This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ping.exe - CPU Virus

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has started running slowly after I accidentally allowed something to run off of a website.
It installed a program which kept asking for me to install an anti-virus program, which i knew was a virus and thus I went into safemode and ran Malware Bytes and deleted a few trojans, which stopped that program.

I began noticing my computer fan was always running at full speed and I became concerned. Looking at Task Manager, it appeared I had a program called PING.EXE taking up alot of resources. Looking online, I stumbled upon a few threads that had answers, but no one really seemed to fix it. I found this thread on your website

http://forums.whatthetech.com/index.php?sh…120395&st;=0


And followed the steps and got the ComboFix program which seemed to fix a lot of things, and I no longer have the ping.exe process. I KNOW now that I wasnt supposed to do that as your http://forums.whatthetech.com/index.php?showtopic=106388 thread specifies that clearly, but I had not looked at that beforehand. Although the problem seems to have disappeared, I am still worried that I may have keyloggers or something else still on the computer, so I am coming to you to ask for advice. I would appreatiate if you could check if there is anything else that either ComboFix or ping.exe did to my machine


Here are my log files from OTL:


OTL.txt:

OTL logfile created on: 11/11/2011 3:05:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.94 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.67% Memory free
7.87 Gb Paging File | 5.72 Gb Available in Paging File | 72.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 75.68 Gb Free Space | 17.04% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32

Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Max\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
PRC - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c5f091ea0acf3fe98c012c1c7251b286\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5bb0e725e6c2be05d136893ea8df3837\IAStorCommon.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll ()
MOD - C:\Windows\SysWOW64\flcdlmsg.dll ()
MOD - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (DpHost) – C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (McAfee Endpoint Encryption Agent) – C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (HPDayStarterService) – c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLCDLOCK) – c:\Windows\SysWOW64\flcdlock.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (AdobeActiveFileMonitor10.0) – C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMwareHostd) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (hpHotkeyMonitor) – C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (hpCMSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (jhi_service) Intel® – C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
SRV - (HPFSService) – C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (Atheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (uArcCapture) – C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (MfeEpeOpal) – C:\windows\SysNative\drivers\MfeEpeOpal.sys (McAfee, Inc.)
DRV:64bit: - (MfeEpePc) – C:\windows\SysNative\drivers\MfeEpePc.sys (McAfee, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmusb) – C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (DAMDrv) – C:\Windows\SysNative\drivers\DAMDrv64.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (ARCVCAM) – C:\Windows\SysNative\drivers\ArcSoftVCapture.sys (ArcSoft, Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8118

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:home"

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/05/08 18:26:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/05/08 18:26:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/09/21 10:34:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ [2011/09/30 23:26:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/30 15:10:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011/08/10 21:17:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]

[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/11/05 13:58:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions
[2011/09/12 12:41:25 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions\[removed]
[2011/08/23 17:48:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\pfy0baj9.default\extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Sunbird\Profiles\lux6pdqw.default\extensions
[2011/11/09 13:49:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/03 18:15:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/08/04 16:53:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/09 13:40:16 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
[2011/10/06 09:15:54 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2
[2011/11/09 13:40:11 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
[2011/10/06 09:15:51 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{20CC25E2-48C9-45E1-9A1F-1CCC1882B81B}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\[removed]
[2011/09/30 15:10:53 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2008/08/23 16:00:54 | 005,150,696 | —- | M] (MathMonkeys, LLC) – C:\Program Files (x86)\mozilla firefox\plugins\NPLM32.DLL
[2010/01/01 03:00:00 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 03:00:00 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 03:00:00 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Max\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Monster Dash = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknghehebaconkajgiobncfleofebcog\2.2_0\
CHR - Extension: DivX HiQ = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: WeatherByte = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlgbglmmkibkhhbnhegkokegdodlgfe\1.0.3_0\
CHR - Extension: AdBlock = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.28_0\
CHR - Extension: The Fancy Pants Adventure: World 2 = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk\14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\
CHR - Extension: Climb or Drown! = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoiaaaplodaeokegmjphakphcbmiip\1.1.0_0\
CHR - Extension: MegaSkipper = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.60_0\
CHR - Extension: Canvas Rider = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.7_0\

O1 HOSTS File: ([2011/11/11 14:23:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (File Sanitizer for HP ProtectTools) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MfeEpePcMonitor] C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futuremark.com/calico/syste…y/FMSI_v420.cab (FuturemarkSystemInfoX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2912C486-28C5-4AF2-B814-E069DD38267A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\kloehk.dll (Kaspersky Lab ZAO)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\sbhook64.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) -C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\sbhook.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\DeviceNP: DllName - (DeviceNP.dll) - C:\windows\SysWow64\DeviceNP.dll (Hewlett-Packard Company)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.VMnc - C:\windows\SysWow64\vmnc.dll (VMware, Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/11 14:44:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/11 14:39:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/11 14:39:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/11 14:23:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/11 14:06:08 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/11/11 14:05:05 | 000,000,000 | —D | C] – C:\Users\Max\Desktop\tdsskiller
[2011/11/11 13:54:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe
[2011/11/10 17:32:39 | 000,000,000 | —D | C] – C:\Sun
[2011/11/09 21:54:22 | 000,066,856 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:54:21 | 000,392,752 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:54:21 | 000,226,600 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:54:21 | 000,148,264 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:54:21 | 000,107,816 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:54:15 | 000,277,288 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:54:15 | 000,222,504 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:54:15 | 000,177,448 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:21:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wwanprotdim.dll
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 13:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2011/11/09 13:37:32 | 000,556,120 | —- | C] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 12:27:49 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2011/11/08 23:50:10 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Malwarebytes
[2011/11/08 23:50:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/08 23:50:02 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/11/08 16:29:24 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Local\VMware
[2011/11/08 16:29:23 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\VMware
[2011/11/08 16:27:01 | 000,062,064 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmx86.sys
[2011/11/08 16:26:28 | 000,354,416 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnetdhcp.exe
[2011/11/08 16:26:25 | 000,432,752 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnat.exe
[2011/11/08 16:26:24 | 000,030,320 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmnetuserif.sys
[2011/11/08 16:26:21 | 000,942,192 | —- | C] (VMware, Inc.) – C:\windows\SysNative\vnetlib64.dll
[2011/11/08 16:26:07 | 000,039,024 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\hcmon.sys
[2011/11/08 16:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\ProgramData\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Shared Virtual Machines
[2011/11/08 16:24:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2011/11/08 15:50:27 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Rainbows!
[2011/11/06 22:58:07 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Symantec
[2011/11/06 22:10:03 | 000,000,000 | —D | C] – C:\ProgramData\Wavefunction
[2011/11/06 21:08:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spartan '08 V1.2.0
[2011/11/06 21:07:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wavefunction
[2011/11/05 10:17:53 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011/11/05 10:17:52 | 000,000,000 | —D | C] – C:\Fraps
[2011/11/04 13:37:51 | 000,000,000 | —D | C] – C:\Users\Max\Documents\GTA San Andreas User Files
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rockstar Games
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\ProgramData\fltk.org
[2011/11/01 19:43:24 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Amnesia
[2011/11/01 12:11:18 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/10/26 11:38:07 | 000,000,000 | —D | C] – C:\Users\Max\Documents\NewBlueFX
[2011/10/26 09:02:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartSound Software
[2011/10/26 09:02:18 | 000,000,000 | —D | C] – C:\ProgramData\SmartSound Software Inc
[2011/10/24 16:54:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveMath
[2011/10/24 16:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\LiveMath
[2011/10/23 16:31:23 | 000,000,000 | —D | C] – C:\MC Server 1.8
[2011/10/13 16:35:41 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\MP3toiPodAudioBookConverter
[2011/10/13 11:48:43 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 to iPod Audio Book Converter
[2011/10/13 11:48:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\MP3ToIpodAudioBookConverter
[2011/02/24 00:10:36 | 000,020,432 | —- | C] (Intel Corporation) – C:\Users\Max\AppData\Roaming\JomCap.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/11 15:03:31 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/11 15:03:31 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/11 14:42:00 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job
[2011/11/11 14:39:06 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 14:23:29 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/11/11 14:22:59 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/11/11 14:22:53 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2011/11/11 14:04:27 | 001,545,878 | —- | M] () – C:\Users\Max\Desktop\tdsskiller.zip
[2011/11/11 13:54:12 | 000,007,598 | —- | M] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/11 13:54:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe
[2011/11/11 13:29:51 | 004,992,368 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/11/11 12:46:09 | 000,002,353 | —- | M] () – C:\Users\Max\Desktop\Google Chrome.lnk
[2011/11/11 12:15:09 | 000,000,848 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job
[2011/11/11 00:22:14 | 000,794,000 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/11/11 00:22:14 | 000,672,826 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/11/11 00:22:14 | 000,128,986 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/11/10 23:30:45 | 000,000,021 | —- | M] () – C:\windows\SurCode.INI
[2011/11/10 20:09:59 | 000,783,562 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/11/10 17:35:49 | 000,000,324 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/10 10:20:33 | 919,371,004 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/10 10:20:33 | 000,448,956 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/09 21:53:39 | 000,066,856 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:53:37 | 000,392,752 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:53:37 | 000,226,600 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:53:37 | 000,148,264 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:53:37 | 000,107,816 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:53:36 | 001,048,576 | —- | M] () – C:\windows\SysNative\syndata.bin
[2011/11/09 21:53:36 | 000,277,288 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:53:36 | 000,222,504 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:53:32 | 000,415,528 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCOM.dll
[2011/11/09 21:53:32 | 000,177,448 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:49:02 | 000,152,233 | —- | M] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:49:02 | 000,107,177 | —- | M] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:37:32 | 000,556,120 | —- | M] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 13:25:58 | 000,089,448 | —- | M] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 1124,496,892 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/09 12:32:53 | 000,549,116 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/08 23:56:16 | 000,000,000 | —- | M] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | M] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | M] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | M] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 1196,602,876 | —- | M] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/04 13:14:29 | 005,550,172 | —- | M] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/03 15:59:45 | 000,299,178 | —- | M] () – C:\Users\Max\Documents\marks.pdf
[2011/11/03 09:37:55 | 854,881,788 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/02 10:18:26 | 1086,019,068 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/02 10:18:26 | 000,530,332 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/01 12:17:00 | 1066,628,818 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:03:17 | 2150,422,524 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 09:00:50 | 004,856,572 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 09:00:49 | 1033,901,564 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 962,287,314 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:58:42 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:45 | 000,485,180 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:39 | 993,572,348 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/30 22:47:06 | 000,000,336 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMAXHP$.job
[2011/10/27 11:17:34 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/27 08:46:10 | 000,001,296 | —- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/10/26 21:14:46 | 1311,806,972 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 10:23:09 | 1082,578,642 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 08:57:51 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:22 | 002,429,826 | —- | M] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:47:52 | 000,332,874 | —- | M] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 975,943,164 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:40:16 | 000,476,572 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:38:48 | 1848,899,068 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/24 10:20:53 | 767,129,084 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:06 | 1077,736,956 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/22 12:17:02 | 1288,992,252 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/21 21:37:21 | 3818,616,316 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/20 09:59:45 | 1031,960,060 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/19 10:16:47 | 1101,297,148 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/18 14:20:51 | 1573,713,404 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.pkf
[2011/10/18 09:13:06 | 1021,621,756 | —- | M] () – C:\Users\Max\Documents\Chemistry October 18.wav
[2011/10/18 09:13:06 | 000,498,876 | —- | M] () – C:\Users\Max\Documents\Chemistry October 18.pkf
[2011/10/17 10:21:44 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/17 10:16:34 | 939,226,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 17th.wav
[2011/10/17 10:16:34 | 000,458,652 | —- | M] () – C:\Users\Max\Documents\Chemistry October 17th.pkf
[2011/10/17 10:13:40 | 1062,983,164 | —- | M] () – C:\Users\Max\Documents\Biology October 17th.wav
[2011/10/17 10:13:40 | 000,519,068 | —- | M] () – C:\Users\Max\Documents\Biology October 17th.pkf
[2011/10/15 20:39:41 | 000,269,496 | —- | M] () – C:\Users\Max\Documents\Unicron 2.png
[2011/10/15 20:39:00 | 000,361,940 | —- | M] () – C:\Users\Max\Documents\Unicorn.png
[2011/10/15 20:38:10 | 000,362,529 | —- | M] () – C:\Users\Max\Documents\Kat pic.png
[2011/10/15 20:34:02 | 000,000,132 | —- | M] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/14 11:13:19 | 1103,993,690 | —- | M] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).wav
[2011/10/14 11:13:19 | 000,539,100 | —- | M] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).pkf
[2011/10/13 09:25:53 | 926,137,596 | —- | M] () – C:\Users\Max\Documents\Chemistry October 13th.wav
[2011/10/13 09:25:53 | 000,452,252 | —- | M] () – C:\Users\Max\Documents\Chemistry October 13th.pkf
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/11 14:39:06 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 14:00:53 | 001,545,878 | —- | C] () – C:\Users\Max\Desktop\tdsskiller.zip
[2011/11/11 13:54:12 | 000,007,598 | —- | C] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/10 10:20:33 | 000,448,956 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/10 10:18:59 | 919,371,004 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/09 21:54:15 | 001,048,576 | —- | C] () – C:\windows\SysNative\syndata.bin
[2011/11/09 20:06:58 | 000,000,324 | —- | C] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:40:01 | 000,152,233 | —- | C] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:40:01 | 000,107,177 | —- | C] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:25:55 | 000,089,448 | —- | C] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 000,549,116 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/09 12:27:46 | 1124,496,892 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/08 23:56:16 | 000,000,000 | —- | C] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | C] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | C] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | C] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | C] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 005,550,172 | —- | C] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/04 13:12:21 | 1196,602,876 | —- | C] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/03 09:37:10 | 854,881,788 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:27:50 | 000,299,178 | —- | C] () – C:\Users\Max\Documents\marks.pdf
[2011/11/02 10:18:26 | 000,530,332 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/02 10:17:01 | 1086,019,068 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:15:49 | 1066,628,818 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 12:02:26 | 2150,422,524 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 09:00:49 | 004,856,572 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 08:59:39 | 1033,901,564 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:59:58 | 962,287,314 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 09:58:04 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:39 | 000,485,180 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:18 | 993,572,348 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/27 11:16:21 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 21:14:04 | 1311,806,972 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 10:22:39 | 1082,578,642 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 09:01:17 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/26 08:57:51 | 000,002,237 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 10.lnk
[2011/10/26 08:57:51 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:20 | 002,429,826 | —- | C] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:46:23 | 000,332,874 | —- | C] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 000,476,572 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:39:52 | 975,943,164 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/25 13:37:33 | 1848,899,068 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:20 | 767,129,084 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/24 10:18:26 | 1077,736,956 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/22 12:16:07 | 1288,992,252 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/21 21:34:21 | 3818,616,316 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/20 09:58:05 | 1031,960,060 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/19 10:15:28 | 1101,297,148 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.pkf
[2011/10/18 14:18:42 | 1573,713,404 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/18 09:13:06 | 000,498,876 | —- | C] () – C:\Users\Max\Documents\Chemistry October 18.pkf
[2011/10/18 09:11:51 | 1021,621,756 | —- | C] () – C:\Users\Max\Documents\Chemistry October 18.wav
[2011/10/17 10:16:34 | 000,458,652 | —- | C] () – C:\Users\Max\Documents\Chemistry October 17th.pkf
[2011/10/17 10:14:57 | 939,226,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 17th.wav
[2011/10/17 10:13:40 | 000,519,068 | —- | C] () – C:\Users\Max\Documents\Biology October 17th.pkf
[2011/10/17 10:11:43 | 1062,983,164 | —- | C] () – C:\Users\Max\Documents\Biology October 17th.wav
[2011/10/15 20:39:41 | 000,269,496 | —- | C] () – C:\Users\Max\Documents\Unicron 2.png
[2011/10/15 20:39:00 | 000,361,940 | —- | C] () – C:\Users\Max\Documents\Unicorn.png
[2011/10/15 20:38:09 | 000,362,529 | —- | C] () – C:\Users\Max\Documents\Kat pic.png
[2011/10/15 20:30:47 | 000,000,132 | —- | C] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/14 11:13:19 | 000,539,100 | —- | C] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).pkf
[2011/10/14 10:06:06 | 1103,993,690 | —- | C] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).wav
[2011/10/13 09:25:53 | 000,452,252 | —- | C] () – C:\Users\Max\Documents\Chemistry October 13th.pkf
[2011/10/13 09:25:02 | 926,137,596 | —- | C] () – C:\Users\Max\Documents\Chemistry October 13th.wav
[2011/10/06 09:16:51 | 000,017,408 | —- | C] () – C:\Users\Max\AppData\Local\WebpageIcons.db
[2011/09/05 08:57:34 | 000,366,136 | —- | C] () – C:\windows\SysWow64\flcdlmsg.dll
[2011/08/24 14:30:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPLic.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPPassFilter.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPCrProv.dll.hpsign
[2011/08/24 13:55:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApiUI.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPSCEL.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApi.dll.hpsign
[2011/08/24 13:53:42 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPClback.dll.hpsign
[2011/08/23 10:10:44 | 000,000,256 | —- | C] () – C:\windows\SysWow64\vcsAPIShared.dll.hpsign
[2011/07/02 21:54:28 | 000,186,460 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/06/15 20:03:03 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/14 17:25:49 | 000,000,021 | —- | C] () – C:\windows\SurCode.INI
[2011/05/30 21:58:34 | 000,185,168 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll
[2011/05/30 21:58:34 | 000,000,256 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll.hpsign
[2011/05/29 14:23:14 | 000,000,355 | —- | C] () – C:\windows\EReg176.dat
[2011/05/20 07:37:54 | 000,000,105 | —- | C] () – C:\windows\Antidote7.ini
[2011/05/18 16:53:37 | 000,963,116 | —- | C] () – C:\windows\SysWow64\igkrng600.bin
[2011/05/18 16:53:36 | 000,216,876 | —- | C] () – C:\windows\SysWow64\igfcg600m.bin
[2011/05/03 21:17:55 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\windows\SysWow64\xlive.dll.cat
[2011/04/08 20:00:20 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgchid.sys
[2011/04/08 19:38:38 | 000,025,984 | —- | C] () – C:\windows\snuvcdsm.exe
[2011/04/08 19:38:38 | 000,015,497 | —- | C] () – C:\windows\snp2uvc.ini
[2011/03/03 14:56:41 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbbb.sys
[2011/03/03 14:38:47 | 000,000,178 | —- | C] () – C:\windows\SysWow64\HPPA.ini
[2011/03/03 14:33:15 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbdf.sys
[2011/03/03 14:04:33 | 000,794,000 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/01/29 18:49:32 | 000,017,232 | —- | C] () – C:\windows\SysWow64\CoHpCasl.exe
[2011/01/26 21:55:20 | 000,145,804 | —- | C] () – C:\windows\SysWow64\igcompkrng600.bin
[2011/01/10 22:03:08 | 086,271,980 | —- | C] () – C:\windows\SysWow64\BioTrustFace.dat
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/11/08 19:56:01 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\.minecraft
[2011/09/01 14:33:45 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Auslogics
[2011/05/10 08:15:02 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Bioshock2
[2011/05/31 08:37:20 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Bitcoin
[2011/06/13 17:10:44 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/06 16:17:10 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/11/09 13:25:09 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DAEMON Tools Lite
[2011/05/03 15:44:26 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DigitalPersona
[2011/09/03 14:23:14 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DiskAid
[2011/11/11 14:25:39 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Dropbox
[2011/05/20 07:36:30 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Druide
[2011/05/17 19:29:15 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Dwarfs
[2011/11/01 19:43:30 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/08/26 20:45:09 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Garmin
[2011/05/03 16:28:46 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\IDT
[2011/08/21 21:57:08 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Imprudence
[2011/08/23 23:48:54 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\mkvtoolnix
[2011/10/13 16:35:41 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\MP3toiPodAudioBookConverter
[2011/06/14 17:25:49 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\PACE Anti-Piracy
[2011/07/26 10:50:26 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Pamela
[2011/05/20 21:07:29 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\poclbm
[2011/09/02 16:16:31 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Recordpad
[2011/06/14 17:32:07 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/05/03 15:51:01 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Synaptics
[2011/08/04 13:47:40 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\The Longest Journey
[2011/09/04 21:12:27 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Thinstall
[2011/09/30 19:26:15 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Ubisoft
[2011/11/10 16:56:42 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\uTorrent
[2011/10/31 21:19:44 | 000,032,584 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/09/14 13:41:14 | 000,004,913 | —- | M] () – C:\aaa.class
[2011/09/14 13:31:56 | 000,002,327 | —- | M] () – C:\acz.class
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/11/11 14:31:21 | 000,034,054 | —- | M] () – C:\ComboFix.txt
[2011/09/14 14:05:08 | 000,005,353 | —- | M] () – C:\dt.class
[2011/09/14 14:03:34 | 000,004,440 | —- | M] () – C:\em.class
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2011/09/14 14:01:06 | 000,001,063 | —- | M] () – C:\fs.class
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/11/11 14:22:53 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 07:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/09/10 11:26:58 | 000,000,342 | —- | M] () – C:\items-nofire.txt
[2011/09/14 14:00:32 | 000,001,234 | —- | M] () – C:\l.class
[2011/07/21 15:42:18 | 2239,683,208 | —- | M] () – C:\MVI_0942.MOV
[2011/11/11 14:22:55 | 4226,146,304 | -HS- | M] () – C:\pagefile.sys
[2011/09/14 17:05:50 | 000,000,889 | —- | M] () – C:\recipes-spawner.txt
[2011/10/05 09:04:28 | 000,000,184 | —- | M] () – C:\setup.log
[2011/09/14 16:25:36 | 000,020,426 | —- | M] () – C:\sz.class
[2011/11/09 13:39:47 | 000,001,886 | —- | M] () – C:\TDSSKiller.2.6.16.0_09.11.2011_13.36.25_log.txt
[2011/11/09 13:59:04 | 000,088,878 | —- | M] () – C:\TDSSKiller.2.6.16.0_09.11.2011_13.58.16_log.txt
[2011/11/11 14:05:38 | 000,089,222 | —- | M] () – C:\TDSSKiller.2.6.18.0_11.11.2011_14.05.09_log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2011/09/14 13:34:42 | 000,003,041 | —- | M] () – C:\xu.class
[2011/09/14 14:41:34 | 000,000,405 | —- | M] () – C:\ZBB.class
[2011/09/14 14:33:12 | 000,000,815 | —- | M] () – C:\ZBM.class
[2011/09/14 14:29:20 | 000,001,087 | —- | M] () – C:\ZBS.class
[2011/09/14 16:23:20 | 000,003,240 | —- | M] () – C:\ZBW.class
[2011/09/14 13:43:58 | 000,004,142 | —- | M] () – C:\zf.class
[2011/09/10 08:16:42 | 000,000,288 | —- | M] () – C:\ZINV.class
[2011/09/14 14:17:58 | 000,000,715 | —- | M] () – C:\ZP250.class
[2011/09/11 22:16:18 | 000,000,985 | —- | M] () – C:\ZRND.class

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/03 15:52:15 | 000,000,221 | -HS- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2011/11/11 13:54:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >
[2009/07/21 14:08:00 | 000,013,021 | —- | M] () – C:\windows\snp2uvc.src
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 979 bytes -> C:\ProgramData\Microsoft:fjShx0za62cdhqPiEGa
@Alternate Data Stream - 1210 bytes -> C:\ProgramData\Microsoft:53T6CuUbnjh9cGmZscbufI
@Alternate Data Stream - 1207 bytes -> C:\Program Files\Common Files\System:kfA4PGra19R2mcTahzOwvsUPu

< End of report >


Extras.txt:

OTL Extras logfile created on: 11/11/2011 3:05:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.94 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.67% Memory free
7.87 Gb Paging File | 5.72 Gb Available in Paging File | 72.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 75.68 Gb Free Space | 17.04% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32

Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{11538652-E5E4-37F1-86D7-418871E45292}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26F481C6-8DBE-4F8B-9D8D-715081C23ADE}" = Adobe Premiere Elements 10
"{2DA0E83F-81B5-4C3F-8F36-8AD30CFF67B4}" = HP ProtectTools Security Manager
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3D8EDF72-13CC-4E51-AAB6-32A20524D2E0}" = HP Power Assistant
"{3DAE9A67-DD8D-4EDB-91F7-7B5132B1864D}" = SmartSound Premiere Elements 10 x64 Plugin
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{483D5A49-A26B-4CB8-AA2D-0D1811322061}" = HP DayStarter
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4CDE3168-D060-4b7c-BC74-4D8F9BB01AFe}" = Python 3.2.2 (64-bit)
"{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}" = Corel Graphics - Windows Shell Extension 64 Bit
"{528E2373-AE49-4802-B4A8-326BBFDAD6A0}" = VmciSockets
"{55B52830-024A-443E-AF61-61E1E71AFA1B}" = Device Access Manager for HP ProtectTools
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{76997589-A71A-4651-9956-F2F79972A54D}" = HP HotKey Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{83DA38AB-1014-41C2-A3CD-E2B93832A71A}" = HP 3D DriveGuard
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8A0041CD-277C-4C1F-BFE4-7AC508B20B4C}" = Drive Encryption For HP ProtectTools
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{997C9EC4-B53D-479D-81B7-0AEC8D174BA1}" = iTunes
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ACA53F68-B003-4D0E-9C3D-0C4EE09D08A8}" = Privacy Manager for HP ProtectTools
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BFA2D2A7-4FAC-4862-B7A3-960B329C2177}" = Validity Fingerprint Sensor Driver
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D3A775F2-2674-4452-8D80-1FC1446052EE}" = Face Recognition for HP ProtectTools
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"CCleaner" = CCleaner
"HPProtectTools" = HP ProtectTools Security Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PremElem100" = Adobe Premiere Elements 10
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW® Graphics Suite X5
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{03046EBB-CB7C-4B98-BEFB-690EB955DA22}" = HP Setup
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}" = HP Wallpaper
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}" = ArcSoft Webcam Sharing Manager
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer
"{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data
"{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications ® Core
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 26
"{28FE073B-1230-4BF6-830C-7434FD0C0069}" = HP Software Framework
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars®: Knights of the Old Republic ™
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{340C0246-975B-420F-8ADD-DEA69B16FDEE}" = Adobe Premiere Elements 10 Content 1
"{344A1AA2-AC8E-4741-BDB0-65B68FDA883C}" = HP SoftPaq Download Manager
"{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = HP Webcam Driver
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45B92257-603B-49C1-943F-EC27367D7CE4}" = Chemistry Add-in for Word
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4F29521F-7338-4D15-8691-8FEEB987780C}" = Adobe Premiere Elements 10 HD Content 3
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{531000B3-DBEE-4115-BBF3-DA48B67C053F}" = HP Software Setup
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect
"{54C65FE7-83BD-4A5B-A9B4-41F793C5F241}" = HP System Default Settings
"{56CDB4FE-895F-4E0D-8BB4-9A8D4310898D}" = Antidote HD
"{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA
"{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist
"{5D037ECA-B00A-466F-848C-D21B4DB69DEA}" = Adobe Premiere Elements 10 HD Content 1
"{5D90E53A-BD7C-8F32-9B82-7733D0F0BC8E}" = Adobe Download Assistant
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{62272D4E-78E9-4BAD-B7AA-63072D06AAA9}" = HP Documentation
"{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6B5E7B4F-64A2-4DEB-B210-0DD92F940A01}" = HP QuickWeb
"{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}" = File Sanitizer For HP ProtectTools
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.1.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7A6B4340-7090-418F-8976-EE9650B35550}" = HP Connection Manager
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7C5B1ECD-FE93-4FB2-A51A-06451BA49969}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0000-0000-0000000FF1CE}" = Microsoft Office Word 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.WORD_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav
"{99C7D73D-E201-4D03-B8A4-5EDBA529B505}" = Adobe Premiere Elements 10 Content 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C8D1290-0A4C-446C-AD86-0590812660CC}" = Adobe Premiere Elements 10 Content
"{9F06F464-479A-403E-AF92-70CBB8D674A1}" = PRE10STI64Installer
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A129D1F2-CAC4-4AD7-B26D-3C6411B87DCC}" = Psychonauts
"{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT
"{A6365256-0FBA-4DCD-88CE-D92A4DC9328E}" = HP ESU for Microsoft Windows 7
"{A66DBCC6-8802-3D15-9FDF-9552742C08B0}" = Google Talk Plugin
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ADC70B7A-530B-46E3-8384-48D22681A41E}" = Theft Recovery for HP ProtectTools
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B001064C-D061-4BAE-9031-416A838D5536}" = Adobe Flash Player 10 ActiveX
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B39177F9-269D-4A9B-82F2-7A48589CCCEF}" = Garmin WebUpdater
"{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel® Identity Protection Technology 1.1.2.0
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C071157F-AB34-4D3F-A0DF-9AC544B3732E}" = Vicon boujou 5.0.2
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common
"{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}" = HP Support Assistant
"{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D1CE6204-061A-43B5-830F-6A8A35C4E0C6}" = Adobe Premiere Elements 10 HD Content 2
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications ® Core - English
"{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin
"{D66A42BA-3747-4628-9CE4-9E7C18C3ED95}" = Adobe Premiere Elements 10 Content 2
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{D7736EE8-AFCE-4735-BBE3-652CDFBBFCA8}_is1" = Imprudence Viewer 1.3.2
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}" = CorelDRAW Graphics Suite X5 - EN
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}" = Realtek Ethernet Controller All-In-One Windows Driver
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Premiere Elements 10 Content" = Adobe Premiere Elements 10 Content
"Adobe Premiere Elements 10 Content 1" = Adobe Premiere Elements 10 Content 1
"Adobe Premiere Elements 10 Content 2" = Adobe Premiere Elements 10 Content 2
"Adobe Premiere Elements 10 Content 3" = Adobe Premiere Elements 10 Content 3
"Adobe Premiere Elements 10 HD Content 1" = Adobe Premiere Elements 10 HD Content 1
"Adobe Premiere Elements 10 HD Content 2" = Adobe Premiere Elements 10 HD Content 2
"Adobe Premiere Elements 10 HD Content 3" = Adobe Premiere Elements 10 HD Content 3
"Bugs Bunny Lost In Time" = Bugs Bunny Lost In Time
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Debut" = Debut Video Capture Software
"DiskAid_is1" = DiskAid 4.5
"DivX Setup.divx.com" = DivX Setup
"DragonNest" = DragonNest
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"ESET Online Scanner" = ESET Online Scanner v3
"Fraps" = Fraps (remove only)
"Half-Life Decay PC_is1" = Half-Life Decay PC 1.0
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{ADC70B7A-530B-46E3-8384-48D22681A41E}" = Theft Recovery for HP ProtectTools
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"LiveMath Plug-In & ActiveX" = LiveMath Plug-In & ActiveX 3.5.9 [U18] - August 2008
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Messenger Plus!" = Messenger Plus! 5
"Mozilla Firefox 7.0.1 (x86 en-GB)" = Mozilla Firefox 7.0.1 (x86 en-GB)
"My HP Game Console" = HP Game Console
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Office14.WORD" = Microsoft Word 2010
"pepakura_viewer3en" = Pepakura Viewer 3
"Privoxy" = Privoxy (remove only)
"Recordpad" = RecordPad Sound Recorder
"Spartan '08 V1.2.0" = Spartan '08 V1.2.0
"Steam App 105600" = Terraria
"Steam App 12900" = Audiosurf
"Steam App 211" = Source SDK
"Steam App 218" = Source SDK Base 2007
"Steam App 220" = Half-Life 2
"Steam App 400" = Portal
"Steam App 40800" = Super Meat Boy
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 5" = Dedicated Server
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Steam App 629" = Portal 2 Authoring Tools - Beta
"Steam App 630" = Alien Swarm
"Steam App 70" = Half-Life
"The Longest Journey_is1" = The Longest Journey
"uTorrent" = µTorrent
"Vampire: The Masquerade - Bloodlines" = Vampire: The Masquerade - Bloodlines
"VIP Access SDK" = VIP Access SDK ([removed])
"VLC media player" = VLC media player 1.1.11
"VMware_Workstation" = VMware Workstation
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WT087330" = Bounce Symphony
"WT087361" = FATE
"WT087380" = John Deere Drive Green
"WT087394" = Penguins!
"WT087396" = Polar Bowler
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087480" = Insaniquarium Deluxe
"WT087485" = Jewel Quest II
"WT087490" = Jewel Quest Solitaire
"WT087501" = Plants vs. Zombies
"WT087510" = Slingo Deluxe
"WT087513" = Virtual Villagers - The Secret City
"WT087519" = Wedding Dash
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089303" = Build-a-Lot - The Elizabethan Era
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >


Appologies again for running ComboFix. I promise to follow all instructions from here on out.

If you can help, thanks.
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)



Post the log from Combofix,it is located at C:\combofix.txt

Open OTL,click run scan and post the new log.
Sorry, dont mean to double post. I thought I could edit my posts.

No threats found.
[external image: Posted Image]


The scan:

09:32:12.0423 1140 TDSS rootkit removing tool 2.6.18.0 Nov 11 2011 15:47:15
09:32:12.0940 1140 ============================================================
09:32:12.0940 1140 Current date / time: 2011/11/15 09:32:12.0940
09:32:12.0940 1140 SystemInfo:
09:32:12.0940 1140
09:32:12.0940 1140 OS Version: 6.1.7600 ServicePack: 0.0
09:32:12.0940 1140 Product type: Workstation
09:32:12.0941 1140 ComputerName: MAXHP
09:32:12.0941 1140 UserName: Max
09:32:12.0941 1140 Windows directory: C:\windows
09:32:12.0941 1140 System windows directory: C:\windows
09:32:12.0941 1140 Running under WOW64
09:32:12.0941 1140 Processor architecture: Intel x64
09:32:12.0941 1140 Number of processors: 4
09:32:12.0942 1140 Page size: 0x1000
09:32:12.0942 1140 Boot type: Normal boot
09:32:12.0942 1140 ============================================================
09:32:13.0570 1140 Initialize success
09:32:24.0835 6496 ============================================================
09:32:24.0835 6496 Scan started
09:32:24.0835 6496 Mode: Manual;
09:32:24.0835 6496 ============================================================
09:32:28.0313 6496 1394ohci (69aa89a20dee08bfa650aab6ce37bd10) C:\windows\system32\DRIVERS\1394ohci.sys
09:32:28.0346 6496 1394ohci - ok
09:32:28.0378 6496 Accelerometer (5c368f4b04ed2a923e6afca2d37baff5) C:\windows\system32\DRIVERS\Accelerometer.sys
09:32:28.0383 6496 Accelerometer - ok
09:32:28.0438 6496 ACPI (6f11e88748cdefd2f76aa215f97ddfe5) C:\windows\system32\DRIVERS\ACPI.sys
09:32:28.0450 6496 ACPI - ok
09:32:28.0519 6496 AcpiPmi (63b05a0420ce4bf0e4af6dcc7cada254) C:\windows\system32\DRIVERS\acpipmi.sys
09:32:28.0523 6496 AcpiPmi - ok
09:32:28.0705 6496 adp94xx (2f6b34b83843f0c5118b63ac634f5bf4) C:\windows\system32\DRIVERS\adp94xx.sys
09:32:28.0713 6496 adp94xx - ok
09:32:28.0780 6496 adpahci (597f78224ee9224ea1a13d6350ced962) C:\windows\system32\DRIVERS\adpahci.sys
09:32:28.0791 6496 adpahci - ok
09:32:28.0819 6496 adpu320 (e109549c90f62fb570b9540c4b148e54) C:\windows\system32\DRIVERS\adpu320.sys
09:32:28.0825 6496 adpu320 - ok
09:32:28.0860 6496 Afc - ok
09:32:29.0061 6496 AFD (6ef20ddf3172e97d69f596fb90602f29) C:\windows\system32\drivers\afd.sys
09:32:29.0086 6496 AFD - ok
09:32:29.0252 6496 AgereSoftModem (98022774d9930ecbb292e70db7601df6) C:\windows\system32\DRIVERS\agrsm64.sys
09:32:29.0288 6496 AgereSoftModem - ok
09:32:29.0354 6496 agp440 (608c14dba7299d8cb6ed035a68a15799) C:\windows\system32\DRIVERS\agp440.sys
09:32:29.0360 6496 agp440 - ok
09:32:29.0470 6496 aliide (5812713a477a3ad7363c7438ca2ee038) C:\windows\system32\DRIVERS\aliide.sys
09:32:29.0476 6496 aliide - ok
09:32:29.0501 6496 amdide (1ff8b4431c353ce385c875f194924c0c) C:\windows\system32\DRIVERS\amdide.sys
09:32:29.0507 6496 amdide - ok
09:32:29.0524 6496 AmdK8 (7024f087cff1833a806193ef9d22cda9) C:\windows\system32\DRIVERS\amdk8.sys
09:32:29.0527 6496 AmdK8 - ok
09:32:29.0571 6496 AmdPPM (1e56388b3fe0d031c44144eb8c4d6217) C:\windows\system32\DRIVERS\amdppm.sys
09:32:29.0575 6496 AmdPPM - ok
09:32:29.0603 6496 amdsata (ec7ebab00a4d8448bab68d1e49b4beb9) C:\windows\system32\drivers\amdsata.sys
09:32:29.0607 6496 amdsata - ok
09:32:29.0637 6496 amdsbs (f67f933e79241ed32ff46a4f29b5120b) C:\windows\system32\DRIVERS\amdsbs.sys
09:32:29.0642 6496 amdsbs - ok
09:32:29.0659 6496 amdxata (db27766102c7bf7e95140a2aa81d042e) C:\windows\system32\drivers\amdxata.sys
09:32:29.0661 6496 amdxata - ok
09:32:29.0799 6496 AppID (42fd751b27fa0e9c69bb39f39e409594) C:\windows\system32\drivers\appid.sys
09:32:29.0828 6496 AppID - ok
09:32:29.0898 6496 arc (c484f8ceb1717c540242531db7845c4e) C:\windows\system32\DRIVERS\arc.sys
09:32:29.0902 6496 arc - ok
09:32:29.0919 6496 arcsas (019af6924aefe7839f61c830227fe79c) C:\windows\system32\DRIVERS\arcsas.sys
09:32:29.0923 6496 arcsas - ok
09:32:30.0005 6496 ARCVCAM (357635f16d28558c50870f4ef8aa4712) C:\windows\system32\DRIVERS\ArcSoftVCapture.sys
09:32:30.0022 6496 ARCVCAM - ok
09:32:30.0102 6496 AsyncMac (769765ce2cc62867468cea93969b2242) C:\windows\system32\DRIVERS\asyncmac.sys
09:32:30.0109 6496 AsyncMac - ok
09:32:30.0151 6496 atapi (02062c0b390b7729edc9e69c680a6f3c) C:\windows\system32\DRIVERS\atapi.sys
09:32:30.0157 6496 atapi - ok
09:32:30.0268 6496 AthBTPort (cbe61b4494165f458bd87e37181ee934) C:\windows\system32\DRIVERS\btath_flt.sys
09:32:30.0273 6496 AthBTPort - ok
09:32:30.0439 6496 athr (a5e770426d18f8ef332a593f3289da91) C:\windows\system32\DRIVERS\athrx.sys
09:32:30.0498 6496 athr - ok
09:32:30.0668 6496 b06bdrv (3e5b191307609f7514148c6832bb0842) C:\windows\system32\DRIVERS\bxvbda.sys
09:32:30.0682 6496 b06bdrv - ok
09:32:30.0807 6496 b57nd60a (b5ace6968304a3900eeb1ebfd9622df2) C:\windows\system32\DRIVERS\b57nd60a.sys
09:32:30.0817 6496 b57nd60a - ok
09:32:30.0893 6496 Beep (16a47ce2decc9b099349a5f840654746) C:\windows\system32\drivers\Beep.sys
09:32:30.0917 6496 Beep - ok
09:32:30.0968 6496 blbdrive (61583ee3c3a17003c4acd0475646b4d3) C:\windows\system32\DRIVERS\blbdrive.sys
09:32:30.0971 6496 blbdrive - ok
09:32:31.0009 6496 bowser (19d20159708e152267e53b66677a4995) C:\windows\system32\DRIVERS\bowser.sys
09:32:31.0012 6496 bowser - ok
09:32:31.0035 6496 BrFiltLo (f09eee9edc320b5e1501f749fde686c8) C:\windows\system32\DRIVERS\BrFiltLo.sys
09:32:31.0037 6496 BrFiltLo - ok
09:32:31.0193 6496 BrFiltUp (b114d3098e9bdb8bea8b053685831be6) C:\windows\system32\DRIVERS\BrFiltUp.sys
09:32:31.0199 6496 BrFiltUp - ok
09:32:31.0238 6496 Brserid (43bea8d483bf1870f018e2d02e06a5bd) C:\windows\System32\Drivers\Brserid.sys
09:32:31.0248 6496 Brserid - ok
09:32:31.0267 6496 BrSerWdm (a6eca2151b08a09caceca35c07f05b42) C:\windows\System32\Drivers\BrSerWdm.sys
09:32:31.0272 6496 BrSerWdm - ok
09:32:31.0291 6496 BrUsbMdm (b79968002c277e869cf38bd22cd61524) C:\windows\System32\Drivers\BrUsbMdm.sys
09:32:31.0298 6496 BrUsbMdm - ok
09:32:31.0324 6496 BrUsbSer (a87528880231c54e75ea7a44943b38bf) C:\windows\System32\Drivers\BrUsbSer.sys
09:32:31.0329 6496 BrUsbSer - ok
09:32:31.0438 6496 BTATH_A2DP (227c8f308de4af4808e587465ceab838) C:\windows\system32\drivers\btath_a2dp.sys
09:32:31.0452 6496 BTATH_A2DP - ok
09:32:31.0493 6496 BTATH_BUS (a83a91d07d1fe6bbe7a9db46ca00434b) C:\windows\system32\DRIVERS\btath_bus.sys
09:32:31.0496 6496 BTATH_BUS - ok
09:32:31.0516 6496 BTATH_HCRP (c864ff85ee16d61c2bdd5ef76824625f) C:\windows\system32\DRIVERS\btath_hcrp.sys
09:32:31.0521 6496 BTATH_HCRP - ok
09:32:31.0549 6496 BTATH_LWFLT (0dea505efb5d771826d177ef8b8a208f) C:\windows\system32\DRIVERS\btath_lwflt.sys
09:32:31.0552 6496 BTATH_LWFLT - ok
09:32:31.0579 6496 BTATH_RCP (724c8088c96efe7a3e63fec21d4681c0) C:\windows\system32\DRIVERS\btath_rcp.sys
09:32:31.0585 6496 BTATH_RCP - ok
09:32:31.0787 6496 BtFilter (ff8b065f96e4d9525aa7227299fbd05c) C:\windows\system32\DRIVERS\btfilter.sys
09:32:31.0796 6496 BtFilter - ok
09:32:31.0845 6496 BthEnum (cf98190a94f62e405c8cb255018b2315) C:\windows\system32\drivers\BthEnum.sys
09:32:31.0873 6496 BthEnum - ok
09:32:31.0922 6496 BTHMODEM (9da669f11d1f894ab4eb69bf546a42e8) C:\windows\system32\DRIVERS\bthmodem.sys
09:32:31.0925 6496 BTHMODEM - ok
09:32:32.0029 6496 BthPan (02dd601b708dd0667e1331fa8518e9ff) C:\windows\system32\DRIVERS\bthpan.sys
09:32:32.0042 6496 BthPan - ok
09:32:32.0148 6496 BTHPORT (538392664fee486620dfea146f2500bc) C:\windows\System32\Drivers\BTHport.sys
09:32:32.0200 6496 BTHPORT - ok
09:32:32.0305 6496 BTHUSB (6e71522e317b22257d8e37a1584b5829) C:\windows\System32\Drivers\BTHUSB.sys
09:32:32.0348 6496 BTHUSB - ok
09:32:32.0383 6496 catchme - ok
09:32:32.0431 6496 cdfs (b8bd2bb284668c84865658c77574381a) C:\windows\system32\DRIVERS\cdfs.sys
09:32:32.0473 6496 cdfs - ok
09:32:32.0579 6496 cdrom (83d2d75e1efb81b3450c18131443f7db) C:\windows\system32\DRIVERS\cdrom.sys
09:32:32.0607 6496 cdrom - ok
09:32:32.0684 6496 circlass (d7cd5c4e1b71fa62050515314cfb52cf) C:\windows\system32\DRIVERS\circlass.sys
09:32:32.0687 6496 circlass - ok
09:32:32.0742 6496 CLFS (fe1ec06f2253f691fe36217c592a0206) C:\windows\system32\CLFS.sys
09:32:32.0746 6496 CLFS - ok
09:32:32.0865 6496 CmBatt (0840155d0bddf1190f84a663c284bd33) C:\windows\system32\DRIVERS\CmBatt.sys
09:32:32.0876 6496 CmBatt - ok
09:32:32.0937 6496 cmdide (e19d3f095812725d88f9001985b94edd) C:\windows\system32\DRIVERS\cmdide.sys
09:32:32.0955 6496 cmdide - ok
09:32:33.0005 6496 CNG (f95fd4cb7da00ba2a63ce9f6b5c053e1) C:\windows\system32\Drivers\cng.sys
09:32:33.0025 6496 CNG - ok
09:32:33.0172 6496 Compbatt (102de219c3f61415f964c88e9085ad14) C:\windows\system32\DRIVERS\compbatt.sys
09:32:33.0175 6496 Compbatt - ok
09:32:33.0271 6496 CompositeBus (f26b3a86f6fa87ca360b879581ab4123) C:\windows\system32\DRIVERS\CompositeBus.sys
09:32:33.0289 6496 CompositeBus - ok
09:32:33.0372 6496 cpuz135 - ok
09:32:33.0449 6496 crcdisk (1c827878a998c18847245fe1f34ee597) C:\windows\system32\DRIVERS\crcdisk.sys
09:32:33.0462 6496 crcdisk - ok
09:32:33.0561 6496 CSC (4a6173c2279b498cd8f57cae504564cb) C:\windows\system32\drivers\csc.sys
09:32:33.0604 6496 CSC - ok
09:32:33.0699 6496 DAMDrv (2e3374f9f0b5a3247b779978980c24cb) C:\windows\system32\DRIVERS\DAMDrv64.sys
09:32:33.0706 6496 DAMDrv - ok
09:32:33.0856 6496 DfsC (9c253ce7311ca60fc11c774692a13208) C:\windows\system32\Drivers\dfsc.sys
09:32:33.0862 6496 DfsC - ok
09:32:33.0918 6496 discache (13096b05847ec78f0977f2c0f79e9ab3) C:\windows\system32\drivers\discache.sys
09:32:33.0920 6496 discache - ok
09:32:33.0974 6496 Disk (9819eee8b5ea3784ec4af3b137a5244c) C:\windows\system32\DRIVERS\disk.sys
09:32:33.0980 6496 Disk - ok
09:32:34.0113 6496 drmkaud (9b19f34400d24df84c858a421c205754) C:\windows\system32\drivers\drmkaud.sys
09:32:34.0128 6496 drmkaud - ok
09:32:34.0197 6496 dtsoftbus01 (d3d64cf7b2bceaa34a270f45a3fffb36) C:\windows\system32\DRIVERS\dtsoftbus01.sys
09:32:34.0206 6496 dtsoftbus01 - ok
09:32:34.0292 6496 DXGKrnl (1633b9abf52784a1331476397a48cbef) C:\windows\System32\drivers\dxgkrnl.sys
09:32:34.0322 6496 DXGKrnl - ok
09:32:34.0401 6496 EagleX64 - ok
09:32:34.0591 6496 ebdrv (dc5d737f51be844d8c82c695eb17372f) C:\windows\system32\DRIVERS\evbda.sys
09:32:34.0722 6496 ebdrv - ok
09:32:34.0855 6496 elxstor (0e5da5369a0fcaea12456dd852545184) C:\windows\system32\DRIVERS\elxstor.sys
09:32:34.0865 6496 elxstor - ok
09:32:34.0882 6496 ErrDev (34a3c54752046e79a126e15c51db409b) C:\windows\system32\DRIVERS\errdev.sys
09:32:34.0885 6496 ErrDev - ok
09:32:35.0040 6496 exfat (a510c654ec00c1e9bdd91eeb3a59823b) C:\windows\system32\drivers\exfat.sys
09:32:35.0077 6496 exfat - ok
09:32:35.0197 6496 fastfat (0adc83218b66a6db380c330836f3e36d) C:\windows\system32\drivers\fastfat.sys
09:32:35.0205 6496 fastfat - ok
09:32:35.0266 6496 fdc (d765d19cd8ef61f650c384f62fac00ab) C:\windows\system32\DRIVERS\fdc.sys
09:32:35.0272 6496 fdc - ok
09:32:35.0325 6496 FileInfo (655661be46b5f5f3fd454e2c3095b930) C:\windows\system32\drivers\fileinfo.sys
09:32:35.0328 6496 FileInfo - ok
09:32:35.0369 6496 Filetrace (5f671ab5bc87eea04ec38a6cd5962a47) C:\windows\system32\drivers\filetrace.sys
09:32:35.0374 6496 Filetrace - ok
09:32:35.0404 6496 flpydisk (c172a0f53008eaeb8ea33fe10e177af5) C:\windows\system32\DRIVERS\flpydisk.sys
09:32:35.0406 6496 flpydisk - ok
09:32:35.0479 6496 FltMgr (f7866af72abbaf84b1fa5aa195378c59) C:\windows\system32\drivers\fltmgr.sys
09:32:35.0487 6496 FltMgr - ok
09:32:35.0525 6496 FsDepends (d43703496149971890703b4b1b723eac) C:\windows\system32\drivers\FsDepends.sys
09:32:35.0570 6496 FsDepends - ok
09:32:35.0602 6496 Fs_Rec (e95ef8547de20cf0603557c0cf7a9462) C:\windows\system32\drivers\Fs_Rec.sys
09:32:35.0648 6496 Fs_Rec - ok
09:32:35.0710 6496 fvevol (ae87ba80d0ec3b57126ed2cdc15b24ed) C:\windows\system32\DRIVERS\fvevol.sys
09:32:35.0713 6496 fvevol - ok
09:32:35.0804 6496 gagp30kx (8c778d335c9d272cfd3298ab02abe3b6) C:\windows\system32\DRIVERS\gagp30kx.sys
09:32:35.0811 6496 gagp30kx - ok
09:32:35.0852 6496 GEARAspiWDM (e403aacf8c7bb11375122d2464560311) C:\windows\system32\DRIVERS\GEARAspiWDM.sys
09:32:35.0862 6496 GEARAspiWDM - ok
09:32:35.0896 6496 hamachi (1e6438d4ea6e1174a3b3b1edc4de660b) C:\windows\system32\DRIVERS\hamachi.sys
09:32:35.0900 6496 hamachi - ok
09:32:35.0967 6496 hcmon (5bf776abedea06b0779c82e9d54b58d7) C:\windows\system32\drivers\hcmon.sys
09:32:35.0980 6496 hcmon - ok
09:32:36.0120 6496 hcw85cir (f2523ef6460fc42405b12248338ab2f0) C:\windows\system32\drivers\hcw85cir.sys
09:32:36.0127 6496 hcw85cir - ok
09:32:36.0180 6496 HdAudAddService (6410f6f415b2a5a9037224c41da8bf12) C:\windows\system32\drivers\HdAudio.sys
09:32:36.0190 6496 HdAudAddService - ok
09:32:36.0230 6496 HDAudBus (0a49913402747a0b67de940fb42cbdbb) C:\windows\system32\DRIVERS\HDAudBus.sys
09:32:36.0233 6496 HDAudBus - ok
09:32:36.0248 6496 HidBatt (78e86380454a7b10a5eb255dc44a355f) C:\windows\system32\DRIVERS\HidBatt.sys
09:32:36.0250 6496 HidBatt - ok
09:32:36.0269 6496 HidBth (7fd2a313f7afe5c4dab14798c48dd104) C:\windows\system32\DRIVERS\hidbth.sys
09:32:36.0272 6496 HidBth - ok
09:32:36.0345 6496 HidIr (0a77d29f311b88cfae3b13f9c1a73825) C:\windows\system32\DRIVERS\hidir.sys
09:32:36.0350 6496 HidIr - ok
09:32:36.0381 6496 HidUsb (b3bf6b5b50006def50b66306d99fcf6f) C:\windows\system32\DRIVERS\hidusb.sys
09:32:36.0386 6496 HidUsb - ok
09:32:36.0485 6496 hpdskflt (4e0bec0f78096ffd6d3314b497fc49d3) C:\windows\system32\DRIVERS\hpdskflt.sys
09:32:36.0488 6496 hpdskflt - ok
09:32:36.0585 6496 HpqKbFiltr (b98ee5d4535a685634b90f7e04de0df7) C:\windows\system32\DRIVERS\HpqKbFiltr.sys
09:32:36.0603 6496 HpqKbFiltr - ok
09:32:36.0736 6496 HpSAMD (0886d440058f203eba0e1825e4355914) C:\windows\system32\DRIVERS\HpSAMD.sys
09:32:36.0740 6496 HpSAMD - ok
09:32:36.0907 6496 HTTP (cee049cac4efa7f4e1e4ad014414a5d4) C:\windows\system32\drivers\HTTP.sys
09:32:36.0928 6496 HTTP - ok
09:32:36.0964 6496 hwpolicy (f17766a19145f111856378df337a5d79) C:\windows\system32\drivers\hwpolicy.sys
