This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems with Norton Antivirus

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After googling for the problem, I have found this:
http://community.norton.com/t5/Norton-Inte…ive/td-p/188823

So I came here. The actual problem is that Norton does not respond, left/right click on the tray or running the program from disc.

I hope this is the right place, apologies in advance if I am mistaken.

Here is my HiJackThis

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:05:25, on 02-Sep-12
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\nvsvc32.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\System32\svchost.exe
D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Program Files\Bonjour\mDNSResponder.exe
D:\Program Files\GNU\GnuPG\dirmngr.exe
D:\Program Files\Java\jre7\bin\jqs.exe
D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
D:\WINDOWS\system32\PnkBstrB.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Tunngle\TnglCtrl.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\wscntfy.exe
D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
D:\WINDOWS\system32\nvraidservice.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\iPod\bin\iPodService.exe
D:\WINDOWS\system32\RUNDLL32.EXE
D:\Program Files\Freecorder\FLVSrvc.exe
D:\WINDOWS\system32\CTHELPER.EXE
D:\Program Files\Citrix\ICA Client\wfcrun32.exe
D:\Program Files\Microsoft IntelliPoint\ipoint.exe
D:\Program Files\Common Files\Java\Java Update\jusched.exe
D:\Program Files\Messenger\msmsgs.exe
D:\FRAPS\FRAPS.EXE
D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe
D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe
D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
D:\Program Files\Mozilla Firefox\firefox.exe
D:\Program Files\Mozilla Firefox\plugin-container.exe
D:\Documents and Settings\Max\My Documents\Downloads\HiJackThis(1).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;
R3 - URLSearchHook: DigiMode Toolbar - {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll
R3 - URLSearchHook: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll
O1 - Hosts: 209.85.137.104 menelgame.pl www.menelgame.pl change.menelgame.pl
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: DigiMode Toolbar - {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\coIEPlg.dll
O2 - BHO: uTorrentControl2 - {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll
O2 - BHO: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\IPS\IPSBHO.DLL
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\All Users\Application Data\Gadu-Gadu 10\_userdata\ggbho.2.dll (file missing)
O3 - Toolbar: DigiMode Toolbar - {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\coIEPlg.dll
O3 - Toolbar: uTorrentControl2 Toolbar - {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll
O4 - HKLM\..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [NVRaidService] D:\WINDOWS\system32\nvraidservice.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [amd_dc_opt] "D:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe"
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installquiet
O4 - HKLM\..\Run: [Freecorder FLV Service] "D:\Program Files\Freecorder\FLVSrvc.exe" /run
O4 - HKLM\..\Run: [ConnectionCenter] "D:\Program Files\Citrix\ICA Client\concentr.exe" /startup
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] D:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [IntelliPoint] "D:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [AmIcoSinglun] D:\Program Files\AmIcoSingLun\AmIcoSinglun.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Fraps] D:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [RGSC] D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent
O4 - HKCU\..\Run: [Facebook Update] "D:\Documents and Settings\Max\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver
O4 - HKCU\..\Run: [Akamai NetSession Interface] "D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Wireless Configuration Utility HW.51.lnk = D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://D:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\Max\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo…iaSmartScan.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4A8A9A1A-2710-46A3-B73D-6350A4386B3A}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DirMngr - Unknown owner - D:\Program Files\GNU\GnuPG\dirmngr.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Us3uga Google Update (gupdate) (gupdate) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Us3uga Google Update (gupdatem) (gupdatem) - Google Inc. - D:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - D:\Program Files\Java\jre7\bin\jqs.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - D:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - D:\WINDOWS\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - D:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - D:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - D:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TunngleService - Tunngle.net GmbH - D:\Program Files\Tunngle\TnglCtrl.exe

–
End of file - 14389 bytes
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post





Please download TDSSKiller.zip
  • Extract it to your desktop
  • Double click TDSSKiller.exe
  • Press Start Scan
    • Only if Malicious objects are found then ensure Cure is selected
      If suspicious objects are found select skip
    • Then click Continue > Reboot now
  • Copy and paste the log in your next reply
    • A copy of the log will be saved automatically to the root of the drive (typically C:\)












  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    C:\Windows\assembly\tmp\U\*.* /s
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hey, sorry for no reply, I was away from my PC. I'm posting this right now so the topic wont get locked. I'm going to run all those in a minute, then I will reply properly.
TDSSKiller18:27:23.0142 2876 TDSS rootkit removing tool 2.8.8.0 Aug 24 2012 13:27:48
18:27:25.0142 2876 ============================================================
18:27:25.0142 2876 Current date / time: 2012/09/08 18:27:25.0142
18:27:25.0142 2876 SystemInfo:
18:27:25.0142 2876
18:27:25.0142 2876 OS Version: 5.1.2600 ServicePack: 3.0
18:27:25.0142 2876 Product type: Workstation
18:27:25.0142 2876 ComputerName: TOMEK
18:27:25.0142 2876 UserName: Max
18:27:25.0142 2876 Windows directory: D:\WINDOWS
18:27:25.0142 2876 System windows directory: D:\WINDOWS
18:27:25.0142 2876 Processor architecture: Intel x86
18:27:25.0142 2876 Number of processors: 2
18:27:25.0142 2876 Page size: 0x1000
18:27:25.0142 2876 Boot type: Normal boot
18:27:25.0142 2876 ============================================================
18:27:28.0049 2876 Drive \Device\Harddisk0\DR0 - Size: 0x4A85C4DE00 (298.09 Gb), SectorSize: 0x200, Cylinders: 0xA181, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xF0, Type 'K0', Flags 0x00000054
18:27:28.0049 2876 Drive \Device\Harddisk1\DR3 - Size: 0x1D1C0F00000 (1863.01 Gb), SectorSize: 0x200, Cylinders: 0x3B601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
18:27:28.0705 2876 ============================================================
18:27:28.0705 2876 \Device\Harddisk0\DR0:
18:27:28.0720 2876 MBR partitions:
18:27:28.0720 2876 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3B4F, BlocksNum 0xFFF6231
18:27:28.0720 2876 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0xFFF9D80, BlocksNum 0x15433590
18:27:28.0720 2876 \Device\Harddisk1\DR3:
18:27:28.0720 2876 MBR partitions:
18:27:28.0720 2876 \Device\Harddisk1\DR3\Partition1: MBR, Type 0x7, StartLBA 0x800, BlocksNum 0xE8E07000
18:27:28.0720 2876 ============================================================
18:27:28.0861 2876 C: <-> \Device\Harddisk0\DR0\Partition2
18:27:28.0939 2876 D: <-> \Device\Harddisk0\DR0\Partition1
18:27:28.0970 2876 O: <-> \Device\Harddisk1\DR3\Partition1
18:27:28.0970 2876 ============================================================
18:27:28.0970 2876 Initialize success
18:27:28.0970 2876 ============================================================
18:27:47.0049 3956 ============================================================
18:27:47.0049 3956 Scan started
18:27:47.0049 3956 Mode: Manual;
18:27:47.0049 3956 ============================================================
18:27:47.0830 3956 ================ Scan system memory ========================
18:27:47.0830 3956 System memory - ok
18:27:47.0845 3956 ================ Scan services =============================
18:27:47.0955 3956 Abiosdsk - ok
18:27:47.0955 3956 abp480n5 - ok
18:27:47.0986 3956 [ 8FD99680A539792A30E97944FDAECF17 ] ACPI D:\WINDOWS\system32\DRIVERS\ACPI.sys
18:27:47.0986 3956 ACPI - ok
18:27:48.0017 3956 [ 9859C0F6936E723E4892D7141B1327D5 ] ACPIEC D:\WINDOWS\system32\drivers\ACPIEC.sys
18:27:48.0049 3956 ACPIEC - ok
18:27:48.0049 3956 adfs - ok
18:27:48.0111 3956 [ A9D3B95E8466BD58EEB8A1154654E162 ] AdobeFlashPlayerUpdateSvc D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
18:27:48.0127 3956 AdobeFlashPlayerUpdateSvc - ok
18:27:48.0127 3956 adpu160m - ok
18:27:48.0158 3956 [ 8BED39E3C35D6A489438B8141717A557 ] aec D:\WINDOWS\system32\drivers\aec.sys
18:27:48.0158 3956 aec - ok
18:27:48.0189 3956 [ 7E775010EF291DA96AD17CA4B17137D7 ] AFD D:\WINDOWS\System32\drivers\afd.sys
18:27:48.0189 3956 AFD - ok
18:27:48.0205 3956 Aha154x - ok
18:27:48.0205 3956 aic78u2 - ok
18:27:48.0205 3956 aic78xx - ok
18:27:48.0392 3956 [ 0923671CF87CD511E46D4668B53F5E76 ] Akamai d:\program files\common files\akamai/netsession_win_5891ae0.dll
18:27:48.0392 3956 Suspicious file (Hidden): d:\program files\common files\akamai/netsession_win_5891ae0.dll. md5: 0923671CF87CD511E46D4668B53F5E76
18:27:48.0392 3956 Akamai ( HiddenFile.Multi.Generic ) - warning
18:27:48.0392 3956 Akamai - detected HiddenFile.Multi.Generic (1)
18:27:48.0424 3956 [ A9A3DAA780CA6C9671A19D52456705B4 ] Alerter D:\WINDOWS\system32\alrsvc.dll
18:27:48.0424 3956 Alerter - ok
18:27:48.0439 3956 [ 8C515081584A38AA007909CD02020B3D ] ALG D:\WINDOWS\System32\alg.exe
18:27:48.0439 3956 ALG - ok
18:27:48.0455 3956 AliIde - ok
18:27:48.0517 3956 [ 267FC636801EDC5AB28E14036349E3BE ] Ambfilt D:\WINDOWS\system32\drivers\Ambfilt.sys
18:27:48.0564 3956 Ambfilt - ok
18:27:48.0595 3956 [ EFBB0956BAED786E137351B5CA272AEF ] AmdK8 D:\WINDOWS\system32\DRIVERS\AmdK8.sys
18:27:48.0595 3956 AmdK8 - ok
18:27:48.0642 3956 [ CEC8B2A9E39D3ECEBB32456DA4D7B6B2 ] AmdTools D:\WINDOWS\system32\DRIVERS\AmdTools.sys
18:27:48.0642 3956 AmdTools - ok
18:27:48.0642 3956 amsint - ok
18:27:48.0720 3956 [ ACB095E7E1663F1B83A41C22C5D75F90 ] Apple Mobile Device D:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
18:27:48.0720 3956 Apple Mobile Device - ok
18:27:48.0752 3956 [ D8849F77C0B66226335A59D26CB4EDC6 ] AppMgmt D:\WINDOWS\System32\appmgmts.dll
18:27:48.0752 3956 AppMgmt - ok
18:27:48.0814 3956 [ 8E2257584B2C52D44B4CB1949947D885 ] AR9271 D:\WINDOWS\system32\DRIVERS\athuw.sys
18:27:48.0877 3956 AR9271 - ok
18:27:48.0924 3956 [ B5B8A80875C1DEDEDA8B02765642C32F ] Arp1394 D:\WINDOWS\system32\DRIVERS\arp1394.sys
18:27:48.0924 3956 Arp1394 - ok
18:27:48.0970 3956 [ D8AA72B3760402B4A30925D9778E4688 ] arusb(TP-LINK) D:\WINDOWS\system32\DRIVERS\arusb.sys
18:27:49.0002 3956 arusb(TP-LINK) - ok
18:27:49.0002 3956 asc - ok
18:27:49.0002 3956 asc3350p - ok
18:27:49.0017 3956 asc3550 - ok
18:27:49.0127 3956 [ 776ACEFA0CA9DF0FAA51A5FB2F435705 ] aspnet_state D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
18:27:49.0205 3956 aspnet_state - ok
18:27:49.0236 3956 [ B153AFFAC761E7F5FCFA822B9C4E97BC ] AsyncMac D:\WINDOWS\system32\DRIVERS\asyncmac.sys
18:27:49.0252 3956 AsyncMac - ok
18:27:49.0283 3956 [ 9F3A2F5AA6875C72BF062C712CFA2674 ] atapi D:\WINDOWS\system32\DRIVERS\atapi.sys
18:27:49.0299 3956 atapi - ok
18:27:49.0299 3956 Atdisk - ok
18:27:49.0314 3956 [ 9916C1225104BA14794209CFA8012159 ] Atmarpc D:\WINDOWS\system32\DRIVERS\atmarpc.sys
18:27:49.0314 3956 Atmarpc - ok
18:27:49.0345 3956 [ DEF7A7882BEC100FE0B2CE2549188F9D ] AudioSrv D:\WINDOWS\System32\audiosrv.dll
18:27:49.0345 3956 AudioSrv - ok
18:27:49.0377 3956 [ D9F724AA26C010A217C97606B160ED68 ] audstub D:\WINDOWS\system32\DRIVERS\audstub.sys
18:27:49.0377 3956 audstub - ok
18:27:49.0424 3956 [ DA1F27D85E0D1525F6621372E7B685E9 ] Beep D:\WINDOWS\system32\drivers\Beep.sys
18:27:49.0424 3956 Beep - ok
18:27:49.0580 3956 [ A9E111A358AC5F7EBA7AC61E43FC6725 ] BHDrvx86 D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120823.007\BHDrvx86.sys
18:27:49.0611 3956 BHDrvx86 - ok
18:27:49.0658 3956 [ 574738F61FCA2935F5265DC4E5691314 ] BITS D:\WINDOWS\system32\qmgr.dll
18:27:49.0674 3956 BITS - ok
18:27:49.0736 3956 [ A065F048E9E23E6C026A7BB548D126A7 ] Bonjour Service D:\Program Files\Bonjour\mDNSResponder.exe
18:27:49.0752 3956 Bonjour Service - ok
18:27:49.0783 3956 [ A06CE3399D16DB864F55FAEB1F1927A9 ] Browser D:\WINDOWS\System32\browser.dll
18:27:49.0783 3956 Browser - ok
18:27:49.0814 3956 [ 90A673FC8E12A79AFBED2576F6A7AAF9 ] cbidf2k D:\WINDOWS\system32\drivers\cbidf2k.sys
18:27:49.0814 3956 cbidf2k - ok
18:27:49.0845 3956 [ 0BE5AEF125BE881C4F854C554F2B025C ] CCDECODE D:\WINDOWS\system32\DRIVERS\CCDECODE.sys
18:27:49.0845 3956 CCDECODE - ok
18:27:49.0892 3956 [ ACE85AF1C31F68BDFEE9333F6592917E ] ccSet_NIS D:\WINDOWS\system32\drivers\NIS\1308000.00E\ccSetx86.sys
18:27:49.0892 3956 ccSet_NIS - ok
18:27:49.0908 3956 cd20xrnt - ok
18:27:49.0908 3956 [ C1B486A7658353D33A10CC15211A873B ] Cdaudio D:\WINDOWS\system32\drivers\Cdaudio.sys
18:27:49.0908 3956 Cdaudio - ok
18:27:49.0924 3956 [ C885B02847F5D2FD45A24E219ED93B32 ] Cdfs D:\WINDOWS\system32\drivers\Cdfs.sys
18:27:49.0924 3956 Cdfs - ok
18:27:49.0970 3956 [ 1F4260CC5B42272D71F79E570A27A4FE ] Cdrom D:\WINDOWS\system32\DRIVERS\cdrom.sys
18:27:49.0970 3956 Cdrom - ok
18:27:49.0970 3956 Changer - ok
18:27:50.0002 3956 [ 1CFE720EB8D93A7158A4EBC3AB178BDE ] CiSvc D:\WINDOWS\system32\cisvc.exe
18:27:50.0033 3956 CiSvc - ok
18:27:50.0049 3956 [ 34CBE729F38138217F9C80212A2A0C82 ] ClipSrv D:\WINDOWS\system32\clipsrv.exe
18:27:50.0064 3956 ClipSrv - ok
18:27:50.0095 3956 [ D87ACAED61E417BBA546CED5E7E36D9C ] clr_optimization_v2.0.50727_32 D:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
18:27:50.0142 3956 clr_optimization_v2.0.50727_32 - ok
18:27:50.0174 3956 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
18:27:50.0267 3956 clr_optimization_v4.0.30319_32 - ok
18:27:50.0267 3956 CmdIde - ok
18:27:50.0267 3956 COMSysApp - ok
18:27:50.0283 3956 Cpqarray - ok
18:27:50.0314 3956 [ 3D4E199942E29207970E04315D02AD3B ] CryptSvc D:\WINDOWS\System32\cryptsvc.dll
18:27:50.0314 3956 CryptSvc - ok
18:27:50.0361 3956 [ 23D6D320C0D236784EF0CCF7CBF6C1C0 ] ctac32k D:\WINDOWS\system32\drivers\ctac32k.sys
18:27:50.0361 3956 ctac32k - ok
18:27:50.0424 3956 [ 16693A385321CEAC8F24A53070EFC378 ] ctaud2k D:\WINDOWS\system32\drivers\ctaud2k.sys
18:27:50.0439 3956 ctaud2k - ok
18:27:50.0470 3956 [ 71007BD2E1E26927FE3E4EB00C0BEEDF ] ctljystk D:\WINDOWS\system32\DRIVERS\ctljystk.sys
18:27:50.0470 3956 ctljystk - ok
18:27:50.0486 3956 [ 53B99368D26AB1BE9C3842976DF5543C ] ctprxy2k D:\WINDOWS\system32\drivers\ctprxy2k.sys
18:27:50.0502 3956 ctprxy2k - ok
18:27:50.0502 3956 [ 73746E147E50249B790BC631891063B5 ] ctsfm2k D:\WINDOWS\system32\drivers\ctsfm2k.sys
18:27:50.0517 3956 ctsfm2k - ok
18:27:50.0564 3956 [ CB6FF7012BB5D59D7C12350DB795CE1F ] ctxusbm D:\WINDOWS\system32\DRIVERS\ctxusbm.sys
18:27:50.0564 3956 ctxusbm - ok
18:27:50.0580 3956 dac2w2k - ok
18:27:50.0580 3956 dac960nt - ok
18:27:50.0689 3956 dbustrcm - ok
18:27:50.0736 3956 [ 6B27A5C03DFB94B4245739065431322C ] DcomLaunch D:\WINDOWS\system32\rpcss.dll
18:27:50.0736 3956 DcomLaunch - ok
18:27:50.0783 3956 [ 5E38D7684A49CACFB752B046357E0589 ] Dhcp D:\WINDOWS\System32\dhcpcsvc.dll
18:27:50.0783 3956 Dhcp - ok
18:27:50.0830 3956 [ 3C1D6D42719C86E8AAD361B60667B012 ] DirMngr D:\Program Files\GNU\GnuPG\dirmngr.exe
18:27:50.0845 3956 DirMngr - ok
18:27:50.0892 3956 [ 044452051F3E02E7963599FC8F4F3E25 ] Disk D:\WINDOWS\system32\DRIVERS\disk.sys
18:27:50.0892 3956 Disk - ok
18:27:50.0892 3956 dmadmin - ok
18:27:50.0924 3956 [ D992FE1274BDE0F84AD826ACAE022A41 ] dmboot D:\WINDOWS\system32\drivers\dmboot.sys
18:27:50.0986 3956 dmboot - ok
18:27:51.0002 3956 [ 7C824CF7BBDE77D95C08005717A95F6F ] dmio D:\WINDOWS\system32\drivers\dmio.sys
18:27:51.0017 3956 dmio - ok
18:27:51.0033 3956 [ E9317282A63CA4D188C0DF5E09C6AC5F ] dmload D:\WINDOWS\system32\drivers\dmload.sys
18:27:51.0064 3956 dmload - ok
18:27:51.0064 3956 [ 57EDEC2E5F59F0335E92F35184BC8631 ] dmserver D:\WINDOWS\System32\dmserver.dll
18:27:51.0064 3956 dmserver - ok
18:27:51.0111 3956 [ 8A208DFCF89792A484E76C40E5F50B45 ] DMusic D:\WINDOWS\system32\drivers\DMusic.sys
18:27:51.0111 3956 DMusic - ok
18:27:51.0142 3956 [ 474B4DC3983173E4B4C9740B0DAC98A6 ] Dnscache D:\WINDOWS\System32\dnsrslvr.dll
18:27:51.0142 3956 Dnscache - ok
18:27:51.0174 3956 [ 0F0F6E687E5E15579EF4DA8DD6945814 ] Dot3svc D:\WINDOWS\System32\dot3svc.dll
18:27:51.0174 3956 Dot3svc - ok
18:27:51.0174 3956 dpti2o - ok
18:27:51.0205 3956 [ 8F5FCFF8E8848AFAC920905FBD9D33C8 ] drmkaud D:\WINDOWS\system32\drivers\drmkaud.sys
18:27:51.0205 3956 drmkaud - ok
18:27:51.0205 3956 EagleNT - ok
18:27:51.0205 3956 EagleXNt - ok
18:27:51.0236 3956 [ 2187855A7703ADEF0CEF9EE4285182CC ] EapHost D:\WINDOWS\System32\eapsvc.dll
18:27:51.0236 3956 EapHost - ok
18:27:51.0314 3956 [ 85B8B4032A895A746D46A288A9B30DED ] eeCtrl D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys
18:27:51.0314 3956 eeCtrl - ok
18:27:51.0361 3956 [ 01F83E1B5DCE05F5CB7D99113CA9E890 ] emu10k D:\WINDOWS\system32\drivers\emu10k1m.sys
18:27:51.0361 3956 emu10k - ok
18:27:51.0377 3956 [ 7FFA171CCE6A8BFC774862A578BA39A2 ] emu10k1 D:\WINDOWS\system32\drivers\ctlfacem.sys
18:27:51.0392 3956 emu10k1 - ok
18:27:51.0439 3956 [ A75959F10B6B536982F872B55FC6CE27 ] emupia D:\WINDOWS\system32\drivers\emupia2k.sys
18:27:51.0439 3956 emupia - ok
18:27:51.0470 3956 [ B5A8A04A6E5B4E86B95B1553AA918F5F ] EraserUtilRebootDrv D:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys
18:27:51.0486 3956 EraserUtilRebootDrv - ok
18:27:51.0517 3956 [ BC93B4A066477954555966D77FEC9ECB ] ERSvc D:\WINDOWS\System32\ersvc.dll
18:27:51.0517 3956 ERSvc - ok
18:27:51.0549 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] Eventlog D:\WINDOWS\system32\services.exe
18:27:51.0549 3956 Eventlog - ok
18:27:51.0580 3956 [ D4991D98F2DB73C60D042F1AEF79EFAE ] EventSystem D:\WINDOWS\system32\es.dll
18:27:51.0595 3956 EventSystem - ok
18:27:51.0627 3956 [ 38D332A6D56AF32635675F132548343E ] Fastfat D:\WINDOWS\system32\drivers\Fastfat.sys
18:27:51.0642 3956 Fastfat - ok
18:27:51.0658 3956 [ 1926899BF9FFE2602B63074971700412 ] FastUserSwitchingCompatibility D:\WINDOWS\System32\shsvcs.dll
18:27:51.0674 3956 FastUserSwitchingCompatibility - ok
18:27:51.0689 3956 [ 92CDD60B6730B9F50F6A1A0C1F8CDC81 ] Fdc D:\WINDOWS\system32\DRIVERS\fdc.sys
18:27:51.0705 3956 Fdc - ok
18:27:51.0736 3956 [ D45926117EB9FA946A6AF572FBE1CAA3 ] Fips D:\WINDOWS\system32\drivers\Fips.sys
18:27:51.0736 3956 Fips - ok
18:27:51.0799 3956 [ 1F63900E2EB00101B9ACA2B7A870704E ] FLEXnet Licensing Service D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
18:27:51.0799 3956 FLEXnet Licensing Service - ok
18:27:51.0830 3956 [ 9D27E7B80BFCDF1CDD9B555862D5E7F0 ] Flpydisk D:\WINDOWS\system32\DRIVERS\flpydisk.sys
18:27:51.0830 3956 Flpydisk - ok
18:27:51.0877 3956 [ B2CF4B0786F8212CB92ED2B50C6DB6B0 ] FltMgr D:\WINDOWS\system32\DRIVERS\fltMgr.sys
18:27:51.0877 3956 FltMgr - ok
18:27:51.0955 3956 [ 8BA7C024070F2B7FDD98ED8A4BA41789 ] FontCache3.0.0.0 D:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
18:27:51.0955 3956 FontCache3.0.0.0 - ok
18:27:52.0002 3956 [ 3E1E2BD4F39B0E2B7DC4F4D2BCC2779A ] Fs_Rec D:\WINDOWS\system32\drivers\Fs_Rec.sys
18:27:52.0002 3956 Fs_Rec - ok
18:27:52.0002 3956 [ 6AC26732762483366C3969C9E4D2259D ] Ftdisk D:\WINDOWS\system32\DRIVERS\ftdisk.sys
18:27:52.0033 3956 Ftdisk - ok
18:27:52.0064 3956 [ 065639773D8B03F33577F6CDAEA21063 ] gameenum D:\WINDOWS\system32\DRIVERS\gameenum.sys
18:27:52.0064 3956 gameenum - ok
18:27:52.0080 3956 [ 8182FF89C65E4D38B2DE4BB0FB18564E ] GEARAspiWDM D:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys
18:27:52.0095 3956 GEARAspiWDM - ok
18:27:52.0127 3956 [ 0A02C63C8B144BD8C86B103DEE7C86A2 ] Gpc D:\WINDOWS\system32\DRIVERS\msgpc.sys
18:27:52.0142 3956 Gpc - ok
18:27:52.0189 3956 [ F02A533F517EB38333CB12A9E8963773 ] gupdate D:\Program Files\Google\Update\GoogleUpdate.exe
18:27:52.0189 3956 gupdate - ok
18:27:52.0189 3956 [ F02A533F517EB38333CB12A9E8963773 ] gupdatem D:\Program Files\Google\Update\GoogleUpdate.exe
18:27:52.0205 3956 gupdatem - ok
18:27:52.0236 3956 [ C1B577B2169900F4CF7190C39F085794 ] gusvc D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
18:27:52.0252 3956 gusvc - ok
18:27:52.0314 3956 [ BCB3281BFC4EEB8D82932669490013CD ] ha10kx2k D:\WINDOWS\system32\drivers\ha10kx2k.sys
18:27:52.0345 3956 ha10kx2k - ok
18:27:52.0392 3956 [ 833051C6C6C42117191935F734CFBD97 ] hamachi D:\WINDOWS\system32\DRIVERS\hamachi.sys
18:27:52.0408 3956 hamachi - ok
18:27:52.0455 3956 [ 573C7D0A32852B48F3058CFD8026F511 ] HDAudBus D:\WINDOWS\system32\DRIVERS\HDAudBus.sys
18:27:52.0455 3956 HDAudBus - ok
18:27:52.0549 3956 [ 4FCCA060DFE0C51A09DD5C3843888BCD ] helpsvc D:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll
18:27:52.0549 3956 helpsvc - ok
18:27:52.0580 3956 [ DEB04DA35CC871B6D309B77E1443C796 ] HidServ D:\WINDOWS\System32\hidserv.dll
18:27:52.0580 3956 HidServ - ok
18:27:52.0611 3956 [ CCF82C5EC8A7326C3066DE870C06DAF1 ] hidusb D:\WINDOWS\system32\DRIVERS\hidusb.sys
18:27:52.0627 3956 hidusb - ok
18:27:52.0658 3956 [ 8878BD685E490239777BFE51320B88E9 ] hkmsvc D:\WINDOWS\System32\kmsvc.dll
18:27:52.0658 3956 hkmsvc - ok
18:27:52.0658 3956 hpn - ok
18:27:52.0689 3956 [ F6AACF5BCE2893E0C1754AFEB672E5C9 ] HTTP D:\WINDOWS\system32\Drivers\HTTP.sys
18:27:52.0705 3956 HTTP - ok
18:27:52.0736 3956 [ 6100A808600F44D999CEBDEF8841C7A3 ] HTTPFilter D:\WINDOWS\System32\w3ssl.dll
18:27:52.0736 3956 HTTPFilter - ok
18:27:52.0736 3956 i2omgmt - ok
18:27:52.0736 3956 i2omp - ok
18:27:52.0767 3956 [ 4A0B06AA8943C1E332520F7440C0AA30 ] i8042prt D:\WINDOWS\system32\DRIVERS\i8042prt.sys
18:27:52.0783 3956 i8042prt - ok
18:27:52.0830 3956 [ 1CF03C69B49ACB70C722DF92755C0C8C ] IDriverT D:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
18:27:52.0861 3956 IDriverT - ok
18:27:52.0908 3956 [ C01AC32DC5C03076CFB852CB5DA5229C ] idsvc D:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
18:27:52.0955 3956 idsvc - ok
18:27:53.0158 3956 [ C19BF2A07BE972A110220DF6B1E89D14 ] IDSxpx86 D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120901.001\IDSxpx86.sys
18:27:53.0158 3956 IDSxpx86 - ok
18:27:53.0205 3956 [ 083A052659F5310DD8B6A6CB05EDCF8E ] Imapi D:\WINDOWS\system32\DRIVERS\imapi.sys
18:27:53.0220 3956 Imapi - ok
18:27:53.0252 3956 [ 30DEAF54A9755BB8546168CFE8A6B5E1 ] ImapiService D:\WINDOWS\system32\imapi.exe
18:27:53.0252 3956 ImapiService - ok
18:27:53.0267 3956 ini910u - ok
18:27:53.0392 3956 [ 4808A5FEF0BF1ACA59300F09920A9CF8 ] IntcAzAudAddService D:\WINDOWS\system32\drivers\RtkHDAud.sys
18:27:53.0533 3956 IntcAzAudAddService - ok
18:27:53.0549 3956 [ B5466A9250342A7AA0CD1FBA13420678 ] IntelIde D:\WINDOWS\system32\DRIVERS\intelide.sys
18:27:53.0564 3956 IntelIde - ok
18:27:53.0611 3956 [ 8C953733D8F36EB2133F5BB58808B66B ] intelppm D:\WINDOWS\system32\DRIVERS\intelppm.sys
18:27:53.0611 3956 intelppm - ok
18:27:53.0689 3956 [ 3BB22519A194418D5FEC05D800A19AD0 ] Ip6Fw D:\WINDOWS\system32\DRIVERS\Ip6Fw.sys
18:27:53.0689 3956 Ip6Fw - ok
18:27:53.0720 3956 [ 731F22BA402EE4B62748ADAF6363C182 ] IpFilterDriver D:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
18:27:53.0736 3956 IpFilterDriver - ok
18:27:53.0752 3956 [ B87AB476DCF76E72010632B5550955F5 ] IpInIp D:\WINDOWS\system32\DRIVERS\ipinip.sys
18:27:53.0752 3956 IpInIp - ok
18:27:53.0767 3956 [ CC748EA12C6EFFDE940EE98098BF96BB ] IpNat D:\WINDOWS\system32\DRIVERS\ipnat.sys
18:27:53.0783 3956 IpNat - ok
18:27:53.0799 3956 [ D8389F60EC63FB8197772349E82B5BB7 ] iPod Service D:\Program Files\iPod\bin\iPodService.exe
18:27:53.0814 3956 iPod Service - ok
18:27:53.0814 3956 [ 23C74D75E36E7158768DD63D92789A91 ] IPSec D:\WINDOWS\system32\DRIVERS\ipsec.sys
18:27:53.0814 3956 IPSec - ok
18:27:53.0845 3956 [ C93C9FF7B04D772627A3646D89F7BF89 ] IRENUM D:\WINDOWS\system32\DRIVERS\irenum.sys
18:27:53.0845 3956 IRENUM - ok
18:27:53.0892 3956 [ 05A299EC56E52649B1CF2FC52D20F2D7 ] isapnp D:\WINDOWS\system32\DRIVERS\isapnp.sys
18:27:53.0908 3956 isapnp - ok
18:27:54.0002 3956 [ 80F08F50D248EEEEB9256F6522891D40 ] JavaQuickStarterService D:\Program Files\Java\jre7\bin\jqs.exe
18:27:54.0002 3956 JavaQuickStarterService - ok
18:27:54.0049 3956 [ 463C1EC80CD17420A542B7F36A36F128 ] Kbdclass D:\WINDOWS\system32\DRIVERS\kbdclass.sys
18:27:54.0049 3956 Kbdclass - ok
18:27:54.0080 3956 [ 9EF487A186DEA361AA06913A75B3FA99 ] kbdhid D:\WINDOWS\system32\DRIVERS\kbdhid.sys
18:27:54.0080 3956 kbdhid - ok
18:27:54.0111 3956 [ 692BCF44383D056AED41B045A323D378 ] kmixer D:\WINDOWS\system32\drivers\kmixer.sys
18:27:54.0111 3956 kmixer - ok
18:27:54.0158 3956 [ B467646C54CC746128904E1654C750C1 ] KSecDD D:\WINDOWS\system32\drivers\KSecDD.sys
18:27:54.0158 3956 KSecDD - ok
18:27:54.0189 3956 [ F385F4B02C535BFFE1D70CAB80838123 ] LanmanServer D:\WINDOWS\System32\srvsvc.dll
18:27:54.0189 3956 LanmanServer - ok
18:27:54.0220 3956 [ A8888A5327621856C0CEC4E385F69309 ] lanmanworkstation D:\WINDOWS\System32\wkssvc.dll
18:27:54.0220 3956 lanmanworkstation - ok
18:27:54.0220 3956 lbrtfdc - ok
18:27:54.0267 3956 [ A7DB739AE99A796D91580147E919CC59 ] LmHosts D:\WINDOWS\System32\lmhsvc.dll
18:27:54.0267 3956 LmHosts - ok
18:27:54.0267 3956 McShield - ok
18:27:54.0267 3956 McSysmon - ok
18:27:54.0299 3956 [ 986B1FF5814366D71E0AC5755C88F2D3 ] Messenger D:\WINDOWS\System32\msgsvc.dll
18:27:54.0299 3956 Messenger - ok
18:27:54.0330 3956 [ BAFDD5E28BAEA99D7F4772AF2F5EC7EE ] mfeavfk D:\WINDOWS\system32\drivers\mfeavfk.sys
18:27:54.0345 3956 mfeavfk - ok
18:27:54.0377 3956 [ 1D003E3056A43D881597D6763E83B943 ] mfebopk D:\WINDOWS\system32\drivers\mfebopk.sys
18:27:54.0392 3956 mfebopk - ok
18:27:54.0424 3956 [ 3F138A1C8A0659F329F242D1E389B2CF ] mfehidk D:\WINDOWS\system32\drivers\mfehidk.sys
18:27:54.0424 3956 mfehidk - ok
18:27:54.0455 3956 [ 41FE2F288E05A6C8AB85DD56770FFBAD ] mferkdk D:\WINDOWS\system32\drivers\mferkdk.sys
18:27:54.0455 3956 mferkdk - ok
18:27:54.0470 3956 [ 096B52EA918AA909BA5903D79E129005 ] mfesmfk D:\WINDOWS\system32\drivers\mfesmfk.sys
18:27:54.0486 3956 mfesmfk - ok
18:27:54.0517 3956 [ 4AE068242760A1FB6E1A44BF4E16AFA6 ] mnmdd D:\WINDOWS\system32\drivers\mnmdd.sys
18:27:54.0533 3956 mnmdd - ok
18:27:54.0564 3956 [ D18F1F0C101D06A1C1ADF26EED16FCDD ] mnmsrvc D:\WINDOWS\system32\mnmsrvc.exe
18:27:54.0580 3956 mnmsrvc - ok
18:27:54.0595 3956 [ DFCBAD3CEC1C5F964962AE10E0BCC8E1 ] Modem D:\WINDOWS\system32\drivers\Modem.sys
18:27:54.0595 3956 Modem - ok
18:27:54.0642 3956 [ C7D9F9717916B34C1B00DD4834AF485C ] Monfilt D:\WINDOWS\system32\drivers\Monfilt.sys
18:27:54.0705 3956 Monfilt - ok
18:27:54.0720 3956 [ 35C9E97194C8CFB8430125F8DBC34D04 ] Mouclass D:\WINDOWS\system32\DRIVERS\mouclass.sys
18:27:54.0720 3956 Mouclass - ok
18:27:54.0767 3956 [ B1C303E17FB9D46E87A98E4BA6769685 ] mouhid D:\WINDOWS\system32\DRIVERS\mouhid.sys
18:27:54.0767 3956 mouhid - ok
18:27:54.0799 3956 [ A80B9A0BAD1B73637DBCBBA7DF72D3FD ] MountMgr D:\WINDOWS\system32\drivers\MountMgr.sys
18:27:54.0799 3956 MountMgr - ok
18:27:54.0861 3956 [ CB8AF049AC9BE419A77ADAE288673359 ] MozillaMaintenance D:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
18:27:54.0877 3956 MozillaMaintenance - ok
18:27:54.0877 3956 mraid35x - ok
18:27:54.0908 3956 [ 11D42BB6206F33FBB3BA0288D3EF81BD ] MRxDAV D:\WINDOWS\system32\DRIVERS\mrxdav.sys
18:27:54.0908 3956 MRxDAV - ok
18:27:54.0970 3956 [ 60AE98742484E7AB80C3C1450E708148 ] MRxSmb D:\WINDOWS\system32\DRIVERS\mrxsmb.sys
18:27:54.0970 3956 MRxSmb - ok
18:27:55.0002 3956 [ A137F1470499A205ABBB9AAFB3B6F2B1 ] MSDTC D:\WINDOWS\system32\msdtc.exe
18:27:55.0002 3956 MSDTC - ok
18:27:55.0017 3956 [ C941EA2454BA8350021D774DAF0F1027 ] Msfs D:\WINDOWS\system32\drivers\Msfs.sys
18:27:55.0017 3956 Msfs - ok
18:27:55.0017 3956 MSIServer - ok
18:27:55.0049 3956 [ D1575E71568F4D9E14CA56B7B0453BF1 ] MSKSSRV D:\WINDOWS\system32\drivers\MSKSSRV.sys
18:27:55.0049 3956 MSKSSRV - ok
18:27:55.0064 3956 [ 325BB26842FC7CCC1FCCE2C457317F3E ] MSPCLOCK D:\WINDOWS\system32\drivers\MSPCLOCK.sys
18:27:55.0064 3956 MSPCLOCK - ok
18:27:55.0064 3956 [ BAD59648BA099DA4A17680B39730CB3D ] MSPQM D:\WINDOWS\system32\drivers\MSPQM.sys
18:27:55.0064 3956 MSPQM - ok
18:27:55.0095 3956 [ AF5F4F3F14A8EA2C26DE30F7A1E17136 ] mssmbios D:\WINDOWS\system32\DRIVERS\mssmbios.sys
18:27:55.0095 3956 mssmbios - ok
18:27:55.0142 3956 [ E53736A9E30C45FA9E7B5EAC55056D1D ] MSTEE D:\WINDOWS\system32\drivers\MSTEE.sys
18:27:55.0142 3956 MSTEE - ok
18:27:55.0174 3956 [ 2F625D11385B1A94360BFC70AAEFDEE1 ] Mup D:\WINDOWS\system32\drivers\Mup.sys
18:27:55.0174 3956 Mup - ok
18:27:55.0189 3956 [ 5B50F1B2A2ED47D560577B221DA734DB ] NABTSFEC D:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
18:27:55.0205 3956 NABTSFEC - ok
18:27:55.0236 3956 [ 0102140028FAD045756796E1C685D695 ] napagent D:\WINDOWS\System32\qagentrt.dll
18:27:55.0267 3956 napagent - ok
18:27:55.0330 3956 [ FA0B7D801E71CE79B915BAE5A90DE224 ] NAVENG D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120907.034\NAVENG.SYS
18:27:55.0330 3956 NAVENG - ok
18:27:55.0377 3956 [ 80BB71A7D14CF14B54514A201BF5B985 ] NAVEX15 D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120907.034\NAVEX15.SYS
18:27:55.0424 3956 NAVEX15 - ok
18:27:55.0470 3956 [ 1DF7F42665C94B825322FAE71721130D ] NDIS D:\WINDOWS\system32\drivers\NDIS.sys
18:27:55.0470 3956 NDIS - ok
18:27:55.0502 3956 [ 7FF1F1FD8609C149AA432F95A8163D97 ] NdisIP D:\WINDOWS\system32\DRIVERS\NdisIP.sys
18:27:55.0502 3956 NdisIP - ok
18:27:55.0517 3956 [ 1AB3D00C991AB086E69DB84B6C0ED78F ] NdisTapi D:\WINDOWS\system32\DRIVERS\ndistapi.sys
18:27:55.0517 3956 NdisTapi - ok
18:27:55.0533 3956 [ F927A4434C5028758A842943EF1A3849 ] Ndisuio D:\WINDOWS\system32\DRIVERS\ndisuio.sys
18:27:55.0533 3956 Ndisuio - ok
18:27:55.0549 3956 [ EDC1531A49C80614B2CFDA43CA8659AB ] NdisWan D:\WINDOWS\system32\DRIVERS\ndiswan.sys
18:27:55.0549 3956 NdisWan - ok
18:27:55.0549 3956 [ 6215023940CFD3702B46ABC304E1D45A ] NDProxy D:\WINDOWS\system32\drivers\NDProxy.sys
18:27:55.0564 3956 NDProxy - ok
18:27:55.0564 3956 [ 5D81CF9A2F1A3A756B66CF684911CDF0 ] NetBIOS D:\WINDOWS\system32\DRIVERS\netbios.sys
18:27:55.0564 3956 NetBIOS - ok
18:27:55.0580 3956 [ 74B2B2F5BEA5E9A3DC021D685551BD3D ] NetBT D:\WINDOWS\system32\DRIVERS\netbt.sys
18:27:55.0580 3956 NetBT - ok
18:27:55.0595 3956 [ B857BA82860D7FF85AE29B095645563B ] NetDDE D:\WINDOWS\system32\netdde.exe
18:27:55.0611 3956 NetDDE - ok
18:27:55.0627 3956 [ B857BA82860D7FF85AE29B095645563B ] NetDDEdsdm D:\WINDOWS\system32\netdde.exe
18:27:55.0627 3956 NetDDEdsdm - ok
18:27:55.0658 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] Netlogon D:\WINDOWS\system32\lsass.exe
18:27:55.0658 3956 Netlogon - ok
18:27:55.0674 3956 [ 13E67B55B3ABD7BF3FE7AAE5A0F9A9DE ] Netman D:\WINDOWS\System32\netman.dll
18:27:55.0689 3956 Netman - ok
18:27:55.0752 3956 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
18:27:55.0814 3956 NetTcpPortSharing - ok
18:27:55.0845 3956 [ E9E47CFB2D461FA0FC75B7A74C6383EA ] NIC1394 D:\WINDOWS\system32\DRIVERS\nic1394.sys
18:27:55.0845 3956 NIC1394 - ok
18:27:55.0939 3956 [ F2840DBFE9322F35557219AE82CC4597 ] NIS D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe
18:27:55.0939 3956 NIS - ok
18:27:55.0970 3956 [ 832E4DD8964AB7ACC880B2837CB1ED20 ] Nla D:\WINDOWS\System32\mswsock.dll
18:27:55.0986 3956 Nla - ok
18:27:56.0017 3956 [ 3182D64AE053D6FB034F44B6DEF8034A ] Npfs D:\WINDOWS\system32\drivers\Npfs.sys
18:27:56.0017 3956 Npfs - ok
18:27:56.0033 3956 npggsvc - ok
18:27:56.0033 3956 [ 78A08DD6A8D65E697C18E1DB01C5CDCA ] Ntfs D:\WINDOWS\system32\drivers\Ntfs.sys
18:27:56.0049 3956 Ntfs - ok
18:27:56.0080 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] NtLmSsp D:\WINDOWS\system32\lsass.exe
18:27:56.0080 3956 NtLmSsp - ok
18:27:56.0111 3956 [ 156F64A3345BD23C600655FB4D10BC08 ] NtmsSvc D:\WINDOWS\system32\ntmssvc.dll
18:27:56.0127 3956 NtmsSvc - ok
18:27:56.0174 3956 [ 73C1E1F395918BC2C6DD67AF7591A3AD ] Null D:\WINDOWS\system32\drivers\Null.sys
18:27:56.0174 3956 Null - ok
18:27:56.0439 3956 [ 18C9B152DA7BEA76B2F9E4B6412E0AAF ] nv D:\WINDOWS\system32\DRIVERS\nv4_mini.sys
18:27:56.0689 3956 nv - ok
18:27:56.0705 3956 [ EF9941593B2E9B436F64A87DDB570D1A ] nvatabus D:\WINDOWS\system32\DRIVERS\nvatabus.sys
18:27:56.0720 3956 nvatabus - ok
18:27:56.0736 3956 [ 0AE6258709D58FB53638E8D28F4480D4 ] NVENETFD D:\WINDOWS\system32\DRIVERS\NVENETFD.sys
18:27:56.0767 3956 NVENETFD - ok
18:27:56.0799 3956 [ 50ACB7253D1104E5917E15A0670D63D5 ] NVHDA D:\WINDOWS\system32\drivers\nvhda32.sys
18:27:56.0814 3956 NVHDA - ok
18:27:56.0830 3956 [ 1296B33C223A58485D5EAA779752216A ] nvnetbus D:\WINDOWS\system32\DRIVERS\nvnetbus.sys
18:27:56.0845 3956 nvnetbus - ok
18:27:56.0861 3956 [ EA4017441889A7E66D8A77BD41AC11C0 ] nvraid D:\WINDOWS\system32\DRIVERS\nvraid.sys
18:27:56.0861 3956 nvraid - ok
18:27:56.0908 3956 [ A8C1E6FF53FB0628A302843EA5FA5AB6 ] NVSvc D:\WINDOWS\system32\nvsvc32.exe
18:27:56.0924 3956 NVSvc - ok
18:27:56.0955 3956 [ B305F3FAD35083837EF46A0BBCE2FC57 ] NwlnkFlt D:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
18:27:56.0970 3956 NwlnkFlt - ok
18:27:57.0002 3956 [ C99B3415198D1AAB7227F2C88FD664B9 ] NwlnkFwd D:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
18:27:57.0017 3956 NwlnkFwd - ok
18:27:57.0033 3956 [ CA33832DF41AFB202EE7AEB05145922F ] ohci1394 D:\WINDOWS\system32\DRIVERS\ohci1394.sys
18:27:57.0033 3956 ohci1394 - ok
18:27:57.0064 3956 [ 64DE7FDE0AAC66F721ADDD1E0394E664 ] ossrv D:\WINDOWS\system32\drivers\ctoss2k.sys
18:27:57.0064 3956 ossrv - ok
18:27:57.0080 3956 [ 5575FAF8F97CE5E713D108C2A58D7C7C ] Parport D:\WINDOWS\system32\DRIVERS\parport.sys
18:27:57.0095 3956 Parport - ok
18:27:57.0111 3956 [ BEB3BA25197665D82EC7065B724171C6 ] PartMgr D:\WINDOWS\system32\drivers\PartMgr.sys
18:27:57.0127 3956 PartMgr - ok
18:27:57.0142 3956 [ 70E98B3FD8E963A6A46A2E6247E0BEA1 ] ParVdm D:\WINDOWS\system32\drivers\ParVdm.sys
18:27:57.0142 3956 ParVdm - ok
18:27:57.0174 3956 [ A219903CCF74233761D92BEF471A07B1 ] PCI D:\WINDOWS\system32\DRIVERS\pci.sys
18:27:57.0189 3956 PCI - ok
18:27:57.0189 3956 PCIDump - ok
18:27:57.0189 3956 [ CCF5F451BB1A5A2A522A76E670000FF0 ] PCIIde D:\WINDOWS\system32\DRIVERS\pciide.sys
18:27:57.0220 3956 PCIIde - ok
18:27:57.0252 3956 [ 9E89EF60E9EE05E3F2EEF2DA7397F1C1 ] Pcmcia D:\WINDOWS\system32\drivers\Pcmcia.sys
18:27:57.0252 3956 Pcmcia - ok
18:27:57.0283 3956 [ 02AAAFB7BA137CE5DDABCDF8090954D9 ] pcouffin D:\WINDOWS\system32\Drivers\pcouffin.sys
18:27:57.0283 3956 pcouffin - ok
18:27:57.0283 3956 PDCOMP - ok
18:27:57.0283 3956 PDFRAME - ok
18:27:57.0299 3956 PDRELI - ok
18:27:57.0299 3956 PDRFRAME - ok
18:27:57.0314 3956 perc2 - ok
18:27:57.0314 3956 perc2hib - ok
18:27:57.0361 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] PlugPlay D:\WINDOWS\system32\services.exe
18:27:57.0361 3956 PlugPlay - ok
18:27:57.0392 3956 [ 9A386EC60A166DF66205343CA12C6B86 ] PnkBstrB D:\WINDOWS\system32\PnkBstrB.exe
18:27:57.0408 3956 PnkBstrB - ok
18:27:57.0439 3956 [ 10BE25C04613B70D8CE1F412E14D9454 ] PnkBstrK D:\WINDOWS\system32\drivers\PnkBstrK.sys
18:27:57.0455 3956 PnkBstrK - ok
18:27:57.0486 3956 [ 60A044879C4FA76314494F5FDDC43B93 ] Point32 D:\WINDOWS\system32\DRIVERS\point32.sys
18:27:57.0486 3956 Point32 - ok
18:27:57.0502 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] PolicyAgent D:\WINDOWS\system32\lsass.exe
18:27:57.0502 3956 PolicyAgent - ok
18:27:57.0549 3956 [ EFEEC01B1D3CF84F16DDD24D9D9D8F99 ] PptpMiniport D:\WINDOWS\system32\DRIVERS\raspptp.sys
18:27:57.0549 3956 PptpMiniport - ok
18:27:57.0549 3956 [ A32BEBAF723557681BFC6BD93E98BD26 ] Processor D:\WINDOWS\system32\DRIVERS\processr.sys
18:27:57.0564 3956 Processor - ok
18:27:57.0564 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] ProtectedStorage D:\WINDOWS\system32\lsass.exe
18:27:57.0564 3956 ProtectedStorage - ok
18:27:57.0564 3956 [ 09298EC810B07E5D582CB3A3F9255424 ] PSched D:\WINDOWS\system32\DRIVERS\psched.sys
18:27:57.0564 3956 PSched - ok
18:27:57.0611 3956 [ 80D317BD1C3DBC5D4FE7B1678C60CADD ] Ptilink D:\WINDOWS\system32\DRIVERS\ptilink.sys
18:27:57.0627 3956 Ptilink - ok
18:27:57.0658 3956 [ 153D02480A0A2F45785522E814C634B6 ] PxHelp20 D:\WINDOWS\system32\Drivers\PxHelp20.sys
18:27:57.0658 3956 PxHelp20 - ok
18:27:57.0705 3956 [ FDDD1AEB9F81EF1E6E48AE1EDC2A97D6 ] QCDonner D:\WINDOWS\system32\DRIVERS\OVCD.sys
18:27:57.0720 3956 QCDonner - ok
18:27:57.0720 3956 ql1080 - ok
18:27:57.0720 3956 Ql10wnt - ok
18:27:57.0736 3956 ql12160 - ok
18:27:57.0736 3956 ql1240 - ok
18:27:57.0752 3956 ql1280 - ok
18:27:57.0783 3956 [ FE0D99D6F31E4FAD8159F690D68DED9C ] RasAcd D:\WINDOWS\system32\DRIVERS\rasacd.sys
18:27:57.0783 3956 RasAcd - ok
18:27:57.0814 3956 [ AD188BE7BDF94E8DF4CA0A55C00A5073 ] RasAuto D:\WINDOWS\System32\rasauto.dll
18:27:57.0814 3956 RasAuto - ok
18:27:57.0830 3956 [ 11B4A627BC9614B885C4969BFA5FF8A6 ] Rasl2tp D:\WINDOWS\system32\DRIVERS\rasl2tp.sys
18:27:57.0845 3956 Rasl2tp - ok
18:27:57.0845 3956 [ 76A9A3CBEADD68CC57CDA5E1D7448235 ] RasMan D:\WINDOWS\System32\rasmans.dll
18:27:57.0861 3956 RasMan - ok
18:27:57.0861 3956 [ 5BC962F2654137C9909C3D4603587DEE ] RasPppoe D:\WINDOWS\system32\DRIVERS\raspppoe.sys
18:27:57.0861 3956 RasPppoe - ok
18:27:57.0877 3956 [ FDBB1D60066FCFBB7452FD8F9829B242 ] Raspti D:\WINDOWS\system32\DRIVERS\raspti.sys
18:27:57.0877 3956 Raspti - ok
18:27:57.0892 3956 [ 7AD224AD1A1437FE28D89CF22B17780A ] Rdbss D:\WINDOWS\system32\DRIVERS\rdbss.sys
18:27:57.0892 3956 Rdbss - ok
18:27:57.0939 3956 [ 4912D5B403614CE99C28420F75353332 ] RDPCDD D:\WINDOWS\system32\DRIVERS\RDPCDD.sys
18:27:57.0939 3956 RDPCDD - ok
18:27:57.0970 3956 [ 15CABD0F7C00C47C70124907916AF3F1 ] rdpdr D:\WINDOWS\system32\DRIVERS\rdpdr.sys
18:27:57.0986 3956 rdpdr - ok
18:27:58.0017 3956 [ 6728E45B66F93C08F11DE2E316FC70DD ] RDPWD D:\WINDOWS\system32\drivers\RDPWD.sys
18:27:58.0017 3956 RDPWD - ok
18:27:58.0033 3956 [ 3C37BF86641BDA977C3BF8A840F3B7FA ] RDSessMgr D:\WINDOWS\system32\sessmgr.exe
18:27:58.0033 3956 RDSessMgr - ok
18:27:58.0064 3956 [ F828DD7E1419B6653894A8F97A0094C5 ] redbook D:\WINDOWS\system32\DRIVERS\redbook.sys
18:27:58.0064 3956 redbook - ok
18:27:58.0111 3956 [ 7E699FF5F59B5D9DE5390E3C34C67CF5 ] RemoteAccess D:\WINDOWS\System32\mprdim.dll
18:27:58.0111 3956 RemoteAccess - ok
18:27:58.0127 3956 [ 5B19B557B0C188210A56A6B699D90B8F ] RemoteRegistry D:\WINDOWS\system32\regsvc.dll
18:27:58.0142 3956 RemoteRegistry - ok
18:27:58.0158 3956 [ AAED593F84AFA419BBAE8572AF87CF6A ] RpcLocator D:\WINDOWS\system32\locator.exe
18:27:58.0158 3956 RpcLocator - ok
18:27:58.0189 3956 [ 6B27A5C03DFB94B4245739065431322C ] RpcSs D:\WINDOWS\system32\rpcss.dll
18:27:58.0205 3956 RpcSs - ok
18:27:58.0220 3956 [ 471B3F9741D762ABE75E9DEEA4787E47 ] RSVP D:\WINDOWS\system32\rsvp.exe
18:27:58.0252 3956 RSVP - ok
18:27:58.0283 3956 [ 6FD9C99F0B8617122AE27392AB1B3059 ] RTLE8023xp D:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
18:27:58.0299 3956 RTLE8023xp - ok
18:27:58.0314 3956 [ BF2466B3E18E970D8A976FB95FC1CA85 ] SamSs D:\WINDOWS\system32\lsass.exe
18:27:58.0314 3956 SamSs - ok
18:27:58.0361 3956 [ 86D007E7A654B9A71D1D7D856B104353 ] SCardSvr D:\WINDOWS\System32\SCardSvr.exe
18:27:58.0377 3956 SCardSvr - ok
18:27:58.0424 3956 [ F441BA47BD8610CB9536965BD7D1F943 ] SCDEmu D:\WINDOWS\system32\drivers\SCDEmu.sys
18:27:58.0424 3956 SCDEmu - ok
18:27:58.0439 3956 [ 0A9A7365A1CA4319AA7C1D6CD8E4EAFA ] Schedule D:\WINDOWS\system32\schedsvc.dll
18:27:58.0455 3956 Schedule - ok
18:27:58.0470 3956 [ 90A3935D05B494A5A39D37E71F09A677 ] Secdrv D:\WINDOWS\system32\DRIVERS\secdrv.sys
18:27:58.0470 3956 Secdrv - ok
18:27:58.0486 3956 [ CBE612E2BB6A10E3563336191EDA1250 ] seclogon D:\WINDOWS\System32\seclogon.dll
18:27:58.0486 3956 seclogon - ok
18:27:58.0517 3956 [ 7FDD5D0684ECA8C1F68B4D99D124DCD0 ] SENS D:\WINDOWS\system32\sens.dll
18:27:58.0517 3956 SENS - ok
18:27:58.0533 3956 [ 0F29512CCD6BEAD730039FB4BD2C85CE ] serenum D:\WINDOWS\system32\DRIVERS\serenum.sys
18:27:58.0533 3956 serenum - ok
18:27:58.0549 3956 [ CCA207A8896D4C6A0C9CE29A4AE411A7 ] Serial D:\WINDOWS\system32\DRIVERS\serial.sys
18:27:58.0549 3956 Serial - ok
18:27:58.0642 3956 [ 56250672235BBE54BA8A4963B1AC997C ] sfdrv01 D:\WINDOWS\system32\drivers\sfdrv01.sys
18:27:58.0658 3956 sfdrv01 - ok
18:27:58.0658 3956 [ 3AD2B15CCC03FEBFBAF5FF057822AA75 ] sfhlp02 D:\WINDOWS\system32\drivers\sfhlp02.sys
18:27:58.0674 3956 sfhlp02 - ok
18:27:58.0705 3956 [ 8E6B8C671615D126FDC553D1E2DE5562 ] Sfloppy D:\WINDOWS\system32\drivers\Sfloppy.sys
18:27:58.0720 3956 Sfloppy - ok
18:27:58.0752 3956 [ 0B1A5E9CACB5CDD54A2815107BD7C772 ] sfman D:\WINDOWS\system32\drivers\sfmanm.sys
18:27:58.0752 3956 sfman - ok
18:27:58.0767 3956 [ 798D918D8F20380008277CE3CE5319D1 ] sfsync02 D:\WINDOWS\system32\drivers\sfsync02.sys
18:27:58.0767 3956 sfsync02 - ok
18:27:58.0783 3956 [ 83F41D0D89645D7235C051AB1D9523AC ] SharedAccess D:\WINDOWS\System32\ipnathlp.dll
18:27:58.0783 3956 SharedAccess - ok
18:27:58.0814 3956 [ 1926899BF9FFE2602B63074971700412 ] ShellHWDetection D:\WINDOWS\System32\shsvcs.dll
18:27:58.0814 3956 ShellHWDetection - ok
18:27:58.0830 3956 Simbad - ok
18:27:58.0877 3956 [ F07AF60B152221472FBDB2FECEC4896D ] SkypeUpdate D:\Program Files\Skype\Updater\Updater.exe
18:27:58.0877 3956 SkypeUpdate - ok
18:27:58.0892 3956 [ 866D538EBE33709A5C9F5C62B73B7D14 ] SLIP D:\WINDOWS\system32\DRIVERS\SLIP.sys
18:27:58.0892 3956 SLIP - ok
18:27:58.0908 3956 Sparrow - ok
18:27:58.0939 3956 [ AB8B92451ECB048A4D1DE7C3FFCB4A9F ] splitter D:\WINDOWS\system32\drivers\splitter.sys
18:27:58.0939 3956 splitter - ok
18:27:58.0970 3956 [ D8E14A61ACC1D4A6CD0D38AEBAC7FA3B ] Spooler D:\WINDOWS\system32\spoolsv.exe
18:27:58.0970 3956 Spooler - ok
18:27:59.0002 3956 [ CDDDEC541BC3C96F91ECB48759673505 ] sptd D:\WINDOWS\system32\Drivers\sptd.sys
18:27:59.0002 3956 Suspicious file (NoAccess): D:\WINDOWS\system32\Drivers\sptd.sys. md5: CDDDEC541BC3C96F91ECB48759673505
18:27:59.0002 3956 sptd ( LockedFile.Multi.Generic ) - warning
18:27:59.0002 3956 sptd - detected LockedFile.Multi.Generic (1)
18:27:59.0033 3956 [ 76BB022C2FB6902FD5BDD4F78FC13A5D ] sr D:\WINDOWS\system32\DRIVERS\sr.sys
18:27:59.0049 3956 sr - ok
18:27:59.0064 3956 [ 3805DF0AC4296A34BA4BF93B346CC378 ] srservice D:\WINDOWS\system32\srsvc.dll
18:27:59.0064 3956 srservice - ok
18:27:59.0127 3956 [ 7BB297CADA42903328E92425D9761DA6 ] SRTSP D:\WINDOWS\System32\Drivers\NIS\1308000.00E\SRTSP.SYS
18:27:59.0142 3956 SRTSP - ok
18:27:59.0174 3956 [ 475FCF0F28D845BF1C8ABAC27F19003E ] SRTSPX D:\WINDOWS\system32\drivers\NIS\1308000.00E\SRTSPX.SYS
18:27:59.0174 3956 SRTSPX - ok
18:27:59.0220 3956 [ 3BB03F2BA89D2BE417206C373D2AF17C ] Srv D:\WINDOWS\system32\DRIVERS\srv.sys
18:27:59.0220 3956 Srv - ok
18:27:59.0252 3956 [ 0A5679B3714EDAB99E357057EE88FCA6 ] SSDPSRV D:\WINDOWS\System32\ssdpsrv.dll
18:27:59.0267 3956 SSDPSRV - ok
18:27:59.0283 3956 Steam Client Service - ok
18:27:59.0314 3956 [ 8BAD69CBAC032D4BBACFCE0306174C30 ] stisvc D:\WINDOWS\system32\wiaservc.dll
18:27:59.0330 3956 stisvc - ok
18:27:59.0361 3956 [ 77813007BA6265C4B6098187E6ED79D2 ] streamip D:\WINDOWS\system32\DRIVERS\StreamIP.sys
18:27:59.0361 3956 streamip - ok
18:27:59.0392 3956 [ 3941D127AEF12E93ADDF6FE6EE027E0F ] swenum D:\WINDOWS\system32\DRIVERS\swenum.sys
18:27:59.0392 3956 swenum - ok
18:27:59.0486 3956 [ F577910A133A592234EBAAD3F3AFA258 ] SwitchBoard D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
18:27:59.0486 3956 SwitchBoard - ok
18:27:59.0517 3956 [ 8CE882BCC6CF8A62F2B2323D95CB3D01 ] swmidi D:\WINDOWS\system32\drivers\swmidi.sys
18:27:59.0517 3956 swmidi - ok
18:27:59.0533 3956 SwPrv - ok
18:27:59.0533 3956 symc810 - ok
18:27:59.0533 3956 symc8xx - ok
18:27:59.0580 3956 [ 690FA0E61B90084C4D9A721BD4F3D779 ] SymDS D:\WINDOWS\system32\drivers\NIS\1308000.00E\SYMDS.SYS
18:27:59.0595 3956 SymDS - ok
18:27:59.0642 3956 [ 8F88EDB211B12537D2DC2A6D73D6067C ] SymEFA D:\WINDOWS\system32\drivers\NIS\1308000.00E\SYMEFA.SYS
18:27:59.0674 3956 SymEFA - ok
18:27:59.0736 3956 [ 74E2521E96176A4449570E50BE91954D ] SymEvent D:\WINDOWS\system32\Drivers\SYMEVENT.SYS
18:27:59.0752 3956 SymEvent - ok
18:27:59.0767 3956 [ 2C356CCA706505CF63CBE39D532B9236 ] SymIRON D:\WINDOWS\system32\drivers\NIS\1308000.00E\Ironx86.SYS
18:27:59.0767 3956 SymIRON - ok
18:27:59.0814 3956 [ 508BD882040F9CB12319E3A4FC78EDB9 ] SYMTDI D:\WINDOWS\System32\Drivers\NIS\1308000.00E\SYMTDI.SYS
18:27:59.0814 3956 SYMTDI - ok
18:27:59.0814 3956 sym_hi - ok
18:27:59.0814 3956 sym_u3 - ok
18:27:59.0861 3956 [ 8B83F3ED0F1688B4958F77CD6D2BF290 ] sysaudio D:\WINDOWS\system32\drivers\sysaudio.sys
18:27:59.0861 3956 sysaudio - ok
18:27:59.0892 3956 [ C7ABBC59B43274B1109DF6B24D617051 ] SysmonLog D:\WINDOWS\system32\smlogsvc.exe
18:27:59.0908 3956 SysmonLog - ok
18:27:59.0939 3956 [ B7AEE68D2E867CBF69B649B18FCEDBBB ] tap0901t D:\WINDOWS\system32\DRIVERS\tap0901t.sys
18:27:59.0955 3956 tap0901t - ok
18:27:59.0986 3956 [ 3CB78C17BB664637787C9A1C98F79C38 ] TapiSrv D:\WINDOWS\System32\tapisrv.dll
18:27:59.0986 3956 TapiSrv - ok
18:28:00.0017 3956 [ 9AEFA14BD6B182D61E3119FA5F436D3D ] Tcpip D:\WINDOWS\system32\DRIVERS\tcpip.sys
18:28:00.0033 3956 Tcpip - ok
18:28:00.0049 3956 [ 6471A66807F5E104E4885F5B67349397 ] TDPIPE D:\WINDOWS\system32\drivers\TDPIPE.sys
18:28:00.0049 3956 TDPIPE - ok
18:28:00.0080 3956 [ C56B6D0402371CF3700EB322EF3AAF61 ] TDTCP D:\WINDOWS\system32\drivers\TDTCP.sys
18:28:00.0080 3956 TDTCP - ok
18:28:00.0095 3956 [ 88155247177638048422893737429D9E ] TermDD D:\WINDOWS\system32\DRIVERS\termdd.sys
18:28:00.0095 3956 TermDD - ok
18:28:00.0111 3956 [ FF3477C03BE7201C294C35F684B3479F ] TermService D:\WINDOWS\System32\termsrv.dll
18:28:00.0127 3956 TermService - ok
18:28:00.0158 3956 [ 1926899BF9FFE2602B63074971700412 ] Themes D:\WINDOWS\System32\shsvcs.dll
18:28:00.0158 3956 Themes - ok
18:28:00.0174 3956 [ DB7205804759FF62C34E3EFD8A4CC76A ] TlntSvr D:\WINDOWS\system32\tlntsvr.exe
18:28:00.0174 3956 TlntSvr - ok
18:28:00.0174 3956 TosIde - ok
18:28:00.0205 3956 [ 55BCA12F7F523D35CA3CB833C725F54E ] TrkWks D:\WINDOWS\system32\trkwks.dll
18:28:00.0220 3956 TrkWks - ok
18:28:00.0299 3956 [ BA28AF5A3F1F868919BA5F6476EBECDA ] TunngleService D:\Program Files\Tunngle\TnglCtrl.exe
18:28:00.0330 3956 TunngleService - ok
18:28:00.0345 3956 [ 5787B80C2E3C5E2F56C2A233D91FA2C9 ] Udfs D:\WINDOWS\system32\drivers\Udfs.sys
18:28:00.0361 3956 Udfs - ok
18:28:00.0361 3956 ultra - ok
18:28:00.0408 3956 [ 402DDC88356B1BAC0EE3DD1580C76A31 ] Update D:\WINDOWS\system32\DRIVERS\update.sys
18:28:00.0424 3956 Update - ok
18:28:00.0470 3956 [ 1EBAFEB9A3FBDC41B8D9C7F0F687AD91 ] upnphost D:\WINDOWS\System32\upnphost.dll
18:28:00.0486 3956 upnphost - ok
18:28:00.0517 3956 [ 05365FB38FCA1E98F7A566AAAF5D1815 ] UPS D:\WINDOWS\System32\ups.exe
18:28:00.0517 3956 UPS - ok
18:28:00.0533 3956 [ E8C1B9EBAC65288E1B51E8A987D98AF6 ] USBAAPL D:\WINDOWS\system32\Drivers\usbaapl.sys
18:28:00.0549 3956 USBAAPL - ok
18:28:00.0595 3956 [ E919708DB44ED8543A7C017953148330 ] usbaudio D:\WINDOWS\system32\drivers\usbaudio.sys
18:28:00.0595 3956 usbaudio - ok
18:28:00.0627 3956 [ 173F317CE0DB8E21322E71B7E60A27E8 ] usbccgp D:\WINDOWS\system32\DRIVERS\usbccgp.sys
18:28:00.0627 3956 usbccgp - ok
18:28:00.0642 3956 [ 65DCF09D0E37D4C6B11B5B0B76D470A7 ] usbehci D:\WINDOWS\system32\DRIVERS\usbehci.sys
18:28:00.0658 3956 usbehci - ok
18:28:00.0689 3956 [ 1AB3CDDE553B6E064D2E754EFE20285C ] usbhub D:\WINDOWS\system32\DRIVERS\usbhub.sys
18:28:00.0705 3956 usbhub - ok
18:28:00.0720 3956 [ 0DAECCE65366EA32B162F85F07C6753B ] usbohci D:\WINDOWS\system32\DRIVERS\usbohci.sys
18:28:00.0720 3956 usbohci - ok
18:28:00.0736 3956 [ A717C8721046828520C9EDF31288FC00 ] usbprint D:\WINDOWS\system32\DRIVERS\usbprint.sys
18:28:00.0752 3956 usbprint - ok
18:28:00.0799 3956 [ A32426D9B14A089EAA1D922E0C5801A9 ] USBSTOR D:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
18:28:00.0814 3956 USBSTOR - ok
18:28:00.0814 3956 [ 26496F9DEE2D787FC3E61AD54821FFE6 ] usbuhci D:\WINDOWS\system32\DRIVERS\usbuhci.sys
18:28:00.0830 3956 usbuhci - ok
18:28:00.0861 3956 [ B6CC50279D6CD28E090A5D33244ADC9A ] usb_rndisx D:\WINDOWS\system32\DRIVERS\usb8023x.sys
18:28:00.0861 3956 usb_rndisx - ok
18:28:00.0877 3956 [ 0D3A8FAFCEACD8B7625CD549757A7DF1 ] VgaSave D:\WINDOWS\System32\drivers\vga.sys
18:28:00.0877 3956 VgaSave - ok
18:28:00.0892 3956 ViaIde - ok
18:28:00.0924 3956 [ 4C8FCB5CC53AAB716D810740FE59D025 ] VolSnap D:\WINDOWS\system32\drivers\VolSnap.sys
18:28:00.0924 3956 VolSnap - ok
18:28:00.0955 3956 [ 7A9DB3A67C333BF0BD42E42B8596854B ] VSS D:\WINDOWS\System32\vssvc.exe
18:28:00.0955 3956 VSS - ok
18:28:00.0986 3956 [ 54AF4B1D5459500EF0937F6D33B1914F ] W32Time D:\WINDOWS\system32\w32time.dll
18:28:00.0986 3956 W32Time - ok
18:28:01.0033 3956 [ 738244934C71118A21F8D678067D057D ] W8335XP D:\WINDOWS\system32\DRIVERS\Mrv8000c.sys
18:28:01.0049 3956 W8335XP - ok
18:28:01.0080 3956 [ E20B95BAEDB550F32DD489265C1DA1F6 ] Wanarp D:\WINDOWS\system32\DRIVERS\wanarp.sys
18:28:01.0080 3956 Wanarp - ok
18:28:01.0127 3956 [ D918617B46457B9AC28027722E30F647 ] Wdf01000 D:\WINDOWS\system32\Drivers\wdf01000.sys
18:28:01.0158 3956 Wdf01000 - ok
18:28:01.0158 3956 WDICA - ok
18:28:01.0205 3956 [ 6768ACF64B18196494413695F0C3A00F ] wdmaud D:\WINDOWS\system32\drivers\wdmaud.sys
18:28:01.0205 3956 wdmaud - ok
18:28:01.0236 3956 [ 77A354E28153AD2D5E120A5A8687BC06 ] WebClient D:\WINDOWS\System32\webclnt.dll
18:28:01.0252 3956 WebClient - ok
18:28:01.0314 3956 [ 2D0E4ED081963804CCC196A0929275B5 ] winmgmt D:\WINDOWS\system32\wbem\WMIsvc.dll
18:28:01.0314 3956 winmgmt - ok
18:28:01.0439 3956 [ 5144AE67D60EC653F97DDF3FEED29E77 ] wlidsvc D:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
18:28:01.0502 3956 wlidsvc - ok
18:28:01.0533 3956 [ C51B4A5C05A5475708E3C81C7765B71D ] WmdmPmSN D:\WINDOWS\system32\MsPMSNSv.dll
18:28:01.0549 3956 WmdmPmSN - ok
18:28:01.0595 3956 [ E76F8807070ED04E7408A86D6D3A6137 ] Wmi D:\WINDOWS\System32\advapi32.dll
18:28:01.0595 3956 Wmi - ok
18:28:01.0627 3956 [ E0673F1106E62A68D2257E376079F821 ] WmiApSrv D:\WINDOWS\system32\wbem\wmiapsrv.exe
18:28:01.0627 3956 WmiApSrv - ok
18:28:01.0689 3956 [ F74E3D9A7FA9556C3BBB14D4E5E63D3B ] WMPNetworkSvc D:\Program Files\Windows Media Player\WMPNetwk.exe
18:28:01.0736 3956 WMPNetworkSvc - ok
18:28:01.0799 3956 [ DCF3E3EDF5109EE8BC02FE6E1F045795 ] WPFFontCache_v0400 D:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
18:28:01.0845 3956 WPFFontCache_v0400 - ok
18:28:01.0892 3956 [ 7C278E6408D1DCE642230C0585A854D5 ] wscsvc D:\WINDOWS\system32\wscsvc.dll
18:28:01.0892 3956 wscsvc - ok
18:28:01.0908 3956 [ C98B39829C2BBD34E454150633C62C78 ] WSTCODEC D:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
18:28:01.0908 3956 WSTCODEC - ok
18:28:01.0939 3956 [ 35321FB577CDC98CE3EB3A3EB9E4610A ] wuauserv D:\WINDOWS\system32\wuauserv.dll
18:28:01.0939 3956 wuauserv - ok
18:28:01.0970 3956 [ F15FEAFFFBB3644CCC80C5DA584E6311 ] WudfPf D:\WINDOWS\system32\DRIVERS\WudfPf.sys
18:28:01.0986 3956 WudfPf - ok
18:28:02.0002 3956 [ 28B524262BCE6DE1F7EF9F510BA3985B ] WudfRd D:\WINDOWS\system32\DRIVERS\wudfrd.sys
18:28:02.0017 3956 WudfRd - ok
18:28:02.0049 3956 [ 05231C04253C5BC30B26CBAAE680ED89 ] WudfSvc D:\WINDOWS\System32\WUDFSvc.dll
18:28:02.0080 3956 WudfSvc - ok
18:28:02.0127 3956 [ 81DC3F549F44B1C1FFF022DEC9ECF30B ] WZCSVC D:\WINDOWS\System32\wzcsvc.dll
18:28:02.0127 3956 WZCSVC - ok
18:28:02.0158 3956 [ 295D21F14C335B53CB8154E5B1F892B9 ] xmlprov D:\WINDOWS\System32\xmlprov.dll
18:28:02.0158 3956 xmlprov - ok
18:28:02.0189 3956 ================ Scan global ===============================
18:28:02.0220 3956 [ 42F1F4C0AFB08410E5F02D4B13EBB623 ] D:\WINDOWS\system32\basesrv.dll
18:28:02.0267 3956 [ 1618F36D4F7F6CCCEB3EE44BA95BE85C ] D:\WINDOWS\system32\winsrv.dll
18:28:02.0267 3956 [ 1618F36D4F7F6CCCEB3EE44BA95BE85C ] D:\WINDOWS\system32\winsrv.dll
18:28:02.0299 3956 [ 65DF52F5B8B6E9BBD183505225C37315 ] D:\WINDOWS\system32\services.exe
18:28:02.0299 3956 [Global] - ok
18:28:02.0299 3956 ================ Scan MBR ==================================
18:28:02.0299 3956 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk0\DR0
18:28:02.0455 3956 \Device\Harddisk0\DR0 - ok
18:28:02.0455 3956 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk1\DR3
18:28:02.0470 3956 \Device\Harddisk1\DR3 - ok
18:28:02.0470 3956 ================ Scan VBR ==================================
18:28:02.0486 3956 [ 6BB1974AD0C583ACBE4DB55C1D7EC859 ] \Device\Harddisk0\DR0\Partition1
18:28:02.0486 3956 \Device\Harddisk0\DR0\Partition1 - ok
18:28:02.0486 3956 [ 1D3169460216A240DB000EF71A0DA1E7 ] \Device\Harddisk0\DR0\Partition2
18:28:02.0486 3956 \Device\Harddisk0\DR0\Partition2 - ok
18:28:02.0502 3956 [ FEA4B8906EC97EDFB935BC05C1DD1C80 ] \Device\Harddisk1\DR3\Partition1
18:28:02.0502 3956 \Device\Harddisk1\DR3\Partition1 - ok
18:28:02.0502 3956 ============================================================
18:28:02.0502 3956 Scan finished
18:28:02.0502 3956 ============================================================
18:28:02.0517 1900 Detected object count: 2
18:28:02.0517 1900 Actual detected object count: 2
18:28:36.0017 1900 Akamai ( HiddenFile.Multi.Generic ) - skipped by user
18:28:36.0017 1900 Akamai ( HiddenFile.Multi.Generic ) - User select action: Skip
18:28:36.0017 1900 sptd ( LockedFile.Multi.Generic ) - skipped by user
18:28:36.0017 1900 sptd ( LockedFile.Multi.Generic ) - User select action: Skip

OTL Extras
OTL Extras logfile created on: 08-Sep-12 18:31:50 - Run 1
OTL by OldTimer - Version 3.2.61.2	 Folder = D:\Documents and Settings\Max\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MMM-yy
 
3.00 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 77.52% Memory free
4.34 Gb Paging File | 3.56 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]
 
%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 170.10 Gb Total Space | 43.68 Gb Free Space | 25.68% Space Free | Partition Type: NTFS
Drive D: | 127.98 Gb Total Space | 16.65 Gb Free Space | 13.01% Space Free | Partition Type: NTFS
Drive O: | 1863.01 Gb Total Space | 1404.92 Gb Free Space | 75.41% Space Free | Partition Type: NTFS
 
Computer Name: TOMEK | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
.url [@ = InternetShortcut] – rundll32.exe shdocvw.dll,OpenURL %l
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
 
========== Shell Spawning ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile [edit] – Reg Error: Key error.
http [open] – "D:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
https [open] – "D:\Program Files\Google\Chrome\Application\chrome.exe" – "%1"
InternetShortcut [open] – rundll32.exe shdocvw.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile [edit] – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [Bridge] – C:\Photoshop\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "D:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "D:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "D:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "D:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
 
========== Security Center Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
 
========== System Restore Settings ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2
 
========== Firewall Settings ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"56777:TCP" = 56777:TCP:*:Enabled:Pando Media Booster
"56777:UDP" = 56777:UDP:*:Enabled:Pando Media Booster
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"56777:TCP" = 56777:TCP:*:Enabled:Pando Media Booster
"56777:UDP" = 56777:UDP:*:Enabled:Pando Media Booster
"10606:TCP" = 10606:TCP:*:Enabled:Remote Assistance Local
"12169:TCP" = 12169:TCP:*:Enabled:Remote Assistance Remote
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\Program Files\Unreal Tournament 3\Binaries\UT3.exe" = D:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:*:Enabled:Unreal Tournament 3 – ()
"D:\Program Files\Valve\Half-Life\hl.exe" = D:\Program Files\Valve\Half-Life\hl.exe:*:Disabled:Half-Life Launcher
"D:\Program Files\Nowe Gadu-Gadu\gg.exe" = D:\Program Files\Nowe Gadu-Gadu\gg.exe:*:Enabled:Nowe Gadu-Gadu – (GG Network S.A.)
"D:\Program Files\Counter-Strike 1.6\hl.exe" = D:\Program Files\Counter-Strike 1.6\hl.exe:*:Enabled:Half-Life Launcher
"D:\Program Files\Shareaza\Shareaza.exe" = D:\Program Files\Shareaza\Shareaza.exe:*:Enabled:Shareaza
"D:\Program Files\Xfire\Xfire.exe" = D:\Program Files\Xfire\Xfire.exe:*:Enabled:Xfire – (Xfire Inc.)
"D:\Program Files\Java\jre6\bin\java.exe" = D:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary – (Sun Microsystems, Inc.)
"C:\AOE2AOK\empires2.exe" = C:\AOE2AOK\empires2.exe:*:Disabled:Age of Empires II – (Microsoft Corporation)
"D:\Documents and Settings\Max\Desktop\Downloads\SRO_L4.5_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\Desktop\Downloads\SRO_L4.5_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader – (Joymax)
"D:\Program Files\PoivY.com\PoivY\PoivY.exe" = D:\Program Files\PoivY.com\PoivY\PoivY.exe:*:Enabled:PoivY
"D:\Program Files\Gadu-Gadu 10\gg.exe" = D:\Program Files\Gadu-Gadu 10\gg.exe:*:Enabled:Gadu-Gadu 10 – (GG Network S.A.)
"D:\Program Files\LucasArts\Jedi Academy\GameData\jamp.exe" = D:\Program Files\LucasArts\Jedi Academy\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer
"D:\Program Files\Valve\Garry's Mod\hl2.exe" = D:\Program Files\Valve\Garry's Mod\hl2.exe:*:Enabled:Garry's_Mod
"D:\Program Files\Valve\Garry's Mod\srcds.exe" = D:\Program Files\Valve\Garry's Mod\srcds.exe:*:Enabled:Garry's_Mod_Dedicated_Server
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L5_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L5_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader
"C:\Metin2\metin2client.bin" = C:\Metin2\metin2client.bin:*:Enabled:metin2client
"C:\MOHPA\mohpa.exe" = C:\MOHPA\mohpa.exe:*:Disabled:Medal of Honor Pacific Assault™
"D:\Program Files\LucasArts\KotF Jedi Academy Expansion Pack\GameData\jamp.exe" = D:\Program Files\LucasArts\KotF Jedi Academy Expansion Pack\GameData\jamp.exe:*:Enabled:Jedi Academy MultiPlayer
"C:\Soldier of Fortune II - Double Helix GOLD\SoF2MP.exe" = C:\Soldier of Fortune II - Double Helix GOLD\SoF2MP.exe:*:Enabled:SoF2MP
"C:\KingdomHeroes\game\kh2.exe" = C:\KingdomHeroes\game\kh2.exe:*:Enabled:kh2
"C:\CABAL Online (EU)\launcher\update\ESTdnheadless.exe" = C:\CABAL Online (EU)\launcher\update\ESTdnheadless.exe:*:Enabled:EST! download engine
"D:\Documents and Settings\Max\Desktop\SRO_L5.5_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\Desktop\SRO_L5.5_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader
"D:\Program Files\Vuze\Azureus.exe" = D:\Program Files\Vuze\Azureus.exe:*:Enabled:Azureus / Vuze
"D:\Program Files\Google\Google Earth\plugin\geplugin.exe" = D:\Program Files\Google\Google Earth\plugin\geplugin.exe:*:Enabled:Google Earth – (Google)
"C:\ArmA\arma.exe" = C:\ArmA\arma.exe:*:Disabled:ArmA
"C:\NFS3HP\nfs3.exe" = C:\NFS3HP\nfs3.exe:*:Disabled:Need For Speed III for Win32
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L6_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L6_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader
"C:\UrbanTerror\ioUrbanTerror.exe" = C:\UrbanTerror\ioUrbanTerror.exe:*:Enabled:ioUrbanTerror
"C:\GTAIV\Grand Theft Auto IV\GTAIV.exe" = C:\GTAIV\Grand Theft Auto IV\GTAIV.exe:*:Enabled:Grand Theft Auto IV – (Take-Two Interactive Software, Inc.)
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L6_Full_Client_Downloader(2).exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L6_Full_Client_Downloader(2).exe:*:Enabled:Full-Client Downloader
"C:\GMOD\hl2.exe" = C:\GMOD\hl2.exe:*:Enabled:hl2
"D:\Program Files\Tunngle\TnglCtrl.exe" = D:\Program Files\Tunngle\TnglCtrl.exe:*:Enabled:Tunngle Service – (Tunngle.net GmbH)
"D:\Program Files\Tunngle\Tunngle.exe" = D:\Program Files\Tunngle\Tunngle.exe:*:Enabled:Tunngle Client – (Tunngle.net GmbH)
"C:\MobileForces\System\MobileForces.exe" = C:\MobileForces\System\MobileForces.exe:*:Enabled:MobileForces
"C:\STARY DYSK\Pulpit\UnrealTournament\System\UnrealTournament.exe" = C:\STARY DYSK\Pulpit\UnrealTournament\System\UnrealTournament.exe:*:Enabled:UnrealTournament – ()
"C:\Azureus Torrenty\Left 4 Dead\left4dead.exe" = C:\Azureus Torrenty\Left 4 Dead\left4dead.exe:*:Disabled:left4dead
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_ManualPatch_Downloader(2).exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_ManualPatch_Downloader(2).exe:*:Enabled:Full-Client Downloader
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_ManualPatch_Downloader.exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_ManualPatch_Downloader.exe:*:Enabled:Full-Client Downloader
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader(2).exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader(2).exe:*:Enabled:Full-Client Downloader
"C:\Silkroad\SRO_Client.exe" = C:\Silkroad\SRO_Client.exe:*:Enabled:SRO_Client.exe – ()
"C:\uTorrent\uTorrent.exe" = C:\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"D:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe" = D:\Program Files\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe:*:Enabled:Ubisoft Game Launcher – (Ubisoft)
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader(1).exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L7_Full_Client_Downloader(1).exe:*:Enabled:Full-Client Downloader
"C:\StarportGE\GEClient.exe" = C:\StarportGE\GEClient.exe:*:Enabled:GEClient – ()
"D:\Program Files\Google\Google Earth\client\googleearth.exe" = D:\Program Files\Google\Google Earth\client\googleearth.exe:*:Enabled:Google Earth – (Google)
"D:\Program Files\APB Reloaded\Binaries\APB.exe" = D:\Program Files\APB Reloaded\Binaries\APB.exe:*:Enabled:APB: APB.exe
"D:\Program Files\APB Reloaded\Binaries\VivoxVoiceService.exe" = D:\Program Files\APB Reloaded\Binaries\VivoxVoiceService.exe:*:Enabled:APB: VivoxVoiceService.exe
"C:\LoTR\lotroclient.exe" = C:\LoTR\lotroclient.exe:*:Enabled:lotroclient
"D:\Program Files\Java\jre6\bin\javaw.exe" = D:\Program Files\Java\jre6\bin\javaw.exe:*:Enabled:Java(TM) Platform SE binary – (Sun Microsystems, Inc.)
"D:\Program Files\Steam\Steam.exe" = D:\Program Files\Steam\Steam.exe:*:Enabled:Steam – (Valve Corporation)
"D:\Program Files\Steam\steamapps\maxthedragon\team fortress 2\hl2.exe" = D:\Program Files\Steam\steamapps\maxthedragon\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"D:\Program Files\Steam\steamapps\maxthedragon\age of chivalry\hl2.exe" = D:\Program Files\Steam\steamapps\maxthedragon\age of chivalry\hl2.exe:*:Enabled:Age of Chivalry – ()
"D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe" = D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe:*:Disabled:netsession_win – (Akamai Technologies, Inc.)
"D:\Documents and Settings\Max\My Documents\Downloads\SRO_L8_Full_Client_Downloader.exe" = D:\Documents and Settings\Max\My Documents\Downloads\SRO_L8_Full_Client_Downloader.exe:*:Enabled:Full-Client Downloader
"C:\Battlefield 2\BFBC2Updater.exe" = C:\Battlefield 2\BFBC2Updater.exe:*:Enabled:Battlefield: Bad Company™ 2
"C:\GTAIV\Grand Theft Auto IV\LaunchGTAIV.exe" = C:\GTAIV\Grand Theft Auto IV\LaunchGTAIV.exe:*:Enabled:Grand Theft Auto IV – (Sony DADC Austria AG)
"C:\uTorrent\New Folder\PC_Saints.Row.2.(-multi.11-)-.direct.play.-ToeD\Saints Row 2\SR2_pc.exe" = C:\uTorrent\New Folder\PC_Saints.Row.2.(-multi.11-)-.direct.play.-ToeD\Saints Row 2\SR2_pc.exe:*:Disabled:SR2_pc
"O:\AOE2AOK\empires2.exe" = O:\AOE2AOK\empires2.exe:*:Disabled:Age of Empires II
"D:\Program Files\AOEII\empires2.EXE" = D:\Program Files\AOEII\empires2.EXE:*:Disabled:Age of Empires II – (Microsoft Corporation)
"D:\Program Files\AOEII\age2_x1.exe" = D:\Program Files\AOEII\age2_x1.exe:*:Disabled:Age of Empires II Expansion – (Microsoft Corporation)
"D:\Documents and Settings\Max\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe" = D:\Documents and Settings\Max\Local Settings\Application Data\Facebook\Video\Skype\FacebookVideoCalling.exe:*:Enabled:Facebook Video Calling Plugin – (Skype Limited)
"D:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe" = D:\Program Files\Steam\steamapps\common\skyrim\SkyrimLauncher.exe:*:Enabled:The Elder Scrolls V: Skyrim – (Bethesda Softworks)
"C:\Steam\steamapps\maxthedragon\age of chivalry dedicated server\srcds.exe" = C:\Steam\steamapps\maxthedragon\age of chivalry dedicated server\srcds.exe:*:Enabled:Age of Chivalry Dedicated Server – ()
"D:\Program Files\Steam\steamapps\maxthedragon\garrysmod\hl2.exe" = D:\Program Files\Steam\steamapps\maxthedragon\garrysmod\hl2.exe:*:Enabled:Garry's Mod – ()
"C:\Steam\steamapps\maxthedragon\team fortress 2\hl2.exe" = C:\Steam\steamapps\maxthedragon\team fortress 2\hl2.exe:*:Enabled:hl2 – ()
"C:\Steam\steamapps\common\saints row the third\game_launcher.exe" = C:\Steam\steamapps\common\saints row the third\game_launcher.exe:*:Enabled:Saints Row: The Third – (THQ Inc.)
"C:\Steam\steamapps\common\saints row the third\saintsrowthethird.exe" = C:\Steam\steamapps\common\saints row the third\saintsrowthethird.exe:*:Enabled:Saints Row: The Third – (THQ Inc.)
"C:\Steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe" = C:\Steam\steamapps\common\saints row the third\saintsrowthethird_dx11.exe:*:Enabled:Saints Row: The Third DX11 – (THQ Inc.)
"C:\Steam\steamapps\common\skyrim\SkyrimLauncher.exe" = C:\Steam\steamapps\common\skyrim\SkyrimLauncher.exe:*:Enabled:The Elder Scrolls V: Skyrim – (Bethesda Softworks)
"C:\Steam\steamapps\maxthedragon\garrysmod\hl2.exe" = C:\Steam\steamapps\maxthedragon\garrysmod\hl2.exe:*:Enabled:Garry's Mod
"C:\Steam\steamapps\common\alien swarm\srcds.exe" = C:\Steam\steamapps\common\alien swarm\srcds.exe:*:Enabled:Alien Swarm Dedicated Server
"C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe" = C:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe:*:Enabled:Counter-Strike: Global Offensive – ()
"C:\Steam\steamapps\common\SourceFilmmaker\game\sfm.exe" = C:\Steam\steamapps\common\SourceFilmmaker\game\sfm.exe:*:Enabled:Source Filmmaker – ()
"C:\Steam\steamapps\common\SourceFilmmaker\game\bin\qsdklauncher.exe" = C:\Steam\steamapps\common\SourceFilmmaker\game\bin\qsdklauncher.exe:*:Enabled:Source Filmmaker – ()
 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{00F93853-D9D3-4795-A89E-84CCBA0205C9}" = Microsoft IntelliPoint 8.0
"{0141D498-16DA-4221-A529-1D7A64BE8B05}" = OpenOffice.org 3.3
"{01501EBA-EC35-4F9F-8889-3BE346E5DA13}" = MSXML4 Parser
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0A60F381-92E2-4F2D-A74B-691A4B4FF0FC}" = TP-LINK Wireless Client Utility
"{0A7B28CF-6BE3-11D6-A285-00A0CC51B2FE}" = Sound Blaster Live! Web 2K/XP
"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{16F0EE77-B2B1-4417-A8CC-07E06C78CCC4}" = Matrix-ks
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{199C20D6-10D3-4210-B361-4760209F56AE}" = Citrix online plug-in (Web)
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Narzędzie do przekazywania usługi Windows Live
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java(TM) 6 Update 32
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{29F15D3F-5B37-44DB-BB89-390B3AD1404E}" = IEEE 802.11g Wireless Cardbus/PCI Adapter
"{2AFF2951-86B1-3C53-B34D-B440F11E7D0A}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PLK
"{2BD5C305-1B27-4D41-B690-7A61172D2FEB}" = Macromedia Flash 8
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3315B802-84C6-47BC-907A-9B77A4646197}_is1" = SWF to AVI 1.7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{39930321-4C58-4B8B-BCBF-342698C9801D}" = Max Payne
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3ECCB578-504E-4F7A-A8B4-CF4F3B939B44}" = Citrix online plug-in (USB)
"{3F0D0ABE-CDAF-431A-00BC-CBBE018EA74E}" = SimCity 4 Deluxe
"{43602F34-1AA3-44FB-AEB2-D08C2C73743F}" = Paint.NET v3.36
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{5454083B-1308-4485-BF17-1110000D8301}" = Grand Theft Auto IV
"{5454083B-1308-4485-BF17-1110000D8302}" = Grand Theft Auto IV
"{5454083B-1308-4485-BF17-1110000D8303}" = Grand Theft Auto IV
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{579BA58C-F33D-4970-9953-B94B43768AC3}" = Grand Theft Auto IV
"{5A0DDC27-88E5-3CAD-BC3D-28FFD05CA6B9}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PLK
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5F4C776F-8CBD-4C4F-892F-B568ABDD70C8}" = GameSpy Comrade
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{678094A1-6250-476B-9AFF-4376E48F135C}" = Citrix online plug-in (DV)
"{6ABE0BEE-D572-4FE8-B434-9E72A289431B}" = Adobe Fonts All
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{76BC2442-0002-47FA-9617-43BAD82BEF4C}" = Bonjour
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{886C92E6-4AF1-4290-BB86-4B5064A1BB7D}" = AMD Dual-Core Optimizer
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}" = Macromedia Flash 8 Video Encoder
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{964D07BE-460C-4862-B59C-49575B8F46DC}" = Google SketchUp Pro 8
"{996A2FAA-7514-4628-9D12-A8FC34A0016E}" = iTunes
"{9A200E68-D5F4-4E70-910F-2871753A0E2B}" = Worms World Party
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9DF0196F-B6B8-4C3A-8790-DE42AA530101}" = SPORE™
"{9EFDFBA8-9174-3C61-8645-28376C5CA994}" = Microsoft .NET Framework 3.5 Language Pack SP1 - plk
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A95000000001}" = Adobe Reader 9.5.2
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView" = NVIDIA nView 135.50
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver [removed]
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{B5C3B892-0849-476C-9F46-B12F84819D57}" = Apple Mobile Device Support
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BA2F3EBC-FE07-4AB5-B906-14DF2C74C523}" = Age of Empires II - the Conquerors WideScreen Patcher
"{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation
"{BC15023B-48DB-4F71-9C25-CFE1A8BB7202}" = Alcor Micro USB Card Reader
"{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C41300B9-185D-475E-BFEC-39EF732F19B1}" = Apple Software Update
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CFC9F871-7C40-40B6-BE4A-B98A5B309716}" = Adobe Flash Professional CS5
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D88C3E7C-1DA6-4AD7-97FC-75BC8705B266}" = runtime
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5D52570-5EF1-4576-A434-6CCD92268F0F}" = Google SketchUp 7
"{E5FCED12-3E77-4C0E-A305-5AEB38A52A70}" = AdobeColorCommonSetCMYK
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F9766AC1-1461-1033-B862-DF8FE1C033BE}" = Adobe InDesign CS5
"{FA365307-1963-4D16-BD44-113C8F037AAD}" = Citrix online plug-in (HDX)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"53F13DB4D9611FD63BE580F06F0729BF236ABE68" = Windows Driver Package - Advanced Micro Devices (AmdK8) Processor  (05/27/2006 1.3.2.0)
"7-Zip" = 7-Zip 4.64
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"Akamai" = Akamai NetSession Interface Service
"Antares Autotune VST RTAS TDM_is1" = Antares Autotune VST RTAS TDM v5.08
"ASIO4ALL" = ASIO4ALL
"Audacity_is1" = Audacity 1.2.6
"AVI GIF Converter_is1" = AVI GIF Converter 1.08
"Avidemux 2.5" = Avidemux 2.5 (32-bit)
"AWP" = Postal 2: AWP
"Blender" = Blender (remove only)
"CamStudio" = CamStudio
"Carmageddon TDR2000" = Carmageddon TDR2000
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.0_is1" = Cheat Engine 6.0
"Cheating-Death" = Cheating-Death 4.33.4
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"CityBars Mod v1.0" = CityBars Mod v1.0
"Collab" = Collab
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"Cool's_Codec_pack_4.12" = Codec Pack - All In 1 6.0.3.0
"DIKO Free_is1" = DIKO 2.47
"DivX to DVD Converter" = DivX to DVD Converter
"DriverEasy_is1" = DriverEasy 3.10.0
"EAX Unified" = EAX Unified
"Feudalism 2_is1" = Feudalism 2
"Fraps" = Fraps (remove only)
"Freecorder4.12B" = Freecorder 4
"Freez FLV to AVI/MPEG/WMV Converter v1.6_is1" = Freez FLV to AVI/MPEG/WMV Converter
"Gadu-Gadu 10" = Gadu-Gadu 10
"GIMP-2_is1" = GIMP 2.8.0
"GPG4Win" = Gpg4win (2.0.1)
"GzegzolkaXP_is1" = G¿eg¿ó³ka XP [removed]
"Handbrake" = Handbrake 0.9.4
"Icy Tower v1.4_is1" = Icy Tower v1.4
"ImageForge version 3.60_is1" = ImageForge version 3.60
"InstallShield_{29F15D3F-5B37-44DB-BB89-390B3AD1404E}" = IEEE 802.11g Wireless Cardbus/PCI Adapter
"InstallShield_{BC15023B-48DB-4F71-9C25-CFE1A8BB7202}" = Alcor Micro USB Card Reader
"IrfanView" = IrfanView (remove only)
"Live 8.2.2" = Live 8.2.2
"Mafia" = Mafia
"Magic Video Converter_is1" = Magic Video Converter 8.0.8.25
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Microsoft .NET Framework 1.1  (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - plk" = Pakiet językowy programu Microsoft .NET Framework 3.5 z dodatkiem SP1 — PLK
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"ModPlug Player v1.46_is1" = ModPlug Player
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"Mozilla Thunderbird (7.0.1)" = Mozilla Thunderbird (7.0.1)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Mp3 To Wave Converter 1.21" = Mp3 To Wave Converter 1.21
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NIS" = Norton Internet Security
"Nowe Gadu-Gadu" = Nowe Gadu-Gadu
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIA nView Desktop Manager" = NVIDIA nView Desktop Manager
"OGM to AVI_is1" = OGM to AVI Beta .6
"OpenAL" = OpenAL
"Phun_is1" = Phun beta 4.20
"Picasa 3" = Picasa 3
"Police Pursuit Mod 7.5d 7.5d" = Police Pursuit Mod 7.5d 7.5d
"Police Pursuit Mod 7.6d 7.6d" = Police Pursuit Mod 7.6d 7.6d
"Postal 2 Apocalypse Weekend Expansion Pack" = Postal 2 Apocalypse Weekend Expansion Pack
"Postal 2 PL" = Postal 2 PL
"PowerISO" = PowerISO
"PunkBusterSvc" = PunkBuster Services
"Recover My Files_is1" = Recover My Files
"San Andreas Mod Installer1.1" = San Andreas Mod Installer
"Serious Samurize" = Serious Samurize
"Silkroad" = Silkroad
"Speccy" = Speccy
"ST6UNST #1" = GTASA-Ultimate Editor
"ST6UNST #2" = GTASA-Ultimate Editor (D:\Program Files\Rockstar Games\editor\)
"ST6UNST #3" = HLTooLz
"Starport GE_is1" = Starport GE v1.0
"Steam App 1840" = Source Filmmaker
"Steam App 4000" = Garry's Mod
"Steam App 440" = Team Fortress 2
"Steam App 55230" = Saints Row: The Third
"Steam App 72850" = The Elder Scrolls V: Skyrim
"Steam App 730" = Counter-Strike: Global Offensive
"Toxic Biohazard" = Toxic Biohazard
"Tunngle beta_is1" = Tunngle beta
"uTorrent" = µTorrent
"uTorrentControl2 Toolbar" = uTorrentControl2 Toolbar
"Visual Basic 6.0 Professional Edition" = Microsoft Visual Basic 6.0 Professional Edition
"VLC media player" = VLC media player 1.0.1
"Wdf01009" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
"WebPost" = Microsoft Web Publishing Wizard 1.53
"Winamp" = Winamp
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Xfire" = Xfire (remove only)
"XpsEPSC" = XML Paper Specification Shared Components Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0
"X-VCD Player_is1" = X-VCD Player
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Facebook Plug-In" = Facebook Plug-In
"IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software
"InstallShield_{BFA90209-7AFF-4DB6-8E4B-E57305751AD7}" = Unreal Tournament 3
"UnityWebPlayer" = Unity Web Player
"Winamp Detect" = Winamp Detector Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 23-Aug-12 17:05:03 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 11734
 
Error - 23-Aug-12 17:29:56 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 23-Aug-12 17:29:56 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1504265
 
Error - 23-Aug-12 17:29:56 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1504265
 
Error - 23-Aug-12 17:30:05 | Computer Name = TOMEK | Source = Google Update | ID = 20
Description = 
 
Error - 31-Dec-06 19:04:45 | Computer Name = TOMEK | Source = Google Update | ID = 20
Description = 
 
Error - 31-Dec-06 19:11:31 | Computer Name = TOMEK | Source = Google Update | ID = 20
Description = 
 
Error - 31-Aug-12 7:30:51 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 31-Aug-12 7:30:51 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1953
 
Error - 31-Aug-12 7:30:51 | Computer Name = TOMEK | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1953
 
[ System Events ]
Error - 07-Sep-12 4:47:23 | Computer Name = TOMEK | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error:   %%2
 
Error - 07-Sep-12 4:47:23 | Computer Name = TOMEK | Source = Service Control Manager | ID = 7000
Description = The McAfee Real-time Scanner service failed to start due to the following
 error:   %%3
 
Error - 07-Sep-12 4:53:35 | Computer Name = TOMEK | Source = AmdTools | ID = 180092939
Description = AdjustCoreTSC()	Node[ 0 ] Core[ 0 ] Cpu[ 0 ] Affinity[ 0x1 ]	Error: 
HalGetBusDataByOffset() failed reading north-bridge TSC.
 
Error - 07-Sep-12 4:53:35 | Computer Name = TOMEK | Source = AmdTools | ID = 180092939
Description = AdjustCoreTSC()	Node[ 0 ] Core[ 1 ] Cpu[ 1 ] Affinity[ 0x2 ]	Error: 
HalGetBusDataByOffset() failed reading north-bridge TSC.
 
Error - 07-Sep-12 5:52:13 | Computer Name = TOMEK | Source = Service Control Manager | ID = 7011
Description = Timeout (30000 milliseconds) waiting for a transaction response from
 the Akamai service.
 
Error - 07-Sep-12 9:28:47 | Computer Name = TOMEK | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.0.30 on
 the  Network Card with network address D85D4C8C93BA.
 
Error - 08-Sep-12 8:37:05 | Computer Name = TOMEK | Source = Service Control Manager | ID = 7000
Description = The adfs service failed to start due to the following error:   %%2
 
Error - 08-Sep-12 8:37:05 | Computer Name = TOMEK | Source = Service Control Manager | ID = 7000
Description = The McAfee Real-time Scanner service failed to start due to the following
 error:   %%3
 
Error - 08-Sep-12 8:38:28 | Computer Name = TOMEK | Source = AmdTools | ID = 180092939
Description = AdjustCoreTSC()	Node[ 0 ] Core[ 0 ] Cpu[ 0 ] Affinity[ 0x1 ]	Error: 
HalGetBusDataByOffset() failed reading north-bridge TSC.
 
Error - 08-Sep-12 8:38:28 | Computer Name = TOMEK | Source = AmdTools | ID = 180092939
Description = AdjustCoreTSC()	Node[ 0 ] Core[ 1 ] Cpu[ 1 ] Affinity[ 0x2 ]	Error: 
HalGetBusDataByOffset() failed reading north-bridge TSC.
 
 
< End of report >
OTL logfile created on: 08-Sep-12 18:31:50 - Run 1
OTL by OldTimer - Version 3.2.61.2 Folder = D:\Documents and Settings\Max\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MMM-yy

3.00 Gb Total Physical Memory | 2.32 Gb Available Physical Memory | 77.52% Memory free
4.34 Gb Paging File | 3.56 Gb Available in Paging File | 82.00% Paging File free
Paging file location(s): D:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = D: | %SystemRoot% = D:\WINDOWS | %ProgramFiles% = D:\Program Files
Drive C: | 170.10 Gb Total Space | 43.68 Gb Free Space | 25.68% Space Free | Partition Type: NTFS
Drive D: | 127.98 Gb Total Space | 16.65 Gb Free Space | 13.01% Space Free | Partition Type: NTFS
Drive O: | 1863.01 Gb Total Space | 1404.92 Gb Free Space | 75.41% Space Free | Partition Type: NTFS

Computer Name: TOMEK | User Name: Max | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - D:\Documents and Settings\Max\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - D:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
PRC - D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccsvchst.exe (Symantec Corporation)
PRC - D:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
PRC - D:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
PRC - D:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - D:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - D:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (Alcor Micro Corp.)
PRC - D:\Program Files\GNU\GnuPG\dirmngr.exe ()
PRC - D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - D:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - D:\Fraps\fraps.exe (Beepa P/L)
PRC - D:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation)
PRC - D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe ()
PRC - D:\WINDOWS\system32\CTHELPER.EXE (Creative Technology Ltd)


========== Modules (No Company Name) ==========

MOD - D:\Program Files\NVIDIA Corporation\nView\nvShell.dll ()
MOD - D:\Program Files\Tunngle\libeay32.dll ()
MOD - D:\Program Files\GNU\GnuPG\dirmngr.exe ()
MOD - D:\Program Files\GNU\GnuPG\libgcrypt-11.dll ()
MOD - D:\Program Files\GNU\GnuPG\libksba-8.dll ()
MOD - D:\Program Files\GNU\GnuPG\libgpg-error-0.dll ()
MOD - D:\Program Files\GNU\GnuPG\libw32pth-0.dll ()
MOD - D:\Program Files\WinRAR\RarExt.dll ()
MOD - D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanDll.dll ()
MOD - D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe ()


========== Services (SafeList) ==========

SRV - (McSysmon) -- D:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe File not found
SRV - (McShield) -- D:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe File not found
SRV - (Akamai) -- d:\program files\common files\akamai/netsession_win_5891ae0.dll ()
SRV - (MozillaMaintenance) -- D:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (JavaQuickStarterService) -- D:\Program Files\Java\jre7\bin\jqs.exe (Oracle Corporation)
SRV - (Steam Client Service) -- D:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) -- D:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- D:\Program Files\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (NIS) -- D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ccSvcHst.exe (Symantec Corporation)
SRV - (TunngleService) -- D:\Program Files\Tunngle\TnglCtrl.exe (Tunngle.net GmbH)
SRV - (npggsvc) -- D:\WINDOWS\system32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (SwitchBoard) -- D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (DirMngr) -- D:\Program Files\GNU\GnuPG\dirmngr.exe ()
SRV - (FLEXnet Licensing Service) -- D:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)


========== Driver Services (SafeList) ==========

DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (EagleXNt) -- D:\WINDOWS\system32\drivers\EagleXNt.sys File not found
DRV - (EagleNT) -- D:\WINDOWS\system32\drivers\EagleNT.sys File not found
DRV - (dbustrcm) -- D:\DOCUME~1\Max\LOCALS~1\Temp\dbustrcm.sys File not found
DRV - (Changer) -- File not found
DRV - (arm26gqf) -- File not found
DRV - (adfs) -- File not found
DRV - (IDSxpx86) -- D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\IPSDefs\20120901.001\IDSXpx86.sys (Symantec Corporation)
DRV - (NAVEX15) -- D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120907.034\NAVEX15.SYS (Symantec Corporation)
DRV - (NAVENG) -- D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\VirusDefs\20120907.034\NAVENG.SYS (Symantec Corporation)
DRV - (eeCtrl) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EraserUtilRebootDrv) -- D:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (SymEvent) -- D:\WINDOWS\system32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SRTSP) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\srtsp.sys (Symantec Corporation)
DRV - (SRTSPX) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\srtspx.sys (Symantec Corporation)
DRV - (BHDrvx86) -- D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\Definitions\BASHDefs\20120823.007\BHDrvx86.sys (Symantec Corporation)
DRV - (ccSet_NIS) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\ccsetx86.sys (Symantec Corporation)
DRV - (SymEFA) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\symefa.sys (Symantec Corporation)
DRV - (SYMTDI) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\symtdi.sys (Symantec Corporation)
DRV - (SymIRON) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\ironx86.sys (Symantec Corporation)
DRV - (PnkBstrK) -- D:\WINDOWS\system32\drivers\PnkBstrK.sys ()
DRV - (SymDS) -- D:\WINDOWS\system32\drivers\NIS\1308000.00E\symds.sys (Symantec Corporation)
DRV - (IntcAzAudAddService) -- D:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) -- D:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (NVHDA) -- D:\WINDOWS\system32\drivers\nvhda32.sys (NVIDIA Corporation)
DRV - (ctxusbm) -- D:\WINDOWS\system32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (sptd) -- D:\WINDOWS\system32\drivers\sptd.sys ()
DRV - (AR9271) -- D:\WINDOWS\system32\drivers\athuw.sys (Atheros Communications, Inc.)
DRV - (Monfilt) -- D:\WINDOWS\system32\drivers\Monfilt.sys (Creative Technology Ltd.)
DRV - (Ambfilt) -- D:\WINDOWS\system32\drivers\Ambfilt.sys (Creative)
DRV - (mfehidk) -- D:\WINDOWS\system32\drivers\mfehidk.sys (McAfee, Inc.)
DRV - (mfeavfk) -- D:\WINDOWS\system32\drivers\mfeavfk.sys (McAfee, Inc.)
DRV - (mfesmfk) -- D:\WINDOWS\system32\drivers\mfesmfk.sys (McAfee, Inc.)
DRV - (mfebopk) -- D:\WINDOWS\system32\drivers\mfebopk.sys (McAfee, Inc.)
DRV - (mferkdk) -- D:\WINDOWS\system32\drivers\mferkdk.sys (McAfee, Inc.)
DRV - (tap0901t) -- D:\WINDOWS\system32\drivers\tap0901t.sys (Tunngle.net)
DRV - (hamachi) -- D:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (SCDEmu) -- D:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (arusb(TP-LINK) -- D:\WINDOWS\system32\drivers\arusb.sys (Atheros Communications, Inc.)
DRV - (gameenum) -- D:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (nvnetbus) -- D:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- D:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvatabus) -- D:\WINDOWS\system32\drivers\nvatabus.sys (NVIDIA Corporation)
DRV - (AmdK8) -- D:\WINDOWS\system32\drivers\AmdK8.sys (Advanced Micro Devices)
DRV - (AmdTools) -- D:\WINDOWS\system32\drivers\AmdTools.sys (AMD, Inc.)
DRV - (W8335XP) -- D:\WINDOWS\system32\drivers\Mrv8000c.sys (Marvell Semiconductor, Inc)
DRV - (sfdrv01) -- D:\WINDOWS\system32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfsync02) -- D:\WINDOWS\system32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfhlp02) -- D:\WINDOWS\system32\drivers\sfhlp02.sys (Protection Technology)
DRV - (ha10kx2k) -- D:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (emupia) -- D:\WINDOWS\system32\drivers\EMUPIA2K.SYS (Creative Technology Ltd)
DRV - (ctsfm2k) -- D:\WINDOWS\system32\drivers\CTSFM2K.SYS (Creative Technology Ltd)
DRV - (ctprxy2k) -- D:\WINDOWS\system32\drivers\CTPRXY2K.SYS (Creative Technology Ltd)
DRV - (ossrv) -- D:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctaud2k) -- D:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- D:\WINDOWS\system32\drivers\CTAC32K.SYS (Creative Technology Ltd)
DRV - (sfman) -- D:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (emu10k1) -- D:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emu10k) -- D:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (ctljystk) -- D:\WINDOWS\system32\drivers\ctljystk.sys (Creative Technology Ltd.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
IE - HKCU\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?...;ctid=CT3072253
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421;

========== FireFox ==========



FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: D:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_271.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: D:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: D:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: D:\WINDOWS\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: D:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: D:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: D:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.0.1: D:\Program Files\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: D:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: D:\Documents and Settings\Max\Application Data\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: D:\Documents and Settings\Max\Application Data\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: D:\Documents and Settings\Max\Local Settings\Application Data\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: D:\Documents and Settings\Max\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\IPSFFPlgn\ [2012-07-12 18:04:36 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: D:\Documents and Settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_19.1.0.28\coFFPlgn\ [2012-09-08 13:36:44 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: D:\Program Files\Mozilla Firefox\components [2012-09-07 10:03:04 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: D:\Program Files\Mozilla Firefox\plugins [2012-09-07 09:59:28 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Components: D:\Program Files\Mozilla Thunderbird\components [2011-09-05 21:58:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 7.0.1\extensions\\Plugins: D:\Program Files\Mozilla Thunderbird\plugins

[2010-10-26 11:47:03 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Extensions
[2010-10-26 11:47:03 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2009-03-12 14:18:59 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\7it66beo.default\extensions
[2012-08-28 11:12:54 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions
[2012-08-13 19:22:34 | 000,000,000 | ---D | M] (Flagfox) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2012-08-21 15:59:25 | 000,000,000 | ---D | M] (Freecorder Community Toolbar) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}
[2009-03-12 14:20:39 | 000,000,000 | ---D | M] (ChatZilla pl-PL) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{318e94d0-f1d8-11dc-95ff-0800200c9a66}
[2012-04-08 11:00:42 | 000,000,000 | ---D | M] (ChatZilla) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2010-02-19 19:33:22 | 000,000,000 | ---D | M] (SmoothWheel (mozdev.org)) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{5F590AA2-1221-4113-A6F4-A4BB62414FAC}
[2012-08-28 11:12:54 | 000,000,000 | ---D | M] (uTorrentControl2) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{687578b9-7132-4a7a-80e4-30ee31099e03}
[2009-07-21 13:17:08 | 000,000,000 | ---D | M] (iFox Smooth) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{d3d70bca-2d54-425e-b02c-b7e2f4b07688}
[2010-09-03 18:15:57 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2010-03-31 23:51:02 | 000,000,000 | ---D | M] (Ctrl-Tab) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2011-04-25 20:22:20 | 000,000,000 | ---D | M] (Conduit Engine) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2012-06-21 22:01:35 | 000,000,000 | ---D | M] (LavaFox V2) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2011-06-29 09:44:43 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2010-11-17 19:14:00 | 000,000,000 | ---D | M] (RedShift V3.6) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2011-04-25 20:22:21 | 000,000,000 | ---D | M] (YouTube Video Download Wizard) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2012-06-21 22:01:34 | 000,000,000 | ---D | M] (BlackFox V2) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2011-04-10 13:05:33 | 000,000,000 | ---D | M] (Zrzuta!) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2009-03-12 14:20:25 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] ("lolifox-ErrorZilla") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{0848DC31-5D1F-45de-907E-8B3E425D0FE4}
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] (gTalk Sidebar) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{29c58eb6-561a-42a5-a4c3-a3a25a3f9c6c}
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] ("MinimizeToTray") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{31513E58-F253-47ad-86DB-D5F21E905429}
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] (ChatZilla pl-PL) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{318e94d0-f1d8-11dc-95ff-0800200c9a66}
[2009-03-12 14:20:20 | 000,000,000 | ---D | M] (ChatZilla) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2009-03-12 14:20:20 | 000,000,000 | ---D | M] (ImageShack® Toolbar) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{7378B8C2-FC38-41b8-A8C9-875D1F5B0A24}
[2009-03-12 14:20:19 | 000,000,000 | ---D | M] (Hyperwords) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{9A752782-D706-479b-98F8-3F66BF921692}
[2009-03-12 14:20:19 | 000,000,000 | ---D | M] (Quitomzilla) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{A154CEEC-79EA-48a8-AD27-BEC22AF360F8}
[2009-03-12 14:20:19 | 000,000,000 | ---D | M] (The Pirate Bay Toolbar) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{a33fa729-d155-4b23-842b-2c665ecabdb6}
[2009-03-12 14:20:19 | 000,000,000 | ---D | M] (FireFTP) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}
[2009-03-12 14:20:19 | 000,000,000 | ---D | M] ("Full Fullscreen") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{bfe3406c-6f31-4789-86d5-efa50e12c9eb}
[2009-03-12 14:20:18 | 000,000,000 | ---D | M] (Download Statusbar) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}
[2009-03-12 14:20:13 | 000,000,000 | ---D | M] (ViewSourceWith) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\{eecba28f-b68b-4b3a-b501-6ce12e6b8696}
[2009-03-12 14:20:25 | 000,000,000 | ---D | M] (FireNes) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:25 | 000,000,000 | ---D | M] (PicLens) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:24 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]-trash
[2009-03-12 14:20:24 | 000,000,000 | ---D | M] (Polski slownik poprawnej pisowni) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:24 | 000,000,000 | ---D | M] ("RedShift V2") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:24 | 000,000,000 | ---D | M] (Tab Scope) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:23 | 000,000,000 | ---D | M] ("Undo Closed Tabs Button") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] ("UnPlug") -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\unplug@compunach
[2009-03-12 14:20:21 | 000,000,000 | ---D | M] (Web Personal Cleaner) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]
[2009-03-12 14:20:12 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\wborupyt.default\extensions
[2009-03-12 14:20:12 | 000,000,000 | ---D | M] (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\zd6e4lwv.default\extensions
[2012-06-20 20:35:29 | 000,695,973 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2012-07-24 16:41:13 | 000,057,698 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2011-08-12 16:54:18 | 000,145,972 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\[removed]
[2012-07-24 16:41:13 | 000,276,167 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{64161300-e22b-11db-8314-0800200c9a66}.xpi
[2012-08-04 00:02:12 | 000,314,397 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{c50ca3c4-5656-43c2-a061-13e717f73fc8}.xpi
[2011-10-29 14:26:40 | 000,434,392 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{D4DD63FA-01E4-46a7-B6B1-EDAB7D6AD389}.xpi
[2012-07-21 11:49:28 | 000,702,524 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
[2012-08-25 00:37:46 | 000,270,021 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2009-07-21 13:17:04 | 000,750,444 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\maxprofile\extensions\{d3d70bca-2d54-425e-b02c-b7e2f4b07688}\chrome\tmp-3.xpi
[2007-09-03 17:11:52 | 000,607,268 | ---- | M] () (No name found) -- D:\Documents and Settings\Max\Application Data\Mozilla\Firefox\Profiles\os8p6ul2.default\extensions\[removed]\chrome\tmp.xpi
[2012-09-07 09:59:23 | 000,000,000 | ---D | M] (No name found) -- D:\Program Files\Mozilla Firefox\extensions
[2012-09-07 09:59:23 | 000,000,000 | ---D | M] (Skype Click to Call) -- D:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012-09-07 10:03:04 | 000,266,720 | ---- | M] (Mozilla Foundation) -- D:\Program Files\mozilla firefox\components\browsercomps.dll
[2010-10-12 16:33:32 | 000,124,344 | ---- | M] (Citrix Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010-10-12 16:37:06 | 000,070,592 | ---- | M] (Citrix Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010-10-12 16:35:42 | 000,091,576 | ---- | M] (Citrix Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010-10-12 16:34:56 | 000,022,464 | ---- | M] (Citrix Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2010-10-12 18:16:54 | 000,484,768 | ---- | M] () -- D:\Program Files\mozilla firefox\plugins\npicaN.dll
[2010-12-09 11:47:06 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- D:\Program Files\mozilla firefox\plugins\npwachk.dll
[2010-10-12 16:37:02 | 000,024,000 | ---- | M] (Citrix Systems, Inc.) -- D:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2012-08-28 23:55:35 | 000,002,465 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012-08-28 23:55:35 | 000,002,253 | ---- | M] () -- D:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}source
id=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = D:\Program Files\Google\Chrome\Application\11.0.696.71\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = D:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.240.7 (Enabled) = D:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java(tm) Platform SE 6 U24 (Enabled) = D:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = D:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Shockwave for Director (Enabled) = D:\WINDOWS\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = D:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = D:\Program Files\Google\Chrome\Application\11.0.696.71\pdf.dll
CHR - plugin: Chrome NaCl (Disabled) = D:\Program Files\Google\Chrome\Application\11.0.696.71\ppGoogleNaClPluginChrome.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = D:\Program Files\Google\Chrome\Application\11.0.696.71\gears.dll
CHR - plugin: Pando Web Installer (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
CHR - plugin: Winamp Application Detector (Enabled) = D:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = D:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = D:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Facebook Plugin (Enabled) = D:\Documents and Settings\Max\Application Data\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Plugin (Enabled) = D:\Documents and Settings\Max\Application Data\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Unity Player (Enabled) = D:\Documents and Settings\Max\Local Settings\Application Data\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Google Earth Plugin (Enabled) = D:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = D:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = D:\Program Files\Google\Update\1.3.21.57\npGoogleUpdate3.dll
CHR - plugin: iTunes Application Detector (Enabled) = D:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

O1 HOSTS File: ([2010-11-12 10:56:34 | 000,001,871 | ---- | M]) - D:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O1 - Hosts: 209.85.137.104 menelgame.pl www.menelgame.pl change.menelgame.pl
O1 - Hosts: 66.98.148.65 auto.search.msn.com
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 125.252.224.90
O1 - Hosts: 127.0.0.1 125.252.224.91
O1 - Hosts: 1 more lines...
O2 - BHO: (DigiMode Toolbar) - {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll (Conduit Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (IEPluginBHO Class) - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - D:\Documents and Settings\All Users\Application Data\Gadu-Gadu 10\_userdata\ggbho.2.dll File not found
O3 - HKLM\..\Toolbar: (DigiMode Toolbar) - {29f0230f-a825-44d0-b98f-a044b7592cff} - D:\Program Files\DigiMode\tbDigi.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - D:\Program Files\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - D:\Program Files\Norton Internet Security\Engine\19.8.0.14\coieplg.dll (Symantec Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (DigiMode Toolbar) - {29F0230F-A825-44D0-B98F-A044B7592CFF} - D:\Program Files\DigiMode\tbDigi.dll (Conduit Ltd.)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] D:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS4ServiceManager] "D:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] D:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [amd_dc_opt] D:\Program Files\AMD\amd_dc_opt\amd_dc_opt.exe ()
O4 - HKLM..\Run: [AmIcoSinglun] D:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (Alcor Micro Corp.)
O4 - HKLM..\Run: [ConnectionCenter] D:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [Freecorder FLV Service] D:\Program Files\Freecorder\FLVSrvc.exe (Applian Technologies, Inc.)
O4 - HKLM..\Run: [Jet Detection] D:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe ()
O4 - HKLM..\Run: [NvCplDaemon] D:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] D:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVRaidService] D:\WINDOWS\system32\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] D:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [SwitchBoard] D:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UpdReg] D:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WINDVDPatch] D:\WINDOWS\System32\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [Akamai NetSession Interface] D:\Documents and Settings\Max\Local Settings\Application Data\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [Facebook Update] D:\Documents and Settings\Max\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [Fraps] D:\Fraps\fraps.exe (Beepa P/L)
O4 - HKCU..\Run: [RGSC] D:\Program Files\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe /silent File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] D:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] D:\WINDOWS\System32\Macromed\Flash\FlashUtil32_11_3_300_271_Plugin.exe (Adobe Systems Incorporated)
O4 - Startup: D:\Documents and Settings\All Users\Start Menu\Programs\Startup\Wireless Configuration Utility HW.51.lnk = D:\Program Files\802.11 Wireless LAN\802.11g Wireless Cardbus & PCI Adapter HW.51 V1.00\WlanCU.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Add to Google Photos Screensa&ver - D:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\Max\Start Menu\Programs\IMVU\Run IMVU.lnk ()
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - D:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_32)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4A8A9A1A-2710-46A3-B73D-6350A4386B3A}: NameServer = 208.67.222.222,208.67.220.220
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5E7073CB-1EC7-4274-B4D7-78A1D8B4EF99}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica; charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=euc-jp {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=ISO-8859-1 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS936 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS949 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=MS950 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\application/x-ica;charset=UTF-8 {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - D:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (D:\WINDOWS\system32\userinit.exe) - D:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (Explorer.exe) - D:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008-06-20 22:54:06 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{235c3396-39e9-11df-b1a0-0016e68727cd}\Shell - "" = AutoRun
O33 - MountPoints2\{235c3396-39e9-11df-b1a0-0016e68727cd}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{235c3396-39e9-11df-b1a0-0016e68727cd}\Shell\AutoRun\command - "" = J:\LaunchU3.exe -a
O33 - MountPoints2\{bf10ac46-3b3b-11de-aef4-0016e68727cd}\Shell\AutoRun\command - "" = F:\svchost.exe
O33 - MountPoints2\{c8202cf2-0f04-11de-ae64-db64b0333ff7}\Shell\AutoRun\command - "" = J:\svchost.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012-09-08 18:27:08 | 002,211,928 | ---- | C] (Kaspersky Lab ZAO) -- D:\Documents and Settings\Max\Desktop\TDSSKiller.exe
[2012-09-07 09:59:22 | 000,000,000 | ---D | C] -- D:\Program Files\Mozilla Firefox
[2012-09-02 15:52:19 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Max\Local Settings\Application Data\NPE
[2012-09-02 15:45:55 | 000,000,000 | -HSD | C] -- D:\Config.Msi
[2012-09-02 11:19:42 | 000,246,760 | ---- | C] (Oracle Corporation) -- D:\WINDOWS\System32\javaws.exe
[2012-09-02 11:19:26 | 000,174,056 | ---- | C] (Oracle Corporation) -- D:\WINDOWS\System32\javaw.exe
[2012-09-02 11:19:26 | 000,174,056 | ---- | C] (Oracle Corporation) -- D:\WINDOWS\System32\java.exe
[2012-09-02 11:19:26 | 000,093,672 | ---- | C] (Oracle Corporation) -- D:\WINDOWS\System32\WindowsAccessBridge.dll
[2012-08-26 02:16:18 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Max\jagexcache
[2012-08-26 02:15:57 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Max\Local Settings\Application Data\Sun
[2012-08-26 02:14:09 | 000,000,000 | ---D | C] -- D:\Program Files\Common Files\Java
[2012-08-22 19:20:59 | 000,000,000 | ---D | C] -- D:\Documents and Settings\Max\Desktop\uni 4 joe
[2012-08-10 15:07:20 | 000,092,208 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\WING.DLL
[2012-08-10 15:07:20 | 000,012,800 | ---- | C] (Microsoft Corporation) -- D:\WINDOWS\System32\WING32.DLL
[2009-06-13 12:47:25 | 000,047,360 | ---- | C] (VSO Software) -- D:\Documents and Settings\Max\Application Data\pcouffin.sys
[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[3 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012-09-08 17:46:00 | 000,000,830 | ---- | M] () -- D:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012-09-08 17:45:00 | 000,001,030 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2012-09-08 16:30:02 | 000,000,990 | ---- | M] () -- D:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1644491937-1532298954-1417001333-1003UA.job
[2012-09-08 13:38:13 | 000,001,026 | ---- | M] () -- D:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2012-09-08 13:36:33 | 000,000,021 | ---- | M] () -- D:\WINDOWS\S.dirmngr
[2012-09-08 13:36:25 | 000,002,228 | ---- | M] () -- D:\WINDOWS\System32\wpa.dbl
[2012-09-08 13:36:15 | 000,002,048 | --S- | M] () -- D:\WINDOWS\bootstat.dat
[2012-09-07 14:53:14 | 000,024,888 | ---- | M] () -- D:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000001-00001102-00000002-80611102}.rfx
[2012-09-07 14:53:14 | 000,024,888 | ---- | M] () -- D:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000001-00001102-00000002-80611102}.rfx
[2012-09-07 14:53:14 | 000,016,420 | ---- | M] () -- D:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000001-00001102-00000002-80611102}.rfx
[2012-09-07 14:53:14 | 000,016,420 | ---- | M] () -- D:\WINDOWS\System32\BMXState-{00000005-00000000-00000001-00001102-00000002-80611102}.rfx
[2012-09-07 14:53:14 | 000,001,080 | ---- | M] () -- D:\WINDOWS\System32\settingsbkup.sfm
[2012-09-07 14:53:14 | 000,001,080 | ---- | M] () -- D:\WINDOWS\System32\settings.sfm
[2012-09-07 14:53:14 | 000,000,024 | ---- | M] () -- D:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000001-00001102-00000002-80611102}.dat
[2012-09-07 14:53:14 | 000,000,024 | ---- | M] () -- D:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000002-80611102}.dat
[2012-09-07 14:52:59 | 000,000,000 | ---- | M] () -- D:\WINDOWS\System32\Access.dat
[2012-09-07 10:22:11 | 000,095,639 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\moses.jpg
[2012-09-05 22:30:00 | 000,000,968 | ---- | M] () -- D:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1644491937-1532298954-1417001333-1003Core.job
[2012-09-04 23:55:02 | 000,889,669 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\bs.jpg
[2012-09-03 18:23:20 | 000,000,024 | ---- | M] () -- D:\Documents and Settings\Max\random.dat
[2012-09-03 18:22:28 | 000,000,059 | ---- | M] () -- D:\Documents and Settings\Max\jagex_cl_runescape_LIVE.dat
[2012-09-02 15:46:12 | 000,001,729 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012-09-02 15:07:01 | 002,715,001 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\Untitled.pdn
[2012-09-02 14:59:12 | 000,231,424 | ---- | M] () -- D:\Documents and Settings\Max\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012-09-02 11:19:10 | 000,093,672 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\WindowsAccessBridge.dll
[2012-09-02 11:19:09 | 000,246,760 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\javaws.exe
[2012-09-02 11:19:09 | 000,174,056 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\javaw.exe
[2012-09-02 11:19:09 | 000,143,872 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\javacpl.cpl
[2012-09-02 11:19:08 | 000,821,736 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\npdeployJava1.dll
[2012-09-02 11:19:08 | 000,746,984 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\deployJava1.dll
[2012-09-02 11:19:08 | 000,174,056 | ---- | M] (Oracle Corporation) -- D:\WINDOWS\System32\java.exe
[2012-09-02 11:06:43 | 000,501,518 | ---- | M] () -- D:\WINDOWS\System32\perfh009.dat
[2012-09-02 11:06:43 | 000,087,424 | ---- | M] () -- D:\WINDOWS\System32\perfc009.dat
[2012-08-28 23:58:41 | 000,000,852 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\Saints Row 2.lnk
[2012-08-28 20:41:28 | 000,000,519 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\Silkroad.lnk
[2012-08-26 02:16:58 | 000,000,069 | ---- | M] () -- D:\Documents and Settings\Max\jagex_runescape_preferences2.dat
[2012-08-26 02:16:18 | 000,000,041 | ---- | M] () -- D:\Documents and Settings\Max\jagex_runescape_preferences.dat
[2012-08-26 02:00:01 | 000,000,338 | ---- | M] () -- D:\WINDOWS\tasks\AdobeAAMUpdater-1.0-TOMEK-Max.job
[2012-08-24 13:28:40 | 002,211,928 | ---- | M] (Kaspersky Lab ZAO) -- D:\Documents and Settings\Max\Desktop\TDSSKiller.exe
[2012-08-23 13:38:56 | 000,000,076 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\Counter-Strike Global Offensive.url
[2012-08-22 19:24:52 | 024,873,262 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\uni 4 joe.zip
[2012-08-15 22:28:56 | 000,008,942 | ---- | M] () -- D:\WINDOWS\System32\drivers\NIS\1308000.00E\VT20120731.038
[2012-08-15 15:27:37 | 000,001,973 | ---- | M] () -- D:\Documents and Settings\All Users\Desktop\Norton Internet Security.LNK
[2012-08-15 15:26:16 | 000,509,594 | ---- | M] () -- D:\WINDOWS\System32\drivers\NIS\1308000.00E\Cat.DB
[2012-08-15 12:46:27 | 000,426,184 | ---- | M] (Adobe Systems Incorporated) -- D:\WINDOWS\System32\FlashPlayerApp.exe
[2012-08-15 12:46:27 | 000,070,344 | ---- | M] (Adobe Systems Incorporated) -- D:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2012-08-15 01:50:48 | 733,908,992 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\The Dictator {2012} DVDRIP. Jaybob.avi
[2012-08-14 23:54:55 | 000,443,286 | ---- | M] () -- D:\Documents and Settings\Max\Desktop\repost.bmp
[2012-08-10 06:28:35 | 000,000,172 | ---- | M] () -- D:\WINDOWS\System32\drivers\NIS\1308000.00E\isolate.ini
[4 D:\WINDOWS\*.tmp files -> D:\WINDOWS\*.tmp -> ]
[3 D:\WINDOWS\System32\*.tmp files -> D:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012-09-08 13:36:33 | 000,000,021 | ---- | C] () -- D:\WINDOWS\S.dirmngr
[2012-09-07 10:19:02 | 000,095,639 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\moses.jpg
[2012-09-04 23:55:02 | 000,889,669 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\bs.jpg
[2012-09-02 15:46:11 | 000,001,729 | ---- | C] () -- D:\Documents and Settings\All Users\Desktop\Adobe Reader 9.lnk
[2012-09-02 14:59:12 | 002,715,001 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\Untitled.pdn
[2012-08-28 20:41:28 | 000,000,519 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\Silkroad.lnk
[2012-08-26 02:16:18 | 000,000,059 | ---- | C] () -- D:\Documents and Settings\Max\jagex_cl_runescape_LIVE.dat
[2012-08-26 02:16:18 | 000,000,024 | ---- | C] () -- D:\Documents and Settings\Max\random.dat
[2012-08-23 13:38:56 | 000,000,076 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\Counter-Strike Global Offensive.url
[2012-08-22 19:24:49 | 024,873,262 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\uni 4 joe.zip
[2012-08-18 19:27:56 | 733,908,992 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\The Dictator {2012} DVDRIP. Jaybob.avi
[2012-08-14 23:54:55 | 000,443,286 | ---- | C] () -- D:\Documents and Settings\Max\Desktop\repost.bmp
[2012-08-07 16:42:50 | 000,000,531 | ---- | C] () -- D:\WINDOWS\eReg.dat
[2012-07-30 19:32:04 | 000,000,657 | ---- | C] () -- D:\WINDOWS\SC2K4WIN.INI
[2012-03-02 13:08:11 | 071,624,279 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\.minecraft.backup020312SDK.rar
[2012-02-28 12:52:27 | 062,483,749 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\.minecraft.backup280212MineColony.rar
[2012-01-29 21:40:29 | 002,434,856 | ---- | C] () -- D:\WINDOWS\System32\pbsvc_bc2.exe
[2011-09-28 18:44:14 | 000,179,271 | ---- | C] () -- D:\WINDOWS\System32\xlive.dll.cat
[2011-09-14 14:05:36 | 128,381,568 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\.minecraft.rar
[2011-08-25 15:56:50 | 000,081,936 | ---- | C] () -- D:\WINDOWS\System32\RtNicProp32.dll
[2011-08-12 12:33:48 | 000,000,024 | ---- | C] () -- D:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000001-00001102-00000002-80611102}.dat
[2011-08-12 12:33:48 | 000,000,024 | ---- | C] () -- D:\WINDOWS\System32\DVCState-{00000005-00000000-00000001-00001102-00000002-80611102}.dat
[2011-08-12 12:25:01 | 000,000,128 | ---- | C] () -- D:\WINDOWS\SBWIN.INI
[2011-08-12 12:25:00 | 001,048,576 | ---- | C] () -- D:\WINDOWS\System32\SFMAN.DAT
[2011-08-12 12:25:00 | 000,000,231 | ---- | C] () -- D:\WINDOWS\AC3API.INI
[2011-08-12 12:24:36 | 000,034,914 | ---- | C] () -- D:\WINDOWS\System32\Emu10kx.ini
[2011-08-12 12:24:36 | 000,000,029 | ---- | C] () -- D:\WINDOWS\System32\ctzapxx.ini
[2011-08-12 12:24:35 | 000,179,669 | ---- | C] () -- D:\WINDOWS\System32\ctstatic.dat
[2011-08-12 12:24:34 | 000,176,128 | ---- | C] () -- D:\WINDOWS\PSCONV.EXE
[2011-08-12 12:24:34 | 000,163,933 | ---- | C] () -- D:\WINDOWS\System32\ctdlang.dat
[2011-08-12 12:24:34 | 000,112,387 | ---- | C] () -- D:\WINDOWS\System32\ctbasicw.dat
[2011-08-12 12:24:34 | 000,112,287 | ---- | C] () -- D:\WINDOWS\System32\CTBAS2W.DAT
[2011-08-12 12:24:34 | 000,049,152 | ---- | C] () -- D:\WINDOWS\System32\KILLAPPS.EXE
[2011-08-12 12:24:34 | 000,049,152 | ---- | C] ( ) -- D:\WINDOWS\System32\a3d.dll
[2011-08-12 12:24:34 | 000,044,055 | ---- | C] () -- D:\WINDOWS\System32\ctdaught.dat
[2011-08-12 12:24:34 | 000,036,864 | ---- | C] () -- D:\WINDOWS\System32\REGPLIB.EXE
[2011-08-12 12:24:34 | 000,000,166 | ---- | C] () -- D:\WINDOWS\System32\KILL.INI
[2011-07-18 12:07:24 | 000,000,269 | ---- | C] () -- D:\WINDOWS\game.ini
[2011-05-22 17:38:33 | 000,000,023 | ---- | C] () -- D:\WINDOWS\BlendSettings.ini
[2011-05-22 17:00:17 | 000,000,032 | ---- | C] () -- D:\WINDOWS\CD_Start.INI
[2011-05-03 17:14:28 | 000,000,126 | ---- | C] () -- D:\Documents and Settings\Max\Local Settings\Application Data\fusioncache.dat
[2011-03-24 14:11:01 | 000,000,000 | ---- | C] () -- D:\WINDOWS\System32\Access.dat
[2011-03-20 11:29:30 | 000,252,940 | ---- | C] () -- D:\WINDOWS\System32\nvdrsdb0.bin
[2011-03-20 11:29:23 | 000,252,940 | ---- | C] () -- D:\WINDOWS\System32\nvdrsdb1.bin
[2011-03-20 11:29:23 | 000,000,001 | ---- | C] () -- D:\WINDOWS\System32\nvdrssel.bin
[2011-01-18 20:40:01 | 000,136,504 | ---- | C] () -- D:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-12-11 13:25:07 | 000,000,287 | ---- | C] () -- D:\WINDOWS\EReg072.dat
[2010-11-02 21:21:23 | 000,002,528 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\$_hpcst$.hpc
[2010-10-16 16:36:32 | 000,000,006 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\start
[2010-10-16 16:22:11 | 000,000,010 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\install
[2010-09-17 21:04:37 | 000,000,132 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\Adobe PNG Format CS5 Prefs
[2010-09-13 19:47:51 | 000,000,000 | ---- | C] () -- D:\WINDOWS\PowerReg.dat
[2009-12-20 19:00:21 | 000,000,000 | ---- | C] () -- D:\Documents and Settings\Max\Picture 0022.jpg
[2009-12-17 10:52:29 | 000,061,224 | ---- | C] () -- D:\Documents and Settings\Max\GoToAssistDownloadHelper.exe
[2009-11-25 14:41:29 | 000,000,218 | ---- | C] () -- D:\Documents and Settings\Max\Local Settings\Application Data\recently-used.xbel
[2009-10-11 13:53:59 | 000,000,069 | ---- | C] () -- D:\Documents and Settings\Max\jagex_runescape_preferences2.dat
[2009-09-05 12:57:58 | 000,138,056 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\PnkBstrK.sys
[2009-06-13 12:47:25 | 000,081,920 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\ezpinst.exe
[2009-06-13 12:47:25 | 000,007,176 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\pcouffin.cat
[2009-06-13 12:47:25 | 000,001,144 | ---- | C] () -- D:\Documents and Settings\Max\Application Data\pcouffin.inf
[2009-05-29 13:46:25 | 000,106,496 | ---- | C] () -- D:\Program Files\hl2.exe
[2009-05-29 13:46:18 | 000,000,164 | ---- | C] () -- D:\Program Files\Launcher.cfg
[2009-04-10 22:21:56 | 000,000,032 | R--- | C] () -- D:\Documents and Settings\Max\hash.dat
[2009-04-04 17:02:11 | 000,000,041 | ---- | C] () -- D:\Documents and Settings\Max\jagex_runescape_preferences.dat
[2009-03-12 19:32:15 | 000,231,424 | ---- | C] () -- D:\Documents and Settings\Max\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

========== LOP Check ==========

[2011-11-08 13:35:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Ableton
[2011-08-25 16:04:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\AmUStor
[2010-11-11 15:20:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Astroburn Pro
[2011-05-19 16:18:21 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\AVAST Software
[2009-03-13 10:51:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Azureus
[2011-07-05 15:55:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Citrix
[2010-06-11 11:00:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2010-04-23 09:44:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Gadu-Gadu 10
[2009-11-25 14:26:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\GNU
[2009-07-16 15:37:37 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\OpenFM
[2009-04-10 15:27:54 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2011-01-15 15:12:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\regid.1986-12.com.adobe
[2012-09-08 13:39:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TEMP
[2010-12-30 23:48:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\TP-LINK
[2011-03-23 15:35:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Tunngle
[2011-05-22 16:52:15 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\Ubisoft
[2010-04-04 00:54:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2012-08-09 13:06:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\.minecraft
[2010-11-18 22:03:41 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\.minecraft server
[2011-04-15 00:28:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\.minecraft_xray
[2012-08-07 20:50:26 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\.Spoutcraft
[2012-02-11 14:23:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\1.0.0.minecraft
[2011-12-05 13:59:19 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Ableton
[2011-01-02 11:26:46 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Aguhqo
[2010-11-04 16:25:27 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Alqu
[2010-11-11 15:20:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Astroburn Pro
[2009-04-22 11:50:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Audacity
[2012-05-09 19:21:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\avidemux
[2011-05-14 13:52:53 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Azureus
[2010-08-06 17:16:11 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Bioshock
[2011-12-20 22:29:20 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Copy of .minecraft
[2010-09-19 23:17:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\CursorArts
[2010-06-11 11:05:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\DAEMON Tools Lite
[2010-10-16 16:17:18 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Dropbox
[2011-01-02 02:11:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Duur
[2011-08-25 11:50:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Easeware
[2010-05-05 22:56:38 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Facebook
[2012-06-08 12:22:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Firefly Studios
[2011-08-07 14:55:49 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Gadu-Gadu 10
[2009-06-04 15:28:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\GetRightToGo
[2009-12-10 17:29:04 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\gnupg
[2009-11-25 14:41:13 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\gtk-2.0
[2011-06-23 19:21:16 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Gzegzolka XP
[2010-09-03 17:26:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\HandBrake
[2011-07-05 15:54:50 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\ICAClient
[2011-09-24 01:41:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\IMVU
[2011-09-15 17:54:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\IMVUClient
[2011-12-11 14:11:40 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\mc backup 11.12.11
[2011-08-22 10:15:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\MC BCKP
[2012-05-29 16:03:55 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\MC BCKP 2
[2012-01-31 13:09:48 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\MC BCKP 3
[2012-04-30 17:25:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\MfcEmbed
[2011-09-11 14:34:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\minecraft
[2011-09-14 10:52:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\minecraft2
[2011-04-28 12:44:30 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Minetographer
[2010-10-25 15:32:45 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Moimgi
[2011-11-14 16:50:44 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\New Technology Studio
[2009-03-12 14:51:22 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Nowe Gadu-Gadu
[2009-07-16 15:37:35 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\OpenFM
[2009-09-24 10:00:06 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\OpenOffice.org
[2011-01-14 00:20:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Oxer
[2009-09-17 22:08:34 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\PoivY
[2009-05-27 12:25:17 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\SPORE
[2010-09-17 11:52:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011-03-22 23:40:23 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\SystemRequirementsLab
[2010-10-26 11:46:59 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Thunderbird
[2011-05-18 16:26:14 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Tunngle
[2011-04-26 14:11:02 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Unity
[2012-08-23 00:14:51 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\uTorrent
[2009-06-13 12:47:31 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Vso
[2009-04-10 22:22:03 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\yoclient
[2011-01-14 10:50:57 | 000,000,000 | ---D | M] -- D:\Documents and Settings\Max\Application Data\Zana
[2011-08-25 11:50:37 | 000,000,366 | ---- | M] () -- D:\WINDOWS\Tasks\DriverEasy Scheduled Scan.job
[2012-09-05 22:30:00 | 000,000,968 | ---- | M] () -- D:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1644491937-1532298954-1417001333-1003Core.job
[2012-09-08 16:30:02 | 000,000,990 | ---- | M] () -- D:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1644491937-1532298954-1417001333-1003UA.job

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008-04-14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- D:\WINDOWS\explorer.exe
[2008-04-14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 -- D:\WINDOWS\system32\dllcache\explorer.exe

< MD5 for: SVCHOST.EXE >
[2012-04-04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- D:\Program Files\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008-04-14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- D:\WINDOWS\system32\dllcache\svchost.exe
[2008-04-14 05:42:38 | 000,014,336 | ---- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 -- D:\WINDOWS\system32\svchost.exe

< MD5 for: USERINIT.EXE >
[2008-04-14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- D:\WINDOWS\system32\dllcache\userinit.exe
[2008-04-14 05:42:40 | 000,026,112 | ---- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 -- D:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012-04-04 15:56:38 | 000,199,240 | ---- | M] () MD5=097D0E812D7A9A3101CE46CB2BE0474D -- D:\Program Files\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008-04-14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- D:\WINDOWS\system32\dllcache\winlogon.exe
[2008-04-14 05:42:40 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- D:\WINDOWS\system32\winlogon.exe

< C:\Windows\assembly\tmp\U\*.* /s >

========== Files - Unicode (All) ==========
[2010-10-17 19:23:12 | 000,000,000 | ---D | M](D:\WINDOWS\System32\?windows) -- D:\WINDOWS\System32\䁜windows
[2010-10-17 19:23:12 | 000,000,000 | ---D | M](D:\windows?system32) -- D:\windows䁜system32
[2010-10-17 19:23:12 | 000,000,000 | ---D | C](D:\WINDOWS\System32\?windows) -- D:\WINDOWS\System32\䁜windows
[2010-10-17 19:23:12 | 000,000,000 | ---D | C](D:\windows?system32) -- D:\windows䁜system32
[2009-06-15 20:44:17 | 000,000,000 | ---D | M](D:\Program Files\G?eg?ó3ka XP) -- D:\Program Files\G¿eg¿ó³ka XP
[2009-06-15 20:44:17 | 000,000,000 | ---D | M](D:\Program Files\G?eg?ó3ka XP) -- D:\Program Files\G¿eg¿ó³ka XP
(D:\Program Files\G?eg?ó3ka XP) -- D:\Program Files\G¿eg¿ó³ka XP

========== Alternate Data Streams ==========

@Alternate Data Stream - 16 bytes -> D:\Documents and Settings\Max\My Documents\Azureus Downloads:Shareaza.GUID
@Alternate Data Stream - 154 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:0CE7F3C9
@Alternate Data Stream - 138 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:63238B95
@Alternate Data Stream - 138 bytes -> D:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF

< End of report >
SPYBOT TEATIMER
  • Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
  • On the left hand side, click on Tools, then click on the Resident Icon in the list.
  • Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
  • Click on the "System Startup" icon in the List
  • Uncheck the "TeaTimer" box and "OK" any prompts.
  • If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
  • Exit Spybot S&D when done and reboot your computer.
    (When we are done, you can re-enable Teatimer using the same steps but this time place a check next to "Resident TeaTimer" and check the "TeaTimer" box in System Startup.]








Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error
Yes, I'm sorry it's taking me a while, but I have a bit difficult situation at home and find it hard to organize some time. If you may, please, don't lock this thread for a while, I will greatly appreciate it. I understand the first logs I've submitted didn't show up anything suspicious?
I am going on holiday so am closing this topic, if you still need help start a new one when you have time to reply to a helper and they will resolve your problem.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI