Thanks for your help
OTL logfile created on: 11/3/2011 11:16:16 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\W@Z@L\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 2.17 Gb Available Physical Memory | 54.32% Memory free
8.00 Gb Paging File | 5.49 Gb Available in Paging File | 68.66% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.48 Gb Total Space | 89.22 Gb Free Space | 31.92% Space Free | Partition Type: NTFS
Drive D: | 931.51 Gb Total Space | 356.51 Gb Free Space | 38.27% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 78.73 Gb Free Space | 8.45% Space Free | Partition Type: NTFS
Computer Name: WEZEL | User Name: W@Z@L | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/11/03 23:15:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\W@Z@L\Desktop\OTL.exe
PRC - [2011/10/15 03:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
PRC - [2011/10/03 16:12:45 | 000,075,136 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2011/09/29 21:19:00 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/15 14:51:08 | 000,683,352 | ---- | M] (IObit) -- C:\Program Files (x86)\IObit\Game Booster\gbtray.exe
PRC - [2011/04/28 22:40:20 | 000,095,656 | ---- | M] (Binary Fortress Software) -- C:\Program Files (x86)\DisplayFusion\DisplayFusionHookx86.exe
PRC - [2011/02/15 06:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
PRC - [2010/12/07 14:41:58 | 000,365,704 | ---- | M] (NovaStor) -- C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\nsService.exe
PRC - [2010/07/04 14:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe
PRC - [2010/03/14 22:56:12 | 001,540,352 | ---- | M] (SmartPCTools) -- C:\Program Files (x86)\SmartPCTools\Registry Repair Wizard\RCHelper.exe
PRC - [2007/09/02 15:58:52 | 000,495,616 | ---- | M] () -- C:\Users\W@Z@L\Desktop\DownloadsBACKUP!!!!\RocketDock Backup\Backup\RocketDock.exe
========== Modules (No Company Name) ==========
MOD - [2011/10/23 14:04:37 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/09/29 21:18:59 | 001,833,944 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
MOD - [2011/06/13 14:21:52 | 000,511,384 | ---- | M] () -- C:\Program Files (x86)\IObit\Game Booster\sqlite3.dll
MOD - [2011/02/15 06:20:22 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
MOD - [2011/02/15 06:20:08 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
MOD - [2011/02/15 06:20:02 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
MOD - [2011/02/15 06:19:44 | 000,229,376 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTCore.dll
MOD - [2011/02/15 06:19:30 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTUI.dll
MOD - [2011/02/15 06:19:20 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTFC.dll
MOD - [2010/11/20 22:24:09 | 000,232,448 | ---- | M] () -- \\?\globalroot\systemroot\syswow64\mswsock.DLL
MOD - [2010/11/20 22:24:09 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2010/07/26 23:37:16 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\MSI Afterburner\RTTSH.dll
MOD - [2010/07/04 16:32:36 | 000,004,608 | ---- | M] () -- C:\Program Files (x86)\Unlocker\UnlockerHook.dll
MOD - [2010/07/04 14:51:26 | 000,017,408 | ---- | M] () -- C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe
MOD - [2007/09/02 15:58:52 | 000,495,616 | ---- | M] () -- C:\Users\W@Z@L\Desktop\DownloadsBACKUP!!!!\RocketDock Backup\Backup\RocketDock.exe
MOD - [2007/09/02 15:57:36 | 000,069,632 | ---- | M] () -- C:\Users\W@Z@L\Desktop\DownloadsBACKUP!!!!\RocketDock Backup\Backup\RocketDock.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2011/09/24 15:03:32 | 000,341,312 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro PDF\Professional\6.0\NitroPDFDriverServicex64.exe -- (NitroDriverReadSpool)
SRV:64bit: - [2011/08/11 18:38:04 | 000,140,672 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE -- (!SASCORE)
SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/08/19 17:43:24 | 000,386,344 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2011/10/15 03:53:00 | 002,253,120 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe -- (nvUpdatusService)
SRV - [2011/10/03 16:12:45 | 000,075,136 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2011/09/24 15:03:42 | 000,068,928 | ---- | M] (Nalpeiron Ltd.) [Disabled | Stopped] -- C:\Windows\SysWOW64\NLSSRV32.EXE -- (nlsX86cc)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/03/04 13:39:14 | 000,584,488 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2011/03/01 18:29:58 | 000,130,976 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2010/12/07 14:41:58 | 000,365,704 | ---- | M] (NovaStor) [Auto | Running] -- C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\nsService.exe -- (nsService)
SRV - [2010/11/22 19:09:14 | 000,179,200 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files (x86)\NovaStor\NovaStor NovaBACKUP\ManagementServer.Agent.Service.exe -- (Backup Client Agent Service)
SRV - [2010/11/16 08:25:29 | 002,249,000 | ---- | M] (TeamViewer GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010/03/18 15:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/11/09 15:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/07/07 18:21:28 | 000,174,184 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2011/06/23 01:43:04 | 001,071,032 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\wcmvcam64.sys -- (WCMVCAM)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 22:24:43 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/11/20 22:24:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 22:23:48 | 000,117,248 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tsusbhub.sys -- (tsusbhub)
DRV:64bit: - [2010/11/20 22:23:48 | 000,088,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 22:23:48 | 000,034,816 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 22:23:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/04/12 03:55:00 | 000,091,568 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\scdemu.sys -- (SCDEmu)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/07/09 03:00:00 | 000,055,280 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64)
DRV:64bit: - [2009/06/10 15:35:35 | 000,408,960 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvm62x64.sys -- (NVENETFD)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2007/02/03 12:30:58 | 000,058,528 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:64bit: - [2007/02/03 12:25:56 | 000,955,680 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CamDrL64.sys -- (CamDrL64) Logitech QuickCam Pro 3000(PID_08B0)
DRV - [2010/05/26 19:43:00 | 000,014,648 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\MSI Afterburner\RTCore64.sys -- (RTCore64)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/?l=dis&o=15434
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = BB 2E EC CC 9E 75 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=382950&ilc=12"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "chrome://speeddial/content/speeddial.xul"
FF - prefs.js..keyword.URL: "http://search.yahoo....type=382950&p="
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.0: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.0\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=0.80.0: C:\Program Files (x86)\Battlelog Web Plugins\0.80.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\W@Z@L\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9}: C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\FirefoxPlugin\{01A8CA0A-4C96-465b-A49B-65C46FAD54F9} [2011/09/25 00:39:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/10/29 23:18:59 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/27 20:50:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/10/27 20:50:22 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/10/29 23:18:59 | 000,000,000 | ---D | M]
[2011/09/17 20:05:57 | 000,000,000 | ---D | M] (No name found) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Extensions
[2011/11/03 21:37:10 | 000,000,000 | ---D | M] (No name found) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions
[2011/09/27 18:26:16 | 000,000,000 | ---D | M] (WebMail Notifier) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{37fa1426-b82d-11db-8314-0800200c9a66}
[2011/09/23 20:29:58 | 000,000,000 | ---D | M] (LightShot (screenshot tool)) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{394DCBA4-1F92-4f8e-8EC9-8D2CB90CB69B}
[2011/10/25 19:01:24 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2011/09/17 20:21:20 | 000,000,000 | ---D | M] (WOT) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2011/11/03 21:37:10 | 000,000,000 | ---D | M] (DownloadHelper) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/10/22 16:45:43 | 000,000,000 | ---D | M] (Flash and Video Download) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}
[2011/10/12 03:06:29 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/09/17 20:21:19 | 000,000,000 | ---D | M] (Microsoft Default Manager) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\DefaultManager@Microsoft
[2011/10/02 17:38:25 | 000,000,000 | ---D | M] (Babylon) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\[email protected]
[2011/09/17 20:21:19 | 000,000,000 | ---D | M] (Ghostery) -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\[email protected]
[2011/09/17 20:21:19 | 000,000,000 | ---D | M] ("NetVideoHunter") -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\extensions\[email protected]
[2011/10/04 16:00:25 | 000,002,572 | ---- | M] () -- C:\Users\W@Z@L\AppData\Roaming\Mozilla\Firefox\Profiles\dyrx68vj.default\searchplugins\askcom.xml
[2011/10/21 17:40:45 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/17 22:38:26 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}
[2011/10/21 16:57:08 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/09/17 20:05:43 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2011/09/17 20:05:43 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Program Files (x86)\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{4176DFF4-4698-11DE-BEEB-45DA55D89593}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{64161300-E22B-11DB-8314-0800200C9A66}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{66E978CD-981F-47DF-AC42-E3CF417C1467}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{AFF87FA2-A58E-4EDD-B852-0A20203C1E17}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{B17C1C5A-04B1-11DB-9804-B622A1EF5492}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\{D4DD63FA-01E4-46A7-B6B1-EDAB7D6AD389}.XPI
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\[email protected]
() (No name found) -- C:\USERS\W@Z@L\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\DYRX68VJ.DEFAULT\EXTENSIONS\[email protected]
[2011/09/29 21:19:00 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/29 21:18:58 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
Hosts file not found
O2:64bit: - BHO: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (ContributeBHO Class) - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O2 - BHO: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5.1\Plugins\IEPlugin\contributeieplugin.dll (Adobe Systems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - No CLSID value found.
O4:64bit: - HKLM..\Run: [combofix] C:\ComboFix\CF15633.3XE (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [Eraser] C:\Program Files\Eraser\Eraser.exe (The Eraser Project)
O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [NVRaidService] C:\Program Files\NVIDIA Corporation\Raid\nvraidservice.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [UnlockerAssistant] C:\Program Files (x86)\Unlocker\UnlockerAssistant.exe ()
O4 - HKCU..\Run: [DisplayFusion] C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (Binary Fortress Software)
O4 - HKCU..\Run: [Registry Repair Wizard Scheduler] C:\Program Files (x86)\SmartPCTools\Registry Repair Wizard\RCHelper.exe (SmartPCTools)
O4 - HKCU..\Run: [RocketDock] C:\Users\W@Z@L\Desktop\DownloadsBACKUP!!!!\RocketDock Backup\Backup\RocketDock.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKCU..\Run: [uTorrent] C:\Program Files (x86)\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Upload to Facebook - C:\Program Files (x86)\WebcamMax\share\iecontext.htm File not found
O8 - Extra context menu item: Upload to Facebook - C:\Program Files (x86)\WebcamMax\share\iecontext.htm File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Program Files (x86)\Bonjour\mdnsNSP.dll File not found
O1364bit: - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: cleverreach.com ([novastor] http in Trusted sites)
O15 - HKCU\..Trusted Domains: google-analytics.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: novastor.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: novastor.com ([]https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1C467AA4-DC81-41E6-A854-E08F21501115}: DhcpNameServer = 192.168.1.1
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {E31004D1-A431-41B8-826F-E902F9D95C81} - Windows DreamScene - C:\Windows\SysNative\DreamScene.dll (Microsoft Corporation)
O22:64bit: - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - Deskscapes - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes3\deskscapes.dll (Stardock Corporation)
O22:64bit: - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - Stardock Vista ControlPanel Extension - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes\DesktopControlPanel.dll (Stardock)
O22:64bit: - SharedTaskScheduler: {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - StardockDreamController - C:\Program Files (x86)\Stardock\Object Desktop\DeskScapes\DreamControl.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/11/03 23:15:39 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\W@Z@L\Desktop\OTL.exe
[2011/11/03 22:29:25 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Malwarebytes
[2011/11/03 22:29:21 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\SUPERAntiSpyware.com
[2011/11/03 22:29:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2011/11/03 22:29:04 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2011/11/03 22:29:04 | 000,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2011/11/03 22:28:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 22:28:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/03 22:28:52 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/03 22:28:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/03 22:27:21 | 013,022,976 | ---- | C] (SUPERAntiSpyware.com) -- C:\Users\W@Z@L\Desktop\SUPERAntiSpyware.exe
[2011/11/03 22:27:05 | 009,852,544 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\W@Z@L\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/03 21:46:29 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Enki Games
[2011/11/03 21:37:03 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reincarnations 3- Back to Reality Collectors Edition
[2011/11/03 21:36:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Reincarnations 3- Back to Reality Collectors Edition
[2011/11/03 21:19:47 | 000,000,000 | ---D | C] -- C:\Windows\system64
[2011/11/03 20:05:04 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\TeamViewer
[2011/11/03 07:01:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2011/11/02 06:47:38 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\Orcs Must Die
[2011/11/02 06:45:04 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orcs Must Die!
[2011/11/02 06:37:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Orcs Must Die!
[2011/11/02 06:36:46 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Desktop\Orcs.Must.Die.v1.0r8.update.cracked.READ.NFO-THETA [ALEX]
[2011/11/02 06:36:45 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Desktop\Orcs.Must.Die.v1.0r7.update.cracked.fixed.READ.NFO-THETA [ALEX]
[2011/11/02 06:34:46 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Desktop\Orcs.Must.Die.v1.0r6.multi9.cracked.READ.NFO-THETA
[2011/10/29 23:25:08 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\HP
[2011/10/29 23:21:26 | 000,000,000 | ---D | C] -- C:\ProgramData\WEBREG
[2011/10/29 23:21:26 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\HP
[2011/10/29 23:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\HP Product Assistant
[2011/10/29 23:16:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\HP
[2011/10/29 23:16:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Hewlett-Packard
[2011/10/29 23:16:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2011/10/29 23:06:06 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
[2011/10/29 23:05:31 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2011/10/29 20:10:28 | 000,000,000 | ---D | C] -- C:\ProgramData\restore
[2011/10/29 19:54:19 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA
[2011/10/29 19:53:44 | 000,000,000 | ---D | C] -- C:\ProgramData\NVIDIA Corporation
[2011/10/29 19:52:56 | 000,068,928 | ---- | C] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/10/29 19:52:56 | 000,061,248 | ---- | C] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/10/29 16:55:35 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/10/29 16:52:56 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/10/29 16:44:27 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/10/29 16:44:27 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/10/29 16:44:27 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/10/29 16:44:22 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/10/29 16:44:21 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/10/29 16:43:16 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/10/29 08:59:24 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\SmartPCTools
[2011/10/29 08:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Registry Repair Wizard
[2011/10/29 08:58:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SmartPCTools
[2011/10/27 20:50:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
[2011/10/27 20:49:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\QuickTime
[2011/10/26 23:50:11 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\Facebook
[2011/10/26 18:31:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2011/10/26 18:31:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2011/10/25 09:02:03 | 000,000,000 | ---D | C] -- C:\ProgramData\RELOADED
[2011/10/25 09:02:03 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\PAYDAY
[2011/10/24 12:35:46 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\My Games
[2011/10/24 09:01:27 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
[2011/10/24 08:57:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\THQ
[2011/10/23 04:47:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Payday The Heist
[2011/10/22 19:36:48 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Sahmon Games
[2011/10/22 18:15:02 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Island - Castaway 2
[2011/10/22 18:14:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\The Island - Castaway 2
[2011/10/21 17:56:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Riot Games
[2011/10/21 14:58:56 | 000,000,000 | ---D | C] -- C:\Windows\FltMgr
[2011/10/21 08:08:47 | 000,000,000 | ---D | C] -- C:\ProgramData\SwagHack_Galaxy_Edition_3
[2011/10/21 08:03:28 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\Panda Security
[2011/10/21 07:59:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Panda Antivirus Pro 2012
[2011/10/21 07:58:46 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\PAV
[2011/10/21 07:58:46 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Panda Security
[2011/10/21 07:58:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2011/10/21 07:58:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
[2011/10/21 07:58:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Panda Security
[2011/10/21 05:46:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Steam
[2011/10/21 05:40:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trendy Entertainment
[2011/10/20 19:44:51 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\My Cheat Tables
[2011/10/20 13:59:29 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Trillian
[2011/10/20 13:58:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Trillian
[2011/10/19 21:07:52 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\201280
[2011/10/19 02:28:49 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/10/19 00:59:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster
[2011/10/19 00:59:35 | 000,000,000 | ---D | C] -- C:\ProgramData\IObit
[2011/10/19 00:59:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit
[2011/10/18 22:11:25 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\The Adventures of Tintin
[2011/10/18 17:28:03 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Realtime Soft
[2011/10/18 16:42:33 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\David_Rudie
[2011/10/18 15:50:31 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\SoftTH
[2011/10/17 22:15:56 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\DeskSoft
[2011/10/17 22:12:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Almeza
[2011/10/17 22:12:23 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\Almeza
[2011/10/17 18:49:44 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\Ubisoft Game Launcher
[2011/10/17 18:43:45 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\Ubisoft
[2011/10/17 18:37:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ubisoft
[2011/10/17 18:36:31 | 000,000,000 | -H-D | C] -- C:\Users\W@Z@L\InstallAnywhere
[2011/10/16 16:15:06 | 000,000,000 | ---D | C] -- C:\Program Files\Computer Artworks
[2011/10/16 16:14:18 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Thing
[2011/10/16 16:14:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Computer Artworks
[2011/10/16 15:38:48 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\Eidos
[2011/10/16 15:21:28 | 000,000,000 | ---D | C] -- C:\Games
[2011/10/13 22:56:26 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/10/13 22:55:47 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/10/13 22:55:46 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/10/13 22:55:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/10/13 22:53:37 | 000,000,000 | ---D | C] -- C:\Program Files\Bonjour
[2011/10/13 22:53:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bonjour
[2011/10/12 14:03:56 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Nitro PDF
[2011/10/12 13:53:27 | 000,028,992 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon.dll
[2011/10/12 13:53:27 | 000,017,216 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui.dll
[2011/10/12 13:53:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF
[2011/10/12 13:53:11 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF
[2011/10/12 13:53:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nitro PDF
[2011/10/12 13:53:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nitro PDF
[2011/10/12 13:52:19 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Downloaded Installations
[2011/10/07 06:35:21 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\SKIDROW
[2011/10/07 06:34:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bethesda Softworks
[2011/10/07 06:21:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Bethesda Softworks
[2011/10/06 08:11:13 | 000,000,000 | --SD | C] -- C:\Users\W@Z@L\Documents\Passwords Database
[2011/10/05 14:42:46 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\dvdcss
[2011/10/05 14:42:26 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\ Studio
[2011/10/05 14:42:26 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\ Studio
[2011/10/05 14:41:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\
[2011/10/05 14:41:53 | 000,000,000 | ---D | C] -- C:\ProgramData\ Studio
[2011/10/05 14:41:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ Studio
[2011/10/05 12:21:25 | 000,085,048 | ---- | C] (Infowatch) -- C:\Windows\SysNative\drivers\CSCrySec.sys
[2011/10/05 12:21:25 | 000,066,104 | ---- | C] (Infowatch) -- C:\Windows\SysNative\drivers\CSVirtualDiskDrv.sys
[2011/10/05 12:20:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab
[2011/10/05 09:49:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Safari
[2011/10/05 09:48:47 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Apple Computer
[2011/10/05 09:48:47 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\Apple Computer
[2011/10/05 09:48:23 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\DRVSTORE
[2011/10/05 09:47:57 | 000,000,000 | ---D | C] -- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2011/10/05 09:47:30 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2011/10/05 09:20:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple Computer
[2011/10/05 08:56:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Apple Software Update
[2011/10/05 02:06:13 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\Documents\CyberLink
[2011/10/05 02:04:50 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Cyberlink
[2011/10/05 02:04:48 | 000,000,000 | ---D | C] -- C:\ProgramData\CyberLink
[2011/10/05 01:44:57 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink WaveEditor
[2011/10/05 01:43:58 | 000,000,000 | ---D | C] -- C:\ProgramData\SmartSound Software Inc
[2011/10/05 01:43:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SmartSound Software
[2011/10/05 01:43:54 | 000,000,000 | ---D | C] -- C:\ProgramData\eSellerate
[2011/10/05 01:42:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Apple
[2011/10/05 01:41:56 | 000,000,000 | ---D | C] -- C:\Users\W@Z@L\AppData\Local\Apple
[2011/10/05 01:41:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Apple
[2011/10/05 01:41:35 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDirector
[2011/10/05 01:41:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Cyberlink
[2011/10/05 01:39:47 | 000,000,000 | ---D | C] -- C:\Program Files\CyberLink
[2011/10/05 01:39:15 | 000,000,000 | ---D | C] -- C:\ProgramData\CLSK
[2011/10/05 01:39:14 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/11/03 23:15:44 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\W@Z@L\Desktop\OTL.exe
[2011/11/03 22:56:19 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/03 22:56:19 | 000,021,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/03 22:48:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/03 22:48:30 | 3220,074,496 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/03 22:29:53 | 000,007,605 | ---- | M] () -- C:\Users\W@Z@L\AppData\Local\Resmon.ResmonCfg
[2011/11/03 22:29:09 | 000,001,808 | ---- | M] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/03 22:28:59 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 22:27:44 | 013,022,976 | ---- | M] (SUPERAntiSpyware.com) -- C:\Users\W@Z@L\Desktop\SUPERAntiSpyware.exe
[2011/11/03 22:27:33 | 009,852,544 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\W@Z@L\Desktop\mbam-setup-1.51.2.1300.exe
[2011/11/03 21:37:03 | 000,002,425 | ---- | M] () -- C:\Users\W@Z@L\Desktop\Reincarnations 3- Back to Reality Collectors Edition.lnk
[2011/11/03 20:19:48 | 366,962,000 | ---- | M] () -- C:\Users\W@Z@L\Desktop\Charlies.Angels.2011.S01E06.HDTV.XviD-ASAP.avi
[2011/11/03 20:08:38 | 182,962,176 | ---- | M] () -- C:\Users\W@Z@L\Desktop\ridiculousness.0109-yestv.avi
[2011/11/03 19:10:57 | 183,859,200 | ---- | M] () -- C:\Users\W@Z@L\Desktop\CelebriDate.S01E04.Dean.Cain.HDTV.XviD-PREMiER.avi
[2011/11/03 17:54:09 | 367,128,576 | ---- | M] () -- C:\Users\W@Z@L\Desktop\Kitchen.Nightmares.US.S05E07.WS.XviD-err0001.avi
[2011/11/03 17:45:21 | 183,562,240 | ---- | M] () -- C:\Users\W@Z@L\Desktop\long.island.medium.s01e08.theresa.explains.it.all.hdtv.xvid-crimson.avi
[2011/11/03 09:05:51 | 182,640,872 | ---- | M] () -- C:\Users\W@Z@L\Desktop\Auction.Kings.S02E21.Wacky.Taxi.HDTV.XviD-MOMENTUM.avi
[2011/11/02 21:34:07 | 576,767,162 | ---- | M] () -- C:\Users\W@Z@L\Desktop\james.mays.man.lab.s01e03.ws.pdtv.xvid-ftp.avi
[2011/11/02 21:08:11 | 576,755,712 | ---- | M] () -- C:\Users\W@Z@L\Desktop\James.Mays.Man.Lab.S01E02.WS.PDTV.XviD-BARGE.avi
[2011/11/02 21:01:33 | 575,969,280 | ---- | M] () -- C:\Users\W@Z@L\Desktop\James.Mays.Man.Lab.S01E01.WS.PDTV.XviD-FTP.avi
[2011/11/01 12:28:46 | 000,001,057 | ---- | M] () -- C:\Users\W@Z@L\AppData\Roaming\vso_ts_preview.xml
[2011/11/01 11:36:00 | 000,782,702 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/01 11:36:00 | 000,662,408 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/01 11:36:00 | 000,122,236 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/10/31 19:38:27 | 419,433,678 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2011/10/30 09:36:59 | 004,841,888 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/10/29 23:21:17 | 000,164,734 | ---- | M] () -- C:\Windows\hpoins29.dat
