I got a problem with Malware/Virus. The problem is: everytime i'm surfing in the web, Firefox opens a new window with 4
tabs: http://www.xn--&-8ga.com/
file:///C:/Windows/
file:///C:/Windows/T%E2%80%98%C3%91%C3%A5%C2%AD%C2%A6%C5%92M%E2%80%98%1A%C2%BD%C5%B8y%C2%A7d%C3%B9%11vU%C2%B0%C2%BEd%C2%B3%C3%A7%C3%94%0EA%C2%AE%C2%A0.%C3%82%C2%BB%C2%A1%C2%AE%11%C3%84%C3%ABF+5%C3%B8%C3%88%E2%80%94%C3%B7%C3%84%08%C3%BD%C3%87%13siB%C3%BD%E2%80%A1%E2%84%A2p%C2%B0%E2%84%A2%C3%BB%C3%BE:%C2%AF%C3%A3%04%5B%C3%94:%C5%BE%20%C3%A1%E2%80%A0H%0B%C2%BDA%E2%82%AC:%C3%A0%C2%9D%C3%84%C2%AA%C3%8A%C5%A0SH%C2%AB%C3%A7%E2%80%98%17%C2%A9%C2%A5:%112%C3%9C%C2%BB%60%0E$%C3%A7%C3%A3%C3%BD%%19xmG%15%C3%B2%C3%B0%C3%99%C2%8F%1F%C3%83b%C3%9Cc%C2%AE%E2%84%A2%C3%9Bj%1FV%C3%91*%C3%87~%E2%84%A2%C3%985S.%04f%C3%8B%C3%86%C3%8C%C3%8B%C3%A0%C2%A8%C3%A55I*D%C3%968%02%C3%8Ad%C3%8DC%E2%80%A0%C3%B7%C3%A8%E2%80%A0%E2%80%BAG%C5%92!%1C%C3%8A:%C2%A5k%C2%B7%C3%B5%5DADj%E2%80%A2%C3%B5S%C3%90l%C3%B9%05%1B%0Cn~%C2%A2%C3%B9%C2%A5%C3%9Fv%C2%8D%C2%AF2Y%C3%B4%C5%BE%C2%BF%C3%A2%E2%80%B9J?^%E2%80%99d%C2%9DTFl%C3%A4zg%C2%B5%C3%B2%7F%C3%91u%C5%BDn%E2%80%98%C2%B3%C3%B4p+%C3%A3f%C2%B5%C2%A9%E2%80%A6%C3%A6l%C3%918%03%C2%AA%C3%AC
http://www.xn--pda.com/
OTL Log: OTL logfile created on: 15.08.2011 18:18:22 - Run 1
OTL by OldTimer - Version 3.2.26.4 Folder = C:\Users\omar\Downloads
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy
1,75 Gb Total Physical Memory | 0,84 Gb Available Physical Memory | 48,02% Memory free
6,63 Gb Paging File | 5,33 Gb Available in Paging File | 80,44% Paging File free
Paging file location(s): c:\pagefile.sys 5000 8000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 232,79 Gb Total Space | 4,70 Gb Free Space | 2,02% Space Free | Partition Type: NTFS
Drive D: | 521,28 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Drive E: | 2,37 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: OMAR-PC | User Name: omar | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011.08.15 18:16:36 | 000,579,584 | ---- | M] (OldTimer Tools) -- C:\Users\omar\Downloads\OTL.exe
PRC - [2011.08.04 14:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) -- C:\Programme\LogMeIn Hamachi\hamachi-2.exe
PRC - [2011.08.02 08:58:46 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Programme\Steam\Steam.exe
PRC - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avguard.exe
PRC - [2011.06.24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) -- C:\Programme\Application Updater\ApplicationUpdater.exe
PRC - [2011.06.24 15:56:56 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Programme\Mozilla Firefox\firefox.exe
PRC - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Programme\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.06.01 14:10:00 | 000,821,080 | ---- | M] (IObit) -- C:\Programme\IObit\IObit Malware Fighter\IMFsrv.exe
PRC - [2011.05.28 14:46:56 | 000,353,168 | ---- | M] (IObit) -- C:\Programme\IObit\Advanced SystemCare 4\ASCService.exe
PRC - [2011.05.24 23:17:32 | 000,294,400 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Programme\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2011.04.21 07:53:10 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\sched.exe
PRC - [2011.04.21 07:52:36 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Programme\Avira\AntiVir Desktop\avgnt.exe
PRC - [2011.03.01 16:47:56 | 002,296,696 | ---- | M] (TeamViewer GmbH) -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011.02.24 11:31:48 | 002,602,920 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec\Symantec System Recovery\Agent\VProTray.exe
PRC - [2011.02.24 11:31:46 | 004,615,080 | ---- | M] (Symantec Corporation) -- C:\Programme\Symantec\Symantec System Recovery\Agent\VProSvc.exe
PRC - [2011.01.12 17:23:08 | 001,966,064 | ---- | M] (Symantec) -- C:\Programme\Symantec\Symantec System Recovery\Shared\Drivers\SymSnapService.exe
PRC - [2010.11.25 22:48:46 | 000,619,288 | ---- | M] (http://tortoisesvn.net) -- C:\Programme\TortoiseSVN\bin\TSVNCache.exe
PRC - [2010.11.10 03:54:18 | 004,240,760 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Messenger\msnmsgr.exe
PRC - [2010.11.10 02:13:30 | 000,025,456 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Live\Contacts\wlcomm.exe
PRC - [2010.09.21 15:03:14 | 001,710,464 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
PRC - [2010.09.21 15:03:14 | 000,193,408 | ---- | M] (Microsoft Corp.) -- C:\Programme\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
PRC - [2009.07.14 03:14:47 | 001,121,280 | ---- | M] (Microsoft Corporation) -- C:\Programme\Windows Media Player\wmpnetwk.exe
PRC - [2009.07.14 03:14:42 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2009.07.14 03:14:15 | 000,271,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2005.03.09 21:50:18 | 000,018,944 | ---- | M] (http://libusb-win32.sourceforge.net) -- C:\Windows\System32\libusbd-nt.exe
========== Modules (No Company Name) ==========
MOD - [2011.08.13 13:16:46 | 014,407,976 | ---- | M] () -- C:\Programme\Steam\bin\libcef.dll
MOD - [2011.08.13 13:16:45 | 000,914,216 | ---- | M] () -- C:\Programme\Steam\bin\avcodec-52.dll
MOD - [2011.08.13 13:16:45 | 000,190,248 | ---- | M] () -- C:\Programme\Steam\bin\chromehtml.dll
MOD - [2011.08.13 13:16:45 | 000,155,432 | ---- | M] () -- C:\Programme\Steam\bin\avformat-52.dll
MOD - [2011.08.13 13:16:45 | 000,091,432 | ---- | M] () -- C:\Programme\Steam\bin\avutil-50.dll
MOD - [2011.06.24 15:56:56 | 001,850,328 | ---- | M] () -- C:\Programme\Mozilla Firefox\mozjs.dll
MOD - [2011.06.17 12:29:30 | 006,271,136 | ---- | M] () -- C:\Windows\System32\Macromed\Flash\NPSWF32.dll
MOD - [2006.08.24 14:17:52 | 000,004,096 | ---- | M] () -- C:\Programme\Messenger Plus! Live\Detoured.dll
========== Win32 Services (SafeList) ==========
SRV - [2011.08.04 21:45:48 | 003,542,616 | ---- | M] () [Auto | Running] -- c:\Programme\Common Files\Akamai\netsession_win_2da1ebd.dll -- (Akamai)
SRV - [2011.08.04 14:34:46 | 001,361,288 | ---- | M] (LogMeIn Inc.) [Auto | Running] -- C:\Program Files\LogMeIn Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2011.08.02 09:55:26 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011.07.21 12:08:02 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011.06.24 17:30:48 | 000,393,112 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater)
SRV - [2011.06.06 12:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.06.01 14:10:00 | 000,821,080 | ---- | M] (IObit) [Auto | Running] -- C:\Programme\IObit\IObit Malware Fighter\IMFsrv.exe -- (IMFservice)
SRV - [2011.05.28 14:46:56 | 000,353,168 | ---- | M] (IObit) [Auto | Running] -- C:\Programme\IObit\Advanced SystemCare 4\ASCService.exe -- (AdvancedSystemCareService)
SRV - [2011.05.24 23:17:32 | 000,294,400 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2011.04.21 07:52:51 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011.03.01 16:47:56 | 002,296,696 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Programme\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011.02.24 11:31:46 | 004,615,080 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Programme\Symantec\Symantec System Recovery\Agent\VProSvc.exe -- (Symantec System Recovery)
SRV - [2011.01.24 14:31:34 | 001,343,400 | ---- | M] (Microsoft Corporation) [Unknown | Stopped] -- C:\Windows\System32\Wat\WatAdminSvc.exe -- (WatAdminSvc)
SRV - [2011.01.14 13:33:40 | 001,574,408 | ---- | M] (Symantec) [On_Demand | Stopped] -- C:\Program Files\Symantec\Symantec System Recovery\Shared\Drivers\GenericMountHelper.exe -- (GenericMount Helper Service)
SRV - [2011.01.12 17:23:08 | 001,966,064 | ---- | M] (Symantec) [On_Demand | Running] -- C:\Program Files\Symantec\Symantec System Recovery\Shared\Drivers\SymSnapService.exe -- (SymSnapService)
SRV - [2010.12.07 22:18:00 | 003,979,632 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\System32\GameMon.des -- (npggsvc)
SRV - [2010.02.17 10:53:18 | 003,093,880 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Programme\Symantec\LiveUpdate\LuComServer_3_3.EXE -- (LiveUpdate)
SRV - [2009.07.14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009.07.14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009.07.14 03:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Programme\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2005.03.09 21:50:18 | 000,018,944 | ---- | M] (http://libusb-win32.sourceforge.net) [Auto | Running] -- C:\Windows\System32\libusbd-nt.exe -- (libusbd)
========== Driver Services (SafeList) ==========
DRV - [2011.07.21 12:11:12 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\avipbb.sys -- (avipbb)
DRV - [2011.07.21 12:11:11 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\Windows\System32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011.06.07 16:04:20 | 000,162,432 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\ithsgt.sys -- (ithsgt)
DRV - [2011.06.07 16:04:14 | 000,012,032 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\System32\drivers\lilsgt.sys -- (lilsgt)
DRV - [2011.05.22 18:23:45 | 000,431,672 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\sptd.sys -- (sptd)
DRV - [2011.04.27 19:17:48 | 000,018,768 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\Programme\IObit\IObit Malware Fighter\Drivers\win7_x86\FileMonitor.sys -- (FileMonitor)
DRV - [2011.03.23 00:58:32 | 000,019,280 | ---- | M] (IObit.com) [Kernel | On_Demand | Stopped] -- C:\Programme\IObit\IObit Malware Fighter\Drivers\win7_x86\UrlFilter.sys -- (UrlFilter)
DRV - [2011.03.23 00:58:28 | 000,030,600 | ---- | M] (IObit.com) [Kernel | On_Demand | Stopped] -- C:\Programme\IObit\IObit Malware Fighter\Drivers\win7_x86\RegFilter.sys -- (RegFilter)
DRV - [2011.02.24 11:52:58 | 000,131,000 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\System32\drivers\WimFltr.sys -- (WimFltr)
DRV - [2011.02.23 16:50:44 | 000,016,184 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\SmartDefragDriver.sys -- (SmartDefragDriver)
DRV - [2011.01.14 13:34:24 | 000,057,840 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\GenericMount.sys -- (GenericMount)
DRV - [2011.01.12 17:25:10 | 000,139,360 | ---- | M] (StorageCraft) [File_System | Boot | Running] -- C:\Windows\system32\DRIVERS\symsnap.sys -- (symsnap)
DRV - [2010.03.18 20:01:22 | 000,048,640 | ---- | M] (MotioninJoy) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\MijXfilt.sys -- (MotioninJoyXFilter)
DRV - [2010.02.18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009.10.08 17:55:33 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Windows\System32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2009.09.21 20:40:14 | 000,015,096 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vproeventmonitor.sys -- (VProEventMonitor)
DRV - [2009.07.14 03:19:10 | 000,175,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vmbus.sys -- (vmbus)
DRV - [2009.07.14 03:19:10 | 000,040,896 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\system32\DRIVERS\vmstorfl.sys -- (storflt)
DRV - [2009.07.14 03:19:10 | 000,028,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\storvsc.sys -- (storvsc)
DRV - [2009.07.14 01:28:47 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\vms3cap.sys -- (s3cap)
DRV - [2009.07.14 01:28:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\system32\DRIVERS\VMBusHID.sys -- (VMBusHID)
DRV - [2009.07.14 00:02:47 | 000,050,688 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1C62x86.sys -- (L1C) NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20)
DRV - [2009.04.22 21:42:30 | 000,304,128 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\VPS3Joy.sys -- (VPS3Joy) Virtual Playstation(3)
DRV - [2009.03.18 17:35:40 | 000,026,176 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\hamachi.sys -- (hamachi)
DRV - [2008.12.01 23:14:34 | 004,179,968 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (atikmdag)
DRV - [2007.06.29 14:47:34 | 000,034,304 | ---- | M] (AMD, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AmdLLD.sys -- (AmdLLD)
DRV - [2005.03.09 21:50:16 | 000,033,792 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\libusb0.sys -- (libusb0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 43 20 34 4C 0C 12 CC 01 [binary data]
IE - HKCU\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programme\IObit Toolbar\IE\4.5\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=382950&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=382950&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=382950&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=382950&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950"
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@bittorrent.com/BitTorrentDNA: C:\Program Files\DNA\plugins\npbtdna.dll (BitTorrent, Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@gamersfirst.com/LiveLauncher: C:\Program Files\GamersFirst\LIVE!\nplivelauncher.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60129.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pages.tvunetworks.com/WebPlayer: C:\Program Files\TVUPlayer\npTVUAx.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKLM\Software\MozillaPlugins\@SonyCreativeSoftware.com/Media Go,version=1.0: C:\Program Files\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Program Files\Roblox\Versions\version-f93a5a6aa7924fae\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\omar\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\omar\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\omar\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2011.07.26 14:28:00 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.06.24 15:56:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.08.03 09:38:19 | 000,000,000 | ---D | M]
[2011.04.07 13:43:09 | 000,000,000 | ---D | M] (No name found) -- C:\Users\omar\AppData\Roaming\mozilla\Extensions
[2011.07.26 14:18:26 | 000,000,000 | ---D | M] (No name found) -- C:\Users\omar\AppData\Roaming\mozilla\Firefox\Profiles\muvhh96j.default\extensions
[2011.07.13 12:36:25 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\omar\AppData\Roaming\mozilla\Firefox\Profiles\muvhh96j.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2011.04.23 19:21:55 | 000,000,000 | ---D | M] (Battlefield Play4Free) -- C:\Users\omar\AppData\Roaming\mozilla\Firefox\Profiles\muvhh96j.default\extensions\[email protected]
[2011.05.22 18:24:20 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\omar\AppData\Roaming\mozilla\Firefox\Profiles\muvhh96j.default\extensions\[email protected]
[2011.08.08 17:16:45 | 000,000,000 | ---D | M] (No name found) -- C:\Users\omar\AppData\Roaming\mozilla\SeaMonkey\Profiles\neu4jwft.default\extensions
[2011.07.30 20:07:23 | 000,000,000 | ---D | M] (No name found) -- C:\Programme\Mozilla Firefox\extensions
[2011.06.14 15:19:53 | 000,000,000 | ---D | M] (Skype extension) -- C:\Programme\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011.06.21 18:15:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
[2011.07.30 20:07:23 | 000,000,000 | ---D | M] (Java Console) -- C:\Programme\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011.06.24 15:56:56 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2008.07.16 15:42:38 | 000,066,208 | ---- | M] (Joost Technologies B.V. ) -- C:\Program Files\mozilla firefox\plugins\npJoostPlugin.dll
[2010.01.01 10:00:00 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2010.01.01 10:00:00 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2010.01.01 10:00:00 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2010.01.01 10:00:00 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2010.01.01 10:00:00 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2010.01.01 10:00:00 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml
O1 HOSTS File: ([2009.06.10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programme\IObit Toolbar\IE\4.5\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Programme\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programme\IObit Toolbar\IE\4.5\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [amd_dc_opt] C:\Programme\AMD\Dual-Core Optimizer\amd_dc_opt.exe (AMD)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Symantec System Recovery 2011] C:\Program Files\Symantec\Symantec System Recovery\Agent\VProTray.exe (Symantec Corporation)
O4 - HKCU..\Run: [Advanced SystemCare 4] C:\Program Files\IObit\Advanced SystemCare 4\ASCTray.exe (IObit)
O4 - HKCU..\Run: [BitTorrent DNA] C:\Program Files\DNA\btdna.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Comrade.exe] C:\Programme\GameSpy\Comrade\Comrade.exe (IGN Entertainment Inc.)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (www.motioninjoy.com)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\RunOnce: [FlashPlayerUpdate] C:\Windows\System32\Macromed\Flash\FlashUtil10t_Plugin.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk = C:\Programme\Xfire\Xfire.exe (Xfire Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Programme\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zon...kr.cab56986.cab (Checkers Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Programme\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Programme\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programme\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Programme\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O27 - HKLM IFEO\notepad.exe: Debugger - "C:\Program Files\Notepad2\Notepad2.exe" /z ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2004.03.31 20:14:30 | 000,000,147 | R--- | M] () - D:\autorun.inf -- [ CDFS ]
O32 - AutoRun File - [2011.08.02 21:14:57 | 000,000,077 | R--- | M] () - E:\autorun.inf -- [ CDFS ]
O33 - MountPoints2\{19cc2840-8e9b-11e0-91dd-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{19cc2840-8e9b-11e0-91dd-806e6f6e6963}\Shell\AutoRun\command - "" = G:\Setup.exe
O33 - MountPoints2\{28c0dcc0-8490-11e0-af17-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{28c0dcc0-8490-11e0-af17-806e6f6e6963}\Shell\AutoRun\command - "" = E:\Setup.exe -- [2011.08.02 21:14:57 | 001,892,384 | R--- | M] (Streum On Studio )
O33 - MountPoints2\{28c0dcc1-8490-11e0-af17-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{28c0dcc1-8490-11e0-af17-806e6f6e6963}\Shell\AutoRun\command - "" = F:\autorun.exe
O33 - MountPoints2\{6956812a-2bad-11e0-a916-00235ad93f8b}\Shell - "" = AutoRun
O33 - MountPoints2\{6956812a-2bad-11e0-a916-00235ad93f8b}\Shell\AutoRun\command - "" = E:\Setup.exe -- [2011.08.02 21:14:57 | 001,892,384 | R--- | M] (Streum On Studio )
O33 - MountPoints2\{b916d440-57f5-11e0-8ddb-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{b916d440-57f5-11e0-8ddb-806e6f6e6963}\Shell\AutoRun\command - "" = F:\Setup\rsrc\autorun.exe
O33 - MountPoints2\{b916d440-57f5-11e0-8ddb-806e6f6e6963}\Shell\dinstall\command - "" = F:\Directx\dxsetup.exe
O33 - MountPoints2\{fe3f64e4-2724-11e0-bad8-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{fe3f64e4-2724-11e0-bad8-806e6f6e6963}\Shell\AutoRun\command - "" = D:\Setup\rsrc\AUTORUN.EXE -- [2000.01.17 18:28:36 | 000,028,672 | R--- | M] (Dipl.-Ing. Stefan Krueger <[email protected]>)
O33 - MountPoints2\{fe3f64e4-2724-11e0-bad8-806e6f6e6963}\Shell\dinstall\command - "" = D:\DirectX\dxsetup.exe -- [2003.08.19 02:15:00 | 000,467,456 | R--- | M] (Microsoft Corporation)
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\Setup.exe -- [2011.08.02 21:14:57 | 001,892,384 | R--- | M] (Streum On Studio )
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011.08.15 18:09:19 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Symantec
[2011.08.15 18:02:59 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{39627752-337C-48A4-9559-6638BD11FECC}
[2011.08.15 18:01:56 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{02AC5E83-7EE0-4891-A33D-CE1D06B8C2B4}
[2011.08.14 21:26:16 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{9E4BB209-BF6F-4C83-9480-26917CE2EDD4}
[2011.08.14 21:25:32 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C5EC83B7-310D-456A-9B75-8CDFFC820DCA}
[2011.08.14 19:52:56 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\Symantec_Corporation
[2011.08.14 17:45:05 | 000,139,360 | ---- | C] (StorageCraft) -- C:\Windows\System32\drivers\symsnap.sys
[2011.08.14 17:44:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Symantec System Recovery
[2011.08.14 17:44:35 | 000,015,096 | ---- | C] (Symantec Corporation) -- C:\Windows\System32\drivers\vproeventmonitor.sys
[2011.08.14 17:43:15 | 000,000,000 | ---D | C] -- C:\ProgramData\79290820-B54E-4bb8-ADA7-3541B45B9445
[2011.08.14 17:43:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Symantec Shared
[2011.08.14 17:42:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Symantec
[2011.08.14 17:42:27 | 000,000,000 | ---D | C] -- C:\Program Files\Symantec
[2011.08.14 13:47:17 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C4EA6215-8F0B-4A21-835C-B5A840C8F3CE}
[2011.08.14 13:46:32 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{7DF09B66-EA77-4829-949F-6874FF66C035}
[2011.08.13 19:44:37 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Avira
[2011.08.13 19:43:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2011.08.13 19:42:25 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\ssmdrv.sys
[2011.08.13 19:42:23 | 000,138,192 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.08.13 19:42:23 | 000,066,616 | ---- | C] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.08.13 19:42:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2011.08.13 19:42:22 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011.08.13 19:41:06 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{93C88E28-252A-44EE-85BC-1495D989CDA0}
[2011.08.13 19:39:37 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{FEC81397-1C04-4727-9B5C-7D9237BAF006}
[2011.08.13 19:12:05 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{3080EFA1-3F99-48CC-A75A-4D3F3DC00729}
[2011.08.13 19:10:53 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{82B3213B-BD5B-46BD-A839-837705C4F724}
[2011.08.13 18:52:20 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{2060857D-6FCA-4534-9DBB-908AFC40D781}
[2011.08.13 13:17:27 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{E82D0F70-0696-4206-9B5A-89105FD6B244}
[2011.08.13 13:17:04 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{94D49ACB-7C77-450E-B887-5E5C65C160B0}
[2011.08.12 18:21:37 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{6A7A624C-0ED0-482C-BB03-FC038A1B9D85}
[2011.08.12 18:19:49 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{96B43B00-8911-4E4A-81C5-773311397A21}
[2011.08.12 16:54:36 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Opera
[2011.08.12 16:54:36 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\Opera
[2011.08.12 16:54:19 | 000,000,000 | ---D | C] -- C:\Program Files\Opera
[2011.08.12 16:50:05 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{672D4E27-3C3E-461E-BE53-73E3AF02E55C}
[2011.08.12 16:49:27 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{F9A6BF8D-3E6B-4F76-91DA-F411B1431E7F}
[2011.08.12 13:32:33 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{ADBD63A6-4FAF-4B4D-9C8C-0E07BD837BCC}
[2011.08.12 13:32:16 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{853EF61F-7158-4BB1-AB72-1394C0B136A7}
[2011.08.11 13:43:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011.08.11 13:43:11 | 000,000,000 | ---D | C] -- C:\Windows\System32\DRVSTORE
[2011.08.11 13:41:24 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011.08.11 13:41:21 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011.08.11 13:41:21 | 000,000,000 | ---D | C] -- C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011.08.11 13:38:59 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011.08.11 13:38:18 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011.08.10 23:54:15 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{0EE57E14-CD71-4774-B80F-25DB1FBF1392}
[2011.08.10 22:06:39 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{27C4D990-3C88-45CB-BFA4-89AD77E3BB62}
[2011.08.10 22:05:22 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{35B95401-16B6-40DF-BBAF-BC6104A4A8DF}
[2011.08.10 20:54:19 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{3DB77F12-3DB7-4119-B0EA-420A3D2B7A29}
[2011.08.10 20:53:41 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{A12251F1-8432-4172-BDA5-E9282F733985}
[2011.08.10 20:34:54 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\mods
[2011.08.10 20:31:10 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\.minecraft
[2011.08.10 19:58:30 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\Amazopack
[2011.08.10 13:19:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Streum On Studio
[2011.08.10 12:59:19 | 000,000,000 | ---D | C] -- C:\Program Files\Streum On Studio
[2011.08.10 12:57:21 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{0A36C644-CE6E-4875-8229-67930836E1CF}
[2011.08.10 09:33:24 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{2648586E-058A-455C-9D55-BB5C42A7BAC8}
[2011.08.09 14:03:38 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\Skylands server
[2011.08.09 13:51:50 | 000,000,000 | ---D | C] -- C:\ProgramData\eMule
[2011.08.09 13:08:28 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\catmario
[2011.08.09 10:28:30 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\Installers
[2011.08.09 09:41:29 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{D4184440-81AA-4328-B65B-0D51DEBF94D7}
[2011.08.09 09:41:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011.08.09 09:41:05 | 000,000,000 | ---D | C] -- C:\Program Files\LogMeIn Hamachi
[2011.08.08 18:43:15 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{8D28D21D-3F61-4DC1-BE38-C94826BD496E}
[2011.08.08 17:06:08 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2011.08.08 10:19:46 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C1DDDD9A-533E-4643-8B72-22DFF69EF1B7}
[2011.08.07 23:33:04 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{AD4127D3-770A-432F-836A-C1EEF1F7803D}
[2011.08.07 20:00:20 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\AdventureCraft
[2011.08.07 18:09:11 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{3CB5CC37-D57E-4E85-95B4-2C4249C22C49}
[2011.08.07 15:24:46 | 000,000,000 | -H-D | C] -- C:\Program Files\Temp
[2011.08.07 00:15:00 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\Arktos
[2011.08.07 00:14:59 | 000,000,000 | ---D | C] -- C:\Users\omar\Documents\Arktos
[2011.08.06 22:04:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Jodix
[2011.08.06 22:04:57 | 000,000,000 | ---D | C] -- C:\Program Files\Free WMA to MP3 Converter
[2011.08.06 21:22:29 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\HLDJ
[2011.08.06 13:23:12 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{E4A7FC10-4846-446B-90BF-8B8A33DDCE56}
[2011.08.06 09:52:12 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{90653FC3-C566-4C73-861C-4514C82BBB67}
[2011.08.05 13:25:11 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{402AB743-D06C-4F74-BE86-E1EA7B8F0C27}
[2011.08.04 19:20:19 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{3A34B3AA-D888-4A8C-90AE-7E5F811CC7DF}
[2011.08.04 16:43:33 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\GetRightToGo
[2011.08.04 16:43:33 | 000,000,000 | ---D | C] -- C:\Users\omar\Documents\Downloads
[2011.08.03 14:15:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ace of Spades
[2011.08.03 14:15:23 | 000,000,000 | ---D | C] -- C:\Ace of Spades
[2011.08.03 12:37:48 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{09C4A7B2-6758-4942-9455-4D65757D7D66}
[2011.08.03 09:37:48 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe
[2011.08.03 09:37:48 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe
[2011.08.02 20:21:49 | 000,000,000 | ---D | C] -- C:\Users\omar\Documents\Duke Nukem Forever Demo
[2011.08.02 20:21:24 | 000,034,304 | ---- | C] (AMD, Inc.) -- C:\Windows\System32\drivers\AmdLLD.sys
[2011.08.02 20:21:00 | 000,000,000 | ---D | C] -- C:\Program Files\AMD
[2011.08.02 13:26:03 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Monolith Productions
[2011.08.02 13:15:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SEGA
[2011.08.02 13:15:39 | 000,000,000 | ---D | C] -- C:\Program Files\SEGA
[2011.08.02 11:22:16 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Half Life Source
[2011.08.02 11:22:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Half Life Source
[2011.08.02 11:22:16 | 000,000,000 | ---D | C] -- C:\Program Files\Half Life
[2011.08.02 09:05:14 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{403A34DB-8A96-496E-9D1A-33F20E4E5D7C}
[2011.08.01 20:31:39 | 000,000,000 | ---D | C] -- C:\Program Files\Fox
[2011.08.01 20:30:12 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fox Interactive
[2011.08.01 20:30:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fox Interactive
[2011.08.01 19:14:53 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{223EC15F-249B-4CA9-96BE-E059849E260E}
[2011.07.31 11:22:48 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{325A6BB1-86CB-4D1D-8317-F8AB0852BBF5}
[2011.07.30 23:20:32 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{BDA28801-4C15-4B6C-9889-BA65274795E5}
[2011.07.30 22:23:55 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heroes of Newerth
[2011.07.30 22:23:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of Newerth
[2011.07.30 22:23:50 | 000,000,000 | ---D | C] -- C:\Users\omar\Documents\Heroes of Newerth
[2011.07.30 22:18:41 | 000,000,000 | ---D | C] -- C:\Program Files\Heroes of Newerth
[2011.07.30 20:08:02 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011.07.30 20:03:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Survivors of Ragnarok
[2011.07.30 20:03:13 | 000,000,000 | ---D | C] -- C:\Program Files\SurvivorsofRagnarok
[2011.07.30 13:31:04 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\Apple Computer
[2011.07.30 13:30:45 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Apple Computer
[2011.07.30 11:19:12 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C8B5A038-E297-40FB-9FD6-988ADED1620C}
[2011.07.29 20:01:13 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{96813E76-C59D-4E69-9E98-99006E76B9D8}
[2011.07.28 13:04:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
[2011.07.28 13:03:55 | 000,000,000 | ---D | C] -- C:\Program Files\GOG.com
[2011.07.27 18:33:11 | 000,000,000 | ---D | C] -- C:\Program Files\Xaya3D
[2011.07.27 14:41:01 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{ED71D90A-7AF6-478D-8911-68155462E6A8}
[2011.07.26 14:29:44 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\DDMSettings
[2011.07.26 14:27:38 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\DivX
[2011.07.26 14:27:01 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\PX Storage Engine
[2011.07.26 14:26:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX Plus
[2011.07.26 14:25:26 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DivX Shared
[2011.07.26 14:22:50 | 000,000,000 | ---D | C] -- C:\Program Files\DivX
[2011.07.26 14:21:24 | 000,000,000 | ---D | C] -- C:\ProgramData\DivX
[2011.07.26 12:31:36 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2011.07.25 11:03:59 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C473905C-7E69-4ABB-8D9E-65CB8C3E2413}
[2011.07.24 22:30:44 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{4807C2BB-BC92-4B5E-816D-01B525454FC0}
[2011.07.24 20:28:08 | 000,000,000 | ---D | C] -- C:\Users\omar\Desktop\Aether
[2011.07.23 21:05:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devolver Digital
[2011.07.23 18:02:17 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Serious Sam 2 Patch 2.066.00
[2011.07.23 18:00:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Xfire
[2011.07.23 17:57:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
[2011.07.23 17:57:28 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Xfire
[2011.07.23 17:57:26 | 000,000,000 | --SD | C] -- C:\Program Files\Xfire
[2011.07.23 17:55:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam 2
[2011.07.23 17:55:41 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Serious Sam 2
[2011.07.23 17:51:30 | 000,000,000 | ---D | C] -- C:\Program Files\Serious Sam 2
[2011.07.23 17:21:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SQ-Girls Bildschirmschoner
[2011.07.23 17:21:07 | 000,000,000 | ---D | C] -- C:\Program Files\Lomex
[2011.07.23 13:20:14 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{04014ADC-C12B-4C0E-B845-FC9C8F3BD077}
[2011.07.22 17:38:19 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\.doomseeker
[2011.07.22 17:33:56 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Skulltag
[2011.07.22 17:33:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skulltag
[2011.07.22 17:33:38 | 000,000,000 | ---D | C] -- C:\Program Files\Skulltag
[2011.07.22 10:58:00 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{38C31BF5-7E50-4F31-881A-7B679472206D}
[2011.07.21 14:26:44 | 000,000,000 | ---D | C] -- C:\DUKE
[2011.07.21 13:40:28 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\True Crime - Streets of LA
[2011.07.21 13:40:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\True Crime - Streets of LA
[2011.07.21 11:39:03 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C0424103-C581-4C2E-9B6B-64F9EC75FCF1}
[2011.07.19 13:43:57 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{C134BDD2-7837-4424-BFEC-3A5E5F0413F8}
[2011.07.18 08:38:13 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{93B89304-5AEF-4C73-BE58-0F5DCBCB6BE4}
[2011.07.17 13:38:18 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Local\{87D0196C-FBDA-483A-A8DF-630D85CA4CAF}
[2011.07.16 19:22:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forgotten Hope 2
[2011.07.16 19:22:13 | 000,000,000 | ---D | C] -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Forgotten Hope 2
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011.08.15 18:12:35 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011.08.15 18:12:35 | 000,017,168 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011.08.15 17:58:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011.08.15 17:58:30 | 1407,787,008 | -HS- | M] () -- C:\hiberfil.sys
[2011.08.15 17:56:08 | 000,001,116 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-752189712-4168365328-2364872346-1000UA.job
[2011.08.14 17:44:33 | 000,000,000 | -H-- | M] () -- C:\Windows\System32\drivers\Msft_Kernel_GenericMount_01009.Wdf
[2011.08.14 16:56:04 | 000,001,064 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-752189712-4168365328-2364872346-1000Core.job
[2011.08.14 16:44:26 | 000,138,160 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.08.14 16:44:18 | 000,271,200 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011.08.14 16:38:26 | 000,103,736 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011.08.13 19:43:00 | 000,002,012 | ---- | M] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011.08.11 13:43:18 | 000,001,753 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.08.11 13:18:20 | 000,023,978 | ---- | M] () -- C:\Users\omar\AppData\Roaming\Notepad2.ini
[2011.08.10 13:19:47 | 000,001,960 | ---- | M] () -- C:\Users\Public\Desktop\E.Y.E Divine Cybermancy.lnk
[2011.08.09 23:47:30 | 000,000,289 | ---- | M] () -- C:\Windows\System32\settings.xml
[2011.08.09 19:06:40 | 000,004,570 | ---- | M] () -- C:\Users\omar\.recently-used.xbel
[2011.08.09 18:51:56 | 000,001,720 | ---- | M] () -- C:\Users\omar\Desktop\Skeleton in Suit_272232.png
[2011.08.07 18:41:52 | 000,270,142 | ---- | M] () -- C:\Users\omar\Desktop\Minecraft.exe
[2011.08.06 22:04:58 | 000,001,043 | ---- | M] () -- C:\Users\omar\Desktop\Jodix Free WMA to MP3 Converter.lnk
[2011.08.03 14:15:26 | 000,000,143 | ---- | M] () -- C:\Users\Public\Desktop\Play Ace of Spades.url
[2011.08.02 13:15:39 | 000,000,986 | ---- | M] () -- C:\Users\Public\Desktop\Condemned - Criminal Origins.lnk
[2011.08.02 11:22:16 | 000,000,794 | ---- | M] () -- C:\Users\omar\Desktop\Half Life Source.lnk
[2011.07.30 14:52:45 | 000,706,838 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2011.07.30 14:52:45 | 000,660,416 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011.07.30 14:52:45 | 000,152,398 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2011.07.30 14:52:45 | 000,124,606 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011.07.28 21:28:26 | 000,000,279 | ---- | M] () -- C:\Users\omar\Desktop\char.png
[2011.07.26 16:24:42 | 000,031,415 | ---- | M] () -- C:\Users\omar\Desktop\U MAD.jpg
[2011.07.26 12:34:46 | 000,032,063 | ---- | M] () -- C:\Users\omar\Desktop\PWND.jpg
[2011.07.23 17:57:31 | 000,000,957 | ---- | M] () -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2011.07.23 17:57:31 | 000,000,921 | ---- | M] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011.07.21 13:40:27 | 000,000,284 | ---- | M] () -- C:\Windows\Tcsofla.INI
[2011.07.21 12:11:12 | 000,138,192 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avipbb.sys
[2011.07.21 12:11:11 | 000,066,616 | ---- | M] (Avira GmbH) -- C:\Windows\System32\drivers\avgntflt.sys
[2011.07.17 14:23:52 | 000,020,009 | ---- | M] () -- C:\Users\omar\Desktop\super_mario_troll.jpg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011.08.14 17:44:33 | 000,000,000 | -H-- | C] () -- C:\Windows\System32\drivers\Msft_Kernel_GenericMount_01009.Wdf
[2011.08.13 19:43:00 | 000,002,012 | ---- | C] () -- C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2011.08.11 13:43:18 | 000,001,753 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011.08.10 13:19:47 | 000,001,960 | ---- | C] () -- C:\Users\Public\Desktop\E.Y.E Divine Cybermancy.lnk
[2011.08.09 23:47:30 | 000,000,289 | ---- | C] () -- C:\Windows\System32\settings.xml
[2011.08.09 19:06:40 | 000,004,570 | ---- | C] () -- C:\Users\omar\.recently-used.xbel
[2011.08.09 18:51:54 | 000,001,720 | ---- | C] () -- C:\Users\omar\Desktop\Skeleton in Suit_272232.png
[2011.08.08 16:51:03 | 000,001,116 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-752189712-4168365328-2364872346-1000UA.job
[2011.08.08 16:51:00 | 000,001,064 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-752189712-4168365328-2364872346-1000Core.job
[2011.08.07 18:41:50 | 000,270,142 | ---- | C] () -- C:\Users\omar\Desktop\Minecraft.exe
[2011.08.06 22:04:58 | 000,001,043 | ---- | C] () -- C:\Users\omar\Desktop\Jodix Free WMA to MP3 Converter.lnk
[2011.08.03 14:15:26 | 000,000,143 | ---- | C] () -- C:\Users\Public\Desktop\Play Ace of Spades.url
[2011.08.03 09:38:19 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011.08.02 13:15:39 | 000,000,986 | ---- | C] () -- C:\Users\Public\Desktop\Condemned - Criminal Origins.lnk
[2011.08.02 11:22:16 | 000,000,794 | ---- | C] () -- C:\Users\omar\Desktop\Half Life Source.lnk
[2011.07.28 21:28:25 | 000,000,279 | ---- | C] () -- C:\Users\omar\Desktop\char.png
[2011.07.26 16:24:42 | 000,031,415 | ---- | C] () -- C:\Users\omar\Desktop\U MAD.jpg
[2011.07.26 12:32:18 | 000,032,063 | ---- | C] () -- C:\Users\omar\Desktop\PWND.jpg
[2011.07.23 17:57:31 | 000,000,957 | ---- | C] () -- C:\Users\omar\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Xfire.lnk
[2011.07.23 17:57:31 | 000,000,921 | ---- | C] () -- C:\Users\Public\Desktop\Xfire.lnk
[2011.07.21 13:08:38 | 000,000,284 | ---- | C] () -- C:\Windows\Tcsofla.INI
[2011.07.17 14:17:02 | 000,020,009 | ---- | C] () -- C:\Users\omar\Desktop\super_mario_troll.jpg
[2011.07.03 22:06:21 | 000,023,978 | ---- | C] () -- C:\Users\omar\AppData\Roaming\Notepad2.ini
[2011.06.26 13:53:03 | 000,029,008 | ---- | C] () -- C:\Windows\System32\SmartDefragBootTime.exe
[2011.06.26 13:53:03 | 000,016,184 | ---- | C] () -- C:\Windows\System32\drivers\SmartDefragDriver.sys
[2011.06.17 19:07:00 | 000,010,240 | ---- | C] () -- C:\Windows\System32\vidx16.dll
[2011.06.17 13:17:06 | 000,000,007 | ---- | C] () -- C:\Windows\treeskp.sys
[2011.06.17 13:17:06 | 000,000,007 | ---- | C] () -- C:\Windows\sbacknt.bin
[2011.06.15 21:50:20 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011.06.14 16:19:52 | 000,941,784 | ---- | C] () -- C:\Windows\System32\drivers\CAMTHWDM.sys
[2011.06.13 00:12:45 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2011.06.07 16:04:20 | 000,162,432 | ---- | C] () -- C:\Windows\System32\drivers\ithsgt.sys
[2011.06.07 16:04:14 | 000,012,032 | ---- | C] () -- C:\Windows\System32\drivers\lilsgt.sys
[2011.06.06 21:13:04 | 000,138,160 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011.05.24 23:44:26 | 000,059,904 | ---- | C] () -- C:\Windows\System32\OVDecode.dll
[2011.04.28 20:11:31 | 000,000,031 | ---- | C] () -- C:\Windows\CAD3D.INI
[2011.04.28 20:11:25 | 000,059,392 | ---- | C] () -- C:\Windows\System32\Gksui16.exe
[2011.04.26 10:43:39 | 000,000,000 | ---- | C] () -- C:\Windows\System32\Access.dat
[2011.04.22 15:15:43 | 000,000,551 | ---- | C] () -- C:\Windows\eReg.dat
[2011.04.17 19:56:16 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011.04.16 18:51:16 | 000,041,872 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2011.04.11 23:47:05 | 000,007,605 | ---- | C] () -- C:\Users\omar\AppData\Local\Resmon.ResmonCfg
[2011.03.27 00:22:58 | 000,000,287 | ---- | C] () -- C:\Windows\game.ini
[2011.03.23 21:49:38 | 000,000,092 | ---- | C] () -- C:\Users\omar\AppData\Local\fusioncache.dat
[2011.03.22 20:29:12 | 000,033,792 | ---- | C] () -- C:\Windows\System32\drivers\libusb0.sys
[2011.01.29 22:18:44 | 000,138,056 | ---- | C] () -- C:\Users\omar\AppData\Roaming\PnkBstrK.sys
[2011.01.29 22:17:57 | 000,271,200 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2011.01.29 22:17:56 | 000,837,192 | ---- | C] () -- C:\Windows\System32\Pbsvc.exe
[2011.01.29 22:17:56 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2011.01.23 23:08:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009.07.14 10:47:43 | 000,706,838 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009.07.14 10:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009.07.14 10:47:43 | 000,152,398 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009.07.14 10:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009.07.14 06:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009.07.14 06:33:53 | 000,294,912 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009.07.14 04:05:48 | 000,660,416 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009.07.14 04:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009.07.14 04:05:48 | 000,124,606 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009.07.14 04:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009.07.14 04:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009.07.14 04:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009.07.14 02:19:49 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009.07.14 01:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009.07.14 01:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009.07.14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009.06.10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008.12.01 21:46:12 | 000,159,744 | ---- | C] () -- C:\Windows\System32\atitmmxx.dll
[2008.12.01 21:08:40 | 003,107,788 | ---- | C] () -- C:\Windows\System32\atiumdva.dat
[2008.10.30 15:45:42 | 000,180,720 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2008.10.22 05:29:06 | 000,173,550 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2008.10.07 09:13:30 | 000,197,912 | ---- | C] () -- C:\Windows\System32\physxcudart_20.dll
[2008.10.07 09:13:22 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelTraditionalChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSwedish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSpanish.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelSimplifiedChinese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelPortugese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelKorean.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelJapanese.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelGerman.dll
[2008.10.07 09:13:20 | 000,058,648 | ---- | C] () -- C:\Windows\System32\AgCPanelFrench.dll
[2005.10.21 00:58:52 | 000,090,112 | ---- | C] () -- C:\Windows\System32\vspxvfw.dll
[2005.09.01 16:20:46 | 000,524,288 | ---- | C] () -- C:\Windows\System32\vspxcore.dll
[1999.01.22 00:40:22 | 000,180,224 | ---- | C] () -- C:\Windows\Res2_uninst.exe
========== LOP Check ==========
[2011.07.22 17:53:05 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\.doomseeker
[2011.08.14 15:15:28 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\.minecraft
[2011.05.27 17:10:26 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\111 Pix Ltd
[2011.06.19 20:33:45 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Audacity
[2011.05.22 18:30:01 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\DAEMON Tools Lite
[2011.01.30 01:26:04 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\DAEMON Tools Pro
[2011.08.15 17:59:38 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\DNA
[2011.03.30 19:53:48 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Downloaded Installations
[2011.08.04 16:44:27 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\GetRightToGo
[2011.08.11 13:06:47 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\go
[2011.07.26 16:24:42 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\gtk-2.0
[2011.06.26 13:53:03 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\IObit
[2011.06.03 20:26:06 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\MAXON
[2011.03.25 22:46:23 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\MotioninJoy
[2011.05.22 16:27:10 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Mount&Blade
[2011.06.21 18:27:47 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\OpenOffice.org
[2011.08.12 16:54:36 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Opera
[2011.07.15 13:57:23 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\PFStaticIP
[2011.06.03 10:31:04 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Sony
[2011.02.03 23:10:13 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Subversion
[2011.01.31 13:21:30 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Synaptics
[2011.03.21 21:22:42 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\TeamViewer
[2011.06.06 21:44:31 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\TerrariaWorldViewer
[2011.04.26 10:42:02 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Tunngle
[2011.05.24 20:01:27 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Unity
[2011.08.15 17:59:59 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\uTorrent
[2011.06.11 19:19:46 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\wargaming.net
[2011.06.14 16:22:38 | 000,000,000 | ---D | M] -- C:\Users\omar\AppData\Roaming\Webcammax
[2011.07.31 11:34:44 | 000,032,632 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.04.17 19:54:45 | 000,000,204 | ---- | M] () -- C:\Windows\Tasks\{4BE033AE-43F4-4B0E-9E6A-8CD91F764958}.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:364682BC
< End of report >