yaniz
Topic Starter
Hello!
After running OTL it provided me with the following logfile (please see below).
I have had some issues lately such as slow PC, XP resets itself randomly, can't access DVD player or burner …
I'd be greatful for any help in the matter. Thank you.
Best regards,
Yaniz
OTL logfile created on: 2012-04-23 12:10:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd
1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS
Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
PRC - C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
PRC - C:\Program Files\AVAST Software\Avast\Setup\avast.setup (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
PRC - C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
PRC - C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
PRC - C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Programi\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AVAST Software\Avast\defs\12042300\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12042201\algo.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avutil-51.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avformat-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avcodec-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll ()
MOD - E:\Programi\Todo Backup\bin\CodeLog.dll ()
MOD - C:\Program Files\AVAST Software\Avast\Setup\setiface.dll ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\ssp2ml3.dll ()
MOD - E:\Programi\RocketDock\RocketDock.exe ()
MOD - E:\Programi\RocketDock\RocketDock.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NovosoftBackupNetworkCoordinator) – File not found
SRV - (Guard Agent) – File not found
SRV - (EaseUS Agent) – File not found
SRV - (COSService.exe) – File not found
SRV - (aswUpdSv) – E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe File not found
SRV - (afcdpsrv) – File not found
SRV - (AcrSch2Svc) – File not found
SRV - (SynchronizationService.exe) – C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (Printer Control) – C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
SRV - (UnsignedThemes) – C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AshampooDefragService) – E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
SRV - (ASTSRV) – C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (NBService) – E:\Program Files\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (InCDsrv) – E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (sptd) – System32\Drivers\sptd.sys File not found
DRV - (RkPavproc1) – C:\WINDOWS\system32\drivers\RkPavproc1.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (cpuz135) – C:\DOCUME~1\Tomas\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys File not found
DRV - (Changer) – File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (cbvd) – C:\WINDOWS\system32\drivers\CBVD.sys (COMODO Security Solutions Inc.)
DRV - (reparse) – C:\WINDOWS\system32\drivers\cbreparse.sys (COMODO Security Solutions Inc.)
DRV - (vdbus) – C:\WINDOWS\system32\drivers\vdbus.sys (COMODO Security Solutions Inc.)
DRV - (CBUfs) – C:\WINDOWS\system32\drivers\cbufs.sys (COMODO Security Solutions Inc.)
DRV - (bdisk) – C:\WINDOWS\system32\drivers\bdisk.sys (COMODO Security Solutions Inc.)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\WINDOWS\system32\drivers\tdrpm251.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (FNETTBOH) – C:\WINDOWS\system32\drivers\FNETTBOH.SYS (FNet Co., Ltd.)
DRV - (FNETURPX) – C:\WINDOWS\system32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (UnlockerDriver5) – E:\Programi\Unlocker\UnlockerDriver5.sys ()
DRV - (SASENUM) – E:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – E:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (uxpatch) – C:\WINDOWS\system32\drivers\uxpatch.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (incdrm) – C:\WINDOWS\System32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\InCDfs.sys (Nero AG)
DRV - (WimFltr) – C:\WINDOWS\system32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delo.si/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://search.yahoo.com/search?fr=chr-pand…type=PCAFSI1190
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web"
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.windowsxlive.net"
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0.1289
FF - prefs.js..extensions.enabledItems: {535531f0-c4f8-11df-851a-0800200c9a66}:0.921
FF - prefs.js..extensions.enabledItems: {1a46a8a0-3278-11dd-bd11-0800200c9a66}:1.1.3
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-21 17:31:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-02-18 16:38:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011-03-23 16:04:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011-03-23 16:04:12 | 000,000,000 | —D | M]
[2008-11-25 14:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Extensions
[2012-03-13 19:40:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions
[2011-12-11 13:17:23 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-01-06 16:52:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-03-25 10:05:21 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2012-01-18 15:35:25 | 000,000,000 | —D | M] (EPUBReader) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2012-01-11 10:47:30 | 000,000,000 | —D | M] (myBabylon EnglishBB Community Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2012-02-13 20:51:20 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2010-11-24 23:10:24 | 000,000,000 | —D | M] ("CoolPreviews") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}(2)
[2010-01-27 18:51:11 | 000,000,000 | —D | M] ("BitDefender QuickScanner") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011-05-25 09:12:59 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\[removed]
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2012-03-04 13:54:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions
[2012-03-01 09:57:04 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-11-11 13:36:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012-02-18 16:38:31 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-18 16:38:07 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-02-18 16:38:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-02-18 16:38:07 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012-02-18 16:38:07 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012-02-18 16:38:07 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = E:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: avast! WebRep = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1289_1\
O1 HOSTS File: ([2010-12-09 16:01:42 | 000,000,853 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 216.55.133.9 handybackup.com www.handybackup.com
O1 - Hosts: 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DefragTaskBar] E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
O4 - HKLM..\Run: [EaseUs Tray] E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Panda Security URL Filtering] C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
O4 - HKLM..\Run: [PrintDisp] C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [UsbBoost] C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [E7C2B7736BF8C5A56B71BC2B8367796465C7B9C0._service_run] C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk = E:\Programi\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\Tomas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D6763AE-B541-4B67-9260-718B786E9597}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-11-25 12:13:37 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\AutoRun\command - "" = H:\
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O34 - HKLM BootExecute: (autocheck autochk *sprestrt)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1056
========== Files/Folders - Created Within 30 Days ==========
[2012-04-22 19:44:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2012-04-22 14:38:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2012-04-22 14:26:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Microangelo On Display
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2012-04-21 10:20:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microangelo On Display
[2012-04-18 18:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Unknown Device Identifier 8.00
[2012-04-18 08:07:04 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:13:43 | 000,278,528 | —- | C] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:12:27 | 000,000,000 | —D | C] – C:\Program Files\C-Media PCI Audio Device
[2012-04-12 12:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Spotify
[2012-04-12 12:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2012-04-11 14:48:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Start Menu\Programs\BricoPacks
[2012-04-04 12:09:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RocketDock
[2012-04-03 16:14:40 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012-04-03 16:08:45 | 000,198,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintime.dll
[2012-04-03 16:08:42 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2012-04-03 16:08:42 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_is2022.dll
[2012-04-03 16:08:41 | 000,218,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_g18030.dll
[2012-04-03 16:08:21 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browscap.dll
[2012-04-03 16:08:17 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\authfilt.dll
[2012-04-03 16:08:15 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asptxn.dll
[2012-04-03 16:08:15 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aspperf.dll
[2012-04-03 16:08:14 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asp51.dll
[2012-04-03 16:08:14 | 000,331,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aqueue.dll
[2012-04-03 16:08:13 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\appconf.dll
[2012-04-03 16:08:13 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2012-04-03 16:08:12 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0804.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0412.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0411.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt040d.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0404.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0401.dll
[2012-04-03 16:08:08 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2012-04-03 16:08:07 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adrot.dll
[2012-04-03 16:08:07 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admxprox.dll
[2012-04-03 16:08:06 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admexs.dll
[2012-04-03 16:07:59 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wamregps.dll
[2012-04-03 16:07:58 | 000,032,827 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptest.exe
[2012-04-03 16:07:58 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptsat.dll
[2012-04-03 16:07:57 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\staxmem.dll
[2012-04-03 16:07:56 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2012-04-03 16:07:56 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpadm.dll
[2012-04-03 16:07:55 | 000,020,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.dll
[2012-04-03 16:07:55 | 000,016,437 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.exe
[2012-04-03 16:07:48 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\logui.ocx
[2012-04-03 16:07:47 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\isatq.dll
[2012-04-03 16:07:47 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetsloc.dll
[2012-04-03 16:07:47 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\infoadmn.dll
[2012-04-03 16:07:46 | 000,829,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.dll
[2012-04-03 16:07:46 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.exe
[2012-04-03 16:07:45 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisui.dll
[2012-04-03 16:07:45 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrtl.dll
[2012-04-03 16:07:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstas.exe
[2012-04-03 16:07:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstap.dll
[2012-04-03 16:07:44 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisext51.dll
[2012-04-03 16:07:44 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iismap.dll
[2012-04-03 16:07:44 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisreset.exe
[2012-04-03 16:07:44 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2012-04-03 16:07:43 | 000,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2012-04-03 16:07:43 | 000,020,538 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpremadm.exe
[2012-04-03 16:07:42 | 000,598,071 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmc.dll
[2012-04-03 16:07:42 | 000,188,494 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpcount.exe
[2012-04-03 16:07:42 | 000,020,541 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpexedll.dll
[2012-04-03 16:07:41 | 000,876,653 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awel.dll
[2012-04-03 16:07:41 | 000,109,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98swin.exe
[2012-04-03 16:07:41 | 000,014,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2012-04-03 16:07:40 | 000,049,212 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2012-04-03 16:07:40 | 000,041,020 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2012-04-03 16:07:40 | 000,032,826 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avss.dll
[2012-04-03 16:07:39 | 000,147,513 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4apws.dll
[2012-04-03 16:07:39 | 000,102,509 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2012-04-03 16:07:39 | 000,049,210 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4areg.dll
[2012-04-03 16:07:38 | 000,184,435 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2012-04-03 16:07:38 | 000,082,035 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2012-04-03 16:07:37 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2012-04-03 16:07:37 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\coadmin.dll
[2012-04-03 16:07:36 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certwiz.ocx
[2012-04-03 16:07:36 | 000,188,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2012-04-03 16:07:36 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certmap.ocx
[2012-04-03 16:07:35 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.dll
[2012-04-03 16:07:35 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.exe
[2012-04-03 16:07:34 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adsiis51.dll
[2012-04-03 16:07:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admwprox.dll
[2012-04-03 16:07:33 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.exe
[2012-04-03 16:07:32 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.dll
[2012-04-03 15:51:55 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\drivers\RTL8139.sys
[2012-04-03 15:45:54 | 000,024,661 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\spxcoins.dll
[2012-04-03 15:45:54 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irclass.dll
[2012-04-03 13:46:05 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Tomas\Recent
[2012-03-28 15:08:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ZIP2FIX
[2012-03-28 12:55:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-03-26 17:05:29 | 000,000,000 | —D | C] – C:\WINDOWS\UXBackup
[2012-03-26 16:42:18 | 000,000,000 | —D | C] – C:\Program Files\UX Pack
[2012-03-26 11:17:41 | 000,000,000 | -H-D | C] – C:\Program Files\WindowsUpdate
[2012-03-26 11:15:15 | 000,000,000 | —D | C] – C:\Program Files\ComPlus Applications
[2012-03-25 12:25:18 | 000,000,000 | -H-D | C] – C:\Program Files\Uninstall Information
[2012-03-24 15:18:06 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-04-23 11:55:21 | 000,001,074 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003UA.job
[2012-04-23 11:35:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-23 10:47:16 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2012-04-22 19:53:21 | 000,242,412 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-22 18:55:12 | 000,001,022 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003Core.job
[2012-04-22 14:27:40 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012-04-22 12:09:05 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012-04-22 11:20:14 | 000,109,056 | —- | M] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-18 18:43:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-18 13:03:38 | 000,113,722 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Got-Zag-Got 2011.pdf
[2012-04-18 08:11:36 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\StartupSlowFix Schedule.job
[2012-04-17 19:11:10 | 000,278,528 | —- | M] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:11:10 | 000,001,480 | —- | M] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:10:52 | 000,002,421 | —- | M] () – C:\WINDOWS\cmudax3.ini
[2012-04-17 19:10:44 | 000,000,039 | —- | M] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-16 08:09:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012-04-12 12:15:37 | 000,001,834 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 15:17:22 | 000,006,550 | —- | M] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-11 15:17:04 | 000,061,845 | —- | M] () – C:\WINDOWS\BricoPackUninst.cmd
[2012-04-11 15:16:19 | 003,888,054 | —- | M] () – C:\WINDOWS\BricoPack Wallpaper.bmp
[2012-04-11 14:59:00 | 000,001,716 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-06 08:10:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012-04-05 08:53:45 | 000,000,573 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012-04-04 14:04:48 | 000,001,330 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 16:11:29 | 000,000,287 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012-04-03 16:06:38 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012-04-03 16:06:35 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012-04-03 16:06:35 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012-04-03 16:06:07 | 000,004,161 | —- | M] () – C:\WINDOWS\ODBCINST.INI
[2012-04-03 16:02:30 | 000,432,574 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012-04-03 16:02:30 | 000,067,530 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012-04-03 16:01:20 | 000,022,780 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012-04-03 13:07:47 | 000,000,604 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-31 16:17:37 | 000,001,057 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2012-03-26 17:18:48 | 002,113,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012-03-25 13:51:45 | 000,001,695 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012-03-25 13:49:57 | 000,002,638 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012-03-25 09:09:44 | 074,755,096 | -H– | M] () – C:\WINDOWS\cbufsscansysdmp.bin
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-04-22 19:53:20 | 000,242,412 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-18 18:43:48 | 000,000,079 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-17 19:13:48 | 000,001,480 | —- | C] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:13:45 | 000,000,039 | —- | C] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-17 19:13:22 | 000,002,421 | —- | C] () – C:\WINDOWS\cmudax3.ini
[2012-04-12 12:15:40 | 000,001,840 | —- | C] () – C:\Documents and Settings\Tomas\Start Menu\Programs\Spotify.lnk
[2012-04-12 12:15:37 | 000,001,834 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 14:59:00 | 000,001,716 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-11 14:48:31 | 000,006,550 | —- | C] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-05 08:53:45 | 000,000,573 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 14:04:48 | 000,001,330 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 15:46:14 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012-04-03 15:45:43 | 000,144,484 | —- | C] () – C:\WINDOWS\System32\dllcache\netfx.cat
[2012-04-03 15:45:43 | 000,034,747 | —- | C] () – C:\WINDOWS\System32\dllcache\mediactr.cat
[2012-04-03 15:45:43 | 000,026,991 | —- | C] () – C:\WINDOWS\System32\dllcache\msn7.cat
[2012-04-03 15:45:43 | 000,014,433 | —- | C] () – C:\WINDOWS\System32\dllcache\msn9.cat
[2012-04-03 15:45:43 | 000,010,027 | —- | C] () – C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2012-04-03 15:45:43 | 000,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012-04-03 15:45:43 | 000,007,382 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012-04-03 15:45:42 | 000,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012-04-03 15:45:42 | 000,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012-04-03 15:45:42 | 000,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2012-04-03 15:45:42 | 000,034,063 | —- | C] () – C:\WINDOWS\System32\dllcache\FP4.CAT
[2012-04-03 15:45:42 | 000,016,535 | —- | C] () – C:\WINDOWS\System32\dllcache\IMS.CAT
[2012-04-03 15:45:42 | 000,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012-04-03 15:45:42 | 000,012,363 | —- | C] () – C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2012-04-03 15:45:41 | 002,144,487 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5.CAT
[2012-04-03 15:45:40 | 000,522,220 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2012-04-03 13:07:46 | 000,000,604 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-26 16:42:18 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\moveex.exe
[2012-03-26 11:05:13 | 001,296,669 | —- | C] () – C:\WINDOWS\System32\dllcache\SP3.CAT
[2012-03-17 23:16:59 | 000,000,227 | —- | C] () – C:\WINDOWS\wininit.ini
[2012-03-17 19:09:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012-03-15 10:39:44 | 074,755,096 | -H– | C] () – C:\WINDOWS\cbufsscansysdmp.bin
[2012-02-16 18:00:07 | 000,043,784 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2012-02-13 20:50:13 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2012-01-08 10:36:57 | 002,113,752 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011-09-25 17:42:16 | 000,001,057 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2011-06-16 20:11:20 | 000,001,390 | —- | C] () – C:\WINDOWS\CDRipper.ini
[2011-03-16 17:38:33 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2011-01-21 09:58:24 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010-12-13 16:57:55 | 000,683,801 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.exe
[2010-12-13 16:57:55 | 000,018,695 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.dat
[2010-10-22 10:36:45 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\msblcd32.dll
[2010-10-22 10:22:03 | 000,109,056 | —- | C] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-10-05 15:01:04 | 001,391,616 | —- | C] () – C:\WINDOWS\System32\ActPDF.dll
[2010-10-05 15:00:50 | 000,691,200 | —- | C] () – C:\WINDOWS\System32\PrintLog.exe
[2010-10-05 15:00:50 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\PrtPass.exe
[2010-09-13 13:59:22 | 000,000,228 | —- | C] () – C:\WINDOWS\System32\edacded0_x.dat
[2010-05-25 21:49:22 | 000,000,192 | -H– | C] () – C:\WINDOWS\€nlsPreferences.dat
========== LOP Check ==========
[2010-12-08 15:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010-09-26 15:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2008-12-01 20:48:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ashampoo
[2011-09-21 17:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010-11-26 21:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010-10-19 10:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EMP
[2010-12-08 13:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FNET
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Iceni
[2012-04-21 10:23:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2011-01-30 13:50:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaStor
[2011-04-12 17:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2012-04-23 11:41:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering
[2009-12-06 17:00:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoGenie
[2011-01-25 17:43:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Power Soft
[2011-04-06 10:32:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Softland
[2010-10-25 16:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2012-04-22 18:34:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008-11-28 15:33:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011-10-27 14:38:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2010-12-08 20:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Acronis
[2010-09-26 15:37:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Alien Skin
[2011-06-27 13:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Amazon
[2011-01-23 17:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ASCOMP Software
[2012-03-23 14:18:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Audacity
[2009-06-17 17:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\com.adobe.ExMan
[2010-11-26 21:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\DAEMON Tools Pro
[2010-11-23 16:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Desktop Sidebar
[2012-04-23 12:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Dropbox
[2012-04-22 14:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2008-11-25 14:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Foxit
[2009-09-28 12:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\FPC
[2012-02-21 21:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Genie-soft
[2010-10-17 07:57:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\gtk-2.0
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Iceni
[2011-04-07 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\IGC
[2010-11-09 21:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ImgBurn
[2012-03-18 16:35:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\JAM Software
[2010-01-09 10:19:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\LightZone
[2012-03-21 18:44:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Magnifier
[2009-03-17 19:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage PS
[2009-03-17 14:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage SL
[2008-11-25 13:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Novosoft
[2011-04-12 17:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Panda Security
[2012-02-18 08:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\pandasecuritytb
[2009-08-26 10:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Participatory Culture Foundation
[2009-08-28 13:57:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\PCF-VLC
[2010-01-28 18:51:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\QuickScan
[2010-11-24 23:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Rainmeter(2)
[2010-01-28 15:05:57 | 000,000,000 | RHSD | M] – C:\Documents and Settings\Tomas\Application Data\RECYCLER
[2012-04-22 19:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2011-04-05 17:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Softland
[2012-03-28 13:01:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-04-12 12:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2010-10-25 17:02:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Stardock
[2012-02-14 13:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\thecleaner
[2011-02-24 13:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uniblue
[2008-12-10 21:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\URSoft
[2012-04-22 13:07:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uTorrent
[2012-04-03 13:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Vso
[2008-12-10 19:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\WordWeb
[2012-03-23 14:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\XnView
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\StartupSlowFix Schedule.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012-02-18 12:40:03 | 000,196,297 | -HS- | M] () – C:\ESLDR
[2012-02-18 12:40:07 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012-02-16 18:15:20 | 000,480,768 | -HS- | M] () – C:\EUMONBMP.SYS
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010-07-01 10:12:13 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011-09-21 16:49:28 | 000,006,272 | —- | M] () – C:\NanoRepository.bin
[2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008-04-14 00:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2007-08-12 07:59:28 | 000,375,054 | —- | M] () – C:\Splash.bmp
[2012-02-16 23:13:44 | 000,004,096 | -HS- | M] () – C:\{96391608-8CA9-438F-A3BF-1846759A831E}.CBM
< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012-04-03 16:04:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010-06-21 01:10:06 | 000,028,672 | —- | M] (ActMask Co.,Ltd) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ActPrint.dll
[2008-07-06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008-07-06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008-01-10 14:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ssp2mpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011-09-06 22:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2010-06-09 17:15:12 | 000,000,174 | —- | M] () – C:\Documents and Settings\All Users\Favorites\The NeoSmart Files.url
< %APPDATA%\Microsoft\*.* >
[2010-09-18 12:35:41 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2012-04-03 17:43:12 | 000,294,912 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012-04-03 15:32:49 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2012-04-03 17:43:12 | 025,427,968 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012-04-03 17:43:12 | 006,029,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012-04-03 16:06:49 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-03-25 12:34:40 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008-11-25 12:20:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011-02-02 21:14:36 | 001,601,024 | —- | M] (Mobatek) – C:\Documents and Settings\Tomas\Desktop\MobaLiveCD_v2.1.exe
[2012-02-16 11:27:17 | 000,076,517 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Patch.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-24 19:41:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 188 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:21654C57
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DBAC2017
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93C2F41D
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CFF5F08
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89EAFAFC
@Alternate Data Stream - 108 bytes -> C:\WINDOWS:
< End of report >
OTL Extras logfile created on: 2012-04-23 12:11:13 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd
1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS
Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with XnView] – Reg Error: Value error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"E:\Program Files\Novosoft\Handy Backup\backup.exe" = E:\Program Files\Novosoft\Handy Backup\backup.exe:*:Enabled:Handy Backup 6.0.8.0 – (Novosoft LLC)
"E:\Program Files\Novosoft\Handy Backup\hbagent.exe" = E:\Program Files\Novosoft\Handy Backup\hbagent.exe:*:Enabled:Handy Backup 6.0.8 Agent – (Novosoft LLC)
"E:\Program Files\uTorrent\uTorrent.exe" = E:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"E:\Program Files\Babylon\Babylon-Pro\Babylon.exe" = E:\Program Files\Babylon\Babylon-Pro\Babylon.exe:*:Enabled:Babylon
"E:\Program Files\spotify.exe" = E:\Program Files\spotify.exe:*:Enabled:Spotify
"E:\Program Files\Spotify\spotify.exe" = E:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify
"C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" = E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe:*:Enabled:SUPERAntiSpyware Free Edition – (SUPERAntiSpyware.com)
"E:\Program Files\Alwil Software\Avast4\ashAvast.exe" = E:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus
"C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\Program Files\Miro\Miro_Downloader.exe" = E:\Program Files\Miro\Miro_Downloader.exe:*:Disabled:Miro_Downloader
"E:\Program Files\VideoLAN\VLC\vlc.exe" = E:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware
"E:\Programi\Todo Backup\bin\Agent.exe" = E:\Programi\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235674B0-A35F-4811-8A8F-E8F42A919EA3}" = PhotoPresets with One-Click WOW!
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 24
"{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1" = Inpaint 3.0
"{2B04D44F-1D1B-4E0E-8431-D04F87C21033}" = Nero 7 Essentials
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{531BC138-F1F7-496B-879C-F039ECEF438D}" = Adobe Photoshop Lightroom 2
"{61A15405-48D5-4F59-966B-A0139FC7C69C}" = Handy Backup
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67B195ED-5174-4CD8-8B3A-A0B4DA3E48B7}" = LRViewer
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72FC0445-FE6D-4E12-815B-3A8C5E3704DA}_is1" = GroupMail :: Free Edition
"{75480068-162F-4D6B-B38E-76606A4E5320}_is1" = Dolphin Futures XPS Viewer version 1.1.0
"{7B4B0AA9-F97E-49C4-AE6F-D40580B65A22}" = onOne PerfectPresets
"{8679D366-D73F-4303-92F7-853B13C1F424}" = Microangelo On Display
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}" = UxStyle Core Beta
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-041D-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Swedish) 12
"{90120000-0015-041D-0000-0000000FF1CE}" = Microsoft Office Access MUI (Swedish) 2007
"{90120000-0015-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-041D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2007
"{90120000-0016-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2007
"{90120000-0018-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-041D-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Swedish) 2007
"{90120000-0019-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-041D-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Swedish) 2007
"{90120000-001A-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-041D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2007
"{90120000-001B-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
"{90120000-001F-0424-0000-0000000FF1CE}" = Microsoft Office Proof (Slovenian) 2007
"{90120000-002C-041D-0000-0000000FF1CE}" = Microsoft Office Proofing (Swedish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-041D-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Swedish) 2007
"{90120000-0044-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-041D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2007
"{90120000-006E-041D-0000-0000000FF1CE}_ENTERPRISE_{8C2A0B2D-382B-428C-9E8D-247D31B22201}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-041D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2007
"{90120000-00A1-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-041D-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Swedish) 2007
"{90120000-00BA-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-041D-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9999C416-FE39-4533-B280-0039E11B59F5}" = WinXP Manager
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5F8FCE2-1677-4370-A857-4976E5A95209}" = Topaz Vivacity
"{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1" = RAR Password Unlocker 4.2.0.0
"{B79E9FF2-D932-4FD5-BCAF-4DE6F2FBE521}" = COMODO BackUp
"{BA789040-B54B-4E7A-BC62-B6719E84CE9B}" = Active@ Disk Image
"{BE2ED609-7C07-4F6B-8E83-3800F8A133D6}" = PhotoPresets Wow Effects for Lightroom
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F1F96A-057E-5819-B52E-FEA1D1D2933B}" = Acronis True Image Home
"{C887C75D-2636-41F6-BB7B-FD4B0314C1E1}" = Paragon Partition Manager 9.0 Professional
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECCF8B1-F595-4845-9AA6-1EC57B9BECBA}_is1" = STP Viewer 2.3
"{CF6C1B06-4F86-4C41-BD21-9E40500006B5}" = COMODO Online Storage
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.19.365
"{DD7CDE4F-23DC-4C51-B749-0198C50F352D}_is1" = PDF to Word
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FD0F8123-9035-44B0-B331-2596979E74ED}_is1" = Book Collector
"{FD93D80D-CB42-483A-924B-CC44D0D32E40}_is1" = ZIP2FIX version 1.0
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"43442AE9-6512-4392-B5DD-9167BECD1114_is1" = Infix 4.22
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Alien Skin Bokeh 2" = Alien Skin Bokeh 2
"Amazon Kindle" = Amazon Kindle
"Ashampoo Magical Defrag 2_is1" = Ashampoo Magical Defrag 2
"ASP32 slovarji 29in1_is1" = ASP32 slovarji 29in1
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"C-Media PCI Sound" = C-Media PCI Audio Device
"Driver Checker_is1" = Driver Checker v2.7.4
"EaseUS Todo Backup Free 4.0_is1" = EaseUS Todo Backup Free 4.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPUB to Kindle converter_is1" = EPUB to Kindle converter version 1.3.6.0
"Exposure" = Alien Skin Exposure
"Foxit Reader" = Foxit Reader
"Fujidirekt Fotoservice_is1" = Fujidirekt Fotoservice 2.6
"iCare Data Recovery_is1" = iCare Data Recovery 4.0
"ImageConverter Plus_is1" = ImageConverter Plus 7.1
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"jv16 PowerTools 2009_is1" = jv16 PowerTools 2009
"LinuxLive USB Creator" = LinuxLive USB Creator
"Magic DVD Copier_is1" = Magic DVD Copier Version 5.0.0
"Magic ISO Maker v5.5 (build 0272)" = Magic ISO Maker v5.5 (build 0272)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"Outlook Express Backup_is1" = Outlook Express Backup V6.5
"Pack Vista Inspirat 2" = Pack Vista Inspirat 2 1.0
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"PeerGuardian_is1" = PeerGuardian 2.0
"Revo Uninstaller" = Revo Uninstaller 1.83
"RocketDock_is1" = RocketDock 1.3.5
"Samsung ML-1640 Series" = Samsung ML-1640 Series
"SilverFast Canon-SE TWAIN" = SilverFast Canon-SE TWAIN 6.6.0r5
"Simpo PDF to Word_is1" = Simpo PDF to Word 2.1.0.0
"Snapshot" = Snapshot (remove only)
"Speccy" = Speccy
"The Cleaner_is1" = The Cleaner 2012
"Toolbar Cleaner" = Toolbar Cleaner 1.0
"TreeSize Free_is1" = TreeSize Free V2.7
"Unknown Device Identifier_is1" = Unknown Device Identifier 8.00
"Unlocker" = Unlocker 1.9.1
"UsbBoost" = UsbBoost
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"VirtualCloneDrive" = VirtualCloneDrive
"Viveza 2" = Viveza 2
"VLC media player" = VLC media player 1.1.5
"VSO PhotoOnWeb_is1" = VSO PhotoOnWeb 0.9.1d
"VueScan" = VueScan
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Spotify" = Spotify
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-24 09:18:11 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-24 11:17:42 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 11307
Description = Produkt: Microsoft Office Enterprise 2007 – Fel 1307.Det finns inte
tillräckligt med diskutrymme för att installera den här filen: C:\WINDOWS\Installer\4e56f4.msp.
Frigör diskutrymme och klicka på Försök igen, eller klicka på Avbryt om du vill
avsluta.
Error - 2012-03-24 11:31:11 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Enterprise 2007 - Update 'Microsoft Office
2007 Service Pack 2 (SP2)' could not be installed. Error code 1603. Windows Installer
can create logs to help troubleshoot issues with installing software packages.
Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
Error - 2012-03-25 02:11:23 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-25 09:50:32 | Computer Name = 8C9EE2AF2 | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
msoe.dll, version 6.0.2900.5931, fault address 0x00016789.
Error - 2012-03-25 13:58:06 | Computer Name = 8C9EE2AF2 | Source = MSDTC | ID = 4404
Description = MS DTC Tracing infrastructure : the initialization of the tracing
infrastructure failed. Internal Information : msdtc_trace : File: d:\comxp_sp3\com\com1x\dtc\dtc\trace\src\tracelib.cpp,
Line: 1115, StartTrace Failed, hr=0x80070070
Error - 2012-03-25 16:04:13 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application CBU.exe, version 1.0.0.471, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-04-05 04:16:14 | Computer Name = 8C9EE2AF2 | Source = EventSystem | ID = 4614
Description = The COM+ Event System detected an inconsistency in its internal state.
The assertion "GetLastError() == 122L" failed at line 201 of f:\xpsp3\com\com1x\src\events\shared\sectools.cpp.
Please contact Microsoft Product Support Services to report this erro
[ OSession Events ]
Error - 2011-05-03 01:20:50 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83
seconds with 60 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:22:05 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:24:02 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:32:08 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 468
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-04 08:01:48 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 54
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-04 08:03:57 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-11-11 06:27:04 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 671842
seconds with 900 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.
Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Acronis Scheduler2 Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Comodo Online Storage Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The EaseUS Agent service failed to start due to the following error:
%%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Guard Agent service failed to start due to the following error:
%%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Novosoft Backup Network Coordinator service failed to start due
to the following error: %%3
Error - 2012-04-23 05:39:13 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.
Error - 2012-04-23 05:39:14 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd
< End of report >
After running OTL it provided me with the following logfile (please see below).
I have had some issues lately such as slow PC, XP resets itself randomly, can't access DVD player or burner …
I'd be greatful for any help in the matter. Thank you.
Best regards,
Yaniz
OTL logfile created on: 2012-04-23 12:10:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd
1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS
Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - E:\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
PRC - C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
PRC - C:\Program Files\AVAST Software\Avast\Setup\avast.setup (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
PRC - C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
PRC - C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
PRC - C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Programi\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\AVAST Software\Avast\defs\12042300\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12042201\algo.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avutil-51.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avformat-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avcodec-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll ()
MOD - E:\Programi\Todo Backup\bin\CodeLog.dll ()
MOD - C:\Program Files\AVAST Software\Avast\Setup\setiface.dll ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\ssp2ml3.dll ()
MOD - E:\Programi\RocketDock\RocketDock.exe ()
MOD - E:\Programi\RocketDock\RocketDock.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()
========== Win32 Services (SafeList) ==========
SRV - (NovosoftBackupNetworkCoordinator) – File not found
SRV - (Guard Agent) – File not found
SRV - (EaseUS Agent) – File not found
SRV - (COSService.exe) – File not found
SRV - (aswUpdSv) – E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe File not found
SRV - (afcdpsrv) – File not found
SRV - (AcrSch2Svc) – File not found
SRV - (SynchronizationService.exe) – C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (Printer Control) – C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
SRV - (UnsignedThemes) – C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AshampooDefragService) – E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
SRV - (ASTSRV) – C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (NBService) – E:\Program Files\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (InCDsrv) – E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)
========== Driver Services (SafeList) ==========
DRV - (WDICA) – File not found
DRV - (sptd) – System32\Drivers\sptd.sys File not found
DRV - (RkPavproc1) – C:\WINDOWS\system32\drivers\RkPavproc1.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (cpuz135) – C:\DOCUME~1\Tomas\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys File not found
DRV - (Changer) – File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (cbvd) – C:\WINDOWS\system32\drivers\CBVD.sys (COMODO Security Solutions Inc.)
DRV - (reparse) – C:\WINDOWS\system32\drivers\cbreparse.sys (COMODO Security Solutions Inc.)
DRV - (vdbus) – C:\WINDOWS\system32\drivers\vdbus.sys (COMODO Security Solutions Inc.)
DRV - (CBUfs) – C:\WINDOWS\system32\drivers\cbufs.sys (COMODO Security Solutions Inc.)
DRV - (bdisk) – C:\WINDOWS\system32\drivers\bdisk.sys (COMODO Security Solutions Inc.)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\WINDOWS\system32\drivers\tdrpm251.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (FNETTBOH) – C:\WINDOWS\system32\drivers\FNETTBOH.SYS (FNet Co., Ltd.)
DRV - (FNETURPX) – C:\WINDOWS\system32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (UnlockerDriver5) – E:\Programi\Unlocker\UnlockerDriver5.sys ()
DRV - (SASENUM) – E:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – E:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (uxpatch) – C:\WINDOWS\system32\drivers\uxpatch.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (incdrm) – C:\WINDOWS\System32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\InCDfs.sys (Nero AG)
DRV - (WimFltr) – C:\WINDOWS\system32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delo.si/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://search.yahoo.com/search?fr=chr-pand…type=PCAFSI1190
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Search the web"
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.windowsxlive.net"
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0.1289
FF - prefs.js..extensions.enabledItems: {535531f0-c4f8-11df-851a-0800200c9a66}:0.921
FF - prefs.js..extensions.enabledItems: {1a46a8a0-3278-11dd-bd11-0800200c9a66}:1.1.3
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-21 17:31:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-02-18 16:38:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011-03-23 16:04:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011-03-23 16:04:12 | 000,000,000 | —D | M]
[2008-11-25 14:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Extensions
[2012-03-13 19:40:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions
[2011-12-11 13:17:23 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-01-06 16:52:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-03-25 10:05:21 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2012-01-18 15:35:25 | 000,000,000 | —D | M] (EPUBReader) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2012-01-11 10:47:30 | 000,000,000 | —D | M] (myBabylon EnglishBB Community Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2012-02-13 20:51:20 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2010-11-24 23:10:24 | 000,000,000 | —D | M] ("CoolPreviews") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}(2)
[2010-01-27 18:51:11 | 000,000,000 | —D | M] ("BitDefender QuickScanner") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011-05-25 09:12:59 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\[removed]
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2012-03-04 13:54:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions
[2012-03-01 09:57:04 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-11-11 13:36:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012-02-18 16:38:31 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-18 16:38:07 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-02-18 16:38:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-02-18 16:38:07 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012-02-18 16:38:07 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012-02-18 16:38:07 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = E:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: avast! WebRep = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1289_1\
O1 HOSTS File: ([2010-12-09 16:01:42 | 000,000,853 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 216.55.133.9 handybackup.com www.handybackup.com
O1 - Hosts: 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DefragTaskBar] E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
O4 - HKLM..\Run: [EaseUs Tray] E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Panda Security URL Filtering] C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
O4 - HKLM..\Run: [PrintDisp] C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [UsbBoost] C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [E7C2B7736BF8C5A56B71BC2B8367796465C7B9C0._service_run] C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk = E:\Programi\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\Tomas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D6763AE-B541-4B67-9260-718B786E9597}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-11-25 12:13:37 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\AutoRun\command - "" = H:\
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O34 - HKLM BootExecute: (autocheck autochk *sprestrt)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1056
========== Files/Folders - Created Within 30 Days ==========
[2012-04-22 19:44:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2012-04-22 14:38:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2012-04-22 14:26:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Microangelo On Display
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2012-04-21 10:20:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microangelo On Display
[2012-04-18 18:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Unknown Device Identifier 8.00
[2012-04-18 08:07:04 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:13:43 | 000,278,528 | —- | C] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:12:27 | 000,000,000 | —D | C] – C:\Program Files\C-Media PCI Audio Device
[2012-04-12 12:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Spotify
[2012-04-12 12:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2012-04-11 14:48:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Start Menu\Programs\BricoPacks
[2012-04-04 12:09:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RocketDock
[2012-04-03 16:14:40 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012-04-03 16:08:45 | 000,198,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintime.dll
[2012-04-03 16:08:42 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2012-04-03 16:08:42 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_is2022.dll
[2012-04-03 16:08:41 | 000,218,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_g18030.dll
[2012-04-03 16:08:21 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browscap.dll
[2012-04-03 16:08:17 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\authfilt.dll
[2012-04-03 16:08:15 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asptxn.dll
[2012-04-03 16:08:15 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aspperf.dll
[2012-04-03 16:08:14 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asp51.dll
[2012-04-03 16:08:14 | 000,331,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aqueue.dll
[2012-04-03 16:08:13 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\appconf.dll
[2012-04-03 16:08:13 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2012-04-03 16:08:12 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0804.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0412.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0411.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt040d.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0404.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0401.dll
[2012-04-03 16:08:08 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2012-04-03 16:08:07 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adrot.dll
[2012-04-03 16:08:07 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admxprox.dll
[2012-04-03 16:08:06 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admexs.dll
[2012-04-03 16:07:59 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wamregps.dll
[2012-04-03 16:07:58 | 000,032,827 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptest.exe
[2012-04-03 16:07:58 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptsat.dll
[2012-04-03 16:07:57 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\staxmem.dll
[2012-04-03 16:07:56 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2012-04-03 16:07:56 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpadm.dll
[2012-04-03 16:07:55 | 000,020,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.dll
[2012-04-03 16:07:55 | 000,016,437 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.exe
[2012-04-03 16:07:48 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\logui.ocx
[2012-04-03 16:07:47 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\isatq.dll
[2012-04-03 16:07:47 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetsloc.dll
[2012-04-03 16:07:47 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\infoadmn.dll
[2012-04-03 16:07:46 | 000,829,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.dll
[2012-04-03 16:07:46 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.exe
[2012-04-03 16:07:45 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisui.dll
[2012-04-03 16:07:45 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrtl.dll
[2012-04-03 16:07:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstas.exe
[2012-04-03 16:07:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstap.dll
[2012-04-03 16:07:44 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisext51.dll
[2012-04-03 16:07:44 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iismap.dll
[2012-04-03 16:07:44 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisreset.exe
[2012-04-03 16:07:44 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2012-04-03 16:07:43 | 000,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2012-04-03 16:07:43 | 000,020,538 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpremadm.exe
[2012-04-03 16:07:42 | 000,598,071 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmc.dll
[2012-04-03 16:07:42 | 000,188,494 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpcount.exe
[2012-04-03 16:07:42 | 000,020,541 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpexedll.dll
[2012-04-03 16:07:41 | 000,876,653 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awel.dll
[2012-04-03 16:07:41 | 000,109,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98swin.exe
[2012-04-03 16:07:41 | 000,014,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2012-04-03 16:07:40 | 000,049,212 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2012-04-03 16:07:40 | 000,041,020 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2012-04-03 16:07:40 | 000,032,826 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avss.dll
[2012-04-03 16:07:39 | 000,147,513 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4apws.dll
[2012-04-03 16:07:39 | 000,102,509 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2012-04-03 16:07:39 | 000,049,210 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4areg.dll
[2012-04-03 16:07:38 | 000,184,435 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2012-04-03 16:07:38 | 000,082,035 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2012-04-03 16:07:37 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2012-04-03 16:07:37 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\coadmin.dll
[2012-04-03 16:07:36 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certwiz.ocx
[2012-04-03 16:07:36 | 000,188,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2012-04-03 16:07:36 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certmap.ocx
[2012-04-03 16:07:35 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.dll
[2012-04-03 16:07:35 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.exe
[2012-04-03 16:07:34 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adsiis51.dll
[2012-04-03 16:07:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admwprox.dll
[2012-04-03 16:07:33 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.exe
[2012-04-03 16:07:32 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.dll
[2012-04-03 15:51:55 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\drivers\RTL8139.sys
[2012-04-03 15:45:54 | 000,024,661 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\spxcoins.dll
[2012-04-03 15:45:54 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irclass.dll
[2012-04-03 13:46:05 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Tomas\Recent
[2012-03-28 15:08:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ZIP2FIX
[2012-03-28 12:55:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-03-26 17:05:29 | 000,000,000 | —D | C] – C:\WINDOWS\UXBackup
[2012-03-26 16:42:18 | 000,000,000 | —D | C] – C:\Program Files\UX Pack
[2012-03-26 11:17:41 | 000,000,000 | -H-D | C] – C:\Program Files\WindowsUpdate
[2012-03-26 11:15:15 | 000,000,000 | —D | C] – C:\Program Files\ComPlus Applications
[2012-03-25 12:25:18 | 000,000,000 | -H-D | C] – C:\Program Files\Uninstall Information
[2012-03-24 15:18:06 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012-04-23 11:55:21 | 000,001,074 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003UA.job
[2012-04-23 11:35:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-23 10:47:16 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2012-04-22 19:53:21 | 000,242,412 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-22 18:55:12 | 000,001,022 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003Core.job
[2012-04-22 14:27:40 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012-04-22 12:09:05 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012-04-22 11:20:14 | 000,109,056 | —- | M] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-18 18:43:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-18 13:03:38 | 000,113,722 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Got-Zag-Got 2011.pdf
[2012-04-18 08:11:36 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\StartupSlowFix Schedule.job
[2012-04-17 19:11:10 | 000,278,528 | —- | M] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:11:10 | 000,001,480 | —- | M] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:10:52 | 000,002,421 | —- | M] () – C:\WINDOWS\cmudax3.ini
[2012-04-17 19:10:44 | 000,000,039 | —- | M] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-16 08:09:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012-04-12 12:15:37 | 000,001,834 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 15:17:22 | 000,006,550 | —- | M] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-11 15:17:04 | 000,061,845 | —- | M] () – C:\WINDOWS\BricoPackUninst.cmd
[2012-04-11 15:16:19 | 003,888,054 | —- | M] () – C:\WINDOWS\BricoPack Wallpaper.bmp
[2012-04-11 14:59:00 | 000,001,716 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-06 08:10:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012-04-05 08:53:45 | 000,000,573 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012-04-04 14:04:48 | 000,001,330 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 16:11:29 | 000,000,287 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012-04-03 16:06:38 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012-04-03 16:06:35 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012-04-03 16:06:35 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012-04-03 16:06:07 | 000,004,161 | —- | M] () – C:\WINDOWS\ODBCINST.INI
[2012-04-03 16:02:30 | 000,432,574 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012-04-03 16:02:30 | 000,067,530 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012-04-03 16:01:20 | 000,022,780 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012-04-03 13:07:47 | 000,000,604 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-31 16:17:37 | 000,001,057 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2012-03-26 17:18:48 | 002,113,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012-03-25 13:51:45 | 000,001,695 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012-03-25 13:49:57 | 000,002,638 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012-03-25 09:09:44 | 074,755,096 | -H– | M] () – C:\WINDOWS\cbufsscansysdmp.bin
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012-04-22 19:53:20 | 000,242,412 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-18 18:43:48 | 000,000,079 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-17 19:13:48 | 000,001,480 | —- | C] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:13:45 | 000,000,039 | —- | C] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-17 19:13:22 | 000,002,421 | —- | C] () – C:\WINDOWS\cmudax3.ini
[2012-04-12 12:15:40 | 000,001,840 | —- | C] () – C:\Documents and Settings\Tomas\Start Menu\Programs\Spotify.lnk
[2012-04-12 12:15:37 | 000,001,834 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 14:59:00 | 000,001,716 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-11 14:48:31 | 000,006,550 | —- | C] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-05 08:53:45 | 000,000,573 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 14:04:48 | 000,001,330 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 15:46:14 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012-04-03 15:45:43 | 000,144,484 | —- | C] () – C:\WINDOWS\System32\dllcache\netfx.cat
[2012-04-03 15:45:43 | 000,034,747 | —- | C] () – C:\WINDOWS\System32\dllcache\mediactr.cat
[2012-04-03 15:45:43 | 000,026,991 | —- | C] () – C:\WINDOWS\System32\dllcache\msn7.cat
[2012-04-03 15:45:43 | 000,014,433 | —- | C] () – C:\WINDOWS\System32\dllcache\msn9.cat
[2012-04-03 15:45:43 | 000,010,027 | —- | C] () – C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2012-04-03 15:45:43 | 000,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012-04-03 15:45:43 | 000,007,382 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012-04-03 15:45:42 | 000,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012-04-03 15:45:42 | 000,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012-04-03 15:45:42 | 000,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2012-04-03 15:45:42 | 000,034,063 | —- | C] () – C:\WINDOWS\System32\dllcache\FP4.CAT
[2012-04-03 15:45:42 | 000,016,535 | —- | C] () – C:\WINDOWS\System32\dllcache\IMS.CAT
[2012-04-03 15:45:42 | 000,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012-04-03 15:45:42 | 000,012,363 | —- | C] () – C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2012-04-03 15:45:41 | 002,144,487 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5.CAT
[2012-04-03 15:45:40 | 000,522,220 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2012-04-03 13:07:46 | 000,000,604 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-26 16:42:18 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\moveex.exe
[2012-03-26 11:05:13 | 001,296,669 | —- | C] () – C:\WINDOWS\System32\dllcache\SP3.CAT
[2012-03-17 23:16:59 | 000,000,227 | —- | C] () – C:\WINDOWS\wininit.ini
[2012-03-17 19:09:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012-03-15 10:39:44 | 074,755,096 | -H– | C] () – C:\WINDOWS\cbufsscansysdmp.bin
[2012-02-16 18:00:07 | 000,043,784 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2012-02-13 20:50:13 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2012-01-08 10:36:57 | 002,113,752 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011-09-25 17:42:16 | 000,001,057 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2011-06-16 20:11:20 | 000,001,390 | —- | C] () – C:\WINDOWS\CDRipper.ini
[2011-03-16 17:38:33 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2011-01-21 09:58:24 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010-12-13 16:57:55 | 000,683,801 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.exe
[2010-12-13 16:57:55 | 000,018,695 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.dat
[2010-10-22 10:36:45 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\msblcd32.dll
[2010-10-22 10:22:03 | 000,109,056 | —- | C] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-10-05 15:01:04 | 001,391,616 | —- | C] () – C:\WINDOWS\System32\ActPDF.dll
[2010-10-05 15:00:50 | 000,691,200 | —- | C] () – C:\WINDOWS\System32\PrintLog.exe
[2010-10-05 15:00:50 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\PrtPass.exe
[2010-09-13 13:59:22 | 000,000,228 | —- | C] () – C:\WINDOWS\System32\edacded0_x.dat
[2010-05-25 21:49:22 | 000,000,192 | -H– | C] () – C:\WINDOWS\€nlsPreferences.dat
========== LOP Check ==========
[2010-12-08 15:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010-09-26 15:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2008-12-01 20:48:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ashampoo
[2011-09-21 17:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010-11-26 21:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010-10-19 10:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EMP
[2010-12-08 13:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FNET
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Iceni
[2012-04-21 10:23:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2011-01-30 13:50:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaStor
[2011-04-12 17:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2012-04-23 11:41:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering
[2009-12-06 17:00:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoGenie
[2011-01-25 17:43:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Power Soft
[2011-04-06 10:32:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Softland
[2010-10-25 16:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2012-04-22 18:34:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008-11-28 15:33:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011-10-27 14:38:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2010-12-08 20:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Acronis
[2010-09-26 15:37:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Alien Skin
[2011-06-27 13:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Amazon
[2011-01-23 17:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ASCOMP Software
[2012-03-23 14:18:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Audacity
[2009-06-17 17:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\com.adobe.ExMan
[2010-11-26 21:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\DAEMON Tools Pro
[2010-11-23 16:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Desktop Sidebar
[2012-04-23 12:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Dropbox
[2012-04-22 14:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2008-11-25 14:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Foxit
[2009-09-28 12:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\FPC
[2012-02-21 21:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Genie-soft
[2010-10-17 07:57:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\gtk-2.0
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Iceni
[2011-04-07 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\IGC
[2010-11-09 21:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ImgBurn
[2012-03-18 16:35:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\JAM Software
[2010-01-09 10:19:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\LightZone
[2012-03-21 18:44:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Magnifier
[2009-03-17 19:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage PS
[2009-03-17 14:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage SL
[2008-11-25 13:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Novosoft
[2011-04-12 17:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Panda Security
[2012-02-18 08:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\pandasecuritytb
[2009-08-26 10:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Participatory Culture Foundation
[2009-08-28 13:57:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\PCF-VLC
[2010-01-28 18:51:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\QuickScan
[2010-11-24 23:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Rainmeter(2)
[2010-01-28 15:05:57 | 000,000,000 | RHSD | M] – C:\Documents and Settings\Tomas\Application Data\RECYCLER
[2012-04-22 19:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2011-04-05 17:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Softland
[2012-03-28 13:01:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-04-12 12:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2010-10-25 17:02:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Stardock
[2012-02-14 13:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\thecleaner
[2011-02-24 13:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uniblue
[2008-12-10 21:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\URSoft
[2012-04-22 13:07:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uTorrent
[2012-04-03 13:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Vso
[2008-12-10 19:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\WordWeb
[2012-03-23 14:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\XnView
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\StartupSlowFix Schedule.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012-02-18 12:40:03 | 000,196,297 | -HS- | M] () – C:\ESLDR
[2012-02-18 12:40:07 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012-02-16 18:15:20 | 000,480,768 | -HS- | M] () – C:\EUMONBMP.SYS
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010-07-01 10:12:13 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011-09-21 16:49:28 | 000,006,272 | —- | M] () – C:\NanoRepository.bin
[2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008-04-14 00:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2007-08-12 07:59:28 | 000,375,054 | —- | M] () – C:\Splash.bmp
[2012-02-16 23:13:44 | 000,004,096 | -HS- | M] () – C:\{96391608-8CA9-438F-A3BF-1846759A831E}.CBM
< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012-04-03 16:04:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010-06-21 01:10:06 | 000,028,672 | —- | M] (ActMask Co.,Ltd) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ActPrint.dll
[2008-07-06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008-07-06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008-01-10 14:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ssp2mpc.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011-09-06 22:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
[2010-06-09 17:15:12 | 000,000,174 | —- | M] () – C:\Documents and Settings\All Users\Favorites\The NeoSmart Files.url
< %APPDATA%\Microsoft\*.* >
[2010-09-18 12:35:41 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2012-04-03 17:43:12 | 000,294,912 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012-04-03 15:32:49 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2012-04-03 17:43:12 | 025,427,968 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012-04-03 17:43:12 | 006,029,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012-04-03 16:06:49 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-03-25 12:34:40 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008-11-25 12:20:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011-02-02 21:14:36 | 001,601,024 | —- | M] (Mobatek) – C:\Documents and Settings\Tomas\Desktop\MobaLiveCD_v2.1.exe
[2012-02-16 11:27:17 | 000,076,517 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Patch.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-24 19:41:03
========== Alternate Data Streams ==========
@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 188 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:21654C57
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DBAC2017
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93C2F41D
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CFF5F08
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89EAFAFC
@Alternate Data Stream - 108 bytes -> C:\WINDOWS:
< End of report >
OTL Extras logfile created on: 2012-04-23 12:11:13 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd
1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS
Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with XnView] – Reg Error: Value error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"E:\Program Files\Novosoft\Handy Backup\backup.exe" = E:\Program Files\Novosoft\Handy Backup\backup.exe:*:Enabled:Handy Backup 6.0.8.0 – (Novosoft LLC)
"E:\Program Files\Novosoft\Handy Backup\hbagent.exe" = E:\Program Files\Novosoft\Handy Backup\hbagent.exe:*:Enabled:Handy Backup 6.0.8 Agent – (Novosoft LLC)
"E:\Program Files\uTorrent\uTorrent.exe" = E:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"E:\Program Files\Babylon\Babylon-Pro\Babylon.exe" = E:\Program Files\Babylon\Babylon-Pro\Babylon.exe:*:Enabled:Babylon
"E:\Program Files\spotify.exe" = E:\Program Files\spotify.exe:*:Enabled:Spotify
"E:\Program Files\Spotify\spotify.exe" = E:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify
"C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" = E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe:*:Enabled:SUPERAntiSpyware Free Edition – (SUPERAntiSpyware.com)
"E:\Program Files\Alwil Software\Avast4\ashAvast.exe" = E:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus
"C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\Program Files\Miro\Miro_Downloader.exe" = E:\Program Files\Miro\Miro_Downloader.exe:*:Disabled:Miro_Downloader
"E:\Program Files\VideoLAN\VLC\vlc.exe" = E:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware
"E:\Programi\Todo Backup\bin\Agent.exe" = E:\Programi\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235674B0-A35F-4811-8A8F-E8F42A919EA3}" = PhotoPresets with One-Click WOW!
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 24
"{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1" = Inpaint 3.0
"{2B04D44F-1D1B-4E0E-8431-D04F87C21033}" = Nero 7 Essentials
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{531BC138-F1F7-496B-879C-F039ECEF438D}" = Adobe Photoshop Lightroom 2
"{61A15405-48D5-4F59-966B-A0139FC7C69C}" = Handy Backup
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67B195ED-5174-4CD8-8B3A-A0B4DA3E48B7}" = LRViewer
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72FC0445-FE6D-4E12-815B-3A8C5E3704DA}_is1" = GroupMail :: Free Edition
"{75480068-162F-4D6B-B38E-76606A4E5320}_is1" = Dolphin Futures XPS Viewer version 1.1.0
"{7B4B0AA9-F97E-49C4-AE6F-D40580B65A22}" = onOne PerfectPresets
"{8679D366-D73F-4303-92F7-853B13C1F424}" = Microangelo On Display
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}" = UxStyle Core Beta
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-041D-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Swedish) 12
"{90120000-0015-041D-0000-0000000FF1CE}" = Microsoft Office Access MUI (Swedish) 2007
"{90120000-0015-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-041D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2007
"{90120000-0016-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2007
"{90120000-0018-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-041D-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Swedish) 2007
"{90120000-0019-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-041D-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Swedish) 2007
"{90120000-001A-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-041D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2007
"{90120000-001B-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
"{90120000-001F-0424-0000-0000000FF1CE}" = Microsoft Office Proof (Slovenian) 2007
"{90120000-002C-041D-0000-0000000FF1CE}" = Microsoft Office Proofing (Swedish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-041D-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Swedish) 2007
"{90120000-0044-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-041D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2007
"{90120000-006E-041D-0000-0000000FF1CE}_ENTERPRISE_{8C2A0B2D-382B-428C-9E8D-247D31B22201}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-041D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2007
"{90120000-00A1-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-041D-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Swedish) 2007
"{90120000-00BA-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-041D-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9999C416-FE39-4533-B280-0039E11B59F5}" = WinXP Manager
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5F8FCE2-1677-4370-A857-4976E5A95209}" = Topaz Vivacity
"{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1" = RAR Password Unlocker 4.2.0.0
"{B79E9FF2-D932-4FD5-BCAF-4DE6F2FBE521}" = COMODO BackUp
"{BA789040-B54B-4E7A-BC62-B6719E84CE9B}" = Active@ Disk Image
"{BE2ED609-7C07-4F6B-8E83-3800F8A133D6}" = PhotoPresets Wow Effects for Lightroom
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F1F96A-057E-5819-B52E-FEA1D1D2933B}" = Acronis True Image Home
"{C887C75D-2636-41F6-BB7B-FD4B0314C1E1}" = Paragon Partition Manager 9.0 Professional
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECCF8B1-F595-4845-9AA6-1EC57B9BECBA}_is1" = STP Viewer 2.3
"{CF6C1B06-4F86-4C41-BD21-9E40500006B5}" = COMODO Online Storage
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.19.365
"{DD7CDE4F-23DC-4C51-B749-0198C50F352D}_is1" = PDF to Word
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FD0F8123-9035-44B0-B331-2596979E74ED}_is1" = Book Collector
"{FD93D80D-CB42-483A-924B-CC44D0D32E40}_is1" = ZIP2FIX version 1.0
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"43442AE9-6512-4392-B5DD-9167BECD1114_is1" = Infix 4.22
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Alien Skin Bokeh 2" = Alien Skin Bokeh 2
"Amazon Kindle" = Amazon Kindle
"Ashampoo Magical Defrag 2_is1" = Ashampoo Magical Defrag 2
"ASP32 slovarji 29in1_is1" = ASP32 slovarji 29in1
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"C-Media PCI Sound" = C-Media PCI Audio Device
"Driver Checker_is1" = Driver Checker v2.7.4
"EaseUS Todo Backup Free 4.0_is1" = EaseUS Todo Backup Free 4.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPUB to Kindle converter_is1" = EPUB to Kindle converter version 1.3.6.0
"Exposure" = Alien Skin Exposure
"Foxit Reader" = Foxit Reader
"Fujidirekt Fotoservice_is1" = Fujidirekt Fotoservice 2.6
"iCare Data Recovery_is1" = iCare Data Recovery 4.0
"ImageConverter Plus_is1" = ImageConverter Plus 7.1
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"jv16 PowerTools 2009_is1" = jv16 PowerTools 2009
"LinuxLive USB Creator" = LinuxLive USB Creator
"Magic DVD Copier_is1" = Magic DVD Copier Version 5.0.0
"Magic ISO Maker v5.5 (build 0272)" = Magic ISO Maker v5.5 (build 0272)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"Outlook Express Backup_is1" = Outlook Express Backup V6.5
"Pack Vista Inspirat 2" = Pack Vista Inspirat 2 1.0
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"PeerGuardian_is1" = PeerGuardian 2.0
"Revo Uninstaller" = Revo Uninstaller 1.83
"RocketDock_is1" = RocketDock 1.3.5
"Samsung ML-1640 Series" = Samsung ML-1640 Series
"SilverFast Canon-SE TWAIN" = SilverFast Canon-SE TWAIN 6.6.0r5
"Simpo PDF to Word_is1" = Simpo PDF to Word 2.1.0.0
"Snapshot" = Snapshot (remove only)
"Speccy" = Speccy
"The Cleaner_is1" = The Cleaner 2012
"Toolbar Cleaner" = Toolbar Cleaner 1.0
"TreeSize Free_is1" = TreeSize Free V2.7
"Unknown Device Identifier_is1" = Unknown Device Identifier 8.00
"Unlocker" = Unlocker 1.9.1
"UsbBoost" = UsbBoost
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"VirtualCloneDrive" = VirtualCloneDrive
"Viveza 2" = Viveza 2
"VLC media player" = VLC media player 1.1.5
"VSO PhotoOnWeb_is1" = VSO PhotoOnWeb 0.9.1d
"VueScan" = VueScan
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Spotify" = Spotify
"uTorrent" = µTorrent
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-24 09:18:11 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-24 11:17:42 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 11307
Description = Produkt: Microsoft Office Enterprise 2007 – Fel 1307.Det finns inte
tillräckligt med diskutrymme för att installera den här filen: C:\WINDOWS\Installer\4e56f4.msp.
Frigör diskutrymme och klicka på Försök igen, eller klicka på Avbryt om du vill
avsluta.
Error - 2012-03-24 11:31:11 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Enterprise 2007 - Update 'Microsoft Office
2007 Service Pack 2 (SP2)' could not be installed. Error code 1603. Windows Installer
can create logs to help troubleshoot issues with installing software packages.
Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
Error - 2012-03-25 02:11:23 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.
Error - 2012-03-25 09:50:32 | Computer Name = 8C9EE2AF2 | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
msoe.dll, version 6.0.2900.5931, fault address 0x00016789.
Error - 2012-03-25 13:58:06 | Computer Name = 8C9EE2AF2 | Source = MSDTC | ID = 4404
Description = MS DTC Tracing infrastructure : the initialization of the tracing
infrastructure failed. Internal Information : msdtc_trace : File: d:\comxp_sp3\com\com1x\dtc\dtc\trace\src\tracelib.cpp,
Line: 1115, StartTrace Failed, hr=0x80070070
Error - 2012-03-25 16:04:13 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application CBU.exe, version 1.0.0.471, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.
Error - 2012-04-05 04:16:14 | Computer Name = 8C9EE2AF2 | Source = EventSystem | ID = 4614
Description = The COM+ Event System detected an inconsistency in its internal state.
The assertion "GetLastError() == 122L" failed at line 201 of f:\xpsp3\com\com1x\src\events\shared\sectools.cpp.
Please contact Microsoft Product Support Services to report this erro
[ OSession Events ]
Error - 2011-05-03 01:20:50 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83
seconds with 60 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:22:05 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:24:02 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-03 01:32:08 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 468
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-04 08:01:48 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 54
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-05-04 08:03:57 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.
Error - 2011-11-11 06:27:04 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 671842
seconds with 900 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.
Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Acronis Scheduler2 Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Comodo Online Storage Service service failed to start due to the
following error: %%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The EaseUS Agent service failed to start due to the following error:
%%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Guard Agent service failed to start due to the following error:
%%3
Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Novosoft Backup Network Coordinator service failed to start due
to the following error: %%3
Error - 2012-04-23 05:39:13 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.
Error - 2012-04-23 05:39:14 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd
< End of report >