This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

XP resets randomly [Closed]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello!

After running OTL it provided me with the following logfile (please see below).

I have had some issues lately such as slow PC, XP resets itself randomly, can't access DVD player or burner …

I'd be greatful for any help in the matter. Thank you.

Best regards,
Yaniz


OTL logfile created on: 2012-04-23 12:10:55 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd

1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS

Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - E:\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
PRC - C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
PRC - C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
PRC - C:\Program Files\AVAST Software\Avast\Setup\avast.setup (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
PRC - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
PRC - C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
PRC - C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
PRC - C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
PRC - C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
PRC - C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
PRC - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
PRC - C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
PRC - C:\Program Files\Outlook Express\msimn.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - E:\Programi\RocketDock\RocketDock.exe ()
PRC - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
PRC - C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
PRC - E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)
PRC - C:\WINDOWS\system32\devldr32.exe (Creative Technology Ltd.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\AVAST Software\Avast\defs\12042300\algo.dll ()
MOD - C:\Program Files\AVAST Software\Avast\defs\12042201\algo.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppgooglenaclpluginchrome.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avutil-51.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avformat-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\avcodec-53.dll ()
MOD - C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll ()
MOD - E:\Programi\Todo Backup\bin\CodeLog.dll ()
MOD - C:\Program Files\AVAST Software\Avast\Setup\setiface.dll ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
MOD - E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragActivityMonitor.exe ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\ssp2ml3.dll ()
MOD - E:\Programi\RocketDock\RocketDock.exe ()
MOD - E:\Programi\RocketDock\RocketDock.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\MiniCrypto.dll ()
MOD - C:\Program Files\Panda Security\Panda Cloud Antivirus\APIcr.dll ()


========== Win32 Services (SafeList) ==========

SRV - (NovosoftBackupNetworkCoordinator) – File not found
SRV - (Guard Agent) – File not found
SRV - (EaseUS Agent) – File not found
SRV - (COSService.exe) – File not found
SRV - (aswUpdSv) – E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe File not found
SRV - (afcdpsrv) – File not found
SRV - (AcrSch2Svc) – File not found
SRV - (SynchronizationService.exe) – C:\Program Files\COMODO\COMMON\SynchronizationService.exe (Comodo Security Solutions)
SRV - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV - (NanoServiceMain) – C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exe (Panda Security, S.L.)
SRV - (nlsX86cc) – C:\WINDOWS\system32\nlssrv32.exe (Nalpeiron Ltd.)
SRV - (Printer Control) – C:\WINDOWS\system32\PrintCtrl.exe (ActMask Co.,Ltd - HTTP://WWW.ALL2PDF.COM)
SRV - (UnsignedThemes) – C:\WINDOWS\UnsignedThemesSvc.exe (The Within Network, LLC)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (AshampooDefragService) – E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\aDefragService.exe ( )
SRV - (ASTSRV) – C:\WINDOWS\system32\ASTSRV.EXE (Nalpeiron Ltd.)
SRV - (NBService) – E:\Program Files\Nero 7\Nero BackItUp\NBService.exe (Nero AG)
SRV - (InCDsrv) – E:\Program Files\Nero 7\InCD\InCDsrv.exe (Nero AG)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (sptd) – System32\Drivers\sptd.sys File not found
DRV - (RkPavproc1) – C:\WINDOWS\system32\drivers\RkPavproc1.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (i2omgmt) – File not found
DRV - (cpuz135) – C:\DOCUME~1\Tomas\LOCALS~1\Temp\cpuz135\cpuz135_x32.sys File not found
DRV - (Changer) – File not found
DRV - (MBAMSwissArmy) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys (Malwarebytes Corporation)
DRV - (PSINAflt) – C:\WINDOWS\system32\drivers\PSINAflt.sys (Panda Security, S.L.)
DRV - (EUFDDISK) – C:\WINDOWS\system32\drivers\EuFdDisk.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBKMON) – C:\WINDOWS\system32\drivers\EUBKMON.sys ()
DRV - (EUDSKACS) – C:\WINDOWS\system32\drivers\eudskacs.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (EUBAKUP) – C:\WINDOWS\system32\drivers\eubakup.sys (CHENGDU YIWO Tech Development Co., Ltd)
DRV - (PSINProt) – C:\WINDOWS\system32\drivers\PSINProt.sys (Panda Security, S.L.)
DRV - (PSINKNC) – C:\WINDOWS\system32\drivers\PSINKNC.sys (Panda Security, S.L.)
DRV - (cbvd) – C:\WINDOWS\system32\drivers\CBVD.sys (COMODO Security Solutions Inc.)
DRV - (reparse) – C:\WINDOWS\system32\drivers\cbreparse.sys (COMODO Security Solutions Inc.)
DRV - (vdbus) – C:\WINDOWS\system32\drivers\vdbus.sys (COMODO Security Solutions Inc.)
DRV - (CBUfs) – C:\WINDOWS\system32\drivers\cbufs.sys (COMODO Security Solutions Inc.)
DRV - (bdisk) – C:\WINDOWS\system32\drivers\bdisk.sys (COMODO Security Solutions Inc.)
DRV - (aswSnx) – C:\WINDOWS\System32\drivers\aswSnx.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (PSINProc) – C:\WINDOWS\system32\drivers\PSINProc.sys (Panda Security, S.L.)
DRV - (PSINFile) – C:\WINDOWS\system32\drivers\PSINFile.sys (Panda Security, S.L.)
DRV - (afcdp) – C:\WINDOWS\system32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman251) Acronis Try&Decide; and Restore Points filter (build 251) – C:\WINDOWS\system32\drivers\tdrpm251.sys (Acronis)
DRV - (timounter) – C:\WINDOWS\system32\drivers\timntr.sys (Acronis)
DRV - (snapman) – C:\WINDOWS\system32\drivers\snapman.sys (Acronis)
DRV - (FNETTBOH) – C:\WINDOWS\system32\drivers\FNETTBOH.SYS (FNet Co., Ltd.)
DRV - (FNETURPX) – C:\WINDOWS\system32\drivers\FNETURPX.SYS (FNet Co., Ltd.)
DRV - (UnlockerDriver5) – E:\Programi\Unlocker\UnlockerDriver5.sys ()
DRV - (SASENUM) – E:\Program Files\SUPERAntiSpyware\SASENUM.SYS ( SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – E:\Program Files\SUPERAntiSpyware\sasdifsv.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASKUTIL) – E:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (uxpatch) – C:\WINDOWS\system32\drivers\uxpatch.sys ()
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINDOWS\system32\drivers\RTL8139.sys (Realtek Semiconductor Corporation)
DRV - (DgiVecp) – C:\WINDOWS\system32\drivers\DGIVECP.SYS (Samsung Electronics Co., Ltd.)
DRV - (Uim_IM) – C:\WINDOWS\system32\drivers\Uim_IM.sys (Paragon)
DRV - (hotcore3) – C:\WINDOWS\system32\drivers\hotcore3.sys (Paragon Software Group)
DRV - (UimBus) – C:\WINDOWS\system32\drivers\UimBus.sys (Windows ® 2000 DDK provider)
DRV - (incdrm) – C:\WINDOWS\System32\drivers\InCDRm.sys (Nero AG)
DRV - (InCDPass) – C:\WINDOWS\system32\drivers\InCDPass.sys (Nero AG)
DRV - (InCDrec) – C:\WINDOWS\System32\drivers\InCDrec.sys (Nero AG)
DRV - (InCDfs) – C:\WINDOWS\System32\drivers\InCDfs.sys (Nero AG)
DRV - (WimFltr) – C:\WINDOWS\system32\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (Aspi32) – C:\WINDOWS\System32\drivers\ASPI32.SYS (Adaptec)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (sfman) Creative SoundFont Manager Driver (WDM) – C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) Creative Interface Manager Driver (WDM) – C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) Creative SB Live! (WDM) – C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) – C:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.delo.si/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…amp;Form=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://search.yahoo.com/search?fr=chr-pand…type=PCAFSI1190
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Search the web"
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.windowsxlive.net"
FF - prefs.js..extensions.enabledItems: {5384767E-00D9-40E9-B72F-9CC39D655D6F}:1.4.1.0
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:2.0.19
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}:[removed]
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [removed]:3.3.3.2
FF - prefs.js..extensions.enabledItems: [removed]:6.0.1289
FF - prefs.js..extensions.enabledItems: {535531f0-c4f8-11df-851a-0800200c9a66}:0.921
FF - prefs.js..extensions.enabledItems: {1a46a8a0-3278-11dd-bd11-0800200c9a66}:1.1.3
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011-09-21 17:31:39 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 10.0.2\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012-02-18 16:38:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2011-03-23 16:04:11 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.16\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2011-03-23 16:04:12 | 000,000,000 | —D | M]

[2008-11-25 14:25:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Extensions
[2012-03-13 19:40:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions
[2011-12-11 13:17:23 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-01-06 16:52:05 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011-03-25 10:05:21 | 000,000,000 | —D | M] (PDF Download) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}
[2012-01-18 15:35:25 | 000,000,000 | —D | M] (EPUBReader) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2012-01-11 10:47:30 | 000,000,000 | —D | M] (myBabylon EnglishBB Community Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}
[2012-02-13 20:51:20 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2010-11-24 23:10:24 | 000,000,000 | —D | M] ("CoolPreviews") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{CE6E6E3B-84DD-4cac-9F63-8D2AE4F30A4B}(2)
[2010-01-27 18:51:11 | 000,000,000 | —D | M] ("BitDefender QuickScanner") – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}
[2011-05-25 09:12:59 | 000,000,000 | —D | M] (Conduit Engine) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\[removed]
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions
[2012-02-13 20:51:19 | 000,000,000 | —D | M] (Panda Security Toolbar) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\4gelnede.default\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}\Setup\bin\PandaSecurityTb_2.0.0.9\$[56]\extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[2012-03-04 13:54:20 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions
[2012-03-01 09:57:04 | 000,000,000 | —D | M] (Forecastfox) – C:\Documents and Settings\Tomas\Application Data\Mozilla\Firefox\Profiles\i5vkoyf2.Feb 2012\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2011-11-11 13:36:19 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012-02-18 16:38:31 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012-02-18 16:38:07 | 000,001,538 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012-02-18 16:38:07 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-02-18 16:38:07 | 000,000,947 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012-02-18 16:38:07 | 000,001,180 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012-02-18 16:38:07 | 000,001,135 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{googl
e:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chro
me&ie;={inputEncoding}&q;={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client
=chrome&hl;={language}&q;={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\18.0.1025.162\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U24 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = E:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: avast! WebRep = C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\6.0.1289_1\

O1 HOSTS File: ([2010-12-09 16:01:42 | 000,000,853 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 216.55.133.9 handybackup.com www.handybackup.com
O1 - Hosts: 69.64.71.218 handybackup.com www.handybackup.com www.softlogica.com softlogica.com
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Panda Security Toolbar) - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files\Panda Security\Panda Security Toolbar\PandaSecurityDx.dll ()
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [DefragTaskBar] E:\Program Files\Ashampoo\Ashampoo Magical Defrag 2\bin\defragTaskBar.exe ()
O4 - HKLM..\Run: [EaseUs Tray] E:\Programi\Todo Backup\bin\TrayNotify.exe (CHENGDU YIWO Tech Development Co., Ltd)
O4 - HKLM..\Run: [InCD] E:\Program Files\Nero 7\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [Panda Security URL Filtering] C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering\Panda_URL_Filtering.exe (Panda Security)
O4 - HKLM..\Run: [PrintDisp] C:\WINDOWS\system32\PrintDisp.exe (ActMask Co.,Ltd - http://www.all2pdf.com)
O4 - HKLM..\Run: [PSUNMain] C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe (Panda Security, S.L.)
O4 - HKLM..\Run: [UsbBoost] C:\Program Files\UsbBoost\TurboHddUsb.exe (FNet Co., Ltd.)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [E7C2B7736BF8C5A56B71BC2B8367796465C7B9C0._service_run] C:\Documents and Settings\Tomas\Local Settings\Application Data\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk = E:\Programi\RocketDock\RocketDock.exe ()
O4 - Startup: C:\Documents and Settings\Tomas\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableCAD = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoWindowsUpdate = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispAppearancePage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoColorChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoSizeChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispBackgroundPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispScrSavPage = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispCPL = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoVisualStyleChoice = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: NoDispSettingsPage = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{9D6763AE-B541-4B67-9260-718B786E9597}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (c:\windows\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O24 - Desktop WallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Tomas\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-11-25 12:13:37 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\AutoRun\command - "" = H:\
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{2a402d51-bada-11dd-91af-806d6172696f}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\AutoRun\command - "" = J:\
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive\command - "" = VirtualBox\Virtualize_This_Key.exe
O33 - MountPoints2\{82b6c184-1022-11e0-a0e8-0030f1337fb0}\Shell\linuxlive2\command - "" = VirtualBox\VirtualBox.exe
O34 - HKLM BootExecute: (autocheck autochk *sprestrt)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: aux - C:\WINDOWS\System32\ctwdm32.dll (Creative Technology Ltd.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)

CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1056

========== Files/Folders - Created Within 30 Days ==========

[2012-04-22 19:44:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2012-04-22 14:38:15 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2012-04-22 14:26:03 | 000,000,000 | —D | C] – C:\WINDOWS\System32\windowspowershell
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Microangelo On Display
[2012-04-21 10:23:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2012-04-21 10:20:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microangelo On Display
[2012-04-18 18:43:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Unknown Device Identifier 8.00
[2012-04-18 08:07:04 | 000,040,776 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:13:43 | 000,278,528 | —- | C] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:12:27 | 000,000,000 | —D | C] – C:\Program Files\C-Media PCI Audio Device
[2012-04-12 12:17:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Local Settings\Application Data\Spotify
[2012-04-12 12:13:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2012-04-11 14:48:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Start Menu\Programs\BricoPacks
[2012-04-04 12:09:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\RocketDock
[2012-04-03 16:14:40 | 000,000,000 | —D | C] – C:\WINDOWS\Prefetch
[2012-04-03 16:08:45 | 000,198,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cintime.dll
[2012-04-03 16:08:42 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_iscii.dll
[2012-04-03 16:08:42 | 000,006,656 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_is2022.dll
[2012-04-03 16:08:41 | 000,218,112 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\c_g18030.dll
[2012-04-03 16:08:21 | 000,045,568 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\browscap.dll
[2012-04-03 16:08:17 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\authfilt.dll
[2012-04-03 16:08:15 | 000,029,184 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asptxn.dll
[2012-04-03 16:08:15 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aspperf.dll
[2012-04-03 16:08:14 | 000,369,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\asp51.dll
[2012-04-03 16:08:14 | 000,331,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\aqueue.dll
[2012-04-03 16:08:13 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\appconf.dll
[2012-04-03 16:08:13 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_aqadmin.dll
[2012-04-03 16:08:12 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0804.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0412.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0411.dll
[2012-04-03 16:08:11 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt040d.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0404.dll
[2012-04-03 16:08:10 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\agt0401.dll
[2012-04-03 16:08:08 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\EXCH_adsiisex.dll
[2012-04-03 16:08:07 | 000,049,664 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adrot.dll
[2012-04-03 16:08:07 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admxprox.dll
[2012-04-03 16:08:06 | 000,029,696 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admexs.dll
[2012-04-03 16:07:59 | 000,007,168 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wamregps.dll
[2012-04-03 16:07:58 | 000,032,827 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptest.exe
[2012-04-03 16:07:58 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\tcptsat.dll
[2012-04-03 16:07:57 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\staxmem.dll
[2012-04-03 16:07:56 | 002,134,528 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpsnap.dll
[2012-04-03 16:07:56 | 000,189,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\smtpadm.dll
[2012-04-03 16:07:55 | 000,020,536 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.dll
[2012-04-03 16:07:55 | 000,016,437 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\shtml.exe
[2012-04-03 16:07:48 | 000,076,800 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\logui.ocx
[2012-04-03 16:07:47 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\isatq.dll
[2012-04-03 16:07:47 | 000,019,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetsloc.dll
[2012-04-03 16:07:47 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\infoadmn.dll
[2012-04-03 16:07:46 | 000,829,440 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.dll
[2012-04-03 16:07:46 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\inetmgr.exe
[2012-04-03 16:07:45 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisui.dll
[2012-04-03 16:07:45 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrtl.dll
[2012-04-03 16:07:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstas.exe
[2012-04-03 16:07:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisrstap.dll
[2012-04-03 16:07:44 | 000,068,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisext51.dll
[2012-04-03 16:07:44 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iismap.dll
[2012-04-03 16:07:44 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\iisreset.exe
[2012-04-03 16:07:44 | 000,006,144 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\ftpsapi2.dll
[2012-04-03 16:07:43 | 000,208,896 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmcsat.dll
[2012-04-03 16:07:43 | 000,020,538 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpremadm.exe
[2012-04-03 16:07:42 | 000,598,071 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpmmc.dll
[2012-04-03 16:07:42 | 000,188,494 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpcount.exe
[2012-04-03 16:07:42 | 000,020,541 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fpexedll.dll
[2012-04-03 16:07:41 | 000,876,653 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awel.dll
[2012-04-03 16:07:41 | 000,109,328 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98swin.exe
[2012-04-03 16:07:41 | 000,014,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp98sadm.exe
[2012-04-03 16:07:40 | 000,049,212 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4awebs.dll
[2012-04-03 16:07:40 | 000,041,020 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avnb.dll
[2012-04-03 16:07:40 | 000,032,826 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4avss.dll
[2012-04-03 16:07:39 | 000,147,513 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4apws.dll
[2012-04-03 16:07:39 | 000,102,509 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4atxt.dll
[2012-04-03 16:07:39 | 000,049,210 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4areg.dll
[2012-04-03 16:07:38 | 000,184,435 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4amsft.dll
[2012-04-03 16:07:38 | 000,082,035 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\fp4anscp.dll
[2012-04-03 16:07:37 | 000,076,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cnfgprts.ocx
[2012-04-03 16:07:37 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\coadmin.dll
[2012-04-03 16:07:36 | 000,275,968 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certwiz.ocx
[2012-04-03 16:07:36 | 000,188,480 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\cfgwiz.exe
[2012-04-03 16:07:36 | 000,094,720 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\certmap.ocx
[2012-04-03 16:07:35 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.dll
[2012-04-03 16:07:35 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\author.exe
[2012-04-03 16:07:34 | 000,290,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\adsiis51.dll
[2012-04-03 16:07:34 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admwprox.dll
[2012-04-03 16:07:33 | 000,016,439 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.exe
[2012-04-03 16:07:32 | 000,020,540 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\admin.dll
[2012-04-03 15:51:55 | 000,020,992 | —- | C] (Realtek Semiconductor Corporation) – C:\WINDOWS\System32\drivers\RTL8139.sys
[2012-04-03 15:45:54 | 000,024,661 | —- | C] (Perle Systems Ltd.) – C:\WINDOWS\System32\spxcoins.dll
[2012-04-03 15:45:54 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irclass.dll
[2012-04-03 13:46:05 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Tomas\Recent
[2012-03-28 15:08:56 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ZIP2FIX
[2012-03-28 12:55:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-03-26 17:05:29 | 000,000,000 | —D | C] – C:\WINDOWS\UXBackup
[2012-03-26 16:42:18 | 000,000,000 | —D | C] – C:\Program Files\UX Pack
[2012-03-26 11:17:41 | 000,000,000 | -H-D | C] – C:\Program Files\WindowsUpdate
[2012-03-26 11:15:15 | 000,000,000 | —D | C] – C:\Program Files\ComPlus Applications
[2012-03-25 12:25:18 | 000,000,000 | -H-D | C] – C:\Program Files\Uninstall Information
[2012-03-24 15:18:06 | 000,000,000 | —D | C] – C:\WINDOWS\SxsCaPendDel
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-04-23 11:55:21 | 000,001,074 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003UA.job
[2012-04-23 11:35:44 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2012-04-23 10:47:16 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2012-04-22 19:53:21 | 000,242,412 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-22 18:55:12 | 000,001,022 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1957994488-1708537768-1606980848-1003Core.job
[2012-04-22 14:27:40 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2012-04-22 12:09:05 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2012-04-22 11:20:14 | 000,109,056 | —- | M] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-04-18 18:43:48 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-18 13:03:38 | 000,113,722 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Got-Zag-Got 2011.pdf
[2012-04-18 08:11:36 | 000,040,776 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\tasks\StartupSlowFix Schedule.job
[2012-04-17 19:11:10 | 000,278,528 | —- | M] (C-Media Corporation) – C:\WINDOWS\CmiPCIUninstall.exe
[2012-04-17 19:11:10 | 000,001,480 | —- | M] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:10:52 | 000,002,421 | —- | M] () – C:\WINDOWS\cmudax3.ini
[2012-04-17 19:10:44 | 000,000,039 | —- | M] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-16 08:09:17 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2012-04-12 12:15:37 | 000,001,834 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 15:17:22 | 000,006,550 | —- | M] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-11 15:17:04 | 000,061,845 | —- | M] () – C:\WINDOWS\BricoPackUninst.cmd
[2012-04-11 15:16:19 | 003,888,054 | —- | M] () – C:\WINDOWS\BricoPack Wallpaper.bmp
[2012-04-11 14:59:00 | 000,001,716 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-06 08:10:45 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012-04-05 08:53:45 | 000,000,573 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 15:56:40 | 000,022,344 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2012-04-04 14:04:48 | 000,001,330 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 16:11:29 | 000,000,287 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2012-04-03 16:06:38 | 000,316,640 | —- | M] () – C:\WINDOWS\WMSysPr9.prx
[2012-04-03 16:06:35 | 000,023,392 | —- | M] () – C:\WINDOWS\System32\nscompat.tlb
[2012-04-03 16:06:35 | 000,016,832 | —- | M] () – C:\WINDOWS\System32\amcompat.tlb
[2012-04-03 16:06:07 | 000,004,161 | —- | M] () – C:\WINDOWS\ODBCINST.INI
[2012-04-03 16:02:30 | 000,432,574 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2012-04-03 16:02:30 | 000,067,530 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2012-04-03 16:01:20 | 000,022,780 | —- | M] () – C:\WINDOWS\System32\emptyregdb.dat
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2012-04-03 13:07:47 | 000,000,604 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-31 16:17:37 | 000,001,057 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2012-03-26 17:18:48 | 002,113,752 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012-03-25 13:51:45 | 000,001,695 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2012-03-25 13:49:57 | 000,002,638 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2012-03-25 09:09:44 | 074,755,096 | -H– | M] () – C:\WINDOWS\cbufsscansysdmp.bin
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[3 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\Tomas\*.tmp files -> C:\Documents and Settings\Tomas\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-04-22 19:53:20 | 000,242,412 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\runscanner.run
[2012-04-18 18:43:48 | 000,000,079 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Huntersoft Free Download.url
[2012-04-17 19:13:48 | 000,001,480 | —- | C] () – C:\WINDOWS\Cmicnfg3.ini.cfg
[2012-04-17 19:13:45 | 000,000,039 | —- | C] () – C:\WINDOWS\System\CmiInst.Ini
[2012-04-17 19:13:22 | 000,002,421 | —- | C] () – C:\WINDOWS\cmudax3.ini
[2012-04-12 12:15:40 | 000,001,840 | —- | C] () – C:\Documents and Settings\Tomas\Start Menu\Programs\Spotify.lnk
[2012-04-12 12:15:37 | 000,001,834 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Spotify.lnk
[2012-04-11 14:59:00 | 000,001,716 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Help.lnk
[2012-04-11 14:56:38 | 000,000,808 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Vista Inspirat 2 Config.lnk
[2012-04-11 14:48:31 | 000,006,550 | —- | C] () – C:\WINDOWS\BricoPackFoldersDelete.cmd
[2012-04-05 08:53:45 | 000,000,573 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RocketDock.lnk
[2012-04-04 14:04:48 | 000,001,330 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Shortcut to Show Desktop.lnk
[2012-04-03 15:46:14 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2012-04-03 15:45:43 | 000,144,484 | —- | C] () – C:\WINDOWS\System32\dllcache\netfx.cat
[2012-04-03 15:45:43 | 000,034,747 | —- | C] () – C:\WINDOWS\System32\dllcache\mediactr.cat
[2012-04-03 15:45:43 | 000,026,991 | —- | C] () – C:\WINDOWS\System32\dllcache\msn7.cat
[2012-04-03 15:45:43 | 000,014,433 | —- | C] () – C:\WINDOWS\System32\dllcache\msn9.cat
[2012-04-03 15:45:43 | 000,010,027 | —- | C] () – C:\WINDOWS\System32\dllcache\MSTSWEB.CAT
[2012-04-03 15:45:43 | 000,008,574 | —- | C] () – C:\WINDOWS\System32\dllcache\IASNT4.CAT
[2012-04-03 15:45:43 | 000,007,382 | —- | C] () – C:\WINDOWS\System32\dllcache\OEMBIOS.CAT
[2012-04-03 15:45:42 | 000,797,189 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5IIS.CAT
[2012-04-03 15:45:42 | 000,399,645 | —- | C] () – C:\WINDOWS\System32\dllcache\MAPIMIG.CAT
[2012-04-03 15:45:42 | 000,037,484 | —- | C] () – C:\WINDOWS\System32\dllcache\MW770.CAT
[2012-04-03 15:45:42 | 000,034,063 | —- | C] () – C:\WINDOWS\System32\dllcache\FP4.CAT
[2012-04-03 15:45:42 | 000,016,535 | —- | C] () – C:\WINDOWS\System32\dllcache\IMS.CAT
[2012-04-03 15:45:42 | 000,013,472 | —- | C] () – C:\WINDOWS\System32\dllcache\HPCRDP.CAT
[2012-04-03 15:45:42 | 000,012,363 | —- | C] () – C:\WINDOWS\System32\dllcache\MSMSGS.CAT
[2012-04-03 15:45:41 | 002,144,487 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5.CAT
[2012-04-03 15:45:40 | 000,522,220 | —- | C] () – C:\WINDOWS\System32\dllcache\NT5INF.CAT
[2012-04-03 13:07:46 | 000,000,604 | —- | C] () – C:\Documents and Settings\Tomas\Desktop\Shortcut to CCEnhancer-3.1.exe.lnk
[2012-03-26 16:42:18 | 000,069,632 | —- | C] () – C:\WINDOWS\System32\moveex.exe
[2012-03-26 11:05:13 | 001,296,669 | —- | C] () – C:\WINDOWS\System32\dllcache\SP3.CAT
[2012-03-17 23:16:59 | 000,000,227 | —- | C] () – C:\WINDOWS\wininit.ini
[2012-03-17 19:09:40 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2012-03-15 10:39:44 | 074,755,096 | -H– | C] () – C:\WINDOWS\cbufsscansysdmp.bin
[2012-02-16 18:00:07 | 000,043,784 | —- | C] () – C:\WINDOWS\System32\drivers\EUBKMON.sys
[2012-02-13 20:50:13 | 000,000,264 | —- | C] () – C:\WINDOWS\System32\PSUNCpl.dat
[2012-01-08 10:36:57 | 002,113,752 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011-09-25 17:42:16 | 000,001,057 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\vso_ts_preview.xml
[2011-06-16 20:11:20 | 000,001,390 | —- | C] () – C:\WINDOWS\CDRipper.ini
[2011-03-16 17:38:33 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2011-01-21 09:58:24 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010-12-13 16:57:55 | 000,683,801 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.exe
[2010-12-13 16:57:55 | 000,018,695 | —- | C] () – C:\Documents and Settings\Tomas\Application Data\unins000.dat
[2010-10-22 10:36:45 | 000,000,185 | —- | C] () – C:\WINDOWS\System32\msblcd32.dll
[2010-10-22 10:22:03 | 000,109,056 | —- | C] () – C:\Documents and Settings\Tomas\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-10-05 15:01:04 | 001,391,616 | —- | C] () – C:\WINDOWS\System32\ActPDF.dll
[2010-10-05 15:00:50 | 000,691,200 | —- | C] () – C:\WINDOWS\System32\PrintLog.exe
[2010-10-05 15:00:50 | 000,524,288 | —- | C] () – C:\WINDOWS\System32\PrtPass.exe
[2010-09-13 13:59:22 | 000,000,228 | —- | C] () – C:\WINDOWS\System32\edacded0_x.dat
[2010-05-25 21:49:22 | 000,000,192 | -H– | C] () – C:\WINDOWS\€nlsPreferences.dat

========== LOP Check ==========

[2010-12-08 15:28:45 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Acronis
[2010-09-26 15:31:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alien Skin
[2008-12-01 20:48:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ashampoo
[2011-09-21 17:31:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AVAST Software
[2010-11-26 21:12:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro
[2010-10-19 10:32:36 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\EMP
[2010-12-08 13:16:12 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\FNET
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Iceni
[2012-04-21 10:23:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Microangelo On Display
[2011-01-30 13:50:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NovaStor
[2011-04-12 17:46:25 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security
[2012-04-23 11:41:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Panda Security URL Filtering
[2009-12-06 17:00:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PhotoGenie
[2011-01-25 17:43:26 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Power Soft
[2011-04-06 10:32:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Softland
[2010-10-25 16:59:42 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Stardock
[2012-04-22 18:34:14 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2008-11-28 15:33:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\vsosdk
[2011-10-27 14:38:22 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\{51019853-129C-4EDE-9030-D5FD7BBD9AD0}
[2010-12-08 20:06:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Acronis
[2010-09-26 15:37:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Alien Skin
[2011-06-27 13:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Amazon
[2011-01-23 17:34:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ASCOMP Software
[2012-03-23 14:18:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Audacity
[2009-06-17 17:11:13 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\com.adobe.ExMan
[2010-11-26 21:07:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\DAEMON Tools Pro
[2010-11-23 16:26:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Desktop Sidebar
[2012-04-23 12:08:11 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Dropbox
[2012-04-22 14:38:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ElevatedDiagnostics
[2008-11-25 14:51:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Foxit
[2009-09-28 12:58:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\FPC
[2012-02-21 21:34:23 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Genie-soft
[2010-10-17 07:57:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\gtk-2.0
[2010-10-05 15:00:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Iceni
[2011-04-07 11:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\IGC
[2010-11-09 21:39:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\ImgBurn
[2012-03-18 16:35:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\JAM Software
[2010-01-09 10:19:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\LightZone
[2012-03-21 18:44:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Magnifier
[2009-03-17 19:52:19 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage PS
[2009-03-17 14:31:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\NeatImage SL
[2008-11-25 13:26:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Novosoft
[2011-04-12 17:58:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Panda Security
[2012-02-18 08:27:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\pandasecuritytb
[2009-08-26 10:57:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Participatory Culture Foundation
[2009-08-28 13:57:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\PCF-VLC
[2010-01-28 18:51:36 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\QuickScan
[2010-11-24 23:10:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Rainmeter(2)
[2010-01-28 15:05:57 | 000,000,000 | RHSD | M] – C:\Documents and Settings\Tomas\Application Data\RECYCLER
[2012-04-22 19:44:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Runscanner.net
[2011-04-05 17:04:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Softland
[2012-03-28 13:01:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\SPlayer
[2012-04-12 12:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Spotify
[2010-10-25 17:02:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Stardock
[2012-02-14 13:56:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\thecleaner
[2011-02-24 13:23:09 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uniblue
[2008-12-10 21:50:52 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\URSoft
[2012-04-22 13:07:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\uTorrent
[2012-04-03 13:46:46 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\Vso
[2008-12-10 19:38:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\WordWeb
[2012-03-23 14:29:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Tomas\Application Data\XnView
[2012-04-17 19:30:00 | 000,000,398 | —- | M] () – C:\WINDOWS\Tasks\StartupSlowFix Schedule.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2012-04-03 15:59:45 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2008-11-25 12:13:37 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2012-02-18 12:40:03 | 000,196,297 | -HS- | M] () – C:\ESLDR
[2012-02-18 12:40:07 | 000,008,192 | -HS- | M] () – C:\ESLOADLX
[2012-02-16 18:15:20 | 000,480,768 | -HS- | M] () – C:\EUMONBMP.SYS
[2012-04-23 11:35:43 | 1073,274,880 | -HS- | M] () – C:\hiberfil.sys
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010-07-01 10:12:13 | 000,000,109 | —- | M] () – C:\mbam-error.txt
[2008-11-25 12:13:37 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2011-09-21 16:49:28 | 000,006,272 | —- | M] () – C:\NanoRepository.bin
[2008-04-13 22:13:04 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008-04-14 00:01:44 | 000,250,048 | RHS- | M] () – C:\ntldr
[2007-08-12 07:59:28 | 000,375,054 | —- | M] () – C:\Splash.bmp
[2012-02-16 23:13:44 | 000,004,096 | -HS- | M] () – C:\{96391608-8CA9-438F-A3BF-1846759A831E}.CBM

< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2012-04-03 16:04:44 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2010-06-21 01:10:06 | 000,028,672 | —- | M] (ActMask Co.,Ltd) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ActPrint.dll
[2008-07-06 14:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008-07-06 12:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
[2008-01-10 14:16:58 | 000,019,968 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\system32\spool\prtprocs\w32x86\ssp2mpc.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011-09-06 22:45:29 | 000,041,184 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >
[2010-06-09 17:15:12 | 000,000,174 | —- | M] () – C:\Documents and Settings\All Users\Favorites\The NeoSmart Files.url

< %APPDATA%\Microsoft\*.* >
[2010-09-18 12:35:41 | 000,001,674 | -H– | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\LastFlashConfig.WFC

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2012-04-03 17:43:12 | 000,294,912 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2012-04-03 15:32:49 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2012-04-03 17:43:12 | 025,427,968 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2012-04-03 17:43:12 | 006,029,312 | —- | M] () – C:\WINDOWS\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2012-04-03 16:06:49 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012-03-25 12:34:40 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2008-11-25 12:20:21 | 000,000,079 | —- | M] () – C:\Documents and Settings\Tomas\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2011-02-02 21:14:36 | 001,601,024 | —- | M] (Mobatek) – C:\Documents and Settings\Tomas\Desktop\MobaLiveCD_v2.1.exe
[2012-02-16 11:27:17 | 000,076,517 | —- | M] () – C:\Documents and Settings\Tomas\Desktop\Patch.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-03-24 19:41:03

========== Alternate Data Streams ==========

@Alternate Data Stream - 236 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 188 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:21654C57
@Alternate Data Stream - 164 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:B3D74A13
@Alternate Data Stream - 153 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DBAC2017
@Alternate Data Stream - 148 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:93C2F41D
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C8B8CEBD
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0CFF5F08
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:89EAFAFC
@Alternate Data Stream - 108 bytes -> C:\WINDOWS:

< End of report >

OTL Extras logfile created on: 2012-04-23 12:11:13 - Run 1
OTL by OldTimer - Version 3.2.41.0 Folder = E:\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 0000041D | Country: Sweden | Language: SVE | Date Format: yyyy-MM-dd

1023,49 Mb Total Physical Memory | 310,45 Mb Available Physical Memory | 30,33% Memory free
2,40 Gb Paging File | 1,42 Gb Available in Paging File | 59,13% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072C:\pagefile.sys 2 2 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14,65 Gb Total Space | 0,71 Gb Free Space | 4,85% Space Free | Partition Type: NTFS
Drive D: | 149,05 Gb Total Space | 19,42 Gb Free Space | 13,03% Space Free | Partition Type: NTFS
Drive E: | 59,88 Gb Total Space | 9,69 Gb Free Space | 16,18% Space Free | Partition Type: NTFS

Computer Name: 8C9EE2AF2 | User Name: Tomas | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Browse with XnView] – Reg Error: Value error.
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "E:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusOverride" = 0
"FirewallOverride" = 0
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"5353:TCP" = 5353:TCP:*:Enabled:Adobe CSI CS4
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" = C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4 – (Adobe Systems Incorporated)
"E:\Program Files\Novosoft\Handy Backup\backup.exe" = E:\Program Files\Novosoft\Handy Backup\backup.exe:*:Enabled:Handy Backup 6.0.8.0 – (Novosoft LLC)
"E:\Program Files\Novosoft\Handy Backup\hbagent.exe" = E:\Program Files\Novosoft\Handy Backup\hbagent.exe:*:Enabled:Handy Backup 6.0.8 Agent – (Novosoft LLC)
"E:\Program Files\uTorrent\uTorrent.exe" = E:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"E:\Program Files\Babylon\Babylon-Pro\Babylon.exe" = E:\Program Files\Babylon\Babylon-Pro\Babylon.exe:*:Enabled:Babylon
"E:\Program Files\spotify.exe" = E:\Program Files\spotify.exe:*:Enabled:Spotify
"E:\Program Files\Spotify\spotify.exe" = E:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify
"C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe" = C:\Documents and Settings\Tomas\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe:*:Enabled:Octoshape add-in for Adobe Flash Player – (Octoshape ApS)
"E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" = E:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe:*:Enabled:SUPERAntiSpyware Free Edition – (SUPERAntiSpyware.com)
"E:\Program Files\Alwil Software\Avast4\ashAvast.exe" = E:\Program Files\Alwil Software\Avast4\ashAvast.exe:*:Enabled:avast! Antivirus
"C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe" = C:\Documents and Settings\Tomas\Application Data\Dropbox\bin\Dropbox.exe:*:Enabled:Dropbox – (Dropbox, Inc.)
"E:\Program Files\Miro\Miro_Downloader.exe" = E:\Program Files\Miro\Miro_Downloader.exe:*:Disabled:Miro_Downloader
"E:\Program Files\VideoLAN\VLC\vlc.exe" = E:\Program Files\VideoLAN\VLC\vlc.exe:*:Enabled:VLC media player – ()
"C:\Program Files\Spotify\spotify.exe" = C:\Program Files\Spotify\spotify.exe:*:Enabled:Spotify – (Spotify Ltd)
"E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" = E:\Program Files\Malwarebytes' Anti-Malware\mbam.exe:*:Enabled:Malwarebytes' Anti-Malware
"E:\Programi\Todo Backup\bin\Agent.exe" = E:\Programi\Todo Backup\bin\Agent.exe:*:Enabled:Agent.exe – (CHENGDU YIWO Tech Development Co., Ltd)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0D67A4E4-5BE0-4C9A-8AD8-AB552B433F23}" = Adobe Setup
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{197A3012-8C85-4FD3-AB66-9EC7E13DB92E}" = Adobe AIR
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{235674B0-A35F-4811-8A8F-E8F42A919EA3}" = PhotoPresets with One-Click WOW!
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 24
"{2AEDC172-479F-47AE-8A48-A0524D4AED5B}_is1" = Inpaint 3.0
"{2B04D44F-1D1B-4E0E-8431-D04F87C21033}" = Nero 7 Essentials
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{531BC138-F1F7-496B-879C-F039ECEF438D}" = Adobe Photoshop Lightroom 2
"{61A15405-48D5-4F59-966B-A0139FC7C69C}" = Handy Backup
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{67B195ED-5174-4CD8-8B3A-A0B4DA3E48B7}" = LRViewer
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{72FC0445-FE6D-4E12-815B-3A8C5E3704DA}_is1" = GroupMail :: Free Edition
"{75480068-162F-4D6B-B38E-76606A4E5320}_is1" = Dolphin Futures XPS Viewer version 1.1.0
"{7B4B0AA9-F97E-49C4-AE6F-D40580B65A22}" = onOne PerfectPresets
"{8679D366-D73F-4303-92F7-853B13C1F424}" = Microangelo On Display
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8D273DE5-ABFA-4BD0-A9D7-EE9C971438C4}_is1" = PDF-Viewer
"{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}" = UxStyle Core Beta
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{90120000-0010-041D-0000-0000000FF1CE}" = Microsoft Software Update for Web Folders (Swedish) 12
"{90120000-0015-041D-0000-0000000FF1CE}" = Microsoft Office Access MUI (Swedish) 2007
"{90120000-0015-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-041D-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Swedish) 2007
"{90120000-0016-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-041D-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Swedish) 2007
"{90120000-0018-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0019-041D-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (Swedish) 2007
"{90120000-0019-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001A-041D-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (Swedish) 2007
"{90120000-001A-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-041D-0000-0000000FF1CE}" = Microsoft Office Word MUI (Swedish) 2007
"{90120000-001B-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040B-0000-0000000FF1CE}" = Microsoft Office Proof (Finnish) 2007
"{90120000-001F-041D-0000-0000000FF1CE}" = Microsoft Office Proof (Swedish) 2007
"{90120000-001F-0424-0000-0000000FF1CE}" = Microsoft Office Proof (Slovenian) 2007
"{90120000-002C-041D-0000-0000000FF1CE}" = Microsoft Office Proofing (Swedish) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0044-041D-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (Swedish) 2007
"{90120000-0044-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-041D-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Swedish) 2007
"{90120000-006E-041D-0000-0000000FF1CE}_ENTERPRISE_{8C2A0B2D-382B-428C-9E8D-247D31B22201}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-041D-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Swedish) 2007
"{90120000-00A1-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00BA-041D-0000-0000000FF1CE}" = Microsoft Office Groove MUI (Swedish) 2007
"{90120000-00BA-041D-0000-0000000FF1CE}_ENTERPRISE_{1AEE207F-E4DC-4A6C-9ACD-D1218F08B442}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-00AF-041D-0000-0000000FF1CE}" = Microsoft PowerPoint Viewer
"{9999C416-FE39-4533-B280-0039E11B59F5}" = WinXP Manager
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B5F8FCE2-1677-4370-A857-4976E5A95209}" = Topaz Vivacity
"{B789FA51-6A71-408F-92DE-EDE4A517B8F9}_is1" = RAR Password Unlocker 4.2.0.0
"{B79E9FF2-D932-4FD5-BCAF-4DE6F2FBE521}" = COMODO BackUp
"{BA789040-B54B-4E7A-BC62-B6719E84CE9B}" = Active@ Disk Image
"{BE2ED609-7C07-4F6B-8E83-3800F8A133D6}" = PhotoPresets Wow Effects for Lightroom
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2F1F96A-057E-5819-B52E-FEA1D1D2933B}" = Acronis True Image Home
"{C887C75D-2636-41F6-BB7B-FD4B0314C1E1}" = Paragon Partition Manager 9.0 Professional
"{C9E4932C-8417-4E4C-A0E3-EE534810AB4D}" = ClearType Tuning Control Panel Applet
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CECCF8B1-F595-4845-9AA6-1EC57B9BECBA}_is1" = STP Viewer 2.3
"{CF6C1B06-4F86-4C41-BD21-9E40500006B5}" = COMODO Online Storage
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.2
"{DB6AB705-C9BD-40E3-8929-2EA57F36A4FF}_is1" = ConvertXtoDVD 4.1.19.365
"{DD7CDE4F-23DC-4C51-B749-0198C50F352D}_is1" = PDF to Word
"{E1180142-3B31-4DCC-9D27-7AC2D37662BF}" = LightScribe 1.4.124.1
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{FD0F8123-9035-44B0-B331-2596979E74ED}_is1" = Book Collector
"{FD93D80D-CB42-483A-924B-CC44D0D32E40}_is1" = ZIP2FIX version 1.0
"{FEB2D0CA-9912-4AA1-8FBE-CFD852F9F1FC}" = Panda Cloud Antivirus
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"43442AE9-6512-4392-B5DD-9167BECD1114_is1" = Infix 4.22
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Alien Skin Bokeh 2" = Alien Skin Bokeh 2
"Amazon Kindle" = Amazon Kindle
"Ashampoo Magical Defrag 2_is1" = Ashampoo Magical Defrag 2
"ASP32 slovarji 29in1_is1" = ASP32 slovarji 29in1
"avast" = avast! Free Antivirus
"CCleaner" = CCleaner
"C-Media PCI Sound" = C-Media PCI Audio Device
"Driver Checker_is1" = Driver Checker v2.7.4
"EaseUS Todo Backup Free 4.0_is1" = EaseUS Todo Backup Free 4.0
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPUB to Kindle converter_is1" = EPUB to Kindle converter version 1.3.6.0
"Exposure" = Alien Skin Exposure
"Foxit Reader" = Foxit Reader
"Fujidirekt Fotoservice_is1" = Fujidirekt Fotoservice 2.6
"iCare Data Recovery_is1" = iCare Data Recovery 4.0
"ImageConverter Plus_is1" = ImageConverter Plus 7.1
"ImgBurn" = ImgBurn
"IrfanView" = IrfanView (remove only)
"jv16 PowerTools 2009_is1" = jv16 PowerTools 2009
"LinuxLive USB Creator" = LinuxLive USB Creator
"Magic DVD Copier_is1" = Magic DVD Copier Version 5.0.0
"Magic ISO Maker v5.5 (build 0272)" = Magic ISO Maker v5.5 (build 0272)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox 10.0.2 (x86 en-GB)" = Mozilla Firefox 10.0.2 (x86 en-GB)
"Outlook Express Backup_is1" = Outlook Express Backup V6.5
"Pack Vista Inspirat 2" = Pack Vista Inspirat 2 1.0
"Panda Cloud Antivirus" = Panda Cloud Antivirus
"Panda Security URL Filtering" = Panda Security URL Filtering
"pandasecuritytb" = Panda Security Toolbar
"PeerGuardian_is1" = PeerGuardian 2.0
"Revo Uninstaller" = Revo Uninstaller 1.83
"RocketDock_is1" = RocketDock 1.3.5
"Samsung ML-1640 Series" = Samsung ML-1640 Series
"SilverFast Canon-SE TWAIN" = SilverFast Canon-SE TWAIN 6.6.0r5
"Simpo PDF to Word_is1" = Simpo PDF to Word 2.1.0.0
"Snapshot" = Snapshot (remove only)
"Speccy" = Speccy
"The Cleaner_is1" = The Cleaner 2012
"Toolbar Cleaner" = Toolbar Cleaner 1.0
"TreeSize Free_is1" = TreeSize Free V2.7
"Unknown Device Identifier_is1" = Unknown Device Identifier 8.00
"Unlocker" = Unlocker 1.9.1
"UsbBoost" = UsbBoost
"Windows Media Format Runtime" = Windows Media Format Runtime
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"VirtualCloneDrive" = VirtualCloneDrive
"Viveza 2" = Viveza 2
"VLC media player" = VLC media player 1.1.5
"VSO PhotoOnWeb_is1" = VSO PhotoOnWeb 0.9.1d
"VueScan" = VueScan
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Octoshape add-in for Adobe Flash Player" = Octoshape add-in for Adobe Flash Player
"Spotify" = Spotify
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2012-03-23 08:37:41 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application siw.exe, version 2010.7.14.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2012-03-24 09:18:11 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2012-03-24 11:17:42 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 11307
Description = Produkt: Microsoft Office Enterprise 2007 – Fel 1307.Det finns inte
tillräckligt med diskutrymme för att installera den här filen: C:\WINDOWS\Installer\4e56f4.msp.
Frigör diskutrymme och klicka på Försök igen, eller klicka på Avbryt om du vill
avsluta.

Error - 2012-03-24 11:31:11 | Computer Name = 8C9EE2AF2 | Source = MsiInstaller | ID = 1024
Description = Product: Microsoft Office Enterprise 2007 - Update 'Microsoft Office
2007 Service Pack 2 (SP2)' could not be installed. Error code 1603. Windows Installer
can create logs to help troubleshoot issues with installing software packages.
Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127

Error - 2012-03-25 02:11:23 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application explorer.exe, version 6.0.2900.5512, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 2012-03-25 09:50:32 | Computer Name = 8C9EE2AF2 | Source = Application Error | ID = 1000
Description = Faulting application msimn.exe, version 6.0.2900.5512, faulting module
msoe.dll, version 6.0.2900.5931, fault address 0x00016789.

Error - 2012-03-25 13:58:06 | Computer Name = 8C9EE2AF2 | Source = MSDTC | ID = 4404
Description = MS DTC Tracing infrastructure : the initialization of the tracing
infrastructure failed. Internal Information : msdtc_trace : File: d:\comxp_sp3\com\com1x\dtc\dtc\trace\src\tracelib.cpp,
Line: 1115, StartTrace Failed, hr=0x80070070

Error - 2012-03-25 16:04:13 | Computer Name = 8C9EE2AF2 | Source = Application Hang | ID = 1002
Description = Hanging application CBU.exe, version 1.0.0.471, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 2012-04-05 04:16:14 | Computer Name = 8C9EE2AF2 | Source = EventSystem | ID = 4614
Description = The COM+ Event System detected an inconsistency in its internal state.
The assertion "GetLastError() == 122L" failed at line 201 of f:\xpsp3\com\com1x\src\events\shared\sectools.cpp.
Please contact Microsoft Product Support Services to report this erro

[ OSession Events ]
Error - 2011-05-03 01:20:50 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 83
seconds with 60 seconds of active time. This session ended with a crash.

Error - 2011-05-03 01:22:05 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2011-05-03 01:24:02 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 10
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2011-05-03 01:32:08 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 468
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2011-05-04 08:01:48 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 54
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2011-05-04 08:03:57 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 6
seconds with 0 seconds of active time. This session ended with a crash.

Error - 2011-11-11 06:27:04 | Computer Name = 8C9EE2AF2 | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 671842
seconds with 900 seconds of active time. This session ended with a crash.

[ System Events ]
Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.

Error - 2012-04-23 02:06:55 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The avast! iAVS4 Control Service service failed to start due to the
following error: %%3

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Acronis Scheduler2 Service service failed to start due to the
following error: %%3

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Comodo Online Storage Service service failed to start due to the
following error: %%3

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The EaseUS Agent service failed to start due to the following error:
%%3

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Guard Agent service failed to start due to the following error:
%%3

Error - 2012-04-23 05:37:22 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7000
Description = The Novosoft Backup Network Coordinator service failed to start due
to the following error: %%3

Error - 2012-04-23 05:39:13 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7022
Description = The Panda Cloud Antivirus Service service hung on starting.

Error - 2012-04-23 05:39:14 | Computer Name = 8C9EE2AF2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
sptd


< End of report >

**In any case where you happen to be busy or unable to give us a reply, we would be grateful if you keep us informed in advance and we will be more than happy to wait. Failure to do so we will have your thread closed in THREE(3) days. :)


Hello there, yaniz

:welcome:

I'm Conspire, I'll be glad to help you with your computer problems.

Please observe these rules while we work:
  • Read the entire procedure
  • It is important to perform ALL actions in sequence.
  • If you don't know, stop and ask! Don't keep going on.
  • Please reply to this thread. Do not start a new topic.
  • Stick with me till you're given the all clear.
  • Remember, absence of symptoms does not mean the infection is all gone.
  • Don't attempt to clean your computer with any tools other than the ones I ask you to use during the cleanup process.

IMPORTANT NOTE : Please do not delete anything unless instructed to. Remember to backup all your important data(if possible) before moving on.

—————————————————————————————————

From the sounds of it, it seems that your laptop is experiencing overheat issue and lack of C: space.

Do you hear a loud fan noise before your laptop shuts down unexpectedly?

—————————————————————————————————
Conspire, thank you for your reply! The computer in question is a pc not a laptop. No, there is not any different fan noise to be heard when the pc shuts down. There is no overheat issue either, but I have been running out of c: space for quite some time now. It runs down to 200 mb, then I free up space with CCleaner to 2-3 gb and so it goes on. I have the impression that something is eating my free space on c: that slows down the pc.. Can this lack of space cause the pc to reboot randomly? Thank you for any help you can provide.
As far as I know, lack of space doesn't cause reboot. But I won't say it is entirely impossible too.

Let's run a rootkit scanner.

[external image: Posted Image]
  • Please download GMER from one of the following locations, and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zip Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Extract the contents of the zipped file to desktop (applicable only to Zip mirror) .
  • Double click [external image: Posted Image] or [external image: Posted Image] on your desktop.
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    [external image: Posted Image]

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
I noticed you have two AV installed, and it is never a good idea to have two to run together at the same time. Uninstall one of them. Either Avast or Panda - it's your choice.

Also we need to reset your host file.

Please download HostsXpert
  • Unzip HostsXpert to it's own folder in a convenient place such as C:\HostsXpert
  • Run: HostsXpert.exe
  • Click: Restore MS Hosts File
  • Click: Replace
  • Click: OK
  • Click: Make ReadOnly
  • Close HostsXpert.

Note: If a custom Hosts file was in place, you will have to run those programs again to reset detections.
If needed Tutorial
Following your instructions I installed HostsXpert but after having pressed "Restore MS Hosts File" a dialogue with the text "Press OK to Restore original Hosts File" surfaced. I pressed OK and nothing else happens! The PC is running incredibly slow and a lot of things are unresponsive a minute or two such as browsers, folders … Can it be a hardware issue?
It is more of the critically low space in C: drive because as a general rule of thumb we need at least 15% of space for Windows to operate. In your case you only have 4.85% of free space which is not enough. Your log doesn't show any signs of malware and I would say the best thing you could do is get a new hard drive.
Dear Conspire, Thank you very much for all help you've provided. I will expand the partition c: by stealing some space from partition e:. Hope this will solve the problem. Yesterday I disabled the autoreboot, so instead of a reboot a blue screen appeard with the following info: ***STOP: 0x0000007E (0x0000005, 0x8044D9A69, 0xF716CB48, 0xF716C844) Has this anything to do with low disk space?
Dear Conspire, Thank you very much for all help you've provided. I will expand the partition c: by stealing some space from partition e:. Hope this will solve the problem. Yesterday I disabled the autoreboot, so instead of a reboot a blue screen appeard with the following info: ***STOP: 0x0000007E (0x0000005, 0x8044D9A69, 0xF716CB48, 0xF716C844) Has this anything to do with low disk space?
I cant interpret the code just like that and usually we will need a mini dump file to analyse what is really going wrong. I hope the increase in space C will help. Do note that for some reason My computer has decided to die on me today. I am now replying through my ipad so this will even make things difficult for me to reply you as I do not have other laptop to access and do a proper reply. Im trying to get things sorted out as soon as possible so that I dont have to delay your time. Your understanding is much appreciated at this point of time. I will let you know when i can get things back up and running. Thanks
The computer was running all day long yesterday but eventually rebooted in the evening (this is an improvement since it rebooted 3-5 times per day earlier). It is however running extremely slow (it takes 15 to boot, 5 min to launch, Outlook Express, browsers and so on …) I have scanned for malware with Malwarebytes, Superantispyware and with the tool recommended by you etc., but the pc seems t be clean. My free space on c: is 1,5 Gb (haven't done the partition resizing yet). I now suspect a hardware failure. Could it be the harddrive or the RAM? I know, it wouldn't be first things to suspect but anyway?
Well did the hard drive make any noise? That would be a clear indicator of failing hardware. But in most cases I would say it's the hard drive. Generally the lifespan is about 5 years until you see some performance degradation.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI