This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe/System Idle Process Taking Up CPU

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, I've only just discovered this today but I happen to be running two Ping.exe processes, both of which take up some portion of my CPU. One is usually low, but the other is very high. Also, for some reason this seems to be alternating with the system idle process, so whenever it's not one ping.exe taking up 75% it's the system idle process instead with another ping.exe taking up the remaining 25%.

One thing to note is that my system doesn't seem to be running any slower, even when I run videogames.

Anyway, here are the HijackThis logs, as per your instructions.


Running processes:
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
C:\Users\Andrei\AppData\Local\Google\Update\1.3.21.69\GoogleCrashHandler.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Andrei\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallati…a4740bca56f572b
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Update] "C:\Users\Andrei\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [OpenDNS Updater] "C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" /autostart
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" -automount
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{E40B5D32-70B5-4A5B-83A0-972193EEAD2E}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: TeknoGods.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASDR - Unknown owner - C:\Windows\SysWOW64\ASDR.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Performance Service (nTuneService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - StarWind Software - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Games\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Update Center Service (UpdateCenterService) - NVIDIA - C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe

–
End of file - 9376 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)










  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lnk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Desktop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    %systemroot%\AppPatch\Custom\*.*
    %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
    %PROGRAMFILES%\PC-Doctor\Downloads\*.*
    %PROGRAMFILES%\Internet Explorer\*.tmp
    %PROGRAMFILES%\Internet Explorer\*.dat
    %USERPROFILE%\My Documents\*.exe
    %USERPROFILE%\*.exe
    %systemroot%\ADDINS\*.*
    %systemroot%\assembly\*.bak2
    %systemroot%\Config\*.*
    %systemroot%\REPAIR\*.bak2
    %systemroot%\SECURITY\Database\*.sdb /x
    %systemroot%\SYSTEM\*.bak2
    %systemroot%\Web\*.bak2
    %systemroot%\Driver Cache\*.*
    %PROGRAMFILES%\Mozilla Firefox\0*.exe
    %ProgramFiles%\Microsoft Common\*.*
    %ProgramFiles%\TinyProxy.
    %USERPROFILE%\Favorites\*.url /x
    %systemroot%\system32\*.bk
    %systemroot%\*.te
    %systemroot%\system32\system32\*.*
    %ALLUSERSPROFILE%\*.dat /x
    %systemroot%\system32\drivers\*.rmv
    dir /b "%systemroot%\system32\*.exe" | find /i " " /c
    dir /b "%systemroot%\*.exe" | find /i " " /c
    %PROGRAMFILES%\Microsoft\*.*
    %systemroot%\System32\Wbem\proquota.exe
    %PROGRAMFILES%\Mozilla Firefox\*.dat
    %USERPROFILE%\Cookies\*.txt /x
    %SystemRoot%\system32\fonts\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thank you for assistance.

TDSSKiller logs:

17:05:27.0828 1428 TDSS rootkit removing tool [removed] Sep 26 2011 09:21:32
17:05:28.0110 1428 ============================================================
17:05:28.0110 1428 Current date / time: 2011/09/26 17:05:28.0110
17:05:28.0110 1428 SystemInfo:
17:05:28.0110 1428
17:05:28.0110 1428 OS Version: 6.1.7600 ServicePack: 0.0
17:05:28.0110 1428 Product type: Workstation
17:05:28.0111 1428 ComputerName: MAINDESKTOP
17:05:28.0111 1428 UserName: Andrei
17:05:28.0111 1428 Windows directory: C:\Windows
17:05:28.0111 1428 System windows directory: C:\Windows
17:05:28.0111 1428 Running under WOW64
17:05:28.0111 1428 Processor architecture: Intel x64
17:05:28.0111 1428 Number of processors: 4
17:05:28.0111 1428 Page size: 0x1000
17:05:28.0111 1428 Boot type: Normal boot
17:05:28.0111 1428 ============================================================
17:05:28.0913 1428 Initialize success
17:05:44.0137 4856 ============================================================
17:05:44.0137 4856 Scan started
17:05:44.0137 4856 Mode: Manual;
17:05:44.0137 4856 ============================================================
17:05:44.0405 4856 1394ohci (1b00662092f9f9568b995902f0cc40d5) C:\Windows\system32\DRIVERS\1394ohci.sys
17:05:44.0408 4856 1394ohci - ok
17:05:44.0458 4856 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\Windows\system32\DRIVERS\ACPI.sys
17:05:44.0463 4856 ACPI - ok
17:05:44.0523 4856 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\Windows\system32\DRIVERS\acpipmi.sys
17:05:44.0524 4856 AcpiPmi - ok
17:05:44.0611 4856 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\Windows\system32\DRIVERS\adp94xx.sys
17:05:44.0618 4856 adp94xx - ok
17:05:44.0670 4856 adpahci (597f78224ee9224ea1a13d6350ced962) C:\Windows\system32\DRIVERS\adpahci.sys
17:05:44.0676 4856 adpahci - ok
17:05:44.0725 4856 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\Windows\system32\DRIVERS\adpu320.sys
17:05:44.0728 4856 adpu320 - ok
17:05:44.0800 4856 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\Windows\system32\drivers\afd.sys
17:05:44.0817 4856 AFD - ok
17:05:44.0870 4856 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\Windows\system32\DRIVERS\agp440.sys
17:05:44.0871 4856 agp440 - ok
17:05:44.0938 4856 aliide (5812713a477a3ad7363c7438ca2ee038) C:\Windows\system32\DRIVERS\aliide.sys
17:05:44.0939 4856 aliide - ok
17:05:44.0995 4856 amdide (1ff8b4431c353ce385c875f194924c0c) C:\Windows\system32\DRIVERS\amdide.sys
17:05:44.0996 4856 amdide - ok
17:05:45.0057 4856 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\Windows\system32\DRIVERS\amdk8.sys
17:05:45.0058 4856 AmdK8 - ok
17:05:45.0110 4856 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\Windows\system32\DRIVERS\amdppm.sys
17:05:45.0111 4856 AmdPPM - ok
17:05:45.0161 4856 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\Windows\system32\drivers\amdsata.sys
17:05:45.0163 4856 amdsata - ok
17:05:45.0225 4856 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\Windows\system32\DRIVERS\amdsbs.sys
17:05:45.0229 4856 amdsbs - ok
17:05:45.0276 4856 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\Windows\system32\drivers\amdxata.sys
17:05:45.0277 4856 amdxata - ok
17:05:45.0342 4856 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\Windows\system32\drivers\appid.sys
17:05:45.0344 4856 AppID - ok
17:05:45.0425 4856 arc (c484f8ceb1717c540242531db7845c4e) C:\Windows\system32\DRIVERS\arc.sys
17:05:45.0427 4856 arc - ok
17:05:45.0465 4856 arcsas (019af6924aefe7839f61c830227fe79c) C:\Windows\system32\DRIVERS\arcsas.sys
17:05:45.0467 4856 arcsas - ok
17:05:45.0499 4856 AsIO - ok
17:05:45.0525 4856 AsUpIO - ok
17:05:45.0595 4856 asusgsb (a4398a8914c32f18ec2ab562cba3caaf) C:\Windows\system32\drivers\asusgsb.sys
17:05:45.0603 4856 asusgsb - ok
17:05:45.0679 4856 AsyncMac (769765ce2cc62867468cea93969b2242) C:\Windows\system32\DRIVERS\asyncmac.sys
17:05:45.0681 4856 AsyncMac - ok
17:05:45.0734 4856 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\Windows\system32\DRIVERS\atapi.sys
17:05:45.0735 4856 atapi - ok
17:05:45.0814 4856 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\Windows\system32\DRIVERS\bxvbda.sys
17:05:45.0821 4856 b06bdrv - ok
17:05:45.0883 4856 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\Windows\system32\DRIVERS\b57nd60a.sys
17:05:45.0887 4856 b57nd60a - ok
17:05:45.0947 4856 Beep (16a47ce2decc9b099349a5f840654746) C:\Windows\system32\drivers\Beep.sys
17:05:45.0949 4856 Beep - ok
17:05:46.0019 4856 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\Windows\system32\DRIVERS\blbdrive.sys
17:05:46.0020 4856 blbdrive - ok
17:05:46.0085 4856 bowser (19d20159708e152267e53b66677a4995) C:\Windows\system32\DRIVERS\bowser.sys
17:05:46.0087 4856 bowser - ok
17:05:46.0160 4856 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\Windows\system32\DRIVERS\BrFiltLo.sys
17:05:46.0162 4856 BrFiltLo - ok
17:05:46.0208 4856 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\Windows\system32\DRIVERS\BrFiltUp.sys
17:05:46.0209 4856 BrFiltUp - ok
17:05:46.0259 4856 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\Windows\System32\Drivers\Brserid.sys
17:05:46.0259 4856 Brserid - ok
17:05:46.0310 4856 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\Windows\System32\Drivers\BrSerWdm.sys
17:05:46.0311 4856 BrSerWdm - ok
17:05:46.0363 4856 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\Windows\System32\Drivers\BrUsbMdm.sys
17:05:46.0364 4856 BrUsbMdm - ok
17:05:46.0397 4856 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\Windows\System32\Drivers\BrUsbSer.sys
17:05:46.0398 4856 BrUsbSer - ok
17:05:46.0455 4856 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\Windows\system32\DRIVERS\bthmodem.sys
17:05:46.0456 4856 BTHMODEM - ok
17:05:46.0520 4856 cdfs (b8bd2bb284668c84865658c77574381a) C:\Windows\system32\DRIVERS\cdfs.sys
17:05:46.0522 4856 cdfs - ok
17:05:46.0592 4856 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\Windows\system32\DRIVERS\cdrom.sys
17:05:46.0595 4856 cdrom - ok
17:05:46.0658 4856 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\Windows\system32\DRIVERS\circlass.sys
17:05:46.0659 4856 circlass - ok
17:05:46.0735 4856 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\Windows\system32\CLFS.sys
17:05:46.0740 4856 CLFS - ok
17:05:46.0828 4856 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\Windows\system32\DRIVERS\CmBatt.sys
17:05:46.0829 4856 CmBatt - ok
17:05:46.0863 4856 cmdide (e19d3f095812725d88f9001985b94edd) C:\Windows\system32\DRIVERS\cmdide.sys
17:05:46.0865 4856 cmdide - ok
17:05:46.0922 4856 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\Windows\system32\Drivers\cng.sys
17:05:46.0928 4856 CNG - ok
17:05:46.0972 4856 Compbatt (102de219c3f61415f964c88e9085ad14) C:\Windows\system32\DRIVERS\compbatt.sys
17:05:46.0973 4856 Compbatt - ok
17:05:47.0020 4856 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\Windows\system32\DRIVERS\CompositeBus.sys
17:05:47.0021 4856 CompositeBus - ok
17:05:47.0063 4856 crcdisk (1c827878a998c18847245fe1f34ee597) C:\Windows\system32\DRIVERS\crcdisk.sys
17:05:47.0064 4856 crcdisk - ok
17:05:47.0136 4856 DfsC (9c253ce7311ca60fc11c774692a13208) C:\Windows\system32\Drivers\dfsc.sys
17:05:47.0138 4856 DfsC - ok
17:05:47.0175 4856 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\Windows\system32\drivers\discache.sys
17:05:47.0176 4856 discache - ok
17:05:47.0245 4856 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\Windows\system32\DRIVERS\disk.sys
17:05:47.0247 4856 Disk - ok
17:05:47.0329 4856 drmkaud (9b19f34400d24df84c858a421c205754) C:\Windows\system32\drivers\drmkaud.sys
17:05:47.0329 4856 drmkaud - ok
17:05:47.0408 4856 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\Windows\System32\drivers\dxgkrnl.sys
17:05:47.0413 4856 DXGKrnl - ok
17:05:47.0706 4856 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\Windows\system32\DRIVERS\evbda.sys
17:05:47.0799 4856 ebdrv - ok
17:05:47.0893 4856 EIO64 (343ada10d948db29251f2d9c809af204) C:\Windows\system32\DRIVERS\EIO64.sys
17:05:47.0894 4856 EIO64 - ok
17:05:48.0008 4856 elxstor (0e5da5369a0fcaea12456dd852545184) C:\Windows\system32\DRIVERS\elxstor.sys
17:05:48.0016 4856 elxstor - ok
17:05:48.0086 4856 ErrDev (34a3c54752046e79a126e15c51db409b) C:\Windows\system32\DRIVERS\errdev.sys
17:05:48.0087 4856 ErrDev - ok
17:05:48.0143 4856 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\Windows\system32\drivers\exfat.sys
17:05:48.0146 4856 exfat - ok
17:05:48.0201 4856 fastfat (0adc83218b66a6db380c330836f3e36d) C:\Windows\system32\drivers\fastfat.sys
17:05:48.0204 4856 fastfat - ok
17:05:48.0256 4856 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\Windows\system32\DRIVERS\fdc.sys
17:05:48.0257 4856 fdc - ok
17:05:48.0306 4856 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\Windows\system32\drivers\fileinfo.sys
17:05:48.0308 4856 FileInfo - ok
17:05:48.0348 4856 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\Windows\system32\drivers\filetrace.sys
17:05:48.0349 4856 Filetrace - ok
17:05:48.0389 4856 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\Windows\system32\DRIVERS\flpydisk.sys
17:05:48.0389 4856 flpydisk - ok
17:05:48.0452 4856 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\Windows\system32\drivers\fltmgr.sys
17:05:48.0456 4856 FltMgr - ok
17:05:48.0511 4856 FsDepends (d43703496149971890703b4b1b723eac) C:\Windows\system32\drivers\FsDepends.sys
17:05:48.0512 4856 FsDepends - ok
17:05:48.0556 4856 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\Windows\system32\drivers\Fs_Rec.sys
17:05:48.0558 4856 Fs_Rec - ok
17:05:48.0622 4856 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\Windows\system32\DRIVERS\fvevol.sys
17:05:48.0626 4856 fvevol - ok
17:05:48.0679 4856 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\Windows\system32\DRIVERS\gagp30kx.sys
17:05:48.0681 4856 gagp30kx - ok
17:05:48.0739 4856 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\Windows\system32\DRIVERS\GEARAspiWDM.sys
17:05:48.0740 4856 GEARAspiWDM - ok
17:05:48.0808 4856 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\Windows\system32\DRIVERS\hamachi.sys
17:05:48.0811 4856 hamachi - ok
17:05:48.0859 4856 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\Windows\system32\drivers\hcw85cir.sys
17:05:48.0860 4856 hcw85cir - ok
17:05:48.0932 4856 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\Windows\system32\drivers\HdAudio.sys
17:05:48.0936 4856 HdAudAddService - ok
17:05:49.0013 4856 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\Windows\system32\DRIVERS\HDAudBus.sys
17:05:49.0014 4856 HDAudBus - ok
17:05:49.0054 4856 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\Windows\system32\DRIVERS\HidBatt.sys
17:05:49.0055 4856 HidBatt - ok
17:05:49.0099 4856 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\Windows\system32\DRIVERS\hidbth.sys
17:05:49.0101 4856 HidBth - ok
17:05:49.0154 4856 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\Windows\system32\DRIVERS\hidir.sys
17:05:49.0156 4856 HidIr - ok
17:05:49.0205 4856 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\Windows\system32\DRIVERS\hidusb.sys
17:05:49.0206 4856 HidUsb - ok
17:05:49.0254 4856 HpSAMD (0886d440058f203eba0e1825e4355914) C:\Windows\system32\DRIVERS\HpSAMD.sys
17:05:49.0256 4856 HpSAMD - ok
17:05:49.0315 4856 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\Windows\system32\drivers\HTTP.sys
17:05:49.0333 4856 HTTP - ok
17:05:49.0367 4856 hwpolicy (f17766a19145f111856378df337a5d79) C:\Windows\system32\drivers\hwpolicy.sys
17:05:49.0368 4856 hwpolicy - ok
17:05:49.0451 4856 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\Windows\system32\DRIVERS\i8042prt.sys
17:05:49.0453 4856 i8042prt - ok
17:05:49.0518 4856 iaStorV (b75e45c564e944a2657167d197ab29da) C:\Windows\system32\drivers\iaStorV.sys
17:05:49.0523 4856 iaStorV - ok
17:05:49.0595 4856 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\Windows\system32\DRIVERS\iirsp.sys
17:05:49.0597 4856 iirsp - ok
17:05:49.0645 4856 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\Windows\system32\DRIVERS\intelide.sys
17:05:49.0646 4856 intelide - ok
17:05:49.0711 4856 intelppm (ada036632c664caa754079041cf1f8c1) C:\Windows\system32\DRIVERS\intelppm.sys
17:05:49.0712 4856 intelppm - ok
17:05:49.0787 4856 IOMap (a01c412699b6f21645b2885c2bae4454) C:\Windows\system32\drivers\IOMap64.sys
17:05:49.0788 4856 IOMap - ok
17:05:49.0846 4856 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\Windows\system32\DRIVERS\ipfltdrv.sys
17:05:49.0848 4856 IpFilterDriver - ok
17:05:49.0898 4856 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\Windows\system32\DRIVERS\IPMIDrv.sys
17:05:49.0900 4856 IPMIDRV - ok
17:05:49.0952 4856 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\Windows\system32\drivers\ipnat.sys
17:05:49.0966 4856 IPNAT - ok
17:05:50.0019 4856 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\Windows\system32\drivers\irenum.sys
17:05:50.0020 4856 IRENUM - ok
17:05:50.0061 4856 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\Windows\system32\DRIVERS\isapnp.sys
17:05:50.0062 4856 isapnp - ok
17:05:50.0136 4856 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\Windows\system32\DRIVERS\msiscsi.sys
17:05:50.0139 4856 iScsiPrt - ok
17:05:50.0199 4856 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\Windows\system32\DRIVERS\kbdclass.sys
17:05:50.0200 4856 kbdclass - ok
17:05:50.0253 4856 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\Windows\system32\DRIVERS\kbdhid.sys
17:05:50.0254 4856 kbdhid - ok
17:05:50.0301 4856 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\Windows\system32\Drivers\ksecdd.sys
17:05:50.0303 4856 KSecDD - ok
17:05:50.0347 4856 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\Windows\system32\Drivers\ksecpkg.sys
17:05:50.0350 4856 KSecPkg - ok
17:05:50.0426 4856 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\Windows\system32\drivers\ksthunk.sys
17:05:50.0427 4856 ksthunk - ok
17:05:50.0506 4856 Lbd (3c46290f7a5d45ba6ef32c248e22aa69) C:\Windows\system32\DRIVERS\Lbd.sys
17:05:50.0516 4856 Lbd - ok
17:05:50.0593 4856 lltdio (1538831cf8ad2979a04c423779465827) C:\Windows\system32\DRIVERS\lltdio.sys
17:05:50.0595 4856 lltdio - ok
17:05:50.0663 4856 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\Windows\system32\DRIVERS\lsi_fc.sys
17:05:50.0665 4856 LSI_FC - ok
17:05:50.0704 4856 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\Windows\system32\DRIVERS\lsi_sas.sys
17:05:50.0706 4856 LSI_SAS - ok
17:05:50.0750 4856 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\Windows\system32\DRIVERS\lsi_sas2.sys
17:05:50.0752 4856 LSI_SAS2 - ok
17:05:50.0809 4856 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\Windows\system32\DRIVERS\lsi_scsi.sys
17:05:50.0812 4856 LSI_SCSI - ok
17:05:50.0867 4856 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\Windows\system32\drivers\luafv.sys
17:05:50.0869 4856 luafv - ok
17:05:50.0912 4856 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\Windows\system32\DRIVERS\megasas.sys
17:05:50.0913 4856 megasas - ok
17:05:50.0976 4856 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\Windows\system32\DRIVERS\MegaSR.sys
17:05:50.0981 4856 MegaSR - ok
17:05:51.0020 4856 Modem (800ba92f7010378b09f9ed9270f07137) C:\Windows\system32\drivers\modem.sys
17:05:51.0021 4856 Modem - ok
17:05:51.0090 4856 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\Windows\system32\DRIVERS\monitor.sys
17:05:51.0090 4856 monitor - ok
17:05:51.0131 4856 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\Windows\system32\DRIVERS\mouclass.sys
17:05:51.0132 4856 mouclass - ok
17:05:51.0184 4856 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\Windows\system32\DRIVERS\mouhid.sys
17:05:51.0185 4856 mouhid - ok
17:05:51.0227 4856 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\Windows\system32\drivers\mountmgr.sys
17:05:51.0229 4856 mountmgr - ok
17:05:51.0303 4856 MpFilter (c177a7ebf5e8a0b596f618870516cab8) C:\Windows\system32\DRIVERS\MpFilter.sys
17:05:51.0304 4856 MpFilter - ok
17:05:51.0370 4856 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\Windows\system32\DRIVERS\mpio.sys
17:05:51.0373 4856 mpio - ok
17:05:51.0435 4856 MpNWMon (8fbf6b31fe8af1833d93c5913d5b4d55) C:\Windows\system32\DRIVERS\MpNWMon.sys
17:05:51.0435 4856 MpNWMon - ok
17:05:51.0475 4856 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\Windows\system32\drivers\mpsdrv.sys
17:05:51.0477 4856 mpsdrv - ok
17:05:51.0521 4856 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\Windows\system32\drivers\mrxdav.sys
17:05:51.0524 4856 MRxDAV - ok
17:05:51.0578 4856 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\Windows\system32\DRIVERS\mrxsmb.sys
17:05:51.0578 4856 mrxsmb - ok
17:05:51.0618 4856 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\Windows\system32\DRIVERS\mrxsmb10.sys
17:05:51.0618 4856 mrxsmb10 - ok
17:05:51.0666 4856 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\Windows\system32\DRIVERS\mrxsmb20.sys
17:05:51.0668 4856 mrxsmb20 - ok
17:05:51.0715 4856 msahci (5c37497276e3b3a5488b23a326a754b7) C:\Windows\system32\DRIVERS\msahci.sys
17:05:51.0716 4856 msahci - ok
17:05:51.0768 4856 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\Windows\system32\DRIVERS\msdsm.sys
17:05:51.0771 4856 msdsm - ok
17:05:51.0821 4856 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\Windows\system32\drivers\Msfs.sys
17:05:51.0822 4856 Msfs - ok
17:05:51.0857 4856 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\Windows\System32\drivers\mshidkmdf.sys
17:05:51.0858 4856 mshidkmdf - ok
17:05:51.0904 4856 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\Windows\system32\DRIVERS\msisadrv.sys
17:05:51.0905 4856 msisadrv - ok
17:05:51.0979 4856 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\Windows\system32\drivers\MSKSSRV.sys
17:05:51.0980 4856 MSKSSRV - ok
17:05:52.0043 4856 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\Windows\system32\drivers\MSPCLOCK.sys
17:05:52.0044 4856 MSPCLOCK - ok
17:05:52.0089 4856 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\Windows\system32\drivers\MSPQM.sys
17:05:52.0090 4856 MSPQM - ok
