bluejam
Topic Starter
Hi,
Having issues with a browser re-direct. It edited my Host file and made it hidden then read only. It also keep updating the proxy address for internet settings every so often. Even when i've fix both of these searches in google it keep re-directing. Sometimes to this address: hxxp://www.kisses-search.net
OTL details below - massive thanks in advance…
OTL logfile created on: 11/20/2011 7:09:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\steve\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.99 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 23.64% Memory free
7.98 Gb Paging File | 4.20 Gb Available in Paging File | 52.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.96 Gb Total Space | 80.21 Gb Free Space | 11.64% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 393.06 Gb Free Space | 42.20% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 233.28 Gb Free Space | 50.09% Space Free | Partition Type: NTFS
Drive F: | 5.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 7.28 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 465.76 Gb Total Space | 9.29 Gb Free Space | 2.00% Space Free | Partition Type: NTFS
Computer Name: DELLXPS | User Name: steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\steve\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
PRC - C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
PRC - C:\Users\steve\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\Evernote\Evernote3.5\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
PRC - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
PRC - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libglesv2.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libegl.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Desura\bin\cef_desura.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Desura\bin\wxmsw290u_vc_desura.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libpcre.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\401d4cd2a06122a32cf094d541dcdd63\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\4ac62cbbdc0e405f1756166dc80edd09\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6afe3a43d112ed5356d73468c5c44045\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\SysWOW64\f5.exe ()
MOD - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\758e0ce53c80a7ad7cf76a4910d27762\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\6b8b76b26be7d7f4c3d1cb644811a2ef\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\c744f0f95227e75796b8689801740d4b\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\935ac020241e59cab3287d5eb38c592d\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f92c882fd4e7005c005e208daa04c28d\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\fdeec42fa02f3d789c42be2e33b130eb\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\5025c0c5e7134226b2fc0c4bdabf67ef\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3060dfcdecbeb8ee65077fb29b217c3d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4be2653d1c9804d2ff6e6b66d22764e1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\500ddd904b1099f95552a81b54223b7f\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f58ab951b57c8526430486dcf7ee38fd\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Windows\SysWOW64\msjetoledb40.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\ioncube_loader_win_5.2.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\libmysql.dll ()
MOD - C:\Program Files (x86)\Mindjet\MindManager 8\zlib.dll ()
MOD - C:\Program Files (x86)\CyberLink\Shared Files\richvideops.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvcPS.dll ()
MOD - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\bin\zlib1.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (Serviio) – C:\Program Files (x86)\Serviio\bin\ServiioService.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (KMService) – C:\Windows\SysWOW64\srvany.exe ()
SRV - (Hauppauge WinTV Extender) – C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
SRV - (HauppaugeTVServer) – C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (dsl-fs-sync) – C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (VMCService) – C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsl-db) – C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (EraserSvc11120) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Apache2.2) – C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (TVECapSvc) TVEnhance Background Capture Service (TBCS) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
SRV - (TVESched) TVEnhance Task Scheduler (TTS)) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
SRV - (LiveUpdate) – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (LVUVC64) Logitech QuickCam Pro 9000(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (Ext2Fsd) – C:\Windows\SysNative\drivers\ext2fsd.sys (www.ext2fsd.com)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ewusbnet) – C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (Packet) – C:\Windows\SysNative\drivers\packet.sys (SingleClick Systems)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (SRTSPL) – C:\Windows\SysNative\drivers\srtspl64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (Ext2fs) – C:\Windows\SysNative\drivers\ext2fs.sys (Stephan Schreiber)
DRV:64bit: - (IfsMount) – C:\Windows\SysNative\drivers\ifsmount.sys (Stephan Schreiber)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ZTEusbser6k) – C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) – C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) – C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\ENG64.SYS (Symantec Corporation)
DRV - (RivaTuner64) – C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (Packet) – C:\Windows\SysWOW64\drivers\packet.sys (SingleClick Systems)
DRV - (SRTSPL) – C:\Windows\SysWOW64\drivers\srtspl64.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\SysWOW64\drivers\srtspx64.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\SysWOW64\drivers\srtsp64.sys (Symantec Corporation)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) – C:\Program Files (x86)\CyberLink\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (ASPI32) – C:\Windows\SysWow64\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/USCON/19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {bcd47b5a-43be-433f-9051-7ce2cdf94ac0}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.608
FF - prefs.js..extensions.enabledItems: {F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}:1.0.1
FF - prefs.js..extensions.enabledItems: {ec268e28-22c6-4a6c-ac22-635cabee283c}:1.0.1
FF - prefs.js..extensions.enabledItems: {AA6F0803-145A-4200-8E5E-68898D02B5B3}:1.1.5
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: TFToolbarX@torrent-finder:1.2.5
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.backup.ftp: "[removed]"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "[removed]"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "[removed]"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "[removed]"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "[removed]"
FF - prefs.js..network.proxy.ssl_port: 3124
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 49192
FF - prefs.js..network.proxy.type: 1
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/01 22:05:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/16 15:02:00 | 000,000,000 | —D | M]
[2010/04/15 10:01:05 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Extensions
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Right-Click-Link) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{AA6F0803-145A-4200-8E5E-68898D02B5B3}
[2010/07/24 14:12:31 | 000,000,000 | —D | M] (ActiveInbox for Gmail and Google Apps) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{bcd47b5a-43be-433f-9051-7ce2cdf94ac0}
[2010/04/10 11:15:18 | 000,000,000 | —D | M] (Web Developer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/10/03 15:20:38 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/30 20:23:22 | 000,000,000 | —D | M] ("Tab Mix Plus") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Plain Text Links) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] ("OpenDownload") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}
[2010/06/09 09:54:31 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/06/30 20:23:19 | 000,000,000 | —D | M] (Save File to) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/22 22:47:14 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (Torrent Finder Toolbar) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\TFToolbarX@torrent-finder
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (URL Suffix) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\urlsuffix@mozilla
[2010/01/22 08:07:10 | 000,001,606 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\amazondotcom.xml
[2009/01/11 14:21:06 | 000,001,595 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\ebay.xml
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/16 09:48:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/28 19:31:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/06 08:23:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/13 16:41:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 05:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/06/26 15:20:28 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/02 03:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/04/02 03:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/04/02 03:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/04/02 03:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Orbit Downloader (Disabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\content\locales\locale_
CHR - Extension: Smartr Inbox for Gmail = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\gakklmehjhhdfjjgnmpkjoemjmeomnli\0.61_1\
CHR - Extension: Add LinkedIn profile to JobAdder = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcminoiojbaeabfpccladipipdelebcl\1.1.5_0\
CHR - Extension: Poppit = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2011/11/20 09:31:09 | 000,000,709 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [msconfig.exe] C:\Users\steve\AppData\Roaming\Microsoft\System\Services\msconfig.exe ()
O4 - HKLM..\Run: [PCMAgent] C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [Desura] C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
O4 - HKCU..\Run: [Evernote] C:\Program Files (x86)\Evernote\Evernote3.5\evernote.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B6295B3-E3F9-4600-8AC0-9F35CE4C4E0E}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD173155-D01E-43CB-839C-81F4E538B3C6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\x-excid - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/30 21:06:55 | 000,000,033 | -HS- | M] () - D:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2011/09/06 18:15:22 | 000,000,051 | R— | M] () - F:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2010/11/10 02:57:14 | 000,000,075 | R— | M] () - G:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Setup.exe – [2011/05/31 20:06:52 | 000,355,920 | R— | M] (Valve Corporation)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck msln)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\Windows\SysWow64\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/20 12:50:00 | 000,067,632 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:17 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/11/20 11:36:17 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/11/20 11:36:17 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/11/20 11:34:53 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/11/20 11:34:52 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/11/20 11:06:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/20 11:01:36 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/11/20 11:01:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/11/20 09:22:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/11/20 09:21:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/20 09:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/20 09:01:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\C6EA0
[2011/11/20 09:00:49 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\2de42b37
[2011/11/20 09:00:37 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/11/20 09:00:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\LP
[2011/11/20 09:00:28 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2011/11/16 22:55:47 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{49606A9B-349D-4D49-B907-53E1ED5C5863}
[2011/11/16 22:55:33 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{7378F475-52C8-4712-9A2C-6E10F6B8B57A}
[2011/11/16 20:36:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/11/16 20:32:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/11/14 20:03:53 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{9A0CCF61-B2D5-4C46-9BF1-AD09E4B3490D}
[2011/11/14 20:03:42 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BE0567DA-DF9B-4BA1-A725-92F9DCA0A2B5}
[2011/11/11 17:51:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/08 23:07:30 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BB8CA1A7-50B6-4E11-B701-03194D1C673C}
[2011/11/08 23:07:18 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{DE729AC6-5163-45FA-BFA2-2A9C79525B33}
[2011/11/06 21:46:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Activision
[2011/11/02 20:11:57 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{91FF9FFD-739F-432E-95AA-7AA40E82F34B}
[2011/11/02 20:11:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{6793D855-B64A-4796-88F6-71BE88D457DF}
[2011/10/30 08:32:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/10/23 14:11:17 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{27A19C73-7241-455B-8631-64BE0E74CDF9}
[2011/10/23 14:11:05 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{A6618503-815F-4392-91BA-0351FDB7A91B}
[2010/09/13 15:47:15 | 000,109,248 | —- | C] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\MSWINSCK.OCX
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/20 18:54:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000UA.job
[2011/11/20 18:49:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 13:49:01 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 12:50:00 | 000,067,632 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:38 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:17:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 11:17:02 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/11/20 09:54:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000Core.job
[2011/11/20 09:31:09 | 000,000,709 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/20 09:22:51 | 000,001,288 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | M] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | M] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/11/20 08:46:17 | 000,000,110 | —- | M] () – C:\Users\steve\Documents\ax_files.xml
[2011/11/20 08:46:02 | 000,001,181 | —- | M] () – C:\Users\Public\Desktop\Alcohol 120%.lnk
[2011/11/20 08:35:19 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/20 08:35:19 | 000,630,928 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/20 08:35:19 | 000,111,052 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/16 21:04:36 | 000,218,332 | -H– | M] () – C:\Windows\SysWow64\mlfcache.dat
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/20 11:36:38 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 09:22:51 | 000,001,288 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | C] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | C] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/09/16 19:40:41 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2011/05/05 02:28:10 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/05/03 22:05:39 | 000,218,332 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/03/18 04:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/02/13 20:28:42 | 000,103,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/02/13 20:28:38 | 000,669,184 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2011/02/13 20:28:38 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/11/30 17:55:23 | 000,007,168 | —- | C] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/06 15:52:32 | 000,000,917 | —- | C] () – C:\Windows\SysWow64\CLWatson.ini
[2010/10/25 21:44:19 | 000,005,015 | —- | C] () – C:\Windows\HCWPNP.INI
[2010/10/14 23:16:43 | 000,237,568 | —- | C] () – C:\Windows\SysWow64\rmc_rtspdl.dll
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/10/04 09:09:28 | 000,000,135 | —- | C] () – C:\Windows\ODBC.INI
[2010/10/04 09:09:27 | 000,000,209 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/10/04 09:09:00 | 000,142,337 | —- | C] () – C:\Windows\SysWow64\Wait.exe
[2010/09/29 09:50:23 | 000,193,024 | —- | C] () – C:\Windows\SysWow64\f5.exe
[2010/09/18 16:14:54 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/08/04 09:11:56 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/08/03 22:50:38 | 000,000,204 | —- | C] () – C:\Windows\MYOBP.INI
[2010/08/03 22:50:38 | 000,000,039 | —- | C] () – C:\Windows\MYOB.INI
[2010/08/03 22:49:57 | 000,000,663 | —- | C] () – C:\Windows\openrda.ini
[2010/08/03 22:49:44 | 000,000,000 | —- | C] () – C:\Windows\drvxl32.INI
[2010/08/03 22:49:43 | 000,000,000 | —- | C] () – C:\Windows\drvwd32.INI
[2010/07/03 13:41:59 | 000,007,622 | —- | C] () – C:\Users\steve\AppData\Local\Resmon.ResmonCfg
[2010/06/12 15:31:36 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2010/05/29 17:15:16 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/05/26 17:17:46 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2010/04/12 19:55:59 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/03/25 12:47:52 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2010/03/25 12:47:52 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2010/03/25 12:47:52 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2010/02/21 05:48:22 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/01/25 12:58:06 | 000,462,848 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/08/16 11:08:36 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/07/14 16:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/16 14:25:02 | 000,121,512 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/06/11 08:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/29 16:52:26 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 16:47:06 | 000,761,856 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2007/11/15 06:37:26 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2007/02/05 21:05:26 | 000,000,038 | —- | C] () – C:\Windows\AviSplitter.INI
[2006/05/05 19:26:00 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\ctreestd.dll
[2000/01/31 09:02:00 | 000,047,104 | —- | C] () – C:\Windows\SysWow64\Wh2Robo.dll
========== LOP Check ==========
[2011/11/20 18:53:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/07/02 11:39:08 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/24 10:34:13 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\DAEMON Tools Pro
[2011/08/22 20:04:19 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\FileZilla
[2010/06/26 15:20:49 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit
[2010/06/29 20:21:43 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit Software
[2011/11/20 09:00:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2010/04/10 10:34:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GlobalSCAPE
[2011/05/08 10:37:26 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GrabPro
[2010/08/04 09:10:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\HandBrake
[2010/04/11 21:37:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ImgBurn
[2010/04/09 09:28:33 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Leadertech
[2011/05/01 12:54:32 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ManyCam
[2011/06/04 09:43:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Orbit
[2011/03/06 11:05:45 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PCDr
[2010/11/06 15:55:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PowerCinema
[2010/10/14 23:29:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ProgSense
[2011/10/09 20:37:54 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\redsn0w
[2010/10/13 21:02:07 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\TeraCopy
[2011/06/04 13:47:39 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Unity
[2011/11/20 19:16:12 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\uTorrent
[2011/05/04 21:24:38 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Vodafone
[2010/04/07 23:46:35 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Win7codecs
[2010/04/10 11:14:44 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Windows Live Writer
[2011/06/04 15:51:56 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Xilisoft
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 16:08:49 | 000,032,402 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/27 11:57:21 | 000,001,024 | —- | M] () – C:\.rnd
[2011/06/14 22:09:14 | 000,000,000 | —- | M] () – C:\10.1.19.109
[2010/07/31 22:20:31 | 000,000,165 | —- | M] () – C:\62P3DTNV.dat
[2010/03/26 04:16:22 | 000,004,889 | RH– | M] () – C:\dell.sdr
[2010/10/25 21:32:46 | 000,297,443 | —- | M] () – C:\hcwclear.txt
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/04/27 08:40:07 | 000,001,821 | —- | M] () – C:\index.html
[2010/10/25 21:44:52 | 000,001,203 | —- | M] () – C:\install.log
[1995/04/27 00:33:10 | 000,146,976 | —- | M] (Microsoft Corporation) – C:\Mfcoleui.dll
[2011/11/20 11:16:55 | 4285,517,824 | -HS- | M] () – C:\pagefile.sys
[2011/11/20 09:55:27 | 000,087,720 | —- | M] () – C:\TDSSKiller.2.6.19.0_20.11.2011_09.54.30_log.txt
[2011/08/26 09:07:03 | 000,000,222 | —- | M] () – C:\test.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/09/13 14:53:20 | 000,109,248 | —- | M] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\Microsoft\MSWINSCK.OCX
< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/06 22:07:04 | 000,000,221 | -HS- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/26 15:20:50 | 000,000,200 | —- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url
< %USERPROFILE%\Desktop\*.exe >
[2011/07/02 10:38:06 | 1463,636,243 | —- | M] () – C:\Users\steve\Desktop\Adobe Premiere Elements 9.exe
[2011/08/21 11:50:48 | 000,483,328 | —- | M] (Simon Tatham) – C:\Users\steve\Desktop\putty.exe
[2010/08/29 08:59:58 | 000,163,840 | —- | M] () – C:\Users\steve\Desktop\ts-koe.exe
[2003/04/04 11:51:12 | 000,073,728 | —- | M] (eXtalia EXP) – C:\Users\steve\Desktop\ts203.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2010/05/11 21:19:20 | 000,014,683 | —- | M] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝
[2010/05/11 21:19:20 | 000,014,683 | —- | C] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝
========== Alternate Data Streams ==========
@Alternate Data Stream - 160 bytes -> C:\Users\steve\pool_stamp_ivy.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 160 bytes -> C:\Users\steve\Fine_back.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >
Having issues with a browser re-direct. It edited my Host file and made it hidden then read only. It also keep updating the proxy address for internet settings every so often. Even when i've fix both of these searches in google it keep re-directing. Sometimes to this address: hxxp://www.kisses-search.net
OTL details below - massive thanks in advance…
OTL logfile created on: 11/20/2011 7:09:11 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\steve\Downloads
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: Australia | Language: ENA | Date Format: d/MM/yyyy
3.99 Gb Total Physical Memory | 0.94 Gb Available Physical Memory | 23.64% Memory free
7.98 Gb Paging File | 4.20 Gb Available in Paging File | 52.63% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 688.96 Gb Total Space | 80.21 Gb Free Space | 11.64% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 393.06 Gb Free Space | 42.20% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 233.28 Gb Free Space | 50.09% Space Free | Partition Type: NTFS
Drive F: | 5.49 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive G: | 7.28 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: CDFS
Drive H: | 465.76 Gb Total Space | 9.29 Gb Free Space | 2.00% Space Free | Partition Type: NTFS
Computer Name: DELLXPS | User Name: steve | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\steve\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
PRC - C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
PRC - C:\Users\steve\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\Evernote\Evernote3.5\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
PRC - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
PRC - C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
PRC - C:\Program Files (x86)\WinTV\WinTV7\WinTVTray.exe (Hauppauge Computer Works, Inc.)
PRC - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
PRC - C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe (Trend Micro Inc.)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
PRC - C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
PRC - C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
PRC - C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
PRC - C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
PRC - C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
PRC - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
PRC - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libglesv2.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\libegl.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avutil-51.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avformat-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\avcodec-53.dll ()
MOD - C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files (x86)\Desura\bin\cef_desura.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Desura\bin\avutil-51.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Desura\bin\wxmsw290u_vc_desura.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libtidy.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libxml2.dll ()
MOD - C:\Program Files (x86)\Evernote\Evernote\libpcre.dll ()
MOD - C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\401d4cd2a06122a32cf094d541dcdd63\Microsoft.VisualBasic.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\4ac62cbbdc0e405f1756166dc80edd09\System.Web.Services.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\6afe3a43d112ed5356d73468c5c44045\System.Runtime.Remoting.ni.dll ()
MOD - C:\Windows\SysWOW64\f5.exe ()
MOD - C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\758e0ce53c80a7ad7cf76a4910d27762\System.Management.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\6b8b76b26be7d7f4c3d1cb644811a2ef\System.ServiceProcess.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\c744f0f95227e75796b8689801740d4b\System.Transactions.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\935ac020241e59cab3287d5eb38c592d\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f92c882fd4e7005c005e208daa04c28d\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\fdeec42fa02f3d789c42be2e33b130eb\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Security\5025c0c5e7134226b2fc0c4bdabf67ef\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\3060dfcdecbeb8ee65077fb29b217c3d\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\4be2653d1c9804d2ff6e6b66d22764e1\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\500ddd904b1099f95552a81b54223b7f\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\f58ab951b57c8526430486dcf7ee38fd\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\zlib1.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STRegistry.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STPE.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STNLS.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\STFiles.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Local Backup\libxml2.dll ()
MOD - C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServerps.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbShared.XmlSerializers.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\SdbUI.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\BalloonWindow.dll ()
MOD - C:\Program Files (x86)\Dell DataSafe Online\CppUtils.dll ()
MOD - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe ()
MOD - C:\Windows\SysWOW64\msjetoledb40.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\ioncube_loader_win_5.2.dll ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\libmysql.dll ()
MOD - C:\Program Files (x86)\Mindjet\MindManager 8\zlib.dll ()
MOD - C:\Program Files (x86)\CyberLink\Shared Files\richvideops.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLSchMgr.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLTinyDB.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapEngine.dll ()
MOD - C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\CLCapSvcps.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMediaLibrary.dll ()
MOD - C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvcPS.dll ()
MOD - C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
MOD - C:\Program Files (x86)\Common Files\Dell\apache\bin\zlib1.dll ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (Desura Install Service) – C:\Program Files (x86)\Common Files\Desura\desura_service.exe (Desura Pty Ltd)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (LMIMaint) – C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe (LogMeIn, Inc.)
SRV - (LMIGuardianSvc) – C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (Serviio) – C:\Program Files (x86)\Serviio\bin\ServiioService.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (LogMeIn) – C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe (LogMeIn, Inc.)
SRV - (AdobeActiveFileMonitor9.0) – C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE (SoftThinks SAS)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (KMService) – C:\Windows\SysWOW64\srvany.exe ()
SRV - (Hauppauge WinTV Extender) – C:\Program Files (x86)\WinTV\Extend\WinTVExtender.exe (Hauppauge Computer Works, Inc)
SRV - (HauppaugeTVServer) – C:\Program Files (x86)\WinTV\TVServer\HauppaugeTVServer.exe (Hauppauge Computer Works)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (GoToAssist) – C:\Program Files (x86)\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (StarWindServiceAE) – C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe (StarWind Software)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (dsl-fs-sync) – C:\Program Files (x86)\Common Files\Dell\Remote Access File Sync Service\dsl_fs_sync.exe (SingleClick Systems)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (VMCService) – C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (dsl-db) – C:\Program Files (x86)\Common Files\Dell\MySQL\bin\mysqld.exe ()
SRV - (IAANTMON) Intel® – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Symantec AntiVirus) – C:\Program Files (x86)\Symantec AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (DefWatch) – C:\Program Files (x86)\Symantec AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (EraserSvc11120) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccEvtMgr) – C:\Program Files (x86)\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (SBSDWSCService) – C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (Apache2.2) – C:\Program Files (x86)\Common Files\Dell\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (TVECapSvc) TVEnhance Background Capture Service (TBCS) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVECapSvc.exe ()
SRV - (TVESched) TVEnhance Task Scheduler (TTS)) – C:\Program Files (x86)\CyberLink\TV Enhance\Kernel\TV\TVESched.exe ()
SRV - (LiveUpdate) – C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (LMIRfsClientNP) – C:\Windows\SysNative\LMIRfsClientNP.dll (LogMeIn, Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (sptd) – C:\Windows\SysNative\drivers\sptd.sys ()
DRV:64bit: - (SymEvent) – C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (PxHlpa64) – C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (HCW85BDA) – C:\Windows\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (ElbyCDIO) – C:\Windows\SysNative\drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\drivers\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (LVUVC64) Logitech QuickCam Pro 9000(UVC) – C:\Windows\SysNative\drivers\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\drivers\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (LVPr2Mon) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (LVPr2M64) – C:\Windows\SysNative\drivers\LVPr2M64.sys ()
DRV:64bit: - (VClone) – C:\Windows\SysNative\drivers\VClone.sys (Elaborate Bytes AG)
DRV:64bit: - (Ext2Fsd) – C:\Windows\SysNative\drivers\ext2fsd.sys (www.ext2fsd.com)
DRV:64bit: - (JRAID) – C:\Windows\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ewusbnet) – C:\Windows\SysNative\drivers\ewusbnet.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (NVHDA) – C:\Windows\SysNative\drivers\nvhda64v.sys (NVIDIA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (Packet) – C:\Windows\SysNative\drivers\packet.sys (SingleClick Systems)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (hwdatacard) – C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (SRTSPL) – C:\Windows\SysNative\drivers\srtspl64.sys (Symantec Corporation)
DRV:64bit: - (SRTSPX) – C:\Windows\SysNative\drivers\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) – C:\Windows\SysNative\drivers\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (Ext2fs) – C:\Windows\SysNative\drivers\ext2fs.sys (Stephan Schreiber)
DRV:64bit: - (IfsMount) – C:\Windows\SysNative\drivers\ifsmount.sys (Stephan Schreiber)
DRV:64bit: - (LMIRfsDriver) – C:\Windows\SysNative\drivers\LMIRfsDriver.sys (LogMeIn, Inc.)
DRV:64bit: - (lmimirr) – C:\Windows\SysNative\drivers\lmimirr.sys (LogMeIn, Inc.)
DRV:64bit: - (ZTEusbser6k) – C:\Windows\SysNative\drivers\ZTEusbser6k.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbnmea) – C:\Windows\SysNative\drivers\ZTEusbnmea.sys (ZTE Incorporated)
DRV:64bit: - (ZTEusbmdm6k) – C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys (ZTE Incorporated)
DRV:64bit: - (NPF) – C:\Windows\SysNative\drivers\npf.sys (CACE Technologies)
DRV:64bit: - (RimUsb) – C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\drivers\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (lvpepf64) – C:\Windows\SysNative\drivers\lv302a64.sys (Logitech Inc.)
DRV:64bit: - (WimFltr) – C:\Windows\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (EraserUtilRebootDrv) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (eeCtrl) – C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVEX15) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\EX64.SYS (Symantec Corporation)
DRV - (NAVENG) – C:\ProgramData\Symantec\Definitions\VirusDefs\20111118.004\ENG64.SYS (Symantec Corporation)
DRV - (RivaTuner64) – C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\Windows\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (Packet) – C:\Windows\SysWOW64\drivers\packet.sys (SingleClick Systems)
DRV - (SRTSPL) – C:\Windows\SysWOW64\drivers\srtspl64.sys (Symantec Corporation)
DRV - (SRTSPX) – C:\Windows\SysWOW64\drivers\srtspx64.sys (Symantec Corporation)
DRV - (SRTSP) – C:\Windows\SysWOW64\drivers\srtsp64.sys (Symantec Corporation)
DRV - (LMIInfo) – C:\Program Files (x86)\LogMeIn\x64\rainfo.sys (LogMeIn, Inc.)
DRV - ({49DE1C67-83F8-4102-99E0-C16DCC7EEC796}) – C:\Program Files (x86)\CyberLink\PlayMovie\000.fcl (Cyberlink Corp.)
DRV - (ASPI32) – C:\Windows\SysWow64\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.jp.msn.com/USCON/19
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com.au/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type;=302398"
FF - prefs.js..browser.startup.homepage: "http://www.google.com.au"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.63
FF - prefs.js..extensions.enabledItems: {bcd47b5a-43be-433f-9051-7ce2cdf94ac0}:[removed]
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.608
FF - prefs.js..extensions.enabledItems: {F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}:1.0.1
FF - prefs.js..extensions.enabledItems: {ec268e28-22c6-4a6c-ac22-635cabee283c}:1.0.1
FF - prefs.js..extensions.enabledItems: {AA6F0803-145A-4200-8E5E-68898D02B5B3}:1.1.5
FF - prefs.js..extensions.enabledItems: [removed]:2.0.2
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: TFToolbarX@torrent-finder:1.2.5
FF - prefs.js..extensions.enabledItems: {c45c406e-ab73-11d8-be73-000a95be3b12}:1.1.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..network.proxy.backup.ftp: "[removed]"
FF - prefs.js..network.proxy.backup.ftp_port: 3128
FF - prefs.js..network.proxy.backup.gopher: "[removed]"
FF - prefs.js..network.proxy.backup.gopher_port: 3128
FF - prefs.js..network.proxy.backup.socks: "[removed]"
FF - prefs.js..network.proxy.backup.socks_port: 3128
FF - prefs.js..network.proxy.backup.ssl: "[removed]"
FF - prefs.js..network.proxy.backup.ssl_port: 3128
FF - prefs.js..network.proxy.ftp: "[removed]"
FF - prefs.js..network.proxy.ftp_port: 3124
FF - prefs.js..network.proxy.gopher: "[removed]"
FF - prefs.js..network.proxy.gopher_port: 3124
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "[removed]"
FF - prefs.js..network.proxy.socks_port: 3124
FF - prefs.js..network.proxy.ssl: "[removed]"
FF - prefs.js..network.proxy.ssl_port: 3124
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 49192
FF - prefs.js..network.proxy.type: 1
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.448: C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\steve\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\steve\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/04/01 22:05:52 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/04/16 15:02:00 | 000,000,000 | —D | M]
[2010/04/15 10:01:05 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Extensions
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Right-Click-Link) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{AA6F0803-145A-4200-8E5E-68898D02B5B3}
[2010/07/24 14:12:31 | 000,000,000 | —D | M] (ActiveInbox for Gmail and Google Apps) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{bcd47b5a-43be-433f-9051-7ce2cdf94ac0}
[2010/04/10 11:15:18 | 000,000,000 | —D | M] (Web Developer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/10/03 15:20:38 | 000,000,000 | —D | M] (Adblock Plus) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/06/30 20:23:22 | 000,000,000 | —D | M] ("Tab Mix Plus") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] (Adobe DLM (powered by getPlus®)) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2010/04/16 20:56:09 | 000,000,000 | —D | M] (Plain Text Links) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}
[2010/04/10 11:15:20 | 000,000,000 | —D | M] ("OpenDownload") – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\{F0B6E3F9-ECD1-40b6-A25F-5C3FF68FB079}
[2010/06/09 09:54:31 | 000,000,000 | —D | M] (LogMeIn, Inc. Remote Access Plugin) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/06/30 20:23:19 | 000,000,000 | —D | M] (Save File to) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/22 22:47:14 | 000,000,000 | —D | M] (Ancestry.com Advanced Image Viewer) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\[removed]
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (Torrent Finder Toolbar) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\TFToolbarX@torrent-finder
[2010/04/10 11:15:10 | 000,000,000 | —D | M] (URL Suffix) – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\extensions\urlsuffix@mozilla
[2010/01/22 08:07:10 | 000,001,606 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\amazondotcom.xml
[2009/01/11 14:21:06 | 000,001,595 | —- | M] () – C:\Users\steve\AppData\Roaming\Mozilla\Firefox\Profiles\yapnzpqt.default\searchplugins\ebay.xml
[2011/10/20 20:39:55 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/04/16 09:48:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/28 19:31:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/06 08:23:15 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/07/13 16:41:53 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 05:52:23 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2010/06/26 15:20:28 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files (x86)\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/04/02 03:56:49 | 000,001,538 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2010/04/02 03:56:50 | 000,000,947 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2010/04/02 03:56:50 | 000,000,769 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2010/04/02 03:56:50 | 000,001,135 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chr
o
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\Win7codecs\rm\browser\plugins\nprpjplug.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\15.0.874.121\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Foxit Reader Plugin for Mozilla (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
CHR - plugin: Orbit Downloader (Disabled) = C:\Users\steve\AppData\Local\Google\Chrome\Application\plugins\nporbit.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.71\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\steve\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.5.7_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\
CHR - Extension: ActiveInbox for Gmail\u2122\u200B = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ddndffgplldhbjpnlgkdihdlfhipagmf\4.0.3.8_0\content\locales\locale_
CHR - Extension: Smartr Inbox for Gmail = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\gakklmehjhhdfjjgnmpkjoemjmeomnli\0.61_1\
CHR - Extension: Add LinkedIn profile to JobAdder = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcminoiojbaeabfpccladipipdelebcl\1.1.5_0\
CHR - Extension: Poppit = C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2011/11/20 09:31:09 | 000,000,709 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (CmjBrowserHelperObject Object) - {6FE6A929-59D1-4763-91AD-29B61CFFB35B} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [LogMeIn GUI] C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe (LogMeIn, Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [RunDLLEntry_EptMon] C:\Windows\SysNative\EptMon64.DLL (Creative Technology Ltd.)
O4:64bit: - HKLM..\Run: [RunDLLEntry_THXCfg] C:\Windows\SysNative\THXCfg64.DLL (Creative Technology Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [autodetect] C:\Windows\SysWOW64\SupportAppXL\AutoDect.exe ()
O4 - HKLM..\Run: [ccApp] C:\Program Files (x86)\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\PowerCinema\Kernel\CLML\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [Dell DataSafe Online] C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe ()
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter File not found
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware (reboot)] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MMReminderService] C:\Program Files (x86)\Mindjet\MindManager 8\MmReminderService.exe (Mindjet)
O4 - HKLM..\Run: [MobileConnect] C:\Program Files (x86)\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone)
O4 - HKLM..\Run: [msconfig.exe] C:\Users\steve\AppData\Roaming\Microsoft\System\Services\msconfig.exe ()
O4 - HKLM..\Run: [PCMAgent] C:\Program Files (x86)\CyberLink\PowerCinema\PCMAgent.exe (CyberLink Corp.)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files (x86)\CyberLink\PlayMovie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [THX Audio Control Panel] C:\Program Files (x86)\Creative\THX TruStudio PC\THXAudioCP\THXAudio.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [TVEService] C:\Program Files (x86)\CyberLink\TV Enhance\TVEService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [vptray] C:\Program Files (x86)\Symantec AntiVirus\VPTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [Desura] C:\Program Files (x86)\Desura\desura.exe (Desura Pty Ltd)
O4 - HKCU..\Run: [Evernote] C:\Program Files (x86)\Evernote\Evernote3.5\evernote.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe (Softthinks)
O4 - HKLM..\RunOnceEx: [ContentMerger] c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\ContentMerger10.exe (Sonic Solutions)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149
O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9 - Extra Button: Send to Mindjet MindManager - {2F72393D-2472-4F82-B600-ED77F354B7FF} - C:\Program Files (x86)\Mindjet\MindManager 8\Mm8InternetExplorer.dll (Mindjet)
O9 - Extra Button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra 'Tools' menuitem : Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll ()
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\steve\Desktop\PartyPoker.lnk File not found
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-31-0.cab (EPUImageControl Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} https://secure.logmein.com/activex/ractrl.cab?lmi=100 (Performance Viewer Activex Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1B6295B3-E3F9-4600-8AC0-9F35CE4C4E0E}: DhcpNameServer = 8.8.8.8
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FD173155-D01E-43CB-839C-81F4E538B3C6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Handler\x-excid - No CLSID value found
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\x-excid {9D6CC632-1337-4a33-9214-2DA092E776F4} - c:\Windows\Downloaded Program Files\mimectl.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\GoToAssist: DllName - (C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/30 21:06:55 | 000,000,033 | -HS- | M] () - D:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2011/09/06 18:15:22 | 000,000,051 | R— | M] () - F:\autorun.inf – [ UDF ]
O32 - AutoRun File - [2010/11/10 02:57:14 | 000,000,075 | R— | M] () - G:\autorun.inf – [ CDFS ]
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb0-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{150eaeb9-73cc-11e0-ba3e-a4badb033177}\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell - "" = AutoRun
O33 - MountPoints2\{c9e5b92c-df3b-11df-a09e-a4badb033177}\Shell\AutoRun\command - "" = J:\Autorun.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\Setup.exe – [2011/05/31 20:06:52 | 000,355,920 | R— | M] (Valve Corporation)
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\setup_vmc_lite.exe /checkApplicationPresence
O34 - HKLM BootExecute: (autocheck msln)
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.i420 - lvcod64.dll (Logitech Inc.)
Drivers32: msacm.ac3filter - C:\Windows\SysWow64\ac3filter.acm ()
Drivers32: msacm.avis - C:\Windows\SysWow64\ff_acm.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - File not found
Drivers32: msacm.lameacm - C:\Windows\SysWow64\lameACM.acm (http://www.mp3dev.org/)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.divx - C:\Windows\SysWow64\divx.dll (DivX, Inc.)
Drivers32: VIDC.FFDS - C:\Windows\SysWow64\ff_vfw.dll ()
Drivers32: vidc.i420 - C:\Windows\SysWow64\lvcodec2.dll (Logitech Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/11/20 12:50:00 | 000,067,632 | —- | C] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:17 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2011/11/20 11:36:17 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2011/11/20 11:36:17 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2011/11/20 11:34:53 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2011/11/20 11:34:52 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2011/11/20 11:06:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/11/20 11:01:36 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2011/11/20 11:01:29 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/11/20 09:22:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2011/11/20 09:22:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2011/11/20 09:21:44 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/11/20 09:21:43 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/11/20 09:01:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\C6EA0
[2011/11/20 09:00:49 | 000,000,000 | -HSD | C] – C:\Users\steve\AppData\Local\2de42b37
[2011/11/20 09:00:37 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/11/20 09:00:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\LP
[2011/11/20 09:00:28 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2011/11/16 22:55:47 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{49606A9B-349D-4D49-B907-53E1ED5C5863}
[2011/11/16 22:55:33 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{7378F475-52C8-4712-9A2C-6E10F6B8B57A}
[2011/11/16 20:36:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2011/11/16 20:32:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2011/11/14 20:03:53 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{9A0CCF61-B2D5-4C46-9BF1-AD09E4B3490D}
[2011/11/14 20:03:42 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BE0567DA-DF9B-4BA1-A725-92F9DCA0A2B5}
[2011/11/11 17:51:57 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2011/11/08 23:07:30 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{BB8CA1A7-50B6-4E11-B701-03194D1C673C}
[2011/11/08 23:07:18 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{DE729AC6-5163-45FA-BFA2-2A9C79525B33}
[2011/11/06 21:46:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\Activision
[2011/11/02 20:11:57 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{91FF9FFD-739F-432E-95AA-7AA40E82F34B}
[2011/11/02 20:11:45 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{6793D855-B64A-4796-88F6-71BE88D457DF}
[2011/10/30 08:32:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
[2011/10/23 14:11:17 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{27A19C73-7241-455B-8631-64BE0E74CDF9}
[2011/10/23 14:11:05 | 000,000,000 | —D | C] – C:\Users\steve\AppData\Local\{A6618503-815F-4392-91BA-0351FDB7A91B}
[2010/09/13 15:47:15 | 000,109,248 | —- | C] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\MSWINSCK.OCX
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/20 18:54:05 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000UA.job
[2011/11/20 18:49:01 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/11/20 13:49:01 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/11/20 12:50:00 | 000,067,632 | —- | M] (Symantec Corporation) – C:\Windows\SysNative\msln.exe
[2011/11/20 11:36:38 | 000,001,785 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:33:12 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/20 11:17:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/11/20 11:17:02 | 000,000,000 | —- | M] () – C:\Windows\SysNative\drivers\lvuvc.hs
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\tasks\SystemToolsDailyTest.job
[2011/11/20 09:54:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-4196817925-3903972391-1900847604-1000Core.job
[2011/11/20 09:31:09 | 000,000,709 | R— | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/11/20 09:22:51 | 000,001,288 | —- | M] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | M] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | M] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/11/20 08:46:17 | 000,000,110 | —- | M] () – C:\Users\steve\Documents\ax_files.xml
[2011/11/20 08:46:02 | 000,001,181 | —- | M] () – C:\Users\Public\Desktop\Alcohol 120%.lnk
[2011/11/20 08:35:19 | 000,730,384 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/20 08:35:19 | 000,630,928 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/11/20 08:35:19 | 000,111,052 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/11/16 21:04:36 | 000,218,332 | -H– | M] () – C:\Windows\SysWow64\mlfcache.dat
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/20 11:36:38 | 000,001,785 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2011/11/20 09:22:51 | 000,001,288 | —- | C] () – C:\Users\steve\Application Data\Microsoft\Internet Explorer\Quick Launch\Spybot - Search & Destroy.lnk
[2011/11/20 09:22:51 | 000,001,264 | —- | C] () – C:\Users\steve\Desktop\Spybot - Search & Destroy.lnk
[2011/11/20 09:21:44 | 000,002,975 | —- | C] () – C:\Users\steve\Desktop\HiJackThis.lnk
[2011/09/16 19:40:41 | 003,596,288 | —- | C] () – C:\Windows\SysWow64\qt-dx331.dll
[2011/05/05 02:28:10 | 000,059,904 | —- | C] () – C:\Windows\SysWow64\OVDecode.dll
[2011/05/03 22:05:39 | 000,218,332 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/03/18 04:51:44 | 000,003,929 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2011/02/13 20:28:42 | 000,103,736 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2011/02/13 20:28:38 | 000,669,184 | —- | C] () – C:\Windows\SysWow64\pbsvc.exe
[2011/02/13 20:28:38 | 000,066,872 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/11/30 17:55:23 | 000,007,168 | —- | C] () – C:\Users\steve\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/06 15:52:32 | 000,000,917 | —- | C] () – C:\Windows\SysWow64\CLWatson.ini
[2010/10/25 21:44:19 | 000,005,015 | —- | C] () – C:\Windows\HCWPNP.INI
[2010/10/14 23:16:43 | 000,237,568 | —- | C] () – C:\Windows\SysWow64\rmc_rtspdl.dll
[2010/10/14 01:36:44 | 000,179,263 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2010/10/04 09:09:28 | 000,000,135 | —- | C] () – C:\Windows\ODBC.INI
[2010/10/04 09:09:27 | 000,000,209 | —- | C] () – C:\Windows\ODBCINST.INI
[2010/10/04 09:09:00 | 000,142,337 | —- | C] () – C:\Windows\SysWow64\Wait.exe
[2010/09/29 09:50:23 | 000,193,024 | —- | C] () – C:\Windows\SysWow64\f5.exe
[2010/09/18 16:14:54 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/08/04 09:11:56 | 000,348,160 | —- | C] () – C:\Windows\SysWow64\cdga.dll
[2010/08/03 22:50:38 | 000,000,204 | —- | C] () – C:\Windows\MYOBP.INI
[2010/08/03 22:50:38 | 000,000,039 | —- | C] () – C:\Windows\MYOB.INI
[2010/08/03 22:49:57 | 000,000,663 | —- | C] () – C:\Windows\openrda.ini
[2010/08/03 22:49:44 | 000,000,000 | —- | C] () – C:\Windows\drvxl32.INI
[2010/08/03 22:49:43 | 000,000,000 | —- | C] () – C:\Windows\drvwd32.INI
[2010/07/03 13:41:59 | 000,007,622 | —- | C] () – C:\Users\steve\AppData\Local\Resmon.ResmonCfg
[2010/06/12 15:31:36 | 000,008,192 | —- | C] () – C:\Windows\SysWow64\srvany.exe
[2010/05/29 17:15:16 | 000,000,000 | —- | C] () – C:\Windows\nsreg.dat
[2010/05/26 17:17:46 | 000,000,000 | —- | C] () – C:\Windows\PowerReg.dat
[2010/04/12 19:55:59 | 000,000,056 | -H– | C] () – C:\Windows\SysWow64\ezsidmv.dat
[2010/03/25 12:47:52 | 000,177,664 | —- | C] () – C:\Windows\SysWow64\APOMngr.DLL
[2010/03/25 12:47:52 | 000,073,728 | —- | C] () – C:\Windows\SysWow64\CmdRtr.DLL
[2010/03/25 12:47:52 | 000,001,264 | —- | C] () – C:\Windows\THXCfg_SP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_HP_APOIM.ini
[2010/03/25 12:47:52 | 000,001,247 | —- | C] () – C:\Windows\THXCfg_APOIM.ini
[2010/02/21 05:48:22 | 000,085,504 | —- | C] () – C:\Windows\SysWow64\ff_vfw.dll
[2010/01/25 12:58:06 | 000,462,848 | —- | C] () – C:\Windows\SysWow64\ractrlkeyhook.dll
[2009/08/16 11:08:36 | 000,178,176 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2009/07/14 16:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/14 13:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 13:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/14 11:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/14 10:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 08:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/16 14:25:02 | 000,121,512 | R— | C] () – C:\ProgramData\DeviceManager.xml.rc4
[2009/06/11 08:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2009/05/29 16:52:26 | 000,180,224 | —- | C] () – C:\Windows\SysWow64\xvidvfw.dll
[2009/05/29 16:47:06 | 000,761,856 | —- | C] () – C:\Windows\SysWow64\xvidcore.dll
[2007/11/15 06:37:26 | 000,053,299 | —- | C] () – C:\Windows\SysWow64\pthreadVC.dll
[2007/02/05 21:05:26 | 000,000,038 | —- | C] () – C:\Windows\AviSplitter.INI
[2006/05/05 19:26:00 | 000,335,872 | —- | C] () – C:\Windows\SysWow64\ctreestd.dll
[2000/01/31 09:02:00 | 000,047,104 | —- | C] () – C:\Windows\SysWow64\Wh2Robo.dll
========== LOP Check ==========
[2011/11/20 18:53:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\BA5C6
[2011/07/02 11:39:08 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/24 10:34:13 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\DAEMON Tools Pro
[2011/08/22 20:04:19 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\FileZilla
[2010/06/26 15:20:49 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit
[2010/06/29 20:21:43 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Foxit Software
[2011/11/20 09:00:28 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GDocsDrive
[2010/04/10 10:34:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GlobalSCAPE
[2011/05/08 10:37:26 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\GrabPro
[2010/08/04 09:10:47 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\HandBrake
[2010/04/11 21:37:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ImgBurn
[2010/04/09 09:28:33 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Leadertech
[2011/05/01 12:54:32 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ManyCam
[2011/06/04 09:43:09 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Orbit
[2011/03/06 11:05:45 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PCDr
[2010/11/06 15:55:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\PowerCinema
[2010/10/14 23:29:25 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\ProgSense
[2011/10/09 20:37:54 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\redsn0w
[2010/10/13 21:02:07 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\TeraCopy
[2011/06/04 13:47:39 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Unity
[2011/11/20 19:16:12 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\uTorrent
[2011/05/04 21:24:38 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Vodafone
[2010/04/07 23:46:35 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Win7codecs
[2010/04/10 11:14:44 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Windows Live Writer
[2011/06/04 15:51:56 | 000,000,000 | —D | M] – C:\Users\steve\AppData\Roaming\Xilisoft
[2011/10/24 09:46:16 | 000,000,564 | —- | M] () – C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 16:08:49 | 000,032,402 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/11/20 11:10:53 | 000,000,506 | —- | M] () – C:\Windows\Tasks\SystemToolsDailyTest.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/04/27 11:57:21 | 000,001,024 | —- | M] () – C:\.rnd
[2011/06/14 22:09:14 | 000,000,000 | —- | M] () – C:\10.1.19.109
[2010/07/31 22:20:31 | 000,000,165 | —- | M] () – C:\62P3DTNV.dat
[2010/03/26 04:16:22 | 000,004,889 | RH– | M] () – C:\dell.sdr
[2010/10/25 21:32:46 | 000,297,443 | —- | M] () – C:\hcwclear.txt
[2011/11/20 11:16:36 | 3214,135,296 | -HS- | M] () – C:\hiberfil.sys
[2011/04/27 08:40:07 | 000,001,821 | —- | M] () – C:\index.html
[2010/10/25 21:44:52 | 000,001,203 | —- | M] () – C:\install.log
[1995/04/27 00:33:10 | 000,146,976 | —- | M] (Microsoft Corporation) – C:\Mfcoleui.dll
[2011/11/20 11:16:55 | 4285,517,824 | -HS- | M] () – C:\pagefile.sys
[2011/11/20 09:55:27 | 000,087,720 | —- | M] () – C:\TDSSKiller.2.6.19.0_20.11.2011_09.54.30_log.txt
[2011/08/26 09:07:03 | 000,000,222 | —- | M] () – C:\test.txt
< %systemroot%\Fonts\*.com >
[2009/07/14 16:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 16:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 16:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 16:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/11 07:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/13 16:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/09/13 14:53:20 | 000,109,248 | —- | M] (Microsoft Corporation) – C:\Users\steve\AppData\Roaming\Microsoft\MSWINSCK.OCX
< %PROGRAMFILES%\*.* >
[2009/07/14 15:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/04/06 22:07:04 | 000,000,221 | -HS- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010/06/26 15:20:50 | 000,000,200 | —- | M] () – C:\Users\steve\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\eBay.url
< %USERPROFILE%\Desktop\*.exe >
[2011/07/02 10:38:06 | 1463,636,243 | —- | M] () – C:\Users\steve\Desktop\Adobe Premiere Elements 9.exe
[2011/08/21 11:50:48 | 000,483,328 | —- | M] (Simon Tatham) – C:\Users\steve\Desktop\putty.exe
[2010/08/29 08:59:58 | 000,163,840 | —- | M] () – C:\Users\steve\Desktop\ts-koe.exe
[2003/04/04 11:51:12 | 000,073,728 | —- | M] (eXtalia EXP) – C:\Users\steve\Desktop\ts203.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2010/05/11 21:19:20 | 000,014,683 | —- | M] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝
[2010/05/11 21:19:20 | 000,014,683 | —- | C] ()(C:\Windows\SysWow64\?????) – C:\Windows\SysWow64\㲫륫ܨᇓ箝
========== Alternate Data Streams ==========
@Alternate Data Stream - 160 bytes -> C:\Users\steve\pool_stamp_ivy.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 160 bytes -> C:\Users\steve\Fine_back.jpeg:3or4kl4x13tuuug3Byamue2s4b
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:5D432CE3
< End of report >