09:32:36.0966 6496 hwpolicy - ok
09:32:37.0026 6496 i8042prt (fa55c73d4affa7ee23ac4be53b4592d3) C:\windows\system32\DRIVERS\i8042prt.sys
09:32:37.0031 6496 i8042prt - ok
09:32:37.0157 6496 iaStor (d469b77687e12fe43e344806740b624d) C:\windows\system32\DRIVERS\iaStor.sys
09:32:37.0166 6496 iaStor - ok
09:32:37.0250 6496 iaStorV (b75e45c564e944a2657167d197ab29da) C:\windows\system32\drivers\iaStorV.sys
09:32:37.0258 6496 iaStorV - ok
09:32:37.0644 6496 igfx (795c99dc4f574c97c03d0bb39cf099ee) C:\windows\system32\DRIVERS\igdkmd64.sys
09:32:37.0913 6496 igfx - ok
09:32:38.0014 6496 iirsp (5c18831c61933628f5bb0ea2675b9d21) C:\windows\system32\DRIVERS\iirsp.sys
09:32:38.0017 6496 iirsp - ok
09:32:38.0068 6496 IntcDAud (fc727061c0f47c8059e88e05d5c8e381) C:\windows\system32\DRIVERS\IntcDAud.sys
09:32:38.0076 6496 IntcDAud - ok
09:32:38.0095 6496 intelide (f00f20e70c6ec3aa366910083a0518aa) C:\windows\system32\DRIVERS\intelide.sys
09:32:38.0099 6496 intelide - ok
09:32:38.0132 6496 intelppm (ada036632c664caa754079041cf1f8c1) C:\windows\system32\DRIVERS\intelppm.sys
09:32:38.0136 6496 intelppm - ok
09:32:38.0282 6496 IpFilterDriver (722dd294df62483cecaae6e094b4d695) C:\windows\system32\DRIVERS\ipfltdrv.sys
09:32:38.0296 6496 IpFilterDriver - ok
09:32:38.0348 6496 IPMIDRV (e2b4a4494db7cb9b89b55ca268c337c5) C:\windows\system32\DRIVERS\IPMIDrv.sys
09:32:38.0350 6496 IPMIDRV - ok
09:32:38.0370 6496 IPNAT (af9b39a7e7b6caa203b3862582e9f2d0) C:\windows\system32\drivers\ipnat.sys
09:32:38.0385 6496 IPNAT - ok
09:32:38.0431 6496 IRENUM (3abf5e7213eb28966d55d58b515d5ce9) C:\windows\system32\drivers\irenum.sys
09:32:38.0443 6496 IRENUM - ok
09:32:38.0567 6496 isapnp (2f7b28dc3e1183e5eb418df55c204f38) C:\windows\system32\DRIVERS\isapnp.sys
09:32:38.0579 6496 isapnp - ok
09:32:38.0635 6496 iScsiPrt (fa4d2557de56d45b0a346f93564be6e1) C:\windows\system32\DRIVERS\msiscsi.sys
09:32:38.0642 6496 iScsiPrt - ok
09:32:38.0753 6496 JMCR (0b44199365a69696109ab9a5855e0841) C:\windows\system32\DRIVERS\jmcr.sys
09:32:38.0758 6496 JMCR - ok
09:32:38.0879 6496 kbdclass (bc02336f1cba7dcc7d1213bb588a68a5) C:\windows\system32\DRIVERS\kbdclass.sys
09:32:38.0922 6496 kbdclass - ok
09:32:38.0983 6496 kbdhid (6def98f8541e1b5dceb2c822a11f7323) C:\windows\system32\DRIVERS\kbdhid.sys
09:32:39.0047 6496 kbdhid - ok
09:32:39.0286 6496 KL1 (8d7120743a0973ceab548b475c9d4289) C:\windows\system32\DRIVERS\kl1.sys
09:32:39.0304 6496 KL1 - ok
09:32:39.0435 6496 kl2 (cd146d8e525d6eebdcaf24120a8ab9ce) C:\windows\system32\DRIVERS\kl2.sys
09:32:39.0441 6496 kl2 - ok
09:32:39.0584 6496 KLIF (c1786c2f8de0f62e076f7ef8dea4e87a) C:\windows\system32\DRIVERS\klif.sys
09:32:39.0602 6496 KLIF - ok
09:32:39.0666 6496 KLIM6 (2a64b3a9eed93a2e96537b67c079fc96) C:\windows\system32\DRIVERS\klim6.sys
09:32:39.0674 6496 KLIM6 - ok
09:32:39.0733 6496 klmouflt (9468d07e91ba136d82415f5dfc1fe168) C:\windows\system32\DRIVERS\klmouflt.sys
09:32:39.0739 6496 klmouflt - ok
09:32:39.0828 6496 KSecDD (e8b6fcc9c83535c67f835d407620bd27) C:\windows\system32\Drivers\ksecdd.sys
09:32:39.0835 6496 KSecDD - ok
09:32:39.0859 6496 KSecPkg (a8c63880ef6f4d3fec7b616b9c060215) C:\windows\system32\Drivers\ksecpkg.sys
09:32:39.0864 6496 KSecPkg - ok
09:32:39.0987 6496 ksthunk (6869281e78cb31a43e969f06b57347c4) C:\windows\system32\drivers\ksthunk.sys
09:32:40.0024 6496 ksthunk - ok
09:32:40.0132 6496 lltdio (1538831cf8ad2979a04c423779465827) C:\windows\system32\DRIVERS\lltdio.sys
09:32:40.0181 6496 lltdio - ok
09:32:40.0276 6496 LSI_FC (1a93e54eb0ece102495a51266dcdb6a6) C:\windows\system32\DRIVERS\lsi_fc.sys
09:32:40.0298 6496 LSI_FC - ok
09:32:40.0355 6496 LSI_SAS (1047184a9fdc8bdbff857175875ee810) C:\windows\system32\DRIVERS\lsi_sas.sys
09:32:40.0361 6496 LSI_SAS - ok
09:32:40.0385 6496 LSI_SAS2 (30f5c0de1ee8b5bc9306c1f0e4a75f93) C:\windows\system32\DRIVERS\lsi_sas2.sys
09:32:40.0390 6496 LSI_SAS2 - ok
09:32:40.0415 6496 LSI_SCSI (0504eacaff0d3c8aed161c4b0d369d4a) C:\windows\system32\DRIVERS\lsi_scsi.sys
09:32:40.0423 6496 LSI_SCSI - ok
09:32:40.0486 6496 luafv (43d0f98e1d56ccddb0d5254cff7b356e) C:\windows\system32\drivers\luafv.sys
09:32:40.0491 6496 luafv - ok
09:32:40.0679 6496 megasas (a55805f747c6edb6a9080d7c633bd0f4) C:\windows\system32\DRIVERS\megasas.sys
09:32:40.0682 6496 megasas - ok
09:32:40.0717 6496 MegaSR (baf74ce0072480c3b6b7c13b2a94d6b3) C:\windows\system32\DRIVERS\MegaSR.sys
09:32:40.0722 6496 MegaSR - ok
09:32:40.0766 6496 MEIx64 (a6518dcc42f7a6e999bb3bea8fd87567) C:\windows\system32\DRIVERS\HECIx64.sys
09:32:40.0770 6496 MEIx64 - ok
09:32:40.0836 6496 MfeEpeOpal (b632a0472012a0d2150e6463b3283fd8) C:\windows\system32\drivers\MfeEpeOpal.sys
09:32:40.0841 6496 MfeEpeOpal - ok
09:32:40.0937 6496 MfeEpePc (44967d7b422e913a93f144a4bff7c16e) C:\windows\system32\drivers\MfeEpePc.sys
09:32:40.0942 6496 MfeEpePc - ok
09:32:40.0984 6496 Modem (800ba92f7010378b09f9ed9270f07137) C:\windows\system32\drivers\modem.sys
09:32:41.0003 6496 Modem - ok
09:32:41.0066 6496 monitor (b03d591dc7da45ece20b3b467e6aadaa) C:\windows\system32\DRIVERS\monitor.sys
09:32:41.0067 6496 monitor - ok
09:32:41.0132 6496 mouclass (7d27ea49f3c1f687d357e77a470aea99) C:\windows\system32\DRIVERS\mouclass.sys
09:32:41.0137 6496 mouclass - ok
09:32:41.0212 6496 mouhid (d3bf052c40b0c4166d9fd86a4288c1e6) C:\windows\system32\DRIVERS\mouhid.sys
09:32:41.0222 6496 mouhid - ok
09:32:41.0248 6496 mountmgr (791af66c4d0e7c90a3646066386fb571) C:\windows\system32\drivers\mountmgr.sys
09:32:41.0250 6496 mountmgr - ok
09:32:41.0281 6496 mpio (609d1d87649ecc19796f4d76d4c15cea) C:\windows\system32\DRIVERS\mpio.sys
09:32:41.0285 6496 mpio - ok
09:32:41.0317 6496 mpsdrv (6c38c9e45ae0ea2fa5e551f2ed5e978f) C:\windows\system32\drivers\mpsdrv.sys
09:32:41.0331 6496 mpsdrv - ok
09:32:41.0353 6496 MRxDAV (30524261bb51d96d6fcbac20c810183c) C:\windows\system32\drivers\mrxdav.sys
09:32:41.0386 6496 MRxDAV - ok
09:32:41.0468 6496 mrxsmb (040d62a9d8ad28922632137acdd984f2) C:\windows\system32\DRIVERS\mrxsmb.sys
09:32:41.0488 6496 mrxsmb - ok
09:32:41.0568 6496 mrxsmb10 (f0067552f8f9b33d7c59403ab808a3cb) C:\windows\system32\DRIVERS\mrxsmb10.sys
09:32:41.0577 6496 mrxsmb10 - ok
09:32:41.0600 6496 mrxsmb20 (3c142d31de9f2f193218a53fe2632051) C:\windows\system32\DRIVERS\mrxsmb20.sys
09:32:41.0607 6496 mrxsmb20 - ok
09:32:41.0654 6496 msahci (2ba4ff3d5eb68587dd662a896f649c7d) C:\windows\system32\DRIVERS\msahci.sys
09:32:41.0659 6496 msahci - ok
09:32:41.0696 6496 msdsm (8d27b597229aed79430fb9db3bcbfbd0) C:\windows\system32\DRIVERS\msdsm.sys
09:32:41.0705 6496 msdsm - ok
09:32:41.0745 6496 Msfs (aa3fb40e17ce1388fa1bedab50ea8f96) C:\windows\system32\drivers\Msfs.sys
09:32:41.0748 6496 Msfs - ok
09:32:41.0782 6496 mshidkmdf (f9d215a46a8b9753f61767fa72a20326) C:\windows\System32\drivers\mshidkmdf.sys
09:32:41.0786 6496 mshidkmdf - ok
09:32:41.0800 6496 msisadrv (d916874bbd4f8b07bfb7fa9b3ccae29d) C:\windows\system32\DRIVERS\msisadrv.sys
09:32:41.0802 6496 msisadrv - ok
09:32:41.0863 6496 MSKSSRV (49ccf2c4fea34ffad8b1b59d49439366) C:\windows\system32\drivers\MSKSSRV.sys
09:32:41.0872 6496 MSKSSRV - ok
09:32:41.0886 6496 MSPCLOCK (bdd71ace35a232104ddd349ee70e1ab3) C:\windows\system32\drivers\MSPCLOCK.sys
09:32:41.0895 6496 MSPCLOCK - ok
09:32:41.0903 6496 MSPQM (4ed981241db27c3383d72092b618a1d0) C:\windows\system32\drivers\MSPQM.sys
09:32:41.0931 6496 MSPQM - ok
09:32:41.0976 6496 MsRPC (89cb141aa8616d8c6a4610fa26c60964) C:\windows\system32\drivers\MsRPC.sys
09:32:41.0988 6496 MsRPC - ok
09:32:42.0029 6496 mssmbios (0eed230e37515a0eaee3c2e1bc97b288) C:\windows\system32\DRIVERS\mssmbios.sys
09:32:42.0035 6496 mssmbios - ok
09:32:42.0074 6496 MSTEE (2e66f9ecb30b4221a318c92ac2250779) C:\windows\system32\drivers\MSTEE.sys
09:32:42.0098 6496 MSTEE - ok
09:32:42.0120 6496 MTConfig (7ea404308934e675bffde8edf0757bcd) C:\windows\system32\DRIVERS\MTConfig.sys
09:32:42.0126 6496 MTConfig - ok
09:32:42.0215 6496 Mup (f9a18612fd3526fe473c1bda678d61c8) C:\windows\system32\Drivers\mup.sys
09:32:42.0236 6496 Mup - ok
09:32:42.0285 6496 NativeWifiP (1ea3749c4114db3e3161156ffffa6b33) C:\windows\system32\DRIVERS\nwifi.sys
09:32:42.0298 6496 NativeWifiP - ok
09:32:42.0356 6496 NDIS (cad515dbd07d082bb317d9928ce8962c) C:\windows\system32\drivers\ndis.sys
09:32:42.0368 6496 NDIS - ok
09:32:42.0421 6496 NdisCap (9f9a1f53aad7da4d6fef5bb73ab811ac) C:\windows\system32\DRIVERS\ndiscap.sys
09:32:42.0448 6496 NdisCap - ok
09:32:42.0501 6496 NdisTapi (30639c932d9fef22b31268fe25a1b6e5) C:\windows\system32\DRIVERS\ndistapi.sys
09:32:42.0514 6496 NdisTapi - ok
09:32:42.0539 6496 Ndisuio (f105ba1e22bf1f2ee8f005d4305e4bec) C:\windows\system32\DRIVERS\ndisuio.sys
09:32:42.0569 6496 Ndisuio - ok
09:32:42.0620 6496 NdisWan (557dfab9ca1fcb036ac77564c010dad3) C:\windows\system32\DRIVERS\ndiswan.sys
09:32:42.0637 6496 NdisWan - ok
09:32:42.0673 6496 NDProxy (659b74fb74b86228d6338d643cd3e3cf) C:\windows\system32\drivers\NDProxy.sys
09:32:42.0700 6496 NDProxy - ok
09:32:42.0750 6496 NetBIOS (86743d9f5d2b1048062b14b1d84501c4) C:\windows\system32\DRIVERS\netbios.sys
09:32:42.0755 6496 NetBIOS - ok
09:32:42.0840 6496 NetBT (9162b273a44ab9dce5b44362731d062a) C:\windows\system32\DRIVERS\netbt.sys
09:32:42.0847 6496 NetBT - ok
09:32:42.0915 6496 nfrd960 (77889813be4d166cdab78ddba990da92) C:\windows\system32\DRIVERS\nfrd960.sys
09:32:42.0918 6496 nfrd960 - ok
09:32:42.0944 6496 Npfs (1e4c4ab5c9b8dd13179bbdc75a2a01f7) C:\windows\system32\drivers\Npfs.sys
09:32:42.0947 6496 Npfs - ok
09:32:42.0981 6496 nsiproxy (e7f5ae18af4168178a642a9247c63001) C:\windows\system32\drivers\nsiproxy.sys
09:32:42.0983 6496 nsiproxy - ok
09:32:43.0035 6496 Ntfs (378e0e0dfea67d98ae6ea53adbbd76bc) C:\windows\system32\drivers\Ntfs.sys
09:32:43.0065 6496 Ntfs - ok
09:32:43.0148 6496 Null (9899284589f75fa8724ff3d16aed75c1) C:\windows\system32\drivers\Null.sys
09:32:43.0180 6496 Null - ok
09:32:43.0225 6496 nusb3hub (9a33100ac62a0463c49e47ee8e77083a) C:\windows\system32\DRIVERS\nusb3hub.sys
09:32:43.0230 6496 nusb3hub - ok
09:32:43.0262 6496 nusb3xhc (87c321f7bee646b7ec6eedd6eb725741) C:\windows\system32\DRIVERS\nusb3xhc.sys
09:32:43.0268 6496 nusb3xhc - ok
09:32:43.0302 6496 nvraid (a4d9c9a608a97f59307c2f2600edc6a4) C:\windows\system32\drivers\nvraid.sys
09:32:43.0307 6496 nvraid - ok
09:32:43.0378 6496 nvstor (6c1d5f70e7a6a3fd1c90d840edc048b9) C:\windows\system32\drivers\nvstor.sys
09:32:43.0383 6496 nvstor - ok
09:32:43.0469 6496 nv_agp (270d7cd42d6e3979f6dd0146650f0e05) C:\windows\system32\DRIVERS\nv_agp.sys
09:32:43.0474 6496 nv_agp - ok
09:32:43.0503 6496 ohci1394 (3589478e4b22ce21b41fa1bfc0b8b8a0) C:\windows\system32\DRIVERS\ohci1394.sys
09:32:43.0521 6496 ohci1394 - ok
09:32:43.0644 6496 Parport (0086431c29c35be1dbc43f52cc273887) C:\windows\system32\DRIVERS\parport.sys
09:32:43.0649 6496 Parport - ok
09:32:43.0712 6496 partmgr (7daa117143316c4a1537e074a5a9eaf0) C:\windows\system32\drivers\partmgr.sys
09:32:43.0716 6496 partmgr - ok
09:32:43.0761 6496 pci (f36f6504009f2fb0dfd1b17a116ad74b) C:\windows\system32\DRIVERS\pci.sys
09:32:43.0768 6496 pci - ok
09:32:43.0794 6496 pciide (b5b8b5ef2e5cb34df8dcf8831e3534fa) C:\windows\system32\DRIVERS\pciide.sys
09:32:43.0799 6496 pciide - ok
09:32:43.0825 6496 pcmcia (b2e81d4e87ce48589f98cb8c05b01f2f) C:\windows\system32\DRIVERS\pcmcia.sys
09:32:43.0831 6496 pcmcia - ok
09:32:43.0852 6496 pcw (d6b9c2e1a11a3a4b26a182ffef18f603) C:\windows\system32\drivers\pcw.sys
09:32:43.0856 6496 pcw - ok
09:32:43.0913 6496 PEAUTH (68769c3356b3be5d1c732c97b9a80d6e) C:\windows\system32\drivers\peauth.sys
09:32:43.0962 6496 PEAUTH - ok
09:32:44.0107 6496 PptpMiniport (27cc19e81ba5e3403c48302127bda717) C:\windows\system32\DRIVERS\raspptp.sys
09:32:44.0113 6496 PptpMiniport - ok
09:32:44.0172 6496 Processor (0d922e23c041efb1c3fac2a6f943c9bf) C:\windows\system32\DRIVERS\processr.sys
09:32:44.0177 6496 Processor - ok
09:32:44.0241 6496 Psched (ee992183bd8eaefd9973f352e587a299) C:\windows\system32\DRIVERS\pacer.sys
09:32:44.0244 6496 Psched - ok
09:32:44.0358 6496 PxHlpa64 (87b04878a6d59d6c79251dc960c674c1) C:\windows\system32\Drivers\PxHlpa64.sys
09:32:44.0361 6496 PxHlpa64 - ok
09:32:44.0432 6496 ql2300 (a53a15a11ebfd21077463ee2c7afeef0) C:\windows\system32\DRIVERS\ql2300.sys
09:32:44.0460 6496 ql2300 - ok
09:32:44.0551 6496 ql40xx (4f6d12b51de1aaeff7dc58c4d75423c8) C:\windows\system32\DRIVERS\ql40xx.sys
09:32:44.0556 6496 ql40xx - ok
09:32:44.0649 6496 QWAVEdrv (76707bb36430888d9ce9d705398adb6c) C:\windows\system32\drivers\qwavedrv.sys
09:32:44.0677 6496 QWAVEdrv - ok
09:32:44.0722 6496 RasAcd (5a0da8ad5762fa2d91678a8a01311704) C:\windows\system32\DRIVERS\rasacd.sys
09:32:44.0736 6496 RasAcd - ok
09:32:44.0764 6496 RasAgileVpn (7ecff9b22276b73f43a99a15a6094e90) C:\windows\system32\DRIVERS\AgileVpn.sys
09:32:44.0777 6496 RasAgileVpn - ok
09:32:44.0800 6496 Rasl2tp (87a6e852a22991580d6d39adc4790463) C:\windows\system32\DRIVERS\rasl2tp.sys
09:32:44.0831 6496 Rasl2tp - ok
09:32:44.0892 6496 RasPppoe (855c9b1cd4756c5e9a2aa58a15f58c25) C:\windows\system32\DRIVERS\raspppoe.sys
09:32:44.0908 6496 RasPppoe - ok
09:32:44.0939 6496 RasSstp (e8b1e447b008d07ff47d016c2b0eeecb) C:\windows\system32\DRIVERS\rassstp.sys
09:32:44.0944 6496 RasSstp - ok
09:32:44.0978 6496 rdbss (3bac8142102c15d59a87757c1d41dce5) C:\windows\system32\DRIVERS\rdbss.sys
09:32:44.0983 6496 rdbss - ok
09:32:45.0055 6496 rdpbus (302da2a0539f2cf54d7c6cc30c1f2d8d) C:\windows\system32\DRIVERS\rdpbus.sys
09:32:45.0061 6496 rdpbus - ok
09:32:45.0110 6496 RDPCDD (cea6cc257fc9b7715f1c2b4849286d24) C:\windows\system32\DRIVERS\RDPCDD.sys
09:32:45.0111 6496 RDPCDD - ok
09:32:45.0147 6496 RDPDR (9706b84dbabfc4b4ca46c5a82b14dfa3) C:\windows\system32\drivers\rdpdr.sys
09:32:45.0154 6496 RDPDR - ok
09:32:45.0241 6496 RDPENCDD (bb5971a4f00659529a5c44831af22365) C:\windows\system32\drivers\rdpencdd.sys
09:32:45.0242 6496 RDPENCDD - ok
09:32:45.0276 6496 RDPREFMP (216f3fa57533d98e1f74ded70113177a) C:\windows\system32\drivers\rdprefmp.sys
09:32:45.0277 6496 RDPREFMP - ok
09:32:45.0299 6496 RDPWD (8a3e6bea1c53ea6177fe2b6eba2c80d7) C:\windows\system32\drivers\RDPWD.sys
09:32:45.0307 6496 RDPWD - ok
09:32:45.0345 6496 rdyboost (634b9a2181d98f15941236886164ec8b) C:\windows\system32\drivers\rdyboost.sys
09:32:45.0349 6496 rdyboost - ok
09:32:45.0488 6496 RFCOMM (3dd798846e2c28102b922c56e71b7932) C:\windows\system32\DRIVERS\rfcomm.sys
09:32:45.0522 6496 RFCOMM - ok
09:32:45.0603 6496 rspndr (ddc86e4f8e7456261e637e3552e804ff) C:\windows\system32\DRIVERS\rspndr.sys
09:32:45.0618 6496 rspndr - ok
09:32:45.0748 6496 RTL8167 (2777226ee8bf50b059d7a7c90177e99c) C:\windows\system32\DRIVERS\Rt64win7.sys
09:32:45.0757 6496 RTL8167 - ok
09:32:45.0780 6496 RTL8192su - ok
09:32:45.0809 6496 s3cap (88af6e02ab19df7fd07ecdf9c91e9af6) C:\windows\system32\DRIVERS\vms3cap.sys
09:32:45.0812 6496 s3cap - ok
09:32:45.0922 6496 SASDIFSV - ok
09:32:45.0941 6496 SASKUTIL - ok
09:32:46.0030 6496 sbp2port (9f0439389fbd5b5f900966c5c66bcfab) C:\windows\system32\DRIVERS\sbp2port.sys
09:32:46.0036 6496 sbp2port - ok
09:32:46.0076 6496 scfilter (c94da20c7e3ba1dca269bc8460d98387) C:\windows\system32\DRIVERS\scfilter.sys
09:32:46.0209 6496 scfilter - ok
09:32:46.0255 6496 sdbus (2c8d162efaf73abd36d8bcbb6340cae7) C:\windows\system32\DRIVERS\sdbus.sys
09:32:46.0263 6496 sdbus - ok
09:32:46.0388 6496 secdrv (3ea8a16169c26afbeb544e0e48421186) C:\windows\system32\drivers\secdrv.sys
09:32:46.0391 6496 secdrv - ok
09:32:46.0437 6496 Serenum (cb624c0035412af0debec78c41f5ca1b) C:\windows\system32\DRIVERS\serenum.sys
09:32:46.0439 6496 Serenum - ok
09:32:46.0458 6496 Serial (c1d8e28b2c2adfaec4ba89e9fda69bd6) C:\windows\system32\DRIVERS\serial.sys
09:32:46.0463 6496 Serial - ok
09:32:46.0511 6496 sermouse (1c545a7d0691cc4a027396535691c3e3) C:\windows\system32\DRIVERS\sermouse.sys
09:32:46.0516 6496 sermouse - ok
09:32:46.0669 6496 sffdisk (a554811bcd09279536440c964ae35bbf) C:\windows\system32\DRIVERS\sffdisk.sys
09:32:46.0674 6496 sffdisk - ok
09:32:46.0733 6496 sffp_mmc (ff414f0baefeba59bc6c04b3db0b87bf) C:\windows\system32\DRIVERS\sffp_mmc.sys
09:32:46.0739 6496 sffp_mmc - ok
09:32:46.0768 6496 sffp_sd (178298f767fe638c9fedcbdef58bb5e4) C:\windows\system32\DRIVERS\sffp_sd.sys
09:32:46.0773 6496 sffp_sd - ok
09:32:46.0792 6496 sfloppy (a9d601643a1647211a1ee2ec4e433ff4) C:\windows\system32\DRIVERS\sfloppy.sys
09:32:46.0798 6496 sfloppy - ok
09:32:47.0017 6496 SiSRaid2 (843caf1e5fde1ffd5ff768f23a51e2e1) C:\windows\system32\DRIVERS\SiSRaid2.sys
09:32:47.0027 6496 SiSRaid2 - ok
09:32:47.0083 6496 SiSRaid4 (6a6c106d42e9ffff8b9fcb4f754f6da4) C:\windows\system32\DRIVERS\sisraid4.sys
09:32:47.0091 6496 SiSRaid4 - ok
09:32:47.0222 6496 Smb (548260a7b8654e024dc30bf8a7c5baa4) C:\windows\system32\DRIVERS\smb.sys
09:32:47.0267 6496 Smb - ok
09:32:47.0369 6496 SNP2UVC (43fbaa2c9e6b01b6afc40b69019c27ec) C:\windows\system32\DRIVERS\snp2uvc.sys
09:32:47.0398 6496 SNP2UVC - ok
09:32:47.0469 6496 spldr (b9e31e5cacdfe584f34f730a677803f9) C:\windows\system32\drivers\spldr.sys
09:32:47.0477 6496 spldr - ok
09:32:47.0558 6496 srv (2408c0366d96bcdf63e8f1c78e4a29c5) C:\windows\system32\DRIVERS\srv.sys
09:32:47.0571 6496 srv - ok
09:32:47.0608 6496 srv2 (76548f7b818881b47d8d1ae1be9c11f8) C:\windows\system32\DRIVERS\srv2.sys
09:32:47.0627 6496 srv2 - ok
09:32:47.0654 6496 srvnet (0af6e19d39c70844c5caa8fb0183c36e) C:\windows\system32\DRIVERS\srvnet.sys
09:32:47.0659 6496 srvnet - ok
09:32:47.0782 6496 stexstor (f3817967ed533d08327dc73bc4d5542a) C:\windows\system32\DRIVERS\stexstor.sys
09:32:47.0793 6496 stexstor - ok
09:32:47.0841 6496 STHDA (eba98394a7d58f7552c52192bd8fa7e6) C:\windows\system32\DRIVERS\stwrt64.sys
09:32:47.0855 6496 STHDA - ok
09:32:47.0894 6496 storflt (ffd7a6f15b14234b5b0e5d49e7961895) C:\windows\system32\DRIVERS\vmstorfl.sys
09:32:47.0897 6496 storflt - ok
09:32:47.0942 6496 storvsc (8fccbefc5c440b3c23454656e551b09a) C:\windows\system32\DRIVERS\storvsc.sys
09:32:47.0946 6496 storvsc - ok
09:32:48.0013 6496 swenum (d01ec09b6711a5f8e7e6564a4d0fbc90) C:\windows\system32\DRIVERS\swenum.sys
09:32:48.0015 6496 swenum - ok
09:32:48.0099 6496 SynTP (0b0ae2373ff3b31cd02f30bd71c7d14c) C:\windows\system32\DRIVERS\SynTP.sys
09:32:48.0115 6496 SynTP - ok
09:32:48.0273 6496 Tcpip (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\drivers\tcpip.sys
09:32:48.0309 6496 Tcpip - ok
09:32:48.0547 6496 TCPIP6 (f18f56efc0bfb9c87ba01c37b27f4da5) C:\windows\system32\DRIVERS\tcpip.sys
09:32:48.0560 6496 TCPIP6 - ok
09:32:48.0710 6496 tcpipreg (76d078af6f587b162d50210f761eb9ed) C:\windows\system32\drivers\tcpipreg.sys
09:32:48.0728 6496 tcpipreg - ok
09:32:48.0764 6496 TDPIPE (3371d21011695b16333a3934340c4e7c) C:\windows\system32\drivers\tdpipe.sys
09:32:48.0800 6496 TDPIPE - ok
09:32:48.0848 6496 TDTCP (e4245bda3190a582d55ed09e137401a9) C:\windows\system32\drivers\tdtcp.sys
09:32:48.0887 6496 TDTCP - ok
09:32:48.0919 6496 tdx (079125c4b17b01fcaeebce0bcb290c0f) C:\windows\system32\DRIVERS\tdx.sys
09:32:49.0002 6496 tdx - ok
09:32:49.0048 6496 TermDD (c448651339196c0e869a355171875522) C:\windows\system32\DRIVERS\termdd.sys
09:32:49.0084 6496 TermDD - ok
09:32:49.0260 6496 TPM (dbcc20c02e8a3e43b03c304a4e40a84f) C:\windows\system32\drivers\tpm.sys
09:32:49.0267 6496 TPM - ok
09:32:49.0320 6496 tssecsrv (61b96c26131e37b24e93327a0bd1fb95) C:\windows\system32\DRIVERS\tssecsrv.sys
09:32:49.0332 6496 tssecsrv - ok
09:32:49.0402 6496 tunnel (3836171a2cdf3af8ef10856db9835a70) C:\windows\system32\DRIVERS\tunnel.sys
09:32:49.0411 6496 tunnel - ok
09:32:49.0467 6496 uagp35 (b4dd609bd7e282bfc683cec7eaaaad67) C:\windows\system32\DRIVERS\uagp35.sys
09:32:49.0472 6496 uagp35 - ok
09:32:49.0575 6496 udfs (0e5e962b5649d544be54e8c90761ea2b) C:\windows\system32\DRIVERS\udfs.sys
09:32:49.0610 6496 udfs - ok
09:32:49.0660 6496 uliagpkx (4bfe1bc28391222894cbf1e7d0e42320) C:\windows\system32\DRIVERS\uliagpkx.sys
09:32:49.0665 6496 uliagpkx - ok
09:32:49.0691 6496 umbus (eab6c35e62b1b0db0d1b48b671d3a117) C:\windows\system32\DRIVERS\umbus.sys
09:32:49.0721 6496 umbus - ok
09:32:49.0768 6496 UmPass (b2e8e8cb557b156da5493bbddcc1474d) C:\windows\system32\DRIVERS\umpass.sys
09:32:49.0787 6496 UmPass - ok
09:32:49.0853 6496 USBAAPL64 (aa33fc47ed58c34e6e9261e4f850b7eb) C:\windows\system32\Drivers\usbaapl64.sys
09:32:49.0858 6496 USBAAPL64 - ok
09:32:49.0988 6496 usbaudio (77b01bc848298223a95d4ec23e1785a1) C:\windows\system32\drivers\usbaudio.sys
09:32:50.0000 6496 usbaudio - ok
09:32:50.0039 6496 usbccgp (537a4e03d7103c12d42dfd8ffdb5bdc9) C:\windows\system32\DRIVERS\usbccgp.sys
09:32:50.0066 6496 usbccgp - ok
09:32:50.0117 6496 usbcir (af0892a803fdda7492f595368e3b68e7) C:\windows\system32\DRIVERS\usbcir.sys
09:32:50.0123 6496 usbcir - ok
09:32:50.0158 6496 usbehci (fbb21ebe49f6d560db37ac25fbc68e66) C:\windows\system32\drivers\usbehci.sys
09:32:50.0201 6496 usbehci - ok
09:32:50.0315 6496 usbhub (6b7a8a99c4a459e73c286a6763ea24cc) C:\windows\system32\DRIVERS\usbhub.sys
09:32:50.0339 6496 usbhub - ok
09:32:50.0378 6496 usbohci (8c88aa7617b4cbc2e4bed61d26b33a27) C:\windows\system32\drivers\usbohci.sys
09:32:50.0385 6496 usbohci - ok
09:32:50.0413 6496 usbprint (73188f58fb384e75c4063d29413cee3d) C:\windows\system32\DRIVERS\usbprint.sys
09:32:50.0416 6496 usbprint - ok
09:32:50.0444 6496 USBSTOR (f39983647bc1f3e6100778ddfe9dce29) C:\windows\system32\DRIVERS\USBSTOR.SYS
09:32:50.0446 6496 USBSTOR - ok
09:32:50.0474 6496 usbuhci (0b5b3b2df3fd1709618acfa50b8392b0) C:\windows\system32\drivers\usbuhci.sys
09:32:50.0527 6496 usbuhci - ok
09:32:50.0600 6496 usbvideo (7cb8c573c6e4a2714402cc0a36eab4fe) C:\windows\system32\Drivers\usbvideo.sys
09:32:50.0610 6496 usbvideo - ok
09:32:50.0818 6496 vdrvroot (c5c876ccfc083ff3b128f933823e87bd) C:\windows\system32\DRIVERS\vdrvroot.sys
09:32:50.0821 6496 vdrvroot - ok
09:32:50.0889 6496 vga (da4da3f5e02943c2dc8c6ed875de68dd) C:\windows\system32\DRIVERS\vgapnp.sys
09:32:50.0998 6496 vga - ok
09:32:51.0055 6496 VgaSave (53e92a310193cb3c03bea963de7d9cfc) C:\windows\System32\drivers\vga.sys
09:32:51.0091 6496 VgaSave - ok
09:32:51.0163 6496 vhdmp (c82e748660f62a242b2dfac1442f22a4) C:\windows\system32\DRIVERS\vhdmp.sys
09:32:51.0170 6496 vhdmp - ok
09:32:51.0212 6496 viaide (e5689d93ffe4e5d66c0178761240dd54) C:\windows\system32\DRIVERS\viaide.sys
09:32:51.0217 6496 viaide - ok
09:32:51.0305 6496 vmbus (1501699d7eda984abc4155a7da5738d1) C:\windows\system32\DRIVERS\vmbus.sys
09:32:51.0310 6496 vmbus - ok
09:32:51.0376 6496 VMBusHID (ae10c35761889e65a6f7176937c5592c) C:\windows\system32\DRIVERS\VMBusHID.sys
09:32:51.0381 6496 VMBusHID - ok
09:32:51.0485 6496 vmci (87fc1dd880e8cac4faebb84af61a87c4) C:\windows\system32\DRIVERS\vmci.sys
09:32:51.0491 6496 vmci - ok
09:32:51.0553 6496 VMnetAdapter (b259c31378bc855afd1b53f59311c251) C:\windows\system32\DRIVERS\vmnetadapter.sys
09:32:51.0575 6496 VMnetAdapter - ok
09:32:51.0620 6496 VMnetBridge (dec4ce720ffeda939cf1ba315cfbd993) C:\windows\system32\DRIVERS\vmnetbridge.sys
09:32:51.0626 6496 VMnetBridge - ok
09:32:51.0712 6496 VMnetuserif (227982e986c02b710630d7fc570caa77) C:\windows\system32\drivers\vmnetuserif.sys
09:32:51.0717 6496 VMnetuserif - ok
09:32:51.0760 6496 vmusb (415b167695c4b5960a13098622ef3d80) C:\windows\system32\Drivers\vmusb.sys
09:32:51.0777 6496 vmusb - ok
09:32:51.0916 6496 vmx86 (86aa5eae57e2eaef3b6f5c16b27e0ec4) C:\windows\system32\drivers\vmx86.sys
09:32:51.0920 6496 vmx86 - ok
09:32:52.0020 6496 volmgr (2b1a3dae2b4e70dbba822b7a03fbd4a3) C:\windows\system32\DRIVERS\volmgr.sys
09:32:52.0041 6496 volmgr - ok
09:32:52.0127 6496 volmgrx (99b0cbb569ca79acaed8c91461d765fb) C:\windows\system32\drivers\volmgrx.sys
09:32:52.0134 6496 volmgrx - ok
09:32:52.0201 6496 volsnap (c9d0eaf58d6ba71e128e715ea43ad87d) C:\windows\system32\drivers\volsnap.sys
09:32:52.0213 6496 volsnap - ok
09:32:52.0252 6496 vpcbus (abd9b4a7e2d0ae51a3b8df1af3152d61) C:\windows\system32\DRIVERS\vpchbus.sys
09:32:52.0272 6496 vpcbus - ok
09:32:52.0308 6496 vpcnfltr (8acda395841538ce9713a67fe8b2a3eb) C:\windows\system32\DRIVERS\vpcnfltr.sys
09:32:52.0313 6496 vpcnfltr - ok
09:32:52.0375 6496 vpcusb (31924e31bc315773e6d149b157db46d5) C:\windows\system32\DRIVERS\vpcusb.sys
09:32:52.0387 6496 vpcusb - ok
09:32:52.0456 6496 vpcvmm (510d250a08c09850f5c78ca2011b3b62) C:\windows\system32\drivers\vpcvmm.sys
09:32:52.0477 6496 vpcvmm - ok
09:32:52.0648 6496 vsmraid (5e2016ea6ebaca03c04feac5f330d997) C:\windows\system32\DRIVERS\vsmraid.sys
09:32:52.0656 6496 vsmraid - ok
09:32:52.0672 6496 vstor2-mntapi10-shared - ok
09:32:52.0798 6496 vwifibus (36d4720b72b5c5d9cb2b9c29e9df67a1) C:\windows\system32\DRIVERS\vwifibus.sys
09:32:52.0801 6496 vwifibus - ok
09:32:52.0874 6496 vwififlt (6a3d66263414ff0d6fa754c646612f3f) C:\windows\system32\DRIVERS\vwififlt.sys
09:32:52.0936 6496 vwififlt - ok
09:32:52.0964 6496 vwifimp (6a638fc4bfddc4d9b186c28c91bd1a01) C:\windows\system32\DRIVERS\vwifimp.sys
09:32:52.0968 6496 vwifimp - ok
09:32:53.0015 6496 WacomPen (4e9440f4f152a7b944cb1663d3935a3e) C:\windows\system32\DRIVERS\wacompen.sys
09:32:53.0019 6496 WacomPen - ok
09:32:53.0095 6496 WANARP (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys
09:32:53.0180 6496 WANARP - ok
09:32:53.0191 6496 Wanarpv6 (47ca49400643effd3f1c9a27e1d69324) C:\windows\system32\DRIVERS\wanarp.sys
09:32:53.0199 6496 Wanarpv6 - ok
09:32:53.0354 6496 Wd (72889e16ff12ba0f235467d6091b17dc) C:\windows\system32\DRIVERS\wd.sys
09:32:53.0360 6496 Wd - ok
09:32:53.0410 6496 Wdf01000 (441bd2d7b4f98134c3a4f9fa570fd250) C:\windows\system32\drivers\Wdf01000.sys
09:32:53.0423 6496 Wdf01000 - ok
09:32:53.0537 6496 WfpLwf (611b23304bf067451a9fdee01fbdd725) C:\windows\system32\DRIVERS\wfplwf.sys
09:32:53.0568 6496 WfpLwf - ok
09:32:53.0617 6496 WIMMount (05ecaec3e4529a7153b3136ceb49f0ec) C:\windows\system32\drivers\wimmount.sys
09:32:53.0634 6496 WIMMount - ok
09:32:53.0719 6496 WinUSB (4d52c872018af7e18d078978dcc3f6f2) C:\windows\system32\DRIVERS\WinUSB.sys
09:32:53.0720 6496 WinUSB - ok
09:32:53.0757 6496 WmiAcpi (f6ff8944478594d0e414d3f048f0d778) C:\windows\system32\DRIVERS\wmiacpi.sys
09:32:53.0759 6496 WmiAcpi - ok
09:32:53.0888 6496 ws2ifsl (6bcc1d7d2fd2453957c5479a32364e52) C:\windows\system32\drivers\ws2ifsl.sys
09:32:53.0903 6496 ws2ifsl - ok
09:32:53.0960 6496 WudfPf (7cadc74271dd6461c452c271b30bd378) C:\windows\system32\drivers\WudfPf.sys
09:32:53.0968 6496 WudfPf - ok
09:32:53.0994 6496 WUDFRd (3b197af0fff08aa66b6b2241ca538d64) C:\windows\system32\DRIVERS\WUDFRd.sys
09:32:53.0998 6496 WUDFRd - ok
09:32:54.0098 6496 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk0\DR0
09:32:54.0115 6496 \Device\Harddisk0\DR0 - ok
09:32:54.0119 6496 Boot (0x1200) (2e7aed8728927fa707309bbf7b2526ef) \Device\Harddisk0\DR0\Partition0
09:32:54.0121 6496 \Device\Harddisk0\DR0\Partition0 - ok
09:32:54.0133 6496 Boot (0x1200) (4b0f1ffa35e08c17fc79fa88d5e4a885) \Device\Harddisk0\DR0\Partition1
09:32:54.0157 6496 \Device\Harddisk0\DR0\Partition1 - ok
09:32:54.0184 6496 Boot (0x1200) (9f1f0837d5430afbfb236d64476b0ef3) \Device\Harddisk0\DR0\Partition2
09:32:54.0185 6496 \Device\Harddisk0\DR0\Partition2 - ok
09:32:54.0204 6496 Boot (0x1200) (c4b1561d1aa9a1275d95b13cf059822b) \Device\Harddisk0\DR0\Partition3
09:32:54.0205 6496 \Device\Harddisk0\DR0\Partition3 - ok
09:32:54.0206 6496 ============================================================
09:32:54.0206 6496 Scan finished
09:32:54.0206 6496 ============================================================
09:32:54.0221 10208 Detected object count: 0
09:32:54.0222 10208 Actual detected object count: 0

Post the log from Combofix,it is located at C:\combofix.txt

Open OTL,click run scan and post the new log.



I need to see these logs please.

No need to use the quote ,just use ad/reply.
Ah, Im sorry. Here you are: ComboFix 11-11-11.04 - Max 11/11/2011 14:08:07.1.4 - x64 Microsoft Windows 7 Professional 6.1.7600.0.1252.2.1033.18.4030.1431 [GMT -5:00] Running from: c:\users\[removed]\Desktop\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {56547CC9-C9B2-849D-8FEF-A496150D6A06} FW: Kaspersky Internet Security *Disabled* {6E6FFDEC-83DD-85C5-A4B0-0DA3EBDE2D7D} SP: Kaspersky Internet Security *Disabled/Updated* {ED359D2D-EF88-8B13-B55F-9FE46E8A20BB} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . C:\install.exe C:\Thumbs.db c:\users\Max\AppData\Roaming\chrtmp c:\users\Max\Documents\~WRL3649.tmp c:\windows\system32\consrv.dll c:\windows\System64 . . ((((((((((((((((((((((((( Files Created from 2011-10-11 to 2011-11-11 ))))))))))))))))))))))))))))))) . . 2011-11-11 19:21 . 2011-11-11 19:21 ——– d—–w- c:\users\Default\AppData\Local\temp 2011-11-11 17:16 . 2011-11-11 18:33 69000 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87107C07-D20C-4F30-987B-B6FB830FB14C}\offreg.dll 2011-11-11 17:16 . 2011-10-07 04:16 8570192 —-a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{87107C07-D20C-4F30-987B-B6FB830FB14C}\mpengine.dll 2011-11-10 22:32 . 2011-11-10 22:32 ——– d—–w- C:\Sun 2011-11-10 02:54 . 2011-11-10 02:53 66856 —-a-w- c:\windows\SysWow64\SynTPEnhPS.dll 2011-11-10 02:54 . 2011-11-10 02:53 392752 —-a-w- c:\windows\system32\drivers\SynTP.sys 2011-11-10 02:54 . 2011-11-10 02:53 226600 —-a-w- c:\windows\system32\SynTPAPI.dll 2011-11-10 02:54 . 2011-11-10 02:53 148264 —-a-w- c:\windows\system32\SynTPCo9.dll 2011-11-10 02:54 . 2011-11-10 02:53 107816 —-a-w- c:\windows\SysWow64\SynTPCOM.dll 2011-11-10 02:54 . 2011-11-10 02:53 277288 —-a-w- c:\windows\system32\SynCtrl.dll 2011-11-10 02:54 . 2011-11-10 02:53 222504 —-a-w- c:\windows\SysWow64\SynCtrl.dll 2011-11-10 02:54 . 2011-11-10 02:53 1048576 —-a-w- c:\windows\system32\syndata.bin 2011-11-10 02:54 . 2011-11-10 02:53 177448 —-a-w- c:\windows\SysWow64\SynCOM.dll 2011-11-10 00:21 . 2011-03-22 05:22 48640 —-a-w- c:\windows\system32\wwanprotdim.dll 2011-11-10 00:21 . 2011-03-22 05:22 229888 —-a-w- c:\windows\system32\wwansvc.dll 2011-11-10 00:19 . 2011-02-25 06:36 295296 —-a-w- c:\windows\system32\drivers\volsnap.sys 2011-11-09 19:02 . 2011-11-09 19:02 ——– d—–w- c:\users\Max\AppData\Roaming\SUPERAntiSpyware.com 2011-11-09 19:02 . 2011-11-09 19:02 ——– d—–w- c:\programdata\SUPERAntiSpyware.com 2011-11-09 18:40 . 2010-10-06 02:26 109240 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak\components\abhelperxpcom.dll 2011-11-09 18:40 . 2010-10-06 02:27 150200 —-a-w- c:\program files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak\components\kavlinkfilter.dll 2011-11-09 18:38 . 2011-11-11 19:23 ——– d—–w- c:\programdata\Kaspersky Lab 2011-11-09 18:38 . 2011-11-09 18:38 ——– d—–w- c:\program files (x86)\Kaspersky Lab 2011-11-09 17:27 . 2011-11-09 17:27 ——– d—–w- c:\programdata\Kaspersky Lab Setup Files 2011-11-09 04:50 . 2011-11-09 04:50 ——– d—–w- c:\users\Max\AppData\Roaming\Malwarebytes 2011-11-09 04:50 . 2011-11-09 04:50 ——– d—–w- c:\programdata\Malwarebytes 2011-11-09 04:50 . 2011-08-31 22:00 25416 —-a-w- c:\windows\system32\drivers\mbam.sys 2011-11-09 04:08 . 2011-10-01 05:28 886784 —-a-w- c:\program files\Common Files\System\wab32.dll 2011-11-09 04:08 . 2011-10-01 04:43 708608 —-a-w- c:\program files (x86)\Common Files\System\wab32.dll 2011-11-09 04:08 . 2011-09-29 16:24 1897328 —-a-w- c:\windows\system32\drivers\tcpip.sys 2011-11-09 04:08 . 2011-09-29 04:09 3141120 —-a-w- c:\windows\system32\win32k.sys 2011-11-08 21:29 . 2011-11-09 01:10 ——– d—–w- c:\users\Max\AppData\Local\VMware 2011-11-08 21:29 . 2011-11-09 01:10 ——– d—–w- c:\users\Max\AppData\Roaming\VMware 2011-11-08 21:27 . 2011-08-22 22:07 62064 —-a-w- c:\windows\system32\drivers\vmx86.sys 2011-11-08 21:26 . 2011-08-22 22:07 354416 —-a-w- c:\windows\SysWow64\vmnetdhcp.exe 2011-11-08 21:26 . 2011-08-22 22:06 432752 —-a-w- c:\windows\SysWow64\vmnat.exe 2011-11-08 21:26 . 2011-08-22 22:06 30320 —-a-w- c:\windows\system32\drivers\vmnetuserif.sys 2011-11-08 21:26 . 2011-08-22 22:07 942192 —-a-w- c:\windows\system32\vnetlib64.dll 2011-11-08 21:26 . 2011-08-22 04:11 39024 —-a-w- c:\windows\system32\drivers\hcmon.sys 2011-11-08 21:24 . 2011-11-11 19:23 ——– d—–w- c:\programdata\VMware 2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files (x86)\VMware 2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files (x86)\Common Files\VMware 2011-11-08 21:24 . 2011-11-08 21:24 ——– d—–w- c:\program files\Common Files\VMware 2011-11-07 03:58 . 2011-11-07 03:58 ——– d—–w- c:\users\Max\AppData\Roaming\Symantec 2011-11-07 03:10 . 2011-11-07 03:10 ——– d—–w- c:\programdata\Wavefunction 2011-11-07 02:07 . 2011-11-07 02:07 ——– d—–w- c:\program files (x86)\Wavefunction 2011-11-05 15:17 . 2011-11-10 00:39 ——– d—–w- C:\Fraps 2011-11-04 18:15 . 2011-11-04 18:15 ——– d—–w- c:\program files (x86)\Rockstar Games 2011-11-02 00:43 . 2011-11-02 00:43 ——– d—–w- c:\users\Max\AppData\Roaming\fltk.org 2011-11-02 00:43 . 2011-11-02 00:43 ——– d—–w- c:\programdata\fltk.org 2011-11-01 17:11 . 2011-11-01 17:11 ——– d—–w- c:\programdata\Trymedia 2011-11-01 16:39 . 2011-11-01 16:39 ——– d—–w- c:\program files (x86)\Activision 2011-10-26 18:50 . 2011-08-15 05:08 6144 —-a-w- c:\program files\Internet Explorer\iecompat.dll 2011-10-26 18:50 . 2011-08-15 04:25 6144 —-a-w- c:\program files (x86)\Internet Explorer\iecompat.dll 2011-10-26 14:02 . 2011-10-27 14:49 ——– d—–w- c:\program files (x86)\SmartSound Software 2011-10-26 14:02 . 2011-10-27 14:49 ——– d—–w- c:\programdata\SmartSound Software Inc 2011-10-24 21:54 . 2011-10-24 21:54 ——– d—–w- c:\program files (x86)\LiveMath 2011-10-23 21:31 . 2011-10-25 04:33 ——– d—–w- C:\MC Server 1.8 2011-10-16 23:55 . 2011-10-16 23:55 18139008 —-a-w- c:\program files (x86)\Common Files\Microsoft Shared\OFFICE14\MSO.DLL 2011-10-13 21:35 . 2011-10-13 21:35 ——– d—–w- c:\users\Max\AppData\Roaming\MP3toiPodAudioBookConverter 2011-10-13 16:48 . 2011-10-13 16:48 ——– d—–w- c:\program files (x86)\MP3ToIpodAudioBookConverter . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2011-11-10 02:53 . 2011-02-04 03:56 415528 —-a-w- c:\windows\system32\SynCOM.dll 2011-10-17 15:21 . 2011-05-18 22:01 414368 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2011-10-05 16:49 . 2011-03-03 20:03 13888 —-a-w- c:\windows\system32\RTNICVer.dll 2011-10-05 16:39 . 2011-08-31 20:09 81920 —-a-w- c:\windows\system32\nusb3co2.dll 2011-10-05 16:04 . 2011-04-09 00:48 224256 —-a-w- c:\windows\system32\staco64.dll 2011-10-01 03:21 . 2011-10-12 10:16 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2011-10-01 02:59 . 2011-10-12 10:16 1638912 —-a-w- c:\windows\SysWow64\mshtml.tlb 2011-09-05 13:57 . 2011-09-05 13:57 366136 —-a-w- c:\windows\SysWow64\flcdlmsg.dll 2011-09-05 13:57 . 2011-09-05 13:57 476728 —-a-w- c:\windows\SysWow64\flcdlock.exe 2011-09-05 05:35 . 2011-09-05 05:35 270912 —-a-w- c:\windows\system32\drivers\dtsoftbus01.sys 2011-09-04 13:07 . 2011-09-04 13:07 2874880 —-a-w- c:\windows\system32\python32.dll 2011-08-31 20:09 . 2011-08-31 20:09 91648 —-a-w- c:\windows\system32\drivers\nusb3hub.sys 2011-08-31 20:09 . 2011-08-31 20:09 208896 —-a-w- c:\windows\system32\drivers\nusb3xhc.sys 2011-08-27 05:40 . 2011-10-12 10:15 861184 —-a-w- c:\windows\system32\oleaut32.dll 2011-08-27 05:40 . 2011-10-12 10:15 331776 —-a-w- c:\windows\system32\oleacc.dll 2011-08-27 04:43 . 2011-10-12 10:15 571904 —-a-w- c:\windows\SysWow64\oleaut32.dll 2011-08-27 04:43 . 2011-10-12 10:15 233472 —-a-w- c:\windows\SysWow64\oleacc.dll 2011-08-24 19:30 . 2011-08-24 19:30 868688 —-a-r- c:\windows\system32\DPLic.dll 2011-08-24 19:30 . 2011-08-24 19:30 621392 —-a-r- c:\windows\SysWow64\DPLic.dll 2011-08-24 18:55 . 2011-08-24 18:55 859472 —-a-r- c:\windows\SysWow64\DPCrProv.dll 2011-08-24 18:55 . 2011-08-24 18:55 330064 —-a-r- c:\windows\system32\DPPassFilter.dll 2011-08-24 18:55 . 2011-08-24 18:55 259408 —-a-r- c:\windows\SysWow64\DPPassFilter.dll 2011-08-24 18:55 . 2011-08-24 18:55 1038672 —-a-r- c:\windows\system32\DPCrProv.dll 2011-08-24 18:55 . 2011-08-24 18:55 765776 —-a-r- c:\windows\system32\DPFPApiUI.dll 2011-08-24 18:55 . 2011-08-24 18:55 664400 —-a-r- c:\windows\SysWow64\DPFPApiUI.dll 2011-08-24 18:53 . 2011-08-24 18:53 652624 —-a-r- c:\windows\system32\DPFPApi.dll 2011-08-24 18:53 . 2011-08-24 18:53 328528 —-a-r- c:\windows\system32\DPSCEL.dll 2011-08-24 18:53 . 2011-08-24 18:53 499536 —-a-r- c:\windows\SysWow64\DPFPApi.dll 2011-08-24 18:53 . 2011-08-24 18:53 378192 —-a-r- c:\windows\system32\DPClback.dll 2011-08-24 18:53 . 2011-08-24 18:53 267088 —-a-r- c:\windows\SysWow64\DPSCEL.dll 2011-08-24 18:53 . 2011-08-24 18:53 311632 —-a-r- c:\windows\SysWow64\DPClback.dll 2011-08-23 15:10 . 2011-08-23 15:10 4406064 —-a-w- c:\windows\system32\vcsAPIShared.dll 2011-08-23 15:10 . 2011-08-23 15:10 3806512 —-a-w- c:\windows\SysWow64\vcsAPIShared.dll 2011-08-23 09:37 . 2011-08-23 09:37 3175728 —-a-w- c:\windows\system32\vcsFPService.exe 2011-08-23 09:24 . 2011-08-23 09:24 8704 —-a-w- c:\windows\system32\vcsEventMsg.dll 2011-08-23 09:23 . 2011-08-23 09:23 2774320 —-a-w- c:\windows\SysWow64\vcsFPService.exe 2011-08-23 09:12 . 2011-08-23 09:12 8704 —-a-w- c:\windows\SysWow64\vcsEventMsg.dll 2011-08-22 20:40 . 2011-08-22 20:40 252016 —-a-w- c:\windows\SysWow64\vmnc.dll 2011-08-22 20:12 . 2011-08-22 20:12 62064 —-a-w- c:\windows\system32\vmnetbridge.dll 2011-08-22 20:12 . 2011-08-22 20:12 48752 —-a-w- c:\windows\system32\vnetinst.dll 2011-08-22 20:12 . 2011-08-22 20:12 45680 —-a-w- c:\windows\system32\drivers\vmnetbridge.sys 2011-08-22 20:12 . 2011-08-22 20:12 24176 —-a-w- c:\windows\system32\drivers\vmnet.sys 2011-08-22 20:12 . 2011-08-22 20:12 20080 —-a-w- c:\windows\system32\drivers\vmnetadapter.sys 2011-08-22 19:59 . 2011-08-22 19:59 100808 —-a-w- c:\windows\system32\drivers\MfeEpeOpal.sys 2011-08-22 19:59 . 2011-08-22 19:59 13256 —-a-w- c:\windows\system32\drivers\MfeEpeHb.sys 2011-08-22 19:59 . 2011-08-22 19:59 158920 —-a-w- c:\windows\system32\drivers\MfeEpePc.sys 2011-08-22 04:01 . 2011-08-22 04:01 37680 —-a-w- c:\windows\system32\drivers\vmusb.sys 2011-08-20 05:45 . 2011-10-12 10:16 1197568 —-a-w- c:\windows\system32\wininet.dll 2011-08-20 05:41 . 2011-10-12 10:16 57856 —-a-w- c:\windows\system32\licmgr10.dll 2011-08-20 04:38 . 2011-10-12 10:16 981504 —-a-w- c:\windows\SysWow64\wininet.dll 2011-08-20 04:35 . 2011-10-12 10:16 44544 —-a-w- c:\windows\SysWow64\licmgr10.dll 2011-08-20 04:20 . 2011-10-12 10:16 482816 —-a-w- c:\windows\system32\html.iec 2011-08-20 03:26 . 2011-10-12 10:16 386048 —-a-w- c:\windows\SysWow64\html.iec 2011-08-17 05:32 . 2011-10-12 10:15 613888 —-a-w- c:\windows\system32\psisdecd.dll 2011-08-17 05:27 . 2011-10-12 10:15 75776 —-a-w- c:\windows\system32\MSDvbNP.ax 2011-08-17 05:27 . 2011-10-12 10:15 288256 —-a-w- c:\windows\system32\MSNP.ax 2011-08-17 05:27 . 2011-10-12 10:15 108032 —-a-w- c:\windows\system32\psisrndr.ax 2011-08-17 05:27 . 2011-10-12 10:15 104960 —-a-w- c:\windows\system32\Mpeg2Data.ax 2011-08-17 04:26 . 2011-10-12 10:15 465408 —-a-w- c:\windows\SysWow64\psisdecd.dll 2011-08-17 04:22 . 2011-10-12 10:15 75776 —-a-w- c:\windows\SysWow64\psisrndr.ax 2011-08-17 04:22 . 2011-10-12 10:15 72704 —-a-w- c:\windows\SysWow64\Mpeg2Data.ax 2011-08-17 04:22 . 2011-10-12 10:15 59904 —-a-w- c:\windows\SysWow64\MSDvbNP.ax 2011-08-17 04:22 . 2011-10-12 10:15 204288 —-a-w- c:\windows\SysWow64\MSNP.ax . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 94208 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite"="c:\program files (x86)\DAEMON Tools Lite\DTLite.exe" [2011-08-02 4910912] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2011-10-17 283160] "NUSB3MON"="c:\program files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2011-10-05 113288] "BCSSync"="c:\program files (x86)\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520] "AdobeCS5.5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" [2011-01-12 1523360] "HPConnectionManager"="c:\program files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe" [2011-05-23 103992] "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-08-19 421736] "HPQuickWebProxy"="c:\program files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe" [2011-08-31 169528] "QLBController"="c:\program files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe" [2011-07-06 323128] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208] "AVP"="c:\program files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe" [2011-11-09 365336] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files (x86)\Windows Live\Messenger\msnmsgr.exe" [2010-04-17 3872080] . c:\users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dropbox.lnk - c:\users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560] OneNote 2010 Screen Clipper and Launcher.lnk - c:\program files (x86)\Microsoft Office\Office14\ONENOTEM.EXE [2011-9-2 227712] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP] 2011-02-03 23:09 75360 —-a-w- c:\windows\System32\DeviceNP.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\sbhook.dll . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R1 SASDIFSV;SASDIFSV;c:\users\Max\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV64.SYS [x] R1 SASKUTIL;SASKUTIL;c:\users\Max\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL64.SYS [x] R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576] R2 HP Power Assistant Service;HP Power Assistant Service;c:\program files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe [2011-01-27 131128] R2 HP Support Assistant Service;HP Support Assistant Service;c:\program files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2011-06-21 85560] R2 VMwareHostd;VMware Workstation Server;c:\program files (x86)\VMware\VMware Workstation\vmware-hostd.exe [2011-08-22 11837440] R3 AthBTPort;Atheros Virtual Bluetooth Class;c:\windows\system32\DRIVERS\btath_flt.sys [x] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;c:\windows\system32\drivers\btath_a2dp.sys [x] R3 BTATH_HCRP;Bluetooth HCRP Server driver;c:\windows\system32\DRIVERS\btath_hcrp.sys [x] R3 BTATH_LWFLT;Bluetooth LWFLT Device;c:\windows\system32\DRIVERS\btath_lwflt.sys [x] R3 BTATH_RCP;Bluetooth AVRCP Device;c:\windows\system32\DRIVERS\btath_rcp.sys [x] R3 BtFilter;BtFilter;c:\windows\system32\DRIVERS\btfilter.sys [x] R3 cpuz135;cpuz135;c:\windows\TEMP\cpuz135\cpuz135_x64.sys [x] R3 DAMDrv;DAMDrv;c:\windows\system32\DRIVERS\DAMDrv64.sys [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys [x] R3 FLCDLOCK;HP ProtectTools Device Locking / Auditing;c:\windows\SysWOW64\flcdlock.exe [2011-09-05 476728] R3 Futuremark SystemInfo Service;Futuremark SystemInfo Service;c:\program files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2011-08-15 130976] R3 hpCMSrv;HP Connection Manager 4 Service;c:\program files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe [2011-05-23 1098296] R3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys [x] R3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files (x86)\Microsoft Office\Office14\GROOVE.EXE [2011-06-12 31125880] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184] R3 RTL8192su;TRENDnet 300Mbps Wireless N USB Adapter;c:\windows\system32\DRIVERS\RTL8192su.sys [x] R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x] S0 MfeEpeOpal;MfeEpeOpal; [x] S0 MfeEpePc;MfeEpePc; [x] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [x] S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [x] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [x] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x] S2 AdobeActiveFileMonitor10.0;Adobe Active File Monitor V10;c:\program files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [2011-09-01 169624] S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 64952] S2 AESTFilters;Andrea ST Filters Service;c:\program files\IDT\WDM\AESTSr64.exe [2011-07-20 89600] S2 Atheros Bt&Wlan Coex Agent;Atheros Bt&Wlan Coex Agent;c:\program files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [2011-01-07 138400] S2 AtherosSvc;AtherosSvc;c:\program files (x86)\Bluetooth Suite\adminservice.exe [2011-01-07 53920] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-08-15 2329480] S2 HPDayStarterService;HP DayStarter Service;c:\program files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe [2011-01-28 133688] S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2011-09-01 227896] S2 HPFSService;File Sanitizer for HP ProtectTools;c:\program files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe [2011-02-07 320000] S2 hpHotkeyMonitor;hpHotkeyMonitor;c:\program files (x86)\Hewlett-Packard\HP Hotkey Support\HpHotkeyMonitor.exe [2011-07-06 1698360] S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x] S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;c:\program files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-10-17 13336] S2 jhi_service;Intel® Identity Protection Technology Host Interface Service;c:\program files (x86)\Intel\Services\IPT\jhi_service.exe [2011-02-24 212944] S2 McAfee Endpoint Encryption Agent;McAfee Endpoint Encryption Agent;c:\program files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe [2011-08-22 1318912] S2 PdiService;Portrait Displays SDK Service;c:\program files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe [2011-01-18 113264] S2 uArcCapture;ArcCapture;c:\windows\SysWow64\ArcVCapRender\uArcCapture.exe [2010-11-11 502464] S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2011-01-03 2656280] S2 vcsFPService;Validity VCS Fingerprint Service;c:\windows\system32\vcsFPService.exe [2011-08-23 3175728] S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [2011-08-22 846448] S2 vstor2-mntapi10-shared;Vstor2 MntApi 1.0 Driver (shared);SysWOW64\drivers\vstor2-mntapi10-shared.sys [x] S3 ARCVCAM;ARCVCAM, ArcSoft Webcam Sharing Manager Driver;c:\windows\system32\DRIVERS\ArcSoftVCapture.sys [x] S3 BTATH_BUS;Atheros Bluetooth Bus;c:\windows\system32\DRIVERS\btath_bus.sys [x] S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [x] S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [x] . . Contents of the 'Scheduled Tasks' folder . 2011-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job - c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-24 05:21] . 2011-11-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job - c:\users\Max\AppData\Local\Google\Update\GoogleUpdate.exe [2011-08-24 05:21] . 2011-11-10 c:\windows\Tasks\HPCeeScheduleForMax.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15] . 2011-10-31 c:\windows\Tasks\HPCeeScheduleForMAXHP$.job - c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2010-09-14 06:15] . . ——— x86-64 ———– . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2011-02-18 05:12 97792 —-a-w- c:\users\Max\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "HPPowerAssistant"="c:\program files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe" [2011-01-27 13880] "MfeEpePcMonitor"="c:\program files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe" [2011-08-22 200704] "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2011-06-16 499608] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-05-18 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-05-18 391704] "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2011-07-20 1128448] "combofix"="c:\combofix\CF15463.3XE" [2009-07-14 344576] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x1 "AppInit_DLLs"=c:\progra~2\KASPER~1\KASPER~1\x64\kloehk.dll c:\progra~2\KASPER~1\KASPER~1\x64\sbhook64.dll . ——- Supplementary Scan ——- . uStart Page = my.daemon-search.com uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local; uInternet Settings,ProxyServer = 127.0.0.1:8118 IE: Append Link Target to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Append to Existing PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert Link Target to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert to Adobe PDF - c:\program files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 LSP: %SystemRoot%\system32\vsocklib.dll DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} - hxxp://clients.futuremark.com/calico/systeminfodeploy/FMSI_v420.cab FF - ProfilePath - c:\users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\ FF - prefs.js: browser.startup.homepage - about:home . - - - - ORPHANS REMOVED - - - - . Wow6432Node-HKLM-Run-TaskTray - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226} - c:\program files (x86)\InstallShield Installation Information\{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}\setup.exe . . . ——————— LOCKED REGISTRY KEYS ——————— . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version] "Version"=hex:6a,26,62,4b,84,a5,e3,95,14,c4,f4,ad,c5,7a,33,84,c9,84,a6,ae,6c, e5,a5,58,03,a2,cc,11,c8,5b,f8,6e,1d,b5,8c,c3,70,40,bc,5e,dd,d8,f2,a6,e0,25,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10o_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash10o.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version] "Version"=hex:6a,26,62,4b,84,a5,e3,95,14,c4,f4,ad,c5,7a,33,84,c9,84,a6,ae,6c, e5,a5,58,03,a2,cc,11,c8,5b,f8,6e,1d,b5,8c,c3,70,40,bc,5e,dd,d8,f2,a6,e0,25,\ . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*€ *] @="\010\01" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*â] @="\06?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\* R] @="\06?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\*] @="?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\* ] @="?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\* ] @="?" . [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Hewlett-Packard\HP Software Framework\{F7A31DE6-534B-4564-808A-7D170A9F74A1}\DeviceDbcc\;¾Q&**€*] @="??&?\02" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ———————— Other Running Processes ———————— . c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe c:\program files (x86)\Bonjour\mDNSResponder.exe c:\program files (x86)\Common Files\Protexis\License Service\PsiService_2.exe c:\windows\SysWOW64\vmnat.exe c:\program files (x86)\VMware\VMware Workstation\vmware-authd.exe c:\program files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe c:\windows\SysWOW64\vmnetdhcp.exe c:\program files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe c:\program files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe . ************************************************************************** . Completion time: 2011-11-11 14:31:21 - machine was rebooted ComboFix-quarantined-files.txt 2011-11-11 19:31 . Pre-Run: 67,415,638,016 bytes free Post-Run: 75,290,472,448 bytes free . - - End Of File - - 0AB6ED9619E579671EEF70318618ACBD
Open OTL.

  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT



  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • Post the new log
It took a bit of time when looking for Manual Folders. Dont know if that's important.


New Log:


OTL logfile created on: 11/17/2011 9:20:00 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Downloads
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.94 Gb Total Physical Memory | 1.35 Gb Available Physical Memory | 34.24% Memory free
7.87 Gb Paging File | 4.67 Gb Available in Paging File | 59.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 52.12 Gb Free Space | 11.74% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32

Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Max\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\Adobe Audition.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
PRC - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (Portrait Displays, Inc)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\pdf.dll ()
MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\avutil-51.dll ()
MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\avformat-53.dll ()
MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\avcodec-53.dll ()
MOD - C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\gcswf32.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c5f091ea0acf3fe98c012c1c7251b286\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5bb0e725e6c2be05d136893ea8df3837\IAStorCommon.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\99bcc03fab1f46d8f7507d518683bb47\System.Data.DataSetExtensions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\2fe1102950b6bb637339b982724ad63d\System.IdentityModel.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\8dba8803fad87c39c0afbdce6c19fdd0\System.Runtime.Serialization.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\cc3d9cb5c17d1863e3146c2a0d5c9e86\System.ServiceModel.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\9123843fd33a30164ceb951c98b7ca2a\SMDiagnostics.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\6d859463c9e6a7423ddb335211a79dda\System.Core.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\5672e6b9d976feca51deb06d8dd1df0e\PresentationFramework.Aero.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5a95ba97100404e2ab26b5a9ab9ef965\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\45a20172acfdcc160ecb6bd358179c31\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\09e39322b47f9b4e8dd2199ff03acb2e\PresentationFramework.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\d2dc021a8311197516e4fa325b292f21\PresentationCore.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\fccf285ecdd9091a3f8d5e73d79c3300\UIAutomationProvider.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Accessibility\d71769228ebe7732ae31ac194fe00ff0\Accessibility.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework.Logging\1.0.0.0__a5a013d267b3a679\HP.SupportFramework.Logging.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportAssistant.ServiceManager\6.0.1.1__afd7346f05a57c11\HP.SupportAssistant.ServiceManager.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework.Communicator\1.0.0.0__370cd15173f7ac8f\HP.SupportFramework.Communicator.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportAssistant.Localization\6.0.1.1__a2352a4c73e11587\HP.SupportAssistant.Localization.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportAssistant.Engine\6.0.1.1__e1eab6ede003577a\HP.SupportAssistant.Engine.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportAssistant.Common\6.0.1.1__41bdec5abf54f6dc\HP.SupportAssistant.Common.dll ()
MOD - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
MOD - C:\Program Files (x86)\Yuna Software\Messenger Plus!\Detour32.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuUIToolkit.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuUI.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuScripting.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuDSP.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuCoreAudioVista.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuCore.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuBackEnd.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuAudioComponentsUI.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuAudioComponents.dll ()
MOD - C:\Program Files (x86)\Adobe\Adobe Audition CS5.5\AuApplication.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (DpHost) – C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (McAfee Endpoint Encryption Agent) – C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (HPDayStarterService) – c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLCDLOCK) – c:\Windows\SysWOW64\flcdlock.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (AdobeActiveFileMonitor10.0) – C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMwareHostd) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (hpHotkeyMonitor) – C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (hpCMSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (jhi_service) Intel® – C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
SRV - (HPFSService) – C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (Atheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (uArcCapture) – C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (MfeEpeOpal) – C:\windows\SysNative\drivers\MfeEpeOpal.sys (McAfee, Inc.)
DRV:64bit: - (MfeEpePc) – C:\windows\SysNative\drivers\MfeEpePc.sys (McAfee, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmusb) – C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (DAMDrv) – C:\Windows\SysNative\drivers\DAMDrv64.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (ARCVCAM) – C:\Windows\SysNative\drivers\ArcSoftVCapture.sys (ArcSoft, Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8118

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:home"

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/05/08 18:26:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/05/08 18:26:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/09/21 10:34:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ [2011/09/30 23:26:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/30 15:10:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011/08/10 21:17:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]

[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/11/05 13:58:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions
[2011/09/12 12:41:25 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions\[removed]
[2011/08/23 17:48:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\pfy0baj9.default\extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Sunbird\Profiles\lux6pdqw.default\extensions
[2011/11/09 13:49:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/03 18:15:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/08/04 16:53:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/09 13:40:16 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
[2011/10/06 09:15:54 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2
[2011/11/09 13:40:11 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
[2011/10/06 09:15:51 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{20CC25E2-48C9-45E1-9A1F-1CCC1882B81B}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\[removed]
[2011/09/30 15:10:53 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2008/08/23 16:00:54 | 005,150,696 | —- | M] (MathMonkeys, LLC) – C:\Program Files (x86)\mozilla firefox\plugins\NPLM32.DLL
[2010/01/01 03:00:00 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 03:00:00 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 03:00:00 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Max\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Monster Dash = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknghehebaconkajgiobncfleofebcog\2.2_0\
CHR - Extension: DivX HiQ = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: WeatherByte = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlgbglmmkibkhhbnhegkokegdodlgfe\1.0.3_0\
CHR - Extension: AdBlock = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.28_0\
CHR - Extension: The Fancy Pants Adventure: World 2 = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk\14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\
CHR - Extension: Climb or Drown! = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoiaaaplodaeokegmjphakphcbmiip\1.1.0_0\
CHR - Extension: MegaSkipper = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.62_0\
CHR - Extension: Canvas Rider = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.7_0\

O1 HOSTS File: ([2011/11/11 18:20:29 | 000,001,374 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 21 more lines…
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (File Sanitizer for HP ProtectTools) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MfeEpePcMonitor] C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futuremark.com/calico/syste…y/FMSI_v420.cab (FuturemarkSystemInfoX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2912C486-28C5-4AF2-B814-E069DD38267A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\kloehk.dll (Kaspersky Lab ZAO)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\sbhook64.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) -C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\sbhook.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\DeviceNP: DllName - (DeviceNP.dll) - C:\windows\SysWow64\DeviceNP.dll (Hewlett-Packard Company)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011/11/15 09:31:41 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Max\Desktop\TDSSKiller.exe
[2011/11/12 16:05:13 | 000,000,000 | —D | C] – C:\windows\SysNative\Macromed
[2011/11/11 14:44:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/11 14:23:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/11 14:06:08 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/11/10 17:32:39 | 000,000,000 | —D | C] – C:\Sun
[2011/11/09 21:54:22 | 000,066,856 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:54:21 | 000,392,752 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:54:21 | 000,226,600 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:54:21 | 000,148,264 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:54:21 | 000,107,816 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:54:15 | 000,277,288 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:54:15 | 000,222,504 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:54:15 | 000,177,448 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:21:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wwanprotdim.dll
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 13:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2011/11/09 13:37:32 | 000,556,120 | —- | C] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 12:27:49 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2011/11/08 23:50:10 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Malwarebytes
[2011/11/08 23:50:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/08 23:50:02 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/11/08 16:29:24 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Local\VMware
[2011/11/08 16:29:23 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\VMware
[2011/11/08 16:27:01 | 000,062,064 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmx86.sys
[2011/11/08 16:26:28 | 000,354,416 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnetdhcp.exe
[2011/11/08 16:26:25 | 000,432,752 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnat.exe
[2011/11/08 16:26:24 | 000,030,320 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmnetuserif.sys
[2011/11/08 16:26:21 | 000,942,192 | —- | C] (VMware, Inc.) – C:\windows\SysNative\vnetlib64.dll
[2011/11/08 16:26:07 | 000,039,024 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\hcmon.sys
[2011/11/08 16:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\ProgramData\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Shared Virtual Machines
[2011/11/08 16:24:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2011/11/08 15:50:27 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Rainbows!
[2011/11/06 22:58:07 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Symantec
[2011/11/06 22:10:03 | 000,000,000 | —D | C] – C:\ProgramData\Wavefunction
[2011/11/06 21:08:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spartan '08 V1.2.0
[2011/11/06 21:07:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wavefunction
[2011/11/05 10:17:53 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011/11/05 10:17:52 | 000,000,000 | —D | C] – C:\Fraps
[2011/11/04 13:37:51 | 000,000,000 | —D | C] – C:\Users\Max\Documents\GTA San Andreas User Files
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rockstar Games
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\ProgramData\fltk.org
[2011/11/01 19:43:24 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Amnesia
[2011/11/01 12:11:18 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/10/26 11:38:07 | 000,000,000 | —D | C] – C:\Users\Max\Documents\NewBlueFX
[2011/10/26 09:02:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartSound Software
[2011/10/26 09:02:18 | 000,000,000 | —D | C] – C:\ProgramData\SmartSound Software Inc
[2011/10/24 16:54:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveMath
[2011/10/24 16:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\LiveMath
[2011/10/23 16:31:23 | 000,000,000 | —D | C] – C:\MC Server 1.8
[2011/02/24 00:10:36 | 000,020,432 | —- | C] (Intel Corporation) – C:\Users\Max\AppData\Roaming\JomCap.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/17 09:13:48 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job
[2011/11/17 09:13:28 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/11/16 21:40:29 | 000,000,324 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/16 20:58:44 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/16 20:58:44 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/16 20:50:16 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2011/11/16 11:48:17 | 000,000,848 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job
[2011/11/16 11:07:36 | 1185,633,788 | —- | M] () – C:\Users\Max\Documents\biology november 16.wav
[2011/11/16 11:07:36 | 000,578,972 | —- | M] () – C:\Users\Max\Documents\biology november 16.pkf
[2011/11/15 13:04:17 | 1939,387,900 | —- | M] () – C:\Users\Max\Documents\TBB November 15.wav
[2011/11/15 13:04:17 | 000,947,004 | —- | M] () – C:\Users\Max\Documents\TBB November 15.pkf
[2011/11/15 10:39:08 | 214,627,836 | —- | M] () – C:\Users\Max\Documents\Chemistry November 15.wav
[2011/11/15 10:39:08 | 000,419,228 | —- | M] () – C:\Users\Max\Documents\Chemistry November 15.pkf
[2011/11/15 09:33:38 | 000,001,296 | —- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/11/14 11:18:20 | 897,062,396 | —- | M] () – C:\Users\Max\Documents\Chemistry November 14.wav
[2011/11/14 11:18:20 | 000,438,044 | —- | M] () – C:\Users\Max\Documents\Chemistry November 14.pkf
[2011/11/14 11:16:26 | 1181,652,476 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 16.wav
[2011/11/14 11:16:26 | 000,577,020 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 16.pkf
[2011/11/12 16:05:18 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/12 16:01:32 | 005,000,616 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/11/11 18:20:29 | 000,001,374 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Max\Desktop\TDSSKiller.exe
[2011/11/11 13:54:12 | 000,007,598 | —- | M] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/11 12:46:09 | 000,002,353 | —- | M] () – C:\Users\Max\Desktop\Google Chrome.lnk
[2011/11/11 00:22:14 | 000,794,000 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/11/11 00:22:14 | 000,672,826 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/11/11 00:22:14 | 000,128,986 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/11/10 23:30:45 | 000,000,021 | —- | M] () – C:\windows\SurCode.INI
[2011/11/10 20:09:59 | 000,783,562 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/11/10 10:20:33 | 919,371,004 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/10 10:20:33 | 000,448,956 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/09 21:53:39 | 000,066,856 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:53:37 | 000,392,752 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:53:37 | 000,226,600 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:53:37 | 000,148,264 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:53:37 | 000,107,816 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:53:36 | 001,048,576 | —- | M] () – C:\windows\SysNative\syndata.bin
[2011/11/09 21:53:36 | 000,277,288 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:53:36 | 000,222,504 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:53:32 | 000,415,528 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCOM.dll
[2011/11/09 21:53:32 | 000,177,448 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:49:02 | 000,152,233 | —- | M] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:49:02 | 000,107,177 | —- | M] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:37:32 | 000,556,120 | —- | M] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 13:25:58 | 000,089,448 | —- | M] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 1124,496,892 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/09 12:32:53 | 000,549,116 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/08 23:56:16 | 000,000,000 | —- | M] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | M] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | M] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | M] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 1196,602,876 | —- | M] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/04 13:14:29 | 005,550,172 | —- | M] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/03 15:59:45 | 000,299,178 | —- | M] () – C:\Users\Max\Documents\marks.pdf
[2011/11/03 09:37:55 | 854,881,788 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/02 10:18:26 | 1086,019,068 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/02 10:18:26 | 000,530,332 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/01 12:17:00 | 1066,628,818 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:03:17 | 2150,422,524 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 09:00:50 | 004,856,572 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 09:00:49 | 1033,901,564 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 962,287,314 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:58:42 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:45 | 000,485,180 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:39 | 993,572,348 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/30 22:47:06 | 000,000,336 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMAXHP$.job
[2011/10/27 11:17:34 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 1311,806,972 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 10:23:09 | 1082,578,642 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 08:57:51 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:22 | 002,429,826 | —- | M] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:47:52 | 000,332,874 | —- | M] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 975,943,164 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:40:16 | 000,476,572 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:38:48 | 1848,899,068 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/24 10:20:53 | 767,129,084 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:06 | 1077,736,956 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/22 12:17:02 | 1288,992,252 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/21 21:37:21 | 3818,616,316 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/20 09:59:45 | 1031,960,060 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/19 10:16:47 | 1101,297,148 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/18 14:20:51 | 1573,713,404 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.pkf
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/16 21:40:29 | 000,000,324 | —- | C] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/16 11:07:36 | 000,578,972 | —- | C] () – C:\Users\Max\Documents\biology november 16.pkf
[2011/11/16 11:06:43 | 1185,633,788 | —- | C] () – C:\Users\Max\Documents\biology november 16.wav
[2011/11/15 13:04:17 | 000,947,004 | —- | C] () – C:\Users\Max\Documents\TBB November 15.pkf
[2011/11/15 13:01:32 | 1939,387,900 | —- | C] () – C:\Users\Max\Documents\TBB November 15.wav
[2011/11/15 10:39:08 | 000,419,228 | —- | C] () – C:\Users\Max\Documents\Chemistry November 15.pkf
[2011/11/15 10:39:03 | 214,627,836 | —- | C] () – C:\Users\Max\Documents\Chemistry November 15.wav
[2011/11/14 11:18:20 | 000,438,044 | —- | C] () – C:\Users\Max\Documents\Chemistry November 14.pkf
[2011/11/14 11:17:04 | 897,062,396 | —- | C] () – C:\Users\Max\Documents\Chemistry November 14.wav
[2011/11/14 11:16:26 | 000,577,020 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 16.pkf
[2011/11/14 11:15:14 | 1181,652,476 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 16.wav
[2011/11/11 13:54:12 | 000,007,598 | —- | C] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/10 10:20:33 | 000,448,956 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/10 10:18:59 | 919,371,004 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/09 21:54:15 | 001,048,576 | —- | C] () – C:\windows\SysNative\syndata.bin
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:40:01 | 000,152,233 | —- | C] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:40:01 | 000,107,177 | —- | C] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:25:55 | 000,089,448 | —- | C] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 000,549,116 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/09 12:27:46 | 1124,496,892 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/08 23:56:16 | 000,000,000 | —- | C] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | C] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | C] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | C] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | C] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 005,550,172 | —- | C] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/04 13:12:21 | 1196,602,876 | —- | C] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/03 09:37:10 | 854,881,788 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:27:50 | 000,299,178 | —- | C] () – C:\Users\Max\Documents\marks.pdf
[2011/11/02 10:18:26 | 000,530,332 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/02 10:17:01 | 1086,019,068 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:15:49 | 1066,628,818 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 12:02:26 | 2150,422,524 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 09:00:49 | 004,856,572 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 08:59:39 | 1033,901,564 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:59:58 | 962,287,314 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 09:58:04 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:39 | 000,485,180 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:18 | 993,572,348 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/27 11:16:21 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 21:14:04 | 1311,806,972 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 10:22:39 | 1082,578,642 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 09:01:17 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/26 08:57:51 | 000,002,237 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 10.lnk
[2011/10/26 08:57:51 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:20 | 002,429,826 | —- | C] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:46:23 | 000,332,874 | —- | C] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 000,476,572 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:39:52 | 975,943,164 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/25 13:37:33 | 1848,899,068 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:20 | 767,129,084 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/24 10:18:26 | 1077,736,956 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/22 12:16:07 | 1288,992,252 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/21 21:34:21 | 3818,616,316 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/20 09:58:05 | 1031,960,060 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/19 10:15:28 | 1101,297,148 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.pkf
[2011/10/18 14:18:42 | 1573,713,404 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/15 20:30:47 | 000,000,132 | —- | C] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/06 09:16:51 | 000,017,408 | —- | C] () – C:\Users\Max\AppData\Local\WebpageIcons.db
[2011/09/05 08:57:34 | 000,366,136 | —- | C] () – C:\windows\SysWow64\flcdlmsg.dll
[2011/08/24 14:30:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPLic.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPPassFilter.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPCrProv.dll.hpsign
[2011/08/24 13:55:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApiUI.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPSCEL.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApi.dll.hpsign
[2011/08/24 13:53:42 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPClback.dll.hpsign
[2011/08/23 10:10:44 | 000,000,256 | —- | C] () – C:\windows\SysWow64\vcsAPIShared.dll.hpsign
[2011/07/02 21:54:28 | 000,186,460 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/06/15 20:03:03 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/14 17:25:49 | 000,000,021 | —- | C] () – C:\windows\SurCode.INI
[2011/05/30 21:58:34 | 000,185,168 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll
[2011/05/30 21:58:34 | 000,000,256 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll.hpsign
[2011/05/29 14:23:14 | 000,000,355 | —- | C] () – C:\windows\EReg176.dat
[2011/05/20 07:37:54 | 000,000,105 | —- | C] () – C:\windows\Antidote7.ini
[2011/05/18 16:53:37 | 000,963,116 | —- | C] () – C:\windows\SysWow64\igkrng600.bin
[2011/05/18 16:53:36 | 000,216,876 | —- | C] () – C:\windows\SysWow64\igfcg600m.bin
[2011/05/03 21:17:55 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\windows\SysWow64\xlive.dll.cat
[2011/04/08 20:00:20 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgchid.sys
[2011/04/08 19:38:38 | 000,025,984 | —- | C] () – C:\windows\snuvcdsm.exe
[2011/04/08 19:38:38 | 000,015,497 | —- | C] () – C:\windows\snp2uvc.ini
[2011/03/03 14:56:41 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbbb.sys
[2011/03/03 14:38:47 | 000,000,178 | —- | C] () – C:\windows\SysWow64\HPPA.ini
[2011/03/03 14:33:15 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbdf.sys
[2011/03/03 14:04:33 | 000,794,000 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/01/29 18:49:32 | 000,017,232 | —- | C] () – C:\windows\SysWow64\CoHpCasl.exe
[2011/01/26 21:55:20 | 000,145,804 | —- | C] () – C:\windows\SysWow64\igcompkrng600.bin
[2011/01/10 22:03:08 | 086,271,980 | —- | C] () – C:\windows\SysWow64\BioTrustFace.dat
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: EXPLORER.EXE >
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\explorer.exe
[2011/02/26 01:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/10/28 22:06:46 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\SysWOW64\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/10/28 22:03:01 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/10/28 22:06:46 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/10/28 22:03:01 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/10/28 22:06:46 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/10/28 22:03:01 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/10/28 22:06:46 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/10/28 22:03:01 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\ERDNT\cache86\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\ERDNT\cache64\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 07:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\ERDNT\cache86\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\SysWOW64\userinit.exe
[2009/07/13 20:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\ERDNT\cache64\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\windows\SysNative\userinit.exe
[2009/07/13 20:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 08:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SoftwareDistribution\Download\488053cdbca3231eeb2c2af7236d09ed\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/10/28 22:06:46 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2010/10/28 22:06:46 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\ERDNT\cache64\winlogon.exe
[2010/10/28 22:06:46 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\windows\SysNative\winlogon.exe
[2010/10/28 22:06:46 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Alternate Data Streams ==========

@Alternate Data Stream - 979 bytes -> C:\ProgramData\Microsoft:fjShx0za62cdhqPiEGa
@Alternate Data Stream - 1210 bytes -> C:\ProgramData\Microsoft:53T6CuUbnjh9cGmZscbufI
@Alternate Data Stream - 1207 bytes -> C:\Program Files\Common Files\System:kfA4PGra19R2mcTahzOwvsUPu

< End of report >
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8118
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    @Alternate Data Stream - 979 bytes -> C:\ProgramData\Microsoft:fjShx0za62cdhqPiEGa
    @Alternate Data Stream - 1210 bytes -> C:\ProgramData\Microsoft:53T6CuUbnjh9cGmZscbufI
    @Alternate Data Stream - 1207 bytes -> C:\Program Files\Common Files\System:kfA4PGra19R2mcTahzOwvsUPu
    
    
    :Commands
    [emptytemp]
    [resethosts]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )










Next

Run the following scan: Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.


Also tell me how the computer is running now.
Hum. I restarted, and tried again. It didnt work again, and I restarted. Each time, this is the log: Files\Folders moved on Reboot… C:\Users\Max\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\windows\temp\vmware-SYSTEM\vmauthd.log scheduled to be moved on reboot. C:\windows\temp\vmware-SYSTEM\vmware-usbarb-SYSTEM-2112.log moved successfully. File\Folder C:\windows\temp\klsC213.tmp not found! Registry entries deleted on Reboot… (This was opened right as I logged in)
Okay, heres the log after i ran the OTL scan.



OTL logfile created on: 11/18/2011 5:46:00 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Downloads
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

3.94 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 46.39% Memory free
7.87 Gb Paging File | 5.28 Gb Available in Paging File | 67.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 55.65 Gb Free Space | 12.53% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32

Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Max\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
PRC - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
PRC - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\SDKCOMServer.exe (Portrait Displays, Inc)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c5f091ea0acf3fe98c012c1c7251b286\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5bb0e725e6c2be05d136893ea8df3837\IAStorCommon.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll ()
MOD - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (DpHost) – C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (McAfee Endpoint Encryption Agent) – C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (HPDayStarterService) – c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLCDLOCK) – c:\Windows\SysWOW64\flcdlock.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (AdobeActiveFileMonitor10.0) – C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMwareHostd) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (hpHotkeyMonitor) – C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (hpCMSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (jhi_service) Intel® – C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
SRV - (HPFSService) – C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (Atheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (uArcCapture) – C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (MfeEpeOpal) – C:\windows\SysNative\drivers\MfeEpeOpal.sys (McAfee, Inc.)
DRV:64bit: - (MfeEpePc) – C:\windows\SysNative\drivers\MfeEpePc.sys (McAfee, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmusb) – C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (DAMDrv) – C:\Windows\SysNative\drivers\DAMDrv64.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (ARCVCAM) – C:\Windows\SysNative\drivers\ArcSoftVCapture.sys (ArcSoft, Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "about:home"

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/05/08 18:26:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/05/08 18:26:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/09/21 10:34:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ [2011/09/30 23:26:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/30 15:10:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011/08/10 21:17:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]

[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/11/05 13:58:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions
[2011/09/12 12:41:25 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions\[removed]
[2011/08/23 17:48:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\pfy0baj9.default\extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Sunbird\Profiles\lux6pdqw.default\extensions
[2011/11/09 13:49:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/03 18:15:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/08/04 16:53:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/09 13:40:16 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
[2011/10/06 09:15:54 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2
[2011/11/09 13:40:11 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
[2011/10/06 09:15:51 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{20CC25E2-48C9-45E1-9A1F-1CCC1882B81B}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\[removed]
[2011/09/30 15:10:53 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2008/08/23 16:00:54 | 005,150,696 | —- | M] (MathMonkeys, LLC) – C:\Program Files (x86)\mozilla firefox\plugins\NPLM32.DLL
[2010/01/01 03:00:00 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 03:00:00 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 03:00:00 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Max\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Monster Dash = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknghehebaconkajgiobncfleofebcog\2.2_0\
CHR - Extension: DivX HiQ = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: WeatherByte = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlgbglmmkibkhhbnhegkokegdodlgfe\1.0.3_0\
CHR - Extension: AdBlock = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.28_0\
CHR - Extension: The Fancy Pants Adventure: World 2 = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk\14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\
CHR - Extension: Climb or Drown! = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoiaaaplodaeokegmjphakphcbmiip\1.1.0_0\
CHR - Extension: MegaSkipper = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.62_0\
CHR - Extension: Canvas Rider = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.7_0\

Hosts file not found
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (File Sanitizer for HP ProtectTools) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MfeEpePcMonitor] C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ie_banner_deny.htm ()
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futuremark.com/calico/syste…y/FMSI_v420.cab (FuturemarkSystemInfoX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2912C486-28C5-4AF2-B814-E069DD38267A}: DhcpNameServer = [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\kloehk.dll (Kaspersky Lab ZAO)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\sbhook64.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) -C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\sbhook.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\DeviceNP: DllName - (DeviceNP.dll) - C:\windows\SysWow64\DeviceNP.dll (Hewlett-Packard Company)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/18 13:10:47 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Contacts-1
[2011/11/18 13:09:46 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Contacts
[2011/11/18 00:23:14 | 000,000,000 | —D | C] – C:\_OTL
[2011/11/15 09:31:41 | 001,564,976 | —- | C] (Kaspersky Lab ZAO) – C:\Users\Max\Desktop\TDSSKiller.exe
[2011/11/12 16:05:13 | 000,000,000 | —D | C] – C:\windows\SysNative\Macromed
[2011/11/11 14:44:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/11 14:23:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/11 14:06:08 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/11/10 17:32:39 | 000,000,000 | —D | C] – C:\Sun
[2011/11/09 21:54:22 | 000,066,856 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:54:21 | 000,392,752 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:54:21 | 000,226,600 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:54:21 | 000,148,264 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:54:21 | 000,107,816 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:54:15 | 000,277,288 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:54:15 | 000,222,504 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:54:15 | 000,177,448 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:21:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wwanprotdim.dll
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 13:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2011/11/09 13:37:32 | 000,556,120 | —- | C] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 12:27:49 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2011/11/08 23:50:10 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Malwarebytes
[2011/11/08 23:50:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/08 23:50:02 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/11/08 16:29:24 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Local\VMware
[2011/11/08 16:29:23 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\VMware
[2011/11/08 16:27:01 | 000,062,064 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmx86.sys
[2011/11/08 16:26:28 | 000,354,416 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnetdhcp.exe
[2011/11/08 16:26:25 | 000,432,752 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnat.exe
[2011/11/08 16:26:24 | 000,030,320 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmnetuserif.sys
[2011/11/08 16:26:21 | 000,942,192 | —- | C] (VMware, Inc.) – C:\windows\SysNative\vnetlib64.dll
[2011/11/08 16:26:07 | 000,039,024 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\hcmon.sys
[2011/11/08 16:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\ProgramData\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Shared Virtual Machines
[2011/11/08 16:24:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2011/11/08 15:50:27 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Rainbows!
[2011/11/06 22:58:07 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Symantec
[2011/11/06 22:10:03 | 000,000,000 | —D | C] – C:\ProgramData\Wavefunction
[2011/11/06 21:08:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spartan '08 V1.2.0
[2011/11/06 21:07:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wavefunction
[2011/11/05 10:17:53 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011/11/05 10:17:52 | 000,000,000 | —D | C] – C:\Fraps
[2011/11/04 13:37:51 | 000,000,000 | —D | C] – C:\Users\Max\Documents\GTA San Andreas User Files
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rockstar Games
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\ProgramData\fltk.org
[2011/11/01 19:43:24 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Amnesia
[2011/11/01 12:11:18 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/10/26 11:38:07 | 000,000,000 | —D | C] – C:\Users\Max\Documents\NewBlueFX
[2011/10/26 09:02:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartSound Software
[2011/10/26 09:02:18 | 000,000,000 | —D | C] – C:\ProgramData\SmartSound Software Inc
[2011/10/24 16:54:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveMath
[2011/10/24 16:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\LiveMath
[2011/10/23 16:31:23 | 000,000,000 | —D | C] – C:\MC Server 1.8
[2011/02/24 00:10:36 | 000,020,432 | —- | C] (Intel Corporation) – C:\Users\Max\AppData\Roaming\JomCap.dll

========== Files - Modified Within 30 Days ==========

[2011/11/18 17:42:00 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job
[2011/11/18 17:14:46 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/18 17:14:46 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/18 17:06:54 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/11/18 17:06:50 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2011/11/18 16:44:05 | 000,002,353 | —- | M] () – C:\Users\Max\Desktop\Google Chrome.lnk
[2011/11/18 16:41:03 | 000,000,324 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/18 11:42:01 | 000,000,848 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job
[2011/11/17 11:16:38 | 1054,404,274 | —- | M] () – C:\Users\Max\Documents\Chemistry November 17(2).wav
[2011/11/17 11:16:38 | 000,514,876 | —- | M] () – C:\Users\Max\Documents\Chemistry November 17(2).pkf
[2011/11/17 10:10:03 | 285,737,006 | —- | M] () – C:\Users\Max\Documents\Chemistry November 17th.wav
[2011/11/16 11:07:36 | 1185,633,788 | —- | M] () – C:\Users\Max\Documents\biology november 16.wav
[2011/11/16 11:07:36 | 000,578,972 | —- | M] () – C:\Users\Max\Documents\biology november 16.pkf
[2011/11/15 13:04:17 | 1939,387,900 | —- | M] () – C:\Users\Max\Documents\TBB November 15.wav
[2011/11/15 13:04:17 | 000,947,004 | —- | M] () – C:\Users\Max\Documents\TBB November 15.pkf
[2011/11/15 10:39:08 | 214,627,836 | —- | M] () – C:\Users\Max\Documents\Chemistry November 15.wav
[2011/11/15 10:39:08 | 000,419,228 | —- | M] () – C:\Users\Max\Documents\Chemistry November 15.pkf
[2011/11/15 09:33:38 | 000,001,296 | —- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/11/14 11:18:20 | 897,062,396 | —- | M] () – C:\Users\Max\Documents\Chemistry November 14.wav
[2011/11/14 11:18:20 | 000,438,044 | —- | M] () – C:\Users\Max\Documents\Chemistry November 14.pkf
[2011/11/14 11:16:26 | 1181,652,476 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 16.wav
[2011/11/14 11:16:26 | 000,577,020 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 16.pkf
[2011/11/12 16:05:18 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/11/12 16:01:32 | 005,000,616 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/11/11 15:48:16 | 001,564,976 | —- | M] (Kaspersky Lab ZAO) – C:\Users\Max\Desktop\TDSSKiller.exe
[2011/11/11 13:54:12 | 000,007,598 | —- | M] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/11 00:22:14 | 000,794,000 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/11/11 00:22:14 | 000,672,826 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/11/11 00:22:14 | 000,128,986 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/11/10 23:30:45 | 000,000,021 | —- | M] () – C:\windows\SurCode.INI
[2011/11/10 20:09:59 | 000,783,562 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/11/10 10:20:33 | 919,371,004 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/10 10:20:33 | 000,448,956 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/09 21:53:39 | 000,066,856 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:53:37 | 000,392,752 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:53:37 | 000,226,600 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:53:37 | 000,148,264 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:53:37 | 000,107,816 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:53:36 | 001,048,576 | —- | M] () – C:\windows\SysNative\syndata.bin
[2011/11/09 21:53:36 | 000,277,288 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:53:36 | 000,222,504 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:53:32 | 000,415,528 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCOM.dll
[2011/11/09 21:53:32 | 000,177,448 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:49:02 | 000,152,233 | —- | M] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:49:02 | 000,107,177 | —- | M] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:37:32 | 000,556,120 | —- | M] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 13:25:58 | 000,089,448 | —- | M] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 1124,496,892 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/09 12:32:53 | 000,549,116 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/08 23:56:16 | 000,000,000 | —- | M] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | M] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | M] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | M] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 1196,602,876 | —- | M] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/04 13:14:29 | 005,550,172 | —- | M] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/03 15:59:45 | 000,299,178 | —- | M] () – C:\Users\Max\Documents\marks.pdf
[2011/11/03 09:37:55 | 854,881,788 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/02 10:18:26 | 1086,019,068 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/02 10:18:26 | 000,530,332 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/01 12:17:00 | 1066,628,818 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:03:17 | 2150,422,524 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 09:00:50 | 004,856,572 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 09:00:49 | 1033,901,564 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 962,287,314 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:58:42 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:45 | 000,485,180 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:39 | 993,572,348 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/30 22:47:06 | 000,000,336 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMAXHP$.job
[2011/10/27 11:17:34 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 1311,806,972 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 10:23:09 | 1082,578,642 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 08:57:51 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:22 | 002,429,826 | —- | M] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:47:52 | 000,332,874 | —- | M] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 975,943,164 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:40:16 | 000,476,572 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:38:48 | 1848,899,068 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/24 10:20:53 | 767,129,084 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:06 | 1077,736,956 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/22 12:17:02 | 1288,992,252 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/21 21:37:21 | 3818,616,316 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/20 09:59:45 | 1031,960,060 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.pkf

========== Files Created - No Company Name ==========

[2011/11/17 11:16:38 | 000,514,876 | —- | C] () – C:\Users\Max\Documents\Chemistry November 17(2).pkf
[2011/11/17 11:16:01 | 1054,404,274 | —- | C] () – C:\Users\Max\Documents\Chemistry November 17(2).wav
[2011/11/17 10:09:50 | 285,737,006 | —- | C] () – C:\Users\Max\Documents\Chemistry November 17th.wav
[2011/11/16 21:40:29 | 000,000,324 | —- | C] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/16 11:07:36 | 000,578,972 | —- | C] () – C:\Users\Max\Documents\biology november 16.pkf
[2011/11/16 11:06:43 | 1185,633,788 | —- | C] () – C:\Users\Max\Documents\biology november 16.wav
[2011/11/15 13:04:17 | 000,947,004 | —- | C] () – C:\Users\Max\Documents\TBB November 15.pkf
[2011/11/15 13:01:32 | 1939,387,900 | —- | C] () – C:\Users\Max\Documents\TBB November 15.wav
[2011/11/15 10:39:08 | 000,419,228 | —- | C] () – C:\Users\Max\Documents\Chemistry November 15.pkf
[2011/11/15 10:39:03 | 214,627,836 | —- | C] () – C:\Users\Max\Documents\Chemistry November 15.wav
[2011/11/14 11:18:20 | 000,438,044 | —- | C] () – C:\Users\Max\Documents\Chemistry November 14.pkf
[2011/11/14 11:17:04 | 897,062,396 | —- | C] () – C:\Users\Max\Documents\Chemistry November 14.wav
[2011/11/14 11:16:26 | 000,577,020 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 16.pkf
[2011/11/14 11:15:14 | 1181,652,476 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 16.wav
[2011/11/11 13:54:12 | 000,007,598 | —- | C] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/10 10:20:33 | 000,448,956 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/10 10:18:59 | 919,371,004 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/09 21:54:15 | 001,048,576 | —- | C] () – C:\windows\SysNative\syndata.bin
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:40:01 | 000,152,233 | —- | C] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:40:01 | 000,107,177 | —- | C] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:25:55 | 000,089,448 | —- | C] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 000,549,116 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/09 12:27:46 | 1124,496,892 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/08 23:56:16 | 000,000,000 | —- | C] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | C] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | C] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | C] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | C] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 005,550,172 | —- | C] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/04 13:12:21 | 1196,602,876 | —- | C] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/03 09:37:10 | 854,881,788 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:27:50 | 000,299,178 | —- | C] () – C:\Users\Max\Documents\marks.pdf
[2011/11/02 10:18:26 | 000,530,332 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/02 10:17:01 | 1086,019,068 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:15:49 | 1066,628,818 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 12:02:26 | 2150,422,524 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 09:00:49 | 004,856,572 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 08:59:39 | 1033,901,564 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:59:58 | 962,287,314 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 09:58:04 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:39 | 000,485,180 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:18 | 993,572,348 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/27 11:16:21 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 21:14:04 | 1311,806,972 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 10:22:39 | 1082,578,642 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 09:01:17 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/26 08:57:51 | 000,002,237 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 10.lnk
[2011/10/26 08:57:51 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:20 | 002,429,826 | —- | C] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:46:23 | 000,332,874 | —- | C] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 000,476,572 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:39:52 | 975,943,164 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/25 13:37:33 | 1848,899,068 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:20 | 767,129,084 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/24 10:18:26 | 1077,736,956 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/22 12:16:07 | 1288,992,252 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/21 21:34:21 | 3818,616,316 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/20 09:58:05 | 1031,960,060 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/15 20:30:47 | 000,000,132 | —- | C] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/06 09:16:51 | 000,017,408 | —- | C] () – C:\Users\Max\AppData\Local\WebpageIcons.db
[2011/09/05 08:57:34 | 000,366,136 | —- | C] () – C:\windows\SysWow64\flcdlmsg.dll
[2011/08/24 14:30:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPLic.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPPassFilter.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPCrProv.dll.hpsign
[2011/08/24 13:55:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApiUI.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPSCEL.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApi.dll.hpsign
[2011/08/24 13:53:42 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPClback.dll.hpsign
[2011/08/23 10:10:44 | 000,000,256 | —- | C] () – C:\windows\SysWow64\vcsAPIShared.dll.hpsign
[2011/07/02 21:54:28 | 000,186,460 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/06/15 20:03:03 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/14 17:25:49 | 000,000,021 | —- | C] () – C:\windows\SurCode.INI
[2011/05/30 21:58:34 | 000,185,168 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll
[2011/05/30 21:58:34 | 000,000,256 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll.hpsign
[2011/05/29 14:23:14 | 000,000,355 | —- | C] () – C:\windows\EReg176.dat
[2011/05/20 07:37:54 | 000,000,105 | —- | C] () – C:\windows\Antidote7.ini
[2011/05/18 16:53:37 | 000,963,116 | —- | C] () – C:\windows\SysWow64\igkrng600.bin
[2011/05/18 16:53:36 | 000,216,876 | —- | C] () – C:\windows\SysWow64\igfcg600m.bin
[2011/05/03 21:17:55 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\windows\SysWow64\xlive.dll.cat
[2011/04/08 20:00:20 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgchid.sys
[2011/04/08 19:38:38 | 000,025,984 | —- | C] () – C:\windows\snuvcdsm.exe
[2011/04/08 19:38:38 | 000,015,497 | —- | C] () – C:\windows\snp2uvc.ini
[2011/03/03 14:56:41 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbbb.sys
[2011/03/03 14:38:47 | 000,000,178 | —- | C] () – C:\windows\SysWow64\HPPA.ini
[2011/03/03 14:33:15 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbdf.sys
[2011/03/03 14:04:33 | 000,794,000 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/01/29 18:49:32 | 000,017,232 | —- | C] () – C:\windows\SysWow64\CoHpCasl.exe
[2011/01/26 21:55:20 | 000,145,804 | —- | C] () – C:\windows\SysWow64\igcompkrng600.bin
[2011/01/10 22:03:08 | 086,271,980 | —- | C] () – C:\windows\SysWow64\BioTrustFace.dat
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI