Computer Name = Blackhole | Source = Application Error | ID = 1000
Description = Faulting application name: OUTLOOK.EXE, version: 12.0.4518.1014, time
stamp: 0x4542840f Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc0000005 Fault offset: 0x07997d22 Faulting process id: 0x1f98 Faulting application
start time: 0x01cc6fd49cdc2fb2 Faulting application path: C:\Program Files (x86)\Microsoft
Office\Office12\OUTLOOK.EXE Faulting module path: unknown Report Id: e9387918-dcdf-11e0-9b63-005056c00008

Error - 09/12/2011 02:04:34 AM | Computer Name = Blackhole | Source = vmauthd | ID = 100
Description = Cannot find perfmon object in array returned by perfDLL, index=0

Error - 09/12/2011 03:31:16 AM | Computer Name = Blackhole | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 09/12/2011 03:08:50 PM | Computer Name = Blackhole | Source = vmauthd | ID = 100
Description = Cannot find perfmon object in array returned by perfDLL, index=0

Error - 09/13/2011 03:12:24 AM | Computer Name = Blackhole | Source = Application Error | ID = 1000
Description = Faulting application name: POPPeeper.exe, version: 3.8.0.0, time stamp:
0x4e4d1c23 Faulting module name: WININET.dll, version: 9.0.8112.16434, time stamp:
0x4e28e4f3 Exception code: 0xc0000005 Fault offset: 0x00027a9b Faulting process id:
0x844 Faulting application start time: 0x01cc71e47b11011c Faulting application path:
C:\Program Files (x86)\POP Peeper\POPPeeper.exe Faulting module path: C:\Windows\syswow64\WININET.dll
Report
Id: baa1a4fb-ddd7-11e0-abec-005056c00008

Error - 09/13/2011 07:21:56 AM | Computer Name = Blackhole | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 09/14/2011 03:10:44 AM | Computer Name = Blackhole | Source = Application Error | ID = 1000
Description = Faulting application name: OUTLOOK.EXE, version: 12.0.4518.1014, time
stamp: 0x4542840f Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception
code: 0xc000041d Fault offset: 0x750a4f0d Faulting process id: 0x1630 Faulting application
start time: 0x01cc72485855996b Faulting application path: C:\Program Files (x86)\Microsoft
Office\Office12\OUTLOOK.EXE Faulting module path: unknown Report Id: a8dd357b-dea0-11e0-abec-005056c00008

Error - 09/14/2011 06:45:05 AM | Computer Name = Blackhole | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 09/14/2011 06:00:34 PM | Computer Name = Blackhole | Source = VSS | ID = 12293
Description =

[ OSession Events ]
Error - 08/29/2011 02:41:06 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 85860
seconds with 1920 seconds of active time. This session ended with a crash.

Error - 08/31/2011 05:14:13 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 16415
seconds with 540 seconds of active time. This session ended with a crash.

Error - 09/01/2011 03:14:58 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 9175
seconds with 420 seconds of active time. This session ended with a crash.

Error - 09/03/2011 06:18:49 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 20098
seconds with 240 seconds of active time. This session ended with a crash.

Error - 09/05/2011 01:00:03 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 40924
seconds with 480 seconds of active time. This session ended with a crash.

Error - 09/06/2011 11:18:44 PM | Computer Name = Blackhole | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 78016
seconds with 1620 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 07/04/2011 07:28:28 AM | Computer Name = Blackhole | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Performance power management features on processor 7 in group 0 are
disabled due to a firmware problem. Check with the computer manufacturer for updated
firmware.

Error - 07/04/2011 07:28:28 AM | Computer Name = Blackhole | Source = Microsoft-Windows-Kernel-Processor-Power | ID = 35
Description = Performance power management features on processor 1 in group 0 are
disabled due to a firmware problem. Check with the computer manufacturer for updated
firmware.

Error - 07/04/2011 07:28:46 AM | Computer Name = Blackhole | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
SABKUTIL

Error - 07/04/2011 07:30:28 AM | Computer Name = Blackhole | Source = WMPNetworkSvc | ID = 866292
Description =

Error - 07/04/2011 07:30:58 AM | Computer Name = Blackhole | Source = WMPNetworkSvc | ID = 866292
Description =

Error - 07/04/2011 07:30:57 AM | Computer Name = Blackhole | Source = Service Control Manager | ID = 7024
Description = The HomeGroup Listener service terminated with service-specific error
%%-2147467262.

Error - 07/04/2011 07:31:35 AM | Computer Name = Blackhole | Source = Service Control Manager | ID = 7034
Description = The Kensington TrackballWorks Service service terminated unexpectedly.
It has done this 1 time(s).

Error - 07/04/2011 07:58:56 AM | Computer Name = Blackhole | Source = WMPNetworkSvc | ID = 866292
Description =

Error - 07/04/2011 07:58:56 AM | Computer Name = Blackhole | Source = WMPNetworkSvc | ID = 866292
Description =

Error - 07/05/2011 06:28:56 AM | Computer Name = Blackhole | Source = WMPNetworkSvc | ID = 866292
Description =


< End of report >


Thanks:)
Hi silat,

:welcome:

My name is Tomk. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

BitTorrent
You have BitTorrent, a P2P/file sharing programs installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.

References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm://http://www.techweb.com/wire/1605005…cles/art053.htm


I would recommend that you uninstall BitTorrent, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.

If you wish to keep it, please do not use it until your computer is cleaned.

Suddenly when I use favorites in Firefox one of the tabs opens www.juego.com/

What should open?

Download ComboFix from one of these locations:

Link 1
Link 2
Link 3

* IMPORTANT !!! Save ComboFix.exe to your Desktop



**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.


Notes:

1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI