The only thing I can notice is that the Action Center appears to have been disabled, by the virus I guess, I can't seem to turn it back on (no icon on the taskbar)
Malwarebtyes log followed by OTL. (OTL didn't create an extras log, just the one log, I ran it twice to be sure.)
Malwarebytes Anti-Malware 1.61.0.1400
www.malwarebytes.org
Database version: v2012.07.05.09
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
P :: P-PC [administrator]
06/07/2012 01:41:50
mbam-log-2012-07-06 (01-41-50).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 215330
Time elapsed: 1 minute(s), 25 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 0
(No malicious items detected)
(end)
-------------------------------------------------------------------------------------------------------------------
OTL logfile created on: 06/07/2012 01:46:41 - Run 2
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\P\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
4.00 Gb Total Physical Memory | 2.14 Gb Available Physical Memory | 53.63% Memory free
17.00 Gb Paging File | 14.51 Gb Available in Paging File | 85.36% Paging File free
Paging file location(s): [Binary data over 100 bytes]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 50.00 Gb Total Space | 22.96 Gb Free Space | 45.91% Space Free | Partition Type: NTFS
Drive D: | 309.51 Gb Total Space | 27.05 Gb Free Space | 8.74% Space Free | Partition Type: NTFS
Drive E: | 50.00 Gb Total Space | 18.61 Gb Free Space | 37.21% Space Free | Partition Type: NTFS
Drive F: | 20.00 Gb Total Space | 7.88 Gb Free Space | 39.37% Space Free | Partition Type: NTFS
Drive G: | 300.00 Gb Total Space | 67.38 Gb Free Space | 22.46% Space Free | Partition Type: NTFS
Drive Z: | 1863.01 Gb Total Space | 28.17 Gb Free Space | 1.51% Space Free | Partition Type: NTFS
Computer Name: P-PC | User Name: P | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/07/06 01:42:53 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\P\Downloads\OTL.exe
PRC - [2011/10/17 15:12:52 | 000,013,592 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2011/08/11 17:00:38 | 000,024,576 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\Ctxfihlp.exe
PRC - [2011/08/11 16:54:20 | 001,268,224 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTxfispi.exe
PRC - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
PRC - [2010/01/28 13:47:44 | 001,737,464 | ---- | M] () -- C:\Program Files (x86)\3 Mobile Broadband\3Connect\BecHelperService.exe
PRC - [2006/11/03 11:01:16 | 000,319,488 | ---- | M] (PixArt Imaging Incorporation) -- C:\Windows\PixArt\PAC7302\Monitor.exe
========== Modules (No Company Name) ==========
MOD - [2012/06/23 07:50:16 | 009,459,912 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll
MOD - [2011/08/11 17:00:42 | 000,002,560 | ---- | M] () -- C:\Windows\SysWOW64\CTXFIRES.DLL
MOD - [2009/06/29 10:54:08 | 000,164,864 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2012/03/11 21:13:24 | 002,815,496 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV:
64bit: - [2012/03/09 06:10:20 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:
64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/06/23 07:50:17 | 000,250,056 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe --
(AdobeFlashPlayerUpdateSvc)
SRV - [2012/06/15 23:21:00 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe --
(MozillaMaintenance)
SRV - [2012/05/25 18:08:03 | 000,076,888 | ---- | M] () [On_Demand | Stopped] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/05/03 08:31:10 | 000,158,856 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/04/03 22:02:01 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative
ALchemy AL6 Licensing Service)
SRV - [2012/04/01 20:01:06 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative
Audio Engine Licensing Service)
SRV - [2011/10/17 15:12:52 | 000,013,592 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe --
(IAStorDataMgrSvc) Intel(R)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2010/01/28 13:47:44 | 001,737,464 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\3 Mobile Broadband\3Connect\BecHelperService.exe -- (BecHelperService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe --
(clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2012/05/21 03:00:32 | 000,090,624 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vrtaucbl.sys --
(EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)
DRV:
64bit: - [2012/03/11 21:13:40 | 000,022,696 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\SysNative\drivers\cmderd.sys -- (cmderd)
DRV:
64bit: - [2012/03/09 07:28:08 | 010,857,984 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:
