I have attempted various "fixes" etc but all to no avail:
1) used Norton's recommended fix (per the security pop-ip) Backdoor Tidserv Removal Tool FixTDSS.exe - ran scan, no infected files found, no action taken
2) browsed various forums for ideas - ran full system scan in both "regular" and "safe" modes with Norton and Malwarebytes - once again, no infected files found, no action taken. One thing to note here - various forums have said to unhide non-plug and play drivers and delete ones labelled TDSS - I never found any labelled as such.
3) Posted issue on Norton forums - was recommended to run TDSSKiller from kaspersky.com. Did so, and once again no infected files found.
4) upon completion of TDSSKiller, with no results was referred to this forum for further assistance. Apparently you use "more advanced tools".
This has been going on for three days now and is driving me crazy - I don't know if I should even be using this computer. I do not know if it is infected, if it is not and just reading a "false positive", if someone is trying to hack it, if there is someting in that is allowing people to hack, or what. I'm at my wit's end right now and need help.
I will attach a jpeg of the response from Norton on the anti-virus history. This screenshot was taken at 10.05pm tonight, since that time I have had two more Trojan.Gen.2 detection alerts and am about due for my next hack attempt from Tidserv. This is getting stupid.
Also, attached please find, per forum instructions, a copy of the OTL log. Thanks again!
OTL logfile created on: 9/20/2011 9:53:28 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Users\Kiwifrost4\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 1.52 Gb Available Physical Memory | 37.97% Memory free
8.20 Gb Paging File | 5.64 Gb Available in Paging File | 68.73% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.76 Gb Total Space | 224.00 Gb Free Space | 48.09% Space Free | Partition Type: NTFS
Computer Name: KIWIFROST4-PC | User Name: Kiwifrost4 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/09/20 21:52:31 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Kiwifrost4\Desktop\OTL.exe
PRC - [2011/09/11 12:10:30 | 000,411,432 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2011/08/31 07:47:27 | 000,243,360 | ---- | M] (Adobe Systems, Inc.) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil10w_ActiveX.exe
PRC - [2011/08/16 22:50:04 | 000,066,872 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/08/02 22:14:29 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\steam.exe
PRC - [2011/07/13 08:27:11 | 000,273,544 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files (x86)\real\realplayer\Update\realsched.exe
PRC - [2011/06/30 09:50:40 | 003,029,208 | ---- | M] (Emsi Software GmbH) -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
PRC - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton AntiVirus\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/04/01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/03/22 23:56:40 | 000,687,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
PRC - [2011/03/21 16:10:00 | 001,230,704 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2011/03/01 23:14:08 | 000,190,808 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/03/01 23:13:44 | 000,203,096 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
PRC - [2010/10/21 13:53:56 | 001,211,216 | ---- | M] (Logitech, Inc.) -- C:\Program Files (x86)\Logitech\LWS\LU\LogitechUpdate.exe
PRC - [2010/10/21 13:53:48 | 000,341,328 | ---- | M] (Logitech, Inc.) -- C:\Program Files (x86)\Logitech\LWS\LU\LULnchr.exe
PRC - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
PRC - [2008/01/20 21:49:49 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE
PRC - [2006/12/28 21:18:00 | 000,122,512 | ---- | M] (B.H.A Corporation) -- C:\Windows\SysWOW64\bgsvcgen.exe
========== Modules (No Company Name) ==========
MOD - [2011/09/11 12:10:30 | 014,407,976 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2011/09/11 12:10:19 | 000,190,248 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2011/09/11 12:10:19 | 000,091,432 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-50.dll
MOD - [2011/09/11 12:10:18 | 000,914,216 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-52.dll
MOD - [2011/09/11 12:10:18 | 000,155,432 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-52.dll
MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/30 18:25:42 | 000,331,608 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll
MOD - [2011/03/22 23:56:40 | 000,687,448 | ---- | M] () -- C:\Program Files (x86)\Common Files\LogiShrd\LQCVFX\COCIManager.exe
MOD - [2011/03/21 16:10:36 | 000,096,112 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2011/03/21 16:10:00 | 001,230,704 | ---- | M] () -- C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/03/15 07:13:46 | 004,254,560 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2011/03/01 23:13:44 | 000,203,096 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
MOD - [2010/05/07 18:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2010/05/07 18:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2010/05/07 18:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2010/05/07 18:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2010/05/07 18:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2010/03/24 22:17:36 | 008,794,464 | ---- | M] () -- C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/04/11 01:28:22 | 000,223,232 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2009/07/02 12:16:05 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/09/11 12:10:30 | 000,411,432 | ---- | M] (Valve Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2011/08/16 22:50:04 | 000,066,872 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/06/30 09:50:40 | 003,029,208 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files (x86)\Norton AntiVirus\Engine\18.6.0.29\ccSvcHst.exe -- (NAV)
SRV - [2011/04/01 05:11:52 | 000,428,640 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/03/29 23:42:14 | 000,066,368 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Auto | Running] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2006/12/28 21:18:00 | 000,122,512 | ---- | M] (B.H.A Corporation) [Auto | Running] -- C:\Windows\SysWOW64\bgsvcgen.exe -- (bgsvcgen)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\Drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/05/02 17:04:42 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\Drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2011/04/01 05:07:54 | 004,184,672 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lvuvc64.sys -- (LVUVC64) Logitech HD Webcam C510(UVC)
DRV:64bit: - [2011/03/30 22:00:09 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\Drivers\NAVx64\1206000.01D\SRTSP64.SYS -- (SRTSP)
DRV:64bit: - [2011/03/30 22:00:09 | 000,040,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NAVx64\1206000.01D\SRTSPX64.SYS -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:64bit: - [2011/03/21 19:39:49 | 000,432,760 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\Drivers\NAVx64\1206000.01D\SYMTDIV.SYS -- (SYMTDIv)
DRV:64bit: - [2011/03/14 21:31:23 | 000,912,504 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NAVx64\1206000.01D\SYMEFA64.SYS -- (SymEFA)
DRV:64bit: - [2011/01/27 01:47:10 | 000,450,680 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NAVx64\1206000.01D\SYMDS64.SYS -- (SymDS)
DRV:64bit: - [2011/01/27 00:07:06 | 000,171,128 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NAVx64\1206000.01D\Ironx64.SYS -- (SymIRON)
DRV:64bit: - [2010/11/09 21:44:24 | 000,341,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lvrs64.sys -- (LVRS64)
DRV:64bit: - [2010/11/09 21:42:34 | 000,024,032 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\lvbflt64.sys -- (CompFilter64)
DRV:64bit: - [2010/05/07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2Mon)
DRV:64bit: - [2010/05/07 18:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\LVPr2M64.sys -- (LVPr2M64)
DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\wpdusb.sys -- (WpdUsb)
DRV:64bit: - [2009/07/02 12:51:28 | 006,036,480 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\atikmdag.sys -- (atikmdag)
DRV:64bit: - [2009/06/04 06:20:48 | 000,113,168 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2008/04/22 10:53:36 | 000,012,744 | R--- | M] (EnTech Taiwan) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\ENTECH64.sys -- (ENTECH64)
DRV:64bit: - [2008/01/20 21:46:55 | 000,317,952 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\DRIVERS\e1e6032e.sys -- (e1express) Intel®
DRV - [2011/09/19 22:55:21 | 002,048,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110920.019\EX64.SYS -- (NAVEX15)
DRV - [2011/09/19 22:55:21 | 000,117,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\VirusDefs\20110920.019\ENG64.SYS -- (NAVENG)
DRV - [2011/09/09 12:44:05 | 001,152,632 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\BASHDefs\20110909.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2011/09/08 20:05:01 | 000,481,912 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2011/08/23 00:17:32 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\Definitions\IPSDefs\20110917.033\IDSviA64.sys -- (IDSVia64)
DRV - [2011/07/27 18:46:05 | 000,136,824 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/02/20 21:30:06 | 000,085,800 | ---- | M] (Emsi Software GmbH) [File_System | On_Demand | Running] -- C:\Program Files (x86)\Emsisoft Anti-Malware\a2accx64.sys -- (a2acc)
DRV - [2006/02/20 19:17:00 | 000,033,408 | ---- | M] (B.H.A Corporation) [Kernel | System | Stopped] -- C:\Windows\SysWow64\drivers\cdrbsdrv.sys -- (cdrbsdrv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,XMLHTTP_UUID_Default = 27 B7 BE 01 E1 AA CB 41 8B 6B 9D 63 F1 12 57 9F [binary data]
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTNavAssist.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>;*.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6522
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.647: c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.647: c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.660: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.660: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.660: c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.1: C:\Users\Kiwifrost4\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll ( )
FF - HKCU\Software\MozillaPlugins\@facebook.com/FBPlugin,version=1.0.3: C:\Users\Kiwifrost4\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll ( )
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Kiwifrost4\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Kiwifrost4\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_18.1.0.37\IPSFFPlgn\ [2011/08/17 08:53:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{5D8CB31C-4E86-4C53-AF81-F6A7345EE51A}: C:\Users\Kiwifrost4\AppData\Local\{5D8CB31C-4E86-4C53-AF81-F6A7345EE51A} [2010/08/20 13:48:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/09/18 18:17:25 | 000,000,000 | ---D | M]
[2010/09/23 20:59:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Kiwifrost4\AppData\Roaming\Mozilla\Extensions
========== Chrome ==========
CHR - default_search_provider: Live Search (Enabled)
CHR - default_search_provider: search_url = http://search.live.c...ferrer:source?}
CHR - default_search_provider: suggest_url =
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\Application\12.0.742.122\pdf.dll
CHR - plugin: Google Gears 0.5.33.0 (Enabled) = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\Application\12.0.742.122\gears.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\Application\12.0.742.122\gcswf32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeploytk.dll
CHR - plugin: Java Platform SE 6 U17 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.5 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Coupon Print Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\Application\plugins\NPcol400.dll
CHR - plugin: Coupon Print Activator Netscape Plugin v. 5.0.0.0 (Enabled) = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\Application\plugins\NPcol500.dll
CHR - plugin: CANON iMAGE GATEWAY Album Plugin Utility (Enabled) = C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.2.183.39\npGoogleOneClick8.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RealPlayer HTML5VideoShim Plug-In (32-bit) (Enabled) = C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Kiwifrost4\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll
CHR - plugin: Facebook Plugin (Enabled) = C:\Users\Kiwifrost4\AppData\Roaming\Facebook\npfbplugin_1_0_3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: RealPlayer G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprjplug.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = c:\program files (x86)\real\realplayer\Netscape6\nprpjplug.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.1.1_0\
CHR - Extension: RealPlayer HTML5Video Downloader Extension = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.5_0\
CHR - Extension: Skype Extension = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.5.0.7896_0\
CHR - Extension: Poppit = C:\Users\Kiwifrost4\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2006/09/18 16:37:24 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton AntiVirus\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn2\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Windows Live Toolbar) - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files (x86)\Windows Live Toolbar\msntb.dll (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\real\realplayer\update\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [BitTorrent] C:\Program Files (x86)\BitTorrent\BitTorrent.exe (BitTorrent, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\SysWOW64\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; WOW64; Trident/5.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET4.0C; InfoPath.3; .NET CLR 3.0.30729)" -"http://www.haelmedia...mc_m2_001.html" File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 205.171.3.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2A38FB7A-51D2-4C8B-8D77-848410063A99}: DhcpNameServer = 192.168.0.1 205.171.3.25
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Kiwifrost4\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Kiwifrost4\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{2cf3234a-940c-11de-950c-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{2cf3234a-940c-11de-950c-806e6f6e6963}\Shell\AutoRun\command - "" = D:\setup\rsrc\Autorun.exe
O33 - MountPoints2\{2cf3234a-940c-11de-950c-806e6f6e6963}\Shell\dinstall\command - "" = D:\Directx\dxsetup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/09/20 21:52:30 | 000,582,656 | ---- | C] (OldTimer Tools) -- C:\Users\Kiwifrost4\Desktop\OTL.exe
[2011/09/20 21:35:38 | 001,403,184 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Kiwifrost4\Desktop\TDSSKiller.exe
[2011/09/19 21:18:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Sun
[2011/09/19 21:18:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/09/19 19:28:43 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware
[2011/09/19 19:28:30 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Anti-Malware
[2011/09/19 19:28:30 | 000,000,000 | ---D | C] -- C:\Users\Kiwifrost4\Documents\Anti-Malware
[2011/09/19 19:22:32 | 101,856,272 | ---- | C] (Emsi Software GmbH ) -- C:\Users\Kiwifrost4\Desktop\EmsisoftAntiMalwareSetup.exe
[2011/09/19 19:16:40 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2011/09/19 19:15:59 | 003,480,352 | ---- | C] (Piriform Ltd) -- C:\Users\Kiwifrost4\Desktop\ccsetup310.exe
[2011/09/19 18:36:27 | 000,000,000 | ---D | C] -- C:\Users\Kiwifrost4\AppData\Local\VirtualStore
[2011/09/19 00:21:25 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2011/09/18 16:33:14 | 000,000,000 | ---D | C] -- C:\Windows\system64
[2011/09/10 00:24:55 | 000,000,000 | ---D | C] -- C:\Users\Kiwifrost4\Documents\Activision
[2011/08/31 08:02:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/08/31 08:01:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/08/31 08:01:55 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/08/31 07:56:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/08/31 07:56:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/08/24 22:51:09 | 000,060,273 | ---- | C] (Open Source Software community project) -- C:\Windows\SysWow64\pthreadGC2.dll
[2011/08/24 22:51:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ffdshow
[2011/08/24 22:51:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Haali
[2011/08/24 22:51:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AviSynth 2.5
[2011/08/24 22:50:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sothink Movie DVD Maker
[2011/08/24 22:50:51 | 000,290,816 | ---- | C] (SourceTec Software Co., LTD) -- C:\Windows\SysWow64\stFLVSource.ax
[2011/08/24 22:50:51 | 000,147,456 | ---- | C] (SourceTec) -- C:\Windows\SysWow64\stQTSource.ax
[2011/08/24 22:50:50 | 000,438,272 | ---- | C] (Gabest) -- C:\Windows\SysWow64\Mpeg2DecFilter.ax
[2011/08/24 22:50:50 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\Windows\SysWow64\pncrt.dll
[2011/08/24 22:50:50 | 000,217,088 | ---- | C] (-) -- C:\Windows\SysWow64\CoreFLACDecoder.ax
[2011/08/24 22:50:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SourceTec
[2011/08/24 22:50:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Sothink Movie DVD Maker
[2011/08/24 22:49:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\dvdmaker
[2011/08/24 22:48:32 | 028,027,144 | ---- | C] (SourceTec Software Co., LTD ) -- C:\Program Files (x86)\Setup.exe
[2011/08/01 20:13:55 | 005,015,880 | ---- | C] (Canneverbe Limited ) -- C:\Program Files (x86)\cdbxp_setup_4.3.8.2568.exe
[2011/07/31 15:01:18 | 065,981,368 | ---- | C] (Online Media Technologies Ltd. ) -- C:\Program Files (x86)\AVSVideoConverter.exe
[2011/07/13 22:23:00 | 001,030,024 | ---- | C] (Skype Technologies S.A.) -- C:\Program Files (x86)\SkypeSetup.exe
[2011/05/03 20:31:01 | 087,359,831 | ---- | C] (Realtek Semiconductor Corp.) -- C:\Program Files (x86)\Vista_Win7_R259.exe
[2011/04/18 21:40:49 | 020,817,978 | ---- | C] (Shark007) -- C:\Program Files (x86)\VistaCodecs_v593.exe
[2011/04/14 23:13:14 | 013,193,238 | ---- | C] (Shark007) -- C:\Program Files (x86)\x64Components_v285.exe
[2011/02/27 14:29:10 | 681,867,016 | ---- | C] (Microsoft Corporation) -- C:\Program Files (x86)\X16-32250.exe
[2010/09/25 23:34:28 | 002,985,328 | ---- | C] (BitTorrent, Inc.) -- C:\Program Files (x86)\BitTorrent-7.1.exe
[2010/09/16 19:56:06 | 010,255,560 | ---- | C] (iSkysoft Software ) -- C:\Program Files (x86)\mkv-converter-win_full676.exe
[2010/08/29 21:03:58 | 005,881,679 | ---- | C] (Moritz Bunkus) -- C:\Program Files (x86)\mkvtoolnix-unicode-4.2.0-setup.exe
[2010/08/29 19:24:19 | 016,847,824 | ---- | C] (Any-Video-Converter.com ) -- C:\Program Files (x86)\avc-free.exe
[2010/08/29 19:18:42 | 000,866,532 | ---- | C] (CHENGDU WEISHU TECHNOLOGY CO., LTD. ) -- C:\Program Files (x86)\mkv-to-wmv.exe
[2010/07/22 00:14:14 | 000,907,735 | ---- | C] ( ) -- C:\Program Files\DVD43_Plugin_Setup_1.0.0.5.exe
[2010/07/22 00:11:10 | 000,568,900 | ---- | C] ( ) -- C:\Program Files\DVD43_4-6-0_Setup.exe
[2010/07/21 23:51:36 | 054,822,952 | ---- | C] (Online Media Technologies Ltd. ) -- C:\Program Files\AVSVideoConverter.exe
[2010/07/21 23:33:00 | 009,423,386 | ---- | C] (Digiarty Software, Inc. ) -- C:\Program Files\winx-dvd-ripper-pt.exe
[2010/07/21 23:28:45 | 006,971,290 | ---- | C] (Digiarty Software, Inc. ) -- C:\Program Files\winx-free-dvd-ripper.exe
[2010/06/10 01:11:30 | 000,895,256 | ---- | C] (DivX, Inc. ) -- C:\Program Files (x86)\DivXInstaller.exe
[2010/05/04 16:06:17 | 003,382,520 | ---- | C] (Piriform Ltd) -- C:\Program Files (x86)\ccsetup231.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/09/20 21:52:31 | 000,582,656 | ---- | M] (OldTimer Tools) -- C:\Users\Kiwifrost4\Desktop\OTL.exe
[2011/09/20 21:35:27 | 001,386,742 | ---- | M] () -- C:\Users\Kiwifrost4\Desktop\tdsskiller.zip
[2011/09/20 21:08:46 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/09/20 21:08:46 | 000,003,616 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/09/20 19:41:55 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1882694805-4187760394-1783181854-1000UA.job
[2011/09/20 19:41:44 | 000,002,067 | ---- | M] () -- C:\Users\Kiwifrost4\Desktop\Google Chrome.lnk
[2011/09/20 19:41:44 | 000,002,029 | ---- | M] () -- C:\Users\Kiwifrost4\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/09/20 19:36:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2011/09/20 19:03:00 | 000,000,282 | ---- | M] () -- C:\Windows\tasks\Check Updates for Windows Live Toolbar.job
[2011/09/20 11:41:00 | 000,000,876 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1882694805-4187760394-1783181854-1000Core.job
[2011/09/20 08:54:14 | 001,403,184 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Kiwifrost4\Desktop\TDSSKiller.exe
[2011/09/20 05:36:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2011/09/19 21:08:23 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/09/19 20:21:27 | 000,000,732 | ---- | M] () -- C:\Users\Kiwifrost4\AppData\Local\d3d9caps64.dat
[2011/09/19 19:28:43 | 000,000,930 | ---- | M] () -- C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2011/09/19 19:26:51 | 101,856,272 | ---- | M] (Emsi Software GmbH ) -- C:\Users\Kiwifrost4\Desktop\EmsisoftAntiMalwareSetup.exe
[2011/09/19 19:15:59 | 003,480,352 | ---- | M] (Piriform Ltd) -- C:\Users\Kiwifrost4\Desktop\ccsetup310.exe
[2011/09/19 18:57:29 | 000,206,848 | ---- | M] () -- C:\Users\Kiwifrost4\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/19 07:43:57 | 000,000,258 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2011/09/19 00:21:32 | 000,000,268 | -H-- | M] () -- C:\sqmdata18.sqm
[2011/09/19 00:21:32 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt18.sqm
[2011/09/18 23:45:57 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/18 21:44:51 | 000,000,268 | -H-- | M] () -- C:\sqmdata17.sqm
[2011/09/18 21:44:51 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt17.sqm
[2011/09/18 21:34:51 | 000,707,392 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/09/18 21:34:51 | 000,607,168 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/09/18 21:34:51 | 000,104,808 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/09/18 20:07:11 | 000,000,268 | -H-- | M] () -- C:\sqmdata16.sqm
[2011/09/18 20:07:11 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt16.sqm
[2011/09/18 18:08:22 | 000,000,268 | -H-- | M] () -- C:\sqmdata15.sqm
[2011/09/18 18:08:22 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt15.sqm
[2011/09/18 17:53:14 | 000,006,192 | ---- | M] () -- C:\{219ACBFF-33E0-45D7-84B9-FE2B16FB6A5F}
[2011/09/18 17:25:34 | 000,000,268 | -H-- | M] () -- C:\sqmdata14.sqm
[2011/09/18 17:25:34 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt14.sqm
[2011/09/18 17:17:02 | 000,000,268 | -H-- | M] () -- C:\sqmdata13.sqm
[2011/09/18 17:17:02 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt13.sqm
[2011/09/18 16:33:31 | 000,000,300 | ---- | M] () -- C:\Users\Kiwifrost4\AppData\Roaming\5F4E.91D
[2011/09/18 15:50:47 | 000,000,268 | -H-- | M] () -- C:\sqmdata12.sqm
[2011/09/18 15:50:47 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt12.sqm
[2011/09/18 03:30:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata11.sqm
[2011/09/18 03:30:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt11.sqm
[2011/09/18 02:02:59 | 000,000,468 | ---- | M] () -- C:\Windows\tasks\Driver Robot.job
[2011/09/15 03:22:24 | 000,000,268 | -H-- | M] () -- C:\sqmdata10.sqm
[2011/09/15 03:22:24 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt10.sqm
[2011/09/13 09:09:49 | 000,000,268 | -H-- | M] () -- C:\sqmdata09.sqm
[2011/09/13 09:09:49 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt09.sqm
[2011/09/12 08:39:37 | 000,000,268 | -H-- | M] () -- C:\sqmdata08.sqm
[2011/09/12 08:39:37 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt08.sqm
[2011/09/11 11:54:15 | 000,000,268 | -H-- | M] () -- C:\sqmdata07.sqm
[2011/09/11 11:54:15 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt07.sqm
[2011/09/06 09:09:13 | 000,000,268 | -H-- | M] () -- C:\sqmdata06.sqm
[2011/09/06 09:09:13 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt06.sqm
[2011/08/31 08:02:12 | 000,001,694 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/08/31 07:50:05 | 000,001,917 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/08/30 23:17:27 | 000,000,268 | -H-- | M] () -- C:\sqmdata05.sqm
[2011/08/30 23:17:26 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt05.sqm
[2011/08/25 23:08:16 | 000,000,268 | -H-- | M] () -- C:\sqmdata04.sqm
[2011/08/25 23:08:16 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt04.sqm
[2011/08/25 09:10:01 | 000,000,268 | -H-- | M] () -- C:\sqmdata03.sqm
[2011/08/25 09:10:01 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt03.sqm
[2011/08/24 22:50:56 | 000,000,975 | ---- | M] () -- C:\Users\Kiwifrost4\Application Data\Microsoft\Internet Explorer\Quick Launch\Sothink Movie DVD Maker.lnk
[2011/08/24 22:48:01 | 027,947,271 | ---- | M] () -- C:\Program Files (x86)\dvdmaker.zip
[2011/08/24 09:04:23 | 000,000,268 | -H-- | M] () -- C:\sqmdata02.sqm
[2011/08/24 09:04:23 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt02.sqm
[2011/08/22 09:05:06 | 000,000,268 | -H-- | M] () -- C:\sqmdata01.sqm
[2011/08/22 09:05:06 | 000,000,244 | -H-- | M] () -- C:\sqmnoopt01.sqm
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/09/20 21:35:27 | 001,386,742 | ---- | C] () -- C:\Users\Kiwifrost4\Desktop\tdsskiller.zip
[2011/09/19 19:28:43 | 000,000,930 | ---- | C] () -- C:\Users\Public\Desktop\Emsisoft Anti-Malware.lnk
[2011/09/19 07:43:57 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/09/19 00:41:32 | 000,000,732 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Local\d3d9caps64.dat
[2011/09/18 17:53:14 | 000,006,192 | ---- | C] () -- C:\{219ACBFF-33E0-45D7-84B9-FE2B16FB6A5F}
[2011/09/18 16:33:31 | 000,000,300 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Roaming\5F4E.91D
[2011/08/31 08:02:12 | 000,001,694 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/08/31 07:48:40 | 000,001,917 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/08/31 07:48:39 | 000,002,425 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/08/24 22:51:09 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2011/08/24 22:50:56 | 000,000,975 | ---- | C] () -- C:\Users\Kiwifrost4\Application Data\Microsoft\Internet Explorer\Quick Launch\Sothink Movie DVD Maker.lnk
[2011/08/24 22:50:50 | 000,070,656 | ---- | C] () -- C:\Windows\SysWow64\RLAPEDec.ax
[2011/08/24 22:47:16 | 027,947,271 | ---- | C] () -- C:\Program Files (x86)\dvdmaker.zip
[2011/08/16 22:50:04 | 000,682,280 | ---- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2011/05/12 00:21:25 | 000,201,444 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/05/03 21:25:28 | 085,083,722 | ---- | C] () -- C:\Program Files (x86)\VistaWindows7HD-256.zip
[2011/04/01 05:07:02 | 010,877,272 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll
[2011/04/01 05:07:02 | 000,102,744 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 05:06:56 | 000,331,608 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll
[2010/12/19 13:44:30 | 000,000,030 | ---- | C] () -- C:\Windows\MotionSDSTUDIO.INI
[2010/11/15 10:02:58 | 020,953,077 | ---- | C] () -- C:\Program Files (x86)\pod-works.exe
[2010/10/26 21:34:47 | 030,355,045 | ---- | C] () -- C:\Program Files (x86)\mov-converter6.exe
[2010/10/14 23:13:15 | 000,001,940 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2010/09/22 17:08:20 | 000,293,144 | ---- | C] () -- C:\Program Files\SoftonicDownloader_for_hjsplit.exe
[2010/09/01 20:25:53 | 001,531,593 | ---- | C] () -- C:\Program Files (x86)\winrar-x64-393.exe
[2010/08/24 18:12:11 | 000,117,248 | ---- | C] () -- C:\Windows\SysWow64\EhStorAuthn.dll
[2010/08/24 18:11:31 | 000,107,612 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/08/24 18:10:48 | 000,368,640 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2010/08/20 13:48:35 | 000,000,120 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Local\Hsogapakukakad.dat
[2010/08/20 13:48:35 | 000,000,000 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Local\Isacir.bin
[2010/07/21 23:42:49 | 001,853,399 | ---- | C] () -- C:\Program Files\EasyDVDClonec.exe
[2010/02/10 00:17:38 | 000,708,868 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2009/12/28 11:14:16 | 000,000,053 | ---- | C] () -- C:\Windows\WININIT.INI
[2009/12/28 11:14:13 | 000,000,000 | ---- | C] () -- C:\Windows\setup32.INI
[2009/10/19 17:33:31 | 000,000,831 | ---- | C] () -- C:\Windows\CoDUO.INI
[2009/10/19 17:09:19 | 000,000,766 | ---- | C] () -- C:\Windows\CoD.INI
[2009/10/19 16:40:08 | 000,010,240 | ---- | C] () -- C:\Windows\SysWow64\vidx16.dll
[2009/10/19 14:15:32 | 000,111,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2009/10/19 14:15:31 | 000,066,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2009/10/19 14:15:30 | 000,000,331 | ---- | C] () -- C:\Windows\game.ini
[2009/10/18 21:21:34 | 000,018,904 | ---- | C] () -- C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2009/10/18 16:58:04 | 000,010,922 | ---- | C] () -- C:\Windows\cdplayer.ini
[2009/10/18 08:23:13 | 000,149,504 | ---- | C] () -- C:\Windows\UNWISE.EXE
[2009/10/17 22:08:29 | 000,206,848 | ---- | C] () -- C:\Users\Kiwifrost4\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/26 19:09:05 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2009/07/10 13:39:00 | 000,350,720 | ---- | C] () -- C:\Program Files\hjsplit.exe
[2008/01/20 21:50:05 | 000,060,124 | ---- | C] () -- C:\Windows\SysWow64\tcpmon.ini
[2007/07/23 11:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2007/07/23 11:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSwedish.dll
[2007/07/23 11:03:32 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSpanish.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelPortugese.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelKorean.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelJapanese.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelGerman.dll
[2007/07/23 11:03:30 | 000,053,248 | ---- | C] () -- C:\Windows\SysWow64\AgCPanelFrench.dll
[2006/11/02 10:37:05 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
========== LOP Check ==========
[2010/08/29 19:26:08 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\AnvSoft
[2011/09/20 08:20:15 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\BitTorrent
[2009/10/18 12:28:03 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Blitware
[2011/08/01 20:15:44 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Canneverbe Limited
[2011/08/03 23:24:46 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Canon
[2010/09/06 13:52:24 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Catalina Marketing Corp
[2010/07/21 23:33:38 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Digiarty
[2009/12/10 19:46:33 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\E-centives
[2010/03/14 22:49:58 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Facebook
[2009/12/26 23:32:57 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\GetRightToGo
[2010/11/15 10:03:36 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\ImTOO
[2009/10/18 09:06:35 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\InterTrust
[2009/12/28 11:35:15 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Leadertech
[2010/08/29 21:04:52 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\mkvtoolnix
[2011/01/04 23:25:25 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Ogg2MP3
[2011/02/04 20:47:03 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\TaxCut
[2010/08/20 14:52:23 | 000,000,000 | ---D | M] -- C:\Users\Kiwifrost4\AppData\Roaming\Tific
[2011/09/20 19:03:00 | 000,000,282 | ---- | M] () -- C:\Windows\Tasks\Check Updates for Windows Live Toolbar.job
[2011/09/18 02:02:59 | 000,000,468 | ---- | M] () -- C:\Windows\Tasks\Driver Robot.job
[2011/09/19 19:32:14 | 000,032,654 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:A8ADE5D8
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >