I have uninstalled norton update (ccSvcHst.exe) and it didn't help.
There is a file called conime.exe that keeps adding itself to the startup at boot. But when I try to look for the file it doesn't exsist.
I think it might be malware or a root/boot kit. I have ran quick scan on malwarebytes updated on the 18th may 2011 and it found nothing.
Avast found nothing except for a few tools from binpack (metasploit,sqlninja and afew similar apps)
Any help will be appreciated.
Thanks in advance.
OTL.Txt
OTL logfile created on: 20/05/2011 09:17:16 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Users\VMw4r3\Desktop
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00001809 | Country: Ireland | Language: ENI | Date Format: dd/MM/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 39.00% Memory free
4.00 Gb Paging File | 2.00 Gb Available in Paging File | 50.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 74.43 Gb Total Space | 27.76 Gb Free Space | 37.29% Space Free | Partition Type: NTFS
Drive E: | 7.15 Gb Total Space | 1.04 Gb Free Space | 14.56% Space Free | Partition Type: FAT32
Computer Name: VMW4R3-PC | User Name: VMw4r3 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/20 08:51:56 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\VMw4r3\Desktop\OTL.exe
PRC - [2011/05/19 21:29:06 | 000,062,464 | ---- | M] () -- C:\Program Files\BWMeter\BWMeterConSvc.exe
PRC - [2011/04/18 18:25:12 | 003,460,784 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastUI.exe
PRC - [2011/04/18 18:25:10 | 000,042,184 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
PRC - [2011/04/15 02:23:22 | 000,127,816 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpntray.exe
PRC - [2011/04/15 02:20:42 | 000,289,096 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2011/04/15 00:18:12 | 000,328,952 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2011/04/15 00:18:10 | 000,352,304 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2011/04/14 17:41:09 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Users\VMw4r3\AppData\Local\Mozilla Firefox\firefox.exe
PRC - [2011/02/25 06:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2010/12/14 14:42:42 | 000,653,120 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesApp32.exe
PRC - [2010/12/14 14:41:10 | 001,517,376 | ---- | M] (TuneUp Software) -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe
PRC - [2010/11/20 13:17:47 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2010/11/20 13:17:00 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\cmd.exe
PRC - [2010/11/20 13:17:00 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2010/10/18 12:41:52 | 002,362,880 | ---- | M] (DSGi) -- C:\Windows\System32\spool\drivers\w32x86\3\ADAiO2MUI.exe
PRC - [2010/09/30 10:53:18 | 000,361,904 | ---- | M] (DSGi) -- C:\Program Files\Advent\AIO\Center\ADAIOHostService.exe
PRC - [2010/07/01 20:52:46 | 000,603,904 | ---- | M] (TuneUp Software) -- C:\Windows\System32\TUProgSt.exe
PRC - [2010/04/29 15:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2010/04/29 15:39:32 | 000,437,584 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2009/03/31 10:39:36 | 000,233,472 | ---- | M] (Teruten) -- C:\Windows\System32\FsUsbExService.Exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/03/13 19:08:58 | 000,024,576 | ---- | M] (Vodafone) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
PRC - [2007/07/02 13:29:22 | 000,159,744 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\Apoint.exe
PRC - [2007/06/06 16:44:44 | 000,049,152 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApntEx.exe
PRC - [2007/05/22 14:18:56 | 000,050,736 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\ApMsgFwd.exe
PRC - [2007/02/20 13:01:12 | 001,125,088 | ---- | M] (Dell Inc) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/02/20 12:58:04 | 000,387,808 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2006/09/08 15:10:22 | 000,040,960 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\DellTPad\hidfind.exe
PRC - [2005/02/16 16:48:18 | 000,225,280 | ---- | M] (Pro²soft) -- C:\Program Files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe
PRC - [2000/05/20 17:23:48 | 000,086,016 | ---- | M] () -- C:\Windows\StartupMonitor.exe
========== Modules (SafeList) ==========
MOD - [2011/05/20 08:51:56 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\VMw4r3\Desktop\OTL.exe
MOD - [2011/04/18 18:25:09 | 000,199,792 | ---- | M] (AVAST Software) -- C:\Program Files\Alwil Software\Avast5\snxhk.dll
MOD - [2010/11/20 12:55:09 | 001,680,896 | ---- | M] (Microsoft Corporation) -- C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/05/19 21:29:06 | 000,062,464 | ---- | M] () [Auto | Running] -- C:\Program Files\BWMeter\BWMeterConSvc.exe -- (BWMeterConSvc)
SRV - [2011/04/18 18:25:10 | 000,042,184 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast5\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/04/15 02:23:30 | 000,063,976 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HssTrayService.exe -- (HssTrayService)
SRV - [2011/04/15 02:20:42 | 000,289,096 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2011/04/15 00:18:12 | 000,328,952 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2011/04/15 00:18:10 | 000,352,304 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2010/12/14 14:41:10 | 001,517,376 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2010/12/14 14:39:10 | 000,029,504 | ---- | M] (TuneUp Software) [Auto | Stopped] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2010/09/30 10:53:18 | 000,361,904 | ---- | M] (DSGi) [Auto | Running] -- C:\Program Files\Advent\AIO\Center\ADAIOHostService.exe -- (Advent AIO Network Discovery Service)
SRV - [2010/09/11 19:34:56 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2010/07/01 20:52:46 | 000,603,904 | ---- | M] (TuneUp Software) [Auto | Running] -- C:\Windows\System32\TUProgSt.exe -- (TuneUp.ProgramStatisticsSvc)
SRV - [2010/07/01 20:52:45 | 000,362,240 | ---- | M] (TuneUp Software) [On_Demand | Stopped] -- C:\Windows\System32\TuneUpDefragService.exe -- (TuneUp.Defrag)
SRV - [2010/04/29 15:39:34 | 000,304,464 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2009/07/14 02:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 02:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/14 02:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/03/31 10:39:36 | 000,233,472 | ---- | M] (Teruten) [Auto | Running] -- C:\Windows\System32\FsUsbExService.Exe -- (FsUsbExService)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)
SRV - [2008/11/09 21:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2008/10/02 18:25:42 | 000,191,024 | ---- | M] (VMware, Inc.) [On_Demand | Stopped] -- C:\Program Files\VMware\VMware Workstation\vmware-ufad.exe -- (ufad-ws60)
SRV - [2008/04/07 10:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2008/03/13 19:08:58 | 000,024,576 | ---- | M] (Vodafone) [Auto | Running] -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- (VMCService)
SRV - [2007/02/20 12:58:04 | 000,387,808 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (nicconfigsvc)
========== Driver Services (SafeList) ==========
DRV - [2011/05/19 21:29:06 | 000,028,552 | ---- | M] (DeskSoft) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\dsnpfd.sys -- (dsnpfdMP)
DRV - [2011/05/19 21:29:06 | 000,028,552 | ---- | M] (DeskSoft) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dsnpfd.sys -- (dsnpfd)
DRV - [2011/05/10 13:03:54 | 000,441,176 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/05/10 13:03:44 | 000,307,928 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/05/10 13:02:37 | 000,049,240 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/05/10 12:59:56 | 000,025,432 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/05/10 12:59:44 | 000,053,592 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2011/05/10 12:59:35 | 000,019,544 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/04/15 00:18:10 | 000,037,376 | ---- | M] (AnchorFree Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\HssDrv.sys -- (HssDrv)
DRV - [2010/11/29 19:27:40 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand | Running] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2010/11/20 13:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 13:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 13:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 11:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 11:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 10:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 10:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 10:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/10/27 17:46:12 | 000,356,352 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\stwrt.sys -- (STHDA)
DRV - [2010/08/03 16:25:28 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tapoas.sys -- (tapoas)
DRV - [2010/06/23 03:47:58 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\System32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2010/02/11 08:42:22 | 004,450,816 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2009/11/20 16:26:50 | 000,025,984 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2009/07/14 01:18:07 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\WSDPrint.sys -- (WSDPrintDevice)
DRV - [2009/07/14 00:52:10 | 000,014,336 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\vwifimp.sys -- (vwifimp)
DRV - [2009/06/22 19:26:06 | 000,100,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbdev.sys -- (hwusbdev)
DRV - [2009/03/31 10:39:36 | 000,036,608 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\FsUsbExDisk.Sys -- (FsUsbExDisk)
DRV - [2009/03/20 11:01:26 | 000,121,856 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdm.sys -- (ss_bmdm)
DRV - [2009/03/20 11:01:26 | 000,090,112 | ---- | M] (MCCI) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bbus.sys -- (ss_bbus) SAMSUNG USB Mobile Device (WDM)
DRV - [2009/03/20 11:01:26 | 000,014,976 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ss_bmdfl.sys -- (ss_bmdfl) SAMSUNG USB Mobile Modem (Filter)
DRV - [2009/02/24 18:42:14 | 000,116,736 | ---- | M] (MagicISO, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\mcdbus.sys -- (mcdbus)
DRV - [2009/02/17 20:38:12 | 000,112,128 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2008/12/13 11:27:50 | 000,102,784 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2008/10/28 23:08:58 | 000,054,960 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\System32\drivers\vmci.sys -- (vmci)
DRV - [2008/10/02 18:24:48 | 000,022,448 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Program Files\VMware\VMware Workstation\vstor2-ws60.sys -- (vstor2-ws60)
DRV - [2007/09/17 16:53:26 | 000,021,632 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/06/25 18:53:10 | 000,155,136 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2006/08/31 03:47:00 | 000,025,856 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0801co.sys -- (tap0801co) TAP-Win32 Adapter V8 (coLinux)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://uk.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eu.ask.com?o=...18&l=dis&gct=hp
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://ie.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-ie
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 24 5F 12 8A 64 DD CA 01 [binary data]
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/19 00:26:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/19 00:26:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Users\VMw4r3\AppData\Local\Mozilla Firefox\components [2011/05/19 00:26:30 | 000,000,000 | ---D | M]
[2010/08/21 06:11:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Extensions
[2010/08/21 00:32:49 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Extensions\net.openvpn.client
[2010/08/21 06:11:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Extensions\[email protected]
[2011/05/19 23:21:24 | 000,000,000 | ---D | M] (No name found) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions
[2010/07/23 23:39:56 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/08/28 10:24:55 | 000,000,000 | ---D | M] (Add N Edit Cookies) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{038dc421-b19e-4711-a218-1fd10de9163b}
[2011/05/01 16:15:01 | 000,000,000 | ---D | M] (Flagfox) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2011/05/19 20:51:27 | 000,000,000 | ---D | M] (Domain Details) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{152455DE-7B40-4bcf-B5B4-C68A1BE85A91}
[2011/04/15 17:36:37 | 000,000,000 | ---D | M] (MiniEvony Community Toolbar) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{1aec5771-fcd6-4537-a6b7-5f1935fd527c}
[2011/02/28 18:32:11 | 000,000,000 | ---D | M] ("Stop Autoplay") -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{2e61e246-e640-4c56-b1ed-f146dbed48cd}
[2010/04/28 14:52:37 | 000,000,000 | ---D | M] (Advanced Dork:) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{31E65147-5A53-4e52-8A64-FF7EBFA36D76}
[2010/10/19 10:24:44 | 000,000,000 | ---D | M] (Flashblock) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2011/05/06 15:52:13 | 000,000,000 | ---D | M] (Zynga Community Toolbar) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2011/05/19 18:46:16 | 000,000,000 | ---D | M] (Live HTTP Headers) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{8f8fe09b-0bd3-4470-bc1b-8cad42b8203a}
[2010/04/14 21:32:54 | 000,000,000 | ---D | M] (Tor-Proxy.NET Toolbar) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{9815d32d-08c2-42ca-a8c6-43e501a4512f}
[2010/04/17 23:54:31 | 000,000,000 | ---D | M] (Tamper Data) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{9c51bd27-6ed8-4000-a2bf-36cb95c0c947}
[2010/04/14 21:32:55 | 000,000,000 | ---D | M] (Direct Link) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{a4ffd900-48b6-11db-b0de-0800200c9a66}
[2011/05/01 13:39:25 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/02/28 18:32:20 | 000,000,000 | ---D | M] (Web Developer) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{c45c406e-ab73-11d8-be73-000a95be3b12}
[2010/04/14 21:39:00 | 000,000,000 | ---D | M] (AmbientFox) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{c8f71e5b-88f8-42a7-98bb-e4c506161de9}
[2010/05/19 09:14:54 | 000,000,000 | ---D | M] (Torbutton) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{e0204bd5-9d31-402b-a99d-a6aa8ffebdca}
[2011/02/28 18:32:18 | 000,000,000 | ---D | M] (User Agent Switcher) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}
[2011/05/01 16:14:49 | 000,000,000 | ---D | M] (PhZilla) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2011/05/19 18:50:48 | 000,000,000 | ---D | M] (Capture Fox) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2010/04/14 21:32:55 | 000,000,000 | ---D | M] (Copy and Go) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\copyandgo@vimperator
[2011/04/15 17:36:38 | 000,000,000 | ---D | M] (Conduit Engine) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2011/05/12 16:18:04 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2011/02/28 18:32:12 | 000,000,000 | ---D | M] (Server Spy) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2010/08/19 22:34:23 | 000,000,000 | ---D | M] (1-Click YouTube Video Downloader) -- C:\Users\VMw4r3\AppData\Roaming\mozilla\Firefox\Profiles\yhqg1pod.default\extensions\[email protected]
[2011/03/17 23:14:05 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/20 11:55:49 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010/12/16 21:57:35 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/02/28 18:26:04 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
[2011/02/02 22:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2011/05/20 05:15:32 | 000,434,608 | R--- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 14955 more lines...
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [ADAiO2StatusMonitor] C:\Windows\System32\spool\drivers\w32x86\3\ADAiO2MUI.exe (DSGi)
O4 - HKLM..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [Run StartupMonitor] C:\Windows\StartupMonitor.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\Run: [Bandwidth Monitor Pro] C:\Program Files\Bandwidth Monitor Pro\Bandwidth Monitor Pro.exe (Pro²soft)
O4 - HKLM..\RunOnce: [aswAhAScr.dll] C:\Program Files\Alwil Software\Avast5\aswRegSvr.exe ()
O4 - HKLM..\RunOnce: [SpybotDeletingA1818] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA2205] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA3540] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4092] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4783] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4822] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA4905] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA5795] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingA6148] C:\Windows\System32\COMMAND.COM ()
O4 - HKLM..\RunOnce: [SpybotDeletingC1025] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1519] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC1778] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC2982] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC3] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5313] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC5572] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC6566] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKLM..\RunOnce: [SpybotDeletingC9697] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB1335] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB1792] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB375] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB4665] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB4770] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB5612] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB596] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB8155] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingB8768] C:\Windows\System32\COMMAND.COM ()
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD1687] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD17] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD2646] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD2791] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD2875] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD4284] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD5985] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD9357] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000..\RunOnce: [SpybotDeletingD949] C:\Windows\System32\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\__aswSnx private storage\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Activities present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\BrowserEmulation present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\CaretBrowsing present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\CommandBar present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Main present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\PhishingFilter present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Privacy present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Safety present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Toolbar present
O7 - HKU\S-1-5-21-3787302479-1792056733-934747533-1000\Software\Policies\Microsoft\Internet Explorer\Toolbars present
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\paltalk.exe (AVM Software Inc.)
O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\VMw4r3\Desktop\PartyPoker.lnk ()
O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\VMw4r3\Desktop\PartyPoker.lnk ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files\VMware\VMware Workstation\vsocklib.dll (VMware, Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files/DDD%20Pool/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} file:///C:/Program%20Files/DDD%20Pool/Images/armhelper.ocx (ArmHelper Control)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{235f6934-4bbf-11df-a823-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{235f6934-4bbf-11df-a823-005056c00008}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{235f6939-4bbf-11df-a823-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{235f6939-4bbf-11df-a823-005056c00008}\Shell\AutoRun\command - "" = H:\AutoRun.exe
O33 - MountPoints2\{6575a2fd-5e0e-11df-b224-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{6575a2fd-5e0e-11df-b224-005056c00008}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{6575a30d-5e0e-11df-b224-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{6575a30d-5e0e-11df-b224-005056c00008}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{671e9311-8532-11df-b6c8-9566c2d1f879}\Shell - "" = AutoRun
O33 - MountPoints2\{671e9311-8532-11df-b6c8-9566c2d1f879}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{671e9313-8532-11df-b6c8-9566c2d1f879}\Shell - "" = AutoRun
O33 - MountPoints2\{671e9313-8532-11df-b6c8-9566c2d1f879}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{bcd4ecb0-a641-11df-8150-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{bcd4ecb0-a641-11df-8150-005056c00008}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{fb851e12-97a9-11df-bc5d-005056c00008}\Shell - "" = AutoRun
O33 - MountPoints2\{fb851e12-97a9-11df-bc5d-005056c00008}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/20 08:51:17 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Users\VMw4r3\Desktop\OTL.exe
[2011/05/20 08:16:49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
[2011/05/20 08:16:44 | 000,000,000 | ---D | C] -- C:\Program Files\Speccy
[2011/05/20 07:36:30 | 000,031,552 | ---- | C] (TuneUp Software) -- C:\Windows\System32\TURegOpt.exe
[2011/05/20 07:36:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011
[2011/05/20 07:35:26 | 000,000,000 | ---D | C] -- C:\Program Files\TuneUp Utilities 2011
[2011/05/20 07:34:41 | 000,000,000 | -HSD | C] -- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2011/05/20 04:28:27 | 000,000,000 | ---D | C] -- C:\Program Files\VirusTotalUploader2
[2011/05/20 04:28:27 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.0
[2011/05/20 00:05:17 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\windows-binaries
[2011/05/19 23:37:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2011/05/19 21:32:16 | 000,000,000 | ---D | C] -- C:\ProgramData\DeskSoft
[2011/05/19 21:31:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BWMeter
[2011/05/19 21:29:06 | 000,028,552 | ---- | C] (DeskSoft) -- C:\Windows\System32\drivers\dsnpfd.sys
[2011/05/19 21:29:03 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\DeskSoft
[2011/05/19 21:29:03 | 000,000,000 | ---D | C] -- C:\Program Files\BWMeter
[2011/05/19 21:08:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7
[2011/05/19 21:07:42 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\python271
[2011/05/19 18:14:27 | 000,000,000 | ---D | C] -- C:\ProgramData\hssff
[2011/05/19 01:06:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Havij 1.13 Free
[2011/05/19 01:05:59 | 000,000,000 | ---D | C] -- C:\Program Files\Havij 1.14 Free
[2011/05/19 00:30:29 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Apple Computer
[2011/05/19 00:30:29 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Local\Apple Computer
[2011/05/19 00:30:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/05/19 00:28:51 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/05/19 00:28:49 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/19 00:28:48 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/05/19 00:26:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/05/19 00:25:51 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2011/05/19 00:25:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/05/19 00:25:34 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Local\Apple
[2011/05/19 00:25:25 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011/05/19 00:24:17 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/05/19 00:24:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/05/19 00:24:03 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/05/19 00:10:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
[2011/05/19 00:10:18 | 000,000,000 | ---D | C] -- C:\Program Files\Hotspot Shield
[2011/05/13 23:00:00 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TheSnookerClub
[2011/05/13 22:59:55 | 000,000,000 | ---D | C] -- C:\Games
[2011/05/12 14:39:55 | 000,000,000 | ---D | C] -- C:\ProgramData\vsosdk
[2011/05/12 13:50:08 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\Documents\DVDFab
[2011/05/12 13:50:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 8 Qt
[2011/05/12 13:49:46 | 000,000,000 | ---D | C] -- C:\Program Files\DVDFab 8 Qt
[2011/05/07 19:32:11 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Local\FlyOrDie
[2011/05/07 19:31:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\3D Billiards
[2011/05/07 19:31:49 | 000,000,000 | ---D | C] -- C:\Program Files\3D Billiards
[2011/05/07 19:05:06 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DDD Pool
[2011/05/07 19:05:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DDD Pool
[2011/05/07 19:05:02 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\SpinTop
[2011/05/07 19:05:02 | 000,000,000 | ---D | C] -- C:\Program Files\DDD Pool
[2011/05/07 01:19:25 | 000,441,176 | ---- | C] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/05/04 19:53:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyPoker
[2011/05/03 13:10:14 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\Documents\03-05-2011
[2011/04/30 21:03:12 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Local\Mozilla Firefox
[2011/04/28 19:41:40 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Tific
[2011/04/28 19:41:40 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Local\Tific
[2011/04/28 19:41:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Norton
[2011/04/28 19:41:24 | 000,000,000 | ---D | C] -- C:\ProgramData\NortonInstaller
[2011/04/26 03:29:26 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Paltalk Messenger
[2011/04/26 03:29:23 | 000,000,000 | ---D | C] -- C:\Users\VMw4r3\AppData\Roaming\Paltalk
[2011/04/26 03:29:19 | 000,000,000 | ---D | C] -- C:\Windows\Paltalk Messenger
[2011/04/26 03:29:19 | 000,000,000 | ---D | C] -- C:\Program Files\Paltalk Messenger
========== Files - Modified Within 30 Days ==========
[2011/05/20 09:04:03 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/05/20 09:02:03 | 000,000,488 | ---- | M] () -- C:\Windows\tasks\1-Click Maintenance.job
[2011/05/20 08:51:56 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Users\VMw4r3\Desktop\OTL.exe
[2011/05/20 08:16:49 | 000,000,937 | ---- | M] () -- C:\Users\Public\Desktop\Speccy.lnk
[2011/05/20 07:36:19 | 000,002,155 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/05/20 07:36:19 | 000,002,137 | ---- | M] () -- C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2011/05/20 07:04:24 | 000,631,144 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/05/20 07:04:24 | 000,111,822 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/05/20 07:02:01 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/05/20 06:35:14 | 000,000,756 | ---- | M] () -- C:\Windows\wininit.ini
[2011/05/20 05:15:32 | 000,434,608 | R--- | M] () -- C:\Windows\System32\drivers\etc\hosts
[2011/05/20 04:42:51 | 000,001,134 | ---- | M] () -- C:\Users\VMw4r3\Desktop\NoVirusThanks Anti-Rootkit (Free Edition).lnk
[2011/05/20 04:37:54 | 000,001,215 | ---- | M] () -- C:\Users\VMw4r3\Application Data\Microsoft\Internet Explorer\Quick Launch\NoVirusThanks Uploader.lnk
[2011/05/20 04:37:54 | 000,001,191 | ---- | M] () -- C:\Users\Public\Desktop\NoVirusThanks Uploader.lnk
[2011/05/20 04:28:27 | 000,001,993 | ---- | M] () -- C:\Users\VMw4r3\Desktop\VirusTotal Uploader 2.0.lnk
[2011/05/20 04:16:58 | 000,080,384 | ---- | M] () -- C:\Users\VMw4r3\Desktop\MBRCheckRanDom______file.exe
[2011/05/20 03:31:10 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 03:31:10 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/05/20 03:26:13 | 000,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2011/05/20 03:20:52 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/05/19 23:37:39 | 000,000,903 | ---- | M] () -- C:\Users\VMw4r3\Desktop\WinRAR.lnk
[2011/05/19 21:32:02 | 000,001,773 | ---- | M] () -- C:\Users\Public\Desktop\BWMeter.lnk
[2011/05/19 21:29:06 | 000,028,552 | ---- | M] (DeskSoft) -- C:\Windows\System32\drivers\dsnpfd.sys
[2011/05/19 01:06:01 | 000,000,933 | ---- | M] () -- C:\Users\Public\Desktop\Havij.lnk
[2011/05/19 00:30:13 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/19 00:26:10 | 000,001,815 | ---- | M] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/19 00:12:04 | 000,001,110 | ---- | M] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2011/05/18 23:59:55 | 007,908,720 | ---- | M] () -- C:\Users\VMw4r3\Desktop\HSS-2.03-install-p14-263-conduit.exe
[2011/05/14 07:03:19 | 000,002,286 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2011/05/13 23:00:00 | 000,000,712 | ---- | M] () -- C:\Users\VMw4r3\Desktop\iSnooker.lnk
[2011/05/12 13:50:02 | 000,000,974 | ---- | M] () -- C:\Users\VMw4r3\Desktop\DVDFab 8 Qt.lnk
[2011/05/10 13:10:59 | 000,040,112 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/05/10 13:10:55 | 000,199,304 | ---- | M] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
[2011/05/10 13:03:54 | 000,441,176 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSnx.sys
[2011/05/10 13:03:44 | 000,307,928 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswSP.sys
[2011/05/10 13:02:37 | 000,049,240 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2011/05/10 12:59:56 | 000,025,432 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2011/05/10 12:59:44 | 000,053,592 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2011/05/10 12:59:35 | 000,019,544 | ---- | M] (AVAST Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2011/05/07 19:31:50 | 000,000,993 | ---- | M] () -- C:\Users\VMw4r3\Desktop\3D Billiards.lnk
[2011/05/07 19:05:06 | 000,000,958 | ---- | M] () -- C:\Users\VMw4r3\Desktop\DDD Pool.lnk
[2011/05/07 19:05:06 | 000,000,164 | ---- | M] () -- C:\Users\VMw4r3\Desktop\More SpinTop Games.url
[2011/05/04 19:53:23 | 000,001,719 | ---- | M] () -- C:\Users\VMw4r3\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2011/05/04 19:53:23 | 000,001,695 | ---- | M] () -- C:\Users\VMw4r3\Desktop\PartyPoker.lnk
[2011/04/30 21:03:17 | 000,001,207 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2011/04/26 03:29:28 | 000,001,108 | ---- | M] () -- C:\Users\VMw4r3\Desktop\Upgrade to Paltalk Extreme.lnk
[2011/04/26 03:29:27 | 000,001,903 | ---- | M] () -- C:\Users\VMw4r3\Desktop\Paltalk Messenger.lnk
========== Files Created - No Company Name ==========
[2011/05/20 08:16:49 | 000,000,937 | ---- | C] () -- C:\Users\Public\Desktop\Speccy.lnk
[2011/05/20 07:36:19 | 000,002,155 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp 1-Click Maintenance.lnk
[2011/05/20 07:36:19 | 000,002,137 | ---- | C] () -- C:\Users\Public\Desktop\TuneUp Utilities 2011.lnk
[2011/05/20 07:36:18 | 000,002,149 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TuneUp Utilities 2011
[2011/05/20 06:35:12 | 000,000,756 | ---- | C] () -- C:\Windows\wininit.ini
[2011/05/20 04:42:51 | 000,001,134 | ---- | C] () -- C:\Users\VMw4r3\Desktop\NoVirusThanks Anti-Rootkit (Free Edition).lnk
[2011/05/20 04:37:54 | 000,001,215 | ---- | C] () -- C:\Users\VMw4r3\Application Data\Microsoft\Internet Explorer\Quick Launch\NoVirusThanks Uploader.lnk
[2011/05/20 04:37:54 | 000,001,191 | ---- | C] () -- C:\Users\Public\Desktop\NoVirusThanks Uploader.lnk
[2011/05/20 04:28:27 | 000,001,993 | ---- | C] () -- C:\Users\VMw4r3\Desktop\VirusTotal Uploader 2.0.lnk
[2011/05/20 04:16:53 | 000,080,384 | ---- | C] () -- C:\Users\VMw4r3\Desktop\MBRCheckRanDom______file.exe
[2011/05/19 23:37:39 | 000,000,903 | ---- | C] () -- C:\Users\VMw4r3\Desktop\WinRAR.lnk
[2011/05/19 23:26:41 | 000,002,853 | ---- | C] () -- C:\Users\VMw4r3\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stop StartupMonitor.lnk
[2011/05/19 21:32:02 | 000,001,773 | ---- | C] () -- C:\Users\Public\Desktop\BWMeter.lnk
[2011/05/19 01:06:01 | 000,000,933 | ---- | C] () -- C:\Users\Public\Desktop\Havij.lnk
[2011/05/19 00:30:13 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/05/19 00:26:10 | 000,001,815 | ---- | C] () -- C:\Users\Public\Desktop\QuickTime Player.lnk
[2011/05/19 00:25:29 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/05/19 00:12:04 | 000,001,110 | ---- | C] () -- C:\Users\Public\Desktop\Hotspot Shield Launch.lnk
[2011/05/18 23:59:21 | 007,908,720 | ---- | C] () -- C:\Users\VMw4r3\Desktop\HSS-2.03-install-p14-263-conduit.exe
[2011/05/13 23:00:00 | 000,000,712 | ---- | C] () -- C:\Users\VMw4r3\Desktop\iSnooker.lnk
[2011/05/12 13:50:02 | 000,000,974 | ---- | C] () -- C:\Users\VMw4r3\Desktop\DVDFab 8 Qt.lnk
[2011/05/07 19:31:50 | 000,000,993 | ---- | C] () -- C:\Users\VMw4r3\Desktop\3D Billiards.lnk
[2011/05/07 19:05:06 | 000,000,958 | ---- | C] () -- C:\Users\VMw4r3\Desktop\DDD Pool.lnk
[2011/05/07 19:05:06 | 000,000,164 | ---- | C] () -- C:\Users\VMw4r3\Desktop\More SpinTop Games.url
[2011/05/04 19:53:23 | 000,001,719 | ---- | C] () -- C:\Users\VMw4r3\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2011/05/04 19:53:23 | 000,001,695 | ---- | C] () -- C:\Users\VMw4r3\Desktop\PartyPoker.lnk
[2011/04/30 21:03:16 | 000,001,237 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox
[2011/04/26 03:29:28 | 000,001,108 | ---- | C] () -- C:\Users\VMw4r3\Desktop\Upgrade to Paltalk Extreme.lnk
[2011/04/26 03:29:27 | 000,001,903 | ---- | C] () -- C:\Users\VMw4r3\Desktop\Paltalk Messenger.lnk
[2011/02/24 20:59:34 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/02/24 20:57:36 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2011/02/23 16:29:45 | 000,110,592 | ---- | C] () -- C:\Windows\System32\FsUsbExDevice.Dll
[2011/02/23 16:29:45 | 000,036,608 | ---- | C] () -- C:\Windows\System32\FsUsbExDisk.Sys
[2010/11/22 02:58:55 | 000,005,632 | ---- | C] () -- C:\Users\VMw4r3\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/01 23:02:07 | 000,000,406 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2010/08/06 00:55:27 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/07/23 12:32:24 | 000,000,600 | ---- | C] () -- C:\Users\VMw4r3\AppData\Local\PUTTY.RND
[2010/05/15 09:16:59 | 000,070,667 | ---- | C] () -- C:\Windows\Huawei ModemsUninstall.exe
[2010/04/14 19:38:51 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/02/11 06:30:38 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 000,274,648 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,631,144 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,111,822 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/04/23 23:29:16 | 000,189,051 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008/03/07 16:43:56 | 000,084,734 | R--- | C] () -- C:\ProgramData\DeviceManager.xml.rc4
[2008/03/07 13:47:30 | 000,020,270 | ---- | C] () -- C:\ProgramData\DeviceInstaller.xml
[2007/10/25 18:26:10 | 000,005,632 | ---- | C] () -- C:\Windows\System32\drivers\StarOpen.sys
[2000/05/20 17:23:48 | 000,086,016 | ---- | C] () -- C:\Windows\StartupMonitor.exe
========== LOP Check ==========
[2010/05/15 09:21:36 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Birdstep Technology
[2011/05/19 21:29:03 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\DeskSoft
[2011/01/15 21:50:27 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\FileZilla
[2010/08/21 06:11:13 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\GNUCITIZEN
[2010/07/23 18:39:13 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Mavituna Security Ltd
[2010/07/01 12:10:37 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Notepad++
[2010/08/21 00:32:38 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\OpenVPN Technologies
[2011/04/26 03:34:55 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Paltalk
[2011/02/23 17:19:23 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\PC Suite
[2010/04/25 20:18:01 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\PyScripter
[2011/02/23 16:28:59 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Samsung
[2010/10/19 10:24:47 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\SecurityHeroes
[2011/05/07 19:05:02 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\SpinTop
[2010/12/27 15:32:50 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Temp
[2011/04/28 19:41:40 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Tific
[2011/05/20 07:35:54 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\TuneUp Software
[2011/05/17 22:51:20 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\uTorrent
[2010/08/12 19:50:12 | 000,000,000 | ---D | M] -- C:\Users\VMw4r3\AppData\Roaming\Vodafone
[2011/05/20 09:02:03 | 000,000,488 | ---- | M] () -- C:\Windows\Tasks\1-Click Maintenance.job
[2011/01/10 07:58:56 | 000,032,620 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
< End of report >