64bit: - [2012/03/09 04:58:02 | 000,328,704 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:
64bit: - [2012/03/01 07:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2011/12/05 20:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:
64bit: - [2011/11/10 18:32:02 | 000,115,272 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV:
64bit: - [2011/10/17 14:55:32 | 000,559,384 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:
64bit: - [2011/10/13 13:06:14 | 000,572,336 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\Uim_IMx64.sys -- (Uim_IM)
DRV:
64bit: - [2011/10/13 13:06:14 | 000,352,816 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\uim_vimx64.sys -- (Uim_VIM)
DRV:
64bit: - [2011/10/13 13:06:14 | 000,059,184 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\uimx64.sys -- (UimBus)
DRV:
64bit: - [2011/09/21 10:25:54 | 000,021,992 | ---- | M] (CPUID) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\cpuz135_x64.sys -- (cpuz135)
DRV:
64bit: - [2011/08/19 10:29:46 | 002,947,968 | ---- | M] (AVerMedia TECHNOLOGIES, Inc. ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVerTM62_x64.sys -- (TRIDCap)
DRV:
64bit: - [2011/08/11 18:50:04 | 001,613,400 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x22k.sys -- (ha20x22k)
DRV:
64bit: - [2011/08/11 18:49:50 | 001,568,344 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)
DRV:
64bit: - [2011/08/11 18:49:40 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)
DRV:
64bit: - [2011/08/11 18:49:28 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)
DRV:
64bit: - [2011/08/11 18:49:18 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)
DRV:
64bit: - [2011/08/11 18:49:06 | 000,179,288 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)
DRV:
64bit: - [2011/08/11 18:48:56 | 000,700,632 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k) Creative
Audio Driver (WDM)
DRV:
64bit: - [2011/08/11 18:48:46 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)
DRV:
64bit: - [2011/08/11 18:48:34 | 001,445,976 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)
DRV:
64bit: - [2011/08/11 18:48:34 | 001,445,976 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)
DRV:
64bit: - [2011/08/11 18:48:22 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)
DRV:
64bit: - [2011/08/11 18:48:22 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)
DRV:
64bit: - [2011/08/11 18:48:12 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)
DRV:
64bit: - [2011/08/11 18:48:12 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)
DRV:
64bit: - [2011/08/01 15:59:06 | 000,045,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:
64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010/11/21 04:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/11/21 04:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/21 04:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:
64bit: - [2010/01/19 12:49:52 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbser6k.sys -- (ZTEusbser6k)
DRV:
64bit: - [2010/01/19 12:49:52 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbnmea.sys -- (ZTEusbnmea)
DRV:
64bit: - [2010/01/19 12:49:52 | 000,119,680 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ZTEusbmdm6k.sys -- (ZTEusbmdm6k)
DRV:
64bit: - [2010/01/19 12:49:52 | 000,011,776 | ---- | M] (ZTE Incorporated) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\massfilter.sys -- (massfilter)
DRV:
64bit: - [2009/09/28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:
64bit: - [2009/08/13 22:10:18 | 000,073,984 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)
DRV:
64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/07/14 01:06:43 | 000,060,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\61883.sys -- (61883)
DRV:
64bit: - [2009/07/14 01:06:43 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\avc.sys -- (Avc)
DRV:
64bit: - [2009/07/14 01:06:42 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\msdv.sys -- (MSDV)
DRV:
64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:
64bit: - [2008/07/04 14:33:32 | 000,115,072 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:
64bit: - [2007/11/08 10:29:22 | 000,527,872 | ---- | M] (PixArt Imaging Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\PAC7302.SYS -- (PAC7302)
DRV:
64bit: - [2005/03/29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2011/06/02 11:08:34 | 000,017,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys -- (cpudrv64)
DRV - [2010/01/28 13:35:24 | 000,010,240 | ---- | M] () [Kernel | Auto | Stopped] -- C:\Windows\SysWOW64\drivers\mdvrmng.sys -- (mdvrmng)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-GB
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 9F D9 8F 85 71 0F CD 01 [binary data]
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&src=IE-
SearchBox&FORM=IE8SRC
IE - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.useDBForOrder: true
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\PDF-XChange PDF Viewer\PDF Viewer
\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\PDF-XChange PDF Viewer\PDF Viewer
\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf: C:\Program Files\PDF-XChange PDF Viewer\PDF Viewer
\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products (Canada) Ltd.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\P\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\P\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/06/15 23:21:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2012/03/31 23:14:52 | 000,000,000 | ---D | M] (No name found) -- C:\Users\P\AppData\Roaming\Mozilla\Extensions
[2012/07/04 18:24:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\P\AppData\Roaming\Mozilla\Firefox\Profiles\a0iekim7.default\extensions
[2012/04/19 18:27:58 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\P\AppData\Roaming\Mozilla\Firefox\Profiles\a0iekim7.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/04/21 20:55:36 | 000,012,703 | ---- | M] () -- C:\Users\P\AppData\Roaming\Mozilla\Firefox\Profiles\a0iekim7.default\searchplugins\imdb.xml
[2012/04/03 19:08:44 | 000,002,057 | ---- | M] () -- C:\Users\P\AppData\Roaming\Mozilla\Firefox\Profiles\a0iekim7.default\searchplugins\youtube-video-search.xml
[2012/03/31 23:14:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/01 13:23:02 | 000,052,184 | ---- | M] () (No name found) -- C:\USERS\P\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\A0IEKIM7.DEFAULT\EXTENSIONS\{9D6218B8-03C7-4B91-AA43-
680B305DD35C}.XPI
[2012/07/04 18:24:11 | 000,743,290 | ---- | M] () (No name found) -- C:\USERS\P\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\A0IEKIM7.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-
2B9879E08C5D}.XPI
[2012/04/01 23:21:03 | 000,113,603 | ---- | M] () (No name found) -- C:\USERS\P\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\A0IEKIM7.DEFAULT\EXTENSIONS\
NOSQUINT@URANDOM.CA.XPI
[2012/06/15 23:21:00 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/03/13 05:38:32 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/03/13 05:38:32 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google

riginalQueryForSuggestion}{google:searchFieldtrialParameter}
sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\P\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\P\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\P\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Java(TM) Platform SE 7 U3 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: PDF-XChange Viewer (Enabled) = C:\Program Files\PDF-XChange PDF Viewer\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\P\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - Extension: YouTube = C:\Users\P\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\P\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: AdBlock = C:\Users\P\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.37_0\
CHR - Extension: RSS Subscription Extension (by Google) = C:\Users\P\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd\2.2.0_0\
CHR - Extension: Gmail = C:\Users\P\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/04 09:31:53 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4:
64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:
64bit: - HKLM..\Run: [PAC7302_Monitor] C:\Windows\PixArt\PAC7302\Monitor.exe (PixArt Imaging Incorporation)
O4:
64bit: - HKLM..\Run: [XboxStat] C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000..\Run: [RESTART_STICKY_NOTES] C:\Windows\System32\StikyNot.exe File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-1648565797-2716223166-2222077553-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O16:
64bit: - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16:
64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 10.3.0)
O16 - DPF: {CAFEEFAC-0017-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0_03-windows-i586.cab (Java Plug-in 1.7.0_03)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{84DF1B0D-0064-4114-A42F-373FE5D796A3}: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FF116AFF-CCAB-480B-8E90-D27EAA7D9727}: DhcpNameServer = 192.168.1.254
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:
64bit: - AppInit_DLLs: (C:\Windows\System32\guard64.dll) - C:\Windows\SysNative\guard64.dll (COMODO)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\guard32.dll) - C:\Windows\SysWOW64\guard32.dll (COMODO)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/07/06 00:51:55 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/07/06 00:47:06 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/07/05 15:39:42 | 000,000,000 | ---D | C] -- C:\FRST
[2012/07/05 02:39:52 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\COMODO
[2012/07/04 23:40:19 | 000,000,000 | ---D | C] -- C:\VritualRoot
[2012/07/04 22:25:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
[2012/07/04 21:00:59 | 000,000,000 | ---D | C] -- C:\Users\P\Desktop\CCE
[2012/07/04 18:49:38 | 000,000,000 | ---D | C] -- C:\Users\P\Desktop\misc
[2012/07/04 10:36:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2012/07/04 10:36:18 | 000,000,000 | ---D | C] -- C:\Program Files\COMODO
[2012/07/04 10:07:36 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\Malwarebytes
[2012/07/04 10:07:33 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/07/04 10:07:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/07/04 10:07:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/07/04 10:07:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/07/04 08:54:30 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/07/04 08:54:30 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/07/04 08:54:30 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/07/04 08:52:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/07/04 08:52:08 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2012/07/03 18:04:21 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\XboxMB
[2012/07/03 18:04:11 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Xenocode
[2012/07/03 18:04:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Xenocode
[2012/07/02 18:17:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft XNA
[2012/07/01 06:37:54 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SWAT 4 - The Stetchkov Syndicate
[2012/07/01 06:37:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWAT 4 - The Stetchkov Syndicate
[2012/07/01 06:29:39 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SWAT 4
[2012/07/01 06:29:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWAT 4
[2012/06/30 17:04:09 | 000,178,800 | ---- | C] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012/06/28 18:22:14 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\SIX_Projects
[2012/06/28 18:20:59 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\six-zsync
[2012/06/28 18:20:59 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\six-updater
[2012/06/28 18:20:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Six Projects
[2012/06/28 18:20:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SIX Projects
[2012/06/28 06:35:31 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\Stella
[2012/06/25 03:58:02 | 000,000,000 | ---D | C] -- C:\Users\P\Documents\capcom
[2012/06/24 23:36:54 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Rockstar Games
[2012/06/24 23:36:50 | 000,000,000 | RH-D | C] -- C:\Users\P\AppData\Roaming\SecuROM
[2012/06/24 17:00:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WindowsFrotz
[2012/06/24 16:52:54 | 000,000,000 | ---D | C] -- C:\Users\P\Documents\Inform
[2012/06/24 16:52:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inform 7
[2012/06/24 16:52:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Inform 7
[2012/06/22 16:25:33 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\mirkes.de
[2012/06/22 04:30:31 | 000,000,000 | ---D | C] -- C:\Users\P\Documents\Games for Windows - LIVE Demos
[2012/06/22 03:40:39 | 000,000,000 | ---D | C] -- C:\Users\P\Documents\WB Games
[2012/06/22 03:40:27 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Downloaded Installations
[2012/06/19 21:40:18 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\GameRanger
[2012/06/18 16:19:52 | 002,947,968 | ---- | C] (AVerMedia TECHNOLOGIES, Inc. ) -- C:\Windows\SysNative\drivers\AVerTM62_x64.sys
[2012/06/18 16:19:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AVerMedia
[2012/06/15 12:50:44 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
[2012/06/11 19:02:16 | 000,071,680 | ---- | C] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2012/06/11 19:02:12 | 000,065,536 | ---- | C] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2012/06/09 16:40:25 | 000,000,000 | ---D | C] -- C:\Program Files\HashTab Shell Extension
[2012/06/08 21:26:30 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Macromedia
[2012/06/08 16:01:17 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Paint.NET
[2012/06/08 16:01:17 | 000,000,000 | ---D | C] -- C:\Program Files\Paint.NET
[2012/06/08 00:29:21 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Roaming\FileZilla
[2012/06/08 00:29:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
[2012/06/08 00:29:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\FileZilla FTP Client
[2012/06/07 14:24:03 | 000,000,000 | ---D | C] -- C:\Windows\en
[2012/06/07 14:22:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2012/06/07 14:21:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live
[2012/06/07 14:19:56 | 000,000,000 | ---D | C] -- C:\Users\P\AppData\Local\Windows Live
[2012/06/07 14:19:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live
[2012/06/06 23:33:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SplitCam
[2012/06/06 19:38:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
[2012/06/06 19:38:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SplitMediaLabs
========== Files - Modified Within 30 Days ==========
[2012/07/06 01:50:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/06 01:41:17 | 000,826,689 | ---- | M] () -- C:\Windows\SysNative\drivers\sfi.dat
[2012/07/06 01:39:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1648565797-2716223166-2222077553-1000UA.job
[2012/07/06 00:58:43 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 00:58:43 | 000,020,496 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 00:57:31 | 001,562,556 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/07/06 00:57:31 | 000,570,340 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/07/06 00:57:31 | 000,006,206 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/07/06 00:51:33 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/07/06 00:51:18 | 3220,504,576 | -HS- | M] () -- C:\hiberfil.sys
[2012/07/06 00:50:22 | 000,062,308 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000005-00000000-00000000-00001102-0000000B-00431102}.rfx
[2012/07/06 00:50:22 | 000,062,308 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000005-00000000-00000000-00001102-0000000B-00431102}.rfx
[2012/07/06 00:50:22 | 000,000,820 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000005-00000000-00000000-00001102-0000000B-00431102}.rfx
[2012/07/05 19:55:28 | 000,003,288 | ---- | M] () -- C:\bootsqm.dat
[2012/07/05 12:39:00 | 000,000,840 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1648565797-2716223166-2222077553-1000Core.job
[2012/07/04 22:10:14 | 000,281,600 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/07/04 18:37:21 | 000,007,609 | ---- | M] () -- C:\Users\P\AppData\Local\resmon.resmoncfg
[2012/07/04 09:31:53 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/07/02 17:19:34 | 000,001,072 | ---- | M] () -- C:\Windows\SysNative\settingsbkup.sfm
[2012/07/02 17:19:34 | 000,001,072 | ---- | M] () -- C:\Windows\SysNative\settings.sfm
[2012/07/02 03:58:14 | 000,005,558 | ---- | M] () -- C:\Users\P\sidplay2.ini
[2012/07/02 03:48:16 | 000,000,372 | -H-- | M] () -- C:\Windows\tasks\DefragExpress.job
[2012/07/01 06:32:18 | 000,043,520 | ---- | M] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2012/06/30 17:04:09 | 000,178,800 | ---- | M] (Sony DADC Austria AG.) -- C:\Windows\SysWow64\CmdLineExt_x64.dll
[2012/06/29 01:17:11 | 000,002,482 | ---- | M] () -- C:\Users\P\Desktop\DNS.bat
[2012/06/25 18:50:54 | 000,000,255 | ---- | M] () -- C:\Windows\n02.ini
[2012/06/25 18:46:04 | 000,000,128 | ---- | M] () -- C:\Windows\kaillera.ini
[2012/06/24 23:12:10 | 000,117,152 | -H-- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/06/11 19:02:16 | 000,071,680 | ---- | M] (Beepa P/L) -- C:\Windows\SysNative\frapsv64.dll
[2012/06/11 19:02:12 | 000,065,536 | ---- | M] (Beepa P/L) -- C:\Windows\SysWow64\frapsvid.dll
[2012/06/07 15:31:08 | 231,271,434 | ---- | M] () -- C:\Users\Public\Documents\backup.reg
========== Files Created - No Company Name ==========
[2012/07/05 19:55:28 | 000,003,288 | ---- | C] () -- C:\bootsqm.dat
[2012/07/04 22:28:57 | 000,826,689 | ---- | C] () -- C:\Windows\SysNative\drivers\sfi.dat
[2012/07/04 18:44:17 | 000,001,456 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Frotz.lnk
[2012/07/04 18:36:40 | 000,007,609 | ---- | C] () -- C:\Users\P\AppData\Local\resmon.resmoncfg
[2012/07/04 08:54:30 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/04 08:54:30 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/04 08:54:30 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/04 08:54:30 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/04 08:54:30 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/07/01 06:32:18 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2012/06/25 19:27:49 | 000,005,558 | ---- | C] () -- C:\Users\P\sidplay2.ini
[2012/06/25 18:47:21 | 000,000,255 | ---- | C] () -- C:\Windows\n02.ini
[2012/06/25 18:46:04 | 000,000,128 | ---- | C] () -- C:\Windows\kaillera.ini
[2012/06/24 23:12:10 | 000,117,152 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/06/19 21:40:21 | 000,001,056 | ---- | C] () -- C:\Users\P\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
[2012/06/16 14:16:36 | 000,002,482 | ---- | C] () -- C:\Users\P\Desktop\DNS.bat
[2012/06/08 21:26:00 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/06/08 16:01:34 | 000,001,197 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2012/06/07 15:30:59 | 231,271,434 | ---- | C] () -- C:\Users\Public\Documents\backup.reg
[2012/06/07 14:23:03 | 000,001,314 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2012/06/07 14:22:51 | 000,001,383 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2012/06/06 23:33:31 | 000,810,496 | ---- | C] () -- C:\Windows\SysNative\xvidcore.dll
[2012/06/06 23:33:31 | 000,183,808 | ---- | C] () -- C:\Windows\SysNative\xvidvfw.dll
[2012/06/06 23:33:31 | 000,080,896 | ---- | C] () -- C:\Windows\SysNative\ff_vfw.dll
[2012/06/06 23:33:29 | 000,389,120 | ---- | C] () -- C:\Windows\SysWow64\actskn43.ocx
[2012/06/06 23:33:29 | 000,389,120 | ---- | C] () -- C:\Windows\SysNative\actskn43.ocx
[2012/05/29 20:55:48 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\drivers\mdvrmng.sys
[2012/05/20 06:02:18 | 000,763,958 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/04/23 07:14:47 | 000,281,032 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/04/23 07:14:46 | 000,794,408 | ---- | C] () -- C:\Windows\SysWow64\Pbsvc.exe
[2012/04/23 07:14:46 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/04/12 04:48:57 | 000,000,566 | ---- | C] () -- C:\Windows\SysWow64\SP7302.ini
[2012/04/06 18:44:48 | 000,000,026 | -H-- | C] () -- C:\ProgramData\.811261211181235583101118113995
[2012/04/01 19:59:49 | 000,164,864 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2012/04/01 19:59:49 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2012/04/01 10:12:23 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2012/04/01 00:32:58 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/03/31 23:58:45 | 000,000,285 | ---- | C] () -- C:\Windows\SysWow64\kill.ini
[2012/03/09 05:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 05:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 23:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/11 17:48:48 | 000,017,871 | ---- | C] () -- C:\Windows\SysWow64\instwdm.ini
[2011/08/11 17:48:44 | 000,000,054 | ---- | C] () -- C:\Windows\SysWow64\ctzapxx.ini
[2011/08/11 17:05:04 | 000,014,336 | ---- | C] ( ) -- C:\Windows\SysWow64\a3d.dll
[2011/08/11 17:00:42 | 000,002,560 | ---- | C] () -- C:\Windows\SysWow64\CTXFIRES.DLL
[2011/08/11 16:47:26 | 000,384,647 | ---- | C] () -- C:\Windows\SysWow64\ctdnlstr.dat
[2011/08/11 16:47:26 | 000,051,787 | ---- | C] () -- C:\Windows\SysWow64\ctdlang.dat
[2011/08/11 16:37:20 | 000,007,680 | ---- | C] () -- C:\Windows\SysWow64\enlocstr.exe
[2011/08/11 16:37:14 | 000,012,800 | ---- | C] ( ) -- C:\Windows\SysWow64\killapps.exe
========== LOP Check ==========
[2012/04/13 18:27:32 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Ableton
[2012/05/29 20:56:34 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Birdstep Technology
[2012/07/05 07:26:37 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\FileZilla
[2012/04/06 18:45:11 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Final Draft
[2012/04/11 00:32:44 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\LS
[2012/06/22 16:25:33 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\mirkes.de
[2012/04/11 01:14:30 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Notepad++
[2012/04/01 21:05:20 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Origin
[2012/06/28 18:25:47 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\six-updater
[2012/06/28 18:20:59 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\six-zsync
[2012/05/06 09:06:01 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Spirited Machine
[2012/04/30 04:05:27 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\SplitMediaLabs
[2012/04/02 00:27:03 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\SystemRequirementsLab
[2012/05/19 20:59:46 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Tunngle
[2012/04/02 21:01:31 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Ubisoft
[2012/07/05 22:10:52 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\uTorrent
[2012/04/07 17:36:03 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\VBA-M
[2012/05/29 20:25:21 | 000,000,000 | ---D | M] -- C:\Users\P\AppData\Roaming\Vodafone
[2012/07/02 03:48:16 | 000,000,372 | -H-- | M] () -- C:\Windows\Tasks\DefragExpress.job
[2012/07/04 05:26:50 | 000,026,926 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >