I am posting in this thread because I was advised to my a G2G Trusted Tech helping me out in another thread (linked below). I noticed some suspicious activity on my machine, notably something called beep.sys and something else with a junk title. Both processes were running and there seems to be no way of stopping them using the tools at my disposal.
For a long time now (6-8 months maybe) I have been experiencing random hard crashes and the occasional BSOD. This started shortly after I installed XP SP3; I have since downgraded to SP2 but the problems have not gone away.
The crashes are always accompanied by a brief crunching noise from the speakers; it is similar yet different every time. After the noise the hard drive gets quiet, the mouse does not move, and I cannot recover using CTRL ALT DEL or any other method known to me. I have to remove power and reapply.
My system doesn't seem to crash when I'm in safe mode. It will, however, sometimes crash if I leave it at the logon screen for a while.
Occasionally (I'd say one time out of five), the crash also includes a slow ramp up of an internal fan, ultimately stopping at what sounds like a jet taking off. At this point I don't know if that's a case fan or the fan on my video card.
I had been getting BSODs as well, always based in win32k.sys. These went away for a while, but now I am starting to get them again, frequently enough to mention (2-3 times in the last 5 days maybe).
I have run malware and virus scanners from an Ultimate Boot CD I made. I have done lots of other things as well, most of which are detailed in this other G2G thread.
It bears mentioning that I do not seem to have problems when running A-list games like Mass Effect 2 or Lord of the Rings Online. Getting into these games is sometimes a problem, however.
My machine seems to crash most reliably when I am trying to download large amounts of data, such as through the browser I use (Google Chrome, mostly) or through Adobe AIR (such as for good old games, or gog.com). Most of the time I am okay with usual browser activity, which for me is 10-15 tabs going all at once. Short bursts seem to be fine, but sustained data transfer will kill my machine.
I have used superantispyware, avast antivirus, ad-aware, spybot and a few other scanning tools. The most recent run of these tools was a month or three ago, and they didn't find anything at that time.
So -- what's my best chance of removing these and any other junk from my system?
OTL log follows:
OTL logfile created on: 11.01.13 3.21.24 PM - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\user1\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: yy.MM.dd
2.00 Gb Total Physical Memory | 0.00 Gb Available Physical Memory | 24.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 18.05 Gb Free Space | 16.14% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive G: | 465.76 Gb Total Space | 88.59 Gb Free Space | 19.02% Space Free | Partition Type: NTFS
Computer Name: GARGANTUBRAIN | User Name: user1 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.01.13 15.20.29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user1\desktop\OTL.exe
PRC - [2011.01.10 04.57.19 | 000,995,896 | ---- | M] (Google Inc.) -- C:\Documents and Settings\user1\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2010.11.10 19.38.40 | 000,380,928 | ---- | M] () -- C:\Program Files\Launchy\Launchy.exe
PRC - [2010.10.18 14.45.05 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.2.183.39\GoogleCrashHandler.exe
PRC - [2010.10.18 04.24.19 | 000,134,808 | ---- | M] (Google Inc.) -- C:\Documents and Settings\user1\Local Settings\Application Data\Google\Update\1.2.183.39\GoogleCrashHandler.exe
PRC - [2010.09.07 10.12.02 | 002,838,912 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2010.09.07 10.11.59 | 000,040,384 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2010.08.13 11.58.56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010.07.13 13.26.12 | 004,302,704 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
PRC - [2010.07.13 13.26.10 | 006,076,272 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe
PRC - [2010.07.13 13.26.10 | 002,533,232 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
PRC - [2010.07.13 13.26.10 | 000,616,816 | ---- | M] (Wacom Technology, Corp.) -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe
PRC - [2010.07.09 13.04.34 | 003,493,776 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\Xfire.exe
PRC - [2010.07.04 17.39.49 | 001,352,832 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2010.06.26 17.00.36 | 000,864,112 | ---- | M] (Lavasoft) -- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2010.02.25 23.10.20 | 021,979,992 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Dropbox\bin\Dropbox.exe
PRC - [2009.10.12 23.16.18 | 003,102,944 | ---- | M] (AnVir Software) -- C:\Program Files\AnVir Task Manager\AnVir.exe
PRC - [2009.05.03 12.28.20 | 000,244,736 | ---- | M] () -- C:\Program Files\AutoHotkey\AutoHotkey.exe
PRC - [2009.04.25 00.00.10 | 000,877,568 | ---- | M] () -- C:\Program Files\HACE\Mmm\Mmm.exe
PRC - [2009.03.05 15.07.20 | 002,260,480 | ---- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2008.07.26 07.25.36 | 000,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcSrv.exe
PRC - [2008.07.26 07.23.42 | 000,186,904 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\Logishrd\LVCOMSER\LVComSer.exe
PRC - [2008.07.21 16.54.34 | 000,169,312 | ---- | M] (Maxtor Corporation) -- C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe
PRC - [2008.07.21 16.53.04 | 000,193,888 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Maxtor\Sync\SyncServices.exe
PRC - [2008.05.02 01.44.08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008.05.02 01.40.56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2007.10.02 09.10.46 | 000,131,072 | ---- | M] (Saitek) -- C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
PRC - [2007.10.02 09.10.14 | 000,233,472 | ---- | M] (Saitek) -- C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
PRC - [2007.06.13 04.23.07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007.03.27 01.29.52 | 000,192,512 | ---- | M] (AltrixSoft (http://www.altrixsoft.com/)) -- C:\WINDOWS\system32\HDDSvc.exe
PRC - [2006.11.03 18.20.12 | 000,866,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2006.11.03 18.19.58 | 000,013,592 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MsMpEng.exe
PRC - [2003.08.28 13.01.22 | 000,061,440 | ---- | M] () -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
========== Modules (SafeList) ==========
MOD - [2011.01.13 15.20.29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user1\desktop\OTL.exe
MOD - [2010.08.23 10.12.02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
MOD - [2010.07.09 13.04.44 | 000,970,640 | ---- | M] (Xfire Inc.) -- C:\Program Files\Xfire\xfire_toucan_43094.dll
MOD - [2009.10.12 23.16.02 | 000,102,112 | ---- | M] (AnVir Software) -- C:\Program Files\AnVir Task Manager\AnvirHook61.dll
MOD - [2009.07.12 00.12.06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008.07.26 07.25.24 | 000,109,080 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\Temp\logishrd\LVPrcInj01.dll
MOD - [2008.05.02 01.42.50 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2008.05.02 01.38.54 | 000,064,016 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\GameHook.dll
MOD - [2004.08.12 07.34.47 | 000,022,528 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wsock32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [On_Demand | Stopped] -- -- (napagent)
SRV - File not found [On_Demand | Stopped] -- -- (hkmsvc)
SRV - File not found [On_Demand | Stopped] -- -- (EapHost)
SRV - File not found [On_Demand | Stopped] -- -- (Dot3svc)
SRV - [2010.09.07 10.11.59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Web Scanner)
SRV - [2010.09.07 10.11.59 | 000,040,384 | ---- | M] (AVAST Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Mail Scanner)
SRV - [2010.09.07 10.11.59 | 000,040,384 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010.08.13 11.58.56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010.07.13 13.26.10 | 006,076,272 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV - [2010.07.13 13.26.10 | 000,616,816 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV - [2010.07.04 21.18.44 | 000,039,936 | ---- | M] (C-Dilla Ltd) [On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CDAC11BA.EXE -- (C-DillaCdaC11BA)
SRV - [2010.07.04 17.39.49 | 001,352,832 | ---- | M] (Lavasoft) [Auto | Running] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009.12.15 14.07.16 | 000,025,832 | ---- | M] (BioWare) [On_Demand | Stopped] -- G:\Programs\Dragon Age\bin_ship\daupdatersvc.service.exe -- (DAUpdaterSvc)
SRV - [2008.08.06 10.34.02 | 000,216,032 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Macrium\Reflect\ReflectService.exe -- (ReflectService)
SRV - [2008.07.26 07.25.36 | 000,150,040 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv)
SRV - [2008.07.26 07.23.42 | 000,186,904 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe -- (LVCOMSer)
SRV - [2008.07.21 16.53.04 | 000,193,888 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Maxtor\Sync\SyncServices.exe -- (Maxtor Sync Service)
SRV - [2008.05.02 01.42.06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2007.03.27 01.29.52 | 000,192,512 | ---- | M] (AltrixSoft (http://www.altrixsoft.com/)) [Auto | Running] -- C:\WINDOWS\system32\HDDSvc.exe -- (HDDSvc)
SRV - [2007.03.19 19.19.14 | 000,263,168 | ---- | M] (Ares Development Group) [On_Demand | Stopped] -- C:\Program Files\Ares\chatServer.exe -- (AresChatServer)
SRV - [2006.11.03 18.19.58 | 000,013,592 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2005.04.04 18.58.28 | 000,163,840 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe -- (Adobe Version Cue CS2)
SRV - [2004.11.02 15.59.50 | 000,316,544 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- (SymWSC)
SRV - [2003.08.28 13.01.22 | 000,061,440 | ---- | M] () [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe -- (spkrmon)
========== Driver Services (SafeList) ==========
DRV - [2010.11.26 14.07.10 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV - [2010.11.26 14.07.10 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV - [2010.11.26 14.07.10 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV - [2010.11.26 14.07.10 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV - [2010.11.26 14.07.10 | 000,025,704 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV - [2010.09.07 09.52.25 | 000,046,672 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2010.09.07 09.52.03 | 000,165,584 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2010.09.07 09.47.46 | 000,023,376 | ---- | M] (AVAST Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2010.09.07 09.47.19 | 000,100,176 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2010.09.07 09.47.07 | 000,017,744 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2010.09.07 09.46.51 | 000,028,880 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2010.07.04 21.18.40 | 000,008,864 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CDAC15BA.SYS -- (CdaC15BA)
DRV - [2010.06.04 14.10.37 | 000,064,288 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\Lbd.sys -- (Lbd)
DRV - [2010.06.01 14.21.21 | 000,067,656 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)
DRV - [2010.06.01 14.21.21 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV)
DRV - [2010.06.01 14.21.21 | 000,012,872 | ---- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)
DRV - [2010.05.19 13.52.36 | 000,016,240 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV - [2009.09.21 15.29.22 | 000,014,120 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacomvhid.sys -- (wacomvhid)
DRV - [2009.02.25 16.58.57 | 003,565,568 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2009.01.11 19.56.58 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2008.12.26 22.28.14 | 000,095,592 | ---- | M] (Rocket Division Software) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\StarPortLite.sys -- (StarPortLite) StarPort Storage Controller (Lite)
DRV - [2008.12.13 13.47.38 | 000,129,896 | ---- | M] (Paragon) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\Uim_IM.sys -- (Uim_IM)
DRV - [2008.12.13 13.47.38 | 000,040,496 | ---- | M] (Paragon Software Group) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\hotcore3.sys -- (hotcore3)
DRV - [2008.12.13 13.47.38 | 000,032,056 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\UimBus.sys -- (UimBus)
DRV - [2008.07.26 07.25.02 | 000,025,624 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVPr2Mon.sys -- (LVPr2Mon)
DRV - [2008.05.20 08.32.40 | 000,015,328 | ---- | M] (Macrium Software) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\pssnap.sys -- (pssnap)
DRV - [2008.02.29 02.13.46 | 000,028,944 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LUsbFilt.sys -- (LUsbFilt)
DRV - [2008.02.29 02.13.24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008.02.29 02.13.16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008.02.11 17.59.01 | 000,278,984 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\atksgt.sys -- (atksgt)
DRV - [2008.02.11 17.59.01 | 000,025,416 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\lirsgt.sys -- (lirsgt)
DRV - [2007.10.05 09.19.26 | 000,035,200 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SaiBus.sys -- (SaiNtBus)
DRV - [2007.10.05 09.19.26 | 000,014,080 | ---- | M] (Saitek) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SaiMini.sys -- (SaiMini)
DRV - [2007.05.11 17.31.22 | 000,041,888 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007.05.11 17.30.04 | 001,921,184 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvpopflt.sys -- (lvpopflt)
DRV - [2007.05.11 16.31.36 | 003,580,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\lvuvc.sys -- (LVUVC) Logitech QuickCam Fusion(UVC)
DRV - [2007.05.03 13.37.08 | 000,022,152 | ---- | M] (Maxtor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mxopswd.sys -- (MXOPSWD)
DRV - [2007.05.01 14.51.10 | 000,132,232 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiH040C.sys -- (SaiH040C)
DRV - [2007.05.01 14.51.10 | 000,028,416 | ---- | M] (Saitek) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SaiU040C.sys -- (SaiU040C)
DRV - [2007.04.25 18.55.12 | 000,040,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2007.02.16 10.12.36 | 000,011,312 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV - [2007.01.26 20.09.40 | 000,068,954 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\jl2005c.sys -- (JL2005C)
DRV - [2006.10.04 20.42.42 | 000,002,560 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdralw2k.sys -- (Cdralw2k)
DRV - [2006.10.04 20.42.42 | 000,002,432 | ---- | M] (Sonic Solutions) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\cdr4_xp.sys -- (Cdr4_xp)
DRV - [2006.09.24 07.28.46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- C:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006.07.03 21.59.24 | 000,223,128 | ---- | M] (Alcohol Soft Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\vaxscsi.sys -- (vaxscsi)
DRV - [2006.03.26 06.22.14 | 000,051,200 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfdrv01.sys -- (sfdrv01) StarForce Protection Environment Driver (version 1.x)
DRV - [2006.03.13 03.38.23 | 000,006,656 | ---- | M] (Protection Technology (StarForce)) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp02.sys -- (sfhlp02) StarForce Protection Helper Driver (version 2.x)
DRV - [2005.08.10 08.06.28 | 000,019,968 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfsync02.sys -- (sfsync02) StarForce Protection Synchronization Driver (version 2.x)
DRV - [2004.08.23 13.49.30 | 000,121,472 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2004.08.12 07.24.55 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2004.08.09 05.33.26 | 000,114,016 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prohlp02.sys -- (prohlp02)
DRV - [2004.08.09 05.29.28 | 000,053,920 | ---- | M] (Protection Technology) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\prodrv06.sys -- (prodrv06)
DRV - [2004.07.19 08.49.54 | 000,007,040 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\prosync1.sys -- (prosync1)
DRV - [2004.04.13 16.03.46 | 000,016,509 | ---- | M] (Palm, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PalmUSBD.sys -- (PalmUSBD)
DRV - [2003.12.01 09.20.52 | 000,004,832 | ---- | M] (Protection Technology) [Kernel | Boot | Running] -- C:\WINDOWS\System32\drivers\sfhlp01.sys -- (sfhlp01)
DRV - [2003.11.07 03.50.00 | 000,070,798 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouFlt2.Sys -- (LMouFlt2)
DRV - [2003.11.07 03.50.00 | 000,037,884 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidUsb.sys -- (LHidUsb)
DRV - [2003.11.07 03.50.00 | 000,025,502 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidFlt2.Sys -- (LHidFlt2)
DRV - [2003.06.24 23.18.48 | 000,146,560 | ---- | M] (Roxio) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\DVDVRRdr_xp.sys -- (DVDVRRdr_xp)
DRV - [2003.05.07 01.54.38 | 000,008,960 | R--- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbbc2.sys -- (PLUsbbc2)
DRV - [2003.05.01 13.26.34 | 000,005,220 | ---- | M] (Cisco Systems, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\CVirtA.sys -- (CVirtA)
DRV - [2003.04.19 00.32.04 | 000,004,736 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\tandpl.sys -- (tandpl)
DRV - [2003.03.02 17.44.26 | 000,007,552 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\enodpl.sys -- (enodpl)
DRV - [2002.08.14 14.03.36 | 000,017,005 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\System32\drivers\ASPI32.SYS -- (Aspi32)
DRV - [1996.04.03 13.33.26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0B D4 00 C1 00 B2 CB 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.1.1
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.21.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.7.4
FF - prefs.js..extensions.enabledItems: {6AC85730-7D0F-4de0-B3FA-21142DD85326}:2.0.2.1
FF - prefs.js..extensions.enabledItems: {2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}:2.1.062
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.07076007
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.1
FF - prefs.js..extensions.enabledItems: {5C3A97C1-1D8C-4577-8D2B-F1C45E72000A}:1.0
FF - prefs.js..extensions.enabledItems: {7ef7f4d6-947d-11dc-8314-0800200c9a66}:3.0.1
FF - prefs.js..extensions.enabledItems: {7694c49c-9fbd-11dc-8314-0800200c9a66}:3.0.2
FF - prefs.js..extensions.enabledItems: {04CA07AB-7FC3-4110-A83F-EF1E6B75D5B0}:4.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:3.8
FF - prefs.js..extensions.enabledItems: [email protected]:1.45
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.5.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.95
FF - HKLM\software\mozilla\Firefox\extensions\\{5C3A97C1-1D8C-4577-8D2B-F1C45E72000A}: C:\Documents and Settings\user1\Local Settings\Application Data\{5C3A97C1-1D8C-4577-8D2B-F1C45E72000A} [2009.04.12 18.57.03 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.12.01 13.35.23 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.11.17 22.15.05 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.16\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010.12.01 13.35.29 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 2.0.0.16\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins [2010.10.23 14.33.08 | 000,000,000 | ---D | M]
[2009.11.16 18.27.31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user1\Application Data\Mozilla\Extensions
[2009.11.16 18.27.31 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user1\Application Data\Mozilla\Extensions\[email protected]
[2010.12.23 15.43.40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions
[2006.05.19 23.36.38 | 000,000,000 | ---D | M] ("Azerty II") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{044FA143-992A-435f-95A5-39E25470F8F0}(2)
[2009.08.03 23.37.13 | 000,000,000 | ---D | M] (Azerty III) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{04CA07AB-7FC3-4110-A83F-EF1E6B75D5B0}
[2006.05.19 23.36.38 | 000,000,000 | ---D | M] (Silver Skin) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}(2)
[2009.08.05 13.45.53 | 000,000,000 | ---D | M] ("Delicious Bookmarks") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}
[2009.05.15 23.28.58 | 000,000,000 | ---D | M] ("Delicious Bookmarks") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{2fa4ed95-0317-4c6a-a74c-5f3e3912c1f9}(2)
[2009.07.30 00.28.15 | 000,000,000 | ---D | M] (FoxyTunes) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{463F6CA5-EE3C-4be1-B7E6-7FEE11953374}
[2009.09.14 15.33.32 | 000,000,000 | ---D | M] (ScrapBook) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{53A03D43-5363-4669-8190-99061B2DEBA5}
[2006.01.20 05.12.58 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2006.05.19 23.36.37 | 000,000,000 | ---D | M] (Aquatint) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{69087485-8EDE-4a6c-91BE-6B882EB268A5}(2)
[2009.07.09 20.11.03 | 000,000,000 | ---D | M] (ColorZilla) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{6AC85730-7D0F-4de0-B3FA-21142DD85326}
[2009.05.09 22.43.41 | 000,000,000 | ---D | M] (Aquatint Black Gloss) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{7694c49c-9fbd-11dc-8314-0800200c9a66}
[2008.12.17 18.16.10 | 000,000,000 | ---D | M] (Abstract Zune) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{7ef7f4d6-947d-11dc-8314-0800200c9a66}
[2006.05.19 23.36.36 | 000,000,000 | ---D | M] (Noia 2.0 (eXtreme)) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{9f08cb5a-76b1-4bcf-aff9-90e1a5d60b1e}(2)
[2009.07.27 02.24.00 | 000,000,000 | ---D | M] (PitchDark) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2009.08.20 13.25.51 | 000,000,000 | ---D | M] (CreativesAre Toolbar) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{c42afa2e-1ffa-47f1-aaed-9dfed53a38ca}
[2008.12.17 20.08.15 | 000,000,000 | ---D | M] (Google Redesigned) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{cc85cd4e-5a5b-4eda-a25c-bdaffa93b406}
[2009.08.16 20.28.28 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009.08.03 23.37.21 | 000,000,000 | ---D | M] ("Tab Mix Plus") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2009.02.19 00.29.24 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2009.05.09 07.10.13 | 000,000,000 | ---D | M] (Autofill Forms) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.07.11 19.10.49 | 000,000,000 | ---D | M] (Battlefield Heroes Updater) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.04.21 16.55.58 | 000,000,000 | ---D | M] ("Better Gmail 2") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.04.21 16.55.58 | 000,000,000 | ---D | M] ("Better GReader") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.07.27 02.24.26 | 000,000,000 | ---D | M] (bit.ly preview) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.05.29 21.47.33 | 000,000,000 | ---D | M] (ChromEdit Plus) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.09.14 14.26.26 | 000,000,000 | ---D | M] (Dark Revisited) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2008.03.10 15.15.08 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2008.09.11 09.25.27 | 000,000,000 | ---D | M] (Google Notebook) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.07.09 20.10.56 | 000,000,000 | ---D | M] ("heaven.cube") -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2008.12.30 03.05.20 | 000,000,000 | ---D | M] (RedShift V3) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2006.01.28 05.06.16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\temp
[2009.04.10 16.47.26 | 000,000,000 | ---D | M] (TiseMe Bar) -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\extensions\[email protected]
[2009.10.01 00.55.18 | 000,001,243 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\a9.xml
[2009.03.20 12.19.10 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\amazondotcom.xml
[2009.03.19 10.27.53 | 000,000,853 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\del.icio.us.xml
[2009.03.16 20.38.41 | 000,002,306 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\duck-duck-go.xml
[2009.03.20 12.19.10 | 000,001,595 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\ebay.xml
[2009.10.01 00.55.18 | 000,002,125 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\flickr-tags.xml
[2008.04.10 03.24.36 | 000,001,192 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\fulltorrent.xml
[2008.06.21 15.33.53 | 000,000,908 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\imdb.xml
[2010.12.23 15.43.44 | 000,005,216 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\linkedin.xml
[2009.10.01 00.55.18 | 000,002,191 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\ljseek.xml
[2008.06.21 15.33.52 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Mozilla\Firefox\Profiles\xsnide43.default\searchplugins\wikipedia.xml
[2010.12.23 15.43.42 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009.04.12 18.57.03 | 000,000,000 | ---D | M] (XUL Cache) -- C:\DOCUMENTS AND SETTINGS\USER1\LOCAL SETTINGS\APPLICATION DATA\{5C3A97C1-1D8C-4577-8D2B-F1C45E72000A}
[2009.08.17 19.19.17 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2005.09.15 17.26.00 | 000,044,153 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\components\inspector.dll
[2004.11.12 21.36.20 | 000,005,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Mozilla Firefox\plugins\NPAdbESD.dll
[2007.12.10 22.56.33 | 000,024,576 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npgcplug.dll
[2005.04.27 14.10.49 | 000,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
O1 HOSTS File: ([2008.12.24 01.20.40 | 000,291,071 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 127.0.0.1 163ns.com
O1 - Hosts: 10025 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Download Guard for Internet Explorer) - {20C1A7F0-528E-444F-BAC5-5804A61CCA7F} - C:\Program Files\Lavasoft\Download Guard for Internet Explorer\DownloadGuardBHO.dll (Lavasoft AB )
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [mxomssmenu] C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe (Maxtor Corporation)
O4 - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4 - HKLM..\Run: [RoxioEngineUtility] C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe (Roxio)
O4 - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [AnVir Task Manager] C:\Program Files\AnVir Task Manager\AnVir.exe (AnVir Software)
O4 - HKCU..\Run: [Mmm] C:\Program Files\HACE\Mmm\Mmm.exe ()
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O4 - Startup: C:\Documents and Settings\user1\Start Menu\Programs\Startup\AutoHotkey.lnk = C:\Program Files\AutoHotkey\AutoHotkey.exe ()
O4 - Startup: C:\Documents and Settings\user1\Start Menu\Programs\Startup\Dropbox.lnk = C:\Documents and Settings\user1\Application Data\Dropbox\bin\Dropbox.exe ()
O4 - Startup: C:\Documents and Settings\user1\Start Menu\Programs\Startup\Launchy.lnk = C:\Program Files\Launchy\Launchy.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Copy to Semagic - C:\Program Files\Semagic\copy.htm ()
O8 - Extra context menu item: Semagic - C:\Program Files\Semagic\link.htm ()
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YPager.exe ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {3234504D-0000-0010-8000-00AA00389B71} http://codecs.micros...386/mpeg4ax.CAB (Reg Error: Key error.)
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.sy...eqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebo...oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.co.../DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell....lSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_15)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcp.../pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\dimsntfy: DllName - %SystemRoot%\System32\dimsntfy.dll - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O20 - Winlogon\Notify\MCPClient: DllName - C:\PROGRA~1\COMMON~1\Stardock\mcpstub.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\user1\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O27 - HKLM IFEO\taskmgr.exe: Debugger - "C:\Program Files\AnVir Task Manager\AnVir.exe" (AnVir Software)
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005.06.30 13.45.42 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010.09.21 22.23.20 | 000,000,055 | ---- | M] () - G:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{6a6c893c-e5e1-11de-9a55-001143a5fab6}\Shell - "" = AutoRun
O33 - MountPoints2\{6a6c893c-e5e1-11de-9a55-001143a5fab6}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{6a6c893c-e5e1-11de-9a55-001143a5fab6}\Shell\AutoRun\command - "" = H:\Photo_Viewer.exe
O33 - MountPoints2\{afcb8830-f7d0-11d9-95c5-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{afcb8830-f7d0-11d9-95c5-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{afcb8830-f7d0-11d9-95c5-806d6172696f}\Shell\AutoRun\command - "" = D:\autorun.exe
O33 - MountPoints2\{e2845c3e-ffa7-11dc-b3ef-001143a5fab6}\Shell\AutoRun\command - "" = G:\ -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.01.13 15.20.28 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user1\Desktop\OTL.exe
[2011.01.13 00.01.37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2011.01.05 13.07.19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011.01.05 13.07.18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype
[2011.01.03 19.38.26 | 000,000,000 | -H-D | C] -- C:\WINDOWS\msdownld.tmp
[2011.01.03 19.36.35 | 000,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2011.01.03 18.42.08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Local Settings\Application Data\Borders Desktop
[2011.01.03 18.41.38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Borders Desktop
[2011.01.03 18.39.42 | 000,000,000 | ---D | C] -- C:\Program Files\Borders Desktop
[2011.01.03 16.50.20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Desktop\ceremony
[2011.01.03 14.28.48 | 017,208,130 | ---- | C] (GOG.com ) -- C:\Documents and Settings\user1\Desktop\freespace_expansion_part0.gogDownload
[2011.01.02 23.08.17 | 000,000,000 | ---D | C] -- C:\Program Files\PDFZilla
[2010.12.27 21.35.16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Desktop\kinship
[2010.12.27 20.33.56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Desktop\100NIKON
[2010.12.23 20.59.04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\My Documents\The Lord of the Rings Online
[2010.12.23 20.59.04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Local Settings\Application Data\The Lord of the Rings Online
[2010.12.23 20.32.49 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2010.12.23 20.32.49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\7-Zip
[2010.12.23 20.32.00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Application Data\WinRAR
[2010.12.23 20.31.50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Start Menu\Programs\WinRAR
[2010.12.23 20.31.50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2010.12.20 22.45.01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user1\Application Data\.minecraft
[2010.12.18 23.23.31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2010.12.17 21.53.20 | 014,715,008 | ---- | C] (Dropbox, Inc.) -- C:\Documents and Settings\user1\Desktop\Dropbox 1.0.10.exe
[2010.12.14 23.14.05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\RVLGames
[2007.12.10 22.56.44 | 000,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.01.13 15.29.55 | 000,000,392 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7DD405FA-CD81-431D-BD0A-0F6B00BA5F78}.job
[2011.01.13 15.29.04 | 000,000,978 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1343024091-682003330-1003UA.job
[2011.01.13 15.27.39 | 000,000,073 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\beep.sys - beep.sys Removal Instructions.url
[2011.01.13 15.20.29 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user1\Desktop\OTL.exe
[2011.01.13 14.56.02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2011.01.13 14.50.58 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2011.01.13 14.50.00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011.01.13 14.48.36 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011.01.13 14.48.20 | 000,000,312 | ---- | M] () -- C:\WINDOWS\tasks\GlaryInitialize.job
[2011.01.13 14.48.14 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011.01.13 14.47.51 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011.01.13 14.47.32 | 000,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2011.01.13 14.29.16 | 000,000,364 | ---- | M] () -- C:\WINDOWS\tasks\Symantec NetDetect.job
[2011.01.13 05.29.00 | 000,000,926 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1343024091-682003330-1003Core.job
[2011.01.13 00.00.37 | 000,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011.01.12 23.33.00 | 000,000,548 | ---- | M] () -- C:\WINDOWS\tasks\Rescue Reminder for 2HAA7K8A.job
[2011.01.12 17.26.01 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011.01.12 02.40.04 | 176,795,648 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011.01.09 23.08.18 | 000,010,062 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\More Questions.rtf
[2011.01.07 22.23.33 | 000,002,155 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011.01.03 19.38.20 | 000,000,873 | ---- | M] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011.01.03 14.28.48 | 017,208,130 | ---- | M] (GOG.com ) -- C:\Documents and Settings\user1\Desktop\freespace_expansion_part0.gogDownload
[2011.01.03 14.26.09 | 000,000,924 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Jagged Alliance - Deadly Games.lnk
[2011.01.03 14.09.36 | 000,000,392 | ---- | M] () -- C:\WINDOWS\tasks\GlaryOneClickOptimizer.job
[2011.01.03 03.55.01 | 000,000,071 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\City of Austin - netLibrary.URL
[2011.01.02 23.12.19 | 000,000,131 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\LOTRO wallpapers.url
[2011.01.02 16.18.39 | 051,557,551 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Drawspace Guide to Getting Started with Drawing.pdf
[2011.01.02 16.18.03 | 012,063,477 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Illustrated Dictionary of Art-related Terms.pdf
[2011.01.02 16.11.57 | 000,000,074 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Welcome to Select Portfolio Servicing, Inc..url
[2011.01.02 15.47.40 | 000,000,046 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Be the curator of your favorite topic! - Scoop.it.url
[2010.12.31 12.28.02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010.12.30 19.15.18 | 000,000,064 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Participation link-.url
[2010.12.30 19.15.12 | 000,000,084 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\Administration link-.url
[2010.12.28 00.01.24 | 002,932,718 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\122710.mp3
[2010.12.27 22.55.54 | 000,002,463 | ---- | M] () -- C:\Documents and Settings\user1\Application Data\Microsoft\Internet Explorer\Quick Launch\Logitech QuickCam.lnk
[2010.12.21 23.14.07 | 000,000,783 | ---- | M] () -- C:\Documents and Settings\user1\Desktop\The Lord of the Rings Online.lnk
[2010.12.17 21.53.45 | 014,715,008 | ---- | M] (Dropbox, Inc.) -- C:\Documents and Settings\user1\Desktop\Dropbox 1.0.10.exe
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.01.13 15.27.39 | 000,000,073 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\beep.sys - beep.sys Removal Instructions.url
[2011.01.09 23.08.18 | 000,010,062 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\More Questions.rtf
[2011.01.03 19.43.20 | 000,000,392 | -H-- | C] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{7DD405FA-CD81-431D-BD0A-0F6B00BA5F78}.job
[2011.01.03 19.38.20 | 000,000,873 | ---- | C] () -- C:\WINDOWS\System32\spupdsvc.inf
[2011.01.03 14.26.09 | 000,000,924 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Jagged Alliance - Deadly Games.lnk
[2011.01.03 03.55.01 | 000,000,071 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\City of Austin - netLibrary.URL
[2011.01.02 23.12.02 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\LOTRO wallpapers.url
[2011.01.02 16.17.47 | 012,063,477 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Illustrated Dictionary of Art-related Terms.pdf
[2011.01.02 16.17.42 | 051,557,551 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Drawspace Guide to Getting Started with Drawing.pdf
[2011.01.02 16.11.57 | 000,000,074 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Welcome to Select Portfolio Servicing, Inc..url
[2011.01.02 15.47.40 | 000,000,046 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Be the curator of your favorite topic! - Scoop.it.url
[2010.12.30 19.15.18 | 000,000,064 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Participation link-.url
[2010.12.30 19.15.12 | 000,000,084 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\Administration link-.url
[2010.12.28 00.01.20 | 002,932,718 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\122710.mp3
[2010.12.21 23.14.07 | 000,000,783 | ---- | C] () -- C:\Documents and Settings\user1\Desktop\The Lord of the Rings Online.lnk
[2010.12.01 01.49.01 | 000,153,600 | ---- | C] () -- C:\WINDOWS\System32\WS_ATLMovie.dll
[2010.10.11 14.58.21 | 000,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2010.10.11 14.37.53 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2010.07.09 13.04.40 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2010.07.04 21.18.42 | 000,008,864 | ---- | C] () -- C:\WINDOWS\System32\drivers\CDAC15BA.SYS
[2010.04.02 16.17.34 | 000,179,091 | ---- | C] () -- C:\WINDOWS\System32\xlive.dll.cat
[2010.02.17 19.09.57 | 000,003,480 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\mindhabits.dat
[2009.12.29 17.32.39 | 000,000,760 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\setup_ldm.iss
[2009.10.18 20.58.04 | 000,819,200 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009.10.18 20.58.04 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009.04.29 22.57.52 | 000,000,211 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\FontAgent Pro.ini
[2009.04.12 17.41.20 | 000,000,000 | ---- | C] () -- C:\WINDOWS\imorefozuzifowa.dll
[2009.03.03 22.12.18 | 000,000,140 | ---- | C] () -- C:\WINDOWS\System32\09wutili.sys
[2008.10.09 20.24.21 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\EZTW32.DLL
[2008.10.07 09.13.30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008.10.07 09.13.22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008.10.07 09.13.20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2008.07.26 07.25.02 | 000,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008.04.02 17.08.43 | 000,138,576 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2008.04.02 17.08.43 | 000,022,328 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\PnkBstrK.sys
[2008.03.10 14.09.12 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
[2008.02.29 16.16.45 | 000,151,040 | -HS- | C] () -- C:\WINDOWS\System32\VistaUltm.dll
[2008.02.29 16.16.45 | 000,027,648 | -HS- | C] () -- C:\WINDOWS\System32\Smab0.dll
[2008.02.11 17.59.01 | 000,278,984 | ---- | C] () -- C:\WINDOWS\System32\drivers\atksgt.sys
[2008.02.11 17.59.01 | 000,025,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\lirsgt.sys
[2008.01.31 03.03.01 | 000,010,240 | ---- | C] () -- C:\WINDOWS\System32\vidx16.dll
[2008.01.09 23.24.17 | 000,000,026 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\tcw_config.cfg
[2008.01.08 03.06.50 | 000,000,276 | ---- | C] () -- C:\WINDOWS\game.ini
[2007.10.16 02.19.30 | 001,060,864 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2007.10.16 02.19.30 | 000,909,312 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2007.10.16 02.19.30 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2007.10.16 02.19.30 | 000,036,864 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2007.10.15 21.41.53 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2007.10.15 21.41.53 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2007.10.15 21.41.53 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2007.10.09 23.18.03 | 000,009,728 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007.08.04 14.01.51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2007.07.05 13.08.17 | 000,077,312 | ---- | C] () -- C:\WINDOWS\ua2.dll
[2007.06.05 01.32.54 | 000,010,085 | ---- | C] () -- C:\WINDOWS\msvrc20.dll
[2007.05.24 16.16.07 | 000,399,360 | ---- | C] () -- C:\WINDOWS\System32\Smab.dll
[2007.05.24 16.16.07 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2007.05.14 14.30.46 | 000,059,904 | ---- | C] () -- C:\WINDOWS\System32\zlib1.dll
[2007.05.11 15.12.54 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2007.05.01 14.51.10 | 000,005,632 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_11.dll
[2007.04.22 18.15.29 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007.01.03 11.48.24 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\dec_jl6.dll
[2006.12.29 21.53.03 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2006.12.02 18.59.01 | 000,139,280 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2006.10.15 20.06.50 | 000,000,025 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2006.07.03 21.55.14 | 000,717,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2006.04.22 23.42.08 | 000,005,265 | ---- | C] () -- C:\Documents and Settings\user1\Application Data\GdiplusUpgrade_MSIApproach_Wrapper.log
[2006.04.22 22.41.11 | 000,011,489 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2006.04.05 03.29.05 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2006.03.24 22.36.37 | 002,502,656 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C.Dll
[2006.03.24 22.36.37 | 000,008,704 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_0C.dll
[2006.03.24 22.36.37 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_10.dll
[2006.03.24 22.36.37 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_0A.dll
[2006.03.24 22.36.37 | 000,008,192 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_07.dll
[2006.03.24 22.36.37 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_09.dll
[2006.03.06 05.24.51 | 000,007,552 | ---- | C] () -- C:\WINDOWS\System32\drivers\enodpl.sys
[2006.03.06 05.24.50 | 000,004,736 | ---- | C] () -- C:\WINDOWS\System32\drivers\tandpl.sys
[2005.12.03 16.36.22 | 000,001,755 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2005.11.03 10.11.44 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\SaiC040C_0402.dll
[2005.09.24 22.39.42 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\user1\Local Settings\Application Data\fusioncache.dat
[2005.09.09 20.54.34 | 000,001,300 | ---- | C] () -- C:\WINDOWS\System32\cool.dll
[2005.08.29 12.11.25 | 000,000,025 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2005.08.26 11.41.40 | 000,176,235 | ---- | C] () -- C:\WINDOWS\System32\Primomonnt.dll
[2005.08.26 11.41.39 | 000,000,129 | ---- | C] () -- C:\WINDOWS\primopdf.ini
[2005.08.25 13.28.50 | 000,364,544 | ---- | C] () -- C:\WINDOWS\System32\psCamDat.dll
[2005.08.21 16.21.24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\QuickInstall.INI
[2005.08.20 01.25.12 | 000,082,432 | ---- | C] () -- C:\Documents and Settings\user1\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005.08.09 16.13.31 | 000,831,488 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2005.08.09 16.13.31 | 000,159,744 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2005.06.30 14.39.59 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005.06.30 08.23.04 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2004.01.27 06.13.54 | 000,421,888 | ---- | C] () -- C:\WINDOWS\System32\OpenQuicktimeLib.dll
[2004.01.27 06.13.14 | 000,061,440 | ---- | C] () -- C:\WINDOWS\System32\libfaac.dll
[1996.04.03 13.33.26 | 000,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2008.12.21 17.19.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\2DBoy
[2010.06.07 11.48.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2006.05.27 12.54.27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Avg7
[2008.06.20 19.47.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Awem
[2009.11.08 23.35.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BioWare
[2010.10.07 13.21.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Extensis
[2007.10.21 17.57.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Extreme Picture Finder
[2008.06.24 22.22.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Flood Light Games
[2007.07.12 21.39.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gameeel
[2007.08.03 23.09.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Games
[2009.04.21 01.16.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Gold Casual Games
[2008.01.07 02.00.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft
[2007.09.23 01.26.45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2008.06.16 20.10.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Macrium
[2008.11.23 14.55.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Maxtor
[2008.02.09 01.00.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Meridian93
[2007.12.10 23.02.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MumboJumbo
[2008.01.18 22.38.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2008.06.28 20.43.16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NeoEdge Networks
[2009.09.14 14.21.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PCPitstop
[2009.03.11 14.26.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PlayFirst
[2010.12.18 23.23.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Playrix Entertainment
[2010.12.15 13.32.04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2010.10.10 21.51.55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010.12.14 23.14.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RVLGames
[2008.04.13 21.17.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Saitek
[2009.08.10 17.39.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Sandlot Games
[2007.09.05 20.14.16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SongbirdVLC
[2009.09.16 11.11.46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2008.01.01 00.31.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
[2008.11.22 01.19.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ubisoft
[2009.12.24 10.39.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Wavelet Labs
[2007.04.13 22.49.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WildTangent
[2007.07.12 16.07.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WinZip
[2009.03.23 23.16.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2010.10.23 14.40.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2009.07.27 02.23.16 | 000,000,000 | -HSD | M] -- C:\Documents and Settings\All Users\Application Data\{55A29068-F2CE-456C-9148-C869879E2357}
[2010.06.01 14.05.02 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2009.12.31 20.44.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009.05.26 15.33.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2010.06.01 14.05.16 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\{CCE9E666-4D7C-4946-A98B-CFDE0A0C1706}
[2005.09.14 06.56.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\.bittorrent
[2007.11.08 02.17.02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\.gaim
[2010.12.20 22.45.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\.minecraft
[2009.05.27 21.39.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\.purple
[2010.08.02 00.59.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Absolute Audio Converter
[2007.12.26 19.16.52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Age of Japan II
[2008.01.08 00.00.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Alawar
[2005.11.21 05.29.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Allume Systems
[2009.06.04 21.00.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Amazon
[2007.10.26 15.27.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\AptEdit
[2009.03.01 23.05.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Archibald's Adventures
[2008.06.12 21.49.40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\ArcticLine
[2009.02.16 23.40.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Bioshock
[2008.06.07 22.05.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Bloom
[2009.06.07 00.02.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Braid
[2009.04.18 20.21.53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Bump Technologies, Inc
[2009.03.25 20.50.08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\com.adobe.kuler.Desktop.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2009.04.21 16.22.15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\com.gog.downloader.87F90EC6C28C7E479115BE2E026DB87A08BC420D.1
[2009.06.08 18.29.18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\com.levitation.ColorBrowser.E8C85B0D1658562C6BF4EE77663EB3C86B87123C.1
[2009.08.21 20.37.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\com.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
[2009.01.10 23.35.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Crayon Physics Deluxe
[2009.03.24 14.13.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\de.makesoft.twhirl.0EA062BC275E7ED1E6EC3762EFFD73C7158ADF33.1
[2010.01.03 16.23.44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\DeepVoyage
[2008.09.04 18.13.06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\DoubleSafety
[2011.01.13 14.52.39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Dropbox
[2008.10.11 21.54.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\EleFun Games
[2007.07.17 14.51.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Eltima Software
[2009.04.30 00.00.51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Extensis
[2006.07.01 22.06.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\FlashFXP
[2006.08.13 20.12.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Flickr
[2008.06.24 22.22.26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Flood Light Games
[2009.03.08 12.08.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Gamelab
[2008.06.29 23.27.01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Genimo
[2008.07.13 00.34.32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\GetRightToGo
[2007.10.13 20.06.23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\GlarySoft
[2009.10.24 21.31.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Gold Casual Games
[2007.11.21 17.34.24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\gtk-2.0
[2008.06.28 17.50.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Home Sweet Home
[2007.09.12 23.03.12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\IcoFX
[2010.07.03 15.19.15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\IdeaBoxGame
[2007.05.04 21.25.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\IMBT
[2005.06.30 14.04.37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Infineon
[2008.11.14 20.18.39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\JAM Software
[2008.04.12 20.51.58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Jane s Hotel
[2009.03.30 00.36.51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Jane s Hotel Family Hero
[2009.04.16 02.04.51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Jetbricks
[2009.04.10 13.28.06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\JustResizeIt.742E03C4887133AEE1D0C646BCFAA94B0D0E9874.1
[2009.03.31 20.42.19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Klok.AF6B2973D903BFAE0589C27890FE0146C233490A.1
[2010.11.18 22.52.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Launchy
[2005.11.20 02.21.20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Leadertech
[2008.01.07 22.38.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Legends of pirates
[2008.11.21 23.52.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\LimeWire
[2008.01.19 20.57.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Meridian93
[2007.11.15 00.28.43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Miranda
[2009.06.04 01.03.31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Mp3 Music Editor
[2005.11.26 21.55.58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\My Games
[2008.08.30 23.37.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Mythic Adventure
[2008.01.18 22.19.56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\NCH Swift Sound
[2009.04.15 18.18.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\NetStat Agent
[2009.03.30 00.33.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Notepad++
[2010.06.14 11.53.28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Obsidium
[2010.07.17 20.07.47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\OnLive
[2008.11.22 22.30.04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\OpenOffice.org
[2007.01.10 17.54.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Opera
[2009.03.11 14.26.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\PlayFirst
[2010.11.11 23.15.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Playrix Entertainment
[2008.02.26 22.59.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\PPTminimizer
[2007.09.29 23.18.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Publish Providers
[2010.06.07 00.50.38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\RainbowGames
[2010.12.06 03.50.42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Raptr
[2009.08.02 15.52.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\RenPy
[2009.12.30 16.58.53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\runic games
[2010.08.02 01.03.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\RunningPillow
[2009.12.07 17.11.22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\SecondLife
[2008.01.19 20.57.05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Softplicity
[2009.09.10 23.39.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Software Informer
[2007.09.05 20.12.56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Songbird
[2007.09.29 23.17.35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Sony
[2008.07.19 00.42.48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\SPORE Creature Creator
[2009.09.24 18.15.52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Systweak
[2005.08.17 22.03.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Thunderbird
[2010.08.01 23.52.10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Trio
[2007.03.14 17.23.08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Turbine
[2009.03.24 14.00.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1
[2010.07.18 21.59.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2007.03.14 23.23.33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\URSE Games
[2010.10.03 20.49.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\uTorrent
[2009.11.16 18.27.29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\user1\Application Data\Yoono
[2011.01.13 14.56.02 | 000,000,472 | ---- | M] () -- C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
[2011.01.13 14.48.20 | 000,000,312 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryInitialize.job
[2011.01.03 14.09.36 | 000,000,392 | ---- | M] () -- C:\WINDOWS\Tasks\GlaryOneClickOptimizer.job
[2011.01.13 14.50.58 | 000,000,330 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Scan.job
[2011.01.12 23.33.00 | 000,000,548 | ---- | M] () -- C:\WINDOWS\Tasks\Rescue Reminder for 2HAA7K8A.job
[2011.01.13 15.29.55 | 000,000,392 | -H-- | M] () -- C:\WINDOWS\Tasks\User_Feed_Synchronization-{7DD405FA-CD81-431D-BD0A-0F6B00BA5F78}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 184 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DCD39382
@Alternate Data Stream - 167 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CF39FA77
@Alternate Data Stream - 166 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:4F0FFA06
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E1D6C864
< End of report >