Hello Conspire
Thank you for your help
Please find below the files you requested
Regards
OTL logfile created on: 16/06/2012 09:09:47 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\Paul\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.50 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 64.81% Memory free
8.74 Gb Paging File | 7.44 Gb Available in Paging File | 85.06% Paging File free
Paging file location(s): c:\pagefile.sys 5373 5373 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 21.59 Gb Free Space | 28.97% Space Free | Partition Type: NTFS
Drive D: | 104.43 Gb Total Space | 66.65 Gb Free Space | 63.83% Space Free | Partition Type: NTFS
Drive E: | 95.39 Gb Total Space | 75.34 Gb Free Space | 78.97% Space Free | Partition Type: NTFS
Drive F: | 30.01 Gb Total Space | 27.37 Gb Free Space | 91.22% Space Free | Partition Type: NTFS
Drive I: | 564.01 Gb Total Space | 558.24 Gb Free Space | 98.98% Space Free | Partition Type: NTFS
Drive J: | 292.97 Gb Total Space | 144.39 Gb Free Space | 49.29% Space Free | Partition Type: NTFS
Drive K: | 465.75 Gb Total Space | 408.23 Gb Free Space | 87.65% Space Free | Partition Type: NTFS
Drive L: | 7.47 Gb Total Space | 5.31 Gb Free Space | 71.05% Space Free | Partition Type: FAT32
Drive O: | 7.81 Mb Total Space | 4.23 Mb Free Space | 54.13% Space Free | Partition Type: NTFS
Drive Q: | 170.01 Gb Total Space | 72.54 Gb Free Space | 42.67% Space Free | Partition Type: NTFS
Drive R: | 170.01 Gb Total Space | 103.67 Gb Free Space | 60.98% Space Free | Partition Type: NTFS
Drive S: | 158.60 Gb Total Space | 108.12 Gb Free Space | 68.17% Space Free | Partition Type: NTFS
Drive U: | 200.01 Gb Total Space | 110.62 Gb Free Space | 55.31% Space Free | Partition Type: NTFS
Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Paul\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
PRC - C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
PRC - C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
PRC - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
PRC - C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe ()
PRC - C:\Program Files\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
PRC - C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
PRC - C:\Windows\System32\CtHelper.exe (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
PRC - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
PRC - C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Creative\ShareDLL\CTNotify.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Creative\ShareDLL\Mediadet.exe (Creative Technology Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\294d439cfe959b5528ca81d37d3d502f\System.Data.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\Maps\R66Api.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.7.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\sqlite3.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetect.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDetectLegend.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\htcDisk.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\OutputLog.dll ()
MOD - C:\Program Files\HTC\HTC Sync 3.0\fdHttpd.dll ()
MOD - C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
MOD - C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe ()
MOD - C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
========== Win32 Services (SafeList) ==========
SRV - (SBSDWSCService) – C:\Program Files\Spybot File not found
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (PassThru Service) – C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe ()
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (afcdpsrv) – C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe (Acronis)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (SbieSvc) – C:\Program Files\Sandboxie\SbieSvc.exe (SANDBOXIE L.T.D)
SRV - (AcrSch2Svc) – C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe (Acronis)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (OS Selector) – C:\Program Files\Acronis\DiskDirector\OSS\reinstall_svc.exe ()
SRV - (EhttpSrv) – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe (ESET)
SRV - (ekrn) – C:\Program Files\ESET\ESET Smart Security\ekrn.exe (ESET)
SRV - (SwitchBoard) – C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (CTAudSvcService) – C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (CTSBLFX.DLL) – system32\CTSBLFX.DLL File not found
DRV - (CTHWIUT.DLL) – system32\CTHWIUT.DLL File not found
DRV - (CTEXFIFX.DLL) – system32\CTEXFIFX.DLL File not found
DRV - (CTERFXFX.DLL) – system32\CTERFXFX.DLL File not found
DRV - (CTEDSPSY.DLL) – system32\CTEDSPSY.DLL File not found
DRV - (CTEDSPIO.DLL) – system32\CTEDSPIO.DLL File not found
DRV - (CTEDSPFX.DLL) – system32\CTEDSPFX.DLL File not found
DRV - (CTEAPSFX.DLL) – system32\CTEAPSFX.DLL File not found
DRV - (CTAUDFX.DLL) – system32\CTAUDFX.DLL File not found
DRV - (CT20XUT.DLL) – system32\CT20XUT.DLL File not found
DRV - (COMMONFX.DLL) – system32\COMMONFX.DLL File not found
DRV - (IDMWFP) – C:\Windows\System32\drivers\idmwfp.sys (Tonec Inc.)
DRV - (StarOpen) – C:\Windows\System32\drivers\StarOpen.sys ()
DRV - (SbieDrv) – C:\Program Files\Sandboxie\SbieDrv.sys (SANDBOXIE L.T.D)
DRV - (afcdp) – C:\Windows\System32\drivers\afcdp.sys (Acronis)
DRV - (tdrpman273) Acronis Try&Decide; and Restore Points filter (build 273) – C:\Windows\System32\drivers\tdrpm273.sys (Acronis)
DRV - (timounter) – C:\Windows\System32\drivers\timntr.sys (Acronis)
DRV - (snapman) – C:\Windows\System32\drivers\snapman.sys (Acronis)
DRV - (tifsfilter) – C:\Windows\System32\drivers\tifsfilt.sys (Acronis)
DRV - (htcnprot) – C:\Windows\System32\drivers\htcnprot.sys (Windows ® Win 7 DDK provider)
DRV - (epfwwfp) – C:\Windows\System32\drivers\epfwwfp.sys (ESET)
DRV - (Epfwndis) – C:\Windows\System32\drivers\epfwndis.sys (ESET)
DRV - (epfw) – C:\Windows\System32\drivers\epfw.sys (ESET)
DRV - (ehdrv) – C:\Windows\System32\drivers\ehdrv.sys (ESET)
DRV - (eamonm) – C:\Windows\System32\drivers\eamonm.sys (ESET)
DRV - (hap17v2k) – C:\Windows\System32\drivers\haP17v2k.sys (Creative Technology Ltd)
DRV - (hap16v2k) – C:\Windows\System32\drivers\haP16v2k.sys (Creative Technology Ltd)
DRV - (ha10kx2k) – C:\Windows\System32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) – C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) – C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) – C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) – C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) – C:\Windows\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) – C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) – C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTERFXFX.SYS) – C:\Windows\System32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTERFXFX) – C:\Windows\System32\drivers\CTERFXFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX.SYS) – C:\Windows\System32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTSBLFX) – C:\Windows\System32\drivers\CTSBLFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX.SYS) – C:\Windows\System32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (CTAUDFX) – C:\Windows\System32\drivers\CTAUDFX.sys (Creative Technology Ltd)
DRV - (COMMONFX.SYS) – C:\Windows\System32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (COMMONFX) – C:\Windows\System32\drivers\COMMONFX.sys (Creative Technology Ltd)
DRV - (dc3d) MS Hardware Device Detection Driver (USB) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (HTCAND32) – C:\Windows\System32\drivers\ANDROIDUSB.sys (HTC, Corporation)
DRV - (LVPr2Mon) – C:\Windows\System32\drivers\LVPr2Mon.sys ()
DRV - (vmbus) – C:\Windows\System32\drivers\vmbus.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\System32\drivers\vmstorfl.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\System32\drivers\storvsc.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\System32\drivers\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\System32\drivers\VMBusHID.sys (Microsoft Corporation)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (LUsbFilt) – C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LHidFilt) – C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LVRS) – C:\Windows\System32\drivers\lvrs.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\System32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\Windows\System32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\Windows\System32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (zebrmdmc) Sony Ericsson mRouter Port (WDM) – C:\Windows\System32\drivers\zebrmdmc.sys (MCCI)
DRV - (zebrmdm) – C:\Windows\System32\drivers\zebrmdm.sys (MCCI)
DRV - (zebrmdfl) – C:\Windows\System32\drivers\zebrmdfl.sys (MCCI)
DRV - (zebrsce) – C:\Windows\System32\drivers\zebrsce.sys (MCCI)
DRV - (zebrceb) Sony Ericsson Cable Emulation Bus (WDM) – C:\Windows\System32\drivers\zebrceb.sys (MCCI)
DRV - (zebrbus) – C:\Windows\System32\drivers\zebrbus.sys (MCCI)
DRV - (IFP700) – C:\Windows\System32\drivers\Ifp700.sys (iRiver, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = AB 73 C7 1E 74 49 CD 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "
https://signin.ebay.co.uk/ws/eBayISAPI.dll?SignIn&UsingSSL;=1&pUserId;=&co;_partnerId=2&siteid;=3&ru;=http%3A%2F%2Fmy.ebay.co.uk%2Fws%2FeBayISAPI.dll%3FMyEbayBeta%26MyeBay%3D%26%26guest%3D1%26guest%3D1&pageType;=3984"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.6
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_257.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.633: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.633: c:\program files\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.633: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.633: c:\program files\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/02/02 17:35:33 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/06 18:10:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/02/20 16:45:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2011/08/18 21:15:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 12.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/08/10 22:30:18 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Users\Paul\AppData\Roaming\IDM\idmmzcc5 [2012/04/02 17:54:19 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[removed]: C:\Users\Paul\AppData\Roaming\IDM\idmmzcc5 [2012/04/02 17:54:19 | 000,000,000 | —D | M]
[2011/07/18 17:46:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions
[2011/01/07 15:05:08 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2011/07/18 17:46:17 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/05/02 10:36:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\6yadk2mh.default\extensions
[2012/02/21 23:51:15 | 000,000,000 | —D | M] (Cookies Manager+) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\6yadk2mh.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2011/08/09 21:47:48 | 000,000,000 | —D | M] (Разпознаване на устройство Logitech) – C:\Users\Paul\AppData\Roaming\Mozilla\Firefox\Profiles\6yadk2mh.default\extensions\[removed]
[2012/03/16 17:50:02 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/01/06 19:21:50 | 000,634,964 | —- | M] () (No name found) – C:\USERS\PAUL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6YADK2MH.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/02/20 13:17:31 | 000,118,971 | —- | M] () (No name found) – C:\USERS\PAUL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6YADK2MH.DEFAULT\EXTENSIONS\[removed]
[2012/02/07 15:33:46 | 000,246,025 | —- | M] () (No name found) – C:\USERS\PAUL\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\6YADK2MH.DEFAULT\EXTENSIONS\[removed]
[2012/06/06 18:10:21 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/02/20 13:22:18 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2012/05/04 17:06:20 | 000,001,525 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012/02/17 23:49:26 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/05/04 17:06:20 | 000,000,935 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2012/05/04 17:06:20 | 000,001,166 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2012/05/04 17:06:21 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
[2012/05/04 17:06:20 | 000,001,121 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2012/05/28 15:43:32 | 000,442,954 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 15217 more lines…
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (CatcherBHO Class) - {9B4DF450-DCC7-4B07-935D-0CD757A64583} - C:\Program Files\Moyea\YouTube FLV Downloader\MoyeaCatcher.dll (Moyea Software Co., Ltd.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [CTHelper] C:\Windows\System32\CtHelper.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CTNotify.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4 - HKLM..\Run: [HTC Sync Loader] C:\Program Files\HTC\HTC Sync 3.0\htcUPCTLoader.exe ()
O4 - HKLM..\Run: [Jet Detection] C:\Program Files\Creative\SBAudigy\Program\ADGJDet.exe ()
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\Windows\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [LogitechQuickCamRibbon] C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.exe (Creative Technology Ltd.)
O4 - HKCU..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [SandboxieControl] C:\Program Files\Sandboxie\SbieCtrl.exe (SANDBOXIE L.T.D)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\Run: [TaskTray] C:\Program Files\Creative\SBAudigy\Taskbar\CTLTray.exe (Creative Technology Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: =
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = _ [binary data]
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E}
http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF}
http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29}
http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4AB9D0AF-141E-4A15-855D-69E02CC12DB7}: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\Windows\System32\acaptuser32.dll (Adobe Systems Incorporated)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Authentication Packages - (relog_ap) - C:\Windows\System32\relog_ap.dll (Acronis)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O32 - AutoRun File - [2009/12/24 20:11:15 | 000,000,000 | —- | M] () - D:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2012/06/13 16:38:39 | 000,000,000 | —D | M] - K:\Auto Cad 2009 – [ NTFS ]
O32 - AutoRun File - [2012/06/13 16:33:27 | 000,000,000 | —D | M] - K:\AutoCAD 2010 [32-Bit] - English – [ NTFS ]
O32 - AutoRun File - [2012/05/20 15:44:28 | 000,000,000 | —D | M] - K:\Autodesk – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.ctmp3 - C:\Windows\System32\ctmp3.acm (Creative Technology Ltd.)
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: MSVideo - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\LVCodec2.dll (Logitech Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/06/15 17:31:59 | 000,000,000 | —D | C] – C:\Users\Paul\AppData\Local\Macromedia
[2012/06/13 17:17:30 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\Paul\Desktop\HiJackThis.exe
[2012/06/13 16:23:45 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2012/06/13 16:00:06 | 000,627,200 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeeds.dll
[2012/06/13 15:59:58 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2012/06/13 15:59:58 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2012/06/13 15:59:58 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iepeers.dll
[2012/06/13 15:59:58 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ieui.dll
[2012/06/13 15:59:58 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2012/06/13 15:59:57 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\System32\url.dll
[2012/06/13 15:59:57 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2012/06/13 15:59:57 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\licmgr10.dll
[2012/06/13 15:59:56 | 001,638,912 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mshtml.tlb
[2012/06/13 15:59:56 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\html.iec
[2012/06/13 15:59:56 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedssync.exe
[2012/06/13 15:59:35 | 000,129,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpcorekmts.dll
[2012/06/13 15:59:35 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdpwsx.dll
[2012/06/13 15:59:35 | 000,008,192 | —- | C] (Microsoft Corporation) – C:\Windows\System32\rdrmemptylst.exe
[2012/06/13 15:58:34 | 002,342,400 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2012/06/11 14:36:05 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZAR
[2012/06/11 14:36:04 | 000,000,000 | —D | C] – C:\Program Files\ZAR
[2012/06/06 17:59:11 | 000,000,000 | —D | C] – C:\Users\Paul\Documents\Tyre
[2012/05/28 14:45:50 | 000,000,000 | —D | C] – C:\Users\Paul\Desktop\dump today
========== Files - Modified Within 30 Days ==========
[2012/06/16 09:05:42 | 000,853,862 | —- | M] () – C:\Users\Paul\Desktop\SecurityCheck.exe
[2012/06/16 09:04:59 | 000,302,592 | —- | M] () – C:\Users\Paul\Desktop\dv1z4qgz.exe
[2012/06/16 08:56:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/16 08:39:48 | 000,009,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 08:39:48 | 000,009,584 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/16 08:38:32 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/06/16 08:38:26 | 2817,114,112 | -HS- | M] () – C:\hiberfil.sys
[2012/06/15 17:34:28 | 000,030,120 | —- | M] () – C:\Windows\System32\BMXStateBkp-{00000003-00000000-00000002-00001102-00000004-00511102}.rfx
[2012/06/15 17:34:28 | 000,030,120 | —- | M] () – C:\Windows\System32\BMXState-{00000003-00000000-00000002-00001102-00000004-00511102}.rfx
[2012/06/15 17:34:28 | 000,027,408 | —- | M] () – C:\Windows\System32\BMXCtrlState-{00000003-00000000-00000002-00001102-00000004-00511102}.rfx
[2012/06/15 17:34:28 | 000,027,408 | —- | M] () – C:\Windows\System32\BMXBkpCtrlState-{00000003-00000000-00000002-00001102-00000004-00511102}.rfx
[2012/06/15 17:34:28 | 000,011,564 | —- | M] () – C:\Windows\System32\DVCState-{00000003-00000000-00000002-00001102-00000004-00511102}.rfx
[2012/06/15 17:32:38 | 003,162,278 | —- | M] () – C:\Windows\{00000003-00000000-00000002-00001102-00000004-00511102}.CDF
[2012/06/15 17:32:38 | 003,162,278 | —- | M] () – C:\Windows\{00000003-00000000-00000002-00001102-00000004-00511102}.BAK
[2012/06/15 17:22:13 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerApp.exe
[2012/06/15 17:22:13 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/06/13 17:17:09 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Paul\Desktop\HiJackThis.exe
[2012/06/13 16:42:43 | 000,630,928 | —- | M] () – C:\Windows\System32\perfh009.dat
[2012/06/13 16:42:43 | 000,111,052 | —- | M] () – C:\Windows\System32\perfc009.dat
[2012/06/13 16:23:33 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2012/06/13 16:10:49 | 003,839,304 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2012/06/11 14:36:05 | 000,000,893 | —- | M] () – C:\Users\Paul\Desktop\Zero Assumption Recovery.lnk
[2012/05/28 15:43:32 | 000,442,954 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2012/05/24 19:32:22 | 000,000,965 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
========== Files Created - No Company Name ==========
[2012/06/16 09:05:55 | 000,853,862 | —- | C] () – C:\Users\Paul\Desktop\SecurityCheck.exe
[2012/06/16 09:05:16 | 000,302,592 | —- | C] () – C:\Users\Paul\Desktop\dv1z4qgz.exe
[2012/06/13 17:24:43 | 003,162,278 | —- | C] () – C:\Windows\{00000003-00000000-00000002-00001102-00000004-00511102}.BAK
[2012/06/11 14:36:05 | 000,000,893 | —- | C] () – C:\Users\Paul\Desktop\Zero Assumption Recovery.lnk
[2012/05/10 14:22:18 | 000,001,456 | —- | C] () – C:\Users\Paul\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012/04/11 19:16:37 | 000,000,000 | —- | C] () – C:\Windows\mngui.INI
[2011/11/08 16:34:58 | 000,000,001 | —- | C] () – C:\Windows\System32\uuddc32.dll
[2011/10/01 16:23:00 | 000,007,605 | —- | C] () – C:\Users\Paul\AppData\Local\Resmon.ResmonCfg
[2011/09/08 14:36:43 | 000,148,480 | —- | C] () – C:\Windows\System32\APOMngr.DLL
[2011/09/08 14:36:43 | 000,073,728 | —- | C] () – C:\Windows\System32\CmdRtr.DLL
[2011/08/06 13:09:46 | 000,082,289 | —- | C] () – C:\Windows\System32\lvcoinst.ini
[2011/07/23 18:44:14 | 000,000,000 | —- | C] () – C:\ProgramData\LauncherAccess.dt
[2011/07/23 18:35:47 | 000,005,632 | —- | C] () – C:\Windows\System32\drivers\StarOpen.sys
[2011/07/23 18:21:23 | 000,003,984 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2011/02/26 15:41:05 | 000,000,000 | —- | C] () – C:\Users\Paul\AppData\Roaming\chrtmp
[2011/02/26 15:15:25 | 000,001,676 | —- | C] () – C:\Windows\Sandboxie.ini
[2011/01/17 11:27:09 | 001,048,576 | —- | C] () – C:\Windows\System32\sfman.dat
[2011/01/17 11:27:08 | 000,000,231 | —- | C] () – C:\Windows\ac3api.ini
[2011/01/17 11:20:54 | 000,000,256 | —- | C] () – C:\Windows\SBWIN.INI
[2010/07/15 00:33:04 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/07/15 00:33:04 | 000,000,000 | —- | C] () – C:\Windows\System32\atiicdxx.dat
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2009/06/10 22:42:20 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2011/07/23 18:44:57 | 000,000,074 | —- | M] () – C:\CMLoader.log
[2009/06/10 22:42:20 | 000,000,010 | —- | M] () – C:\config.sys
[2012/03/12 17:51:10 | 001,333,760 | —- | M] () – C:\FastActivate.exe
[2012/06/16 08:38:26 | 2817,114,112 | -HS- | M] () – C:\hiberfil.sys
[2011/01/17 11:17:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2011/01/17 11:17:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2012/06/16 08:38:29 | 1339,031,551 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 05:52:25 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 05:52:25 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 05:52:25 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 05:52:25 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 22:31:19 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/07/14 02:15:18 | 000,033,280 | —- | M] (SEIKO EPSON CORPORATION) – C:\Windows\system32\spool\prtprocs\w32x86\EP0NPP01.DLL
[2009/06/22 18:58:20 | 000,089,600 | —- | M] (Hewlett-Packard Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\HPZPPLHN.DLL
[2009/07/14 02:15:35 | 000,022,528 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\jnwppr.dll
[2009/07/14 02:16:19 | 000,029,696 | —- | M] (Microsoft Corporation) – C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/14 05:41:57 | 000,000,174 | -HS- | M] () – C:\Program Files\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/07/15 01:27:18 | 000,000,221 | -HS- | M] () – C:\Users\Paul\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2012/06/16 09:04:59 | 000,302,592 | —- | M] () – C:\Users\Paul\Desktop\dv1z4qgz.exe
[2012/06/13 17:17:09 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\Paul\Desktop\HiJackThis.exe
[2012/06/13 16:23:33 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Users\Paul\Desktop\OTL.exe
[2012/06/16 09:05:42 | 000,853,862 | —- | M] () – C:\Users\Paul\Desktop\SecurityCheck.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2012-06-13 15:08:27
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:DBC416F8
< End of report >
OTL Extras logfile created on: 16/06/2012 09:09:47 - Run 1
OTL by OldTimer - Version 3.2.48.0 Folder = C:\Users\Paul\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.50 Gb Total Physical Memory | 2.27 Gb Available Physical Memory | 64.81% Memory free
8.74 Gb Paging File | 7.44 Gb Available in Paging File | 85.06% Paging File free
Paging file location(s): c:\pagefile.sys 5373 5373 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 21.59 Gb Free Space | 28.97% Space Free | Partition Type: NTFS
Drive D: | 104.43 Gb Total Space | 66.65 Gb Free Space | 63.83% Space Free | Partition Type: NTFS
Drive E: | 95.39 Gb Total Space | 75.34 Gb Free Space | 78.97% Space Free | Partition Type: NTFS
Drive F: | 30.01 Gb Total Space | 27.37 Gb Free Space | 91.22% Space Free | Partition Type: NTFS
Drive I: | 564.01 Gb Total Space | 558.24 Gb Free Space | 98.98% Space Free | Partition Type: NTFS
Drive J: | 292.97 Gb Total Space | 144.39 Gb Free Space | 49.29% Space Free | Partition Type: NTFS
Drive K: | 465.75 Gb Total Space | 408.23 Gb Free Space | 87.65% Space Free | Partition Type: NTFS
Drive L: | 7.47 Gb Total Space | 5.31 Gb Free Space | 71.05% Space Free | Partition Type: FAT32
Drive O: | 7.81 Mb Total Space | 4.23 Mb Free Space | 54.13% Space Free | Partition Type: NTFS
Drive Q: | 170.01 Gb Total Space | 72.54 Gb Free Space | 42.67% Space Free | Partition Type: NTFS
Drive R: | 170.01 Gb Total Space | 103.67 Gb Free Space | 60.98% Space Free | Partition Type: NTFS
Drive S: | 158.60 Gb Total Space | 108.12 Gb Free Space | 68.17% Space Free | Partition Type: NTFS
Drive U: | 200.01 Gb Total Space | 110.62 Gb Free Space | 55.31% Space Free | Partition Type: NTFS
Computer Name: PAUL-PC | User Name: Paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{092256E5-938F-4AC1-97E3-63E8A2079722}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{1176E4B9-9D98-4059-A571-6E14A478A394}" = lport=2869 | protocol=6 | dir=in | app=system |
"{11974B04-C5C5-4733-ABC4-92CCEA895C0A}" = rport=137 | protocol=17 | dir=out | app=system |
"{1E2F3E35-B54C-42F3-8ACA-AA73B2A99CA9}" = rport=139 | protocol=6 | dir=out | app=system |
"{3A2A2A6F-173D-4C84-A802-C51C9C25ECF1}" = lport=138 | protocol=17 | dir=in | app=system |
"{49A461D4-5398-409D-BDB6-7E0FC6DC2B4B}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{507AACA8-C475-4905-9331-D64181514ED5}" = lport=445 | protocol=6 | dir=in | app=system |
"{62EA51F8-4B6D-4D8F-8F9E-209E1D82778D}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{7FC6999D-8A77-4104-8870-E07F8AE50C2F}" = lport=10243 | protocol=6 | dir=in | app=system |
"{83FAF095-3113-4FD1-9378-B5C2605E4DB4}" = lport=137 | protocol=17 | dir=in | app=system |
"{8C06C89C-6280-4D89-A976-363963D88009}" = rport=138 | protocol=17 | dir=out | app=system |
"{96B89273-A199-4A6F-AD59-F526347EAFB7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9ACBF3E9-B411-46A1-A09B-B3E075665277}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9D790096-26ED-4C67-9A2F-A15B517D156C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{A5ECE41E-4066-412F-9574-7C37074F2F97}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A67168CB-A6A3-4052-9DC3-DAEE62943376}" = lport=139 | protocol=6 | dir=in | app=system |
"{AE8B4D80-6D06-4567-9A88-E69D0ECB4D2A}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{BD7B063A-8C07-4229-A5E2-A996E08CD22C}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{C25C0F36-2806-499A-BB35-D91E03A0CF17}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{C544A575-D76A-442C-9580-5F03FC0267E6}" = rport=10243 | protocol=6 | dir=out | app=system |
"{D0972E26-7EBA-41B6-A85F-5BDE6B26F3E2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{D5875907-37A6-4043-95B1-B84ED09611AB}" = rport=445 | protocol=6 | dir=out | app=system |
"{E34C0F9A-25AC-4224-B1D8-8D5852F87E0E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{EA29E207-5246-44A8-9472-A3684351D468}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0AE45CD2-489E-4044-B710-2F4E995E5539}" = protocol=6 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{2D898ECD-CA46-4560-802E-9C4FB262E5BA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3418CFC1-69F7-4AC0-A508-5B5EED9A93EC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3A84B04A-9C8E-4D44-A6C8-509661E0CB09}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{3CEC8C82-007C-4E44-8E4A-37D7FD9459BA}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{3E635DB4-BCF0-4214-B0A2-845F8919D427}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{57D1FA31-BC88-4227-844A-323D7C197148}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5D0EE781-EFD7-4F46-8D95-5FCA74D9F91C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5F10D089-5380-448A-99C5-A616D1D2A552}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{79C6A389-E8FD-4F7A-8733-8AE53F7BA791}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{84599DF1-BC24-42C1-B22C-C72ADBA6ACDE}" = protocol=6 | dir=out | app=system |
"{87D129B7-378D-4A8C-A777-20BA7995E086}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{8C000258-FE4C-4BBD-B730-D0599F176E30}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{8E948CFC-C794-4525-B4A3-A0567BE47766}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{980931C6-9D4E-41DE-B896-B71DA2628A3F}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9C0297AA-302E-4803-AF20-A5359D92FC4F}" = dir=in | app=c:\program files\skype\phone\skype.exe |
"{AE5D95E6-E265-4219-A301-F9E0FF20AC1E}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{BD7B446D-FD4F-48A2-A26A-06A8DFB2A406}" = dir=in | app=c:\program files\itunes\itunes.exe |
"{C8BC5DD9-A994-4728-8866-49E91AB33D10}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{CF92E610-87B2-4E84-8F84-63C813E7A457}" = protocol=17 | dir=in | app=c:\program files\logitech\vid hd\vid.exe |
"{F4BAE776-1BB4-4DF4-8D32-D49A63A1962D}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F84F8307-A8C6-48A7-804A-56BAC4D0C5FF}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{007811BF-E310-4285-BFC6-55DB29B3EDDE}" = WinPatrol
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{04A3A6B0-8E19-49BB-82FF-65C5A55F917D}" = Acronis True Image Home 2011
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0C826C5B-B131-423A-A229-C71B3CACCD6A}" = CDDRV_Installer
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A697B53-0DE3-42DA-B41D-C3F804B1C538}" = iTunes
"{2A981294-F14C-4F0F-9627-D793270922F8}" = Bonjour
"{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}" = Apple Application Support
"{302A1E2E-DD58-4673-BC99-9CC10EC2637A}" = WinPatrol
"{3101CB58-3482-4D21-AF1A-7057FC935355}" = KhalInstallWrapper
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{46C1C6DF-ADD5-4FD3-99EB-E6EE020ABA7E}" = Microsoft Camera Codec Pack
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{49272E0B-CF97-4BD6-85A0-9B1C59495850}_is1" = Able2Extract 7.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{5783F2D7-8001-0409-0002-0060B0CE6BBA}" = AutoCAD 2010 - English
"{5783F2D7-8001-0409-1002-0060B0CE6BBA}" = AutoCAD 2010 Language Pack - English
"{5986F167-4C6C-4D03-9706-E1189B2A1462}" = iriver Music Manager
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{6D6664A9-3342-4948-9B7E-034EFE366F0F}" = HTC Driver Installer
"{7216871F-869E-437C-B9BF-2A13F2DCE63F}_is1" = AusLogics BoostSpeed
"{77077FFF-8831-470F-9627-E86F06A50CCD}" = Avery Wizard 3.1
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}" = TomTom HOME Visual Studio Merge Modules
"{90120000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2007
"{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_PROPLUS_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_PROPLUS_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_PROPLUS_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_PROPLUS_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_PROPLUS_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = 2007 Microsoft Office Suite Service Pack 2 (SP2)
"{91B7CEB3-4331-427B-AA7A-2898BE8F9DC6}" = Samsung PC Studio 3
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{942E5031-2BD6-4C1B-918C-C8A1CBAE7B8C}" = Microsoft IntelliPoint 8.2
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CCC78EF-027E-40E0-9B61-39932C65E3FE}" = Acronis Disk Director Home
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AB77DFDE-9949-4AEF-B180-BE322C3E65D0}" = HTC Sync
"{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-1033-F400-7761-000000000004}_942" = Adobe Acrobat 9.4.2 - CPSID_83708
"{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}" = Adobe Acrobat 9 Pro Extended - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-A94000000001}" = Adobe Reader 9.4.2
"{AC76BA86-7AD7-2447-0000-900000000003}" = Chinese Simplified Fonts Support For Adobe Reader 9
"{B0513493-04B9-4F21-B4AB-83E750D54256}" = Adobe Photoshop Lightroom 2.7
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C27BC2A2-30DD-4014-B22E-63EB0DB572F9}" = Logitech Webcam Software
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C4A4722E-79F9-417C-BD72-8D359A090C97}" = Samsung PC Studio 3
"{CACAEB5F-174D-4C7C-AC56-A33289A807CA}" = Apple Mobile Device Support
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{EA426461-31AA-4AB3-B15D-EDD748F08394}_is1" = Moyea YouTube FLV Downloader version: 3.1.2.26
"{F1ED5BD7-4770-4037-9CBD-5DF9A5BEC408}" = Plus Pack for Acronis True Image Home 2011
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ALchemy" = Creative ALchemy
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"AudioCS" = Creative Audio Console
"AutoCAD 2010 - English" = AutoCAD 2010 - English
"BayGenie eBay Auction Sniper Pro Edition_is1" = BayGenie eBay Auction Sniper Pro Edition [removed]
"Canon RAW Codec" = Canon RAW Codec
"CCleaner" = CCleaner
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"EAGLE 5.11.0" = EAGLE 5.11.0
"EAGLE PCB Power Tools 5.06" = EAGLE PCB Power Tools 5.06
"EPSON Scanner" = EPSON Scan
"FLV Player2.0.25" = FLV Player
"Img2CAD_is1" = Img2CAD 7.0
"Internet Download Manager" = Internet Download Manager
"JDownloader" = JDownloader
"Logitech Vid" = Logitech Vid HD
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"Mozilla Firefox 13.0 (x86 en-GB)" = Mozilla Firefox 13.0 (x86 en-GB)
"Mozilla Thunderbird 12.0.1 (x86 en-US)" = Mozilla Thunderbird 12.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mp3tag" = Mp3tag v2.49
"MPE" = MyPhoneExplorer
"OpenAL" = OpenAL
"PoiEdit" = PoiEdit
"PROPLUS" = Microsoft Office Professional Plus 2007
"RealPlayer 12.0" = RealPlayer
"SAMSUNG Mobile Composite Device" = SAMSUNG Mobile Composite Device Software
"SAMSUNG Mobile Modem" = SAMSUNG Mobile Modem Driver Set
"Samsung Mobile phone USB driver Drive" = Samsung Mobile phone USB driver Drive Software
"SAMSUNG Mobile USB Modem" = SAMSUNG Mobile USB Modem Software
"SAMSUNG Mobile USB Modem 1.0" = SAMSUNG Mobile USB Modem 1.0 Software
"Sandboxie" = Sandboxie 3.52
"Sony Ericsson" = Sony Ericsson Symbian 9 Drivers
"SopCast" = SopCast 3.5.0
"Sound Blaster Audigy" = Sound Blaster Audigy
"TomTom HOME" = TomTom HOME 2.8.3.2499
"Tyre_is1" = Tyre
"Veetle TV" = Veetle TV 0.9.18
"WaveStudio 7" = Creative WaveStudio 7
"WinRAR archiver" = WinRAR 4.11 (32-bit)
"Zero Assumption Recovery_is1" = Zero Assumption Recovery Version 9
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 14/06/2012 11:22:14 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Common
Files\Acronis\DiskDirector\WinPE\Files\systeminfo.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 14/06/2012 11:22:33 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Common
Files\Acronis\DiskDirector\WinPE\Files\RecoveryExpert.exe". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 14/06/2012 11:22:38 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Common
Files\Acronis\DiskDirector\WinPE\Files\ManagementConsole.exe". Dependent Assembly
Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 14/06/2012 11:22:42 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Common
Files\Acronis\DiskDirector\WinPE\Files\mmsBundle.dll". Dependent Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 14/06/2012 11:22:53 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\HTC\HTC
Sync 3.0\FDAgentForOutlook64.exe". Dependent Assembly Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 14/06/2012 11:22:58 | Computer Name = Paul-PC | Source = SideBySide | ID = 16842785
Description = Activation context generation failed for "C:\Program Files\Acronis\TrueImageHome\BartPE\Files\TrueImage.exe".
Dependent
Assembly Microsoft.VC80.CRT,processorArchitecture="x86",type="win32",version="8.0.50727.762"
could not be found. Please use sxstrace.exe for detailed diagnosis.
Error - 15/06/2012 11:05:38 | Computer Name = Paul-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 15/06/2012 12:19:42 | Computer Name = Paul-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 16/06/2012 03:38:43 | Computer Name = Paul-PC | Source = Winlogon | ID = 4103
Description = Windows license activation failed. Error 0x80070005.
Error - 16/06/2012 03:43:17 | Computer Name = Paul-PC | Source = Application Error | ID = 1000
Description = Faulting application name: plugin-container.exe, version: 13.0.0.4535,
time stamp: 0x4fc8de63 Faulting module name: NPSWF32_11_3_300_257.dll_unloaded,
version: 0.0.0.0, time stamp: 0x4fc821fc Exception code: 0xc0000005 Fault offset:
0x64879903 Faulting process id: 0x1020 Faulting application start time: 0x01cd4b933c47e169
Faulting
application path: C:\Program Files\Mozilla Firefox\plugin-container.exe Faulting
module path: NPSWF32_11_3_300_257.dll Report Id: ef2f60cb-b786-11e1-8256-001372cce8e1
[ OSession Events ]
Error - 04/03/2011 12:38:15 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 4
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/06/2011 14:32:25 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 13
seconds with 0 seconds of active time. This session ended with a crash.
Error - 24/06/2011 16:19:15 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 7
seconds with 0 seconds of active time. This session ended with a crash.
Error - 14/07/2011 02:59:20 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 5
seconds with 0 seconds of active time. This session ended with a crash.
Error - 28/09/2011 11:31:54 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 1874
seconds with 120 seconds of active time. This session ended with a crash.
Error - 09/11/2011 11:04:41 | Computer Name = Paul-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6425.1000, Microsoft Office Version: 12.0.6425.1000. This session lasted 751
seconds with 60 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 15/06/2012 12:34:20 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7000
Description = The IPsec Policy Agent service failed to start due to the following
error: %%1069
Error - 15/06/2012 12:34:20 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7038
Description = The PolicyAgent service was unable to log on as NT Authority\NetworkService
with the currently configured password due to the following error: %%1352 To ensure
that the service is configured properly, use the Services snap-in in Microsoft
Management Console (MMC).
Error - 15/06/2012 12:34:20 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7000
Description = The IPsec Policy Agent service failed to start due to the following
error: %%1069
Error - 15/06/2012 12:34:20 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7023
Description = The Windows Defender service terminated with the following error:
%%-2147023781
Error - 15/06/2012 12:34:23 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1115
Error - 15/06/2012 12:34:23 | Computer Name = Paul-PC | Source = Service Control Manager | ID = 7023
Description = The Server service terminated with the following error: %%13
Error - 16/06/2012 03:38:19 | Computer Name = Paul-PC | Source = volsnap | ID = 393245
Description = The shadow copies of volume D: were aborted during detection.
Error - 16/06/2012 03:38:19 | Computer Name = Paul-PC | Source = volsnap | ID = 393245
Description = The shadow copies of volume C: were aborted during detection.
Error - 16/06/2012 03:38:44 | Computer Name = Paul-PC | Source = Ntfs | ID = 262281
Description = The default transaction resource manager on volume O: encountered
a non-retryable error and could not start. The data contains the error code.
Error - 16/06/2012 03:39:38 | Computer Name = Paul-PC | Source = DCOM | ID = 10001
Description =
< End of report >
GMER 1.0.15.15641 -
http://www.gmer.net
Rootkit scan 2012-06-16 09:50:42
Windows 6.1.7600 Harddisk1\DR1 -> \Device\Ide\IdeDeviceP1T1L0-3 WDC_WD10EARS-00Y5B1 rev.80.00A80
Running: dv1z4qgz.exe; Driver: C:\Users\Paul\AppData\Local\Temp\kxldapod.sys
—- System - GMER 1.0.15 —-
Code 94F5BBFC ZwTraceEvent
Code 94F5BBFB NtTraceEvent
—- Kernel code sections - GMER 1.0.15 —-
.text ntkrnlpa.exe!NtTraceEvent 83085E34 5 Bytes JMP 94F5BC00
.text ntkrnlpa.exe!ZwRollbackTransaction + 13E9 83096599 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 830BB092 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, …] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 2 832C8753 5 Bytes JMP 94F5BDE0
PAGE ntkrnlpa.exe!NtRequestWaitReplyPort + 2 832CA17B 5 Bytes JMP 94F5BD40
PAGE ntkrnlpa.exe!NtRequestPort + 2 832DE3E1 5 Bytes JMP 94F5BCA0
.text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x92415000, 0x227A14, 0xE8000020]
.text win32k.sys!XFORMOBJ_iGetXform + 3332 98CC5E7F 5 Bytes JMP 94F5B5C0
.text win32k.sys!EngAllocMem + 7E5C 98CD6712 5 Bytes JMP 94F5B700
.text win32k.sys!PATHOBJ_bEnum + 79A9 98CE8DA2 5 Bytes JMP 94F5B660
.text win32k.sys!PATHOBJ_bEnum + 868E 98CE9A87 5 Bytes JMP 94F5B8E0
.text win32k.sys!EngCreateSemaphore + CA12 98D078C0 5 Bytes JMP 94F5B980
.text win32k.sys!EngCreateSemaphore + CD4E 98D07BFC 5 Bytes JMP 94F5B520
.text win32k.sys!EngCopyBits + 1FB9 98D09F7C 5 Bytes JMP 94F5B480
.text win32k.sys!EngBitBlt + 2401 98D12DA0 5 Bytes JMP 94F5B3E0
.text win32k.sys!EngLpkInstalled + 6119 98D28F0A 5 Bytes JMP 94F5BA20
.text win32k.sys!PATHOBJ_vGetBounds + EB7 98DA7201 5 Bytes JMP 94F5B840
.text win32k.sys!EngCTGetCurrentGamma + 1C88 98DAB22A 5 Bytes JMP 94F5B7A0
.text win32k.sys!CLIPOBJ_cEnumStart + 6DAE 98DB6C85 5 Bytes JMP 94F5BAC0
.text win32k.sys!CLIPOBJ_cEnumStart + 72B6 98DB718D 5 Bytes JMP 94F5BB60
PAGE spsys.sys!?SPRevision@@3PADA + 4F90 B9652000 290 Bytes [8B, FF, 55, 8B, EC, 33, C0, …]
PAGE spsys.sys!?SPRevision@@3PADA + 50B3 B9652123 486 Bytes [D5, 64, B9, FE, 05, 34, D5, …]
PAGE spsys.sys!?SPRevision@@3PADA + 529A B965230A 142 Bytes [64, B9, 3B, 08, 77, 04, 3B, …]
PAGE spsys.sys!?SPRevision@@3PADA + 5329 B9652399 101 Bytes [6A, 28, 59, A5, 5E, C6, 03, …]
PAGE spsys.sys!?SPRevision@@3PADA + 538F B96523FF 148 Bytes [18, 5D, C2, 14, 00, 8B, FF, …]
PAGE …
—- User code sections - GMER 1.0.15 —-
.text C:\Program Files\ESET\ESET Smart Security\ekrn.exe[924] kernel32.dll!SetUnhandledExceptionFilter 75BC30E2 4 Bytes [C2, 04, 00, 00]
.text C:\Program Files\Microsoft Office\Office12\WINWORD.EXE[4664] kernel32.dll!SetUnhandledExceptionFilter 75BC30E2 5 Bytes JMP 5DC05436 C:\Program Files\Common Files\Microsoft Shared\office12\mso.dll (2007 Microsoft Office component/Microsoft Corporation)
—- Devices - GMER 1.0.15 —-
Device Ntfs.sys (NT File System Driver/Microsoft Corporation)
AttachedDevice snapman.sys (Acronis Snapshot API/Acronis)
Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation)
Device volmgr.sys (Volume Manager Driver/Microsoft Corporation)
AttachedDevice fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
Device usbhub.sys (Default Hub Driver for USB/Microsoft Corporation)
Device \Driver\ACPI_HAL \Device\00000058 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\tdrpman273 \Device\tdrpman snapman.sys (Acronis Snapshot API/Acronis)
—- Registry - GMER 1.0.15 —-
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000b0d314d2e
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\000b0d314d2e@000ad9a85322 0x3D 0x1A 0xBA 0xA9 …
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\000b0d314d2e (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\000b0d314d2e@000ad9a85322 0x3D 0x1A 0xBA 0xA9 …
—- EOF - GMER 1.0.15 —-
Results of screen317's Security Check version 0.99.41
Windows 7 x86
(UAC is disabled!)
Out of date service pack!!
Internet Explorer 8
Out of date!
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
ESET Smart Security 4.2
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
WinPatrol
MVPS Hosts File
Spybot - Search & Destroy
CCleaner
Java™ 6 Update 31
Java version out of date!
Adobe Flash Player 11.3.300.257
Adobe Reader 9
Adobe Reader out of date!
Mozilla Firefox (13.0)
Mozilla Thunderbird (12.0.1)
````````Process Check: objlist.exe by Laurent````````
WinPatrol winpatrol.exe is disabled!
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 1%
````````````````````End of Log``````````````````````