17:05:52.0143 4856 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\Windows\system32\drivers\MsRPC.sys
17:05:52.0148 4856 MsRPC - ok
17:05:52.0195 4856 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\Windows\system32\DRIVERS\mssmbios.sys
17:05:52.0196 4856 mssmbios - ok
17:05:52.0235 4856 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\Windows\system32\drivers\MSTEE.sys
17:05:52.0236 4856 MSTEE - ok
17:05:52.0277 4856 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\Windows\system32\DRIVERS\MTConfig.sys
17:05:52.0278 4856 MTConfig - ok
17:05:52.0353 4856 MTsensor (19b006b181e3875fd254f7b67acf1e7c) C:\Windows\system32\DRIVERS\ASACPI.sys
17:05:52.0353 4856 MTsensor - ok
17:05:52.0394 4856 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\Windows\system32\Drivers\mup.sys
17:05:52.0395 4856 Mup - ok
17:05:52.0453 4856 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\Windows\system32\DRIVERS\nwifi.sys
17:05:52.0458 4856 NativeWifiP - ok
17:05:52.0529 4856 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\Windows\system32\drivers\ndis.sys
17:05:52.0555 4856 NDIS - ok
17:05:52.0605 4856 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\Windows\system32\DRIVERS\ndiscap.sys
17:05:52.0606 4856 NdisCap - ok
17:05:52.0657 4856 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\Windows\system32\DRIVERS\ndistapi.sys
17:05:52.0658 4856 NdisTapi - ok
17:05:52.0688 4856 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\Windows\system32\DRIVERS\ndisuio.sys
17:05:52.0688 4856 Ndisuio - ok
17:05:52.0728 4856 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\Windows\system32\DRIVERS\ndiswan.sys
17:05:52.0738 4856 NdisWan - ok
17:05:52.0772 4856 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\Windows\system32\drivers\NDProxy.sys
17:05:52.0773 4856 NDProxy - ok
17:05:52.0865 4856 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\Windows\system32\DRIVERS\netbios.sys
17:05:52.0866 4856 NetBIOS - ok
17:05:52.0906 4856 NetBT (9162b273a44ab9dce5b44362731d062a) C:\Windows\system32\DRIVERS\netbt.sys
17:05:52.0911 4856 NetBT - ok
17:05:53.0001 4856 nfrd960 (77889813be4d166cdab78ddba990da92) C:\Windows\system32\DRIVERS\nfrd960.sys
17:05:53.0003 4856 nfrd960 - ok
17:05:53.0076 4856 NisDrv (5f7d72cbcdd025af1f38fdeee5646968) C:\Windows\system32\DRIVERS\NisDrvWFP.sys
17:05:53.0077 4856 NisDrv - ok
17:05:53.0123 4856 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\Windows\system32\drivers\Npfs.sys
17:05:53.0124 4856 Npfs - ok
17:05:53.0167 4856 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\Windows\system32\drivers\nsiproxy.sys
17:05:53.0168 4856 nsiproxy - ok
17:05:53.0250 4856 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\Windows\system32\drivers\Ntfs.sys
17:05:53.0285 4856 Ntfs - ok
17:05:53.0341 4856 Null (9899284589f75fa8724ff3d16aed75c1) C:\Windows\system32\drivers\Null.sys
17:05:53.0342 4856 Null - ok
17:05:53.0429 4856 NVHDA (960e39a54e525df58cb29193147dffa1) C:\Windows\system32\drivers\nvhda64v.sys
17:05:53.0430 4856 NVHDA - ok
17:05:53.0725 4856 nvlddmkm (cc1efea1f0ab17e59bd4b5baff3e5cb0) C:\Windows\system32\DRIVERS\nvlddmkm.sys
17:05:53.0776 4856 nvlddmkm - ok
17:05:53.0835 4856 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\Windows\system32\drivers\nvraid.sys
17:05:53.0838 4856 nvraid - ok
17:05:53.0894 4856 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\Windows\system32\drivers\nvstor.sys
17:05:53.0897 4856 nvstor - ok
17:05:54.0014 4856 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\Windows\system32\DRIVERS\nv_agp.sys
17:05:54.0017 4856 nv_agp - ok
17:05:54.0063 4856 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\Windows\system32\DRIVERS\ohci1394.sys
17:05:54.0065 4856 ohci1394 - ok
17:05:54.0115 4856 Parport (0086431c29c35be1dbc43f52cc273887) C:\Windows\system32\DRIVERS\parport.sys
17:05:54.0117 4856 Parport - ok
17:05:54.0166 4856 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\Windows\system32\drivers\partmgr.sys
17:05:54.0168 4856 partmgr - ok
17:05:54.0229 4856 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\Windows\system32\DRIVERS\pci.sys
17:05:54.0232 4856 pci - ok
17:05:54.0277 4856 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\Windows\system32\DRIVERS\pciide.sys
17:05:54.0278 4856 pciide - ok
17:05:54.0325 4856 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\Windows\system32\DRIVERS\pcmcia.sys
17:05:54.0329 4856 pcmcia - ok
17:05:54.0373 4856 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\Windows\system32\drivers\pcw.sys
17:05:54.0375 4856 pcw - ok
17:05:54.0426 4856 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\Windows\system32\drivers\peauth.sys
17:05:54.0434 4856 PEAUTH - ok
17:05:54.0526 4856 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\Windows\system32\DRIVERS\raspptp.sys
17:05:54.0529 4856 PptpMiniport - ok
17:05:54.0575 4856 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\Windows\system32\DRIVERS\processr.sys
17:05:54.0576 4856 Processor - ok
17:05:54.0646 4856 Psched (ee992183bd8eaefd9973f352e587a299) C:\Windows\system32\DRIVERS\pacer.sys
17:05:54.0647 4856 Psched - ok
17:05:54.0719 4856 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\Windows\system32\DRIVERS\ql2300.sys
17:05:54.0752 4856 ql2300 - ok
17:05:54.0810 4856 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\Windows\system32\DRIVERS\ql40xx.sys
17:05:54.0812 4856 ql40xx - ok
17:05:54.0848 4856 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\Windows\system32\drivers\qwavedrv.sys
17:05:54.0858 4856 QWAVEdrv - ok
17:05:54.0907 4856 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\Windows\system32\DRIVERS\rasacd.sys
17:05:54.0908 4856 RasAcd - ok
17:05:55.0004 4856 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\Windows\system32\DRIVERS\AgileVpn.sys
17:05:55.0006 4856 RasAgileVpn - ok
17:05:55.0047 4856 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\Windows\system32\DRIVERS\rasl2tp.sys
17:05:55.0049 4856 Rasl2tp - ok
17:05:55.0096 4856 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\Windows\system32\DRIVERS\raspppoe.sys
17:05:55.0097 4856 RasPppoe - ok
17:05:55.0154 4856 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\Windows\system32\DRIVERS\rassstp.sys
17:05:55.0156 4856 RasSstp - ok
17:05:55.0201 4856 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\Windows\system32\DRIVERS\rdbss.sys
17:05:55.0205 4856 rdbss - ok
17:05:55.0257 4856 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\Windows\system32\DRIVERS\rdpbus.sys
17:05:55.0258 4856 rdpbus - ok
17:05:55.0301 4856 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\Windows\system32\DRIVERS\RDPCDD.sys
17:05:55.0302 4856 RDPCDD - ok
17:05:55.0344 4856 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\Windows\system32\drivers\rdpencdd.sys
17:05:55.0345 4856 RDPENCDD - ok
17:05:55.0380 4856 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\Windows\system32\drivers\rdprefmp.sys
17:05:55.0381 4856 RDPREFMP - ok
17:05:55.0430 4856 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\Windows\system32\drivers\RDPWD.sys
17:05:55.0433 4856 RDPWD - ok
17:05:55.0513 4856 rdyboost (634b9a2181d98f15941236886164ec8b) C:\Windows\system32\drivers\rdyboost.sys
17:05:55.0517 4856 rdyboost - ok
17:05:55.0585 4856 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\Windows\system32\DRIVERS\rspndr.sys
17:05:55.0587 4856 rspndr - ok
17:05:55.0662 4856 RTL8167 (ee082e06a82ff630351d1e0ebbd3d8d0) C:\Windows\system32\DRIVERS\Rt64win7.sys
17:05:55.0665 4856 RTL8167 - ok
17:05:55.0717 4856 sbp2port (e3bbb89983daf5622c1d50cf49f28227) C:\Windows\system32\DRIVERS\sbp2port.sys
17:05:55.0720 4856 sbp2port - ok
17:05:55.0779 4856 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\Windows\system32\DRIVERS\scfilter.sys
17:05:55.0780 4856 scfilter - ok
17:05:55.0829 4856 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\Windows\system32\drivers\secdrv.sys
17:05:55.0830 4856 secdrv - ok
17:05:55.0880 4856 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\Windows\system32\DRIVERS\serenum.sys
17:05:55.0881 4856 Serenum - ok
17:05:55.0919 4856 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\Windows\system32\DRIVERS\serial.sys
17:05:55.0919 4856 Serial - ok
17:05:55.0980 4856 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\Windows\system32\DRIVERS\sermouse.sys
17:05:55.0982 4856 sermouse - ok
17:05:56.0040 4856 sffdisk (a554811bcd09279536440c964ae35bbf) C:\Windows\system32\DRIVERS\sffdisk.sys
17:05:56.0041 4856 sffdisk - ok
17:05:56.0084 4856 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\Windows\system32\DRIVERS\sffp_mmc.sys
17:05:56.0085 4856 sffp_mmc - ok
17:05:56.0128 4856 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\Windows\system32\DRIVERS\sffp_sd.sys
17:05:56.0129 4856 sffp_sd - ok
17:05:56.0199 4856 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\Windows\system32\DRIVERS\sfloppy.sys
17:05:56.0200 4856 sfloppy - ok
17:05:56.0253 4856 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\Windows\system32\DRIVERS\SiSRaid2.sys
17:05:56.0255 4856 SiSRaid2 - ok
17:05:56.0310 4856 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\Windows\system32\DRIVERS\sisraid4.sys
17:05:56.0313 4856 SiSRaid4 - ok
17:05:56.0360 4856 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\Windows\system32\DRIVERS\smb.sys
17:05:56.0362 4856 Smb - ok
17:05:56.0424 4856 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\Windows\system32\drivers\spldr.sys
17:05:56.0425 4856 spldr - ok
17:05:56.0516 4856 sptd (602884696850c86434530790b110e8eb) C:\Windows\system32\Drivers\sptd.sys
17:05:56.0516 4856 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 602884696850c86434530790b110e8eb
17:05:56.0518 4856 sptd ( LockedFile.Multi.Generic ) - warning
17:05:56.0518 4856 sptd - detected LockedFile.Multi.Generic (1)
17:05:56.0586 4856 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\Windows\system32\DRIVERS\srv.sys
17:05:56.0603 4856 srv - ok
17:05:56.0652 4856 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\Windows\system32\DRIVERS\srv2.sys
17:05:56.0657 4856 srv2 - ok
17:05:56.0721 4856 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\Windows\system32\DRIVERS\srvnet.sys
17:05:56.0724 4856 srvnet - ok
17:05:56.0811 4856 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\Windows\system32\DRIVERS\stexstor.sys
17:05:56.0813 4856 stexstor - ok
17:05:56.0886 4856 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\Windows\system32\DRIVERS\swenum.sys
17:05:56.0886 4856 swenum - ok
17:05:56.0968 4856 tap0901 (b6e9df4829cd9fcbb8c69b8da4c5108f) C:\Windows\system32\DRIVERS\tap0901.sys
17:05:56.0979 4856 tap0901 - ok
17:05:57.0065 4856 tap0901t (b08740047145b9bce15bf75ca0f9718a) C:\Windows\system32\DRIVERS\tap0901t.sys
17:05:57.0072 4856 tap0901t - ok
17:05:57.0165 4856 Tcpip (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\drivers\tcpip.sys
17:05:57.0223 4856 Tcpip - ok
17:05:57.0306 4856 TCPIP6 (b9d87c7707f058ac652a398cd28de14b) C:\Windows\system32\DRIVERS\tcpip.sys
17:05:57.0314 4856 TCPIP6 - ok
17:05:57.0377 4856 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\Windows\system32\drivers\tcpipreg.sys
17:05:57.0379 4856 tcpipreg - ok
17:05:57.0435 4856 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\Windows\system32\drivers\tdpipe.sys
17:05:57.0436 4856 TDPIPE - ok
17:05:57.0485 4856 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\Windows\system32\drivers\tdtcp.sys
17:05:57.0486 4856 TDTCP - ok
17:05:57.0543 4856 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\Windows\system32\DRIVERS\tdx.sys
17:05:57.0545 4856 tdx - ok
17:05:57.0589 4856 TermDD (c448651339196c0e869a355171875522) C:\Windows\system32\DRIVERS\termdd.sys
17:05:57.0590 4856 TermDD - ok
17:05:57.0648 4856 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\Windows\system32\DRIVERS\tssecsrv.sys
17:05:57.0649 4856 tssecsrv - ok
17:05:57.0704 4856 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\Windows\system32\DRIVERS\tunnel.sys
17:05:57.0707 4856 tunnel - ok
17:05:57.0765 4856 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\Windows\system32\DRIVERS\uagp35.sys
17:05:57.0767 4856 uagp35 - ok
17:05:57.0827 4856 udfs (d47baead86c65d4f4069d7ce0a4edceb) C:\Windows\system32\DRIVERS\udfs.sys
17:05:57.0831 4856 udfs - ok
17:05:57.0881 4856 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\Windows\system32\DRIVERS\uliagpkx.sys
17:05:57.0883 4856 uliagpkx - ok
17:05:57.0947 4856 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\Windows\system32\DRIVERS\umbus.sys
17:05:57.0948 4856 umbus - ok
17:05:57.0992 4856 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\Windows\system32\DRIVERS\umpass.sys
17:05:57.0993 4856 UmPass - ok
17:05:58.0067 4856 USBAAPL64 (f724b03c3dfaacf08d17d38bf3333583) C:\Windows\system32\Drivers\usbaapl64.sys
17:05:58.0068 4856 USBAAPL64 - ok
17:05:58.0113 4856 usbccgp (7b6a127c93ee590e4d79a5f2a76fe46f) C:\Windows\system32\drivers\usbccgp.sys
17:05:58.0115 4856 usbccgp - ok
17:05:58.0186 4856 usbcir (af0892a803fdda7492f595368e3b68e7) C:\Windows\system32\DRIVERS\usbcir.sys
17:05:58.0188 4856 usbcir - ok
17:05:58.0235 4856 usbehci (92969ba5ac44e229c55a332864f79677) C:\Windows\system32\DRIVERS\usbehci.sys
17:05:58.0236 4856 usbehci - ok
17:05:58.0288 4856 usbhub (e7df1cfd28ca86b35ef5add0735ceef3) C:\Windows\system32\DRIVERS\usbhub.sys
17:05:58.0293 4856 usbhub - ok
17:05:58.0332 4856 usbohci (f1bb1e55f1e7a65c5839ccc7b36d773e) C:\Windows\system32\drivers\usbohci.sys
17:05:58.0333 4856 usbohci - ok
17:05:58.0387 4856 usbprint (73188f58fb384e75c4063d29413cee3d) C:\Windows\system32\DRIVERS\usbprint.sys
17:05:58.0388 4856 usbprint - ok
17:05:58.0470 4856 usbscan (aaa2513c8aed8b54b189fd0c6b1634c0) C:\Windows\system32\DRIVERS\usbscan.sys
17:05:58.0472 4856 usbscan - ok
17:05:58.0529 4856 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\Windows\system32\drivers\USBSTOR.SYS
17:05:58.0530 4856 USBSTOR - ok
17:05:58.0580 4856 usbuhci (bc3070350a491d84b518d7cca9abd36f) C:\Windows\system32\drivers\usbuhci.sys
17:05:58.0581 4856 usbuhci - ok
17:05:58.0646 4856 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\Windows\system32\DRIVERS\vdrvroot.sys
17:05:58.0647 4856 vdrvroot - ok
17:05:58.0718 4856 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\Windows\system32\DRIVERS\vgapnp.sys
17:05:58.0720 4856 vga - ok
17:05:58.0762 4856 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\Windows\System32\drivers\vga.sys
17:05:58.0763 4856 VgaSave - ok
17:05:58.0808 4856 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\Windows\system32\DRIVERS\vhdmp.sys
17:05:58.0812 4856 vhdmp - ok
17:05:58.0865 4856 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\Windows\system32\DRIVERS\viaide.sys
17:05:58.0866 4856 viaide - ok
17:05:58.0916 4856 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\Windows\system32\DRIVERS\volmgr.sys
17:05:58.0918 4856 volmgr - ok
17:05:58.0976 4856 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\Windows\system32\drivers\volmgrx.sys
17:05:58.0980 4856 volmgrx - ok
17:05:59.0058 4856 volsnap (58f82eed8ca24b461441f9c3e4f0bf5c) C:\Windows\system32\DRIVERS\volsnap.sys
17:05:59.0063 4856 volsnap - ok
17:05:59.0116 4856 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\Windows\system32\DRIVERS\vsmraid.sys
17:05:59.0116 4856 vsmraid - ok
17:05:59.0189 4856 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\Windows\System32\drivers\vwifibus.sys
17:05:59.0190 4856 vwifibus - ok
17:05:59.0239 4856 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\Windows\system32\DRIVERS\wacompen.sys
17:05:59.0240 4856 WacomPen - ok
17:05:59.0300 4856 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
17:05:59.0302 4856 WANARP - ok
17:05:59.0306 4856 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\Windows\system32\DRIVERS\wanarp.sys
17:05:59.0307 4856 Wanarpv6 - ok
17:05:59.0358 4856 Wd (72889e16ff12ba0f235467d6091b17dc) C:\Windows\system32\DRIVERS\wd.sys
17:05:59.0359 4856 Wd - ok
17:05:59.0413 4856 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\Windows\system32\drivers\Wdf01000.sys
17:05:59.0421 4856 Wdf01000 - ok
17:05:59.0481 4856 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\Windows\system32\DRIVERS\wfplwf.sys
17:05:59.0482 4856 WfpLwf - ok
17:05:59.0530 4856 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\Windows\system32\drivers\wimmount.sys
17:05:59.0531 4856 WIMMount - ok
17:05:59.0604 4856 WinRing0_1_2_0 - ok
17:05:59.0779 4856 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\Windows\system32\DRIVERS\wmiacpi.sys
17:05:59.0780 4856 WmiAcpi - ok
17:05:59.0849 4856 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\Windows\system32\drivers\ws2ifsl.sys
17:05:59.0850 4856 ws2ifsl - ok
17:05:59.0921 4856 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\Windows\system32\drivers\WudfPf.sys
17:05:59.0923 4856 WudfPf - ok
17:05:59.0978 4856 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\Windows\system32\DRIVERS\WUDFRd.sys
17:05:59.0981 4856 WUDFRd - ok
17:06:00.0029 4856 MBR (0x1B8) (de1996b5390bac8242e23168f828c750) \Device\Harddisk0\DR0
17:06:00.0029 4856 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - infected
17:06:00.0029 4856 \Device\Harddisk0\DR0 - detected Rootkit.Win32.TDSS.tdl4 (0)
17:06:00.0034 4856 Boot (0x1200) (bb0e588642b30f67af3ccc705272fd6b) \Device\Harddisk0\DR0\Partition0
17:06:00.0034 4856 \Device\Harddisk0\DR0\Partition0 - ok
17:06:00.0035 4856 ============================================================
17:06:00.0035 4856 Scan finished
17:06:00.0035 4856 ============================================================
17:06:00.0045 1108 Detected object count: 2
17:06:00.0045 1108 Actual detected object count: 2
17:06:18.0952 1108 sptd ( LockedFile.Multi.Generic ) - skipped by user
17:06:18.0952 1108 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
17:06:18.0995 1108 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - will be cured on reboot
17:06:18.0996 1108 \Device\Harddisk0\DR0 - ok
17:06:18.0997 1108 \Device\Harddisk0\DR0 ( Rootkit.Win32.TDSS.tdl4 ) - User select action: Cure
17:06:28.0083 4100 Deinitialize success

OTL log #1

OTL logfile created on: 9/26/2011 5:11:39 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Andrei\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.99 Gb Total Physical Memory | 2.78 Gb Available Physical Memory | 69.67% Memory free
7.98 Gb Paging File | 6.68 Gb Available in Paging File | 83.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 70.07 Gb Free Space | 30.09% Space Free | Partition Type: NTFS

Computer Name: MAINDESKTOP | User Name: Andrei | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Andrei\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Andrei\AppData\Local\Google\Update\1.3.21.69\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Games\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
PRC - C:\Windows\SysWOW64\ASDR.exe ()
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files (x86)\ASUS\SmartDoctor\SmartDoctor.exe (ASUSTeK Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
MOD - C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
MOD - C:\Program Files (x86)\ASUS\SmartDoctor\VOV32.dll ()
MOD - C:\Program Files (x86)\ASUS\SmartDoctor\aticlocklib.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Akamai) – c:\Program Files (x86)\Common Files\Akamai\netsession_win_b31de1e.dll ()
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (TunngleService) – C:\Games\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nTuneService) – C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe (NVIDIA)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (UpdateCenterService) – C:\Program Files (x86)\NVIDIA Corporation\System Update\UpdateCenterService.exe (NVIDIA)
SRV - (ASDR) – C:\Windows\SysWOW64\ASDR.exe ()
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (EIO64) – C:\Windows\SysNative\drivers\EIO64.sys (ASUSTeK Computer Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (IOMap) – C:\Windows\SysNative\drivers\IOMap64.sys (ASUSTeK Computer Inc.)
DRV:64bit: - (tap0901t) TAP-Win32 Adapter V9 (Tunngle) – C:\Windows\SysNative\drivers\tap0901t.sys (Tunngle.net)
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\drivers\ASACPI.sys ()
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (asusgsb) – C:\Windows\SysNative\drivers\asusgsb.sys (ASUSTeK Computer Inc.)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://it.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 37 35 2E 1B B3 6D CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.selectedEngine: "DAEMON Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/ig"


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@onlive.com/OnLiveGameClientDetector,version=1.0.0: C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Andrei\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Andrei\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 8\components [2011/09/21 15:37:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 8\plugins

[2010/12/22 22:23:33 | 000,000,000 | —D | M] (No name found) – C:\Users\Andrei\AppData\Roaming\Mozilla\Extensions
[2011/09/22 07:02:35 | 000,000,000 | —D | M] (No name found) – C:\Users\Andrei\AppData\Roaming\Mozilla\Firefox\Profiles\3yurb4sk.default\extensions
[2011/02/18 14:27:21 | 000,000,000 | —D | M] (EPUBReader) – C:\Users\Andrei\AppData\Roaming\Mozilla\Firefox\Profiles\3yurb4sk.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2011/04/30 05:46:54 | 000,000,000 | —D | M] (Dizionario italiano) – C:\Users\Andrei\AppData\Roaming\Mozilla\Firefox\Profiles\3yurb4sk.default\extensions\[removed]
[2011/09/14 16:25:24 | 000,002,055 | —- | M] () – C:\Users\Andrei\AppData\Roaming\Mozilla\Firefox\Profiles\3yurb4sk.default\searchplugins\daemon-search.xml
() (No name found) – C:\USERS\ANDREI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3YURB4SK.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) – C:\USERS\ANDREI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3YURB4SK.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\ANDREI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\3YURB4SK.DEFAULT\EXTENSIONS\[removed]

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Andrei\AppData\Local\Google\Chrome\Application\14.0.835.186\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Andrei\AppData\Local\Google\Chrome\Application\14.0.835.186\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Andrei\AppData\Local\Google\Chrome\Application\14.0.835.186\pdf.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Andrei\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Art Project, powered by Google = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aafjiaooblldgcephecfcafbmckcfeep\0.0.0.4_0\
CHR - Extension: Atari - Lunar Lander = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\aheampccjiggeiflpcjolbabpohbpclg\1.0_0\
CHR - Extension: AdBlock+ = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\chmimgmjdabgiilljdjfbonifbhiglao\1.1.9.18_0\
CHR - Extension: Search by Image (by Google) = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\dajedkncpodkggklbegccjpmnglmnflm\1.0.0_0\
CHR - Extension: Keep My Opt-Outs = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\hhnjdplhmcnkiecampfdgfjilccfpfoe\1.0.13_0\
CHR - Extension: AT_Akira = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\igmggajponoffjmhekbonemlgidfgdao\3_0\
CHR - Extension: FlashControl = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe\2.8.1_0\
CHR - Extension: Team Liquid Streams = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\padelkgfoancpcpjlhfnamekcomkhbnk\1.2_0\
CHR - Extension: 4chan Plus = C:\Users\Andrei\AppData\Local\Google\Chrome\User Data\Default\Extensions\pinelipedelckihohgdlpcclgocodhjj\2.3.9_0\

O1 HOSTS File: ([2011/09/20 14:40:42 | 000,436,871 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 123fporn.info
O1 - Hosts: 15052 more lines…
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [OpenDNS Updater] C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe ()
O4 - HKCU..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKLM..\RunOnce: [AvgUninstallURL] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{D06CE44B-7D7F-40C6-A97E-93B893DB8898}: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E40B5D32-70B5-4A5B-83A0-972193EEAD2E}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E40B5D32-70B5-4A5B-83A0-972193EEAD2E}: NameServer = 208.67.222.222,208.67.220.220
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - AppInit_DLLs: (TeknoGods.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.divxa32 - C:\Windows\SysWow64\msaud32_divx.acm (Microsoft Corporation)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.XVID - xvidvfw.dll File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/09/26 17:09:28 | 000,582,656 | —- | C] (OldTimer Tools) – C:\Users\Andrei\Desktop\OTL.exe
[2011/09/26 17:05:06 | 001,548,080 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Andrei\Desktop\TDSSKiller.exe
[2011/09/26 15:36:20 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{F43A1D50-BCA5-41AC-993E-447C783DC4A9}
[2011/09/26 15:36:06 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{474C651A-BE8B-4828-9CDD-07D3AD226159}
[2011/09/25 13:40:39 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\LogMeIn Hamachi
[2011/09/23 11:49:57 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{D951E3B0-6847-4DD4-8062-655A15097258}
[2011/09/23 11:49:32 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{FC5654C6-1787-4C31-8183-AF948BF09561}
[2011/09/21 11:31:51 | 001,540,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2011/09/21 11:31:51 | 000,902,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d2d1.dll
[2011/09/20 16:39:42 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2011/09/20 09:08:31 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/09/20 09:08:31 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/09/20 09:08:31 | 000,367,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/09/20 09:08:31 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/09/20 09:08:31 | 000,162,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/09/20 09:08:31 | 000,130,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/09/20 09:08:31 | 000,118,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/09/20 09:08:31 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/09/20 09:08:31 | 000,086,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/09/20 09:08:31 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/09/20 09:08:31 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/09/20 09:08:31 | 000,063,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/09/20 09:08:31 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/09/20 09:08:31 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/09/20 09:08:30 | 001,427,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/09/20 09:08:30 | 000,434,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/09/20 09:08:30 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/09/20 09:08:30 | 000,227,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/09/20 09:08:30 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/09/20 09:08:30 | 000,152,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/09/20 09:08:30 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/09/20 09:08:30 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/09/20 09:08:30 | 000,123,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/09/20 09:08:30 | 000,101,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/09/20 09:08:30 | 000,078,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/09/20 09:08:30 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/09/20 09:08:30 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/09/20 09:08:30 | 000,072,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/09/20 09:08:30 | 000,066,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/09/20 09:08:30 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/09/20 09:08:30 | 000,031,744 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/09/20 09:08:30 | 000,023,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/09/20 09:08:29 | 002,303,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/09/20 09:08:29 | 000,818,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/09/20 09:08:29 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/09/20 09:08:29 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/09/20 09:08:29 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/09/20 09:08:29 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/09/20 09:08:29 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/09/20 09:08:29 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/09/20 09:08:29 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/09/20 09:08:29 | 000,145,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/09/20 09:08:29 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/09/20 09:08:29 | 000,114,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/09/20 09:08:29 | 000,111,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/09/20 09:08:29 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/09/20 09:08:29 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/09/20 09:08:29 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/09/20 09:08:29 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/09/20 09:08:29 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/09/20 09:08:29 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/09/20 09:08:29 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/09/20 09:08:28 | 003,695,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/09/20 09:08:28 | 001,492,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/09/20 09:08:28 | 000,697,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/09/20 09:08:28 | 000,603,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/09/20 09:08:28 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/09/20 09:08:28 | 000,452,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/09/20 09:08:28 | 000,448,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/09/20 09:08:28 | 000,282,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/09/20 09:08:28 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/09/20 09:08:28 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/09/20 09:08:28 | 000,165,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2011/09/20 09:08:28 | 000,160,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/09/20 09:08:28 | 000,103,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/09/20 09:08:28 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/09/20 09:08:28 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/09/20 09:08:28 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/09/20 09:08:28 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/09/20 09:08:28 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/09/20 09:08:28 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/09/20 09:08:28 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/09/20 08:29:42 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{96FE358F-F8F2-4CA9-B802-6108E5B0DD49}
[2011/09/20 08:29:24 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{8631195D-6DE9-47FE-8906-91413A06F4DB}
[2011/09/19 18:10:19 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/09/19 18:10:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/09/18 03:39:20 | 002,566,144 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2011/09/18 03:39:19 | 000,107,904 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdsata.sys
[2011/09/18 03:39:18 | 001,686,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[2011/09/18 03:39:18 | 000,187,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\storport.sys
[2011/09/18 03:39:18 | 000,027,008 | —- | C] (Advanced Micro Devices) – C:\Windows\SysNative\drivers\amdxata.sys
[2011/09/18 03:39:17 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fsutil.exe
[2011/09/18 03:39:16 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fsutil.exe
[2011/09/18 02:57:48 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbport.sys
[2011/09/18 02:57:48 | 000,007,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\usbd.sys
[2011/09/17 09:50:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
[2011/09/17 08:33:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft.NET
[2011/09/17 08:24:39 | 000,000,000 | —D | C] – C:\Windows\SysNative\Wat
[2011/09/17 08:00:11 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\ApplicationHistory
[2011/09/17 07:50:35 | 000,000,000 | —D | C] – C:\Windows\SysWow64\URTTEMP
[2011/09/17 06:55:09 | 000,000,000 | —D | C] – C:\ProgramData\Windows Genuine Advantage
[2011/09/17 06:42:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
[2011/09/17 06:00:31 | 002,228,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2011/09/17 06:00:31 | 001,401,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2011/09/17 06:00:30 | 002,326,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2011/09/17 06:00:30 | 001,553,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2011/09/17 06:00:29 | 000,491,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2011/09/17 06:00:28 | 000,779,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2011/09/17 06:00:28 | 000,666,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2011/09/17 06:00:28 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2011/09/17 06:00:28 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2011/09/17 06:00:28 | 000,113,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2011/09/17 06:00:28 | 000,075,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2011/09/17 06:00:27 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssphtb.dll
[2011/09/17 06:00:27 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msscntrs.dll
[2011/09/17 05:54:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2011/09/17 05:54:53 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2011/09/17 05:54:52 | 001,698,408 | —- | C] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[2011/09/17 05:48:59 | 024,692,840 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcompiler.dll
[2011/09/17 05:48:59 | 022,470,248 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvoglv64.dll
[2011/09/17 05:48:59 | 017,193,576 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcompiler.dll
[2011/09/17 05:48:59 | 016,595,560 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvoglv32.dll
[2011/09/17 05:48:59 | 015,064,168 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvd3dumx.dll
[2011/09/17 05:48:59 | 007,254,632 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuda.dll
[2011/09/17 05:48:59 | 006,613,096 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvwgf2um.dll
[2011/09/17 05:48:59 | 005,404,776 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuda.dll
[2011/09/17 05:48:59 | 002,532,456 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvid.dll
[2011/09/17 05:48:59 | 002,391,656 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvid.dll
[2011/09/17 05:48:59 | 002,222,184 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvcuvenc.dll
[2011/09/17 05:48:59 | 002,090,088 | —- | C] (NVIDIA Corporation) – C:\Windows\SysWow64\nvcuvenc.dll
[2011/09/17 05:48:59 | 001,519,720 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvdispco64.dll
[2011/09/17 05:48:59 | 001,453,160 | —- | C] (NVIDIA Corporation) – C:\Windows\SysNative\nvgenco64.dll
[2011/09/17 05:48:59 | 000,067,176 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2011/09/17 05:48:59 | 000,057,960 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2011/09/17 05:45:56 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccu32.dll
[2011/09/17 05:45:56 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccr32.dll
[2011/09/17 05:45:54 | 000,319,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbcjt32.dll
[2011/09/17 05:45:54 | 000,212,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbctrac.dll
[2011/09/17 05:45:54 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbccp32.dll
[2011/09/17 05:45:54 | 000,122,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccp32.dll
[2011/09/17 05:45:53 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbctrac.dll
[2011/09/17 05:45:53 | 000,086,016 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccu32.dll
[2011/09/17 05:45:53 | 000,081,920 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbccr32.dll
[2011/09/17 05:45:34 | 002,870,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2011/09/17 05:45:34 | 002,614,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2011/09/17 05:43:42 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\xmllite.dll
[2011/09/17 05:43:35 | 000,142,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\poqexec.exe
[2011/09/17 05:43:35 | 000,123,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\poqexec.exe
[2011/09/17 05:43:19 | 000,723,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\EncDec.dll
[2011/09/17 05:43:18 | 001,118,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\sbe.dll
[2011/09/17 05:43:18 | 000,961,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\CPFilters.dll
[2011/09/17 05:43:18 | 000,642,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\CPFilters.dll
[2011/09/17 05:43:18 | 000,534,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\EncDec.dll
[2011/09/17 05:43:18 | 000,259,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mpg2splt.ax
[2011/09/17 05:43:17 | 000,850,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\sbe.dll
[2011/09/17 05:43:17 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mpg2splt.ax
[2011/09/17 05:38:30 | 000,476,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2011/09/17 05:38:30 | 000,288,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2011/09/17 05:38:01 | 000,264,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\upnp.dll
[2011/09/17 05:38:00 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\upnp.dll
[2011/09/17 05:37:59 | 000,100,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\davclnt.dll
[2011/09/17 05:37:58 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wscapi.dll
[2011/09/17 05:37:57 | 000,051,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2011/09/17 05:37:57 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\slwga.dll
[2011/09/17 05:37:57 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\slwga.dll
[2011/09/17 05:37:47 | 000,662,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsPrint.dll
[2011/09/17 05:37:47 | 000,442,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsPrint.dll
[2011/09/17 05:37:44 | 001,395,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42.dll
[2011/09/17 05:37:44 | 001,359,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfc42u.dll
[2011/09/17 05:37:43 | 001,164,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42u.dll
[2011/09/17 05:37:43 | 001,137,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc42.dll
[2011/09/17 05:37:08 | 000,367,104 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2011/09/17 05:37:08 | 000,294,912 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2011/09/17 05:37:08 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2011/09/17 05:37:08 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2011/09/17 05:37:03 | 001,837,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10warp.dll
[2011/09/17 05:36:59 | 001,863,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ExplorerFrame.dll
[2011/09/17 05:36:59 | 001,495,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ExplorerFrame.dll
[2011/09/17 05:36:59 | 000,265,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dxgmms1.sys
[2011/09/17 05:36:59 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsRasterService.dll
[2011/09/17 05:36:58 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cdd.dll
[2011/09/17 05:36:58 | 000,135,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsRasterService.dll
[2011/09/17 05:34:33 | 000,027,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\Diskdump.sys
[2011/09/17 05:31:38 | 000,356,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnsapi.dll
[2011/09/17 05:31:37 | 000,030,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dnscacheugc.exe
[2011/09/17 05:31:37 | 000,028,672 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dnscacheugc.exe
[2011/09/17 05:29:27 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1core.dll
[2011/09/17 05:29:27 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/09/17 05:29:20 | 003,138,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2011/09/17 05:29:20 | 002,690,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2011/09/17 05:29:19 | 001,034,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2011/09/17 05:29:18 | 001,097,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2011/09/17 05:23:13 | 005,510,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2011/09/17 05:23:12 | 003,901,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2011/09/17 05:23:12 | 001,739,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2011/09/17 05:23:10 | 003,957,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2011/09/17 04:49:54 | 000,422,400 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2011/09/17 04:49:53 | 001,162,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2011/09/17 04:49:52 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2011/09/17 04:49:51 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2011/09/17 04:49:51 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2011/09/17 04:49:49 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2011/09/17 04:49:48 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2011/09/17 04:49:48 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2011/09/17 04:49:48 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2011/09/17 04:49:47 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2011/09/17 04:49:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/17 04:49:47 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2011/09/17 04:49:46 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2011/09/17 04:49:46 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2011/09/17 04:49:45 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2011/09/17 04:49:45 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2011/09/17 04:49:45 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2011/09/17 04:49:45 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2011/09/17 04:49:45 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2011/09/17 04:49:44 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2011/09/17 04:49:44 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2011/09/17 04:49:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/17 04:49:43 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2011/09/17 04:49:43 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/17 04:49:42 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2011/09/17 04:49:42 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2011/09/17 04:49:42 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2011/09/17 04:49:42 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2011/09/17 04:49:42 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2011/09/17 04:49:42 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2011/09/17 04:49:41 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2011/09/17 04:45:08 | 000,252,928 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\drvinst.exe
[2011/09/17 04:45:08 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\devrtl.dll
[2011/09/17 04:38:57 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\prevhost.exe
[2011/09/17 04:38:57 | 000,031,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\prevhost.exe
[2011/09/17 04:38:56 | 000,267,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\FXSCOVER.exe
[2011/09/17 04:33:02 | 000,720,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\odbc32.dll
[2011/09/17 04:33:02 | 000,573,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\odbc32.dll
[2011/09/17 04:29:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Security Client
[2011/09/17 04:28:38 | 000,374,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\netio.sys
[2011/09/17 03:32:30 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Wat
[2011/09/17 00:14:53 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\Darksiders
[2011/09/16 12:37:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[2011/09/16 12:31:49 | 000,000,000 | —D | C] – C:\13ec462a2df6f9c7ed010ae9
[2011/09/15 01:12:42 | 000,000,000 | —D | C] – C:\Users\Andrei\Documents\Max Payne 2 Savegames
[2011/09/15 01:07:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/09/15 01:04:10 | 001,060,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfc71.dll
[2011/09/14 20:13:06 | 000,000,000 | —D | C] – C:\Users\Andrei\Documents\Hard Reset
[2011/09/14 20:02:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flying Wild Hog
[2011/09/14 19:42:53 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Alcohol 120%
[2011/09/14 19:42:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alcohol 120%
[2011/09/14 19:17:04 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\AVG2012
[2011/09/14 19:16:18 | 000,000,000 | —D | C] – C:\ProgramData\AVG2012
[2011/09/14 17:45:44 | 000,055,384 | —- | C] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/09/14 17:15:00 | 000,069,152 | —- | C] (Lavasoft AB) – C:\Windows\SysNative\drivers\Lbd.sys
[2011/09/14 17:11:55 | 000,000,000 | —D | C] – C:\ProgramData\Lavasoft
[2011/09/14 16:25:13 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\DAEMON Tools Lite
[2011/09/14 16:25:13 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2011/09/13 22:22:57 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{40919A4B-4772-47A5-AAF8-259D230D0ADC}
[2011/09/13 22:22:31 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{2A8EE88B-AEBA-4BB7-A007-2C27732437CB}
[2011/09/13 07:56:17 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{898EB987-6F5D-4A97-9502-86031274FC53}
[2011/09/12 17:08:07 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{3AB749E4-F2D0-4FBD-8218-8B670C1B5D3B}
[2011/09/12 17:07:44 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{2E579D7F-A2E2-4A13-B2A3-A1085BFC8BF1}
[2011/09/11 22:20:20 | 000,000,000 | —D | C] – C:\ProgramData\NFS Underground
[2011/09/11 18:17:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III Beta
[2011/09/11 17:43:11 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\X-Chat 2
[2011/09/11 17:43:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XChat
[2011/09/11 17:43:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\xchat
[2011/09/11 05:58:57 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\Malwarebytes
[2011/09/11 05:56:49 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/09/11 05:56:45 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/09/10 02:57:38 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\mIRC
[2011/09/10 02:57:36 | 000,000,000 | —D | C] – C:\Program Files (x86)\mIRC
[2011/09/08 03:33:10 | 000,000,000 | —D | C] – C:\Users\Andrei\Documents\Diablo III
[2011/09/08 03:09:56 | 000,000,000 | —D | C] – C:\ProgramData\Battle.net
[2011/09/06 03:51:29 | 000,000,000 | —D | C] – C:\Users\Andrei\riotsGamesLogs
[2011/09/06 03:27:38 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\LolClient
[2011/09/06 03:12:44 | 001,493,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\D3DCompiler_39.dll
[2011/09/06 03:12:44 | 000,467,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3dx10_39.dll
[2011/09/05 21:12:58 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\PMB Files
[2011/09/05 21:12:57 | 000,000,000 | —D | C] – C:\ProgramData\PMB Files
[2011/09/05 21:12:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Pando Networks
[2011/09/04 17:29:20 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{79E05372-EDBB-4EE7-8F0D-B1C8BBE04C01}
[2011/09/04 17:28:56 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{BB986EFE-E07B-42B2-ADE8-F277B759FBFC}
[2011/09/04 03:41:02 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{EC38F192-DD09-4A59-8B94-ED113A2842FF}
[2011/09/04 03:40:40 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{46239048-C91F-45C6-9C6D-ED6E8C89D28A}
[2011/09/03 18:20:33 | 000,000,000 | —D | C] – C:\Users\Andrei\Documents\OnLive App
[2011/09/03 18:20:10 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Roaming\OnLive App
[2011/08/28 23:53:36 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{772924F8-5C10-4D26-91C8-606C78F2FE7D}
[2011/08/28 23:53:16 | 000,000,000 | —D | C] – C:\Users\Andrei\AppData\Local\{9CE99A06-EBFC-4BA5-A489-54889E96EF2D}
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/09/26 17:14:49 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/26 17:14:49 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/26 17:09:19 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Users\Andrei\Desktop\OTL.exe
[2011/09/26 17:07:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/09/26 17:07:12 | 3214,188,544 | -HS- | M] () – C:\hiberfil.sys
[2011/09/26 17:06:34 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\Access.dat
[2011/09/26 16:39:00 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4002316052-3815423388-3284804311-1001UA.job
[2011/09/26 09:22:32 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Andrei\Desktop\TDSSKiller.exe
[2011/09/25 21:48:08 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4002316052-3815423388-3284804311-1001Core.job
[2011/09/24 15:57:12 | 000,280,736 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2011/09/24 15:57:12 | 000,280,736 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/24 15:53:45 | 000,215,128 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.ex0
[2011/09/21 15:37:52 | 000,002,155 | —- | M] () – C:\Users\Andrei\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox 4.0 Beta 8.lnk
[2011/09/21 10:50:25 | 000,000,000 | RHS- | M] () – C:\corh.ld
[2011/09/21 10:50:21 | 000,353,946 | RHS- | M] () – C:\YXOAU
[2011/09/21 10:23:53 | 000,795,490 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/21 10:23:53 | 000,670,936 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/09/21 10:23:53 | 000,126,022 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/09/20 14:58:58 | 000,001,441 | —- | M] () – C:\Users\Andrei\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2011/09/20 14:56:22 | 667,418,072 | —- | M] () – C:\Windows\MEMORY.DMP
[2011/09/20 14:40:42 | 000,436,871 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/09/20 09:08:31 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dat
[2011/09/20 09:08:31 | 000,716,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2011/09/20 09:08:31 | 000,434,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieapfltr.dll
[2011/09/20 09:08:31 | 000,367,104 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/09/20 09:08:31 | 000,176,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/09/20 09:08:31 | 000,162,304 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msrating.dll
[2011/09/20 09:08:31 | 000,130,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakeng.dll
[2011/09/20 09:08:31 | 000,118,784 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/09/20 09:08:31 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\IEAdvpack.dll
[2011/09/20 09:08:31 | 000,086,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/09/20 09:08:31 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\SetIEInstalledDate.exe
[2011/09/20 09:08:31 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2011/09/20 09:08:31 | 000,063,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\tdc.ocx
[2011/09/20 09:08:31 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmler.dll
[2011/09/20 09:08:31 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/09/20 09:08:30 | 001,427,456 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/09/20 09:08:30 | 000,231,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2011/09/20 09:08:30 | 000,227,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieaksie.dll
[2011/09/20 09:08:30 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieakui.dll
[2011/09/20 09:08:30 | 000,152,064 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\wextract.exe
[2011/09/20 09:08:30 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iexpress.exe
[2011/09/20 09:08:30 | 000,142,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/09/20 09:08:30 | 000,123,392 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/09/20 09:08:30 | 000,101,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\admparse.dll
[2011/09/20 09:08:30 | 000,078,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inseng.dll
[2011/09/20 09:08:30 | 000,074,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/09/20 09:08:30 | 000,074,240 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/09/20 09:08:30 | 000,072,822 | —- | M] () – C:\Windows\SysWow64\ieuinit.inf
[2011/09/20 09:08:30 | 000,072,704 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/09/20 09:08:30 | 000,066,048 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\icardie.dll
[2011/09/20 09:08:30 | 000,054,272 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\pngfilt.dll
[2011/09/20 09:08:30 | 000,031,744 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/09/20 09:08:30 | 000,023,552 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/09/20 09:08:29 | 002,303,488 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2011/09/20 09:08:29 | 000,818,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2011/09/20 09:08:29 | 000,267,776 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieaksie.dll
[2011/09/20 09:08:29 | 000,248,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/09/20 09:08:29 | 000,222,208 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msls31.dll
[2011/09/20 09:08:29 | 000,197,120 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msrating.dll
[2011/09/20 09:08:29 | 000,173,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/09/20 09:08:29 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakui.dll
[2011/09/20 09:08:29 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieakeng.dll
[2011/09/20 09:08:29 | 000,149,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/09/20 09:08:29 | 000,145,920 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/09/20 09:08:29 | 000,135,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\IEAdvpack.dll
[2011/09/20 09:08:29 | 000,114,176 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\admparse.dll
[2011/09/20 09:08:29 | 000,111,616 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/09/20 09:08:29 | 000,091,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\SetIEInstalledDate.exe
[2011/09/20 09:08:29 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2011/09/20 09:08:29 | 000,065,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\pngfilt.dll
[2011/09/20 09:08:29 | 000,049,664 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\imgutil.dll
[2011/09/20 09:08:29 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmler.dll
[2011/09/20 09:08:29 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshta.exe
[2011/09/20 09:08:29 | 000,010,752 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/09/20 09:08:28 | 003,695,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dat
[2011/09/20 09:08:28 | 001,492,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/09/20 09:08:28 | 000,697,344 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/09/20 09:08:28 | 000,603,648 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2011/09/20 09:08:28 | 000,534,528 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieapfltr.dll
[2011/09/20 09:08:28 | 000,452,608 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtmsft.dll
[2011/09/20 09:08:28 | 000,448,512 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/09/20 09:08:28 | 000,282,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\dxtrans.dll
[2011/09/20 09:08:28 | 000,237,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2011/09/20 09:08:28 | 000,165,888 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iexpress.exe
[2011/09/20 09:08:28 | 000,160,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\wextract.exe
[2011/09/20 09:08:28 | 000,103,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inseng.dll
[2011/09/20 09:08:28 | 000,096,256 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/09/20 09:08:28 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/09/20 09:08:28 | 000,085,504 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/09/20 09:08:28 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\icardie.dll
[2011/09/20 09:08:28 | 000,076,800 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tdc.ocx
[2011/09/20 09:08:28 | 000,072,822 | —- | M] () – C:\Windows\SysNative\ieuinit.inf
[2011/09/20 09:08:28 | 000,039,936 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/09/20 09:08:28 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/09/20 05:15:33 | 000,788,870 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/19 18:15:51 | 000,820,164 | —- | M] () – C:\Users\Andrei\AppData\Local\census.cache
[2011/09/19 18:15:03 | 000,104,769 | —- | M] () – C:\Users\Andrei\AppData\Local\ars.cache
[2011/09/19 18:04:07 | 000,000,036 | —- | M] () – C:\Users\Andrei\AppData\Local\housecall.guid.cache
[2011/09/17 08:27:21 | 004,868,200 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/09/17 04:31:56 | 000,002,154 | —- | M] () – C:\Windows\epplauncher.mif
[2011/09/16 08:20:11 | 104,223,281 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm.old
[2011/09/15 18:25:13 | 000,000,110 | —- | M] () – C:\Users\Andrei\Documents\ax_files.xml
[2011/09/14 19:36:19 | 000,834,544 | —- | M] () – C:\Windows\SysNative\drivers\sptd.sys
[2011/09/14 17:46:12 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/09/14 17:46:12 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/09/14 17:45:43 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/08/31 19:12:00 | 001,698,408 | —- | M] (Realtek Semiconductor Corp.) – C:\Windows\RtlExUpd.dll
[5 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[3 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/09/21 10:50:25 | 000,000,000 | RHS- | C] () – C:\corh.ld
[2011/09/21 10:50:21 | 000,353,946 | RHS- | C] () – C:\YXOAU
[2011/09/20 14:56:22 | 667,418,072 | —- | C] () – C:\Windows\MEMORY.DMP
[2011/09/20 09:08:30 | 000,072,822 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2011/09/20 09:08:28 | 000,072,822 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2011/09/19 18:15:51 | 000,820,164 | —- | C] () – C:\Users\Andrei\AppData\Local\census.cache
[2011/09/19 18:15:03 | 000,104,769 | —- | C] () – C:\Users\Andrei\AppData\Local\ars.cache
[2011/09/19 18:04:07 | 000,000,036 | —- | C] () – C:\Users\Andrei\AppData\Local\housecall.guid.cache
[2011/09/17 04:31:56 | 000,002,154 | —- | C] () – C:\Windows\epplauncher.mif
[2011/09/17 04:29:40 | 000,788,870 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/17 04:29:14 | 000,001,897 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/09/14 19:46:06 | 000,000,110 | —- | C] () – C:\Users\Andrei\Documents\ax_files.xml
[2011/09/14 17:46:12 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/09/14 17:46:12 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/08/27 05:43:45 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\CmdLineExt03.dll
[2011/07/03 13:20:51 | 000,280,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/07/03 13:20:48 | 002,434,856 | —- | C] () – C:\Windows\SysWow64\pbsvc_bc2.exe
[2011/07/03 13:20:48 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2011/06/20 23:42:42 | 000,000,313 | —- | C] () – C:\Windows\doom3.ini
[2011/05/20 22:35:28 | 000,304,744 | —- | C] () – C:\Windows\SysWow64\nvStreaming.exe
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/02/25 23:15:43 | 000,010,240 | —- | C] () – C:\Windows\SysWow64\vidx16.dll
[2011/02/12 22:01:14 | 000,000,132 | —- | C] () – C:\Users\Andrei\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/02/10 20:01:50 | 000,021,840 | —- | C] () – C:\Windows\SysWow64\SIntfNT.dll
[2011/02/10 20:01:50 | 000,017,212 | —- | C] () – C:\Windows\SysWow64\SIntf32.dll
[2011/02/10 20:01:50 | 000,012,067 | —- | C] () – C:\Windows\SysWow64\SIntf16.dll
[2011/02/07 20:08:09 | 000,003,584 | —- | C] () – C:\Users\Andrei\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/04 01:27:42 | 000,165,376 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2011/01/02 04:07:19 | 000,069,632 | R— | C] () – C:\Windows\SysWow64\xmltok.dll
[2011/01/02 04:07:19 | 000,036,864 | R— | C] () – C:\Windows\SysWow64\xmlparse.dll
[2010/12/28 21:55:05 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\Access.dat
[2010/12/25 21:32:38 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/12/23 20:24:41 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2010/12/23 20:24:41 | 000,013,440 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2010/12/23 20:21:14 | 000,028,421 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2010/12/23 20:21:14 | 000,001,769 | —- | C] () – C:\Windows\Language_trs.ini
[2009/07/27 11:13:28 | 000,061,440 | —- | C] () – C:\Windows\SysWow64\ASDR.exe
[2009/07/14 07:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 04:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 04:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 02:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 01:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 23:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/07/06 04:48:34 | 000,013,368 | R— | C] () – C:\Windows\SysWow64\drivers\AsUpIO.sys
[2009/06/10 23:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/04/02 14:30:14 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS

========== LOP Check ==========

[2011/09/14 19:17:04 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\AVG2012
[2011/03/04 00:16:07 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Braid
[2011/02/17 19:22:08 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/09/14 16:43:31 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\DAEMON Tools Lite
[2011/09/26 09:18:11 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\foobar2000
[2011/09/17 13:57:02 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\IrfanView
[2011/06/16 18:58:35 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\KeePass
[2011/05/25 23:27:46 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Lionhead Studios
[2011/09/06 03:27:38 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\LolClient
[2011/04/04 03:44:40 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Octoshape
[2011/09/07 02:59:18 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\OnLive App
[2011/07/01 20:03:03 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\OpenDNS Updater
[2010/12/29 05:28:18 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\OpenOffice.org
[2011/03/17 04:37:02 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\PunkBuster
[2011/03/12 06:11:27 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Rainmeter
[2011/02/17 01:03:03 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/02/25 20:33:00 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\The Creative Assembly
[2011/07/05 11:40:26 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\The Longest Journey
[2011/09/25 20:18:18 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Tunngle
[2011/01/05 21:51:37 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Ubisoft
[2011/09/26 17:03:01 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\uTorrent
[2011/04/07 21:30:21 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Windows Live Writer
[2010/12/31 19:04:48 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\Wippien
[2011/09/17 23:44:18 | 000,000,000 | —D | M] – C:\Users\Andrei\AppData\Roaming\X-Chat 2
[2011/09/24 10:35:21 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/02/10 19:19:03 | 000,000,667 | —- | M] () – C:\BnetLog.txt
[2009/07/14 03:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2010/12/23 07:11:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2011/09/21 10:50:25 | 000,000,000 | RHS- | M] () – C:\corh.ld
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 08:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 08:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 08:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2007/11/07 08:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/09/26 17:07:12 | 3214,188,544 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 08:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2007/11/07 08:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 08:03:18 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 08:03:18 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 08:03:18 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 08:03:18 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 08:03:18 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 08:03:18 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 08:03:18 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 08:03:18 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/07/14 00:23:08 | 000,000,359 | -H– | M] () – C:\IPH.PH
[2006/12/02 00:37:14 | 000,904,704 | —- | M] (Microsoft Corporation) – C:\msdia80.dll
[2011/09/26 17:07:16 | 4285,587,456 | -HS- | M] () – C:\pagefile.sys
[2011/09/26 17:06:28 | 000,074,720 | —- | M] () – C:\TDSSKiller.2.6.1.0_26.09.2011_17.05.27_log.txt
[2007/11/07 08:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 08:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 08:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2011/09/21 10:50:21 | 000,353,946 | RHS- | M] () – C:\YXOAU

< %systemroot%\Fonts\*.com >
[2009/07/14 07:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 07:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 07:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 07:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 22:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 06:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/09/20 14:58:58 | 000,000,221 | -HS- | M] () – C:\Users\Andrei\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/09/26 17:09:19 | 000,582,656 | —- | M] (OldTimer Tools) – C:\Users\Andrei\Desktop\OTL.exe
[2011/09/26 09:22:32 | 001,548,080 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Andrei\Desktop\TDSSKiller.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/10 23:20:04 | 000,000,802 | —- | M] () – C:\Windows\ADDINS\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >
[2011/06/28 10:05:48 | 000,008,192 | —- | M] () – C:\Windows\SECURITY\Database\edb.chk
[2011/06/28 10:05:48 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edb.log
[2011/05/25 03:23:16 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00001.jrs
[2011/05/25 03:23:16 | 001,048,576 | —- | M] () – C:\Windows\SECURITY\Database\edbres00002.jrs
[2011/06/28 10:05:48 | 001,056,768 | —- | M] () – C:\Windows\SECURITY\Database\tmp.edb

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >
[2010/12/24 04:39:24 | 000,000,402 | -HS- | M] () – C:\Users\Andrei\Favorites\desktop.ini

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >

< %systemroot%\system32\system32\*.* >

< %ALLUSERSPROFILE%\*.dat /x >

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >

< dir /b "%systemroot%\*.exe" | find /i " " /c >

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

OTL log #2

OTL Extras logfile created on: 9/26/2011 5:11:40 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Andrei\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.99 Gb Total Physical Memory | 2.78 Gb Available Physical Memory | 69.67% Memory free
7.98 Gb Paging File | 6.68 Gb Available in Paging File | 83.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.88 Gb Total Space | 70.07 Gb Free Space | 30.09% Space Free | Partition Type: NTFS

Computer Name: MAINDESKTOP | User Name: Andrei | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\xchat\xchat.exe" = C:\Program Files (x86)\xchat\xchat.exe:*:Enabled:XChat IRC Client – ()
"C:\Program Files (x86)\xchat\xchat.exe" = C:\Program Files (x86)\xchat\xchat.exe:*:Enabled:XChat IRC Client – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0C682623-8F66-46A8-B9B3-93FE1E66A001}" = iTunes
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{42738DB0-FC3E-4672-A99B-9372F5696E30}" = Microsoft Security Client
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{963BFE7E-C350-4346-B43C-B02358306A45}" = Apple Mobile Device Support
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 280.26
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.4.28
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{E4F5E48E-7155-4CF9-88CD-7F377EC9AC54}" = Bonjour
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1A1FA4C1-2701-401C-8CE1-FDDE45304FF5}" = ASUS nVidia Driver
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 26
"{45410935-B52C-468A-A836-0D1000018201}" = BulletStorm
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4D53090A-CE35-42BD-B377-831000018301}" = Fable III
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"{7E40C178-43BD-4431-AC09-074336E57A87}" = Utility
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{809D7E6D-915D-4EAD-821F-E13D93F37161}" = ASUS Smart Doctor
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{918A9082-6287-4D25-9002-5E5D5E4971CB}" = League of Legends
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B93EEE50-9C8F-45DF-95E4-3D85A6E242F3}" = DarksidersInstaller
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE6097DD-05F4-4178-9719-D3170BF098E8}" = Apple Application Support
"{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"{EFE1AB94-5466-4B6E-BE31-FF4C115FD25D}" = Max Payne 2
"{F03CB3EF-DC16-35CE-B3C1-C68EA09E5E97}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"7-Zip" = 7-Zip 9.20
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Age of Wonders: Shadow Magic_is1" = Age of Wonders: Shadow Magic
"Akamai" = Akamai NetSession Interface
"Baldur's Gate II_is1" = Baldur's Gate II
"Beyond Good and Evil_is1" = Beyond Good and Evil
"CDisplay_is1" = CDisplay 1.8
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Diablo III Beta" = Diablo III Beta
"EPSON Scanner" = EPSON Scan
"foobar2000" = foobar2000 v1.1.1
"GOM Player" = GOM Player
"GomTVStreamer" = GOMTV Streamer
"Hard Reset_is1" = Hard Reset
"InstallShield_{65A92AAA-3D05-4C94-9F70-731C05E60C16}" = NVIDIA System Update
"InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}" = NVIDIA Performance
"InstallShield_{809D7E6D-915D-4EAD-821F-E13D93F37161}" = ASUS Smart Doctor
"InstallShield_{EEFB15EB-FE8B-47DF-A496-1C4D1420294A}" = Doom 3
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 6.7.0 (Standard)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Mozilla Firefox 7.0 (x86 en-US)" = Mozilla Firefox 7.0 (x86 en-US)
"Neverwinter Nights Diamond Edition_is1" = Neverwinter Nights Diamond Edition
"OpenAL" = OpenAL
"OpenDNS Updater" = OpenDNS Updater 2.2.1
"PunkBusterSvc" = PunkBuster Services
"StarCraft II" = StarCraft II
"Steam App 107100" = Bastion
"Steam App 24960" = Battlefield: Bad Company 2
"Steam App 42910" = Magicka
"Steam App 6310" = The Longest Journey
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"VLC media player" = VLC media player 1.1.5
"WinLiveSuite" = Windows Live Essentials
"xchat" = XChat 2 (remove only)
"xvid" = XviD MPEG-4 Video Codec
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/24/2011 6:31:07 PM | Computer Name = MainDesktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/24/2011 6:32:59 PM | Computer Name = MainDesktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/25/2011 7:47:27 AM | Computer Name = MainDesktop | Source = EventSystem | ID = 4621
Description =

Error - 9/25/2011 7:55:41 AM | Computer Name = MainDesktop | Source = MsiInstaller | ID = 11316
Description =

Error - 9/25/2011 8:41:51 AM | Computer Name = MainDesktop | Source = Application Hang | ID = 1002
Description = The program mpc-hc.exe version 1.4.2803.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 9e8 Start
Time: 01cc7b7ea7b9e64d Termination Time: 29 Application Path: C:\Program Files (x86)\K-Lite
Codec Pack\Media Player Classic\mpc-hc.exe Report Id: bb5ae5f0-e773-11e0-b5e8-bcaec503ae67


Error - 9/25/2011 6:31:09 PM | Computer Name = MainDesktop | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.

Error - 9/25/2011 6:31:12 PM | Computer Name = MainDesktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "C:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "C:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/25/2011 6:32:47 PM | Computer Name = MainDesktop | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/26/2011 2:10:01 AM | Computer Name = MainDesktop | Source = EventSystem | ID = 4621
Description =

Error - 9/26/2011 11:06:28 AM | Computer Name = MainDesktop | Source = EventSystem | ID = 4621
Description =

[ System Events ]
Error - 9/3/2011 11:56:32 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:34 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:36 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:37 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:39 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:39 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:40 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:40 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:42 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.

Error - 9/3/2011 11:56:44 PM | Computer Name = MainDesktop | Source = atapi | ID = 262155
Description = The driver detected a controller error on \Device\Ide\IdePort5.


< End of report >
Download Combofix from either of the links below, and save it to your desktop.

Link 1
Link 2



**Note: It is important that it is saved directly to your desktop**

——————————————————————–
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
——————————————————————–

Double click on ComboFix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt for further review.
ComboFix 11-09-26.02 - Andrei 09/26/2011 20:52:03.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.4087.2376 [GMT 2:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
SP: Microsoft Security Essentials *Disabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\Install.exe
c:\users\Andrei\AppData\Local\ApplicationHistory
c:\users\Andrei\AppData\Local\ApplicationHistory\ngen.exe.2c05686e.ini
.
.
((((((((((((((((((((((((( Files Created from 2011-08-26 to 2011-09-26 )))))))))))))))))))))))))))))))
.
.
2011-09-26 07:28 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2BAB8832-D581-420C-8AAC-873837BF4201}\mpengine.dll
2011-09-25 11:40 . 2011-09-25 12:02 ——– d—–w- c:\users\Andrei\AppData\Local\LogMeIn Hamachi
2011-09-21 09:31 . 2011-02-19 06:37 1135104 —-a-w- c:\windows\system32\FntCache.dll
2011-09-21 09:31 . 2011-02-19 06:37 1540608 —-a-w- c:\windows\system32\DWrite.dll
2011-09-21 09:31 . 2011-02-19 06:36 902656 —-a-w- c:\windows\system32\d2d1.dll
2011-09-21 09:31 . 2011-02-19 05:32 1074176 —-a-w- c:\windows\SysWow64\DWrite.dll
2011-09-21 09:31 . 2011-02-19 05:32 739840 —-a-w- c:\windows\SysWow64\d2d1.dll
2011-09-19 16:10 . 2011-09-19 16:10 388096 —-a-r- c:\users\Andrei\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-09-19 16:10 . 2011-09-19 16:10 ——– d—–w- c:\program files (x86)\Trend Micro
2011-09-18 07:02 . 2011-09-13 00:26 9049936 —-a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-09-18 01:39 . 2011-03-11 06:23 1657216 —-a-w- c:\windows\system32\drivers\ntfs.sys
2011-09-18 01:39 . 2011-03-11 06:18 2566144 —-a-w- c:\windows\system32\esent.dll
2011-09-18 01:39 . 2011-03-11 06:23 166272 —-a-w- c:\windows\system32\drivers\nvstor.sys
2011-09-18 01:39 . 2011-03-11 06:23 148352 —-a-w- c:\windows\system32\drivers\nvraid.sys
2011-09-18 01:39 . 2011-03-11 06:22 107904 —-a-w- c:\windows\system32\drivers\amdsata.sys
2011-09-18 01:39 . 2011-03-11 06:23 187264 —-a-w- c:\windows\system32\drivers\storport.sys
2011-09-18 01:39 . 2011-03-11 06:23 410496 —-a-w- c:\windows\system32\drivers\iaStorV.sys
2011-09-18 01:39 . 2011-03-11 06:22 27008 —-a-w- c:\windows\system32\drivers\amdxata.sys
2011-09-18 01:39 . 2011-03-11 05:39 1686016 —-a-w- c:\windows\SysWow64\esent.dll
2011-09-18 01:39 . 2011-03-11 06:15 96768 —-a-w- c:\windows\system32\fsutil.exe
2011-09-18 01:39 . 2011-03-11 05:37 74240 —-a-w- c:\windows\SysWow64\fsutil.exe
2011-09-18 00:57 . 2011-03-25 03:23 343040 —-a-w- c:\windows\system32\drivers\usbhub.sys
2011-09-18 00:57 . 2011-03-25 03:23 98816 —-a-w- c:\windows\system32\drivers\usbccgp.sys
2011-09-18 00:57 . 2011-03-25 03:23 324608 —-a-w- c:\windows\system32\drivers\usbport.sys
2011-09-18 00:57 . 2011-03-25 03:22 52224 —-a-w- c:\windows\system32\drivers\usbehci.sys
2011-09-18 00:57 . 2011-03-25 03:22 25600 —-a-w- c:\windows\system32\drivers\usbohci.sys
2011-09-18 00:57 . 2011-03-25 03:22 30720 —-a-w- c:\windows\system32\drivers\usbuhci.sys
2011-09-18 00:57 . 2011-03-25 03:22 7936 —-a-w- c:\windows\system32\drivers\usbd.sys
2011-09-17 06:33 . 2011-09-17 06:33 ——– d—–w- c:\program files (x86)\Microsoft.NET
2011-09-17 06:24 . 2011-09-17 06:24 ——– d—–w- c:\windows\system32\Wat
2011-09-17 06:17 . 2010-09-14 06:45 367104 —-a-w- c:\windows\system32\wcncsvc.dll
2011-09-17 06:17 . 2010-09-14 06:07 276992 —-a-w- c:\windows\SysWow64\wcncsvc.dll
2011-09-17 05:50 . 2011-09-17 05:50 ——– d—–w- c:\windows\SysWow64\URTTEMP
2011-09-17 04:25 . 2011-04-25 02:44 499712 —-a-w- c:\windows\system32\drivers\afd.sys
2011-09-17 03:54 . 2011-09-17 03:54 ——– d—–w- c:\program files (x86)\Realtek
2011-09-17 03:54 . 2011-09-17 03:58 ——– d–h–w- c:\program files (x86)\Temp
2011-09-17 03:54 . 2011-08-31 17:12 1698408 —-a-w- c:\windows\RtlExUpd.dll
2011-09-17 03:54 . 2006-02-07 13:44 65024 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ISBEW64.exe
2011-09-17 03:54 . 2006-02-07 13:40 204800 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iuser.dll
2011-09-17 03:54 . 2006-02-07 13:40 274432 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iscript.dll
2011-09-17 03:54 . 2006-02-07 13:40 69715 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\ctor.dll
2011-09-17 03:54 . 2005-11-13 21:19 5632 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\DotNetInstaller.exe
2011-09-17 03:54 . 2006-02-07 13:45 757760 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iKernel.dll
2011-09-17 03:54 . 2011-09-17 03:54 331908 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\setup.dll
2011-09-17 03:54 . 2011-09-17 03:54 200836 —-a-w- c:\program files (x86)\Common Files\InstallShield\Professional\RunTime\11\50\Intel32\iGdi.dll
2011-09-17 03:45 . 2011-06-15 09:58 106496 —-a-w- c:\windows\system32\odbccu32.dll
2011-09-17 03:45 . 2011-06-15 09:58 106496 —-a-w- c:\windows\system32\odbccr32.dll
2011-09-17 03:45 . 2011-06-15 09:58 212992 —-a-w- c:\windows\system32\odbctrac.dll
2011-09-17 03:45 . 2011-06-15 09:58 163840 —-a-w- c:\windows\system32\odbccp32.dll
2011-09-17 03:45 . 2011-06-15 09:58 126976 —-a-w- c:\program files\Common Files\System\Ole DB\msdaosp.dll
2011-09-17 03:45 . 2011-06-15 09:04 319488 —-a-w- c:\windows\SysWow64\odbcjt32.dll
2011-09-17 03:45 . 2011-06-15 09:04 122880 —-a-w- c:\windows\SysWow64\odbccp32.dll
2011-09-17 03:45 . 2011-06-15 09:04 86016 —-a-w- c:\windows\SysWow64\odbccu32.dll
2011-09-17 03:45 . 2011-06-15 09:04 81920 —-a-w- c:\windows\SysWow64\odbccr32.dll
2011-09-17 03:45 . 2011-06-15 09:04 163840 —-a-w- c:\windows\SysWow64\odbctrac.dll
2011-09-17 03:45 . 2011-06-15 09:04 94208 —-a-w- c:\program files (x86)\Common Files\System\Ole DB\msdaosp.dll
2011-09-17 03:45 . 2011-02-26 06:23 2870272 —-a-w- c:\windows\explorer.exe
2011-09-17 03:45 . 2011-02-26 05:33 2614784 —-a-w- c:\windows\SysWow64\explorer.exe
2011-09-17 03:44 . 2011-06-11 02:56 3134464 —-a-w- c:\windows\system32\win32k.sys
2011-09-17 03:44 . 2011-07-09 05:14 2048 —-a-w- c:\windows\system32\tzres.dll
2011-09-17 03:44 . 2011-07-09 04:30 2048 —-a-w- c:\windows\SysWow64\tzres.dll
2011-09-17 03:42 . 2011-07-09 02:44 287744 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-09-17 03:42 . 2011-05-04 02:51 157696 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-09-17 03:42 . 2011-05-04 02:51 126464 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-09-17 03:38 . 2011-02-24 06:30 476160 —-a-w- c:\windows\system32\XpsGdiConverter.dll
2011-09-17 03:38 . 2011-02-24 05:32 288256 —-a-w- c:\windows\SysWow64\XpsGdiConverter.dll
2011-09-17 03:38 . 2010-12-21 06:13 2003968 —-a-w- c:\windows\system32\msxml6.dll
2011-09-17 03:38 . 2010-12-21 06:13 1880576 —-a-w- c:\windows\system32\msxml3.dll
2011-09-17 03:38 . 2010-12-21 06:15 264192 —-a-w- c:\windows\system32\upnp.dll
2011-09-17 03:38 . 2010-12-21 05:38 204288 —-a-w- c:\windows\SysWow64\upnp.dll
2011-09-17 03:36 . 2011-01-26 06:53 982912 —-a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-09-17 03:36 . 2011-01-26 06:53 265088 —-a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-09-17 03:36 . 2010-11-02 05:18 229888 —-a-w- c:\windows\system32\XpsRasterService.dll
2011-09-17 03:36 . 2010-06-26 05:31 1863680 —-a-w- c:\windows\system32\ExplorerFrame.dll
2011-09-17 03:36 . 2010-06-26 05:14 1495040 —-a-w- c:\windows\SysWow64\ExplorerFrame.dll
2011-09-17 03:36 . 2011-01-26 06:31 144384 —-a-w- c:\windows\system32\cdd.dll
2011-09-17 03:36 . 2010-11-02 04:41 135168 —-a-w- c:\windows\SysWow64\XpsRasterService.dll
2011-09-17 03:34 . 2011-04-22 20:18 27008 —-a-w- c:\windows\system32\drivers\Diskdump.sys
2011-09-17 03:31 . 2011-03-03 06:17 182272 —-a-w- c:\windows\system32\dnsrslvr.dll
2011-09-17 03:31 . 2011-03-03 06:14 30208 —-a-w- c:\windows\system32\dnscacheugc.exe
2011-09-17 03:31 . 2011-03-03 05:27 28672 —-a-w- c:\windows\SysWow64\dnscacheugc.exe
2011-09-17 03:29 . 2011-01-17 06:17 197120 —-a-w- c:\windows\system32\d3d10_1.dll
2011-09-17 03:29 . 2011-01-17 05:38 161792 —-a-w- c:\windows\SysWow64\d3d10_1.dll
2011-09-17 03:29 . 2010-11-02 05:12 320512 —-a-w- c:\windows\system32\d3d10_1core.dll
2011-09-17 03:29 . 2010-11-02 04:35 218624 —-a-w- c:\windows\SysWow64\d3d10_1core.dll
2011-09-17 03:29 . 2011-04-29 03:13 461312 —-a-w- c:\windows\system32\drivers\srv.sys
2011-09-17 03:29 . 2011-04-29 03:12 399872 —-a-w- c:\windows\system32\drivers\srv2.sys
2011-09-17 03:29 . 2011-04-29 03:12 161792 —-a-w- c:\windows\system32\drivers\srvnet.sys
2011-09-17 03:29 . 2010-12-18 06:12 3138048 —-a-w- c:\windows\system32\mstscax.dll
2011-09-17 03:29 . 2010-12-18 05:30 2690560 —-a-w- c:\windows\SysWow64\mstscax.dll
2011-09-17 03:29 . 2010-12-18 05:26 1034240 —-a-w- c:\windows\SysWow64\mstsc.exe
2011-09-17 03:29 . 2010-12-18 06:08 1097216 —-a-w- c:\windows\system32\mstsc.exe
2011-09-17 03:24 . 2011-06-21 06:27 1896832 —-a-w- c:\windows\system32\drivers\tcpip.sys
2011-09-17 03:23 . 2010-10-27 05:18 5510528 —-a-w- c:\windows\system32\ntoskrnl.exe
2011-09-17 03:23 . 2010-10-27 05:16 1739176 —-a-w- c:\windows\system32\ntdll.dll
2011-09-17 03:23 . 2010-10-27 04:43 3901824 —-a-w- c:\windows\SysWow64\ntoskrnl.exe
2011-09-17 03:23 . 2010-10-27 04:40 1293120 —-a-w- c:\windows\SysWow64\ntdll.dll
2011-09-17 03:23 . 2010-10-27 04:43 3957120 —-a-w- c:\windows\SysWow64\ntkrnlpa.exe
2011-09-17 02:45 . 2011-05-24 11:21 404992 —-a-w- c:\windows\system32\umpnpmgr.dll
2011-09-17 02:45 . 2011-05-24 10:34 64512 —-a-w- c:\windows\SysWow64\devobj.dll
2011-09-17 02:45 . 2011-05-24 10:34 44544 —-a-w- c:\windows\SysWow64\devrtl.dll
2011-09-17 02:45 . 2011-05-24 10:34 145920 —-a-w- c:\windows\SysWow64\cfgmgr32.dll
2011-09-17 02:45 . 2011-05-24 10:32 252928 —-a-w- c:\windows\SysWow64\drvinst.exe
2011-09-17 02:38 . 2011-02-18 06:33 31232 —-a-w- c:\windows\system32\prevhost.exe
2011-09-17 02:38 . 2011-02-18 05:33 31232 —-a-w- c:\windows\SysWow64\prevhost.exe
2011-09-17 02:38 . 2011-02-12 06:14 267776 —-a-w- c:\windows\system32\FXSCOVER.exe
2011-09-17 02:38 . 2011-05-03 05:21 976896 —-a-w- c:\windows\system32\inetcomm.dll
2011-09-17 02:38 . 2011-05-03 04:50 740864 —-a-w- c:\windows\SysWow64\inetcomm.dll
2011-09-17 02:38 . 2010-11-30 09:43 601424 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2011-09-17 02:38 . 2010-11-30 09:43 601424 ——w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{0843CB17-13ED-453A-BFE2-1E523CC89821}\gapaengine.dll
2011-09-17 02:38 . 2011-02-23 05:15 90624 —-a-w- c:\windows\system32\drivers\bowser.sys
2011-09-17 02:33 . 2010-10-16 05:17 720896 —-a-w- c:\windows\system32\odbc32.dll
2011-09-17 02:33 . 2010-10-16 05:16 495616 —-a-w- c:\program files\Common Files\System\ado\msadox.dll
2011-09-17 02:33 . 2010-10-16 05:16 466944 —-a-w- c:\program files\Common Files\System\ado\msadomd.dll
2011-09-17 02:33 . 2010-10-16 05:16 1425408 —-a-w- c:\program files\Common Files\System\ado\msado15.dll
2011-09-17 02:33 . 2010-10-16 05:16 258048 —-a-w- c:\program files\Common Files\System\msadc\msadco.dll
2011-09-17 02:33 . 2010-10-16 04:34 573440 —-a-w- c:\windows\SysWow64\odbc32.dll
2011-09-17 02:33 . 2010-10-16 04:33 372736 —-a-w- c:\program files (x86)\Common Files\System\ado\msadox.dll
2011-09-17 02:33 . 2010-10-16 04:33 352256 —-a-w- c:\program files (x86)\Common Files\System\ado\msadomd.dll
2011-09-17 02:33 . 2010-10-16 04:33 987136 —-a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2011-09-17 02:33 . 2010-10-16 04:33 208896 —-a-w- c:\program files (x86)\Common Files\System\msadc\msadco.dll
2011-09-17 02:29 . 2011-09-17 02:29 ——– d—–w- c:\program files (x86)\Microsoft Security Client
2011-09-17 02:28 . 2010-04-09 11:06 374664 —-a-w- c:\windows\system32\drivers\netio.sys
2011-09-17 02:21 . 2011-08-16 06:48 8862544 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0A660923-0F30-4A45-885E-A2EDD5176F37}\mpengine.dll
2011-09-17 02:21 . 2010-10-19 20:51 270720 ——w- c:\windows\system32\MpSigStub.exe
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-09-24 13:57 . 2011-07-03 12:59 280736 —-a-w- c:\windows\SysWow64\PnkBstrB.xtr
2011-09-24 13:57 . 2011-07-03 11:20 280736 —-a-w- c:\windows\SysWow64\PnkBstrB.exe
2011-09-24 13:53 . 2011-07-03 11:20 215128 —-a-w- c:\windows\SysWow64\PnkBstrB.ex0
2011-08-27 03:43 . 2011-08-27 03:43 43520 —-a-w- c:\windows\SysWow64\CmdLineExt03.dll
2011-08-18 09:51 . 2011-05-18 14:29 404640 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-03 11:50 . 2011-06-28 08:11 2412136 —-a-w- c:\windows\SysWow64\nvapi.dll
2011-08-03 11:50 . 2011-06-28 08:11 12636776 —-a-w- c:\windows\SysWow64\nvd3dum.dll
2011-08-03 11:50 . 2011-05-25 01:21 8355944 —-a-w- c:\windows\system32\nvwgf2umx.dll
2011-08-03 11:50 . 2011-05-25 01:21 2758760 —-a-w- c:\windows\system32\nvapi64.dll
2011-08-03 11:50 . 2011-04-07 21:19 117864 —-a-w- c:\windows\system32\nvmctray.dll
2011-08-03 11:50 . 2011-04-07 21:19 980072 —-a-w- c:\windows\system32\nvvsvc.exe
2011-08-03 11:50 . 2011-04-07 21:19 836200 —-a-w- c:\windows\system32\easyupdatusapiu64.dll
2011-08-03 11:50 . 2011-04-07 21:19 61544 —-a-w- c:\windows\system32\nvshext.dll
2011-08-03 11:50 . 2011-04-07 21:19 6136936 —-a-w- c:\windows\system32\nvcpl.dll
2011-08-03 11:50 . 2011-04-07 21:19 3021416 —-a-w- c:\windows\system32\nvsvc64.dll
2011-07-19 10:08 . 2011-07-03 11:20 2434856 —-a-w- c:\windows\SysWow64\pbsvc_bc2.exe
2011-07-16 04:32 . 2011-09-17 02:49 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2011-07-03 13:43 . 2011-07-03 11:20 75136 —-a-w- c:\windows\SysWow64\PnkBstrA.exe
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"OpenDNS Updater"="c:\program files (x86)\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
"Pando Media Booster"="c:\program files (x86)\Pando Networks\Media Booster\PMB.exe" [2011-09-05 3077528]
"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2009-11-15 33120]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce]
"AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallati...ca56f572b" [?]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [2011-04-27 288272]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R3 WinRing0_1_2_0;WinRing0_1_2_0;c:\users\Andrei\Downloads\sad\WinRing0x64.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
S1 AsUpIO;AsUpIO;SysWow64\drivers\AsUpIO.sys [x]
S1 EIO64;EIO Driver;c:\windows\system32\DRIVERS\EIO64.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952]
S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2009-07-14 27136]
S2 nvUpdatusService;NVIDIA Update Service Daemon;c:\program files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe [2011-08-03 2255464]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 TunngleService;TunngleService;c:\games\Tunngle\TnglCtrl.exe [2011-06-15 737016]
S3 IOMap;IOMap;c:\windows\system32\drivers\IOMap64.sys [x]
S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
S3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);c:\windows\system32\DRIVERS\tap0901t.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contents of the 'Scheduled Tasks' folder
.
2011-09-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4002316052-3815423388-3284804311-1001Core.job
- c:\users\Andrei\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-14 00:04]
.
2011-09-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4002316052-3815423388-3284804311-1001UA.job
- c:\users\Andrei\AppData\Local\Google\Update\GoogleUpdate.exe [2011-03-14 00:04]
.
.
——— x86-64 ———–
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 1436736]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = my.daemon-search.com
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
TCP: DhcpNameServer = [removed] [removed]
TCP: Interfaces\{E40B5D32-70B5-4A5B-83A0-972193EEAD2E}: NameServer = 208.67.222.222,208.67.220.220
FF - ProfilePath - c:\users\Andrei\AppData\Roaming\Mozilla\Firefox\Profiles\3yurb4sk.default\
FF - prefs.js: browser.search.selectedEngine - DAEMON Search
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig
FF - user.js: yahoo.ytff.general.dontshowhpoffer - true);user_pref(network.protocol-handler.warn-external.dnupdate, false
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-EPSON Scanner - c:\program files (x86)\epson\escndv\setup\setup.exe
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc_bc2.exe
.
.
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-4002316052-3815423388-3284804311-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-4002316052-3815423388-3284804311-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-4002316052-3815423388-3284804311-1001\Software\SecuROM\License information*]
"datasecu"=hex:db,d5,9e,9f,15,0b,c9,65,ee,74,49,e1,60,6f,3f,e2,31,42,2e,78,1d,
33,e6,cc,ed,eb,7d,d1,87,72,26,ab,aa,56,b3,73,5b,f3,83,b0,da,ac,fe,98,84,56,\
"rkeysecu"=hex:86,d9,a6,61,7e,27,60,8e,27,e3,48,ba,35,3e,e2,28
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10p_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10p.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
———————— Other Running Processes ————————
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\windows\SysWOW64\ASDR.exe
c:\windows\SysWOW64\PnkBstrA.exe
c:\program files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\program files (x86)\ASUS\SmartDoctor\SmartDoctor.exe
.
**************************************************************************
.
Completion time: 2011-09-26 21:05:32 - machine was rebooted
ComboFix-quarantined-files.txt 2011-09-26 19:05
.
Pre-Run: 88,322,240,512 bytes free
Post-Run: 91,480,150,016 bytes free
.
- - End Of File - - 849FBAECD28FDF03D9A4D1D7BA3BF6A8
Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the log please












Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
PC seems to be running fine. Ping.exe no longer autoruns. Malwarebytes' Anti-Malware 1.51.2.1300 www.malwarebytes.org Database version: 7805 Windows 6.1.7600 Internet Explorer 9.0.8112.16421 9/27/2011 6:08:29 AM mbam-log-2011-09-27 (06-08-29).txt Scan type: Quick scan Objects scanned: 199376 Time elapsed: 2 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6528 # api_version=3.0.2 # EOSSerial=a001f1723fb5e049a109e67642bf3343 # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2011-09-27 05:43:25 # local_time=2011-09-27 07:43:25 (+0100, W. Europe Daylight Time) # country="United States" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=1024 16777215 100 0 837613 837613 0 0 # compatibility_mode=5893 16776574 100 94 836180 68726829 0 0 # compatibility_mode=8192 67108863 100 0 452 452 0 0 # scanned=222705 # found=0 # cleaned=0 # scan_time=5247
You appear clean of infections,please do the following.



ComboFix - Cleanup
Time for some housekeeping
  • Click Start…select Run from the menu.
  • Copy and paste the following into the text entry box:
    Combofix /Uninstall
  • Click the OK button. (See image below as reference.)
🖼Click to load external image (Posted Image)









Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.











Download TFC to your desktop

Close any open windows.
Double click the TFC icon to run the program
TFC will close all open programs itself in order to run,
Click the Start button to begin the process.
Allow TFC to run uninterrupted.
The program should not take long to finish it's job
Once its finished it should automatically reboot your machine,
if it doesn't, manually reboot to ensure a complete clean

















Here are some recommendations to help you stay clean.


Update your Antivirus programs and other security products regularly to avoid new threats that could infect your system.

Visit Microsoft often to get the latest updates for your computer.
http://www.update.microsoft.com/



Make sure you are running a FIREWALL.The windows firewall is not sufficient to protect your system. It doesn't monitor outgoing traffic and this is a must.
Please read this article 'Safe Computing Practices'.
So how did I get infected in the first place.

please take a moment to read quietman7's excellent prevention tips in post 3 here
Click >>>> Tips to protect yourself against malware and reduce the potential for re-infection:

Preventing Infections in the Future

Please also have a look at the following links, giving some advice and Tips to protect yourself against malware and reduce the potential for re-infection:

  • Avoid gaming sites, underground web pages, pirated software sites, and peer-to-peer (P2P) file sharing programs. They are a security risk which can make your computer susceptible to a smörgåsbord of malware infections, remote attacks, exposure of personal information, and identity theft. Many malicious worms and Trojans spread across P2P file sharing networks, gaming and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and Flash ads that install viruses, Trojans and spyware. Ads are a target for hackers because they offer a stealthy way to distribute malware to a wide range of Internet users. The best way to reduce the risk of infection is to avoid these types of web sites and not use any P2P applications. Read P2P Software User Advisories and Risks of File-Sharing Technology.

Update Non-Microsoft Programs

It is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector and Calendar of Updates.


Thats it you are good to go.Safe surfing

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI