It installed a program which kept asking for me to install an anti-virus program, which i knew was a virus and thus I went into safemode and ran Malware Bytes and deleted a few trojans, which stopped that program.
I began noticing my computer fan was always running at full speed and I became concerned. Looking at Task Manager, it appeared I had a program called PING.EXE taking up alot of resources. Looking online, I stumbled upon a few threads that had answers, but no one really seemed to fix it. I found this thread on your website
And followed the steps and got the ComboFix program which seemed to fix a lot of things, and I no longer have the ping.exe process. I KNOW now that I wasnt supposed to do that as your http://forums.whatthetech.com/index.php?showtopic=106388 thread specifies that clearly, but I had not looked at that beforehand. Although the problem seems to have disappeared, I am still worried that I may have keyloggers or something else still on the computer, so I am coming to you to ask for advice. I would appreatiate if you could check if there is anything else that either ComboFix or ping.exe did to my machine
Here are my log files from OTL:
OTL.txt:
OTL logfile created on: 11/11/2011 3:05:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.94 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.67% Memory free
7.87 Gb Paging File | 5.72 Gb Available in Paging File | 72.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 75.68 Gb Free Space | 17.04% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32
Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Max\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
PRC - C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
PRC - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
PRC - C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
PRC - c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
PRC - C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\c5f091ea0acf3fe98c012c1c7251b286\IAStorUtil.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\5bb0e725e6c2be05d136893ea8df3837\IAStorCommon.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\cc6713be0e405d5a89a2783103f7e771\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\018d2569cf208acbe8ad73908705f607\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\d76221993c2fdfb991b8c12ae50a30eb\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\0e245eb9c1067cabd5673fe832d28613\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\3136e12cfb8809d39813e76c766c782c\WindowsBase.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\275680f2b9db0501d53c50ea7d7a43f0\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\e9ebeb7959f1c916ebf6fca8f7077d6c\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\95b9866ab6e4437ef5dc5855ebab4e33\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\1b31ced9bb880d94fff1c6d47c16a81e\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
MOD - C:\windows\assembly\GAC_MSIL\HP.SupportFramework\1.0.0.0__2a4860322af7ba08\HP.SupportFramework.dll ()
MOD - C:\Windows\SysWOW64\flcdlmsg.dll ()
MOD - C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (DpHost) – C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (McAfee Endpoint Encryption Agent) – C:\Program Files\Hewlett-Packard\Drive Encryption\EEAgent\MfeEpeHost.exe ()
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (HPDayStarterService) – c:\Program Files\Hewlett-Packard\HP DayStarter\32-bit\HPDayStarterService.exe (Hewlett-Packard Company)
SRV:64bit: - (HP Power Assistant Service) – C:\Program Files\Hewlett-Packard\HP Power Assistant\HPPA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) – C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV - (AVP) – C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
SRV - (IAStorDataMgrSvc) Intel® – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (FLCDLOCK) – c:\Windows\SysWOW64\flcdlock.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (AdobeActiveFileMonitor10.0) – C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (VMnetDHCP) – C:\Windows\SysWOW64\vmnetdhcp.exe (VMware, Inc.)
SRV - (VMware NAT Service) – C:\Windows\SysWOW64\vmnat.exe (VMware, Inc.)
SRV - (VMwareHostd) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe ()
SRV - (VMAuthdService) – C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (VMware, Inc.)
SRV - (VMUSBArbService) – C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (VMware, Inc.)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (Futuremark SystemInfo Service) – C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (hpHotkeyMonitor) – C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\hpHotkeyMonitor.exe (Hewlett-Packard Company)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Hewlett-Packard Company)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (hpCMSrv) – C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\hpCMSrv.exe (Hewlett-Packard Development Company L.P.)
SRV - (jhi_service) Intel® – C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe (Intel Corporation)
SRV - (HPFSService) – C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\HPFSService.exe (Hewlett-Packard)
SRV - (PdiService) – C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Portrait Displays, Inc.)
SRV - (Atheros Bt&Wlan; Coex Agent) – C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros)
SRV - (AtherosSvc) – C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Atheros Commnucations)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (uArcCapture) – C:\Windows\SysWOW64\ArcVCapRender\uArcCapture.exe (ArcSoft, Inc.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (KLIF) – C:\Windows\SysNative\drivers\klif.sys (Kaspersky Lab)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (nusb3xhc) – C:\Windows\SysNative\drivers\nusb3xhc.sys (Renesas Electronics Corporation)
DRV:64bit: - (nusb3hub) – C:\Windows\SysNative\drivers\nusb3hub.sys (Renesas Electronics Corporation)
DRV:64bit: - (vmx86) – C:\Windows\SysNative\drivers\vmx86.sys (VMware, Inc.)
DRV:64bit: - (VMnetuserif) – C:\Windows\SysNative\drivers\vmnetuserif.sys (VMware, Inc.)
DRV:64bit: - (VMnetBridge) – C:\Windows\SysNative\drivers\vmnetbridge.sys (VMware, Inc.)
DRV:64bit: - (VMnetAdapter) – C:\Windows\SysNative\drivers\vmnetadapter.sys (VMware, Inc.)
DRV:64bit: - (MfeEpeOpal) – C:\windows\SysNative\drivers\MfeEpeOpal.sys (McAfee, Inc.)
DRV:64bit: - (MfeEpePc) – C:\windows\SysNative\drivers\MfeEpePc.sys (McAfee, Inc.)
DRV:64bit: - (hcmon) – C:\Windows\SysNative\drivers\hcmon.sys (VMware, Inc.)
DRV:64bit: - (vmusb) – C:\Windows\SysNative\drivers\vmusb.sys (VMware, Inc.)
DRV:64bit: - (vmci) – C:\Windows\SysNative\drivers\vmci.sys (VMware, Inc.)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
DRV:64bit: - (JMCR) – C:\Windows\SysNative\drivers\jmcr.sys (JMicron Technology Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (DAMDrv) – C:\Windows\SysNative\drivers\DAMDrv64.sys (Hewlett-Packard Company)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (BtFilter) – C:\Windows\SysNative\drivers\btfilter.sys (Atheros)
DRV:64bit: - (BTATH_HCRP) – C:\Windows\SysNative\drivers\btath_hcrp.sys (Atheros)
DRV:64bit: - (BTATH_RCP) – C:\Windows\SysNative\drivers\btath_rcp.sys (Atheros)
DRV:64bit: - (BTATH_LWFLT) – C:\Windows\SysNative\drivers\btath_lwflt.sys (Atheros)
DRV:64bit: - (AthBTPort) – C:\Windows\SysNative\drivers\btath_flt.sys (Atheros)
DRV:64bit: - (BTATH_A2DP) – C:\Windows\SysNative\drivers\btath_a2dp.sys (Atheros)
DRV:64bit: - (BTATH_BUS) – C:\Windows\SysNative\drivers\btath_bus.sys (Atheros)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\drivers\snp2uvc.sys ()
DRV:64bit: - (HpqKbFiltr) – C:\Windows\SysNative\drivers\HpqKbFiltr.sys (Hewlett-Packard Company)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (ARCVCAM) – C:\Windows\SysNative\drivers\ArcSoftVCapture.sys (ArcSoft, Inc.)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (MEIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (IntcDAud) Intel® – C:\Windows\SysNative\drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (kl2) – C:\Windows\SysNative\drivers\kl2.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KL1) – C:\Windows\SysNative\drivers\kl1.sys (Kaspersky Lab ZAO)
DRV:64bit: - (KLIM6) – C:\Windows\SysNative\drivers\klim6.sys (Kaspersky Lab ZAO)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (vpcvmm) – C:\Windows\SysNative\drivers\vpcvmm.sys (Microsoft Corporation)
DRV:64bit: - (klmouflt) – C:\Windows\SysNative\drivers\klmouflt.sys (Kaspersky Lab)
DRV:64bit: - (vpcnfltr) – C:\Windows\SysNative\drivers\vpcnfltr.sys (Microsoft Corporation)
DRV:64bit: - (vpcusb) – C:\Windows\SysNative\drivers\vpcusb.sys (Microsoft Corporation)
DRV:64bit: - (vpcbus) – C:\Windows\SysNative\drivers\vpchbus.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TPM) – C:\Windows\SysNative\drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (AgereSoftModem) – C:\Windows\SysNative\drivers\agrsm64.sys (LSI Corp)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPCOM/7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 127.0.0.1:8118
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "about:home"
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Acrobat: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Max\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\html5video [2011/05/08 18:26:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\wpa [2011/05/08 18:26:09 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/09/21 10:34:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\FirefoxExt\ [2011/09/30 23:26:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\FFExt\[removed] [2011/11/09 13:49:08 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/09/30 15:10:53 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Components: C:\Program Files (x86)\Mozilla Sunbird\components [2011/08/10 21:17:43 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Sunbird 1.0b1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Sunbird\plugins [2011/10/24 16:54:56 | 000,000,000 | —D | M]
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Extensions\{718e30fb-e89b-41dd-9da7-e25a45638b28}
[2011/11/05 13:58:49 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions
[2011/09/12 12:41:25 | 000,000,000 | —D | M] (United States English Spellchecker) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\8jnh9p7q.default\extensions\[removed]
[2011/08/23 17:48:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Firefox\Profiles\pfy0baj9.default\extensions
[2011/07/06 01:08:47 | 000,000,000 | —D | M] (No name found) – C:\Users\Max\AppData\Roaming\Mozilla\Sunbird\Profiles\lux6pdqw.default\extensions
[2011/11/09 13:49:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/03 18:15:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/08/04 16:53:16 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/09 13:40:16 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak
[2011/10/06 09:15:54 | 000,000,000 | —D | M] (Anti-Banner) – C:\Program Files (x86)\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2
[2011/11/09 13:40:11 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak
[2011/10/06 09:15:51 | 000,000,000 | —D | M] (Kaspersky URL Advisor) – C:\Program Files (x86)\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{19503E42-CA3C-4C27-B1E2-9CDB2170EE34}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{20CC25E2-48C9-45E1-9A1F-1CCC1882B81B}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{53A03D43-5363-4669-8190-99061B2DEBA5}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) – C:\USERS\MAX\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\8JNH9P7Q.DEFAULT\EXTENSIONS\[removed]
[2011/09/30 15:10:53 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2008/08/23 16:00:54 | 005,150,696 | —- | M] (MathMonkeys, LLC) – C:\Program Files (x86)\mozilla firefox\plugins\NPLM32.DLL
[2010/01/01 03:00:00 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/01/01 03:00:00 | 000,001,180 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/01/01 03:00:00 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: AVG Internet Security (Enabled) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1409_0\plugins/avgnpss.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Max\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Nexon Game Controller (Enabled) = C:\ProgramData\NexonUS\NGM\npNxGameUS.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Max\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Adblock Plus for Google Chrome\u2122 (Beta) = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.1.4_0\
CHR - Extension: Monster Dash = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\cknghehebaconkajgiobncfleofebcog\2.2_0\
CHR - Extension: DivX HiQ = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnjbmmemklcjgepojigaapkoodmkgbae\2.1.1.94_0\
CHR - Extension: WeatherByte = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnlgbglmmkibkhhbnhegkokegdodlgfe\1.0.3_0\
CHR - Extension: AdBlock = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.4.28_0\
CHR - Extension: The Fancy Pants Adventure: World 2 = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk\14_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.1.94_0\
CHR - Extension: Climb or Drown! = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\omfoiaaaplodaeokegmjphakphcbmiip\1.1.0_0\
CHR - Extension: MegaSkipper = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\phlpjnmkcepflfoglccifhajagahaglm\19.60_0\
CHR - Extension: Canvas Rider = C:\Users\Max\AppData\Local\Google\Chrome\User Data\Default\Extensions\poknhlcknimnnbfcombaooklofipaibk\0.7_0\
O1 HOSTS File: ([2011/11/11 14:23:29 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\ievkbd.dll (Kaspersky Lab ZAO)
O2:64bit: - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (File Sanitizer for HP ProtectTools) - {3134413B-49B4-425C-98A5-893C1F195601} - C:\Program Files (x86)\Hewlett-Packard\File Sanitizer\IEBHO.dll (Hewlett-Packard)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (IEVkbdBHO Class) - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\ievkbd.dll (Kaspersky Lab ZAO)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (CIESpeechBHO Class) - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (FilterBHO Class) - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPPowerAssistant] C:\Program Files\Hewlett-Packard\HP Power Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [MfeEpePcMonitor] C:\Program Files\Hewlett-Packard\Drive Encryption\EpePcMonitor.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AVP] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\avp.exe (Kaspersky Lab ZAO)
O4 - HKLM..\Run: [HPConnectionManager] C:\Program Files (x86)\Hewlett-Packard\HP Connection Manager\HPCMDelayStart.exe (Hewlett-Packard Development Company L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [NUSB3MON] c:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Renesas Electronics Corporation)
O4 - HKLM..\Run: [QLBController] C:\Program Files (x86)\Hewlett-Packard\HP HotKey Support\QLBController.exe (Hewlett-Packard Company)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Max\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 60
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:64bit: - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9:64bit: - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - Reg Error: Value error. File not found
O9:64bit: - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: &Virtual; Keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra 'Tools' menuitem : Send by Bluetooth to - {7815BE26-237D-41A8-A98F-F7BD75F71086} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
O9 - Extra Button: URLs c&heck; - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\klwtbbho.dll (Kaspersky Lab ZAO)
O9 - Extra Button: Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O9 - Extra 'Tools' menuitem : Add to Evernote - {E0B8C461-F8FB-49b4-8373-FE32E92528A6} - C:\Program Files (x86)\Evernote\Evernote3.5\enbar.dll (Evernote Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000013 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {BAD4FE2C-503B-45CC-88CD-4B0574057D11} http://clients.futuremark.com/calico/syste…y/FMSI_v420.cab (FuturemarkSystemInfoX Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.systemrequirementslab.com.s…ri_4.4.26.0.cab (SysInfo Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2912C486-28C5-4AF2-B814-E069DD38267A}: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\kloehk.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\kloehk.dll (Kaspersky Lab ZAO)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\x64\sbhook64.dll) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\x64\sbhook64.dll (Kaspersky Lab ZAO)
O20 - AppInit_DLLs: (C:\PROGRA~2\KASPER~1\KASPER~1\sbhook.dll) -C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2011\sbhook.dll (Kaspersky Lab ZAO)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\klogon: DllName - (%SystemRoot%\System32\klogon.dll) - C:\Windows\SysNative\klogon.dll (Kaspersky Lab ZAO)
O20 - Winlogon\Notify\DeviceNP: DllName - (DeviceNP.dll) - C:\windows\SysWow64\DeviceNP.dll (Hewlett-Packard Company)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: VIDC.FPS1 - C:\windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: VIDC.VMnc - C:\windows\SysWow64\vmnc.dll (VMware, Inc.)
Drivers32: vidc.VP60 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\SysWOW64\vp6vfw.dll (On2.com)
Drivers32: vidc.yv12 - C:\windows\SysWow64\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/11 14:44:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2011/11/11 14:39:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/11 14:39:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/11 14:23:52 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/11/11 14:06:08 | 000,000,000 | —D | C] – C:\windows\ERDNT
[2011/11/11 14:05:05 | 000,000,000 | —D | C] – C:\Users\Max\Desktop\tdsskiller
[2011/11/11 13:54:00 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe
[2011/11/10 17:32:39 | 000,000,000 | —D | C] – C:\Sun
[2011/11/09 21:54:22 | 000,066,856 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:54:21 | 000,392,752 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:54:21 | 000,226,600 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:54:21 | 000,148,264 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:54:21 | 000,107,816 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:54:15 | 000,277,288 | —- | C] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:54:15 | 000,222,504 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:54:15 | 000,177,448 | —- | C] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:21:22 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wwanprotdim.dll
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/09 14:02:04 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2011/11/09 13:40:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2011
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab
[2011/11/09 13:38:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2011/11/09 13:37:32 | 000,556,120 | —- | C] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 12:27:49 | 000,000,000 | —D | C] – C:\ProgramData\Kaspersky Lab Setup Files
[2011/11/08 23:50:10 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Malwarebytes
[2011/11/08 23:50:05 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/11/08 23:50:02 | 000,025,416 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2011/11/08 16:29:24 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Local\VMware
[2011/11/08 16:29:23 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\VMware
[2011/11/08 16:27:01 | 000,062,064 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmx86.sys
[2011/11/08 16:26:28 | 000,354,416 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnetdhcp.exe
[2011/11/08 16:26:25 | 000,432,752 | —- | C] (VMware, Inc.) – C:\windows\SysWow64\vmnat.exe
[2011/11/08 16:26:24 | 000,030,320 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\vmnetuserif.sys
[2011/11/08 16:26:21 | 000,942,192 | —- | C] (VMware, Inc.) – C:\windows\SysNative\vnetlib64.dll
[2011/11/08 16:26:07 | 000,039,024 | —- | C] (VMware, Inc.) – C:\windows\SysNative\drivers\hcmon.sys
[2011/11/08 16:25:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\ProgramData\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\VMware
[2011/11/08 16:24:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Shared Virtual Machines
[2011/11/08 16:24:25 | 000,000,000 | —D | C] – C:\Program Files\Common Files\VMware
[2011/11/08 15:50:27 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Rainbows!
[2011/11/06 22:58:07 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Symantec
[2011/11/06 22:10:03 | 000,000,000 | —D | C] – C:\ProgramData\Wavefunction
[2011/11/06 21:08:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spartan '08 V1.2.0
[2011/11/06 21:07:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wavefunction
[2011/11/05 10:17:53 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2011/11/05 10:17:52 | 000,000,000 | —D | C] – C:\Fraps
[2011/11/04 13:37:51 | 000,000,000 | —D | C] – C:\Users\Max\Documents\GTA San Andreas User Files
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
[2011/11/04 13:15:09 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rockstar Games
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/11/01 19:43:30 | 000,000,000 | —D | C] – C:\ProgramData\fltk.org
[2011/11/01 19:43:24 | 000,000,000 | —D | C] – C:\Users\Max\Documents\Amnesia
[2011/11/01 12:11:18 | 000,000,000 | —D | C] – C:\ProgramData\Trymedia
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:49:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/11/01 11:39:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Activision
[2011/10/26 11:38:07 | 000,000,000 | —D | C] – C:\Users\Max\Documents\NewBlueFX
[2011/10/26 09:02:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\SmartSound Software
[2011/10/26 09:02:18 | 000,000,000 | —D | C] – C:\ProgramData\SmartSound Software Inc
[2011/10/24 16:54:56 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LiveMath
[2011/10/24 16:54:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\LiveMath
[2011/10/23 16:31:23 | 000,000,000 | —D | C] – C:\MC Server 1.8
[2011/10/13 16:35:41 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\MP3toiPodAudioBookConverter
[2011/10/13 11:48:43 | 000,000,000 | —D | C] – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 to iPod Audio Book Converter
[2011/10/13 11:48:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\MP3ToIpodAudioBookConverter
[2011/02/24 00:10:36 | 000,020,432 | —- | C] (Intel Corporation) – C:\Users\Max\AppData\Roaming\JomCap.dll
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/11 15:03:31 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/11 15:03:31 | 000,020,944 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/11 14:42:00 | 000,000,900 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001UA.job
[2011/11/11 14:39:06 | 000,001,113 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 14:23:29 | 000,000,027 | —- | M] () – C:\windows\SysNative\drivers\etc\hosts
[2011/11/11 14:22:59 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2011/11/11 14:22:53 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2011/11/11 14:04:27 | 001,545,878 | —- | M] () – C:\Users\Max\Desktop\tdsskiller.zip
[2011/11/11 13:54:12 | 000,007,598 | —- | M] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/11 13:54:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe
[2011/11/11 13:29:51 | 004,992,368 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2011/11/11 12:46:09 | 000,002,353 | —- | M] () – C:\Users\Max\Desktop\Google Chrome.lnk
[2011/11/11 12:15:09 | 000,000,848 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskUserS-1-5-21-1559286956-1952481419-3090631150-1001Core.job
[2011/11/11 00:22:14 | 000,794,000 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/11/11 00:22:14 | 000,672,826 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2011/11/11 00:22:14 | 000,128,986 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2011/11/10 23:30:45 | 000,000,021 | —- | M] () – C:\windows\SurCode.INI
[2011/11/10 20:09:59 | 000,783,562 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2011/11/10 17:35:49 | 000,000,324 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/10 10:20:33 | 919,371,004 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/10 10:20:33 | 000,448,956 | —- | M] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/09 21:53:39 | 000,066,856 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPEnhPS.dll
[2011/11/09 21:53:37 | 000,392,752 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\drivers\SynTP.sys
[2011/11/09 21:53:37 | 000,226,600 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPAPI.dll
[2011/11/09 21:53:37 | 000,148,264 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynTPCo9.dll
[2011/11/09 21:53:37 | 000,107,816 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynTPCOM.dll
[2011/11/09 21:53:36 | 001,048,576 | —- | M] () – C:\windows\SysNative\syndata.bin
[2011/11/09 21:53:36 | 000,277,288 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCtrl.dll
[2011/11/09 21:53:36 | 000,222,504 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCtrl.dll
[2011/11/09 21:53:32 | 000,415,528 | —- | M] (Synaptics Incorporated) – C:\windows\SysNative\SynCOM.dll
[2011/11/09 21:53:32 | 000,177,448 | —- | M] (Synaptics Incorporated) – C:\windows\SysWow64\SynCOM.dll
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | M] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:49:02 | 000,152,233 | —- | M] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:49:02 | 000,107,177 | —- | M] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:37:32 | 000,556,120 | —- | M] (Kaspersky Lab) – C:\windows\SysNative\drivers\klif.sys
[2011/11/09 13:25:58 | 000,089,448 | —- | M] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 1124,496,892 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/09 12:32:53 | 000,549,116 | —- | M] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/08 23:56:16 | 000,000,000 | —- | M] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | M] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | M] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | M] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 1196,602,876 | —- | M] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/04 13:14:29 | 005,550,172 | —- | M] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/03 15:59:45 | 000,299,178 | —- | M] () – C:\Users\Max\Documents\marks.pdf
[2011/11/03 09:37:55 | 854,881,788 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | M] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/02 10:18:26 | 1086,019,068 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/02 10:18:26 | 000,530,332 | —- | M] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/01 12:17:00 | 1066,628,818 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:03:17 | 2150,422,524 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | M] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 09:00:50 | 004,856,572 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 09:00:49 | 1033,901,564 | —- | M] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 962,287,314 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | M] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:58:42 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:45 | 000,485,180 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:39 | 993,572,348 | —- | M] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/30 22:47:06 | 000,000,336 | —- | M] () – C:\windows\tasks\HPCeeScheduleForMAXHP$.job
[2011/10/27 11:17:34 | 1066,623,022 | —- | M] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/27 08:46:10 | 000,001,296 | —- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2011/10/26 21:14:46 | 1311,806,972 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | M] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 10:23:09 | 1082,578,642 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | M] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 08:57:51 | 000,001,217 | —- | M] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:22 | 002,429,826 | —- | M] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:47:52 | 000,332,874 | —- | M] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 975,943,164 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:40:16 | 000,476,572 | —- | M] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:38:48 | 1848,899,068 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | M] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/24 10:20:53 | 767,129,084 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:06 | 1077,736,956 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | M] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/22 12:17:02 | 1288,992,252 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | M] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/21 21:37:21 | 3818,616,316 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | M] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/20 09:59:45 | 1031,960,060 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | M] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/19 10:16:47 | 1101,297,148 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | M] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/18 14:20:51 | 1573,713,404 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | M] () – C:\Users\Max\Documents\TTB October 18th.pkf
[2011/10/18 09:13:06 | 1021,621,756 | —- | M] () – C:\Users\Max\Documents\Chemistry October 18.wav
[2011/10/18 09:13:06 | 000,498,876 | —- | M] () – C:\Users\Max\Documents\Chemistry October 18.pkf
[2011/10/17 10:21:44 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/10/17 10:16:34 | 939,226,620 | —- | M] () – C:\Users\Max\Documents\Chemistry October 17th.wav
[2011/10/17 10:16:34 | 000,458,652 | —- | M] () – C:\Users\Max\Documents\Chemistry October 17th.pkf
[2011/10/17 10:13:40 | 1062,983,164 | —- | M] () – C:\Users\Max\Documents\Biology October 17th.wav
[2011/10/17 10:13:40 | 000,519,068 | —- | M] () – C:\Users\Max\Documents\Biology October 17th.pkf
[2011/10/15 20:39:41 | 000,269,496 | —- | M] () – C:\Users\Max\Documents\Unicron 2.png
[2011/10/15 20:39:00 | 000,361,940 | —- | M] () – C:\Users\Max\Documents\Unicorn.png
[2011/10/15 20:38:10 | 000,362,529 | —- | M] () – C:\Users\Max\Documents\Kat pic.png
[2011/10/15 20:34:02 | 000,000,132 | —- | M] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/14 11:13:19 | 1103,993,690 | —- | M] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).wav
[2011/10/14 11:13:19 | 000,539,100 | —- | M] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).pkf
[2011/10/13 09:25:53 | 926,137,596 | —- | M] () – C:\Users\Max\Documents\Chemistry October 13th.wav
[2011/10/13 09:25:53 | 000,452,252 | —- | M] () – C:\Users\Max\Documents\Chemistry October 13th.pkf
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/11 14:39:06 | 000,001,113 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/11 14:00:53 | 001,545,878 | —- | C] () – C:\Users\Max\Desktop\tdsskiller.zip
[2011/11/11 13:54:12 | 000,007,598 | —- | C] () – C:\Users\Max\AppData\Local\Resmon.ResmonCfg
[2011/11/10 10:20:33 | 000,448,956 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.pkf
[2011/11/10 10:18:59 | 919,371,004 | —- | C] () – C:\Users\Max\Documents\CHemistry November 11.wav
[2011/11/09 21:54:15 | 001,048,576 | —- | C] () – C:\windows\SysNative\syndata.bin
[2011/11/09 20:06:58 | 000,000,324 | —- | C] () – C:\windows\tasks\HPCeeScheduleForMax.job
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysWow64\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 19:18:53 | 000,000,000 | RHS- | C] () – C:\windows\SysNative\drivers\103C_HP_bNB_ProBook 4530s_Y5336AN_0U_QCNU1141CHT_E636603-001_4A_I167C_SHP_V22.1F_B68SRR F.0A_T110718_W748-0_L409_M4031_J500_7Intel_86A7_92.30_#110303_N10EC8168;168C002B_(XU018UT#ABA)_XMO
BILE_CN10_Z_2A0001D02.MRK
[2011/11/09 13:40:01 | 000,152,233 | —- | C] () – C:\windows\SysNative\drivers\klin.dat
[2011/11/09 13:40:01 | 000,107,177 | —- | C] () – C:\windows\SysNative\drivers\klick.dat
[2011/11/09 13:25:55 | 000,089,448 | —- | C] () – C:\Users\Max\Documents\cc_20111109_132551.reg
[2011/11/09 12:32:53 | 000,549,116 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.pkf
[2011/11/09 12:27:46 | 1124,496,892 | —- | C] () – C:\Users\Max\Documents\Biology Lecture 11.wav
[2011/11/08 23:56:16 | 000,000,000 | —- | C] () – C:\ProgramData\wbVr3TUk.dat
[2011/11/08 16:27:13 | 000,001,028 | —- | C] () – C:\Users\Max\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Workstation.lnk
[2011/11/08 16:25:53 | 000,001,024 | —- | C] () – C:\.rnd
[2011/11/06 21:08:44 | 000,001,198 | —- | C] () – C:\Users\Public\Desktop\Spartan '08 V1.2.0.lnk
[2011/11/05 10:17:53 | 000,000,562 | —- | C] () – C:\Users\Max\Desktop\Fraps.lnk
[2011/11/04 13:14:29 | 005,550,172 | —- | C] () – C:\Users\Max\Documents\che totorial.pkf
[2011/11/04 13:12:21 | 1196,602,876 | —- | C] () – C:\Users\Max\Documents\che totorial.wav
[2011/11/03 09:37:55 | 000,417,468 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.pkf
[2011/11/03 09:37:10 | 854,881,788 | —- | C] () – C:\Users\Max\Documents\Chemistry November 3rd.wav
[2011/11/03 09:27:50 | 000,299,178 | —- | C] () – C:\Users\Max\Documents\marks.pdf
[2011/11/02 10:18:26 | 000,530,332 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.pkf
[2011/11/02 10:17:01 | 1086,019,068 | —- | C] () – C:\Users\Max\Documents\Biology November 2nd.wav
[2011/11/01 12:17:00 | 033,331,996 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.pkf
[2011/11/01 12:15:49 | 1066,628,818 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-90.wav
[2011/11/01 12:03:17 | 001,050,044 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.pkf
[2011/11/01 12:02:26 | 2150,422,524 | —- | C] () – C:\Users\Max\Documents\TBBT November 1st.wav
[2011/11/01 09:00:49 | 004,856,572 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.pkf
[2011/11/01 08:59:39 | 1033,901,564 | —- | C] () – C:\Users\Max\Documents\Chemistry November 1st.wav
[2011/10/31 10:01:17 | 030,071,324 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.pkf
[2011/10/31 09:59:58 | 962,287,314 | —- | C] () – C:\Users\Max\Documents\Chemistry October 31st.wav
[2011/10/31 09:58:04 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th-2.wav
[2011/10/31 09:57:39 | 000,485,180 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.pkf
[2011/10/31 09:57:18 | 993,572,348 | —- | C] () – C:\Users\Max\Documents\Biology October 31st.wav
[2011/10/27 11:16:21 | 1066,623,022 | —- | C] () – C:\Users\Max\Documents\Chemistry October 27th.wav
[2011/10/26 21:14:46 | 006,041,276 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.pkf
[2011/10/26 21:14:04 | 1311,806,972 | —- | C] () – C:\Users\Max\Documents\Chemistry Tutor 26th.wav
[2011/10/26 10:23:09 | 005,064,092 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.pkf
[2011/10/26 10:22:39 | 1082,578,642 | —- | C] () – C:\Users\Max\Documents\Chemistry October 26th.wav
[2011/10/26 09:01:17 | 000,000,997 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2011/10/26 08:57:51 | 000,002,237 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Elements 10.lnk
[2011/10/26 08:57:51 | 000,001,217 | —- | C] () – C:\Users\Public\Desktop\Adobe Premiere Elements 10.lnk
[2011/10/25 19:30:20 | 002,429,826 | —- | C] () – C:\Users\Max\Documents\Cathedral.psd
[2011/10/25 15:46:23 | 000,332,874 | —- | C] () – C:\Users\Max\Documents\Cathedral.jpg
[2011/10/25 13:40:16 | 000,476,572 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.pkf
[2011/10/25 13:39:52 | 975,943,164 | —- | C] () – C:\Users\Max\Documents\Chemistrry October 25th.wav
[2011/10/25 13:38:48 | 000,903,900 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.pkf
[2011/10/25 13:37:33 | 1848,899,068 | —- | C] () – C:\Users\Max\Documents\TTB October 25th.wav
[2011/10/24 10:20:53 | 000,374,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.pkf
[2011/10/24 10:20:20 | 767,129,084 | —- | C] () – C:\Users\Max\Documents\Chemistry October 24th.wav
[2011/10/24 10:20:06 | 000,526,268 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.pkf
[2011/10/24 10:18:26 | 1077,736,956 | —- | C] () – C:\Users\Max\Documents\Biology October 24th.wav
[2011/10/22 12:17:02 | 000,629,436 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.pkf
[2011/10/22 12:16:07 | 1288,992,252 | —- | C] () – C:\Users\Max\Documents\Math Seminar 2 October 22nd.wav
[2011/10/21 21:37:21 | 001,864,604 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.pkf
[2011/10/21 21:34:21 | 3818,616,316 | —- | C] () – C:\Users\Max\Documents\Math Seminar October 21th.wav
[2011/10/20 09:59:45 | 000,503,932 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.pkf
[2011/10/20 09:58:05 | 1031,960,060 | —- | C] () – C:\Users\Max\Documents\Chemistry October 20th.wav
[2011/10/19 10:16:47 | 005,143,868 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.pkf
[2011/10/19 10:15:28 | 1101,297,148 | —- | C] () – C:\Users\Max\Documents\Biology october 19th.wav
[2011/10/18 14:20:51 | 000,768,444 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.pkf
[2011/10/18 14:18:42 | 1573,713,404 | —- | C] () – C:\Users\Max\Documents\TTB October 18th.wav
[2011/10/18 09:13:06 | 000,498,876 | —- | C] () – C:\Users\Max\Documents\Chemistry October 18.pkf
[2011/10/18 09:11:51 | 1021,621,756 | —- | C] () – C:\Users\Max\Documents\Chemistry October 18.wav
[2011/10/17 10:16:34 | 000,458,652 | —- | C] () – C:\Users\Max\Documents\Chemistry October 17th.pkf
[2011/10/17 10:14:57 | 939,226,620 | —- | C] () – C:\Users\Max\Documents\Chemistry October 17th.wav
[2011/10/17 10:13:40 | 000,519,068 | —- | C] () – C:\Users\Max\Documents\Biology October 17th.pkf
[2011/10/17 10:11:43 | 1062,983,164 | —- | C] () – C:\Users\Max\Documents\Biology October 17th.wav
[2011/10/15 20:39:41 | 000,269,496 | —- | C] () – C:\Users\Max\Documents\Unicron 2.png
[2011/10/15 20:39:00 | 000,361,940 | —- | C] () – C:\Users\Max\Documents\Unicorn.png
[2011/10/15 20:38:09 | 000,362,529 | —- | C] () – C:\Users\Max\Documents\Kat pic.png
[2011/10/15 20:30:47 | 000,000,132 | —- | C] () – C:\Users\Max\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/10/14 11:13:19 | 000,539,100 | —- | C] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).pkf
[2011/10/14 10:06:06 | 1103,993,690 | —- | C] () – C:\Users\Max\Documents\Chemistry Oct 11(REDONE).wav
[2011/10/13 09:25:53 | 000,452,252 | —- | C] () – C:\Users\Max\Documents\Chemistry October 13th.pkf
[2011/10/13 09:25:02 | 926,137,596 | —- | C] () – C:\Users\Max\Documents\Chemistry October 13th.wav
[2011/10/06 09:16:51 | 000,017,408 | —- | C] () – C:\Users\Max\AppData\Local\WebpageIcons.db
[2011/09/05 08:57:34 | 000,366,136 | —- | C] () – C:\windows\SysWow64\flcdlmsg.dll
[2011/08/24 14:30:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPLic.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPPassFilter.dll.hpsign
[2011/08/24 13:55:46 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPCrProv.dll.hpsign
[2011/08/24 13:55:30 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApiUI.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPSCEL.dll.hpsign
[2011/08/24 13:53:44 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPFPApi.dll.hpsign
[2011/08/24 13:53:42 | 000,000,256 | R— | C] () – C:\windows\SysWow64\DPClback.dll.hpsign
[2011/08/23 10:10:44 | 000,000,256 | —- | C] () – C:\windows\SysWow64\vcsAPIShared.dll.hpsign
[2011/07/02 21:54:28 | 000,186,460 | -H– | C] () – C:\windows\SysWow64\mlfcache.dat
[2011/06/15 20:03:03 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/14 17:25:49 | 000,000,021 | —- | C] () – C:\windows\SurCode.INI
[2011/05/30 21:58:34 | 000,185,168 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll
[2011/05/30 21:58:34 | 000,000,256 | —- | C] () – C:\windows\SysWow64\PassThroughOTP.dll.hpsign
[2011/05/29 14:23:14 | 000,000,355 | —- | C] () – C:\windows\EReg176.dat
[2011/05/20 07:37:54 | 000,000,105 | —- | C] () – C:\windows\Antidote7.ini
[2011/05/18 16:53:37 | 000,963,116 | —- | C] () – C:\windows\SysWow64\igkrng600.bin
[2011/05/18 16:53:36 | 000,216,876 | —- | C] () – C:\windows\SysWow64\igfcg600m.bin
[2011/05/03 21:17:55 | 000,000,056 | -H– | C] () – C:\windows\SysWow64\ezsidmv.dat
[2011/04/09 17:55:28 | 000,179,261 | —- | C] () – C:\windows\SysWow64\xlive.dll.cat
[2011/04/08 20:00:20 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgchid.sys
[2011/04/08 19:38:38 | 000,025,984 | —- | C] () – C:\windows\snuvcdsm.exe
[2011/04/08 19:38:38 | 000,015,497 | —- | C] () – C:\windows\snp2uvc.ini
[2011/03/03 14:56:41 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbbb.sys
[2011/03/03 14:38:47 | 000,000,178 | —- | C] () – C:\windows\SysWow64\HPPA.ini
[2011/03/03 14:33:15 | 000,003,120 | —- | C] () – C:\windows\SysWow64\drivers\wdgdbdf.sys
[2011/03/03 14:04:33 | 000,794,000 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2011/01/29 18:49:32 | 000,017,232 | —- | C] () – C:\windows\SysWow64\CoHpCasl.exe
[2011/01/26 21:55:20 | 000,145,804 | —- | C] () – C:\windows\SysWow64\igcompkrng600.bin
[2011/01/10 22:03:08 | 086,271,980 | —- | C] () – C:\windows\SysWow64\BioTrustFace.dat
[2009/07/14 00:38:36 | 000,067,584 | –S- | C] () – C:\windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | —- | C] () – C:\windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | —- | C] () – C:\windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | —- | C] () – C:\windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | —- | C] () – C:\windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | —- | C] () – C:\windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/11/08 19:56:01 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\.minecraft
[2011/09/01 14:33:45 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Auslogics
[2011/05/10 08:15:02 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Bioshock2
[2011/05/31 08:37:20 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Bitcoin
[2011/06/13 17:10:44 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/06/06 16:17:10 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\com.adobe.downloadassistant.AdobeDownloadAssistant
[2011/11/09 13:25:09 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DAEMON Tools Lite
[2011/05/03 15:44:26 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DigitalPersona
[2011/09/03 14:23:14 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\DiskAid
[2011/11/11 14:25:39 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Dropbox
[2011/05/20 07:36:30 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Druide
[2011/05/17 19:29:15 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Dwarfs
[2011/11/01 19:43:30 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\fltk.org
[2011/08/26 20:45:09 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Garmin
[2011/05/03 16:28:46 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\IDT
[2011/08/21 21:57:08 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Imprudence
[2011/08/23 23:48:54 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\mkvtoolnix
[2011/10/13 16:35:41 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\MP3toiPodAudioBookConverter
[2011/06/14 17:25:49 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\PACE Anti-Piracy
[2011/07/26 10:50:26 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Pamela
[2011/05/20 21:07:29 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\poclbm
[2011/09/02 16:16:31 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Recordpad
[2011/06/14 17:32:07 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/05/03 15:51:01 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Synaptics
[2011/08/04 13:47:40 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\The Longest Journey
[2011/09/04 21:12:27 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Thinstall
[2011/09/30 19:26:15 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\Ubisoft
[2011/11/10 16:56:42 | 000,000,000 | —D | M] – C:\Users\Max\AppData\Roaming\uTorrent
[2011/10/31 21:19:44 | 000,032,584 | —- | M] () – C:\windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2011/11/08 16:25:53 | 000,001,024 | —- | M] () – C:\.rnd
[2011/09/14 13:41:14 | 000,004,913 | —- | M] () – C:\aaa.class
[2011/09/14 13:31:56 | 000,002,327 | —- | M] () – C:\acz.class
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2011/11/11 14:31:21 | 000,034,054 | —- | M] () – C:\ComboFix.txt
[2011/09/14 14:05:08 | 000,005,353 | —- | M] () – C:\dt.class
[2011/09/14 14:03:34 | 000,004,440 | —- | M] () – C:\em.class
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1028.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1031.txt
[2007/11/07 07:00:40 | 000,010,134 | —- | M] () – C:\eula.1033.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1036.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1040.txt
[2007/11/07 07:00:40 | 000,000,118 | —- | M] () – C:\eula.1041.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.1042.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.2052.txt
[2007/11/07 07:00:40 | 000,017,734 | —- | M] () – C:\eula.3082.txt
[2011/09/14 14:01:06 | 000,001,063 | —- | M] () – C:\fs.class
[2007/11/07 07:00:40 | 000,001,110 | —- | M] () – C:\globdata.ini
[2011/11/11 14:22:53 | 4226,146,304 | -HS- | M] () – C:\hiberfil.sys
[2007/11/07 07:00:40 | 000,000,843 | —- | M] () – C:\install.ini
[2007/11/07 07:44:20 | 000,075,280 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2007/11/07 07:44:20 | 000,090,128 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2007/11/07 07:44:20 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2007/11/07 07:44:20 | 000,094,224 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2007/11/07 07:44:20 | 000,080,400 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2007/11/07 07:44:20 | 000,078,864 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2007/11/07 07:44:20 | 000,074,768 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2007/11/07 07:44:20 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2011/09/10 11:26:58 | 000,000,342 | —- | M] () – C:\items-nofire.txt
[2011/09/14 14:00:32 | 000,001,234 | —- | M] () – C:\l.class
[2011/07/21 15:42:18 | 2239,683,208 | —- | M] () – C:\MVI_0942.MOV
[2011/11/11 14:22:55 | 4226,146,304 | -HS- | M] () – C:\pagefile.sys
[2011/09/14 17:05:50 | 000,000,889 | —- | M] () – C:\recipes-spawner.txt
[2011/10/05 09:04:28 | 000,000,184 | —- | M] () – C:\setup.log
[2011/09/14 16:25:36 | 000,020,426 | —- | M] () – C:\sz.class
[2011/11/09 13:39:47 | 000,001,886 | —- | M] () – C:\TDSSKiller.2.6.16.0_09.11.2011_13.36.25_log.txt
[2011/11/09 13:59:04 | 000,088,878 | —- | M] () – C:\TDSSKiller.2.6.16.0_09.11.2011_13.58.16_log.txt
[2011/11/11 14:05:38 | 000,089,222 | —- | M] () – C:\TDSSKiller.2.6.18.0_11.11.2011_14.05.09_log.txt
[2007/11/07 07:00:40 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2007/11/07 07:09:22 | 001,442,522 | —- | M] () – C:\VC_RED.cab
[2007/11/07 07:12:28 | 000,232,960 | —- | M] () – C:\VC_RED.MSI
[2011/09/14 13:34:42 | 000,003,041 | —- | M] () – C:\xu.class
[2011/09/14 14:41:34 | 000,000,405 | —- | M] () – C:\ZBB.class
[2011/09/14 14:33:12 | 000,000,815 | —- | M] () – C:\ZBM.class
[2011/09/14 14:29:20 | 000,001,087 | —- | M] () – C:\ZBS.class
[2011/09/14 16:23:20 | 000,003,240 | —- | M] () – C:\ZBW.class
[2011/09/14 13:43:58 | 000,004,142 | —- | M] () – C:\zf.class
[2011/09/10 08:16:42 | 000,000,288 | —- | M] () – C:\ZINV.class
[2011/09/14 14:17:58 | 000,000,715 | —- | M] () – C:\ZP250.class
[2011/09/11 22:16:18 | 000,000,985 | —- | M] () – C:\ZRND.class
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/04/16 23:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/05/03 15:52:15 | 000,000,221 | -HS- | M] () – C:\Users\Max\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2011/11/11 13:54:08 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Users\Max\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2009/07/21 14:08:00 | 000,013,021 | —- | M] () – C:\windows\snp2uvc.src
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 979 bytes -> C:\ProgramData\Microsoft:fjShx0za62cdhqPiEGa
@Alternate Data Stream - 1210 bytes -> C:\ProgramData\Microsoft:53T6CuUbnjh9cGmZscbufI
@Alternate Data Stream - 1207 bytes -> C:\Program Files\Common Files\System:kfA4PGra19R2mcTahzOwvsUPu
< End of report >
Extras.txt:
OTL Extras logfile created on: 11/11/2011 3:05:29 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Max\Desktop
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
3.94 Gb Total Physical Memory | 1.80 Gb Available Physical Memory | 45.67% Memory free
7.87 Gb Paging File | 5.72 Gb Available in Paging File | 72.67% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.10 Gb Total Space | 75.68 Gb Free Space | 17.04% Space Free | Partition Type: NTFS
Drive E: | 16.37 Gb Total Space | 2.47 Gb Free Space | 15.10% Space Free | Partition Type: NTFS
Drive F: | 4.98 Gb Total Space | 2.12 Gb Free Space | 42.55% Space Free | Partition Type: FAT32
Computer Name: MAXHP | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{11538652-E5E4-37F1-86D7-418871E45292}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{230D1595-57DA-4933-8C4E-375797EBB7E1}" = Bluetooth Win7 Suite (64)
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26F481C6-8DBE-4F8B-9D8D-715081C23ADE}" = Adobe Premiere Elements 10
"{2DA0E83F-81B5-4C3F-8F36-8AD30CFF67B4}" = HP ProtectTools Security Manager
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{3D8EDF72-13CC-4E51-AAB6-32A20524D2E0}" = HP Power Assistant
"{3DAE9A67-DD8D-4EDB-91F7-7B5132B1864D}" = SmartSound Premiere Elements 10 x64 Plugin
"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{483D5A49-A26B-4CB8-AA2D-0D1811322061}" = HP DayStarter
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4CDE3168-D060-4b7c-BC74-4D8F9BB01AFe}" = Python 3.2.2 (64-bit)
"{51DDB4F9-7FFF-4970-AED4-DB3C22A5C522}" = Corel Graphics - Windows Shell Extension 64 Bit
"{528E2373-AE49-4802-B4A8-326BBFDAD6A0}" = VmciSockets
"{55B52830-024A-443E-AF61-61E1E71AFA1B}" = Device Access Manager for HP ProtectTools
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{76997589-A71A-4651-9956-F2F79972A54D}" = HP HotKey Support
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{83DA38AB-1014-41C2-A3CD-E2B93832A71A}" = HP 3D DriveGuard
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8A0041CD-277C-4C1F-BFE4-7AC508B20B4C}" = Drive Encryption For HP ProtectTools
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{90BF0360-A1DB-4599-A643-95AB90A52C1E}" = Microsoft_VC90_MFCLOC_x86_x64
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{997C9EC4-B53D-479D-81B7-0AEC8D174BA1}" = iTunes
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ACA53F68-B003-4D0E-9C3D-0C4EE09D08A8}" = Privacy Manager for HP ProtectTools
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BFA2D2A7-4FAC-4862-B7A3-960B329C2177}" = Validity Fingerprint Sensor Driver
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{D3A775F2-2674-4452-8D80-1FC1446052EE}" = Face Recognition for HP ProtectTools
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"49CF605F02C7954F4E139D18828DE298CD59217C" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (06/03/2009 2.3.0.0)
"CCleaner" = CCleaner
"HPProtectTools" = HP ProtectTools Security Manager
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"PremElem100" = Adobe Premiere Elements 10
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"_{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW® Graphics Suite X5
"{003BFBBD-6C67-419E-A24D-0DCAFC3A5249}" = tools-freebsd
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{03046EBB-CB7C-4B98-BEFB-690EB955DA22}" = HP Setup
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0D94F75A-0EA6-4951-B3AF-B145FA9E05C6}" = VMware Workstation
"{0DEA342C-15CB-4F52-97B6-06A9C4B9C06F}" = SDK
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{11C9A461-DD9D-4C71-85A4-6DCE7F99CC44}" = HP Wallpaper
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{190A7D93-3823-439C-91B9-ADCE3EC2A6A2}" = ArcSoft Webcam Sharing Manager
"{197597A7-AD33-4898-9D8E-73066818B464}" = tools-netware
"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F77C418-2C90-459C-BD33-B56A4182B9FA}" = System Requirements Lab CYRI
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{22D3A614-482C-444A-932C-9DA1B8ECDFD2}" = Elements 10 Organizer
"{24D9A3E0-D086-4B62-AF93-63CF6B05CB48}" = CorelDRAW Graphics Suite X5 - Custom Data
"{260ED378-2B8C-4831-ADAE-D0712D119AC5}" = CorelDRAW Graphics Suite X5 - VSTA
"{26604C7E-A313-4D12-867F-7C6E7820BE4C}" = JMicron Flash Media Controller Driver
"{26945917-E053-45F6-AF98-309730CFC318}" = Visual Basic for Applications ® Core
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 26
"{28FE073B-1230-4BF6-830C-7434FD0C0069}" = HP Software Framework
"{299C0434-4F4E-341F-A916-4E07AEB35E79}" = Microsoft Visual Studio Tools for Applications 2.0 Runtime
"{2A9A40C7-6670-4D5F-8F41-D12E2E08B48B}" = Star Wars®: Knights of the Old Republic ™
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{340C0246-975B-420F-8ADD-DEA69B16FDEE}" = Adobe Premiere Elements 10 Content 1
"{344A1AA2-AC8E-4741-BDB0-65B68FDA883C}" = HP SoftPaq Download Manager
"{3472C84E-2FD0-439F-B27F-C290C1E4CD8B}" = CorelDRAW Graphics Suite X5 - Filters
"{399C37FB-08AF-493B-BFED-20FBD85EDF7F}" = HP Webcam Driver
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45B92257-603B-49C1-943F-EC27367D7CE4}" = Chemistry Add-in for Word
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4F29521F-7338-4D15-8691-8FEEB987780C}" = Adobe Premiere Elements 10 HD Content 3
"{510D2239-6C2E-457B-9590-485EC552D94D}" = Garmin USB Drivers
"{51C7AD07-C3F6-4635-8E8A-231306D810FE}" = Cisco LEAP Module
"{531000B3-DBEE-4115-BBF3-DA48B67C053F}" = HP Software Setup
"{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"{54B8F4A1-02B0-4D32-8F37-925526C0EEC6}" = CorelDRAW Graphics Suite X5 - Connect
"{54C65FE7-83BD-4A5B-A9B4-41F793C5F241}" = HP System Default Settings
"{56CDB4FE-895F-4E0D-8BB4-9A8D4310898D}" = Antidote HD
"{57400C1E-BC51-4ECE-AD2A-A6096204DDEC}" = CorelDRAW Graphics Suite X5 - VBA
"{59123CCF-FED2-46FF-9293-D1DC80042219}" = CorelDRAW Graphics Suite X5 - Redist
"{5D037ECA-B00A-466F-848C-D21B4DB69DEA}" = Adobe Premiere Elements 10 HD Content 1
"{5D90E53A-BD7C-8F32-9B82-7733D0F0BC8E}" = Adobe Download Assistant
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{62272D4E-78E9-4BAD-B7AA-63072D06AAA9}" = HP Documentation
"{62978C1C-FE2E-4A4E-851D-3EB406C9EBC2}" = CorelDRAW Graphics Suite X5 - Draw
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}" = Cisco EAP-FAST Module
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"{6A3F9D74-BB80-4451-8CA1-4B3A857F1359}" = Apple Application Support
"{6B5E7B4F-64A2-4DEB-B210-0DD92F940A01}" = HP QuickWeb
"{6D6ADF03-B257-4EA5-BBC1-1D145AF8D514}" = File Sanitizer For HP ProtectTools
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.1.0
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7A6B4340-7090-418F-8976-EE9650B35550}" = HP Connection Manager
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8570BEE8-0CA3-4977-9AB1-80ED93F0513C}" = Assassin's Creed II
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8BBB5E4C-3F5E-4C07-BFBE-33B34600783A}" = LogMeIn Hamachi
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{7C5B1ECD-FE93-4FB2-A51A-06451BA49969}" =
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0000-0000-0000000FF1CE}" = Microsoft Office Word 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUS_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.WORD_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUS_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.WORD_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUS_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.WORD_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{9244E956-5939-4B88-930C-0699D4AB2B95}" = CorelDRAW Graphics Suite X5 - WT
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{983F7145-CABF-4EDD-9F3D-E06B2F024BD3}" = CorelDRAW Graphics Suite X5 - FontNav
"{99C7D73D-E201-4D03-B8A4-5EDBA529B505}" = Adobe Premiere Elements 10 Content 3
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C8D1290-0A4C-446C-AD86-0590812660CC}" = Adobe Premiere Elements 10 Content
"{9F06F464-479A-403E-AF92-70CBB8D674A1}" = PRE10STI64Installer
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A129D1F2-CAC4-4AD7-B26D-3C6411B87DCC}" = Psychonauts
"{A1B04B6B-25BB-48AD-8BD9-D31A86E89F3E}" = CorelDRAW Graphics Suite X5 - PHOTO-PAINT
"{A6365256-0FBA-4DCD-88CE-D92A4DC9328E}" = HP ESU for Microsoft Windows 7
"{A66DBCC6-8802-3D15-9FDF-9552742C08B0}" = Google Talk Plugin
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU
"{AB1C87CB-1807-4CF0-B4C2-CEE14C18CDB4}" = tools-solaris
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.1)
"{ADC70B7A-530B-46E3-8384-48D22681A41E}" = Theft Recovery for HP ProtectTools
"{AE0F62A7-A1A2-407F-9F4C-48939BD9AD8D}" = tools-winPre2k
"{AFF7E080-1974-45BF-9310-10DE1A1F5ED0}" = Adobe AIR
"{B001064C-D061-4BAE-9031-416A838D5536}" = Adobe Flash Player 10 ActiveX
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B39177F9-269D-4A9B-82F2-7A48589CCCEF}" = Garmin WebUpdater
"{B399C91E-96F2-4265-9884-1C9A10E9FCF4}" = CorelDRAW Graphics Suite X5
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B6BFCD02-BA0E-41A9-9C9C-6624C4BB475F}" = Corel Graphics - Windows Shell Extension
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel® Identity Protection Technology 1.1.2.0
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C071157F-AB34-4D3F-A0DF-9AC544B3732E}" = Vicon boujou 5.0.2
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C3A32068-8AB1-4327-BB16-BED9C6219DC7}" = Atheros Driver Installation Program
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C9E14402-3631-4182-B377-6B0DFB1C0339}" = QuickTime
"{CA3861BA-1D96-4D66-B577-318E1602C4F3}" = CorelDRAW Graphics Suite X5 - Common
"{CA43FE4F-9FF2-4AD7-88F0-CC3BAC17B226}" = HP Support Assistant
"{CE54DCE1-E00A-4D91-ACB9-A2D916C24051}" = CorelDRAW Graphics Suite X5 - Setup Files
"{D102611A-6466-4101-A51D-51069303AC65}" = tools-linux
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D1CE6204-061A-43B5-830F-6A8A35C4E0C6}" = Adobe Premiere Elements 10 HD Content 2
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D57FC112-312E-4D70-860F-2DB8FB6858F0}" = Adobe Creative Suite 5.5 Master Collection
"{D596EEA2-C6C8-45D3-89DF-FA2DBE99F829}" = Visual Basic for Applications ® Core - English
"{D642FF8D-438D-4545-A1D5-2EDB4BCAE3BA}" = CorelDRAW Graphics Suite X5 - Photozoom Plugin
"{D66A42BA-3747-4628-9CE4-9E7C18C3ED95}" = Adobe Premiere Elements 10 Content 2
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{D7736EE8-AFCE-4735-BBE3-652CDFBBFCA8}_is1" = Imprudence Viewer 1.3.2
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DE6CBC04-8673-4DBA-BA81-07F1639CEB5F}" = CorelDRAW Graphics Suite X5 - IPM
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics Disk Defrag
"{E34C6AA4-AE8E-4677-912A-92FC2E039DD9}" = CorelDRAW Graphics Suite X5 - EN
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}" = Cisco PEAP Module
"{EDB98D5A-A6FB-425C-BFB7-51A0924B762D}" = CorelDRAW Graphics Suite X5 - Capture
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote
"{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}" = Realtek Ethernet Controller All-In-One Windows Driver
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE4B83DE-85CF-4DE5-90CE-A2735A0E1F21}" = CorelDRAW Graphics Suite X5 - VideoBrowser
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFD9383C-01D5-4897-A954-43AF599AED30}" = tools-windows
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Premiere Elements 10 Content" = Adobe Premiere Elements 10 Content
"Adobe Premiere Elements 10 Content 1" = Adobe Premiere Elements 10 Content 1
"Adobe Premiere Elements 10 Content 2" = Adobe Premiere Elements 10 Content 2
"Adobe Premiere Elements 10 Content 3" = Adobe Premiere Elements 10 Content 3
"Adobe Premiere Elements 10 HD Content 1" = Adobe Premiere Elements 10 HD Content 1
"Adobe Premiere Elements 10 HD Content 2" = Adobe Premiere Elements 10 HD Content 2
"Adobe Premiere Elements 10 HD Content 3" = Adobe Premiere Elements 10 HD Content 3
"Bugs Bunny Lost In Time" = Bugs Bunny Lost In Time
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"com.adobe.downloadassistant.AdobeDownloadAssistant" = Adobe Download Assistant
"DAEMON Tools Lite" = DAEMON Tools Lite
"DAEMON Tools Toolbar" = DAEMON Tools Toolbar
"Debut" = Debut Video Capture Software
"DiskAid_is1" = DiskAid 4.5
"DivX Setup.divx.com" = DivX Setup
"DragonNest" = DragonNest
"Driver Genius Professional Edition_is1" = Driver Genius Professional Edition
"ESET Online Scanner" = ESET Online Scanner v3
"Fraps" = Fraps (remove only)
"Half-Life Decay PC_is1" = Half-Life Decay PC 1.0
"InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}" = Renesas Electronics USB 3.0 Host Controller Driver
"InstallShield_{ADC70B7A-530B-46E3-8384-48D22681A41E}" = Theft Recovery for HP ProtectTools
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallWIX_{66F1F013-008F-4875-B283-5A814B820347}" = Kaspersky Internet Security 2011
"LiveMath Plug-In & ActiveX" = LiveMath Plug-In & ActiveX 3.5.9 [U18] - August 2008
"LogMeIn Hamachi" = LogMeIn Hamachi
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Messenger Plus!" = Messenger Plus! 5
"Mozilla Firefox 7.0.1 (x86 en-GB)" = Mozilla Firefox 7.0.1 (x86 en-GB)
"My HP Game Console" = HP Game Console
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"Office14.WORD" = Microsoft Word 2010
"pepakura_viewer3en" = Pepakura Viewer 3
"Privoxy" = Privoxy (remove only)
"Recordpad" = RecordPad Sound Recorder
"Spartan '08 V1.2.0" = Spartan '08 V1.2.0
"Steam App 105600" = Terraria
"Steam App 12900" = Audiosurf
"Steam App 211" = Source SDK
"Steam App 218" = Source SDK Base 2007
"Steam App 220" = Half-Life 2
"Steam App 400" = Portal
"Steam App 40800" = Super Meat Boy
"Steam App 420" = Half-Life 2: Episode Two
"Steam App 440" = Team Fortress 2
"Steam App 5" = Dedicated Server
"Steam App 500" = Left 4 Dead
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Steam App 629" = Portal 2 Authoring Tools - Beta
"Steam App 630" = Alien Swarm
"Steam App 70" = Half-Life
"The Longest Journey_is1" = The Longest Journey
"uTorrent" = µTorrent
"Vampire: The Masquerade - Bloodlines" = Vampire: The Masquerade - Bloodlines
"VIP Access SDK" = VIP Access SDK ([removed])
"VLC media player" = VLC media player 1.1.11
"VMware_Workstation" = VMware Workstation
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite_Wave3" = Windows Live Essentials
"WT087330" = Bounce Symphony
"WT087361" = FATE
"WT087380" = John Deere Drive Green
"WT087394" = Penguins!
"WT087396" = Polar Bowler
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087480" = Insaniquarium Deluxe
"WT087485" = Jewel Quest II
"WT087490" = Jewel Quest Solitaire
"WT087501" = Plants vs. Zombies
"WT087510" = Slingo Deluxe
"WT087513" = Virtual Villagers - The Secret City
"WT087519" = Wedding Dash
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089303" = Build-a-Lot - The Elizabethan Era
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
========== Last 10 Event Log Errors ==========
Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!
< End of report >
Appologies again for running ComboFix. I promise to follow all instructions from here on out.
If you can help, thanks.