[2011/10/29 23:18:22 | 000,002,099 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/10/29 07:33:56 | 183,485,720 | ---- | M] () -- C:\Users\W@Z@L\Desktop\X-Men.2011.S01E02.HDTV.XviD-LMAO.avi
[2011/10/26 23:50:13 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3491092077-2592809933-3551427508-1000Core.job
[2011/10/26 18:34:56 | 000,001,945 | ---- | M] () -- C:\Windows\epplauncher.mif
[2011/10/26 18:31:17 | 000,796,360 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/10/15 03:53:00 | 000,068,928 | ---- | M] (Khronos Group) -- C:\Windows\SysNative\OpenCL.dll
[2011/10/15 03:53:00 | 000,061,248 | ---- | M] (Khronos Group) -- C:\Windows\SysWow64\OpenCL.dll
[2011/10/15 03:53:00 | 000,007,384 | ---- | M] () -- C:\Windows\SysNative\nvinfo.pb
[2011/10/13 22:58:41 | 000,002,515 | ---- | M] () -- C:\Users\W@Z@L\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/10/11 09:25:39 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/10 12:27:45 | 000,111,928 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2011/10/08 16:39:53 | 000,000,117 | ---- | M] () -- C:\Users\W@Z@L\Documents\Rage.cht
[2011/10/08 14:26:28 | 000,001,806 | ---- | M] () -- C:\Windows\TSearch.INI
[2011/10/05 14:41:58 | 000,002,223 | ---- | M] () -- C:\Users\W@Z@L\Application Data\Microsoft\Internet Explorer\Quick Launch\ DVD Ripper.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/11/03 22:29:09 | 000,001,808 | ---- | C] () -- C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2011/11/03 22:28:59 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 21:37:03 | 000,002,425 | ---- | C] () -- C:\Users\W@Z@L\Desktop\Reincarnations 3- Back to Reality Collectors Edition.lnk
[2011/11/03 20:12:14 | 366,962,000 | ---- | C] () -- C:\Users\W@Z@L\Desktop\Charlies.Angels.2011.S01E06.HDTV.XviD-ASAP.avi
[2011/11/03 20:03:05 | 182,962,176 | ---- | C] () -- C:\Users\W@Z@L\Desktop\ridiculousness.0109-yestv.avi
[2011/11/03 19:08:21 | 183,859,200 | ---- | C] () -- C:\Users\W@Z@L\Desktop\CelebriDate.S01E04.Dean.Cain.HDTV.XviD-PREMiER.avi
[2011/11/03 17:45:38 | 367,128,576 | ---- | C] () -- C:\Users\W@Z@L\Desktop\Kitchen.Nightmares.US.S05E07.WS.XviD-err0001.avi
[2011/11/03 17:45:20 | 183,562,240 | ---- | C] () -- C:\Users\W@Z@L\Desktop\long.island.medium.s01e08.theresa.explains.it.all.hdtv.xvid-crimson.avi
[2011/11/03 09:02:45 | 182,640,872 | ---- | C] () -- C:\Users\W@Z@L\Desktop\Auction.Kings.S02E21.Wacky.Taxi.HDTV.XviD-MOMENTUM.avi
[2011/11/02 21:12:11 | 576,767,162 | ---- | C] () -- C:\Users\W@Z@L\Desktop\james.mays.man.lab.s01e03.ws.pdtv.xvid-ftp.avi
[2011/11/02 21:02:42 | 576,755,712 | ---- | C] () -- C:\Users\W@Z@L\Desktop\James.Mays.Man.Lab.S01E02.WS.PDTV.XviD-BARGE.avi
[2011/11/02 20:49:36 | 575,969,280 | ---- | C] () -- C:\Users\W@Z@L\Desktop\James.Mays.Man.Lab.S01E01.WS.PDTV.XviD-FTP.avi
[2011/11/01 11:03:21 | 000,001,057 | ---- | C] () -- C:\Users\W@Z@L\AppData\Roaming\vso_ts_preview.xml
[2011/10/29 23:18:44 | 000,001,058 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk
[2011/10/29 23:18:22 | 000,002,099 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
[2011/10/29 23:15:18 | 000,164,734 | ---- | C] () -- C:\Windows\hpoins29.dat
[2011/10/29 23:15:17 | 000,000,457 | ---- | C] () -- C:\Windows\hpomdl29.dat
[2011/10/29 19:52:56 | 000,007,384 | ---- | C] () -- C:\Windows\SysNative\nvinfo.pb
[2011/10/29 16:44:27 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/10/29 16:44:27 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/10/29 16:44:27 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/10/29 16:44:27 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/10/29 16:44:27 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/10/29 07:30:42 | 183,485,720 | ---- | C] () -- C:\Users\W@Z@L\Desktop\X-Men.2011.S01E02.HDTV.XviD-LMAO.avi
[2011/10/26 23:50:13 | 000,000,906 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-3491092077-2592809933-3551427508-1000Core.job
[2011/10/26 18:34:56 | 000,001,945 | ---- | C] () -- C:\Windows\epplauncher.mif
[2011/10/26 18:31:09 | 000,001,897 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2011/10/23 04:49:38 | 000,000,922 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Payday The Heist.lnk
[2011/10/12 13:53:19 | 000,002,553 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro PDF Professional.lnk
[2011/10/07 18:07:38 | 000,000,117 | ---- | C] () -- C:\Users\W@Z@L\Documents\Rage.cht
[2011/10/07 07:29:04 | 000,001,806 | ---- | C] () -- C:\Windows\TSearch.INI
[2011/10/05 14:41:58 | 000,002,223 | ---- | C] () -- C:\Users\W@Z@L\Application Data\Microsoft\Internet Explorer\Quick Launch\ DVD Ripper.lnk
[2011/10/05 09:49:25 | 000,002,515 | ---- | C] () -- C:\Users\W@Z@L\Application Data\Microsoft\Internet Explorer\Quick Launch\Apple Safari.lnk
[2011/10/05 09:49:25 | 000,002,503 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2011/10/05 01:41:54 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2011/10/03 15:58:22 | 000,000,531 | ---- | C] () -- C:\Windows\eReg.dat
[2011/10/02 07:33:12 | 000,000,126 | ---- | C] () -- C:\Users\W@Z@L\AppData\Roaming\Earthquakes Meter_Settings.ini
[2011/09/28 01:59:34 | 000,111,928 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/09/28 01:59:29 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/09/25 06:24:42 | 000,007,605 | ---- | C] () -- C:\Users\W@Z@L\AppData\Local\Resmon.ResmonCfg
[2011/09/21 14:26:25 | 000,796,360 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/21 01:41:53 | 000,000,097 | RHS- | C] () -- C:\ProgramData\1.12.0.lic
[2011/09/18 02:51:50 | 000,050,536 | ---- | C] () -- C:\Windows\UTP.exe
[2011/09/17 23:25:50 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2011/08/03 03:31:54 | 000,311,912 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2009/09/16 17:27:58 | 000,508,224 | ---- | C] () -- C:\Windows\SysWow64\ICCProfiles.dll
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
========== LOP Check ==========
[2011/09/25 06:55:42 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\AnvSoft
[2011/09/18 15:13:26 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Ashampoo
[2011/10/02 17:38:19 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Babylon
[2011/09/25 05:09:56 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\com.adobe.dmp.contentviewer
[2011/09/25 00:45:30 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\com.adobe.WidgetBrowser.E7BED6E5DDA59983786DD72EBFA46B1598278E07.1
[2011/10/19 02:26:13 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\DeskSoft
[2011/10/04 16:35:27 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\DisneyInteractiveStudios
[2011/10/05 10:41:07 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\DisplayFusion
[2011/10/12 13:52:19 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Downloaded Installations
[2011/11/03 21:46:29 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Enki Games
[2011/09/22 05:04:38 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\HdO Adventure
[2011/09/18 00:30:47 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\LolClient
[2011/10/12 14:03:56 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Nitro PDF
[2011/09/28 01:08:55 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Origin
[2011/10/21 07:58:46 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Panda Security
[2011/09/28 07:39:31 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Reviversoft
[2011/09/17 20:51:52 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\RocketDock Backup
[2011/10/22 19:36:48 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Sahmon Games
[2011/10/29 08:59:24 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\SmartPCTools
[2011/11/03 20:05:04 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\TeamViewer
[2011/09/28 07:29:04 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Thinstall
[2011/10/20 14:05:26 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Trillian
[2011/11/03 22:50:34 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\uTorrent
[2011/11/01 12:28:47 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Vso
[2011/10/04 12:33:07 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\WCMShare
[2011/10/04 08:00:02 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\WebcamMax
[2011/09/17 20:35:13 | 000,000,000 | ---D | M] -- C:\Users\W@Z@L\AppData\Roaming\Windows SideBar
[2011/10/26 23:50:13 | 000,000,906 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3491092077-2592809933-3551427508-1000Core.job
[2009/07/14 00:08:49 | 000,026,260 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 192 bytes -> C:\Windows:nlsPreferences
@Alternate Data Stream - 151 bytes -> C:\ProgramData\Temp:ECF54A0E
< End of report >