OTL logfile created on: 6/17/2011 12:44:59 AM - Run 1
OTL by OldTimer - Version 3.2.24.0 Folder = C:\Users\Ruben\Documents\Downloads\Programs
Windows Vista Ultimate Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19019)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.25 Gb Total Physical Memory | 2.03 Gb Available Physical Memory | 62.51% Memory free
6.73 Gb Paging File | 5.58 Gb Available in Paging File | 82.87% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 71.08 Gb Free Space | 15.26% Space Free | Partition Type: NTFS
Computer Name: NIRVANA | User Name: Ruben | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/06/17 00:40:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ruben\Documents\Downloads\Programs\OTL.exe
PRC - [2011/05/29 09:11:28 | 000,449,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/03/28 16:15:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\System32\NLSSRV32.EXE
PRC - [2011/03/21 11:17:44 | 000,196,928 | ---- | M] (Nitro PDF Software) -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe
PRC - [2011/03/17 09:31:44 | 003,278,232 | ---- | M] (Tonec Inc.) -- C:\Program Files\Internet Download Manager\IDMan.exe
PRC - [2011/01/20 17:20:34 | 000,426,840 | ---- | M] (IObit) -- C:\Program Files\IObit\Game Booster\gbtray.exe
PRC - [2010/10/16 13:42:12 | 000,792,680 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2010/10/16 12:46:40 | 000,369,256 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2009/07/29 11:29:37 | 000,598,696 | ---- | M] ( ) -- C:\Windows\System32\lxedcoms.exe
PRC - [2009/04/11 02:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/06/17 00:40:27 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\Ruben\Documents\Downloads\Programs\OTL.exe
MOD - [2010/08/31 11:43:52 | 001,686,016 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/05/29 09:11:28 | 000,366,640 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011/03/21 11:17:56 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\System32\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/03/21 11:17:44 | 000,196,928 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Nitro PDF\Professional\NitroPDFDriverService.exe -- (NitroDriverReadSpool)
SRV - [2011/03/09 20:07:10 | 000,083,456 | ---- | M] () [Disabled | Stopped] -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\startup.service@mozilla.com\svc.exe -- (Firefox Service)
SRV - [2010/10/16 12:46:40 | 000,369,256 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/08/29 18:29:58 | 003,893,752 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2010/04/14 20:00:48 | 000,193,192 | ---- | M] () [Auto | Stopped] -- C:\Windows\System32\spool\DRIVERS\W32X86\3\\lxedserv.exe -- (lxedCATSCustConnectService)
SRV - [2009/07/29 11:29:37 | 000,598,696 | ---- | M] ( ) [Auto | Running] -- C:\Windows\System32\lxedcoms.exe -- (lxed_device)
SRV - [2009/07/16 17:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/03/23 10:31:04 | 000,013,824 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\TestOut\Orbis\OrbisClient.Services.exe -- (OrbisClient.Services)
SRV - [2008/04/24 14:26:18 | 000,202,560 | ---- | M] (SupportSoft, Inc.) [Disabled | Stopped] -- C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe -- (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/04/01 17:07:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/01 17:07:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011/03/17 11:52:34 | 000,086,280 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2011/02/23 08:27:00 | 010,468,360 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/10/21 15:11:02 | 000,081,680 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV - [2010/10/14 14:08:53 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010/10/14 14:08:52 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010/10/14 14:08:52 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/01 16:39:56 | 000,240,128 | ---- | M] (PARADOX) [Kernel | Boot | Stopped] -- C:\Windows\System32\drivers\royal.sys -- (OemBiosDevice)
DRV - [2010/05/04 11:51:46 | 000,020,096 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MRESP50.sys -- (MRESP50)
DRV - [2010/05/04 11:50:54 | 000,021,248 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] -- C:\Program Files\Common Files\Motive\MREMP50.sys -- (MREMP50)
DRV - [2009/12/21 22:50:16 | 000,005,760 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vHidDev.sys -- (vHidDev)
DRV - [2009/08/10 16:25:36 | 000,039,936 | ---- | M] (Cypress Semiconductor) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\CYUSB.sys -- (CYUSB)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2008/01/18 06:43:16 | 000,016,128 | ---- | M] (Razer USA Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Lycosa.sys -- (LycoFltr)
DRV - [2007/08/02 09:32:26 | 000,022,784 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dadder.sys -- (DAdderFltr)
DRV - [2004/08/13 09:56:20 | 000,005,810 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepage
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://securityresponse.symantec.com/avcenter/fix_homepage
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.att.net
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FB 51 A8 43 F1 38 CB 01 [binary data]
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\..\URLSearchHook: {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaultthis.engineName: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://google.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems:
battlefieldheroespatcher@ea.com:5.0.67.0
FF - prefs.js..extensions.enabledItems: {000F1EA4-5E08-4564-A29B-29076F63A37A}:1.0.3.126
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3
FF - prefs.js..extensions.enabledItems: {BBDA0591-3099-440a-AA10-41764D9DB4DB}:2.0
FF - prefs.js..extensions.enabledItems:
adblockpopups@jessehakanen.net:0.2.2
FF - prefs.js..extensions.enabledItems: {C8E400E3-44BC-4e78-8C17-8C48E74C67F4}:3.6
FF - prefs.js..keyword.URL: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2504091&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/01 12:27:31 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/16 15:34:23 | 000,000,000 | ---D | M]
[2010/12/24 19:27:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Extensions
[2010/12/24 19:27:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Extensions\home2@tomtom.com
[2011/06/12 17:59:04 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions
[2010/09/18 22:01:59 | 000,000,000 | ---D | M] () -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
[2011/03/11 00:50:09 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\battlefieldheroespatcher@ea.com
[2011/04/04 21:45:19 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\battlefieldplay4free@ea.com
[2011/06/12 17:59:04 | 000,000,000 | ---D | M] (Yontoo Layers) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\plugin@yontoo.com
[2011/03/23 21:31:13 | 000,000,000 | ---D | M] (startup.service) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\startup.service@mozilla.com
[2011/03/23 21:11:28 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\extensions\support@lastpass.com
[2010/08/09 00:45:15 | 000,001,832 | ---- | M] () -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\searchplugins\bing.xml
[2011/05/25 16:18:08 | 000,000,879 | ---- | M] () -- C:\Users\Ruben\AppData\Roaming\Mozilla\Firefox\Profiles\85ycv5pw.default\searchplugins\conduit.xml
[2011/03/23 20:57:19 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/06/17 20:32:18 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) --
[2011/03/28 14:39:40 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\RUBEN\APPDATA\ROAMING\IDM\IDMMZCC3
() (No name found) -- C:\USERS\RUBEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\85YCV5PW.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2010/06/16 03:00:40 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011/05/01 12:27:28 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/06/17 20:32:03 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/07/27 16:13:46 | 000,027,136 | ---- | M] (NHN USA Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
[2010/07/28 18:14:08 | 000,022,016 | ---- | M] (NHN USA Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
[2011/06/13 17:23:46 | 000,001,919 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing-zugo.xml
[2010/01/01 04:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/17 00:22:59 | 000,000,027 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (IDMIEHlprObj Class) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O2 - BHO: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine ) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (XfireXO Toolbar) - {5e5ab302-7f65-44cd-8211-c1d4caaccea3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Vuze Remote Toolbar) - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\..\Toolbar\WebBrowser: (XfireXO Toolbar) - {5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} - C:\Program Files\XfireXO\prxtbXfi2.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\..\Toolbar\WebBrowser: (Vuze Remote Toolbar) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - C:\Program Files\Vuze_Remote\prxtbVuz2.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [EzPrint] C:\Program Files\Lexmark S600 Series\ezprint.exe ()
O4 - HKLM..\Run: [lxedmon.exe] C:\Program Files\Lexmark S600 Series\lxedmon.exe ()
O4 - HKLM..\Run: [Lycosa] C:\Program Files\Razer\Lycosa\razerhid.exe (Razer USA Ltd.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe (Tonec Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 68.87.74.166 68.87.68.166
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img29.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 17:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O35 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKU\S-1-5-21-4131535426-1223570999-1301256555-1000\...exe [@ = exefile] -- "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - File not found
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.bdmpeg - C:\Windows\System32\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.mpeg - C:\Windows\System32\bdmpegv.dll ()
Drivers32: vidc.tscc - C:\Windows\System32\TSCCVID.DLL (TechSmith Corporation)
Drivers32: vidc.VP60 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: vidc.VP61 - C:\Windows\System32\vp6vfw.dll (On2.com)
Drivers32: VIDC.XFR1 - C:\Windows\System32\xfcodec.dll ()
Drivers32: vidc.XVID - C:\Windows\System32\xvidvfw.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/06/17 00:26:40 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/06/17 00:26:38 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/06/17 00:26:38 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Local\temp
[2011/06/16 23:59:53 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/06/16 23:59:53 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/06/16 23:59:53 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/06/16 23:59:49 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/06/16 23:59:45 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/06/16 23:06:52 | 000,000,000 | ---D | C] -- C:\Users\Ruben\Documents\Battlefield Heroes
[2011/06/16 15:47:00 | 000,607,310 | R--- | C] (Swearware) -- C:\Users\Ruben\Desktop\dds.scr
[2011/06/16 14:59:10 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/06/16 08:41:43 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Avira
[2011/06/16 08:40:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011/06/16 08:39:53 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011/06/16 08:39:52 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011/06/16 08:39:52 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011/06/16 08:39:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011/06/16 08:39:52 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/06/15 22:19:26 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Malwarebytes
[2011/06/15 22:18:38 | 000,039,984 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/06/15 22:18:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/06/15 22:18:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/06/15 22:18:35 | 000,022,712 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/06/15 22:18:35 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/06/15 14:28:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Macromedia
[2011/06/12 20:50:07 | 000,000,000 | ---D | C] -- C:\ProgramData\WindowsSearch
[2011/06/12 18:07:44 | 000,000,000 | ---D | C] -- C:\ProgramData\mP28621EnNfJ28621
[2011/06/12 13:33:11 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\GARMIN
[2011/06/12 13:33:04 | 000,000,000 | ---D | C] -- C:\Program Files\Garmin GPS Plugin
[2011/06/11 13:02:15 | 000,000,000 | ---D | C] -- C:\Program Files\iPod(5)
[2011/06/07 17:37:07 | 000,000,000 | ---D | C] -- C:\Users\Ruben\Desktop\files
[2011/06/02 18:01:12 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Nitro PDF
[2011/06/02 17:58:49 | 000,026,432 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalmon.dll
[2011/06/02 17:58:49 | 000,017,728 | ---- | C] (Nitro PDF Software) -- C:\Windows\System32\nitrolocalui.dll
[2011/06/02 17:58:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF
[2011/06/02 17:58:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF
[2011/06/02 17:58:21 | 000,000,000 | ---D | C] -- C:\Program Files\Nitro PDF
[2011/06/02 17:56:37 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Downloaded Installations
[2011/06/02 17:53:22 | 000,000,000 | ---D | C] -- C:\Program Files\psconvert
[2011/06/02 17:53:22 | 000,000,000 | ---D | C] -- C:\Windows\System32\psconv
[2011/06/01 22:44:39 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUpMedia
[2011/06/01 22:18:52 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/06/01 22:17:13 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/06/01 22:13:02 | 000,000,000 | ---D | C] -- C:\Users\Ruben\Desktop\redsn0w_win_0.9.6rc16
[2011/05/30 14:23:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GamersFirst
[2011/05/30 14:23:48 | 000,000,000 | ---D | C] -- C:\Program Files\GamersFirst
[2011/05/24 18:52:36 | 000,000,000 | ---D | C] -- C:\newFolder
[2011/05/24 18:34:39 | 000,000,000 | ---D | C] -- C:\testFolder
[2011/05/24 17:02:53 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Thinstall
[2011/05/24 17:02:52 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Local\Thinstall
[2011/05/21 15:10:31 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Local\ElevatedDiagnostics
[2011/05/21 15:08:52 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ATS
[2011/05/20 21:32:54 | 000,000,000 | -HSD | C] -- C:\ProgramData\DSS
[2011/05/20 21:15:21 | 000,000,000 | ---D | C] -- C:\Users\Ruben\AppData\Roaming\Lionhead Studios
[2011/05/18 23:27:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zuxxez
[2011/05/18 23:25:53 | 000,000,000 | ---D | C] -- C:\Program Files\Zuxxez
[2010/11/22 22:46:59 | 000,643,072 | ---- | C] ( ) -- C:\Windows\System32\lxedpmui.dll
[2010/11/22 22:46:58 | 000,324,264 | ---- | C] ( ) -- C:\Windows\System32\lxedih.exe
[2010/11/22 22:46:57 | 000,679,936 | ---- | C] ( ) -- C:\Windows\System32\lxedhbn3.dll
[2010/11/22 22:46:56 | 000,425,984 | ---- | C] ( ) -- C:\Windows\System32\lxedcoin.dll
[2010/11/22 22:46:56 | 000,369,320 | ---- | C] ( ) -- C:\Windows\System32\lxedcfg.exe
[2010/11/22 22:46:55 | 000,356,352 | ---- | C] ( ) -- C:\Windows\System32\lxedhcp.dll
[2010/11/22 22:45:40 | 001,044,480 | ---- | C] ( ) -- C:\Windows\System32\lxedserv.dll
[2010/11/22 22:45:40 | 000,847,872 | ---- | C] ( ) -- C:\Windows\System32\lxedusb1.dll
[2010/11/22 22:45:40 | 000,598,696 | ---- | C] ( ) -- C:\Windows\System32\lxedcoms.exe
[2010/11/22 22:45:40 | 000,569,344 | ---- | C] ( ) -- C:\Windows\System32\lxedlmpm.dll
[2010/11/22 22:45:40 | 000,372,736 | ---- | C] ( ) -- C:\Windows\System32\lxedcomm.dll
[2010/11/22 22:45:40 | 000,364,544 | ---- | C] ( ) -- C:\Windows\System32\lxedinpa.dll
[2010/11/22 22:45:40 | 000,344,064 | ---- | C] ( ) -- C:\Windows\System32\lxediesc.dll
[2009/12/09 20:35:44 | 000,802,816 | ---- | C] ( ) -- C:\Windows\System32\lxedcomc.dll
[4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/17 00:25:17 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/06/17 00:22:59 | 000,000,027 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/06/17 00:07:07 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/06/17 00:06:55 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 00:06:55 | 000,003,760 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/17 00:06:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/06/17 00:06:46 | 3488,735,232 | -HS- | M] () -- C:\hiberfil.sys
[2011/06/17 00:05:55 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2011/06/16 23:25:15 | 313,647,158 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/06/16 15:34:23 | 000,001,887 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/06/16 15:30:09 | 000,371,072 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/06/16 15:09:49 | 000,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{AEA45842-1F86-4FBD-95A1-80B4C6E0C0B0}.job
[2011/06/16 15:00:08 | 000,642,808 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/06/16 15:00:08 | 000,119,000 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/06/16 08:40:05 | 000,001,847 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011/06/16 08:31:07 | 000,607,310 | R--- | M] (Swearware) -- C:\Users\Ruben\Desktop\dds.scr
[2011/06/16 01:08:01 | 000,009,300 | -HS- | M] () -- C:\Users\Ruben\AppData\Local\gpcsj0vt0ce
[2011/06/16 01:08:01 | 000,009,300 | -HS- | M] () -- C:\ProgramData\gpcsj0vt0ce
[2011/06/15 22:18:38 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/15 20:32:32 | 000,138,056 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/06/15 20:32:32 | 000,138,056 | ---- | M] () -- C:\Users\Ruben\AppData\Roaming\PnkBstrK.sys
[2011/06/15 20:31:59 | 000,189,248 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/06/15 16:08:29 | 000,011,022 | -HS- | M] () -- C:\ProgramData\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/15 16:08:28 | 000,011,022 | -HS- | M] () -- C:\Users\Ruben\AppData\Local\48us8w3f1to16xul6toc58xy324vsb8o1vj8118lxm1s
[2011/06/14 13:28:39 | 000,010,442 | -HS- | M] () -- C:\ProgramData\2755211163
[2011/06/02 18:31:30 | 000,563,443 | ---- | M] () -- C:\Users\Ruben\Documents\RubenResume.pdf
[2011/06/02 17:58:45 | 000,001,910 | ---- | M] () -- C:\Users\Public\Desktop\Nitro PDF Professional.lnk
[2011/06/02 17:53:23 | 000,000,164 | ---- | M] () -- C:\Windows\System32\psconv.ini
[2011/06/01 22:44:18 | 000,190,464 | ---- | M] () -- C:\Users\Ruben\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/01 22:43:53 | 000,001,633 | ---- | M] () -- C:\Users\Ruben\Application Data\Microsoft\Internet Explorer\Quick Launch\Vuze.lnk
[2011/06/01 22:43:53 | 000,001,633 | ---- | M] () -- C:\Users\Public\Desktop\Vuze.lnk
[2011/06/01 22:28:26 | 637,183,974 | ---- | M] () -- C:\Users\Ruben\Desktop\iPad2,1_4.3.3_8J2_Restore.ipsw
[2011/06/01 22:12:38 | 013,963,665 | ---- | M] () -- C:\Users\Ruben\Desktop\redsn0w_win_0.9.6rc16.zip
[2011/05/31 19:23:06 | 000,000,894 | ---- | M] () -- C:\Users\Ruben\Desktop\WORD.lnk
[2011/05/30 17:56:27 | 000,281,656 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011/05/29 21:27:06 | 000,002,029 | ---- | M] () -- C:\Users\Public\Desktop\Google Earth.lnk
[2011/05/29 09:11:30 | 000,039,984 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2011/05/29 09:11:20 | 000,022,712 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2011/05/21 15:10:51 | 000,001,706 | ---- | M] () -- C:\Users\Ruben\Desktop\Fix it - Microsoft ATS.lnk
[2011/05/21 14:43:25 | 000,000,918 | ---- | M] () -- C:\Users\Ruben\Desktop\FableLauncher.exe - Shortcut.lnk
[2011/05/20 13:57:46 | 000,001,940 | ---- | M] () -- C:\Users\Ruben\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[4 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]