Jump to content

Welcome Guest to Geeks to Go - Register now for FREE
Geeks To Go is a helpful hub, where thousands of friendly volunteers serve up answers and support. Get free advice from the experts. Feel free to browse the site as a guest. However, you must log in to reply to existing topics or start a new topic of your own, and enjoy all this forum has to offer. Additionally, if you can assist another member by sharing your knowledge, please post a reply! Best of all - Registration and all assistance, is FREE! Learn more about How it Works. Infected? Malware Cleaning Guide. What are you waiting for?
Create an Account Login to Account

Hitman Pro 3.5 - can't remove


  • Please log in to reply

#1
ongre

ongre

    Member

  • Member
  • PipPip
  • 12 posts
Hello everyone, I've got a problem.

I downloaded Hitman Pro to run a system scan yesterday, detected some "suspicous" files and deleted it. All good. Now everytime I boot my computer a message saying " Hitman Pro 3.5 Surf .. " ( black background, white font) appears during 2 seconds. I didn't even install the program. I searched over the internet withouth succes. Nobody has complained ever about this little message during boot.
Following some instructions how to remove Hitman Pro I found on internet : I re-executed my Hitman Pro installer, chose to install the program in my computer ( before it wasn't even in the add/remove panel), installed right. Then I rebooted in safe-mode, removed hitman , run a search in my registry with the words "hitman" deleted everything and also run a search on my hdd with the word "hitman" and deleted everything. I reboot and the message keeps appearing. I don't get any register keys nor files with the word "hitman". I think it's some sort of fast scan that runs everytime I boot, I checked my task scheduler but I don't know what to look for.

This is driving me crazy I never installed this program and it is acting like a virus : can't get rid of IT !
Precision : the message appears after the logo of Windows 7 loading is shown, and before the "Welcome" message of windows with the mouse playing the loading animation.
Help me please or I think I'll have to reinstall Windows ...

( And sorry I didn't know where to post this since I didn't find a section about uninstalling "crap" anti-malware software )

OTL logfile created on: 29/08/2011 10:04:56 - Run 1
OTL by OldTimer - Version 3.2.26.6 Folder = C:\Users\Ezequiel\Downloads
64bit- Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 0000080c | Country: Belgique | Language: FRB | Date Format: d/MM/yyyy

4,00 Gb Total Physical Memory | 2,25 Gb Available Physical Memory | 56,35% Memory free
7,99 Gb Paging File | 6,18 Gb Available in Paging File | 77,29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 244,04 Gb Total Space | 75,45 Gb Free Space | 30,92% Space Free | Partition Type: NTFS
Drive D: | 221,62 Gb Total Space | 154,35 Gb Free Space | 69,65% Space Free | Partition Type: NTFS

Computer Name: EZEQUIEL-PC | User Name: Ezequiel | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/08/29 10:04:39 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Users\Ezequiel\Downloads\OTL.exe
PRC - [2011/05/25 09:25:28 | 002,214,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/04/14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
PRC - [2011/03/21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
PRC - [2010/09/01 06:26:04 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe
PRC - [2010/04/27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe
PRC - [2009/10/07 01:47:22 | 000,125,464 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\LVPrS64H.exe
PRC - [2009/09/29 14:03:46 | 000,735,960 | ---- | M] (ESET) -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe
PRC - [2009/03/05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/12/19 11:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- C:\Program Files (x86)\Razer\DeathAdder\razerofa.exe


========== Modules (No Company Name) ==========

MOD - [2011/08/17 11:49:17 | 000,400,440 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\ppGoogleNaClPluginChrome.dll
MOD - [2011/08/17 11:49:15 | 004,118,072 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\pdf.dll
MOD - [2011/08/17 11:47:49 | 000,104,520 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\avutil-50.dll
MOD - [2011/08/17 11:47:48 | 000,203,848 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\avformat-52.dll
MOD - [2011/08/17 11:47:47 | 001,846,344 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\avcodec-52.dll
MOD - [2011/08/17 09:49:17 | 006,338,720 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\Application\13.0.782.215\gcswf32.dll
MOD - [2011/08/17 09:49:17 | 006,338,720 | ---- | M] () -- C:\Users\Ezequiel\AppData\Local\Google\Chrome\APPLIC~1\130782~1.215\gcswf32.dll
MOD - [2011/07/14 18:01:59 | 000,958,976 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avformat-53.dll
MOD - [2011/07/14 18:01:59 | 000,132,096 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avutil-51.dll
MOD - [2011/07/14 18:01:58 | 007,006,208 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\avcodec-53.dll
MOD - [2011/07/14 18:01:58 | 000,239,616 | ---- | M] () -- C:\Program Files (x86)\SplitMediaLabs\XSplit\swscale-0.dll
MOD - [2011/04/14 11:48:32 | 001,758,208 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\vdDaemon.exe
MOD - [2011/03/21 11:06:08 | 000,248,320 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe
MOD - [2010/04/27 14:41:26 | 000,218,112 | ---- | M] () -- C:\Program Files (x86)\Razer\DeathAdder\razertra.exe


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2009/10/07 01:47:10 | 000,191,000 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcS64)
SRV:64bit: - [2009/09/29 14:11:14 | 000,023,296 | ---- | M] (ESET) [On_Demand | Stopped] -- C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe -- (EhttpSrv)
SRV:64bit: - [2009/09/29 14:03:46 | 000,735,960 | ---- | M] (ESET) [Auto | Running] -- C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe -- (ekrn)
SRV:64bit: - [2009/07/14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/08/02 15:58:00 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/05/25 09:25:28 | 002,214,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/05/20 22:35:16 | 000,378,472 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 15:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/08/16 20:38:07 | 000,314,016 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\atksgt.sys -- (atksgt)
DRV:64bit: - [2011/08/16 20:38:07 | 000,043,680 | ---- | M] () [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\lirsgt.sys -- (lirsgt)
DRV:64bit: - [2011/07/16 23:28:41 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV:64bit: - [2011/07/16 23:28:41 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)
DRV:64bit: - [2011/05/25 09:25:48 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/04/13 15:04:38 | 000,045,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:64bit: - [2011/03/11 08:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 08:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/10/10 22:17:58 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010/10/01 00:16:34 | 000,013,312 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VKbms.sys -- (VKbms)
DRV:64bit: - [2010/03/23 16:37:34 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\danew.sys -- (danewFltr)
DRV:64bit: - [2010/02/03 16:56:56 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2010/01/11 18:05:20 | 001,290,752 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV:64bit: - [2009/10/07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2009/10/07 01:45:50 | 000,030,232 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009/09/29 14:06:16 | 000,123,200 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2009/09/29 14:03:00 | 000,136,584 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2009/09/29 13:56:36 | 000,144,824 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamon.sys -- (eamon)
DRV:64bit: - [2009/08/19 09:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 03:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/14 03:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\svchost.exe -- (1394hub)
DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/01 01:01:34 | 000,327,576 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2009/05/01 00:55:56 | 002,755,096 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV:64bit: - [2009/05/01 00:55:46 | 000,015,896 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lv302a64.sys -- (lvpepf64)
DRV:64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:64bit: - [2005/03/29 01:30:38 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)
DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files (x86)\uTorrentBar_FR\tbuTo1.dll (Conduit Ltd.)

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://be.msn.com/de...fr-be&ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr-be
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1F BD BC ED 49 66 CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files (x86)\uTorrentBar_FR\tbuTo1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60310.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@viewpoint.com/VMP: C:\Program Files (x86)\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Ezequiel\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Ezequiel\AppData\Local\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2011/02/18 18:09:26 | 000,000,000 | ---D | M]

[2010/10/14 16:36:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ezequiel\AppData\Roaming\mozilla\Extensions
[2010/10/14 16:36:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Ezequiel\AppData\Roaming\mozilla\Extensions\mozswing@mozswing.org

O1 HOSTS File: ([2011/08/18 00:21:07 | 000,437,464 | R--- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 15044 more lines...
O2 - BHO: (uTorrentBar_FR Toolbar) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files (x86)\uTorrentBar_FR\tbuTo1.dll (Conduit Ltd.)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngin1.dll (Conduit Ltd.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (uTorrentBar_FR Toolbar) - {05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - C:\Program Files (x86)\uTorrentBar_FR\tbuTo1.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEngin1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (uTorrentBar_FR Toolbar) - {05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - C:\Program Files (x86)\uTorrentBar_FR\tbuTo1.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [DeathAdder] C:\Program Files (x86)\Razer\DeathAdder\razerhid.exe ()
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Enregistrement du produit.lnk = C:\Program Files\Logitech\Logitech WebCam Software\eReg.exe (Leader Technologies/Logitech)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ent/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 195.130.131.129 195.130.130.1
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18:64bit: - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (bootdelete) - File not found
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/08/29 08:31:04 | 000,032,824 | ---- | C] (Resplendence Software Projects Sp) -- C:\Windows\SysWow64\rrMon.sys
[2011/08/29 08:31:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registrar Registry Manager
[2011/08/29 08:31:01 | 000,000,000 | ---D | C] -- C:\Program Files\Registrar Registry Manager
[2011/08/29 08:22:50 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{D6A346CE-5E76-467E-9370-73B86F575F09}
[2011/08/29 08:22:31 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{2D3E5692-4078-4926-AB21-E172501D5CF7}
[2011/08/28 23:16:01 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MCEdit-64bit
[2011/08/28 23:16:00 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\MCEdit-64bit
[2011/08/28 16:46:39 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2011/08/28 12:22:14 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{CE841A24-ADF2-429B-9D92-1BF8ECB9EABC}
[2011/08/28 12:22:03 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{577D3ADC-B66E-4247-9B1B-ED0AA118EC26}
[2011/08/27 22:27:15 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{E2ABBA09-BCE4-4032-900C-5AE15B915D6C}
[2011/08/27 10:26:46 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{BE42C772-75DD-4F0F-9E4F-B8358E439391}
[2011/08/27 10:26:30 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{F7B003F8-2B2D-4A00-932B-58577E36D0E7}
[2011/08/26 17:07:07 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\Documents\DragonNest
[2011/08/26 17:05:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cherry De Games
[2011/08/26 17:02:44 | 000,000,000 | ---D | C] -- C:\CherryDeGames
[2011/08/26 13:31:25 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{3F5E6E19-DA9A-4349-9051-A461DBFCAB1E}
[2011/08/26 13:31:12 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{9BD0BCDC-EA1C-4F28-86A9-6EE18221BDD0}
[2011/08/25 18:58:55 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{D58BC710-4E25-4206-AE3D-3744440111C8}
[2011/08/25 18:58:43 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{FBA876E8-6192-47F4-93FB-C183F02473FB}
[2011/08/24 17:30:30 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{BA9B5B5B-E279-42FE-8F1F-4F59B6F91E3B}
[2011/08/24 17:30:14 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{A691B2D2-DDE9-4CA4-9D66-D85705BEAAAB}
[2011/08/23 22:05:23 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{B7B69FDA-54D6-4F78-A951-C65C45B08F6E}
[2011/08/23 22:05:12 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{4ED29648-B213-49FB-B0DB-A67B8576E566}
[2011/08/23 10:04:47 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{96986944-9664-482D-BD5D-9EAF14A904A9}
[2011/08/23 10:04:34 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{9165E183-5212-44E3-B3BB-A99023029A83}
[2011/08/22 16:34:08 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{39C1BEA4-809C-4C30-BBE3-76F29680A5CE}
[2011/08/22 16:33:57 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{10F82E68-1146-4428-9EA1-0DCE804D3387}
[2011/08/22 00:24:08 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{A86EA1F0-8440-4CBD-9264-F1D19BAF4A2A}
[2011/08/22 00:23:57 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{1532D84B-1CF1-4A85-A599-EC13FF6F06C9}
[2011/08/21 13:36:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
[2011/08/21 12:23:31 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{6C65661E-7DDA-41C2-A811-9BBCFFD85653}
[2011/08/21 12:23:20 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{A53E9442-084E-4D62-8501-691699F8ACBD}
[2011/08/21 00:22:55 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{75371CEA-7621-479F-AE24-1CBA8951E3B8}
[2011/08/21 00:22:43 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{874F42FD-A191-4C1C-B429-C5BE345F9A3A}
[2011/08/20 12:22:29 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{976D6DFA-90CD-4EF6-877B-E8590BC3E000}
[2011/08/20 12:22:14 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{C81CC166-F12B-416E-B47B-87B9EE24072E}
[2011/08/19 22:36:07 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{DB6C3D8B-4825-40EB-BCAE-DC0EC9DA5D7C}
[2011/08/19 22:35:53 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{87B0C472-A682-4A98-9ED7-8A5CDF42DC9A}
[2011/08/19 16:53:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2011/08/19 10:35:26 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{D1089EC6-1802-440B-AA39-7CE7CA77E404}
[2011/08/19 10:35:14 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{C0DACF81-7ED9-4480-AC0B-75A94C394AEB}
[2011/08/18 13:28:30 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{32D8804F-FFFF-48A2-AE99-D640330D0A99}
[2011/08/18 13:28:18 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{33B29A38-EFDD-4CD3-A550-A18BD0AD482C}
[2011/08/18 01:27:53 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{002D0EA2-E68D-4F29-8ADB-7F40EC69286F}
[2011/08/18 01:27:41 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{3DE9DBE3-7876-4205-BF03-565FCA21B02E}
[2011/08/18 00:03:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy
[2011/08/18 00:03:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Spybot - Search & Destroy
[2011/08/18 00:03:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Spybot - Search & Destroy
[2011/08/17 17:59:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/08/17 17:59:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/08/17 17:59:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/08/17 17:59:04 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011/08/17 17:58:59 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\Apple
[2011/08/17 17:58:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/08/17 17:58:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/08/17 13:27:16 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{EEC7B7D5-378E-41CE-A296-01C8F64A8D39}
[2011/08/17 13:27:04 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{44EBA9E1-0706-4769-AE73-DC6FB5B68588}
[2011/08/17 01:26:38 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{2F04BC84-7E7C-44F3-A773-4FC1D2677279}
[2011/08/17 01:26:27 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{66100CF2-C6E6-4D34-8C0A-D97FC3757918}
[2011/08/16 22:32:58 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\Documents\My Downloads
[2011/08/16 20:37:23 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\.spoutcraft
[2011/08/16 13:25:54 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{11E39A76-E1CD-4ACB-9EBE-882487972B3A}
[2011/08/16 13:25:43 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{CA18A6AF-4659-4F74-8DCB-C4DF74B3D609}
[2011/08/16 00:35:18 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{CB177077-044B-4B1B-81A7-93765A64A932}
[2011/08/16 00:35:07 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{B754F692-FBE9-45D1-99D6-5BCB94D2BDA4}
[2011/08/15 12:34:40 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{A266C61A-AF6C-48DE-B368-7A603A561EC3}
[2011/08/15 12:34:27 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{828A8B46-7D3D-4B05-B3EB-7F60367F4A7B}
[2011/08/15 00:00:28 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{28D98AB7-4452-4B2B-9758-0C4CDB0ABF42}
[2011/08/15 00:00:16 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{F9A74C7A-3AAB-43B5-9003-2C4FCC372B55}
[2011/08/14 11:59:50 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{3F271D9F-A63B-4348-B90F-565AD413D61F}
[2011/08/14 11:59:38 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{C922CA7E-3F5C-4FFB-987D-B9931DC59D74}
[2011/08/13 12:57:01 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{336087CF-0343-4199-8745-F76ED2685A13}
[2011/08/13 12:56:50 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{52BD6F97-C375-4A75-A5A6-5E363B132575}
[2011/08/13 00:11:22 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{AD7F8F08-1891-47F0-B8BD-CF85174D1E53}
[2011/08/13 00:11:11 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{37DA93A4-5854-41AD-B70F-3A374035F494}
[2011/08/12 13:15:41 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\DoFUpdater
[2011/08/12 13:15:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dawn of Fantasy
[2011/08/12 13:15:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reverie World Studios
[2011/08/12 12:10:44 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{43BAC724-8B21-4B59-B6CF-0EA111C6236C}
[2011/08/12 12:10:32 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{5A9DC497-479D-4681-AC80-F37C079B21E6}
[2011/08/11 15:40:59 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\LogiShrd
[2011/08/11 15:40:50 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Leadertech
[2011/08/11 15:39:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\LogiShrd
[2011/08/11 15:39:16 | 000,000,000 | ---D | C] -- C:\Program Files\Logitech
[2011/08/11 15:39:16 | 000,000,000 | ---D | C] -- C:\ProgramData\LogiShrd
[2011/08/11 15:26:35 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\logishrd
[2011/08/11 12:44:48 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{F0A29FBD-87F5-4967-86DB-D3FB3F09D15D}
[2011/08/11 12:44:36 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{6B2D4CE2-5B1C-4078-A463-3DF32D1224B1}
[2011/08/11 00:14:31 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{62EACD79-7382-48E8-9F15-AC5349863C99}
[2011/08/11 00:14:19 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{4C3AF74E-497C-4CF4-8527-82DEE752DD7D}
[2011/08/10 22:31:52 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\AOL
[2011/08/10 22:31:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Viewpoint
[2011/08/10 22:31:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Viewpoint
[2011/08/10 21:55:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Nexon
[2011/08/10 21:53:59 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\Documents\Vindictus
[2011/08/10 21:34:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexon
[2011/08/10 21:34:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\BandiMPEG1
[2011/08/10 21:27:34 | 000,000,000 | ---D | C] -- C:\Nexon
[2011/08/10 12:13:53 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{2F04ADDC-5056-45C8-9949-BF2AEBC718E7}
[2011/08/10 12:13:42 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{C1CC1490-75C4-494E-AB6A-D1CCA44FAD17}
[2011/08/10 00:13:16 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{14B79908-DFEA-4104-9B1F-7E021EACBBBC}
[2011/08/10 00:13:05 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{A85B2E88-332D-4ABC-BEE8-D5FAF6F64F3C}
[2011/08/09 13:27:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011/08/09 12:12:38 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{621339E5-77F1-47EB-A975-FC90B87AEBE1}
[2011/08/09 12:12:26 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{C90FC45B-8130-402F-91CD-1A199BD08E1F}
[2011/08/08 13:52:09 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{BDB1DF5A-F624-4227-94A1-46CE1A232918}
[2011/08/08 13:51:58 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{619FB5BF-EB8E-4909-A341-81AF566A8127}
[2011/08/08 01:51:32 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{E0E36895-E8D1-4AA5-A887-DE289AA6FD79}
[2011/08/08 01:51:21 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{3964D25F-CB70-4D19-9093-C470C979D97F}
[2011/08/07 21:29:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\directx
[2011/08/07 21:28:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
[2011/08/07 21:28:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Logitech
[2011/08/07 13:50:56 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{D3DBCED5-5201-40D8-AC2D-4826CA00BD8A}
[2011/08/07 13:50:43 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{D9B04622-C442-488D-AD9B-F27E48D315C4}
[2011/08/07 01:40:45 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{97FC319A-E6D2-4985-9A02-DE6F02E923DF}
[2011/08/06 13:40:20 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{3792A685-33BC-4CBE-A71C-6EDB48FCE17A}
[2011/08/06 13:40:09 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{8F8AF11E-C0CA-4D5B-8356-D4A5F284C304}
[2011/08/05 15:02:58 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{327A6575-924C-4ECB-9098-05F2E5EC3986}
[2011/08/05 15:02:46 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Local\{39F9BEC2-A302-4A0C-AB53-704EC1122476}
[2011/08/05 14:13:06 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\Documents\Nitro Games
[2011/08/05 11:37:33 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2011/08/04 13:41:27 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVEMon
[2011/08/02 17:55:07 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Razer
[2011/08/02 17:53:03 | 000,085,504 | ---- | C] (Razer USA Ltd.) -- C:\Windows\SysWow64\DeathAdder64.cpl
[2011/08/02 17:53:01 | 000,013,312 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\Windows\SysNative\drivers\VKbms.sys
[2011/08/02 17:53:01 | 000,006,656 | ---- | C] (Windows ® Win 7 DDK provider) -- C:\Windows\SysNative\drivers\hidkmdf.sys
[2011/08/02 17:52:59 | 000,012,032 | ---- | C] (Razer (Asia-Pacific) Pte Ltd) -- C:\Windows\SysNative\drivers\danew.sys
[2011/08/02 17:52:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
[2011/08/02 17:52:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Razer
[2011/08/02 17:52:24 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\InstallShield
[2011/07/31 10:33:48 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/30 21:06:58 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/30 21:06:58 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\app
[2011/07/30 19:03:13 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/30 18:34:57 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/30 18:34:57 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\dofus 2
[2011/07/30 18:01:56 | 000,000,000 | ---D | C] -- C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dofus 2
[2011/07/30 18:01:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dofus 2
[2011/07/30 18:01:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dofus 2
[2011/01/26 19:26:33 | 006,637,056 | ---- | C] ( Taleworlds Entertainment) -- C:\Program Files (x86)\mb_warband.exe
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Ezequiel\Documents\*.tmp files -> C:\Users\Ezequiel\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/08/29 09:52:02 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/08/29 09:52:02 | 000,014,224 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/08/29 09:43:36 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/08/29 09:43:32 | 3219,693,568 | -HS- | M] () -- C:\hiberfil.sys
[2011/08/29 09:27:35 | 000,001,972 | ---- | M] () -- C:\Users\Ezequiel\Documents\cc_20110829_092734.reg
[2011/08/29 09:27:16 | 000,008,826 | ---- | M] () -- C:\Users\Ezequiel\Documents\cc_20110829_092714.reg
[2011/08/29 09:19:01 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-697454127-3317646506-589619845-1001UA.job
[2011/08/28 21:19:23 | 001,309,239 | ---- | M] () -- C:\Users\Ezequiel\Documents\IMG_0099.JPG
[2011/08/28 19:23:33 | 000,001,038 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-697454127-3317646506-589619845-1001Core.job
[2011/08/28 16:46:39 | 000,012,872 | ---- | M] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2011/08/28 16:46:39 | 000,002,090 | ---- | M] () -- C:\Windows\SysNative\bootdelete.lst
[2011/08/28 13:58:15 | 000,007,218 | ---- | M] () -- C:\Users\Ezequiel\Documents\cc_20110828_135813.reg
[2011/08/28 12:22:30 | 000,001,029 | ---- | M] () -- C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Enregistrement du produit.lnk
[2011/08/27 11:51:06 | 000,000,008 | ---- | M] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_1
[2011/08/27 11:22:05 | 000,000,173 | ---- | M] () -- C:\Users\Ezequiel\AppData\Roaming\D2Info0
[2011/08/26 17:05:38 | 000,001,679 | ---- | M] () -- C:\Users\Public\Desktop\Dragon Nest.lnk
[2011/08/25 19:19:32 | 000,002,415 | ---- | M] () -- C:\Users\Ezequiel\Desktop\Google Chrome.lnk
[2011/08/22 17:39:33 | 001,039,571 | ---- | M] () -- C:\Users\Ezequiel\Documents\IMG_0087.JPG
[2011/08/18 00:21:07 | 000,437,464 | R--- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/08/18 00:03:23 | 000,001,258 | ---- | M] () -- C:\Users\Ezequiel\Desktop\Spybot - Search & Destroy.lnk
[2011/08/18 00:00:49 | 000,015,924 | ---- | M] () -- C:\Users\Ezequiel\Documents\cc_20110818_000046.reg
[2011/08/17 23:58:26 | 000,253,015 | ---- | M] () -- C:\Users\Ezequiel\Documents\IMG_17082011_235752.png
[2011/08/17 22:44:48 | 000,000,697 | ---- | M] () -- C:\Users\Ezequiel\Ezequiel - Raccourci.lnk
[2011/08/17 20:28:58 | 000,587,022 | ---- | M] () -- C:\Users\Ezequiel\Documents\Full zizi.jpg
[2011/08/16 22:52:24 | 000,001,158 | ---- | M] () -- C:\Users\Ezequiel\Desktop\Spoutcraft.jar - Raccourci.lnk
[2011/08/16 20:38:07 | 000,314,016 | ---- | M] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2011/08/16 20:38:07 | 000,043,680 | ---- | M] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2011/08/16 13:28:03 | 001,662,566 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/08/16 13:28:03 | 000,745,268 | ---- | M] () -- C:\Windows\SysNative\perfh00C.dat
[2011/08/16 13:28:03 | 000,652,150 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/08/16 13:28:03 | 000,148,786 | ---- | M] () -- C:\Windows\SysNative\perfc00C.dat
[2011/08/16 13:28:03 | 000,121,082 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/08/13 15:49:08 | 000,000,008 | ---- | M] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_3
[2011/08/13 01:14:45 | 000,000,008 | ---- | M] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_2
[2011/08/12 13:15:32 | 000,002,637 | ---- | M] () -- C:\Users\Public\Desktop\Dawn of Fantasy.lnk
[2011/08/11 22:26:58 | 000,082,665 | ---- | M] () -- C:\Users\Ezequiel\Documents\IMG_11082011_222633.png
[2011/08/11 19:48:56 | 001,640,176 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/08/11 15:39:17 | 000,002,107 | ---- | M] () -- C:\Users\Public\Desktop\Logiciel de caméra Web Logitech.lnk
[2011/08/11 15:36:20 | 000,000,039 | ---- | M] () -- C:\Windows\WININIT.INI
[2011/08/10 22:26:07 | 000,000,335 | ---- | M] () -- C:\Windows\nsreg.dat
[2011/08/07 21:28:57 | 000,000,280 | ---- | M] () -- C:\Windows\_delis32.ini
[2011/08/07 21:28:27 | 000,081,920 | ---- | M] () -- C:\Windows\bwUnin-6.1.4.36-8876480L.exe
[2011/08/05 14:27:51 | 000,042,554 | ---- | M] () -- C:\Users\Ezequiel\Documents\cc_20110805_142745.reg
[2011/08/04 13:41:21 | 000,040,656 | ---- | M] () -- C:\Users\Ezequiel\Documents\EVEMon_Settings_2798.xml.bak
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
[1 C:\Users\Ezequiel\Documents\*.tmp files -> C:\Users\Ezequiel\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/08/29 09:27:35 | 000,001,972 | ---- | C] () -- C:\Users\Ezequiel\Documents\cc_20110829_092734.reg
[2011/08/29 09:27:15 | 000,008,826 | ---- | C] () -- C:\Users\Ezequiel\Documents\cc_20110829_092714.reg
[2011/08/29 08:31:02 | 000,120,376 | ---- | C] () -- C:\Windows\SysWow64\rrsec.dll
[2011/08/29 08:31:02 | 000,097,888 | ---- | C] () -- C:\Windows\SysWow64\rrsec2k.exe
[2011/08/28 21:17:15 | 001,309,239 | ---- | C] () -- C:\Users\Ezequiel\Documents\IMG_0099.JPG
[2011/08/28 16:46:39 | 000,002,090 | ---- | C] () -- C:\Windows\SysNative\bootdelete.lst
[2011/08/28 13:58:14 | 000,007,218 | ---- | C] () -- C:\Users\Ezequiel\Documents\cc_20110828_135813.reg
[2011/08/28 12:22:30 | 000,001,029 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Enregistrement du produit.lnk
[2011/08/26 17:05:38 | 000,001,679 | ---- | C] () -- C:\Users\Public\Desktop\Dragon Nest.lnk
[2011/08/22 17:37:57 | 001,039,571 | ---- | C] () -- C:\Users\Ezequiel\Documents\IMG_0087.JPG
[2011/08/18 00:03:23 | 000,001,258 | ---- | C] () -- C:\Users\Ezequiel\Desktop\Spybot - Search & Destroy.lnk
[2011/08/18 00:00:47 | 000,015,924 | ---- | C] () -- C:\Users\Ezequiel\Documents\cc_20110818_000046.reg
[2011/08/17 23:58:06 | 000,253,015 | ---- | C] () -- C:\Users\Ezequiel\Documents\IMG_17082011_235752.png
[2011/08/17 22:44:48 | 000,000,697 | ---- | C] () -- C:\Users\Ezequiel\Ezequiel - Raccourci.lnk
[2011/08/17 20:27:19 | 000,587,022 | ---- | C] () -- C:\Users\Ezequiel\Documents\Full zizi.jpg
[2011/08/17 17:58:59 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/08/16 22:52:24 | 000,001,158 | ---- | C] () -- C:\Users\Ezequiel\Desktop\Spoutcraft.jar - Raccourci.lnk
[2011/08/16 20:38:07 | 000,314,016 | ---- | C] () -- C:\Windows\SysNative\drivers\atksgt.sys
[2011/08/16 20:38:07 | 000,043,680 | ---- | C] () -- C:\Windows\SysNative\drivers\lirsgt.sys
[2011/08/12 13:15:32 | 000,002,637 | ---- | C] () -- C:\Users\Public\Desktop\Dawn of Fantasy.lnk
[2011/08/11 22:26:49 | 000,082,665 | ---- | C] () -- C:\Users\Ezequiel\Documents\IMG_11082011_222633.png
[2011/08/11 15:39:43 | 000,082,289 | ---- | C] () -- C:\Windows\SysNative\lvcoin64.ini
[2011/08/11 15:39:43 | 000,034,068 | ---- | C] () -- C:\Windows\SysNative\Repository.reg
[2011/08/11 15:39:17 | 000,002,107 | ---- | C] () -- C:\Users\Public\Desktop\Logiciel de caméra Web Logitech.lnk
[2011/08/11 15:36:20 | 000,000,039 | ---- | C] () -- C:\Windows\WININIT.INI
[2011/08/10 22:26:07 | 000,000,335 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/08/07 21:28:57 | 000,000,280 | ---- | C] () -- C:\Windows\_delis32.ini
[2011/08/07 21:28:27 | 000,081,920 | ---- | C] () -- C:\Windows\bwUnin-6.1.4.36-8876480L.exe
[2011/08/05 14:27:50 | 000,042,554 | ---- | C] () -- C:\Users\Ezequiel\Documents\cc_20110805_142745.reg
[2011/08/04 13:41:57 | 000,040,656 | ---- | C] () -- C:\Users\Ezequiel\Documents\EVEMon_Settings_2798.xml.bak
[2011/07/31 10:33:48 | 000,000,008 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_3
[2011/07/30 19:03:13 | 000,000,008 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_1
[2011/07/30 18:34:57 | 000,000,173 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\D2Info0
[2011/07/30 18:34:57 | 000,000,008 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\DofusAppId0_2
[2011/06/25 23:28:34 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2011/05/20 22:35:28 | 000,304,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/04/10 15:07:15 | 000,142,888 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/02/26 03:19:32 | 000,041,872 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2010/11/17 23:13:47 | 001,640,176 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2010/10/23 16:32:56 | 000,000,132 | ---- | C] () -- C:\Users\Ezequiel\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2010/10/12 16:53:23 | 000,021,840 | ---- | C] () -- C:\Windows\SysWow64\SIntfNT.dll
[2010/10/12 16:53:23 | 000,017,212 | ---- | C] () -- C:\Windows\SysWow64\SIntf32.dll
[2010/10/12 16:53:23 | 000,012,067 | ---- | C] () -- C:\Windows\SysWow64\SIntf16.dll
[2010/10/09 16:32:02 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/10/08 19:02:29 | 000,013,368 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsUpIO.sys
[2010/10/08 19:02:27 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\AsIO.dll
[2010/10/08 19:02:27 | 000,013,440 | ---- | C] () -- C:\Windows\SysWow64\drivers\AsIO.sys
[2010/10/07 20:38:22 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2009/07/14 07:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 04:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 04:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 02:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 01:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 23:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/07/09 03:03:02 | 000,058,880 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2009/06/10 23:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\Windows\SysWow64\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\Iyvu9_32.dll

========== LOP Check ==========

[2011/08/26 20:58:25 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\.minecraft
[2011/08/28 22:34:33 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\.spoutcraft
[2011/07/30 21:06:58 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\app
[2010/12/25 17:19:26 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Braid
[2010/10/23 16:45:48 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/10/10 22:21:14 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\DAEMON Tools Lite
[2011/08/07 20:20:40 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\dofus 2
[2011/07/30 18:34:57 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Dofus-2.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/31 10:33:48 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Dofus-3.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/07/30 19:03:13 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Dofus.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/08/04 13:43:35 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\EVEMon
[2011/03/30 14:55:29 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\FOG Downloader
[2011/08/11 15:40:50 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Leadertech
[2011/01/30 19:02:52 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\LolClient
[2011/03/30 19:47:01 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\MD5 Checksum Verifier
[2011/03/07 13:49:03 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Mount&Blade Warband
[2011/08/12 22:06:14 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Mumble
[2011/06/08 01:50:33 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Natural Selection 2
[2011/06/28 16:05:02 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Notepad++
[2011/06/05 19:53:25 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Publish Providers
[2011/08/29 09:42:36 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Razer
[2011/07/30 21:06:58 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Reg.C9ECCBDBA4E09304DEEFB106465BC17F6D6749B9.1
[2011/04/12 01:07:10 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Rovio
[2011/06/08 19:44:53 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Sony
[2011/06/09 08:19:47 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Sony Creative Software Inc
[2011/08/29 09:42:28 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\TS3Client
[2011/08/29 09:42:28 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\uTorrent
[2011/04/16 11:52:44 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\wargaming.net
[2010/10/14 22:22:45 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Windows Live Writer
[2010/10/24 13:01:28 | 000,000,000 | ---D | M] -- C:\Users\Ezequiel\AppData\Roaming\Youtube Downloader HD
[2011/08/09 16:33:29 | 000,032,552 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >

Edited by ongre, 29 August 2011 - 06:42 AM.

  • 0

Similar Topics: Hitman Pro 3.5 - can't remove     x


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 13,200 posts
  • MVP
Disable Spybot's TeaTimer to make sure it won't interfere with fixes. You can re-enable it when you're clean again:

* Run Spybot-S&D in Advanced Mode
* If it is not already set to do this, go to the Mode menu
select
Advanced Mode
* On the left hand side, click on Tools
* Then click on the Resident icon in the list
* Uncheck
Resident TeaTimer
and OK any prompts.
* Restart your computer



Copy the text in the code box by highlighting and Ctrl + c


:processes
killallprocesses


:OTL
O34 - HKLM BootExecute: (bootdelete) - File not found
[2011/08/28 16:46:39 | 000,012,872 | ---- | C] (SurfRight B.V.) -- C:\Windows\SysNative\bootdelete.exe
[2011/08/28 16:46:39 | 000,002,090 | ---- | M] () -- C:\Windows\SysNative\bootdelete.lst
     
:Commands
[Reboot]


then Rightclick on OTL and select Run As Administrator to start. Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the RUN FIX button (NOT THE QUICK SCAN button!) at the top
Let the program run unhindered, OTL will reboot the PC when it is done.

Did it work?

Ron
  • 0

#3
ongre

ongre

    Member

  • Member
  • PipPip
  • 12 posts
It worked many thanks !! So the software is definitely removed from my computer ?

Thanks again for this quick fix !
  • 0

#4
RKinner

RKinner

    Malware Expert

  • Expert
  • 13,200 posts
  • MVP
That's all of it that I can see from the OTL logs. If it's not coming up on boot now then I think it's gone for good.

Ron
  • 0


0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

featured