Solved @Broni the saver! please save my PC from Sirefef..:(

That looks good.

Restart computer normally.

Download Malwarebytes' Anti-Malware: http://www.malwarebytes.org/products/malwarebytes_free to your desktop.

* Double-click mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform quick scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad.
* Post the log back here.

Be sure to restart the computer.

The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\log-date.txt
 
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org

Database version: v2012.06.27.01

Windows 7 Service Pack 1 x86 NTFS
Internet Explorer 9.0.8112.16421
Bisho :: TOMASADISON [administrator]

6/28/2012 1:08:13 AM
mbam-log-2012-06-28 (01-08-13).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 329058
Time elapsed: 12 minute(s), 22 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

(end)
 
How is computer doing right now?

Download OTL to your Desktop.

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Click the Scan All Users checkbox.
  • Under the Custom Scan box paste this in:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg
%systemroot%\*.jpg
%systemroot%\*.png
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
%APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x
%USERPROFILE%\Desktop\*.exe
%PROGRAMFILES%\Common Files\*.*
%systemroot%\*.src
%systemroot%\install\*.*
%systemroot%\system32\DLL\*.*
%systemroot%\system32\HelpFiles\*.*
%systemroot%\tasks\*.*
%systemroot%\system32\rundll\*.*
%systemroot%\winn32\*.*
%systemroot%\Java\*.*
%systemroot%\system32\test\*.*
%systemroot%\system32\Rundll32\*.*
%systemroot%\AppPatch\Custom\*.*
%APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x
%PROGRAMFILES%\PC-Doctor\Downloads\*.*
%PROGRAMFILES%\Internet Explorer\*.tmp
%PROGRAMFILES%\Internet Explorer\*.dat
%USERPROFILE%\My Documents\*.exe
%USERPROFILE%\*.exe
%systemroot%\ADDINS\*.*
%systemroot%\assembly\*.bak2
%systemroot%\Config\*.*
%systemroot%\REPAIR\*.bak2
%systemroot%\SECURITY\Database\*.sdb /x
%systemroot%\SYSTEM\*.bak2
%systemroot%\Web\*.bak2
%systemroot%\Driver Cache\*.*
%PROGRAMFILES%\Mozilla Firefox\0*.exe
%ProgramFiles%\Microsoft Common\*.*
%ProgramFiles%\TinyProxy.
%USERPROFILE%\Favorites\*.url /x
%systemroot%\system32\*.bk
%systemroot%\*.te
%systemroot%\system32\system32\*.*
%ALLUSERSPROFILE%\*.dat /x
%systemroot%\system32\drivers\*.rmv
dir /b "%systemroot%\system32\*.exe" | find /I " " /c
dir /b "%systemroot%\*.exe" | find /I " " /c
%PROGRAMFILES%\Microsoft\*.*
%systemroot%\System32\Wbem\proquota.exe
%PROGRAMFILES%\Mozilla Firefox\*.dat
%USERPROFILE%\Cookies\*.txt /x
%SystemRoot%\system32\fonts\*.*
%systemroot%\system32\winlog\*.*
%systemroot%\system32\Language\*.*
%systemroot%\system32\Settings\*.*
%systemroot%\system32\*.quo
%SYSTEMROOT%\AppPatch\*.exe
%SYSTEMROOT%\inf\*.exe
%SYSTEMROOT%\Installer\*.exe
%systemroot%\system32\config\*.bak2
%systemroot%\system32\Computers\*.*
%SystemRoot%\system32\Sound\*.*
%SystemRoot%\system32\SpecialImg\*.*
%SystemRoot%\system32\code\*.*
%SystemRoot%\system32\draft\*.*
%SystemRoot%\system32\MSSSys\*.*
%ProgramFiles%\Javascript\*.*
%systemroot%\pchealth\helpctr\System\*.exe /s
%systemroot%\Web\*.exe
%systemroot%\system32\msn\*.*
%systemroot%\system32\*.tro
%AppData%\Microsoft\Installer\msupdates\*.*
%ProgramFiles%\Messenger\*.*
%systemroot%\system32\systhem32\*.*
%systemroot%\system\*.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs
/md5start
/md5stop


  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows: OTL.txt and Extras.txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post them back here.
 
I coudln't complete the scan.. here what it give me:

2lkxj4w.jpg


I also have an internal HDD seagate 1TB.. while my computer was not stable like now .. error accoured like explorer goes and back.. and HDD not seen in my computer nor in disk management.. but I can see it in BIOS info. it could be from the malware? or this is another issue?? please tell me I am willing to make something if you cure my personal PC.. Thanks in advance
 
Run hard drive diagnostics: http://www.tacktech.com/display.cfm?ttid=287
Make sure, you select tool, which is appropriate for the brand of your hard drive.
Depending on the program, it'll create bootable floppy, or bootable CD.
If downloaded file is of .iso type, use ImgBurn: http://www.imgburn.com/ to burn .iso file to a CD (select "Write image file to disc" option), and make the CD bootable.
For Toshiba hard drives, see here: http://storage.toshiba.com/storage-services-support/warranty-support/software-utilities#diagnostic

Note : If you do not know how to set your computer to boot from CD follow the steps here
 
I tried SeaTools for Windows since the image burn iso links are not found in server.. it didn't recognize it..I will try to unplug SATA cable and power cable and put them again.. but what about the sirefef? it is gone forever? and Microsoft Security Essential is good to keep?
 
Yes.. it didn't see the drive.. it partitioned into 2 hard disk one for music and my documents and one for videos and my videos.. so all my documents in the library are inside this hard disk..
Seatools for DOS pictures see below it seems the hard disk working properly but the windows can't see it even in disk managment ..

28jza5z.jpg


15miikx.jpg
 
I'm not really a hardware person so I suggest you create new topic in hardware forum and ask for explanation.
I'll keep this topic open.
 
1TB HDD Seagate are back to work.. It was from power failure I changed the stock power to another cable :)
OTL Quick Scan finishes successful are the logs:
OTL.txt:
OTL logfile created on: 6/30/2012 4:02:00 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = D:\My data\Desktop\Desktop\OTL
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 56.45% Memory free
6.48 Gb Paging File | 5.19 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.80 Gb Total Space | 24.67 Gb Free Space | 25.23% Space Free | Partition Type: NTFS
Drive D: | 200.19 Gb Total Space | 25.08 Gb Free Space | 12.53% Space Free | Partition Type: NTFS
Drive E: | 492.06 Gb Total Space | 392.46 Gb Free Space | 79.76% Space Free | Partition Type: NTFS
Drive F: | 439.45 Gb Total Space | 323.99 Gb Free Space | 73.73% Space Free | Partition Type: NTFS

Computer Name: TOMASADISON | User Name: Bisho | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/06/28 01:42:43 | 000,596,992 | ---- | M] (OldTimer Tools) -- D:\My data\Desktop\Desktop\OTL\OTL.exe
PRC - [2012/06/08 14:02:10 | 000,021,432 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
PRC - [2012/06/04 15:23:16 | 000,931,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/06/04 15:20:26 | 000,011,552 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2011/10/24 17:51:19 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe
PRC - [2011/05/25 09:09:08 | 000,839,272 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
PRC - [2011/05/25 09:09:06 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/02/25 08:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2011/02/18 12:47:12 | 000,079,192 | ---- | M] (Research In Motion Limited) -- C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
PRC - [2010/11/20 05:17:48 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/10/25 16:13:42 | 000,821,144 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
PRC - [2010/03/10 15:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2010/01/21 02:18:38 | 000,226,176 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE
PRC - [2009/10/30 14:57:08 | 000,369,200 | ---- | M] (DT Soft Ltd) -- C:\Program Files\DAEMON Tools Lite\DTLite.exe
PRC - [2009/06/20 02:31:39 | 000,651,264 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerQuick.exe
PRC - [2009/04/09 04:49:30 | 000,344,064 | ---- | M] (AVerMedia) -- C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe
PRC - [2009/03/30 15:00:54 | 000,221,184 | ---- | M] (Brother Industries, Ltd.) -- C:\Program Files\Brother\Brmfcmon\BrMfcMon.exe
PRC - [2008/12/10 11:01:50 | 000,405,504 | ---- | M] () -- C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe
PRC - [2008/06/11 11:34:02 | 000,159,744 | ---- | M] () -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe
PRC - [2007/03/06 11:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
PRC - [2007/02/20 12:07:40 | 000,199,752 | ---- | M] (Pinnacle Systems GmbH) -- C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/18 01:10:38 | 000,115,137 | ---- | M] () -- C:\Users\Bisho\AppData\Local\Temp\26b4a1dd-e07b-48af-be4e-9642b273284b\CliSecureRT.dll
MOD - [2012/06/08 14:02:10 | 000,021,432 | ---- | M] () -- C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe
MOD - [2012/05/30 20:06:48 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2012/05/30 20:06:30 | 001,242,512 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2012/01/08 16:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2011/12/17 09:53:26 | 001,218,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Management\ab1a41d184118635218d38da3f4bcae8\System.Management.ni.dll
MOD - [2011/12/17 08:32:30 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Remo#\4d72e6878b73da48f7a6953a5e0b9332\System.Runtime.Remoting.ni.dll
MOD - [2011/12/17 08:31:54 | 001,782,272 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\2b0b477db8f5a19d6365b93106b26651\System.Xaml.ni.dll
MOD - [2011/12/17 03:38:23 | 001,670,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\32f68764be7200d3796b55e377311245\Microsoft.VisualBasic.ni.dll
MOD - [2011/12/16 10:08:34 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/12/16 10:08:31 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/12/16 10:08:27 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/12/16 10:08:09 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/12/16 08:43:32 | 018,019,328 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\401a9dbeaad6b6ca70c90ae4fbd2e0b8\PresentationFramework.ni.dll
MOD - [2011/12/16 08:43:21 | 011,470,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\b540398c49e7c32ab58666de7f09f645\PresentationCore.ni.dll
MOD - [2011/12/16 08:43:19 | 013,138,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\fa45e7d581b80c34cb0d5518491c7387\System.Windows.Forms.ni.dll
MOD - [2011/12/16 08:43:15 | 007,069,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\90223e809b1ff291a7f65509702e2fa1\System.Core.ni.dll
MOD - [2011/12/16 08:43:13 | 005,617,664 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\a48e483c6b13da563725d72ec518a0bb\System.Xml.ni.dll
MOD - [2011/12/16 08:43:12 | 003,881,984 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\c0afb5fbfbc7a8d670b430672c5fd578\WindowsBase.ni.dll
MOD - [2011/12/16 08:43:12 | 001,652,736 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\fd0f015bc4324d8b9716ae38083a4e4d\System.Drawing.ni.dll
MOD - [2011/12/16 08:43:11 | 000,595,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\af091a68303117ca2166aa13bcbfbbd0\PresentationFramework.Aero.ni.dll
MOD - [2011/12/16 08:43:09 | 009,086,976 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\69adb8f9940fa1330f6f1b706e3dc31e\System.ni.dll
MOD - [2011/12/16 08:43:05 | 014,409,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\2b1af7649e57195b4b85bbf4c5cb7c90\mscorlib.ni.dll
MOD - [2011/06/29 16:46:36 | 000,008,704 | ---- | M] () -- C:\Users\Bisho\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.7.gadget\GetCoreTempInfoNET.dll
MOD - [2011/06/29 16:46:36 | 000,007,680 | ---- | M] () -- C:\Users\Bisho\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.7.gadget\SystemInfo.dll
MOD - [2011/06/29 16:46:36 | 000,006,144 | ---- | M] () -- C:\Users\Bisho\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.7.gadget\CoreTempReader.dll
MOD - [2011/03/02 13:40:51 | 000,140,288 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2009/02/27 16:38:20 | 000,139,264 | R--- | M] () -- C:\Program Files\Brother\BrUtilities\BrLogAPI.dll
MOD - [2008/06/11 11:34:02 | 000,159,744 | ---- | M] () -- C:\Program Files\Common Files\AVerMedia\AVerQuick\AVerHIDReceiver.exe


========== Win32 Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- -- (FLEXnet Licensing Manager)
SRV - [2012/06/17 04:29:49 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2012/06/04 15:20:26 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/06/04 15:20:26 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/05/26 00:50:01 | 003,417,376 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_80c2ffa.dll -- (Akamai)
SRV - [2012/02/23 13:40:40 | 002,886,528 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/01/18 14:38:28 | 000,155,320 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2012/01/04 13:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/05/25 09:09:06 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/01/21 20:23:04 | 000,008,192 | ---- | M] () [Disabled | Stopped] -- C:\Windows\System32\srvany.exe -- (KMService)
SRV - [2010/12/20 09:42:04 | 000,217,088 | ---- | M] (Teruten) [Disabled | Stopped] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2010/06/23 19:21:31 | 001,343,400 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/03/10 15:26:48 | 000,189,728 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/10/20 21:19:48 | 000,117,264 | ---- | M] (CACE Technologies, Inc.) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2009/07/16 18:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/07/14 04:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 04:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/04/09 04:49:30 | 000,344,064 | ---- | M] (AVerMedia) [Auto | Running] -- C:\Program Files\Common Files\AVerMedia\Service\AVerRemote.exe -- (AVerRemote)
SRV - [2008/12/10 11:01:50 | 000,405,504 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\AVerMedia\Service\AVerScheduleService.exe -- (AVerScheduleService)
SRV - [2007/03/06 11:35:02 | 000,198,168 | ---- | M] (InterVideo Inc.) [Auto | Running] -- C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe -- (Capture Device Service)
SRV - [2006/03/01 04:10:18 | 000,069,632 | ---- | M] (CrypKey (Canada) Ltd.) [Disabled | Stopped] -- C:\Windows\System32\Crypserv.exe -- (Crypkey License)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\vmnetadapter.sys -- (VMnetAdapter)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc)
DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E57A4CF-A0CD-4FC2-94F1-9AA1DE82192E}\MpKsl8ae75fa0.sys -- (MpKsl8ae75fa0)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\iBurstu.sys -- (iBurstu)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\dgderdrv.sys -- (dgderdrv)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\AmdLLD.sys -- (AmdLLD)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a0gnhw78)
DRV - File not found [2009/11/07 22:59:05] [Kernel | Auto | Stopped] -- C:\Program Files\CyberLink\PowerDVD9\000.fcl -- ({B154377D-700F-42cc-9474-23858FBDF4BD})
DRV - [2012/05/21 05:09:00 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.)
DRV - [2012/05/21 05:09:00 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV - [2012/04/23 14:26:26 | 000,096,056 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\idmwfp.sys -- (IDMWFP)
DRV - [2012/04/06 21:15:10 | 000,033,512 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2012/04/04 17:52:56 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/11/01 10:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 10:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 10:07:24 | 000,137,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2011/11/01 10:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/11/01 10:07:24 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/08/04 05:29:01 | 000,038,976 | ---- | M] (microOLAP Technologies LTD) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pssdk42.sys -- (PSSDK42)
DRV - [2011/07/09 22:10:56 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ANDROIDUSB.sys -- (HTCAND32)
DRV - [2011/07/01 11:46:40 | 000,026,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2011/06/02 08:47:22 | 000,136,808 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdm.sys -- (ssadmdm)
DRV - [2011/06/02 08:47:22 | 000,121,064 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadbus.sys -- (ssadbus) SAMSUNG Android USB Composite Device driver (WDM)
DRV - [2011/06/02 08:47:22 | 000,114,280 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadserd.sys -- (ssadserd) SAMSUNG Android USB Diagnostic Serial Port (WDM)
DRV - [2011/06/02 08:47:22 | 000,012,776 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadmdfl.sys -- (ssadmdfl) SAMSUNG Android USB Modem (Filter)
DRV - [2011/05/25 09:09:05 | 010,589,800 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2010/12/21 08:55:02 | 000,132,424 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdm.sys -- (sscdmdm)
DRV - [2010/12/21 08:55:02 | 000,104,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdbus.sys -- (sscdbus) SAMSUNG USB Composite Device driver (WDM)
DRV - [2010/12/21 08:55:02 | 000,030,312 | ---- | M] (Google Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssadadb.sys -- (androidusb)
DRV - [2010/12/21 08:55:02 | 000,014,920 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\sscdmdfl.sys -- (sscdmdfl)
DRV - [2010/12/20 09:42:04 | 000,036,640 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2010/11/20 05:30:16 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 05:30:16 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 05:30:16 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 03:24:42 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 03:21:16 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 02:59:46 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 02:14:46 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 02:14:42 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/11/10 06:57:48 | 000,506,752 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AVerFx2hbtv.sys -- (AVerFx2hbtv)
DRV - [2010/07/09 13:18:56 | 000,020,328 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Program Files\CPUID\PC Wizard 2010\pcwiz_x32.sys -- (cpuz134)
DRV - [2010/03/31 03:13:28 | 000,379,904 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL8187B.sys -- (RTL8187B)
DRV - [2010/03/26 02:36:41 | 000,841,504 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\netr28u.sys -- (netr28u)
DRV - [2010/01/20 12:03:40 | 000,022,528 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\intelsmb.sys -- (smbusp) Intel(R)
DRV - [2009/12/18 12:58:52 | 000,011,336 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\SystemRequirementsLab\cpudrv.sys -- (cpudrv)
DRV - [2009/11/13 22:29:35 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2009/10/20 21:19:44 | 000,050,704 | ---- | M] (CACE Technologies, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\npf.sys -- (NPF)
DRV - [2009/08/28 13:33:12 | 000,840,576 | ---- | M] (VIMICRO) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VC025x.sys -- (VC025x)
DRV - [2009/08/13 09:23:02 | 000,022,528 | ---- | M] (CSR, plc) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BthAvrcp.sys -- (BthAvrcp)
DRV - [2009/07/14 02:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/07/14 01:02:53 | 000,044,032 | ---- | M] (VIA Technologies, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\fetnd6.sys -- (FETNDIS)
DRV - [2009/07/14 01:02:52 | 000,214,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\e1y6032.sys -- (e1yexpress) Intel(R)
DRV - [2009/05/14 04:30:58 | 000,019,584 | ---- | M] (AVerMedia TECHNOLOGIES, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\AVerEth.sys -- (AVerEth)
DRV - [2009/03/12 06:46:28 | 000,017,024 | ---- | M] (Vimicro) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VC025xHID.sys -- (VC025xHID)
DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/07/23 19:29:18 | 000,047,744 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vserial.sys -- (vserial)
DRV - [2008/07/23 19:29:18 | 000,015,264 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vsb.sys -- (vsbus)
DRV - [2008/06/27 04:40:18 | 000,335,872 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\RTL8187.sys -- (RTL8187)
DRV - [2008/04/24 12:42:46 | 000,054,272 | ---- | M] (DAVICOM Semiconductor, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dm9usb.sys -- (DM9USB)
DRV - [2007/03/20 16:59:00 | 000,049,664 | ---- | M] (Winbond Electronics Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\wbondir.sys -- (wbondir)
DRV - [2006/08/29 17:56:20 | 000,032,377 | ---- | M] (B-phreaks) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\prodigy.sys -- (PRODIGY)
DRV - [2006/01/10 05:47:27 | 000,031,846 | ---- | M] () [Kernel | System | Running] -- C:\Windows\System32\Ckldrv.sys -- (NetworkX)
DRV - [2005/09/23 23:18:32 | 000,171,520 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\MarvinBus.sys -- (MarvinBus)
DRV - [2004/03/19 18:11:22 | 000,090,968 | ---- | M] (VM) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbVM31b.sys -- (ZSMC301b)
DRV - [2004/01/23 12:33:36 | 000,116,509 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emDevice.sys -- (DCamUSBEMPIA)
DRV - [2004/01/23 12:33:24 | 000,004,525 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emScan.sys -- (ScanUSBEMPIA)
DRV - [2004/01/22 21:44:06 | 000,020,352 | ---- | M] (eMPIA Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\emFilter.sys -- (FiltUSBEMPIA)
DRV - [2001/06/17 22:47:00 | 000,021,237 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\UX2000.sys -- (TELEMANN)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...putEncoding}&oe={outputEncoding}&sourceid=ie7


IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 24 D7 53 00 AF 42 B1 47 A7 DC 76 9B 84 BC B4 0C [binary data]

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 24 D7 53 00 AF 42 B1 47 A7 DC 76 9B 84 BC B4 0C [binary data]

IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 31 11 7B F2 C9 5F CA 01 [binary data]
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 24 D7 53 00 AF 42 B1 47 A7 DC 76 9B 84 BC B4 0C [binary data]
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://tbsearch.ask.com/redirect?client=ie&tb=UT2V5&o=&src=crm&q={searchTerms}&locale=
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes\{2D636E9E-0D80-4C34-AD1D-3250150B232A}: "URL" = http://search.imgag.com/?appid=kwap...AD1D-3250150B232A}&component=&q={searchTerms}
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes\{395CBC4A-AAED-41F4-BEC8-75A43B2BB06F}: "URL" = http://www.youtube.com/results?search_query={searchTerms}&page={startPage?}&utm_source=opensearch
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sea...={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_en
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========



FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_33: C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=15.0.4.53: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Bisho\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Bisho\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Bisho\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Bisho\AppData\Local\Facebook\Messenger\2.1.4554.0\npFbDesktopPlugin.dll (Facebook, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\web2pdfextension@web2pdf.adobedotcom: C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2011/03/31 11:20:19 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fiddlerhook@fiddler2.com: C:\Program Files\Fiddler2\FiddlerHook [2012/04/22 01:51:06 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/02/24 21:34:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/17 04:29:49 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/06/18 03:18:23 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_9.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/03/29 21:48:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Bisho\AppData\Roaming\IDM\idmmzcc5 [2012/06/18 01:45:15 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\mozilla_cc@internetdownloadmanager.com: C:\Users\Bisho\AppData\Roaming\IDM\idmmzcc5 [2012/06/18 01:45:15 | 000,000,000 | ---D | M]

[2011/12/19 10:17:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Extensions
[2010/10/29 03:35:43 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Extensions\IMVUClientXUL@imvu.com
[2009/11/11 20:42:21 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Extensions\mozswing@mozswing.org
[2012/06/30 15:28:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions
[2012/02/07 04:38:41 | 000,000,000 | ---D | M] (Domain Details) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{152455DE-7B40-4bcf-B5B4-C68A1BE85A91}
[2012/05/19 13:31:18 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/16 04:43:49 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2012/06/09 03:25:55 | 000,000,000 | ---D | M] (ClixSense.com) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{70df8d13-bdd3-448e-944c-efde21b77161}
[2012/05/21 18:41:41 | 000,000,000 | ---D | M] (GamesSMS Download Community Toolbar) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{a3c5d329-a2b9-474b-bf10-d4d9535d3b26}
[2012/04/22 12:56:14 | 000,000,000 | ---D | M] (Cookies Manager+) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2012/05/21 18:41:42 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/12/20 09:33:59 | 000,000,000 | ---D | M] ("KGen") -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\kgen@elitwork.com
[2012/06/08 04:59:38 | 000,000,000 | ---D | M] (IDM CC) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\mozilla_cc@internetdownloadmanager.com
[2012/06/30 15:28:32 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\staged
[2012/03/18 10:42:18 | 000,000,000 | ---D | M] (Echofon) -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\extensions\twitternotifier@naan.net
[2012/06/27 03:16:58 | 000,001,018 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\searchplugins\facebook.xml
[2008/06/25 00:48:38 | 000,000,908 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\searchplugins\imdb.xml
[2011/06/27 04:18:58 | 000,001,170 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\searchplugins\subscene.xml
[2007/10/26 19:22:36 | 000,002,109 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Mozilla\Firefox\Profiles\ae6j2iby.default\searchplugins\youtube-video-search.xml
[2012/06/18 03:19:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2012/06/18 03:19:41 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/04/22 01:51:06 | 000,000,000 | ---D | M] (FiddlerHook) -- C:\PROGRAM FILES\FIDDLER2\FIDDLERHOOK
[2012/06/01 13:21:23 | 000,505,801 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{1280606B-2510-4FE0-97EF-9B5A22EAFE30}.XPI
[2012/03/14 05:28:46 | 000,009,524 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{3E9A3920-1B27-11DA-8CD6-0800200C9A66}.XPI
[2012/03/03 00:02:29 | 000,033,619 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{578E7CAA-210F-4967-A0D3-88FE5B59A39F}.XPI
[2011/12/20 09:46:45 | 000,372,140 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{5C46D283-ABDE-4DCE-B83C-08881401921C}.XPI
[2012/06/07 01:06:10 | 000,030,312 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{888D99E7-E8B5-46A3-851E-1EC45DA1E644}.XPI
[2012/04/21 04:21:38 | 000,080,872 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{9C51BD27-6ED8-4000-A2BF-36CB95C0C947}.XPI
[2012/04/20 16:32:38 | 000,377,615 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{AE93811A-5C9A-4D34-8462-F7B864FC4696}.XPI
[2012/06/09 22:54:59 | 000,068,257 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\{D57C9FF1-6389-48FC-B770-F78BD89B6E8A}.XPI
[2012/02/26 01:29:26 | 000,001,647 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\SAMPLESTAT@LIVEINTERNET.RU.XPI
[2012/01/11 20:35:14 | 000,074,993 | ---- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\SEO-BLOGGER@WORDTRACKER.COM.XPI
[2012/03/09 01:33:10 | 000,024,227 | R--- | M] () (No name found) -- C:\USERS\BISHO\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\AE6J2IBY.DEFAULT\EXTENSIONS\SM@SUBMITTER.NET.XPI
[2012/06/17 04:29:49 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2009/07/31 14:06:48 | 001,654,784 | ---- | M] (LizardTech) -- C:\Program Files\mozilla firefox\plugins\npdjvu.dll
[2011/10/25 19:55:54 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\mozilla firefox\plugins\npwachk.dll
[2011/07/29 16:33:40 | 000,108,480 | ---- | M] ( ) -- C:\Program Files\mozilla firefox\plugins\npwangwang.dll
[2012/04/21 04:18:25 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/04/21 04:18:25 | 000,002,040 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
 
========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = http://www.google.com/search?q={searchTerms}
CHR - default_search_provider: suggest_url = ,
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Bisho\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Bisho\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Bisho\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Windows\system32\Macromed\Flash\NPSWF32_11_3_300_262.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: LizardTech DjVu (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npdjvu.dll
CHR - plugin: Winamp Application Detector (Disabled) = C:\Program Files\Mozilla Firefox\plugins\npwachk.dll
CHR - plugin: AliWangWang Plug-In For Firefox and Netscape (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npwangwang.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL
CHR - plugin: RIM Handheld Application Loader (Disabled) = C:\Program Files\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: DivX VOD Helper Plug-in (Disabled) = C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Plus Web Player (Disabled) = C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Java(TM) Platform SE 6 U33 (Enabled) = C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.330.3 (Enabled) = C:\Windows\system32\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Disabled) = C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
CHR - plugin: RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\Bisho\AppData\Local\Facebook\Messenger\2.1.4554.0\npFbDesktopPlugin.dll
CHR - plugin: Facebook Video Calling Plugin (Enabled) = C:\Users\Bisho\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll
CHR - Extension: Google Translate = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb\1.2.3.1_0\
CHR - Extension: Fancy Gaming Simplifier = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahcaniaehcjkignnobkmdgacafghkplh\2.0.0.1_0\
CHR - Extension: Frank Smith = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\bjgpmafbkgcchdjehdpnfgfgbdfahapa\1.8_0\
CHR - Extension: FlashBlock = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdngiadmnkhgemkimkhiilgffbjijcie\1.2.11.12_0\
CHR - Extension: Tampermonkey = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo\2.5.24_0\
CHR - Extension: Pixlr-o-matic = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj\1.2_0\
CHR - Extension: Classic = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkacjpbfdknhflllbcmjibkdeoafencn\1.1_0\
CHR - Extension: bitly | \u2665 your bitmarks = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabeihobmhlgpkcgjiloemdbofjbdcic\2.0.15_0\
CHR - Extension: Picnik = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\inmnggcpelemfookhlhkdfbechcdadfp\1.0.6_0\
CHR - Extension: Grammar and Spell Checker by Ginger = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdfieneakcjfaiglcfcgkidlkmlijjnh\0.1.0.19_0\
CHR - Extension: Webcam Toy = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade\1.2.2_0\
CHR - Extension: Google Dictionary (by Google) = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.12_0\
CHR - Extension: Google Mail Checker = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\3.2_0\
CHR - Extension: Google I/O: input/output = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbmphclbekipaojhpbkbofoioffecilh\1.3.3.7_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: ClixSense.com = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\odiaflgoglmdpognebeehehkabaclnpb\2.3.4.920_0\
CHR - Extension: Picky Wallpapers = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\odklcfojpedohplkimfdpcamkjnhanaj\1.0.0_0\
CHR - Extension: Google Publisher Toolbar (by Google) = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\omioeahgfecgfpfldejlnideemfidnkc\3.3.2_0\
CHR - Extension: Psykopaint = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\
CHR - Extension: Psykopaint = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil\0.0.0.10_0\.bak
CHR - Extension: Weather Underground = C:\Users\Bisho\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjejbgheonogbpfkkjigbmahaljipoej\1.6_0\

O1 HOSTS File: ([2012/06/11 02:42:34 | 000,000,861 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (FlashFXP Helper for Internet Explorer) - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program Files\FlashFXP\IEFlash.dll (IniCom Networks, Inc.)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.)
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PlusService] C:\Program Files\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [USBToolTip] C:\Program Files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe (Pinnacle Systems GmbH)
O4 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001..\Run: [] File not found
O4 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001..\Run: [KiesPDLR] C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe ()
O4 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1009..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - Startup: C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 95
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AlwaysShowClassicMenu = 1
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O7 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1009\Software\Policies\Microsoft\Internet Explorer\InfoDelivery present
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Se&nd to OneNote - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra Button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll (Microsoft Corporation)
O9 - Extra Button: Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O9 - Extra 'Tools' menuitem : Fiddler2 - {CF819DA3-9882-4944-ADF5-6EF17ECF3C6E} - C:\Program Files\Fiddler2\Fiddler.exe (Eric Lawrence)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000030 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000031 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000032 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000033 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000034 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000035 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000036 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000037 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000038 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000039 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000040 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000041 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000042 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000043 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000044 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000045 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000046 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000047 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000048 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000049 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000050 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000051 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000052 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000053 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000054 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000055 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000056 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000057 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000058 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000059 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000060 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000061 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000062 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000063 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000064 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000065 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000066 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000067 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000068 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000069 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000070 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000071 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000072 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000073 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000074 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000075 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000076 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000077 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000078 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000079 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000080 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000081 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000082 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000083 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000084 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000085 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000086 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000087 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000088 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000089 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000090 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000091 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000092 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000093 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000094 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000095 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000096 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000097 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000098 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000099 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000100 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000101 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000102 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000103 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000104 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000105 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000106 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000107 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000108 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000109 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000110 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000111 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000112 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000113 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000114 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000115 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000116 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000117 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000118 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000119 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000120 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000121 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000122 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000123 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000124 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000125 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000126 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000127 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000128 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000129 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000130 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000131 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000132 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000133 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000134 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000135 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000136 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000137 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000138 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000139 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000140 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000141 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000142 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000143 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000144 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000145 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000146 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000147 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000148 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000149 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000150 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000151 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000152 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000153 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000154 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000155 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000156 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000157 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000158 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000159 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000160 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000161 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000162 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000163 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000164 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000165 - C:\Program Files\Bonjour\mdnsNSP.dll File not found
O13 - gopher Prefix: missing
O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: alipay.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: alisoft.com ([]https in Trusted sites)
O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: taobao.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_33-windows-i586.cab (Java Plug-in 1.6.0_33)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1072D39E-F0B4-4166-A31A-0753987B9A88}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{305690D4-D367-4AD2-B2D1-38D02245D807}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{BF31799D-85D9-4DFB-BABB-CC064915E874}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F593D914-2561-475E-9072-0EBD68F57C6A}: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/11 00:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\Shell - "" = AutoRun
O33 - MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\Shell\AutoRun\command - "" = G:\Startme.exe
O33 - MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\Shell\AutoRun\command - "" = notepad SeaToolsDOSguide.EN.txt
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codec - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\System32\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.voxacm160 - C:\Windows\System32\vct3216.acm (Voxware, Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.I420 - C:\Windows\System32\emYUV.dll (Microsoft Corporation)
Drivers32: vidc.pDAD - C:\Windows\System32\prodad-codec.dll (proDAD GmbH)
Drivers32: vidc.tscc - C:\Windows\System32\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/06/30 16:01:50 | 000,000,000 | ---D | C] -- D:\My data\Desktop\Desktop\OTL
[2012/06/28 23:44:59 | 000,000,000 | ---D | C] -- C:\2012-06-28_0002
[2012/06/28 23:43:18 | 000,000,000 | ---D | C] -- C:\2012-06-28_0001
[2012/06/28 23:42:05 | 000,000,000 | ---D | C] -- C:\2012-06-28
[2012/06/28 23:41:04 | 000,000,000 | R--D | C] -- C:\Users\Bisho\Pictures
[2012/06/28 16:29:45 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\ImgBurn
[2012/06/28 16:27:35 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImgBurn
[2012/06/28 16:27:30 | 000,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2012/06/28 00:55:33 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{B67049F4-F022-4935-B1F7-287CC201D3A5}
[2012/06/28 00:55:18 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{F2FCE2C8-0D3B-40BC-AD83-ACC01E82BD54}
[2012/06/27 15:42:10 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
[2012/06/27 13:33:22 | 000,000,000 | ---D | C] -- D:\My data\Desktop\Desktop\tdsskiller
[2012/06/27 13:01:04 | 000,000,000 | ---D | C] -- C:\FRST
[2012/06/27 06:06:24 | 000,000,000 | ---D | C] -- D:\My data\Desktop\Desktop\bootkit_remover
[2012/06/27 06:06:04 | 004,731,392 | ---- | C] (AVAST Software) -- D:\My data\Desktop\Desktop\aswMBR.exe
[2012/06/27 04:51:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/06/27 04:51:46 | 000,022,344 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/06/27 04:51:45 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/06/27 03:27:55 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/06/27 03:27:51 | 000,000,000 | --SD | C] -- C:\32788R22FWJFW
[2012/06/23 18:04:11 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/06/23 02:16:08 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/06/23 01:35:36 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{C43C6127-A7FF-45DC-A5AE-0FF1BFF90976}
[2012/06/23 01:35:25 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{065076BA-575E-4538-B26B-EDECC5D72429}
[2012/06/23 00:52:28 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{4DE7BF4B-7E01-4E27-9BB4-88A3753B2917}
[2012/06/21 23:37:27 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{0678E3D3-422B-40FA-986B-D29BC6A60A2F}
[2012/06/21 23:37:13 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{5E801A8A-F905-4E80-AB1F-9EE013BB71F4}
[2012/06/21 14:26:32 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Media Player Classic
[2012/06/21 04:29:18 | 000,000,000 | ---D | C] -- C:\Windows\System32\Macromed
[2012/06/21 04:29:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
[2012/06/20 14:01:31 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{FDA19AB1-6BD7-4221-81C2-123F701A2044}
[2012/06/20 14:01:16 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{1339E2F0-0898-4A1A-90EE-45E65370B9E3}
[2012/06/20 01:55:34 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{E62E5AD8-E86A-4DF4-A627-C8FE355EF0CB}
[2012/06/20 01:55:21 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{0625B66D-F1EC-49A0-914F-5BB78979A3D5}
[2012/06/18 06:49:39 | 000,000,000 | ---D | C] -- C:\Samsung Galaxy S3 ToolKit
[2012/06/18 02:37:52 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{6CAF425C-BE6E-45BE-ABE5-796DE1228AF4}
[2012/06/18 01:45:12 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2012/06/18 01:45:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2012/06/18 01:12:03 | 000,181,432 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudmdm.sys
[2012/06/18 01:12:03 | 000,080,824 | ---- | C] (DEVGURU Co., LTD.(www.devguru.co.kr)) -- C:\Windows\System32\drivers\ssudbus.sys
[2012/06/17 14:37:24 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{F6ACF6FD-B54D-442F-B19E-9D57CADC5CF6}
[2012/06/17 02:36:50 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{35660FCA-8C88-44DF-A376-E218614A3AB7}
[2012/06/16 14:36:22 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{775D1AE3-A936-4C11-A317-DBD7222DFE25}
[2012/06/16 00:53:28 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{AEE7D9F0-F4AC-444E-99AD-96B3911A0B0D}
[2012/06/15 04:59:06 | 000,000,000 | ---D | C] -- C:\Windows\System32\1056
[2012/06/15 00:15:15 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{1CBD6B84-781C-40FD-86ED-EA3CFDBF2ECA}
[2012/06/15 00:15:04 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{8B10F81E-B4C4-48C5-B4AA-B72DF1D31F11}
[2012/06/13 14:31:17 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{12C5CCCC-A0FF-4044-B9D6-D445AD0EAB66}
[2012/06/13 14:31:05 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{88D1BAAD-19F1-4664-AA15-735C170FC220}
[2012/06/12 22:20:46 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{0DC74891-02F3-44B1-B87B-BF0C0EE2693B}
[2012/06/12 22:20:34 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{398D6AA7-82B4-4126-A37E-9D1C18D1187A}
[2012/06/12 03:24:55 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{EE84F72B-1959-4BD3-ADF2-7B901B90EA72}
[2012/06/12 03:24:37 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{20003CBF-1B19-44B6-B73C-0CDD87A7A9D5}
[2012/06/12 02:22:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/12 02:21:12 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/06/12 02:21:11 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/06/12 02:19:29 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2012/06/11 03:48:52 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\IObit
[2012/06/11 03:48:46 | 000,000,000 | ---D | C] -- C:\Program Files\IObit
[2012/06/11 03:18:12 | 000,000,000 | ---D | C] -- F:\Documents\JoWooD
[2012/06/11 02:45:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
[2012/06/11 02:32:10 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\Macromedia
[2012/06/09 22:58:31 | 000,000,000 | ---D | C] -- C:\Program Files\fr3nsis
[2012/06/09 03:26:33 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\CRE
[2012/06/09 03:25:24 | 000,000,000 | ---D | C] -- C:\Program Files\Conduit
[2012/06/09 03:25:23 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\Conduit
[2012/06/08 22:03:38 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{C2756249-6B3F-421F-98CB-E510DA8713B8}
[2012/06/08 22:03:26 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{EF5A350C-4A79-4A6F-8A99-DCED60A1AFBC}
[2012/06/07 14:54:29 | 000,000,000 | ---D | C] -- D:\My data\Desktop\Desktop\bio keratine
[2012/06/07 09:18:01 | 000,096,056 | ---- | C] (Tonec Inc.) -- C:\Windows\System32\drivers\idmwfp.sys
[2012/06/06 19:22:21 | 000,000,000 | ---D | C] -- D:\My data\Desktop\Desktop\RM-530
[2012/06/06 19:10:19 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{9C1F7C7A-8EDA-48F1-8B36-268C28A208CC}
[2012/06/06 19:10:07 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{4576DBA7-2953-4F36-9FC2-DFD7A164E2AF}
[2012/06/05 21:33:39 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{6A82BB6B-F73A-494E-B2DE-020E2480A8AF}
[2012/06/05 21:33:25 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{C6060028-C0DD-4AED-A7F7-E64E27C02FB0}
[2012/06/05 03:40:28 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2012/06/05 03:18:16 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/06/04 23:15:16 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Roaming\Yahoo!
[2012/06/04 16:21:52 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{EB2BBEFF-FEE9-47F4-818D-5B97F3B913CD}
[2012/06/04 16:21:29 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{768CBF18-F3F5-414A-9AF7-53C7D1461177}
[2012/06/03 14:39:24 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{85C3E1BE-CBC7-46ED-BB1B-2ED2B096103E}
[2012/06/03 14:39:08 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{D0305CEA-6719-4196-9878-625C4EC26E73}
[2012/06/03 02:42:23 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\ESET
[2012/06/02 20:07:09 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{06C2CC86-8AF0-4D41-B9A3-A68BE6B4B49E}
[2012/06/02 20:06:52 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\{FB24A4E1-8D9A-424C-A4F5-1482718872A7}
[2012/06/01 02:59:07 | 000,000,000 | ---D | C] -- C:\Program Files\ESET
[2012/06/01 02:34:23 | 000,000,000 | ---D | C] -- C:\Users\Bisho\AppData\Local\http___www.julien-manici
[2011/12/16 06:51:16 | 000,047,360 | ---- | C] (VSO Software) -- C:\Users\Bisho\AppData\Roaming\pcouffin.sys
[1 F:\Documents\*.tmp files -> F:\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Bisho\AppData\Roaming\*.tmp files -> C:\Users\Bisho\AppData\Roaming\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

File not found -- D:\My data\Desktop\Desktop\SL CHI
[2012/06/30 15:44:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/30 15:29:02 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001UA.job
[2012/06/30 15:23:10 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001UA.job
[2012/06/30 15:22:04 | 000,000,216 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2012/06/30 15:22:02 | 000,000,218 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
[2012/06/30 15:21:50 | 000,151,552 | ---- | M] () -- C:\Windows\KMSEmulator.exe
[2012/06/30 15:21:50 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/30 15:21:13 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/06/30 04:05:49 | 000,028,864 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 04:05:48 | 000,028,864 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/06/30 03:43:59 | 000,072,609 | ---- | M] () -- D:\My data\Desktop\Desktop\528917_10150936399051633_426304155_n.jpg
[2012/06/30 03:25:27 | 003,609,078 | ---- | M] () -- D:\My data\Desktop\Desktop\دمع العين حنين كرم 2012.mp3
[2012/06/30 00:41:04 | 000,012,266 | ---- | M] () -- D:\My data\Desktop\Desktop\2.jpg
[2012/06/30 00:37:40 | 000,013,653 | ---- | M] () -- D:\My data\Desktop\Desktop\1.jpg
[2012/06/29 16:28:40 | 000,222,731 | ---- | M] () -- D:\My data\Desktop\Desktop\20120629_144937.jpg
[2012/06/29 16:28:17 | 000,251,468 | ---- | M] () -- D:\My data\Desktop\Desktop\20120629_144143.jpg
[2012/06/29 16:27:44 | 003,210,532 | ---- | M] () -- D:\My data\Desktop\Desktop\Sm3na_com_26487.mp3
[2012/06/29 14:49:23 | 002,011,276 | ---- | M] () -- D:\My data\Desktop\Desktop\20120629_144900_5_bestshot.jpg
[2012/06/28 23:42:33 | 011,923,854 | ---- | M] () -- D:\My data\Desktop\Desktop\IMG25.bmp
[2012/06/28 23:41:33 | 001,074,460 | ---- | M] () -- D:\My data\Desktop\Desktop\Untitled-1.jpg
[2012/06/28 23:25:43 | 011,923,854 | ---- | M] () -- D:\My data\Desktop\Desktop\IMG.bmp
[2012/06/28 23:23:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001Core.job
[2012/06/28 19:20:53 | 001,631,456 | ---- | M] () -- D:\My data\Desktop\Desktop\20120628_192053.jpg
[2012/06/28 16:27:35 | 000,001,689 | ---- | M] () -- D:\My data\Desktop\Desktop\ImgBurn.lnk
[2012/06/28 02:08:56 | 007,313,194 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2012/06/28 02:08:56 | 003,036,512 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2012/06/28 02:08:56 | 003,008,486 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/06/28 02:08:56 | 002,409,960 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2012/06/28 02:08:56 | 002,375,562 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2012/06/28 02:08:56 | 002,367,812 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/06/28 01:04:35 | 004,632,298 | ---- | M] () -- D:\My data\Desktop\Desktop\IMG_0002 (2).jpg
[2012/06/27 23:28:42 | 000,387,826 | ---- | M] () -- C:\0627232842Analog TV.jpg
[2012/06/27 16:18:57 | 000,128,271 | ---- | M] () -- D:\My data\Desktop\Desktop\487208_395088223871886_344600766_n.jpg
[2012/06/27 13:32:31 | 002,109,990 | ---- | M] () -- D:\My data\Desktop\Desktop\tdsskiller.zip
[2012/06/27 06:06:05 | 004,731,392 | ---- | M] (AVAST Software) -- D:\My data\Desktop\Desktop\aswMBR.exe
[2012/06/27 06:04:45 | 000,044,607 | ---- | M] () -- D:\My data\Desktop\Desktop\bootkit_remover.zip
[2012/06/27 04:51:52 | 000,001,031 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/27 03:41:09 | 002,393,690 | ---- | M] () -- D:\My data\Desktop\Desktop\20120627_034109.jpg
[2012/06/26 01:00:43 | 000,003,400 | ---- | M] () -- C:\bootsqm.dat
[2012/06/23 02:17:14 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2012/06/23 01:16:52 | 001,135,188 | ---- | M] () -- D:\My data\Desktop\Desktop\ProcessExplorer.zip
[2012/06/21 03:08:30 | 000,031,970 | ---- | M] () -- D:\My data\Desktop\Desktop\337641.zip
[2012/06/20 12:29:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001Core.job
[2012/06/18 06:49:46 | 000,001,510 | ---- | M] () -- D:\My data\Desktop\Desktop\Samsung GS3 ToolKit v1.0.lnk
[2012/06/18 06:18:03 | 000,000,360 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Network Meter_Settings.ini
[2012/06/17 04:12:14 | 000,001,226 | ---- | M] () -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
[2012/06/16 02:35:10 | 000,000,657 | ---- | M] () -- C:\Windows\wafi2000.ini
[2012/06/16 01:59:51 | 000,001,555 | ---- | M] () -- C:\Windows\ata live update.ini
[2012/06/12 02:48:14 | 000,998,188 | -H-- | M] () -- C:\Windows\System32\mlfcache.dat
[2012/06/12 02:22:28 | 000,001,713 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/11 14:54:42 | 005,169,576 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/06/11 02:42:34 | 000,000,861 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2012/06/10 03:26:07 | 000,014,391 | ---- | M] () -- D:\My data\Desktop\Desktop\Blogger-And-Wordpress.jpg
[2012/06/10 03:03:26 | 000,021,885 | ---- | M] () -- D:\My data\Desktop\Desktop\400491697628332296.jpg
[2012/06/10 02:59:20 | 000,005,042 | ---- | M] () -- D:\My data\Desktop\Desktop\400491697628332296.png
[2012/06/09 20:21:56 | 000,178,688 | ---- | M] () -- C:\Windows\System32\unrar.dll
[2012/06/09 04:26:06 | 000,110,453 | ---- | M] () -- F:\Documents\webcam-toy-photo1.jpg
[2012/06/09 00:02:22 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2012/06/08 16:29:05 | 031,708,487 | ---- | M] () -- D:\My data\Desktop\Desktop\max payne 3 update.rar
[2012/06/07 01:05:42 | 000,002,048 | ---- | M] () -- C:\Uninstall.dat
[2012/06/05 03:34:33 | 000,000,000 | ---- | M] () -- C:\Windows\System32\drivers\etc\hosts.old
[2012/06/05 03:18:17 | 000,002,777 | ---- | M] () -- D:\My data\Desktop\Desktop\HiJackThis.lnk
[2012/06/05 02:58:41 | 000,000,233 | ---- | M] () -- C:\Users\Bisho\SecurityKISSTunnel.config
[2012/06/04 01:56:56 | 001,010,148 | ---- | M] () -- D:\My data\Desktop\Desktop\iphonecarrierchecker_1.3.zip
[2012/06/03 14:36:23 | 000,000,418 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2012/06/01 19:31:40 | 000,000,419 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2012/06/01 02:33:56 | 000,795,217 | ---- | M] () -- D:\My data\Desktop\Desktop\Win7LogonBackgroundChanger_1_5_2.zip
[2012/05/31 16:16:20 | 001,132,032 | ---- | M] () -- D:\My data\Desktop\Desktop\IphoneCarrierChecker.exe
[1 F:\Documents\*.tmp files -> F:\Documents\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Bisho\AppData\Roaming\*.tmp files -> C:\Users\Bisho\AppData\Roaming\*.tmp -> ]

========== Files Created - No Company Name ==========

File not found -- D:\My data\Desktop\Desktop\SL CHI
[2012/06/30 03:44:04 | 000,072,609 | ---- | C] () -- D:\My data\Desktop\Desktop\528917_10150936399051633_426304155_n.jpg
[2012/06/30 03:25:27 | 003,609,078 | ---- | C] () -- D:\My data\Desktop\Desktop\دمع العين حنين كرم 2012.mp3
[2012/06/30 00:40:08 | 000,012,266 | ---- | C] () -- D:\My data\Desktop\Desktop\2.jpg
[2012/06/30 00:36:51 | 000,013,653 | ---- | C] () -- D:\My data\Desktop\Desktop\1.jpg
[2012/06/29 16:27:44 | 003,210,532 | ---- | C] () -- D:\My data\Desktop\Desktop\Sm3na_com_26487.mp3
[2012/06/29 16:27:40 | 001,631,456 | ---- | C] () -- D:\My data\Desktop\Desktop\20120628_192053.jpg
[2012/06/29 16:27:40 | 000,222,731 | ---- | C] () -- D:\My data\Desktop\Desktop\20120629_144937.jpg
[2012/06/29 16:27:39 | 002,011,276 | ---- | C] () -- D:\My data\Desktop\Desktop\20120629_144900_5_bestshot.jpg
[2012/06/29 16:27:39 | 000,251,468 | ---- | C] () -- D:\My data\Desktop\Desktop\20120629_144143.jpg
[2012/06/28 23:52:36 | 011,923,854 | ---- | C] () -- D:\My data\Desktop\Desktop\IMG25.bmp
[2012/06/28 23:40:36 | 001,074,460 | ---- | C] () -- D:\My data\Desktop\Desktop\Untitled-1.jpg
[2012/06/28 23:25:43 | 011,923,854 | ---- | C] () -- D:\My data\Desktop\Desktop\IMG.bmp
[2012/06/28 16:27:35 | 000,001,805 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
[2012/06/28 16:27:35 | 000,001,689 | ---- | C] () -- D:\My data\Desktop\Desktop\ImgBurn.lnk
[2012/06/28 02:06:40 | 004,632,298 | ---- | C] () -- D:\My data\Desktop\Desktop\IMG_0002 (2).jpg
[2012/06/27 23:28:42 | 000,387,826 | ---- | C] () -- C:\0627232842Analog TV.jpg
[2012/06/27 16:19:00 | 000,128,271 | ---- | C] () -- D:\My data\Desktop\Desktop\487208_395088223871886_344600766_n.jpg
[2012/06/27 13:32:31 | 002,109,990 | ---- | C] () -- D:\My data\Desktop\Desktop\tdsskiller.zip
[2012/06/27 06:04:45 | 000,044,607 | ---- | C] () -- D:\My data\Desktop\Desktop\bootkit_remover.zip
[2012/06/27 04:51:52 | 000,001,031 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/06/27 03:47:44 | 002,393,690 | ---- | C] () -- D:\My data\Desktop\Desktop\20120627_034109.jpg
[2012/06/26 01:00:43 | 000,003,400 | ---- | C] () -- C:\bootsqm.dat
[2012/06/23 02:17:14 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2012/06/23 02:16:22 | 000,001,917 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials Prerelease.lnk
[2012/06/23 01:16:22 | 001,135,188 | ---- | C] () -- D:\My data\Desktop\Desktop\ProcessExplorer.zip
[2012/06/21 03:08:30 | 000,031,970 | ---- | C] () -- D:\My data\Desktop\Desktop\337641.zip
[2012/06/18 06:49:45 | 000,001,510 | ---- | C] () -- D:\My data\Desktop\Desktop\Samsung GS3 ToolKit v1.0.lnk
[2012/06/12 02:22:28 | 000,001,713 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/06/11 03:58:10 | 000,000,216 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job
[2012/06/11 03:58:09 | 000,000,218 | ---- | C] () -- C:\Windows\tasks\AutoKMSDaily.job
[2012/06/11 03:57:29 | 000,151,552 | ---- | C] () -- C:\Windows\KMSEmulator.exe
[2012/06/11 02:42:00 | 000,000,927 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012/06/10 03:26:09 | 000,014,391 | ---- | C] () -- D:\My data\Desktop\Desktop\Blogger-And-Wordpress.jpg
[2012/06/10 03:03:26 | 000,021,885 | ---- | C] () -- D:\My data\Desktop\Desktop\400491697628332296.jpg
[2012/06/10 02:59:22 | 000,005,042 | ---- | C] () -- D:\My data\Desktop\Desktop\400491697628332296.png
[2012/06/09 04:26:06 | 000,110,453 | ---- | C] () -- F:\Documents\webcam-toy-photo1.jpg
[2012/06/08 16:28:25 | 031,708,487 | ---- | C] () -- D:\My data\Desktop\Desktop\max payne 3 update.rar
[2012/06/07 01:05:32 | 000,002,048 | ---- | C] () -- C:\Uninstall.dat
[2012/06/05 03:18:17 | 000,002,777 | ---- | C] () -- D:\My data\Desktop\Desktop\HiJackThis.lnk
[2012/06/04 02:35:31 | 001,132,032 | ---- | C] () -- D:\My data\Desktop\Desktop\IphoneCarrierChecker.exe
[2012/06/04 01:56:51 | 001,010,148 | ---- | C] () -- D:\My data\Desktop\Desktop\iphonecarrierchecker_1.3.zip
[2012/06/01 02:33:55 | 000,795,217 | ---- | C] () -- D:\My data\Desktop\Desktop\Win7LogonBackgroundChanger_1_5_2.zip
[2012/05/07 03:20:47 | 000,000,218 | ---- | C] () -- C:\Users\Bisho\.recently-used.xbel
[2012/04/22 14:33:24 | 000,000,233 | ---- | C] () -- C:\Users\Bisho\SecurityKISSTunnel.config
[2012/04/20 07:54:38 | 002,484,592 | ---- | C] () -- C:\Windows\System32\pbsvc_p4f.exe
[2012/04/20 07:35:54 | 000,138,056 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2012/04/20 07:35:27 | 000,189,248 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2012/04/17 01:18:58 | 000,000,040 | ---- | C] () -- C:\Users\Bisho\jagex_cl_runescape_LIVE.dat
[2012/04/16 04:40:09 | 000,000,211 | ---- | C] () -- C:\Users\Bisho\.swfinfo
[2012/03/28 22:11:08 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/03/12 06:25:48 | 000,974,848 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\chrtmp
[2012/03/12 06:25:11 | 000,522,598 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\Patch.zip
[2012/02/15 12:06:51 | 000,000,132 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2012/02/15 07:16:02 | 000,000,033 | ---- | C] () -- C:\Users\Bisho\.gtkrc-2.0
[2012/02/12 21:20:04 | 000,000,600 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\winscp.rnd
[2012/02/08 04:57:44 | 000,005,023 | ---- | C] () -- C:\ProgramData\mxnhytee.feu
[2011/12/16 06:51:16 | 000,087,608 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\inst.exe
[2011/12/16 06:51:16 | 000,007,887 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\pcouffin.cat
[2011/12/16 06:51:16 | 000,001,144 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\pcouffin.inf
[2011/11/10 20:50:15 | 005,169,576 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/08/20 22:57:38 | 000,000,010 | ---- | C] () -- C:\Windows\popcinfo.dat
[2011/08/05 04:40:42 | 000,000,071 | ---- | C] () -- C:\Windows\Crypkey.ini
[2011/08/05 04:40:38 | 000,031,846 | ---- | C] () -- C:\Windows\System32\Ckldrv.sys
[2011/08/05 04:40:38 | 000,027,648 | R--- | C] () -- C:\Windows\Setup_ck.exe
[2011/08/05 04:40:38 | 000,018,432 | ---- | C] () -- C:\Windows\Setup_ck.dll
[2011/08/05 04:40:38 | 000,011,776 | ---- | C] () -- C:\Windows\Ckrfresh.exe
[2011/08/05 04:38:26 | 000,000,471 | ---- | C] () -- C:\ProgramData\ReclaiMe.config
[2011/08/05 04:38:25 | 000,000,438 | ---- | C] () -- C:\Users\Bisho\AppData\Local\ReclaiMe.config
[2011/08/03 18:28:20 | 000,000,014 | ---- | C] () -- C:\Windows\System32\SysInfo_6_5_p.dll
[2011/07/19 02:26:45 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011/07/19 02:26:45 | 000,036,640 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2011/07/15 18:03:48 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011/07/15 18:03:48 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2011/07/15 16:55:32 | 000,000,050 | ---- | C] () -- C:\Windows\System32\bridf07a.dat
[2011/07/12 11:40:13 | 000,000,000 | ---- | C] () -- C:\Users\Bisho\AppData\Local\{8E1DA622-3AD1-4FE0-8D29-8C9065DC9F0E}
[2011/06/30 17:18:49 | 000,451,072 | ---- | C] () -- C:\Windows\System32\ISSRemoveSP.exe
[2011/06/29 16:48:23 | 000,000,419 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\All CPU Meter_Settings.ini
[2011/06/29 16:48:08 | 000,000,360 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\Network Meter_Settings.ini
[2011/06/18 15:48:49 | 000,000,050 | ---- | C] () -- C:\Windows\wininit.ini
[2011/06/07 11:13:38 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2011/06/07 11:13:38 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2011/06/07 11:13:38 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2011/06/07 11:13:38 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2011/06/03 05:04:08 | 000,001,456 | ---- | C] () -- C:\Users\Bisho\AppData\Local\Adobe Save for Web 12.0 Prefs ME
[2011/05/20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\System32\nvStreaming.exe
[2011/05/10 09:37:51 | 000,050,536 | ---- | C] () -- C:\Windows\UTP.exe
[2011/05/02 02:49:45 | 000,049,152 | ---- | C] () -- C:\Windows\System32\AVerIO.dll
[2011/05/02 02:49:45 | 000,003,456 | ---- | C] () -- C:\Windows\System32\AVerIO.sys
[2011/05/02 02:49:44 | 000,598,016 | ---- | C] () -- C:\Windows\System32\sptlib21.dll
[2011/05/02 02:49:44 | 000,294,912 | ---- | C] () -- C:\Windows\System32\sptlib11.dll
[2011/05/02 02:49:44 | 000,290,816 | ---- | C] () -- C:\Windows\System32\sptlib22.dll
[2011/05/02 02:49:44 | 000,249,856 | ---- | C] () -- C:\Windows\System32\sptlib03.dll
[2011/05/02 02:49:44 | 000,249,856 | ---- | C] () -- C:\Windows\System32\sptlib01.dll
[2011/05/02 02:49:44 | 000,225,280 | ---- | C] () -- C:\Windows\System32\sptlib02.dll
[2011/05/02 02:49:44 | 000,135,168 | ---- | C] () -- C:\Windows\System32\sptlib12.dll
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/03/02 00:30:58 | 000,135,168 | R--- | C] () -- C:\Windows\System32\VC025Xcoinst.dll
[2011/03/01 08:47:07 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/03/01 08:46:52 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/02/25 07:18:11 | 000,000,088 | RHS- | C] () -- C:\ProgramData\9B8B3F0050.sys
[2011/01/21 20:23:47 | 000,008,192 | ---- | C] () -- C:\Windows\System32\srvany.exe
[2011/01/03 01:14:46 | 000,998,188 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/12/03 05:59:18 | 000,001,189 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\vso_ts_preview.xml
[2010/10/29 03:03:24 | 008,673,792 | ---- | C] () -- C:\ProgramData\atscie.msi
[2010/09/16 16:07:23 | 000,000,172 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2010/06/11 13:01:50 | 000,000,632 | RHS- | C] () -- C:\Users\Bisho\ntuser.pol
[2010/04/01 01:56:02 | 000,000,000 | ---- | C] () -- C:\Users\Bisho\jagex__preferences3.dat
[2010/02/04 04:31:36 | 000,000,088 | RHS- | C] () -- C:\ProgramData\5019F804B8.sys
[2009/11/18 09:58:19 | 000,000,129 | ---- | C] () -- C:\Users\Bisho\jagex_runescape_preferences2.dat
[2009/11/18 09:53:28 | 000,000,042 | ---- | C] () -- C:\Users\Bisho\jagex_runescape_preferences.dat
[2009/11/14 18:25:35 | 000,138,056 | ---- | C] () -- C:\Users\Bisho\AppData\Roaming\PnkBstrK.sys
[2009/11/12 03:34:40 | 000,000,418 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2009/11/08 16:12:10 | 000,094,720 | ---- | C] () -- C:\Users\Bisho\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/11/08 00:13:34 | 000,013,356 | -HS- | C] () -- C:\ProgramData\KGyGaAvL.sys
[2009/11/08 00:13:34 | 000,000,088 | RHS- | C] () -- C:\ProgramData\A522B7E563.sys
[2009/11/07 21:18:38 | 000,007,593 | ---- | C] () -- C:\Users\Bisho\AppData\Local\resmon.resmoncfg
 
========== LOP Check ==========

[2012/05/03 14:34:16 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Acapela Group
[2011/06/05 00:02:50 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DAEMON Tools Lite
[2012/06/27 22:40:18 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\DMCache
[2010/03/02 18:00:13 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\ESET
[2012/04/14 21:25:20 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\HTC
[2012/06/18 03:24:45 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\IDM
[2012/04/14 21:25:25 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Nokia
[2012/03/29 14:54:07 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\PC Suite
[2011/05/28 01:33:16 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Research In Motion
[2012/06/18 03:02:26 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Samsung
[2010/04/05 02:48:50 | 000,000,000 | ---D | M] -- C:\Users\Administrator\AppData\Roaming\Ulead Systems
[2012/04/29 12:29:34 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Acapela Group
[2010/03/24 11:47:02 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Any Video Converter
[2010/04/08 20:51:06 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Autodesk
[2011/06/08 05:33:25 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Canon
[2011/10/26 10:38:22 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\casualArts
[2010/03/11 13:57:22 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\CasualForge
[2010/12/22 03:27:45 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Certblaster
[2012/06/23 03:36:07 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\DAEMON Tools Lite
[2011/07/04 05:02:00 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\DeskSoft
[2012/06/30 04:05:06 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\DMCache
[2010/04/29 02:51:03 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Easy Thumbnails
[2012/01/10 06:19:19 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Elephant Games
[2011/12/01 19:26:00 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\empireCinemasWidget
[2012/02/15 07:18:25 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\eType
[2011/07/15 18:11:17 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\FairStars Recorder
[2012/05/31 05:03:23 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\FileZilla
[2009/11/07 22:57:10 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\FlashFXP
[2010/03/04 10:00:51 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Flood Light Games
[2010/06/15 03:51:19 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Floodlight Games
[2011/01/03 06:14:21 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\FrostWire
[2012/04/26 00:59:58 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\GFI Software
[2010/07/30 20:08:44 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\GOL_byHasbro
[2012/03/01 21:42:23 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\GPass
[2012/05/07 02:53:26 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\gtk-2.0
[2012/04/09 18:19:43 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\HTC
[2012/04/09 18:21:19 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\HTC.388BC06ACDAB6261375BCE37FBA2E023C0D7EE34.1
[2011/01/25 18:32:05 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\HyperLyrics
[2012/06/27 04:53:21 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\IDM
[2011/05/02 02:09:44 | 000,000,000 | -H-D | M] -- C:\Users\Bisho\AppData\Roaming\IFViewer
[2012/06/29 13:52:13 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\ImgBurn
[2011/06/01 07:56:44 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\IMVU
[2011/04/11 03:31:27 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\IMVUClient
[2012/06/12 15:06:12 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\IObit
[2009/11/14 01:50:41 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Jumblo
[2011/08/06 07:50:06 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Kernel for Windows Data Recovery
[2009/11/11 22:16:51 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Locktime
[2012/04/20 21:27:18 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Mael
[2010/02/27 16:31:42 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\MAGIX
[2012/01/19 09:10:15 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2010/04/06 17:56:53 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\MOVAVI
[2010/02/20 22:52:21 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\MSNRecorderMax
[2010/03/21 10:35:24 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\muvee Technologies
[2012/05/06 16:21:32 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Need for Speed World
[2009/11/11 22:04:03 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\NetMeter
[2012/03/29 21:48:52 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Nokia
[2010/09/18 02:41:49 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Nokia Ovi Suite
[2012/03/29 22:29:19 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Nokia Suite
[2010/04/15 14:46:53 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Nseries
[2011/04/11 20:02:50 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\OneUpIndustries
[2011/01/24 02:03:07 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\ooVoo Details
[2011/06/11 12:24:33 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Opera
[2012/03/04 04:32:43 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Paltalk
[2011/01/27 05:39:36 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Pamela
[2012/04/14 21:00:20 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\PC Suite
[2010/11/07 14:02:41 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\PlatinumHideIP
[2010/02/22 19:19:43 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\PlayFirst
[2010/06/23 04:55:27 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Pogo
[2009/11/08 21:48:37 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Publish Providers
[2011/04/04 12:08:11 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\PunkBuster
[2012/05/28 02:16:51 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\redsn0w
[2012/03/24 20:31:45 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Research In Motion
[2012/04/20 06:23:27 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Samsung
[2012/03/21 21:13:33 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Saxo Bank
[2011/01/09 11:31:37 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\SecondLife
[2010/03/17 11:25:53 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Sony
[2010/12/22 03:02:26 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2010/08/02 03:20:44 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Stereoscopic Player
[2011/12/11 21:43:20 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\SystemRequirementsLab
[2011/10/02 05:40:03 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\TeamViewer
[2012/06/18 03:00:44 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Temp
[2010/08/07 17:33:02 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\The Creative Assembly
[2011/06/14 23:42:17 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Thinstall
[2010/04/13 02:37:00 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Ubisoft
[2012/01/30 20:50:45 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Ulead Systems
[2012/06/27 06:00:43 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\uTorrent
[2011/12/12 06:03:42 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\VitySoft
[2010/11/04 11:30:57 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Vivox
[2012/03/11 19:00:33 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Vso
[2009/11/08 15:10:58 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Webcammax
[2010/08/02 03:14:04 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\WinAVI
[2010/04/12 19:25:38 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Windows Live Writer
[2011/07/19 12:37:12 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Wondershare
[2011/06/05 07:42:22 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Xilisoft
[2010/10/24 18:51:45 | 000,000,000 | ---D | M] -- C:\Users\Bisho\AppData\Roaming\Zoner
[2010/02/01 02:12:44 | 000,000,000 | ---D | M] -- C:\Users\nad\AppData\Roaming\ESET
[2012/04/29 16:14:24 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\Acapela Group
[2012/06/29 14:51:46 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\DMCache
[2009/11/14 19:36:05 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\ESET
[2012/04/25 12:52:17 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\HTC
[2012/06/03 16:10:02 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\IDM
[2009/12/14 19:30:41 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\Nokia
[2009/12/07 17:39:10 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\PC Suite
[2010/05/23 17:00:03 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\TuneUp Software
[2010/03/28 18:49:57 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\Ulead Systems
[2010/08/13 15:41:56 | 000,000,000 | ---D | M] -- C:\Users\Trial\AppData\Roaming\Zoner
[2012/06/30 15:22:04 | 000,000,216 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2012/06/30 15:22:02 | 000,000,218 | ---- | M] () -- C:\Windows\Tasks\AutoKMSDaily.job
[2012/06/20 12:29:00 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001Core.job
[2012/06/30 15:29:02 | 000,000,928 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001UA.job
[2012/06/08 21:08:06 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2011/12/27 18:01:33 | 000,001,024 | ---- | M] () -- C:\.rnd
[2012/06/27 23:28:42 | 000,387,826 | ---- | M] () -- C:\0627232842Analog TV.jpg
[2009/06/11 00:42:20 | 000,000,024 | ---- | M] () -- C:\autoexec.bat
[2012/06/26 01:00:43 | 000,003,400 | ---- | M] () -- C:\bootsqm.dat
[2009/06/11 00:42:20 | 000,000,010 | ---- | M] () -- C:\config.sys
[2012/03/23 16:08:08 | 000,000,256 | ---- | M] () -- C:\dk2.mem
[2009/12/19 14:55:36 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/12/19 14:55:36 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2012/06/30 15:21:11 | 3479,126,016 | -HS- | M] () -- C:\pagefile.sys
[2012/06/28 23:44:54 | 000,042,099 | ---- | M] () -- C:\swtag.log
[2012/06/27 13:38:56 | 000,148,378 | ---- | M] () -- C:\TDSSKiller.2.7.42.0_27.06.2012_13.34.45_log.txt
[2012/06/07 01:05:42 | 000,002,048 | ---- | M] () -- C:\Uninstall.dat

< %systemroot%\Fonts\*.com >
[2009/07/14 07:52:25 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 07:52:25 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 07:52:25 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 07:52:25 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/11 00:31:19 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2006/10/26 20:58:12 | 000,030,512 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\mdippr.dll
[2006/10/26 20:56:12 | 000,033,104 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\msonpppr.dll
[2010/11/20 05:21:38 | 000,030,208 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\spool\prtprocs\w32x86\winprint.dll

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 07:41:57 | 000,000,174 | -HS- | M] () -- C:\Program Files\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >
[2010/10/11 01:10:02 | 000,000,006 | ---- | M] () -- C:\Windows\system32\config\systemprofile\ddid
[2010/06/23 19:23:19 | 000,000,660 | ---- | M] () -- C:\Windows\system32\config\systemprofile\dd_SetupUtility.txt
[2011/12/01 00:08:05 | 000,007,196 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_0dMEtL9OmZOKX5N
[2012/04/09 00:28:31 | 002,009,088 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_0IcMMK6I4t8WWcr
[2012/04/02 00:23:46 | 001,864,704 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_69lqk6ho5jLjohN
[2012/01/09 01:06:13 | 000,005,140 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_8N9oad07BcliCPF
[2012/03/26 00:20:21 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_9QvrMFb6gUd9fiN
[2012/06/08 01:16:53 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_B2bcEpS0TmBuS2x
[2012/04/16 01:30:03 | 002,263,040 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_BGt3UCyHxu1fU8k
[2012/04/02 00:23:46 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_D1hBHyj2DR7OIns
[2012/03/26 00:20:21 | 001,615,872 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_D2fdEIKO2x8pdiE
[2012/06/15 01:19:35 | 003,183,616 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_e9R5tbE7ss8jRtJ
[2012/04/09 00:28:31 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_gjm93qcNfXqu3nx
[2012/06/22 01:20:29 | 004,303,872 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_GkWPWtk9fiGjydD
[2012/03/11 21:02:14 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_HJs8KchDUmwUGij
[2012/03/04 20:59:45 | 001,005,568 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_IAB1oeph16kQ8hK
[2012/06/22 01:20:29 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_ir7tT85CrC83nmj
[2012/03/18 21:02:53 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_k3gbylj3l64r9Ar
[2012/02/26 20:54:58 | 000,816,128 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_kfrIvEBUJHLxvI4
[2012/03/11 21:02:14 | 001,129,472 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_L3KJWePRJSUzaRh
[2012/02/26 20:54:58 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_MbEklofXWhTswxc
[2012/04/23 07:09:14 | 002,116,608 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_nkDVfZdyY2ejyER
[2012/03/18 21:02:53 | 001,247,232 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_nnHElOXbHXRekVZ
[2012/04/16 01:30:01 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_OWT7Ii9lULRcuJp
[2011/11/09 21:19:45 | 000,006,168 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_Re3l3VWuBpJioVb
[2012/06/15 01:19:35 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_rpCqvjVNeClIYBS
[2012/06/08 01:16:53 | 002,665,472 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_rpMgDcgNImwIls9
[2012/03/04 20:59:45 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_UkH0emXeSiZG7HR
[2012/04/23 07:09:14 | 000,000,512 | ---- | M] () -- C:\Windows\system32\config\systemprofile\etilqs_YaXhKB2NkNs264H
[2011/03/01 09:24:41 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\FXSAPIDebugLogFile.txt
[2011/03/01 09:24:40 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\FXSTIFFDebugLogFile.txt
[2011/12/01 16:34:17 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\GoogleQuickSearchBoxSetup.log
[2011/08/17 21:39:02 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\GoogleQuickSearchBoxSetup_F8DB49E787CC0771.log
[2012/06/27 22:34:20 | 000,067,909 | ---- | M] () -- C:\Windows\system32\config\systemprofile\GoogleToolbarInstaller1.log
[2012/03/17 10:43:26 | 000,071,749 | ---- | M] () -- C:\Windows\system32\config\systemprofile\GoogleToolbarInstaller2.log
[2012/03/12 05:26:45 | 000,013,926 | ---- | M] () -- C:\Windows\system32\config\systemprofile\HideMyIpSRV.log
[2012/03/12 05:26:45 | 000,006,116 | ---- | M] () -- C:\Windows\system32\config\systemprofile\HideMyIpSRVr.log
[2010/06/23 19:23:18 | 003,521,966 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Microsoft .NET Framework 4 Client Profile Setup_20100623_182201845-MSI_netfx_Core_x86.msi.txt
[2010/06/23 19:23:36 | 000,575,948 | ---- | M] () -- C:\Windows\system32\config\systemprofile\Microsoft .NET Framework 4 Client Profile Setup_20100623_182201845.html
[2012/06/30 15:32:15 | 000,275,062 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MpCmdRun.log
[2010/11/04 02:28:00 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI1143b.LOG
[2010/06/01 22:26:08 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI13d33.LOG
[2010/05/23 17:26:23 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI14cbe.LOG
[2010/10/12 20:34:04 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI15ce9.LOG
[2010/10/24 22:49:20 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI18b61.LOG
[2010/11/04 02:28:31 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI18fef.LOG
[2010/06/10 02:26:10 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI1a926.LOG
[2010/11/23 02:43:49 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI1a93a.LOG
[2010/05/30 13:25:40 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI1bca6.LOG
[2010/05/29 13:25:46 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI1cf53.LOG
[2010/11/04 02:29:01 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2058b.LOG
[2010/11/03 08:44:05 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI21104.LOG
[2010/07/30 20:07:12 | 000,068,990 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2246f.LOG
[2010/10/17 17:40:00 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI232e9.LOG
[2010/10/13 01:34:25 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2572.LOG
[2010/11/04 02:26:59 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI272f.LOG
[2010/11/04 02:29:30 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI27696.LOG
[2010/11/11 11:44:17 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI27747.LOG
[2010/11/03 19:43:57 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2849a.LOG
[2010/11/09 22:43:57 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI28d62.LOG
[2010/05/28 11:26:04 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2960c.LOG
[2010/06/12 03:27:55 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2aea3.LOG
[2010/11/08 07:43:46 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2b13a.LOG
[2010/11/21 23:43:58 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2dbae.LOG
[2010/11/04 02:29:59 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2e6c5.LOG
[2010/11/08 02:43:56 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2e6f.LOG
 
[2010/05/28 21:26:03 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI2fa8a.LOG
[2010/10/05 00:34:19 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI35571.LOG
[2010/11/02 22:43:57 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI35e1d.LOG
[2010/06/07 16:26:03 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3605a.LOG
[2010/10/15 00:34:08 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI369be.LOG
[2010/11/14 10:43:45 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI37e05.LOG
[2010/06/06 19:26:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI388cf.LOG
[2010/06/12 13:25:56 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI39156.LOG
[2010/11/19 12:43:44 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3a756.LOG
[2010/10/23 17:21:32 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3af23.LOG
[2010/06/03 13:26:22 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3bf1f.LOG
[2010/11/23 17:44:02 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3cc72.LOG
[2010/11/13 10:44:20 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3cd9b.LOG
[2010/05/31 13:26:22 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3d578.LOG
[2010/06/02 03:26:08 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI3e351.LOG
[2010/06/13 18:27:35 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI43c0b.LOG
[2010/11/19 22:43:47 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI44710.LOG
[2010/05/24 21:26:14 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI44a47.LOG
[2010/11/03 02:49:41 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI457ab.LOG
[2010/11/12 07:44:00 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4672c.LOG
[2010/10/08 20:34:23 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI469c9.LOG
[2010/05/26 21:26:09 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI48b38.LOG
[2010/10/18 18:40:12 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI49ac5.LOG
[2010/05/24 06:25:54 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4bee9.LOG
[2010/05/29 18:26:06 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4c680.LOG
[2010/10/19 19:41:21 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4e4b5.LOG
[2010/05/30 18:26:15 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4ef84.LOG
[2010/11/10 03:43:40 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4f2fd.LOG
[2010/10/21 10:34:07 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI4f3b3.LOG
[2012/06/01 03:00:31 | 001,541,756 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5200d.LOG
[2010/06/02 14:26:41 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5267f.LOG
[2010/11/17 11:44:27 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI53775.LOG
[2010/11/04 02:44:39 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5521.LOG
[2010/11/07 00:43:49 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI553bb.LOG
[2010/10/17 22:40:33 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI55c70.LOG
[2010/11/04 06:02:09 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI563d1.LOG
[2010/10/04 19:34:18 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI576be.LOG
[2010/11/22 04:43:56 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI57a43.LOG
[2010/11/03 09:22:47 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI57ec5.LOG
[2010/05/26 05:26:13 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI58e34.LOG
[2010/11/15 09:43:53 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI59665.LOG
[2010/05/29 02:26:04 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5a6f2.LOG
[2010/10/07 19:34:16 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5a724.LOG
[2010/10/26 00:03:51 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5a896.LOG
[2010/06/07 11:25:39 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5b14.LOG
[2010/11/04 20:43:47 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5c1b9.LOG
[2010/11/03 04:01:11 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5cdd5.LOG
[2010/11/04 06:02:37 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5d326.LOG
[2010/10/25 00:03:57 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5dbf7.LOG
[2010/11/03 09:23:15 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5eee5.LOG
[2010/05/31 18:26:13 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI5f489.LOG
[2010/11/03 03:44:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI62d62.LOG
[2010/10/06 19:34:09 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI63129.LOG
[2010/09/06 05:05:50 | 000,000,322 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI63159.LOG
[2010/11/03 04:01:39 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI63c7f.LOG
[2010/11/04 06:03:05 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI64182.LOG
[2010/11/23 22:43:55 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI658de.LOG
[2010/11/03 09:23:44 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI65d60.LOG
[2010/10/20 00:40:03 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI65f64.LOG
[2010/11/04 04:01:14 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI66eea.LOG
[2010/10/11 11:34:55 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI67323.LOG
[2010/06/07 00:26:31 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI68ed0.LOG
[2010/11/03 04:02:08 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6ab86.LOG
[2010/11/08 16:43:46 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6ab8b.LOG
[2010/11/04 06:03:33 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6ae96.LOG
[2010/06/10 14:25:41 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6afaf.LOG
[2010/11/16 11:44:24 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6ba4a.LOG
[2010/11/03 09:24:12 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6c9f7.LOG
[2010/05/25 02:26:05 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6d145.LOG
[2010/10/22 19:34:31 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6d798.LOG
[2010/10/09 01:34:09 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6d966.LOG
[2010/11/04 04:01:42 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6dcaa.LOG
[2010/11/18 12:43:56 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6eacb.LOG
[2010/11/20 03:43:46 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI6ebad.LOG
[2010/10/15 05:52:41 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI70a6c.LOG
[2010/09/06 05:06:46 | 000,000,322 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI70c86.LOG
[2010/11/04 06:04:01 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI71baa.LOG
[2010/11/17 16:43:40 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI729e3.LOG
[2010/10/18 23:40:08 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI73386.LOG
[2010/11/03 09:24:40 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7374a.LOG
[2010/11/03 04:02:45 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI73e72.LOG
[2010/11/04 04:02:09 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI74886.LOG
[2010/06/02 19:26:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI74b68.LOG
[2010/10/09 16:34:10 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI753d1.LOG
[2010/06/11 12:26:02 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI77242.LOG
[2010/06/04 21:26:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI77d7b.LOG
[2010/10/04 13:34:12 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI77fa0.LOG
[2010/05/30 23:26:09 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI780f1.LOG
[2010/11/19 17:43:46 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7847b.LOG
[2010/11/04 06:04:29 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI789c7.LOG
[2010/10/20 15:40:14 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI79c63.LOG
[2010/11/21 16:43:58 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7a064.LOG
[2010/11/03 09:25:07 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7a45e.LOG
[2010/11/03 04:03:13 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7aa9c.LOG
[2010/11/10 10:44:08 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7ae97.LOG
[2010/11/04 04:02:37 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7b3d5.LOG
[2010/10/11 17:34:16 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7c88d.LOG
[2010/06/14 14:26:24 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7d016.LOG
[2010/09/06 05:07:42 | 000,000,322 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7e746.LOG
[2010/11/02 04:44:15 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7e88.LOG
[2010/11/04 06:04:58 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI7f804.LOG
[2010/11/03 09:25:35 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI811d0.LOG
[2010/11/09 07:44:19 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8143d.LOG
[2010/11/03 04:03:41 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI816a7.LOG
[2010/11/04 04:03:04 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI81fb2.LOG
[2010/10/08 00:34:08 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8319d.LOG
[2010/10/27 19:38:39 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8391b.LOG
[2010/11/01 16:43:55 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI83d3e.LOG
[2010/10/29 21:43:46 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI84aa6.LOG
[2010/05/25 13:25:42 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI858e9.LOG
[2010/10/25 05:03:47 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI85ff7.LOG
[2010/05/29 23:27:10 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8698c.LOG
[2010/11/03 04:04:08 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI883bc.LOG
[2010/11/04 04:03:32 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI88b40.LOG
[2010/11/16 16:43:52 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI88cd4.LOG
[2010/11/05 01:44:00 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI89c26.LOG
[2010/05/28 16:26:17 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8a11.LOG
[2010/10/07 00:34:01 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8b930.LOG
[2010/05/31 23:26:20 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8ba45.LOG
[2010/06/23 19:21:26 | 000,000,326 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8c1c7.LOG
[2010/09/06 05:08:39 | 000,000,206 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8c2b2.LOG
[2010/11/21 02:43:54 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8ea91.LOG
[2010/11/04 04:03:59 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI8f6fd.LOG
[2010/10/20 05:40:03 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI90582.LOG
[2010/11/24 03:43:57 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI90825.LOG
[2010/10/13 18:34:12 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI90b62.LOG
[2010/05/20 02:05:09 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9379e.LOG
[2010/06/09 10:26:10 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI94879.LOG
[2010/10/23 00:34:25 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI96721.LOG
[2010/11/04 02:27:28 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI97cc.LOG
[2010/06/03 18:26:14 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI980a0.LOG
[2010/11/18 17:43:57 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI997f0.LOG
[2010/10/23 21:40:19 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9a72.LOG
[2010/06/10 19:26:07 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9bca6.LOG
[2010/11/04 07:43:58 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9d00c.LOG
[2010/10/09 21:34:03 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9e109.LOG
[2010/06/07 21:26:04 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9f0e9.LOG
[2010/06/03 00:26:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSI9f138.LOG
[2010/10/21 15:34:07 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa012a.LOG
[2010/10/19 04:40:19 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa04cb.LOG
[2010/10/20 20:40:01 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa13b1.LOG
[2010/06/05 02:26:06 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa20ea.LOG
[2010/06/09 16:26:06 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa3008.LOG
[2010/10/31 17:43:52 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa428b.LOG
[2010/06/14 20:26:59 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa50af.LOG
[2010/06/11 17:26:16 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa5133.LOG
[2010/11/10 16:43:43 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa5cb0.LOG
[2010/10/16 21:40:17 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIa694a.LOG
[2010/05/20 02:06:44 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIaa799.LOG
[2010/10/11 22:34:35 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIabbb3.LOG
[2010/11/25 02:43:43 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIabe30.LOG
[2010/10/08 05:34:02 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIac2bc.LOG
[2010/11/15 19:44:05 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb0695.LOG
[2010/10/30 02:43:55 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb17ba.LOG
[2010/11/15 14:47:00 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb1ab6.LOG
[2010/06/12 18:27:01 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb1d94.LOG
[2010/11/05 23:43:45 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb2a2c.LOG
[2010/11/16 21:43:51 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb3326.LOG
[2010/11/05 06:43:57 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb38f6.LOG
[2010/10/31 23:44:12 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb4c0d.LOG
[2010/10/21 20:34:34 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb7612.LOG
[2010/11/02 17:43:57 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb828.LOG
[2010/06/23 19:24:28 | 000,000,326 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb884a.LOG
[2010/05/25 18:26:12 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb90be.LOG
[2010/10/10 14:34:08 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb9ad5.LOG
[2010/11/18 00:43:47 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIb9ff6.LOG
[2010/06/05 17:26:05 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIbaa0e.LOG
[2010/10/13 23:34:14 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIbb8e3.LOG
[2010/11/13 15:43:49 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIbddef.LOG
[2010/10/31 03:43:50 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIbdfb4.LOG
[2010/11/24 20:43:58 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIbe20.LOG
[2010/06/23 05:40:27 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc0ea3.LOG
[2010/06/03 23:26:09 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc14ad.LOG
[2010/11/18 22:43:48 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc1d5a.LOG
[2010/10/10 21:34:36 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc5609.LOG
[2010/06/08 22:26:15 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc69b0.LOG
[2010/10/25 17:03:56 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc6fd6.LOG
[2010/11/07 10:45:51 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc7f68.LOG
[2010/05/27 20:25:45 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc9338.LOG
[2010/06/11 00:26:19 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIc95db.LOG
[2010/11/20 21:43:52 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIca266.LOG
[2010/06/08 02:26:10 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIcafee.LOG
[2010/06/11 22:26:03 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIcc620.LOG
[2010/10/17 02:40:02 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIcd51f.LOG
[2010/10/12 03:34:03 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIce6e5.LOG
[2010/11/09 02:43:58 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIcfd32.LOG
[2010/10/26 05:04:16 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId2664.LOG
[2010/10/28 05:43:51 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId2bf.LOG
[2010/10/21 01:40:09 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId2f34.LOG
[2010/11/11 06:45:24 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId558.LOG
[2010/11/01 23:43:48 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId6bae.LOG
[2010/06/23 05:42:08 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSId9802.LOG
[2010/06/04 12:35:42 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIdac5f.LOG
[2010/11/01 04:43:55 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIdb3e9.LOG
[2010/05/21 14:07:40 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIdbdb9.LOG
[2010/06/14 03:26:21 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIdbf4d.LOG
[2010/06/09 21:26:07 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIdc2b1.LOG
[2010/06/05 12:26:05 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIded9c.LOG
[2010/06/12 23:27:16 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe002f.LOG
[2010/10/14 19:34:16 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe08e.LOG
[2010/10/28 00:43:45 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe1296.LOG
[2010/06/23 05:42:43 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe1e3a.LOG
[2010/11/07 05:50:32 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe20cf.LOG
[2010/10/05 22:34:07 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe22d.LOG
[2010/05/25 23:26:06 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe2345.LOG
[2010/06/05 22:26:03 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe4aed.LOG
[2010/11/06 04:44:17 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe4e83.LOG
[2010/10/05 17:34:13 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe5072.LOG
[2010/06/04 04:25:43 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe5859.LOG
[2010/10/29 01:52:24 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe5b78.LOG
[2010/05/27 08:25:50 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe6f6f.LOG
[2010/05/21 18:26:05 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe8245.LOG
[2010/06/23 05:08:12 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIe85c9.LOG
[2010/11/12 21:44:31 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIea815.LOG
[2010/10/11 02:34:17 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIeb3d4.LOG
[2010/06/01 17:26:25 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIed5d2.LOG
[2010/11/09 13:43:49 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIee54f.LOG
[2010/06/23 05:08:40 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIef3f4.LOG
[2010/06/06 03:26:02 | 000,000,334 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf021.LOG
[2010/10/12 15:34:27 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf10a3.LOG
[2010/06/01 12:26:14 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf190d.LOG
[2010/06/23 05:43:47 | 000,000,324 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf19d0.LOG
[2010/08/02 03:59:06 | 000,000,322 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf3f91.LOG
[2010/06/06 14:25:51 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf76fe.LOG
[2010/05/28 01:26:06 | 000,000,336 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIf8d14.LOG
[2010/10/07 11:34:06 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIfa747.LOG
[2010/10/17 12:40:11 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIfb764.LOG
[2010/10/03 19:48:54 | 000,000,338 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIfce64.LOG
[2010/11/22 15:43:55 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIfdae4.LOG
[2010/10/28 18:44:26 | 000,000,340 | ---- | M] () -- C:\Windows\system32\config\systemprofile\MSIfe10b.LOG
[2012/06/01 02:49:33 | 010,350,080 | ---- | M] () -- C:\Windows\system32\config\systemprofile\NUP1E7E.msi
[2010/06/23 19:24:39 | 000,004,524 | ---- | M] () -- C:\Windows\system32\config\systemprofile\OutofProcReport18588511.txt
[2012/06/23 02:32:17 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000156DC22830BA0841C
[2012/06/23 02:42:08 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000001CDE3961F15764A67
[2012/06/23 03:03:34 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000025E843E1EB1C5DDC6
[2012/06/24 00:03:16 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000026219535A4B0B5264
[2012/06/23 23:48:24 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000002C43923655088FC09
[2012/06/23 13:24:34 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000002F465F4D647ABF5DA
[2012/06/23 03:03:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000003061AC51266ACF372
[2012/06/23 13:24:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000033E97AB528675A6F9
[2012/06/24 00:27:50 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000398CFDEDDF987F2F1
[2012/06/24 00:03:16 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000003C3E47992E9B7FA34
[2012/06/23 23:48:24 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000003FACEB070AC69BED1
[2012/06/23 02:49:06 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000460E50C178576F570
[2012/06/23 02:42:26 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000004F83FD2E36210FF80
[2012/06/23 03:07:06 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000084F39878F49E9982E
[2012/06/24 00:28:02 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000008B9399ECECB9E8686
[2012/06/23 02:49:39 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000008F4F28243CA8D1FB2
[2012/06/23 03:07:13 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000990D550C8629D3BD3
[2012/06/23 02:42:58 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000099EB21C40A5499AF7
[2012/06/23 02:55:21 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000B849095D6CEF25EB6
[2012/06/23 23:52:54 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000C2B0A4C99DC196FE8
[2012/06/23 02:43:43 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000000D8630ACBE9EAE282F
[2012/06/23 02:43:58 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000106B12E8660296D45F
[2012/06/24 00:28:43 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000011C481850C359A4C9B
[2012/06/24 00:28:43 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000001269728E809900358D
[2012/06/23 23:53:19 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000013F33744BA118BA7D3
[2012/06/23 23:53:19 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000001444915DC6EAB73FEA
[2012/06/23 03:53:10 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000148D5FCA91A6D79CA5
[2012/06/23 02:38:59 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000015B1AC4173DF245907
[2012/06/24 00:29:51 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000015FD18F8119CF153F3
[2012/06/23 13:27:26 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000016AC3AA532290E44D7
[2012/06/23 02:50:20 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000018E6B3B410D2E1E6FE
[2012/06/23 23:58:41 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000001AE4ACE1F6989B8E16
[2012/06/23 23:58:41 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000001BE310CB404C01839B
[2012/06/23 02:44:04 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000002196FC924AEEB83630
[2012/06/23 02:55:32 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000021C61A47AF0FF0309F
[2012/06/23 02:44:40 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000234FE25052AE5B2665
[2012/06/23 02:50:39 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000237BCB468D5FA4D902
[2012/06/23 03:53:40 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000023C6BF2994B6089850
[2012/06/23 03:53:49 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000259750D18AAC1362D8
[2012/06/23 03:53:49 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000026621AD051048ECA3A
[2012/06/23 04:06:31 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000002C6B8021B7D02DBA66
[2012/06/23 04:06:31 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000002DDE9A0392DCCE2C6D
[2012/06/23 02:55:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000002F25BFD55811D46619
[2012/06/23 03:57:27 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000002FDD32DE2BCBD1393F
[2012/06/23 03:57:27 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000030256C038FFAF69DC4
[2012/06/23 13:27:56 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000030FBC0FE35DEEF139E
[2012/06/23 02:55:36 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000326DCE00C042C700ED
[2012/06/24 01:02:27 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000035109C67C86E40F5E4
[2012/06/23 13:28:05 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000355A9B716FF9760EF0
[2012/06/23 02:51:05 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000035E114530C3E0BE87B
[2012/06/23 13:28:05 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000362243DB47D6AFF379
[2012/06/23 02:39:19 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000037C5819F3CF0163374
[2012/06/23 04:07:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000003889447789FB7B1E7A
[2012/06/24 01:03:22 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000039FB41E39C257C0B5E
[2012/06/23 13:31:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000003A4285C7380EDF13E6
[2012/06/23 13:31:35 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000003BD170BF1040408D6D
[2012/06/23 13:15:49 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000043489A8A9DD17C5C6E
[2012/06/26 01:07:07 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000043D88F5FE63204BCA9
[2012/06/23 02:51:13 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000004557F941B682E21ADC
[2012/06/23 02:40:41 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000000460F2A6D7B79AA9D00
[2012/06/23 03:58:37 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000053E71041CED399191B
[2012/06/26 01:08:01 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000005A58A684CEB31E6254
[2012/06/23 13:16:44 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000064AFBF2696BCA15598
[2012/06/23 13:29:07 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP0000006D0987F6C0AE21160F
[2012/06/27 03:37:50 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000086D12229B86D7167DB
[2012/06/23 02:33:21 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000002FD43DF9806D60251CB
[2012/06/23 03:44:27 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000863C9B257FAD4B9B4CF
[2012/06/23 03:45:14 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP000009DBD43FB5112561B0E9
[2012/06/23 02:35:43 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000A0646811C1DBC7CC68A
[2012/06/23 03:45:33 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000A4B4B1C88A9975C4F4A
[2012/06/23 02:36:58 | 000,524,288 | ---- | M] () -- C:\Windows\system32\config\systemprofile\TMP00000ED64D8229839AADA756
[2010/09/01 21:00:38 | 000,001,946 | R--- | M] () -- C:\Windows\system32\config\systemprofile\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml1604936
[2010/09/01 21:00:38 | 000,001,946 | R--- | M] () -- C:\Windows\system32\config\systemprofile\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml23694ad
[2010/09/01 21:00:38 | 000,001,946 | R--- | M] () -- C:\Windows\system32\config\systemprofile\toolbar.google.com_MXE8GT6B9RBHXCGLZ06L.xml8e121
[2011/12/30 21:34:11 | 000,341,813 | ---- | M] () -- C:\Windows\system32\config\systemprofile\vminst.log
[2011/07/08 02:03:25 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER1721.tmp.WERInternalMetadata.xml
[2011/10/10 04:44:20 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER1AB5.tmp.WERInternalMetadata.xml
[2011/10/10 04:44:20 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER1AD5.tmp.hdmp
[2011/10/09 14:57:27 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER2220.tmp.WERInternalMetadata.xml
[2011/10/09 14:57:27 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER2231.tmp.hdmp
[2012/01/07 16:36:12 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER24A3.tmp.WERInternalMetadata.xml
[2012/01/07 16:36:13 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER24D3.tmp.hdmp
[2011/01/22 21:50:54 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3017.tmp.WERInternalMetadata.xml
[2011/01/22 21:50:54 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3028.tmp.hdmp
[2011/06/24 05:18:00 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3474.tmp.WERInternalMetadata.xml
[2011/06/24 05:18:00 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3540.tmp.hdmp
[2011/04/04 15:55:46 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3C3A.tmp.WERInternalMetadata.xml
[2011/04/04 15:55:46 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER3C69.tmp.hdmp
[2011/05/28 07:39:07 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4522.tmp.WERInternalMetadata.xml
[2011/05/28 07:39:07 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4542.tmp.hdmp
[2011/11/10 19:21:03 | 000,002,954 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4816.tmp.WERInternalMetadata.xml
[2011/11/10 19:21:03 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4865.tmp.hdmp
[2011/11/10 06:52:45 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4AE4.tmp.WERInternalMetadata.xml
[2011/11/10 06:52:46 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4B33.tmp.hdmp
[2011/02/08 19:51:34 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4F7A.tmp.WERInternalMetadata.xml
[2011/02/08 19:51:34 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4FD8.tmp.hdmp
[2011/11/08 06:04:12 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER4FF3.tmp.WERInternalMetadata.xml
[2011/11/08 06:04:12 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5051.tmp.hdmp
[2011/06/25 16:19:14 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5207.tmp.WERInternalMetadata.xml
[2011/06/25 16:19:14 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5237.tmp.hdmp
[2011/10/23 23:52:06 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER58C4.tmp.WERInternalMetadata.xml
[2011/10/23 23:52:06 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5932.tmp.hdmp
[2011/02/28 11:44:58 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5FE9.tmp.WERInternalMetadata.xml
[2011/02/28 11:44:58 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5FEA.tmp.hdmp
[2011/10/24 10:25:13 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER5FFB.tmp.WERInternalMetadata.xml
[2011/10/24 10:25:13 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER600C.tmp.hdmp
[2011/03/04 20:57:34 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER603C.tmp.WERInternalMetadata.xml
[2011/03/04 20:57:34 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER603D.tmp.hdmp
[2011/03/01 09:19:03 | 000,037,788 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER60B2.tmp.appcompat.txt
[2011/11/12 20:33:48 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER6450.tmp.WERInternalMetadata.xml
[2011/11/12 20:33:48 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER6470.tmp.hdmp
[2011/06/09 08:56:46 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER677E.tmp.WERInternalMetadata.xml
[2011/06/09 08:56:46 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER67AE.tmp.hdmp
[2011/06/27 14:54:52 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER823B.tmp.WERInternalMetadata.xml
[2011/06/27 14:54:52 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER826A.tmp.hdmp
[2011/09/20 11:55:39 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER82B7.tmp.WERInternalMetadata.xml
[2011/09/20 11:55:39 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER82B8.tmp.hdmp
[2012/06/24 01:06:21 | 000,002,954 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8564.tmp.WERInternalMetadata.xml
[2012/06/24 01:06:21 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8575.tmp.hdmp
[2011/12/12 07:09:30 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER862F.tmp.WERInternalMetadata.xml
[2011/10/10 17:32:45 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER868F.tmp.WERInternalMetadata.xml
[2011/10/10 17:32:45 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER86A0.tmp.hdmp
[2011/03/03 15:51:46 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8D17.tmp.WERInternalMetadata.xml
[2011/03/03 15:51:46 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8D37.tmp.hdmp
[2011/12/12 12:06:03 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8F18.tmp.WERInternalMetadata.xml
[2011/12/12 12:06:03 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8F29.tmp.hdmp
[2012/01/25 02:50:39 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER8F96.tmp.hdmp
[2011/12/13 09:04:00 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER92AD.tmp.WERInternalMetadata.xml
[2011/12/13 09:04:00 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER92BD.tmp.hdmp
[2011/12/12 07:09:34 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WER9405.tmp.hdmp
[2012/06/25 13:48:23 | 000,002,954 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERA37F.tmp.WERInternalMetadata.xml
[2012/06/25 13:48:23 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERA3BE.tmp.hdmp
[2011/11/10 19:17:19 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB200.tmp.WERInternalMetadata.xml
[2011/11/13 07:14:38 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB223.tmp.WERInternalMetadata.xml
[2011/11/13 07:14:38 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB224.tmp.hdmp
[2011/11/10 19:17:20 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB367.tmp.hdmp
[2010/06/23 19:24:43 | 012,894,686 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB507.tmp.hdmp
[2011/09/19 14:50:09 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB8EB.tmp.WERInternalMetadata.xml
[2011/09/19 14:50:09 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERB959.tmp.hdmp
[2011/06/22 19:19:47 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBB3D.tmp.WERInternalMetadata.xml
[2011/06/22 19:19:47 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBB6D.tmp.hdmp
[2011/03/28 21:29:01 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBCFD.tmp.WERInternalMetadata.xml
[2011/03/28 21:29:01 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBCFE.tmp.hdmp
[2011/01/28 14:05:56 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBD94.tmp.WERInternalMetadata.xml
[2011/01/28 14:05:56 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERBE12.tmp.hdmp
[2010/06/23 19:24:43 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERC3DD.tmp.mdmp
[2011/12/16 11:51:07 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERC746.tmp.WERInternalMetadata.xml
[2011/12/16 11:51:07 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERC766.tmp.hdmp
[2011/06/22 02:17:32 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERCE06.tmp.WERInternalMetadata.xml
[2011/06/22 02:17:32 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERCE27.tmp.hdmp
[2011/03/25 09:55:37 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERD595.tmp.WERInternalMetadata.xml
[2011/03/25 09:55:37 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERD5A6.tmp.hdmp
[2011/02/27 21:52:12 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERD5D5.tmp.WERInternalMetadata.xml
[2011/02/27 21:52:12 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERD643.tmp.hdmp
[2011/02/27 22:09:05 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERDCE6.tmp.WERInternalMetadata.xml
[2011/02/27 22:09:05 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERDD06.tmp.hdmp
[2011/10/23 03:03:19 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERDF41.tmp.WERInternalMetadata.xml
[2011/10/23 03:03:19 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERDFEE.tmp.hdmp
[2011/12/23 12:33:18 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERE0A5.tmp.hdmp
[2010/12/19 06:57:58 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF25A.tmp.WERInternalMetadata.xml
[2010/12/19 06:57:58 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF25B.tmp.hdmp
[2011/02/07 00:28:35 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF2E7.tmp.WERInternalMetadata.xml
[2011/02/07 00:28:35 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF365.tmp.hdmp
[2011/12/11 06:44:19 | 000,002,952 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF759.tmp.WERInternalMetadata.xml
[2011/12/11 06:44:19 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERF76A.tmp.hdmp
[2011/06/21 00:17:52 | 000,002,476 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERFE93.tmp.WERInternalMetadata.xml
[2011/06/21 00:17:52 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERFEA4.tmp.hdmp
[2010/11/21 04:47:25 | 000,002,912 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERFEFE.tmp.WERInternalMetadata.xml
[2010/11/21 04:47:25 | 000,000,000 | ---- | M] () -- C:\Windows\system32\config\systemprofile\WERFF8B.tmp.hdmp
[2011/04/12 04:01:11 | 000,000,273 | ---- | M] () -- C:\Windows\system32\config\systemprofile\wmsetup.log
[939 C:\Windows\system32\config\systemprofile\*.tmp files -> C:\Windows\system32\config\systemprofile\*.tmp -> ]

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/03/15 15:45:34 | 000,000,221 | -HS- | M] () -- C:\Users\Bisho\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\tasks\*.* >
[2012/06/30 15:22:04 | 000,000,216 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2012/06/30 15:22:02 | 000,000,218 | ---- | M] () -- C:\Windows\tasks\AutoKMSDaily.job
[2012/06/20 12:29:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001Core.job
[2012/06/30 15:29:02 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001UA.job
[2012/06/30 15:21:50 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/06/30 15:44:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/06/28 23:23:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001Core.job
[2012/06/30 15:23:10 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2546657983-1106873551-1639024377-1001UA.job
[2012/06/30 15:21:26 | 000,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2012/06/08 21:08:06 | 000,032,612 | ---- | M] () -- C:\Windows\tasks\SCHEDLGU.TXT
< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >

< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >

< %PROGRAMFILES%\Internet Explorer\*.tmp >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %USERPROFILE%\My Documents\*.exe >

< %USERPROFILE%\*.exe >

< %systemroot%\ADDINS\*.* >
[2009/06/11 00:20:04 | 000,000,802 | ---- | M] () -- C:\Windows\ADDINS\FXSEXT.ecf

< %systemroot%\assembly\*.bak2 >

< %systemroot%\Config\*.* >

< %systemroot%\REPAIR\*.bak2 >

< %systemroot%\SECURITY\Database\*.sdb /x >

< %systemroot%\SYSTEM\*.bak2 >

< %systemroot%\Web\*.bak2 >

< %systemroot%\Driver Cache\*.* >

< %PROGRAMFILES%\Mozilla Firefox\0*.exe >

< %ProgramFiles%\Microsoft Common\*.* >

< %ProgramFiles%\TinyProxy. >

< %USERPROFILE%\Favorites\*.url /x >

< %systemroot%\system32\*.bk >

< %systemroot%\*.te >
 
< %systemroot%\system32\system32\*.* >
[2011/09/16 05:54:44 | 000,143,360 | ---- | M] () -- C:\Windows\system32\system32\3DAudio.ax
[2011/09/16 05:54:44 | 000,014,336 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\system32\avrt.dll
[2011/09/16 05:54:44 | 000,974,848 | ---- | M] () -- C:\Windows\system32\system32\cis-2.4.dll
[2011/09/16 05:54:44 | 000,081,920 | ---- | M] () -- C:\Windows\system32\system32\issacapi_bs-2.3.dll
[2011/09/16 05:54:44 | 000,065,536 | ---- | M] () -- C:\Windows\system32\system32\issacapi_pe-2.3.dll
[2011/09/16 05:54:44 | 000,057,344 | ---- | M] () -- C:\Windows\system32\system32\issacapi_se-2.3.dll
[2011/09/16 05:54:44 | 000,045,056 | ---- | M] ((주) 마크애니) -- C:\Windows\system32\system32\MACXMLProto.dll
[2011/09/16 05:54:44 | 000,118,784 | ---- | M] ((주)마크애니) -- C:\Windows\system32\system32\MaDRM.dll
[2011/09/16 05:54:44 | 000,049,152 | ---- | M] ((주) 마크애니) -- C:\Windows\system32\system32\MaJGUILib.dll
[2012/05/01 09:01:12 | 000,045,320 | ---- | M] (MARKANY) -- C:\Windows\system32\system32\MAMACExtract.dll
[2011/09/16 05:54:44 | 000,024,576 | ---- | M] ((주)마크애니) -- C:\Windows\system32\system32\MASetupCleaner.exe
[2011/09/16 05:54:44 | 000,045,056 | ---- | M] ((주) 마크애니) -- C:\Windows\system32\system32\MaXMLProto.dll
[2011/09/16 05:54:44 | 000,382,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\system32\mfplat.dll
[2011/09/16 05:54:44 | 000,057,344 | ---- | M] (Marktek) -- C:\Windows\system32\system32\MK_Lyric.dll
[2011/09/16 05:54:44 | 000,245,760 | ---- | M] (Teruten Inc.) -- C:\Windows\system32\system32\MSCLib.dll
[2011/09/16 05:54:44 | 000,155,648 | ---- | M] (Teruten Inc.) -- C:\Windows\system32\system32\MSFLib.dll
[2011/09/16 05:54:44 | 000,352,256 | ---- | M] (Sample Corporation) -- C:\Windows\system32\system32\MSLUR71.dll
[2011/09/16 05:54:44 | 000,413,696 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\system32\msvcp60.dll
[2011/09/16 05:54:44 | 000,040,960 | ---- | M] (Telechips Inc.,) -- C:\Windows\system32\system32\MTTELECHIP.dll
[2011/09/16 05:54:44 | 000,057,344 | ---- | M] (Marktek Inc.) -- C:\Windows\system32\system32\MTXSYNCICON.dll
[2011/09/16 05:54:44 | 000,135,168 | ---- | M] (Musiccity Co.Ltd.) -- C:\Windows\system32\system32\muzaf1.dll
[2011/09/16 05:54:44 | 000,491,520 | ---- | M] (Musiccity Co.Ltd.) -- C:\Windows\system32\system32\muzapp.dll
[2011/09/16 05:54:44 | 000,172,032 | ---- | M] (Musiccity Co.Ltd.) -- C:\Windows\system32\system32\muzapp.exe
[2011/09/16 05:54:44 | 000,569,344 | ---- | M] ((c) MusicCity) -- C:\Windows\system32\system32\muzdecode.ax
[2011/09/16 05:54:44 | 000,122,880 | ---- | M] ((c) MUSICCITY) -- C:\Windows\system32\system32\muzeffect.ax
[2011/09/16 05:54:44 | 000,110,592 | ---- | M] ((c) MusicCity) -- C:\Windows\system32\system32\muzmp4sp.ax
[2011/09/16 05:54:44 | 000,131,072 | ---- | M] ((c) MusicCity) -- C:\Windows\system32\system32\muzmpgsp.ax
[2011/09/16 05:54:44 | 000,258,048 | ---- | M] ((c) PeeringPortal) -- C:\Windows\system32\system32\muzoggsp.ax
[2011/09/16 05:54:44 | 000,200,704 | ---- | M] ( (c) MusicCity) -- C:\Windows\system32\system32\muzwmts.dll
[2011/09/16 05:54:44 | 000,023,040 | ---- | M] (Microsoft Corporation) -- C:\Windows\system32\system32\psapi.dll

< %ALLUSERSPROFILE%\*.dat /x >
[2010/02/04 04:31:38 | 000,000,088 | RHS- | M] () -- C:\ProgramData\5019F804B8.sys
[2011/02/25 07:22:30 | 000,000,088 | RHS- | M] () -- C:\ProgramData\9B8B3F0050.sys
[2010/02/04 04:35:56 | 000,000,088 | RHS- | M] () -- C:\ProgramData\A522B7E563.sys
[2011/01/29 05:45:47 | 008,673,792 | ---- | M] () -- C:\ProgramData\atscie.msi
[2011/07/17 00:02:25 | 000,001,284 | ---- | M] () -- C:\ProgramData\hpzinstall.log
[2011/10/27 21:33:16 | 000,013,356 | -HS- | M] () -- C:\ProgramData\KGyGaAvL.sys
[2011/08/04 03:21:03 | 000,001,908 | ---- | M] () -- C:\ProgramData\LmeUSB.log
[2011/08/04 03:21:03 | 000,001,909 | ---- | M] () -- C:\ProgramData\LSDmbTH.log
[2012/05/19 01:09:57 | 000,005,023 | ---- | M] () -- C:\ProgramData\mxnhytee.feu
[2012/06/03 14:36:23 | 000,000,418 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/08/04 03:21:04 | 000,001,946 | ---- | M] () -- C:\ProgramData\PipShareTuner.log
[2011/08/05 04:38:26 | 000,000,471 | ---- | M] () -- C:\ProgramData\ReclaiMe.config
[2012/04/15 01:47:13 | 000,001,695 | ---- | M] () -- C:\ProgramData\SystemInformation.txt
[2011/12/31 00:41:28 | 000,000,346 | ---- | M] () -- C:\ProgramData\__FileUploader.log

< %systemroot%\system32\drivers\*.rmv >

< dir /b "%systemroot%\system32\*.exe" | find /I " " /c >
Launch JAF..exe

< dir /b "%systemroot%\*.exe" | find /I " " /c >
ATA Live Update.exe

< %PROGRAMFILES%\Microsoft\*.* >

< %systemroot%\System32\Wbem\proquota.exe >

< %PROGRAMFILES%\Mozilla Firefox\*.dat >

< %USERPROFILE%\Cookies\*.txt /x >

< %SystemRoot%\system32\fonts\*.* >

< %systemroot%\system32\winlog\*.* >

< %systemroot%\system32\Language\*.* >

< %systemroot%\system32\Settings\*.* >

< %systemroot%\system32\*.quo >

< %SYSTEMROOT%\AppPatch\*.exe >

< %SYSTEMROOT%\inf\*.exe >

< %SYSTEMROOT%\Installer\*.exe >

< %systemroot%\system32\config\*.bak2 >

< %systemroot%\system32\Computers\*.* >

< %SystemRoot%\system32\Sound\*.* >

< %SystemRoot%\system32\SpecialImg\*.* >

< %SystemRoot%\system32\code\*.* >

< %SystemRoot%\system32\draft\*.* >

< %SystemRoot%\system32\MSSSys\*.* >

< %ProgramFiles%\Javascript\*.* >

< %systemroot%\pchealth\helpctr\System\*.exe /s >

< %systemroot%\Web\*.exe >

< %systemroot%\system32\msn\*.* >

< %systemroot%\system32\*.tro >

< %AppData%\Microsoft\Installer\msupdates\*.* >

< %ProgramFiles%\Messenger\*.* >
[2008/05/21 14:01:58 | 000,111,342 | ---- | M] () -- C:\Program Files\Messenger\2kmsgr5.chm
[2008/06/02 16:13:48 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\custsat.dll
[2008/05/21 14:04:24 | 000,004,821 | ---- | M] () -- C:\Program Files\Messenger\logo.gif
[2008/05/21 14:04:24 | 000,007,047 | ---- | M] () -- C:\Program Files\Messenger\lvback.gif
[2008/06/02 21:41:36 | 000,082,968 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\Msgsc.dll
[2008/06/02 21:42:16 | 000,192,024 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msgslang.dll
[2008/06/02 21:44:10 | 000,209,944 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msimmsgr.dll
[2008/06/02 21:42:36 | 000,205,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msimnetc.dll
[2008/06/02 21:44:28 | 001,660,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\Msmsgs.exe
[2008/06/02 16:13:50 | 000,348,160 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\msvcr71.dll
[2008/05/21 14:04:24 | 000,002,882 | ---- | M] () -- C:\Program Files\Messenger\newalert.wav
[2008/05/21 14:04:24 | 000,006,156 | ---- | M] () -- C:\Program Files\Messenger\newemail.wav
[2008/05/21 14:04:24 | 000,006,160 | ---- | M] () -- C:\Program Files\Messenger\online.wav
[2008/06/02 21:43:48 | 000,217,624 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Messenger\rtcimsp.dll
[2008/05/21 14:04:24 | 000,004,454 | ---- | M] () -- C:\Program Files\Messenger\type.wav
[2008/05/21 14:03:00 | 000,120,233 | ---- | M] () -- C:\Program Files\Messenger\xpmsgr.chm

< %systemroot%\system32\systhem32\*.* >

< %systemroot%\system\*.exe >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\LastSuccessTime /rs >

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\$NtUninstallKB13182$] -> Error: Cannot create file handle -> Unknown point type
< End of report >

Extras.Txt:
OTL Extras logfile created on: 6/30/2012 4:02:00 PM - Run 1
OTL by OldTimer - Version 3.2.53.0 Folder = D:\My data\Desktop\Desktop\OTL
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.24 Gb Total Physical Memory | 1.83 Gb Available Physical Memory | 56.45% Memory free
6.48 Gb Paging File | 5.19 Gb Available in Paging File | 80.06% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 97.80 Gb Total Space | 24.67 Gb Free Space | 25.23% Space Free | Partition Type: NTFS
Drive D: | 200.19 Gb Total Space | 25.08 Gb Free Space | 12.53% Space Free | Partition Type: NTFS
Drive E: | 492.06 Gb Total Space | 392.46 Gb Free Space | 79.76% Space Free | Partition Type: NTFS
Drive F: | 439.45 Gb Total Space | 323.99 Gb Free Space | 73.73% Space Free | Partition Type: NTFS

Computer Name: TOMASADISON | User Name: Bisho | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
jsfile [edit] -- "C:\Program Files\Macromedia\Dreamweaver 8\dreamweaver.exe" "%1" (Macromedia, Inc.)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [Browse with Corel PaintShop Pro X4] -- "c:\Program Files\Corel\Corel PaintShop Pro X4\Corel PaintShop Pro.exe" "%L" (Corel, Inc.)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [runas] -- cmd.exe /c takeown /f "%1" /r /d y && icacls "%1" /grant administrators:F /t (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"UacDisableNotify" = 1
"AutoUpdateDisableNotify" = 1
"AntiSpyWareDisableNotify" = 1
"InternetSettingsDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{00580795-581C-4587-B9F2-37320D7AB37F}" = Corel PaintShop Pro X4
"_{AA902C31-B49D-4608-BCCF-2519EB77722D}" = Corel VideoStudio Pro X4
"{00580795-581C-4587-B9F2-37320D7AB37F}" = ICA
"{006CAAEF-CA96-4181-AC22-FE56D61432E4}" = PSPPContent
"{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}" = Corel PaintShop Pro X4
"{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}" = IPM_PSP_COM
"{00D13418-7DDF-4D3D-A237-E297B103BB6B}" = Setup
"{00D74A7A-F7AD-4D00-ABD2-0973836292C7}" = PSPPHelp
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{0299DF57-FF2E-42C6-A4D7-9480E537D191}" = Pinnacle Creative Pack Volume 2
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{040FF9BD-17BE-427B-85DD-67694FB8F786}" = Badoo Desktop
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0837A661-FEC3-48B3-876C-91E7D32048A9}" = Macromedia Dreamweaver 8
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{105CFC7C-6992-11D5-BD9D-000102C10FD8}" = LizardTech DjVu Control
"{107254A0-0ADF-11D4-9397-00D0B7020B38}" =
"{1170D24F-42B7-40CF-AA1B-6395CE562354}" = Gears of War
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}" = BlackBerry Device Software Updater
"{15663E2F-4C49-4949-9490-8806050654E0}" = Avid Studio Bonus Content
"{158F46C5-768B-45E4-9EF8-E0F3E2889D0B}" = EmbFlashPlugin
"{17504ED4-DB08-40A8-81C2-27D8C01581DA}" = Windows Live Remote Service Resources
"{1845470B-EB14-4ABC-835B-E36C693DC07D}" = Skype™ 5.9
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{19A4A990-5343-4FF7-B3B5-6F046C091EDF}" = Windows Live Remote Client
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{227E8782-B2F4-4E97-B0EE-49DE9CC1C0C0}" = Windows Live Remote Service
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{23E445D5-FD83-4C50-A211-EB26A2975317}" = Adobe Flash Professional CS5.5
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java(TM) 6 Update 33
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A83C813-AB00-475C-975D-8F5127108CCB}" = Assassin's Creed Revelations
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"{2FF5FC32-B2AC-4505-A381-350670AA46D4}" = Fuse Drivers
"{31A559C1-9E4D-423B-9DD3-34A6C5398752}" = HTC BMP USB Driver
"{32A3A4F4-B792-11D6-A78A-00B0D0160260}" = Java(TM) SE Development Kit 6 Update 26
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{3990E632-42C3-4A25-ADFF-1101E3D6DD47}" = VSClassic
"{3C0983B6-C10A-4956-9131-666BE7AEFE5D}" = Flickr4Writer
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3DAD83B9-4C8B-4AC6-BF5E-B9FB181CCBE8}" = Nokia Service Tool Drivers
"{3EB745BA-194F-4475-9164-B20BB2172395}" = Adobe Photoshop CS5
"{3FAD68D9-1FA1-4871-9ADF-9151D969E943}" = Activision(R)
"{41313863-5170-4D7E-AD60-3CDF4DEBA81F}" = Nokia PC Suite
"{41E496B5-47F4-11D6-9BBB-00E0987BB2CD}" = LG webpro Driver
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{464B3406-A4D0-4914-910F-7CA4380DCC13}" = Windows Live Remote Client Resources
"{47FA2C44-D148-4DBC-AF60-B91934AA4842}" = Adobe AIR
"{49C14B93-58AD-4178-B52C-750D54CE618D}" = SaxoTrader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A423411-E28A-4A13-BDB0-8E8BC42FFA29}" = HTC Sync
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4AA68A73-DB9C-439D-9481-981C82BD008B}" = Nokia Connectivity Cable Driver
"{4B4E8814-F682-4197-8F4B-E9FFC6F08977}" = System Requirements Lab for Intel
"{4BBC7CF4-DCAE-494E-99E5-891553653208}" = Nokia Firmware RM-495 'DP20_07.97'
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{520A8627-E1B7-4808-8F04-03A013CBBD10}" = Noise Reduction Plug-in 2.0i
"{521AAD14-5030-44BB-8B0E-5CE65FCE57E0}" = InterVideo DeviceService
"{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}" = Macromedia Extension Manager
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5BD6DE00-9A77-4A63-801C-AEDD38C5176B}" = TagCreator for Windows Live Writer
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{66E61920-3CC7-469A-BBB5-FDC7BD4EFB99}" = WinUSB Drivers x86
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{697E41EA-AEBE-4B5F-884E-87B5CD6C70AC}" = 네이트온
"{6A519E1D-44B8-4DC9-BC30-552C68D41C01}" = Avid Studio Plugins
"{6AD9F5F3-5BD0-4000-BD9C-B536CF86D988}" = iTunes
"{6AE35C55-F02A-41EE-B694-8F2706FE4819}" = NOKIA 3806 USB DRIVER Ver:1.5
"{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}" = MSVC80_x86_v2
"{6DB7AD00-F781-11DF-9EEF-001279CD8240}" = Google Earth
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73EC658D-A1C6-40CA-8E86-E05821BAACE7}" = Java DB 10.6.2.1
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7B2CC3DF-64FA-44AE-8F57-B0F915147E4F}_is1" = Need For Speed™ World
"{7B3F0113-E63C-4D6D-AF19-111A3165CCA2}" = Text-To-Speech-Runtime
"{7B542FE3-0A01-482A-9080-A5F531D47E02}" = Duke Nukem Forever
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7EE8ED57-682B-4AB0-860C-2E079BCD90B1}" = Pinnacle Creative Pack Volume 1
"{8019FC33-098C-424F-AEA5-D924BACE69C5}" = Microsoft Security Client
"{80A17ED7-059E-40FF-B5D6-F37C737CA693}" = Adobe Photoshop Lightroom 4
"{82696435-8572-4D8B-A230-D1AA567D0F0F}" = Command & Conquer™ 4 Tiberian Twilight
"{82EF29B1-9B60-4142-A155-0599216DD053}" = LightScribe System Software
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{87686C21-8A15-4b4d-A3F1-11141D9BE094}" = Battlefield Play4Free
"{87DF5956-A327-4304-8338-8E2B0AAB843E}" = BlackBerry Desktop Software 6.0.2
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DA37A5A-55BF-47B3-A7F7-09FB3F3CF965}" = BlackBerry Device Software v5.0.0 for the BlackBerry 8520 smartphone
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8F1ADE4D-EFAC-4F5A-B346-23C2687FAF50}" = Apple Mobile Device Support
"{90140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{92D1CEBC-7C72-4ECF-BFC6-C131EF3FE6A7}" = Nokia Suite
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{92EC1A84-7FFC-42DF-A8F6-79C21C4765A5}" = Nero DiscCopy Gadget 10
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{943A8D28-80D6-41DC-AE94-81FEB42041BF}" = System Requirements Lab CYRI
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v4.0
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C1E105E-7EFB-4A57-917D-8859E296E153}" = Alan Wake
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2AA4204-C05A-4013-888A-AD153139297F}" = PC Connectivity Solution
"{A2C59F3C-4039-4B92-B2DD-704A7C5F9DC0}" = Fuse Drivers
"{A3FEC306-FBFF-4B0D-95B9-F9C67C65079E}" = Brother MFL-Pro Suite DCP-135C
"{A567895C-1D23-48ED-BE83-FB3ED7D30442}" = IPM_VS_Pro
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A8AF728F-2EE8-4322-96B3-656CAD1F7805}" = Facebook Messenger 2.1.4554.0
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA902C31-B49D-4608-BCCF-2519EB77722D}" = ICA
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-1033-F400-7760-000000000005}" = Adobe Acrobat X Pro - English, Français, Deutsch
"{AE5FFCC2-664B-43BF-BA66-E6C8F252E8FD}" = Nokia Firmware RM-409 'EMEA_05.16'
"{AEE93272-FF47-4B20-BFB4-D80D759AA1E3}" = Nokia Care Suite 5.0
"{AF111648-99A1-453E-81DD-80DBBF6DAD0D}" = MSVC90_x86
"{B0125BEB-6731-43FA-88DA-B64D7BD3AD2D}" = VSPro
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B23F12D4-17DE-453A-B1F4-55E501FE0EBF}" = BBSAK
"{B2EC4A38-B545-4A00-8214-13FE0E915E6D}" = Advertising Center
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 275.33
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 275.33
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.3.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{B35DC076-CEF2-4631-9EF7-45380E27C841}" = Avid Studio
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B84ECBE1-6ED5-4E86-B4AB-DF46D342411F}" = Share
"{B87FAC24-973D-4A4F-AFC4-555FB95B32DB}" = PureHD
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{B8A817D7-AE0F-42BA-AEB9-B5F1F3EFB7AF}" = Sound Forge Pro 10.0
"{B9707430-2F34-40B6-ADC2-48A2BA29D46A}" = WLW Bit.ly
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BA3DD2F2-6818-4720-89EB-E42F0B75BFBE}" = Fuse Drivers FPS-xx
"{BD5CA0DA-71AD-43DA-B19E-6EEE0C9ADC9A}" = Nero ControlCenter
"{BE2ED609-7C07-4F6B-8E83-3800F8A133D6}" = PhotoPresets Wow Effects for Lightroom
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C4778408-3268-45CE-AE15-772D1739A1F1}" = VIO
"{C6017EEA-9E51-4129-84BA-EFA9520E69D8}" = Common
"{C6150D8A-86ED-41D3-87BB-F3BB51B0B77F}" = Windows Live ID Sign-in Assistant
"{CA31F991-DBD2-4DE1-B6D2-30105F23CBBC}" = RapeLay
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CC4C7E9B-4B26-4D8D-8076-40CF708A9FA4}" = Contents
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF40DA70-3021-482C-BE70-2CCE26A2BF5C}" = Civilization V
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D07F85DE-22F1-4FB4-B3D1-402FD22C4870}" = DeviceIO
"{D089378C-9E18-4462-AB6F-D60AB33DF2A0}" = Phoenix Service Software
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D1E44702-21F5-4918-B8A3-6D126D5BD33C}" = Windows Messenger 5.1
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D43014FB-A1BD-4D76-8921-A14CC1E02AEA}_is1" = CastleVilleBot
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D68897FC-7E8D-4849-819A-726B2489713C}" = ISCOM
"{D8D9BCF5-0F5F-4D3F-8427-64B7632F93BE}" = Setup
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D98D2FD8-26FB-4B92-B2B8-75DE8FB28FC4}_is1" = FLV to MP4 Converter 2009.2.20
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD 10
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}" = AVerTV
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3B64CC5-C011-40C0-92BC-7316CD5E5688}" = Microsoft_VC100_CRT_SP1_x86
"{E3B67F67-F1BA-4709-96CE-72E92A8BF5E3}" = hpg2410
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E47D2974-AA5E-FlvMP3-B984-3CA48DFA2849}_is1" = FLAV FLV to MP3 Converter 2.58.15
"{E5B04674-1885-4B08-BAE7-ECDEC1F84677}" = HP Scanjet G2410 and 2400
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E8A80433-302B-4FF1-815D-FCC8EAC482FF}" = Nero Installer
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F09EF8F2-0976-42C1-8D9D-8DF78337C6E3}" = Sony PC Companion 2.10.030
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE112F6C-D282-4547-BAC7-EB4745615592}" = Nokia Firmware RM-356 EMEA
"{FE3997D3-6B56-4AC4-A99C-9DDFC45359BF}" = TuneUp Utilities Language Pack (en-US)
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FFF918DD-4C0E-49B6-8C52-1D3424651B24}" = Nokia Data Package Manager
"1AB1FAC2FD03A2E5AD55CD28ABCC3C8CE34F0A60" = Windows Driver Package - SarasSoft UFSx Driver Package (05/18/2011 3.08.14)
"504244733D18C8F63FF584AEB290E3904E791693" = Windows Driver Package - Nokia pccsmcfd (08/22/2008 7.0.0.0)
"72A50F48CC5601190B9C4E74D81161693133E7F7" = Windows Driver Package - Nokia Modem (02/25/2011 7.01.0.9)
"AAA Logo 2008_is1" = AAA Logo 2008 2.10
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Akamai" = Akamai NetSession Interface Service
"Allscoop RSS Submit Pro 1.0" = Allscoop RSS Submit Pro 1.0
"Android SDK Tools" = Android SDK Tools
"AVerMedia A816 series driver" = AVerMedia A816 series driver 2.0.0.124
"AVerMedia Media Center Plug-ins" = AVerMedia Media Center Plug-ins 2.0.10.0
"BlackBerry_Desktop" = BlackBerry Desktop Software 6.0.2
"CCleaner" = CCleaner
"Charles_XK72" = Charles
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cheat Engine 6.1_is1" = Cheat Engine 6.1
"DivX Setup" = DivX Setup
"E0AC723A3DE3A04256288CADBBB011B112AED454" = Windows Driver Package - Nokia Modem (02/25/2011 4.7)
"FE6F385A54D12F7C8459466625BE8A478BA59D47" = Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (12/06/2010 4.0.0000.00000)
"Fiddler2" = Fiddler2
"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0
"ImgBurn" = ImgBurn
"InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{E28B1E6F-E0AA-4228-AB89-DB4A0C89D426}" = AVerTV
"InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}" = CyberLink MediaEspresso
"Internet Download Manager" = Internet Download Manager
"IrfanView" = IrfanView (remove only)
"KLiteCodecPack_is1" = K-Lite Codec Pack 8.9.2 (Full)
"Knoll Light Factory EZ Studio" = Knoll Light Factory EZ Studio
"Magic Bullet Looks Studio" = Magic Bullet Looks Studio
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400
"Messenger Plus!" = Messenger Plus! 5
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials Prerelease
"MozBackup" = MozBackup 1.5.1
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSTTS" = Microsoft Text-to-Speech Engine 4.0 (English)
"Nokia PC Suite" = Nokia PC Suite
"Nokia Suite" = Nokia Suite
"NVIDIA StereoUSB Driver" = NVIDIA 3D Vision Controller Driver
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Office14.PROPLUS" = Microsoft Office Professional Plus 2010
"PalTalk8.2" = Paltalk Messenger
"Pamela" = Pamela Pro 4.6
"PC Wizard 2010_is1" = PC Wizard 2010.1.96
"Phoenix Service Software 2011.46.002.47246_is1" = Phoenix Service Software 2011.46.002.47246
"Picasa 3" = Picasa 3
"Plants vs. Zombies" = Plants vs. Zombies
"ProgDVB" = ProgDVB
"PunkBusterSvc" = PunkBuster Services
"Red Giant ToonIt Studio" = Red Giant ToonIt Studio
"ResourceHacker_is1" = Resource Hacker Version 3.6.0
"SecurityKISS Certificate_is1" = v0.2.2
"SMBus" = Intel(R) SMBus
"ST6UNST #1" = Golden Al-Wafi Translator
"SubtitleWorkshop" = Subtitle Workshop 2.51
"TeamViewer 7" = TeamViewer 7
"Trapcode 3DStroke Studio" = Trapcode 3DStroke Studio
"Trapcode Particular Studio" = Trapcode Particular Studio
"Trapcode Shine Studio" = Trapcode Shine Studio
"Universal Extractor_is1" = Universal Extractor 1.6
"UnLock Root" = UnLock Root 2.31
"uTorrent" = µTorrent
"Virtual Piano_is1" = Virtual Piano 3.0
"VLC media player" = VLC media player 2.0.1
"WebcamMax" = WebcamMax
"Winamp" = Winamp
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"WinPcapInst" = WinPcap 4.1.1
"WinRAR archiver" = WinRAR 4.00 (32-bit)
"Xilisoft DVD Ripper Ultimate 6" = Xilisoft DVD Ripper Ultimate 6
"Yahoo! Messenger" = Yahoo! Messenger
"Zekr" = Zekr

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"FileZilla Client" = FileZilla Client 3.5.3
"Google Chrome" = Google Chrome
"IMVU Avatar chat client software BETA" = IMVU Avatar Chat Software
"MyFreeCodec" = MyFreeCodec
"Tango" = Tango
"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/28/2012 4:22:58 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/28/2012 4:22:58 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/28/2012 4:47:32 PM | Computer Name = TomasAdison | Source = Brother BrLog | ID = 1001
Description = CTLCN BrtCTLCN: [2012/06/28 23:47:32.391]: [00005988]: brccFCtl.dll:
### ERROR ### Failed Make Folder "F:\Pictures\ControlCenter3\Scan"

Error - 6/29/2012 6:46:15 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 6:46:15 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 6:52:04 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 7:14:14 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 7:14:14 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 7:14:15 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 7:14:17 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

Error - 6/29/2012 7:15:25 PM | Computer Name = TomasAdison | Source = Microsoft-Windows-CAPI2 | ID = 4107
Description = Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>
with error: A required certificate is not within its validity period when verifying
against the current system clock or the timestamp in the signed file. .

[ System Events ]
Error - 6/29/2012 8:42:11 PM | Computer Name = TomasAdison | Source = DCOM | ID = 10010
Description =

Error - 6/30/2012 8:21:30 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 6/30/2012 8:21:32 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7000
Description = The FLEXnet Licensing Manager for Adobe Products service failed to
start due to the following error: %%3

Error - 6/30/2012 8:21:33 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891

Error - 6/30/2012 8:21:38 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7000
Description = The Power Control [2009/11/07 22:59:05] service failed to start due
to the following error: %%3

Error - 6/30/2012 8:21:38 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Resource
Publication service which failed to start because of the following error: %%-2147024891

Error - 6/30/2012 8:21:43 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
cdrom

Error - 6/30/2012 8:21:45 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 6/30/2012 8:22:04 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7001
Description = The HomeGroup Provider service depends on the Function Discovery Resource
Publication service which failed to start because of the following error: %%-2147024891

Error - 6/30/2012 8:22:04 AM | Computer Name = TomasAdison | Source = Service Control Manager | ID = 7023
Description = The Function Discovery Resource Publication service terminated with
the following error: %%-2147024891


< End of report >
 
Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    DRV - File not found [Kernel | System | Stopped] -- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E57A4CF-A0CD-4FC2-94F1-9AA1DE82192E}\MpKsl8ae75fa0.sys -- (MpKsl8ae75fa0)
    DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a0gnhw78)
    IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
    O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: alipay.com ([]https in Trusted sites)
    O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: alisoft.com ([]https in Trusted sites)
    O15 - HKU\S-1-5-21-2546657983-1106873551-1639024377-1001\..Trusted Domains: taobao.com ([]https in Trusted sites)
    O33 - MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\Shell - "" = AutoRun
    O33 - MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\Shell\AutoRun\command - "" = G:\Startme.exe
    O33 - MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\Shell - "" = AutoRun
    O33 - MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\Shell\AutoRun\command - "" = notepad SeaToolsDOSguide.EN.txt
    [2011/02/25 07:18:11 | 000,000,088 | RHS- | C] () -- C:\ProgramData\9B8B3F0050.sys
    [2010/02/04 04:31:36 | 000,000,088 | RHS- | C] () -- C:\ProgramData\5019F804B8.sys
    [2009/11/08 00:13:34 | 000,000,088 | RHS- | C] () -- C:\ProgramData\A522B7E563.sys
    [C:\Windows\$NtUninstallKB13182$] -> Error: Cannot create file handle -> Unknown point type
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.

======================================================

Last scans....

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE SecurityCheck may produce some false warning(s), so leave the results reading to me.

2. Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.


3. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


4. Please run a free online scan with the ESET Online Scanner

  • Disable your antivirus program
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • Accept any security warnings from your browser.
  • Check Scan archives
  • Click Start
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click on List of found threats
  • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • NOTE. If Eset won't find any threats, it won't produce any log.
 
All processes killed
========== OTL ==========
Service MpKsl8ae75fa0 stopped successfully!
Service MpKsl8ae75fa0 deleted successfully!
File C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{5E57A4CF-A0CD-4FC2-94F1-9AA1DE82192E}\MpKsl8ae75fa0.sys not found.
Error: No service named a0gnhw78 was found to stop!
Service\Driver key a0gnhw78 not found.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alipay.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\alisoft.com\ deleted successfully.
Registry key HKEY_USERS\S-1-5-21-2546657983-1106873551-1639024377-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\taobao.com\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{260a83bd-9117-11e1-a50b-0021919148fd}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{260a83bd-9117-11e1-a50b-0021919148fd}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{260a83bd-9117-11e1-a50b-0021919148fd}\ not found.
File G:\Startme.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47ee91e8-5c38-11e0-962b-806e6f6e6963}\ not found.
File notepad SeaToolsDOSguide.EN.txt not found.
C:\ProgramData\9B8B3F0050.sys moved successfully.
C:\ProgramData\5019F804B8.sys moved successfully.
C:\ProgramData\A522B7E563.sys moved successfully.
Unable to remove Unknown point type C:\Windows\$NtUninstallKB13182$
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 2470205 bytes
->Temporary Internet Files folder emptied: 12618737 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5242912 bytes
->Flash cache emptied: 470 bytes

User: All Users

User: Bisho
->Temp folder emptied: 163713587 bytes
->Temporary Internet Files folder emptied: 70166248 bytes
->Java cache emptied: 11760235 bytes
->FireFox cache emptied: 77086953 bytes
->Google Chrome cache emptied: 262816914 bytes
->Apple Safari cache emptied: 877568 bytes
->Flash cache emptied: 110734 bytes

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Desktop

User: nad
->Temp folder emptied: 162535 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Public

User: Trial
->Temp folder emptied: 127588548 bytes
->Temporary Internet Files folder emptied: 61194868 bytes
->Java cache emptied: 513 bytes
->FireFox cache emptied: 82775958 bytes
->Flash cache emptied: 5907 bytes

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 39734 bytes
RecycleBin emptied: 443292 bytes

Total Files Cleaned = 838.00 mb


[EMPTYJAVA]

User: Administrator
->Java cache emptied: 0 bytes

User: All Users

User: Bisho
->Java cache emptied: 0 bytes

User: Default

User: Default User

User: Desktop

User: nad

User: Public

User: Trial
->Java cache emptied: 0 bytes

User: UpdatusUser

Total Java Files Cleaned = 0.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Bisho
->Flash cache emptied: 0 bytes

User: Default

User: Default User

User: Desktop

User: nad

User: Public

User: Trial
->Flash cache emptied: 0 bytes

User: UpdatusUser

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.53.0 log created on 06302012_235511

Files\Folders moved on Reboot...

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
Results of screen317's Security Check version 0.99.24
Windows 7 Service Pack 1 x86 (UAC is disabled!)
Internet Explorer 9
``````````````````````````````
Antivirus/Firewall Check:

Windows Security Center service is not running! This report may not be accurate!
Microsoft Security Essentials Prerelease
[size=1]WMI entry may not exist for antivirus; attempting automatic update.[/size]
```````````````````````````````
Anti-malware/Other Utilities Check:

TuneUp Utilities Language Pack (en-US)
CCleaner
Java(TM) 6 Update 33
Java(TM) SE Development Kit 6 Update 26
Java DB 10.6.2.1
Adobe Flash Player11.3.300.262
Mozilla Firefox (x86 en-US..)
````````````````````````````````
Process Check:
objlist.exe by Laurent

Windows Defender MSMpEng.exe
Microsoft Security Essentials msseces.exe
``````````End of Log````````````
 
Farbar Service Scanner Version: 25-06-2012 01
Ran by Bisho (administrator) on 01-07-2012 at 00:06:50
Running from "D:\Downloads\Programs"
Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************
Internet Services:
============
Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.
Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.
MpsSvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open MpsSvc registry key. The service key does not exist.
Firewall Disabled Policy:
==================
System Restore:
============
System Restore Disabled Policy:
========================
Action Center:
============
wscsvc Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open wscsvc registry key. The service key does not exist.
Windows Update:
============
Windows Autoupdate Disabled Policy:
============================
Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
Checking Start type: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ImagePath: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
Checking ServiceDll: ATTENTION!=====> Unable to open WinDefend registry key. The service key does not exist.
File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
**** End of log ****
 
I will try to make it tonight.. cause I tried but took more than 3 hours and it didn't finished..so I slept and it was 24% and found 3 infected files.
Thanks for everything
 
ESET scan log:

C:\Program Files\Unlockroot\unlockroot.exea variant of Win32/Packed.VProtect.C applicationcleaned by deleting - quarantined
C:\Windows\System32\Launch JAF..exea variant of Win32/Packed.Themida applicationcleaned by deleting - quarantined
D:\$RECYCLE.BIN\S-1-5-21-935990401-1012392228-1743835088-1000\$R8DT869\Net\MsgPlusLive-483.exea variant of Win32/Adware.CiDHelp applicationcleaned by deleting - quarantined
D:\$RECYCLE.BIN\S-1-5-21-935990401-1012392228-1743835088-1000\$R8DT869\Sys Tools\Eset Keyfinder.exeWin32/RiskWare.HackAV.FG applicationcleaned by deleting - quarantined
D:\Downloads\SoftonicDownloader_for_steam.exea variant of Win32/SoftonicDownloader.A applicationcleaned by deleting - quarantined
D:\Downloads\Collection Freeware to Create Bootable USB Drive to Install Windows and Linux\isotousb_setup.exea variant of Win32/TrojanDownloader.FakeAlert.FL trojancleaned by deleting - quarantined
D:\Downloads\Collection Freeware to Create Bootable USB Drive to Install Windows and Linux\WinToFlash_0.7.0048-Beta.exea variant of Win32/InstallCore.W applicationcleaned by deleting - quarantined
D:\Downloads\Picture Collage Maker Pro 3.0.3 build 3402\PictureCollageMakerPro.exea variant of Win32/Injector.HGV trojancleaned by deleting - quarantined
D:\Downloads\Programs\cole2k.media.-.codec.pack.v7.9.5.-advanced-.setup.exea variant of Win32/Toolbar.Widgi applicationcleaned by deleting - quarantined
D:\Downloads\Programs\JAF_Setup_1.98.63_PK_BUG_REMOVED.exea variant of Win32/Packed.Themida applicationcleaned by deleting - quarantined
D:\Downloads\Programs\Setup-MsgPlus-510.exea variant of Win32/MessengerPlus.A applicationdeleted - quarantined
D:\Downloads\Programs\unlockroot23-eng.exea variant of Win32/Packed.VProtect.C applicationcleaned by deleting - quarantined
D:\Downloads\Programs\unlockroot23.exea variant of Win32/Packed.VProtect.C applicationcleaned by deleting - quarantined
D:\Program Files\LIMBO\limbo_lang.exea variant of Win32/Kryptik.EIF trojancleaned by deleting - quarantined
F:\BASHIR\download\Prostitution.FRENCH.XXX.DVDRiP.XViD-LiPS_downloader.exea variant of Win32/ExpressFiles applicationcleaned by deleting - quarantined
 
Very well.

Now, we have several registry keys missing.

Following steps involve registry editing. Please create new restore point before proceeding!!!
How to:
XP - http://support.microsoft.com/kb/948247
Vista and Seven - http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/


Download Seven.zip file from here: http://www.smartestcomputing.us.com/files/download/9-registry-network-keys/
Unzip the file.
You'll find several files inside.
Double click on windefend.reg file and confirm the prompt.
Double click on wscsvc.reg file and confirm the prompt.
Double click on mpssvc.reg file and confirm the prompt.Restart computer.
Post new FSS log.
 
Farbar Service Scanner Version: 25-06-2012 01
Ran by Bisho (administrator) on 02-07-2012 at 02:39:49
Running from "D:\Downloads\Programs"
Microsoft Windows 7 Ultimate Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============
mpsdrv Service is not running. Checking service configuration:
The start type of mpsdrv service is OK.
The ImagePath of mpsdrv service is OK.

MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.


Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============
wscsvc Service is not running. Checking service configuration:
The start type of wscsvc service is OK.
The ImagePath of wscsvc service is OK.
The ServiceDll of wscsvc service is OK.


Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Disabled. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


File Check:
========
C:\Windows\system32\nsisvc.dll => MD5 is legit
C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\Windows\system32\dhcpcore.dll => MD5 is legit
C:\Windows\system32\Drivers\afd.sys => MD5 is legit
C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\system32\dnsrslvr.dll => MD5 is legit
C:\Windows\system32\mpssvc.dll => MD5 is legit
C:\Windows\system32\bfe.dll => MD5 is legit
C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\Windows\system32\SDRSVC.dll => MD5 is legit
C:\Windows\system32\vssvc.exe => MD5 is legit
C:\Windows\system32\wscsvc.dll => MD5 is legit
C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\system32\wuaueng.dll => MD5 is legit
C:\Windows\system32\qmgr.dll => MD5 is legit
C:\Windows\system32\es.dll => MD5 is legit
C:\Windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit


**** End of log ****
 
Back