Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan.FakeAlert : wyWFqiPoNAGy.exe


  • Please log in to reply

#1
Magicless

Magicless

    Member

  • Member
  • PipPip
  • 12 posts
My OS:
Win7 Home Premium SP1

My computer:
Acer Aspire M3920
Intel Core i7-2600 CPU @ 3.40\GHz
RAM: 6GB
64-bit operating system

Hiya,

What happened to me is basically described in this topic: System Restore window "PC Performance & Stability analysis rep Which, for the ease of the reader, I will shamelessly copy paste :) I am running FF 3.6.23 (mostly because the changes that happened to FF 4 were horrid).

I clicked on a bad link while browsing using Firefox7.0.1 and started to get a number of "Windows Delayed Write Failed"pop-up alerts saying like "Failed to save all the components for the file \\Systems32100001366. The file is corrupted or unreadable. This error maybe caused by PC hardware problem" and with choice buttons of Cancel - Try Again - Continue.
-- where the systems32 file (\\Systems32100001366 on my sample pop-up message) changes on each of the pop-up alerts.

I tried to close all the pop-up alerts and then I got the "System Restore" window with "PC Performance & Stability analysis report" header which lists all the possible damaged files and systems on my machine. I think I clicked on a "Resolve" or "Restore" or "Fix" button. Once I clicked the button, the System Restore starts scanning and indicated a couple of errors that were fixed and I got this error report:
- Hard drive rotational speed decreasedd by 20%
- Drive C initializing error
- Disk drive c:\ is unreadable
- System files are damaged. System is unstable
- GPU RAM temperature is critically high. Urgent RAM memory optimization...
- The problem may cause errors while loading your operating system
- RAM memory speed decreased significantly and may cause a system...

And then at there's 2 links at the end of the "System Restore" window
- Click here to activate full-functional version
- Continue with limited resolutions

I clicked on the second option, but the window didn't go away. So I clicked on the other link, which of course goes to this secured system-restore dot com page (i can't place the link here cause it might cause also cause you trouble). I ignored the form, did not buy their product. And my laptop restarted.

Took a while for the laptop to restart and when it did, my desktop files and folders were gone. And then I got the "System Restore" window again. And also got the "Files indexation process failed" window on top of that.

The Files indexation process failed window got this message --
"Indexation process failure may cause:
- File may became unreadable
- Files and documents can be lost
- Operation System may slow down dramatically
To prevent possible damage to this PC follow the recommendations.
Recommendations:
It's highly recommended to run integrity checker now and resolve this issue."
-- and a "Resolve this issue" button after the above message.

I'm not clicking any buttons and link because it may further damage my laptop. So those 2 windows are still on my desktop, Obviously, I can still work on my machine, but with these 2 windows on top of everything, so I can just work on a minimized browser and applications.

And from time to time, those "Windows Delayed Write Failed"pop-up alerts goes up. So I have to close them one by one each time.

What I have done so far:

- I used Micro housecall to scan and clean my computer of viruses.(there was just the trojan that I'd picked up last night while looking for a picture)
- I used Malwarebytes' Anti-Malware having started my computer in safe mode with networking ability (however I cannot access the internet using that so have to reboot into normal mode to do anything online) I spent several hours running this, removing *anything* it told me to, rebooting back into safe mode with networking ability and running it again till it came up clean. I did both a quick scan and the full scan just to be safe. (Found out about this from another topic here - but carefully didn't use any of the OTL fixes offered as you clearly say not to)

Log 1 of stuff found/ removed:

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wyWFqiPoNAGy.exe (Trojan.FakeAlert) -> Value: wyWFqiPoNAGy.exe -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\programdata\wywfqiponagy.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\programdata\6dss92c31apgjk.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Log 2 of stuff found/removed:

Files Infected:
c:\Users\Magical\AppData\LocalLow\Sun\Java\deployment\cache\6.0\40\39a696a8-3372324a (Trojan.Inject.adb) -> Quarantined and deleted successfully.
f:\documents and settings\Magical\mijn documenten\evid4226patch.exe (Malware.Tool) -> Quarantined and deleted successfully.
f:\program files\erightsoft\SUPER\00IM.exe (Adware.Agent) -> Quarantined and deleted successfully.

What I did not do:
- Install new firewall/antivirus as it seemed better to wait with this till the computer is sorted out, I'm not browsing the net to go anywhere but this forum for now till I know everything is back to normal so there is no risk of picking up something new.

Right now my computer is still very unhappy
- The start menu is completely empty apart from the Malwarebytes' Anti-Malware if I click on "all programmes" and computer in the side bar of the menu.
- All my personal files etc. are missing
- Catalyst Control Center has given me two popups saying "Catalyst Control Center: Host application has stopped working" - I only moved them out of my way - there is no way I'm going to click on them after what happened earlier.
- The computers sound level is above normal, cycling up and running as if I'm putting a heavy load on it for a while, then slowing down and sounding normal, it spends more time in the non-normal state than it does in the normal state.

OTL Logs:

OTL logfile created on: 11/4/2011 9:18:59 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 4.13 Gb Available Physical Memory | 69.01% Memory free
11.96 Gb Paging File | 9.92 Gb Available in Paging File | 82.90% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 885.58 Gb Free Space | 95.95% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 261.57 Gb Free Space | 53.56% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 153.22 Gb Free Space | 78.45% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 217.78 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive K: | 249.91 Mb Total Space | 169.34 Mb Free Space | 67.76% Space Free | Partition Type: FAT
Drive M: | 434.57 Gb Total Space | 98.27 Gb Free Space | 22.61% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/04 09:18:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Magical\Downloads\OTL.com
PRC - [2011/10/28 19:35:26 | 002,152,152 | -H-- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/10/28 19:35:26 | 001,187,072 | -H-- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/09/28 09:32:23 | 000,912,344 | -H-- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | -H-- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2010/12/03 07:00:42 | 000,618,600 | -H-- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/10/05 14:08:46 | 002,655,768 | -H-- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/10/05 14:08:42 | 000,325,656 | -H-- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | -H-- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | -H-- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/09/14 02:32:32 | 000,013,336 | -H-- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/14 02:32:30 | 000,283,160 | -H-- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/06/01 09:17:48 | 005,252,408 | -H-- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/05/27 03:41:24 | 000,349,552 | -H-- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010/03/11 06:11:56 | 000,407,920 | -H-- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010/03/11 06:11:42 | 000,201,584 | -H-- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/01/29 00:27:36 | 000,243,232 | -H-- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | -H-- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/08/11 12:57:26 | 000,303,104 | -H-- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
PRC - [2009/07/14 02:14:28 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\PING.EXE
PRC - [2009/05/01 12:54:46 | 000,082,600 | -H-- | M] (Lexmark International Inc.) -- C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | -H-- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/01/01 22:22:02 | 003,739,648 | -H-- | M] (Google) -- C:\Program Files (x86)\Google\Google Talk\googletalk.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/03 20:00:31 | 000,475,136 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll
MOD - [2011/11/03 20:00:31 | 000,014,336 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll
MOD - [2011/11/03 18:53:23 | 000,771,584 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/11/03 18:52:54 | 012,433,408 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/11/03 18:52:46 | 001,587,200 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/11/03 18:52:30 | 003,347,968 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/11/03 18:52:25 | 005,453,312 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/11/03 18:52:21 | 000,971,264 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/11/03 18:52:20 | 007,963,648 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/11/03 18:51:31 | 011,490,304 | -H-- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/09/28 09:32:23 | 001,015,256 | -H-- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2011/08/28 04:48:57 | 006,277,280 | -H-- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010/12/03 07:00:42 | 000,618,600 | -H-- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/12/03 04:44:54 | 000,151,656 | -H-- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
MOD - [2010/11/20 13:19:56 | 000,232,448 | ---- | M] () -- \\.\globalroot\systemroot\syswow64\mswsock.dll
MOD - [2010/06/01 09:17:46 | 000,929,792 | -H-- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2009/08/11 12:57:26 | 000,303,104 | -H-- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
MOD - [2009/08/11 12:56:52 | 000,053,248 | -H-- | M] () -- C:\Program Files (x86)\MultiScreen\MGResEng.dll
MOD - [2009/08/11 12:54:36 | 000,053,248 | -H-- | M] () -- C:\Program Files (x86)\MultiScreen\SmartMouseDll.dll
MOD - [2009/08/11 12:54:28 | 000,094,208 | -H-- | M] () -- C:\Program Files (x86)\MultiScreen\TitleBar.dll
MOD - [2006/05/25 15:20:44 | 000,241,664 | -H-- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\iptk.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/01/10 10:03:43 | 000,203,776 | -H-- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | -H-- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/29 00:27:36 | 000,243,232 | -H-- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/10/28 19:35:26 | 002,152,152 | -H-- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 11:55:28 | 000,064,952 | -H-- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/20 13:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010/10/05 14:08:46 | 002,655,768 | -H-- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/10/05 14:08:42 | 000,325,656 | -H-- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/09/14 04:45:56 | 000,219,496 | -H-- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010/09/14 04:45:44 | 000,508,264 | -H-- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010/09/14 02:32:32 | 000,013,336 | -H-- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/05/27 03:41:06 | 000,305,520 | -H-- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | -H-- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/08 14:21:22 | 000,023,584 | -H-- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | -H-- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/10/28 19:35:28 | 000,069,376 | -H-- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | -H-- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | -H-- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/01/15 17:21:04 | 000,036,352 | -H-- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2011/01/10 10:31:20 | 008,283,136 | -H-- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/01/10 09:28:18 | 000,295,424 | -H-- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/21 09:31:00 | 000,316,080 | -H-- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010/12/16 23:58:14 | 000,040,816 | -H-- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | -H-- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/17 13:04:32 | 000,115,216 | -H-- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | -H-- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/09/14 04:45:52 | 000,022,376 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010/09/14 04:45:50 | 000,025,960 | -H-- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010/09/14 04:45:48 | 000,268,648 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010/09/14 04:45:44 | 000,760,168 | -H-- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010/09/14 02:24:26 | 000,437,272 | -H-- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/08/11 04:40:06 | 001,014,624 | -H-- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | -H-- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | -H-- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | -H-- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | -H-- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | -H-- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/03 03:15:30 | 000,060,464 | -H-- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/03 03:15:30 | 000,022,576 | -H-- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/03 03:15:30 | 000,020,016 | -H-- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2011/11/03 19:40:49 | 000,017,152 | -H-- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:4.0.2
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.12
FF - prefs.js..extensions.enabledItems: {b442f4c0-c292-4998-aabe-48608a73ba75}:1.0.1.3
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:9
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.4.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.3.50136
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: tabcounter@morac:1.8.8
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {7d575baa-b543-11dc-8314-0800200c9a66}:2.0.5
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.6


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/16 21:03:12 | 000,000,000 | -H-D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/28 09:32:23 | 000,000,000 | -H-D | M]

[2011/05/01 18:09:35 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Extensions
[2011/11/03 23:24:47 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions
[2011/05/02 12:16:00 | 000,000,000 | -H-D | M] (Screengrab) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/05/02 12:15:59 | 000,000,000 | -H-D | M] (Image Zoom) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2011/09/13 12:21:34 | 000,000,000 | -H-D | M] (RSS Ticker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
[2011/08/26 08:18:32 | 000,000,000 | -H-D | M] (Integrated Gmail) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2011/06/16 01:41:34 | 000,000,000 | -H-D | M] (Favicon Picker 2) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
[2011/06/06 01:55:11 | 000,000,000 | -H-D | M] (ChatZilla) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2011/05/02 12:16:00 | 000,000,000 | -H-D | M] (BitmeTV Menu) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{633b7287-e788-4131-a31c-db09d8ebbe51}(2)
[2011/05/02 12:16:00 | 000,000,000 | -H-D | M] (DNS Flusher) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{7d575baa-b543-11dc-8314-0800200c9a66}
[2011/08/31 21:54:04 | 000,000,000 | -H-D | M] (Showcase) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2011/08/26 13:00:38 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2011/05/01 21:32:21 | 000,000,000 | -H-D | M] (Smartest Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{b442f4c0-c292-4998-aabe-48608a73ba75}
[2011/10/01 01:21:40 | 000,000,000 | -H-D | M] (Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/10/16 21:04:20 | 000,000,000 | -H-D | M] (Greasemonkey) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/05/02 12:16:00 | 000,000,000 | -H-D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011/10/01 01:21:41 | 000,000,000 | -H-D | M] (Add-on Compatibility Reporter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:15:57 | 000,000,000 | -H-D | M] (DNS Cache) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/10/01 01:21:40 | 000,000,000 | -H-D | M] (Element Hiding Helper for Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:15 | 000,000,000 | -H-D | M] (British English Dictionary) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/25 20:57:40 | 000,000,000 | -H-D | M] ("Xmarks") -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/13 12:21:34 | 000,000,000 | -H-D | M] (Webmail Ad Blocker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/19 01:13:54 | 000,000,000 | -H-D | M] (Cooliris) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/19 01:13:54 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:16 | 000,000,000 | -H-D | M] (Smart Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:17 | 000,000,000 | -H-D | M] (Tab Counter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\tabcounter@morac
[2011/10/01 01:21:41 | 000,000,000 | -H-D | M] (BlackFox V1-Blue) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/26 13:00:44 | 000,000,000 | -H-D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/11/01 10:08:47 | 000,001,032 | -H-- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\exigo.xml
[2010/04/30 18:04:17 | 000,001,504 | -H-- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\imdb.xml
[2010/04/24 17:18:48 | 000,002,352 | -H-- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\search-firefox-addons.xml
[2010/05/25 00:38:29 | 000,004,140 | -H-- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\youtube.xml
[2011/11/03 23:24:47 | 000,000,000 | -H-D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/01 20:50:24 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/09/28 09:35:16 | 000,000,000 | -H-D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/05/04 03:52:23 | 000,476,904 | -H-- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/04/21 00:07:17 | 000,001,538 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/21 00:07:17 | 000,000,947 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/21 00:07:17 | 000,000,769 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/04/21 00:07:17 | 000,001,135 | -H-- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

Hosts file not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [LXCYCATS] C:\Windows\SysNative\spool\DRIVERS\x64\3\LXCYtime.DLL (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [lxcymon.exe] C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe ()
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MultiScreen] C:\Program Files (x86)\MultiScreen\MultiScreen.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O29:64bit: - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/22 11:24:38 | 000,000,000 | -H-- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{82808511-a0b8-11e0-9341-f80f410c79fa}\Shell - "" = AutoRun
O33 - MountPoints2\{82808511-a0b8-11e0-9341-f80f410c79fa}\Shell\AutoRun\command - "" = G:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/04 08:34:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A48E29C5-8D30-46E1-B3DD-A4ACBB35EE02}
[2011/11/04 08:33:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CBBD8B9-07D0-4110-B258-D84D562E514F}
[2011/11/03 23:33:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Roaming\Malwarebytes
[2011/11/03 23:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 23:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/03 23:32:42 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/03 23:32:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/03 19:32:52 | 000,069,376 | -H-- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2011/11/03 19:32:44 | 000,000,000 | -H-D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/11/03 19:32:15 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/11/03 18:43:56 | 000,200,976 | -H-- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/11/03 18:06:53 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
[2011/11/03 18:04:15 | 000,000,000 | ---D | C] -- C:\Windows\system64
[2011/11/03 17:50:36 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D4C94249-A4BD-4B7D-887D-884E143AAD16}
[2011/11/03 05:49:54 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D63D7844-9801-42DD-ADE6-4831ED93C8D2}
[2011/11/02 17:49:12 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{87E3EBB1-7FF7-4901-99D7-4DAF46AAF9D3}
[2011/11/02 05:48:33 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{43EDBA0A-6DD0-4C23-B7E8-B1B0A86B9334}
[2011/11/01 17:47:55 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{EE36652D-BAFE-4F17-9AD5-3E4DF5765A31}
[2011/11/01 05:47:18 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{637D5548-7DE6-49B0-8549-1D983001FA07}
[2011/10/31 17:46:40 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{F784FAAE-CC16-49BD-947A-884C8279F464}
[2011/10/31 11:18:29 | 000,000,000 | -H-D | C] -- C:\Users\Magical\Documents\Stuff that used to be in dropbox
[2011/10/31 05:46:02 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{92CBC907-2386-47DA-9958-63C7EFF57ED9}
[2011/10/30 17:45:25 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{35E733DD-0BA5-440F-BEC9-749E4867548A}
[2011/10/30 05:44:49 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{5CC4A491-409E-49DE-8278-786C38FA7BDC}
[2011/10/29 17:44:12 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{E6782204-61AC-493C-8AEE-B5AE825874DB}
[2011/10/29 05:43:37 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{3DC0B751-9BC6-48F2-BF39-B648D11D53A9}
[2011/10/28 17:43:01 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{0EB83299-8115-4D51-BAEE-DDCE4741254F}
[2011/10/28 05:42:27 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{F6424066-E600-4DB4-9273-8C01C900025C}
[2011/10/27 17:41:51 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{72A3BAC0-E766-4697-B006-B74608057CE6}
[2011/10/27 05:41:10 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{FEC61A44-90AF-4347-AB20-B68D9194669F}
[2011/10/26 17:40:35 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{B0B050C5-5F13-4BAD-A334-9AE589773182}
[2011/10/26 05:40:03 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{356B0CFB-26EC-426E-BAA3-CE05C2C1E2D8}
[2011/10/25 17:39:32 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{359FCEBE-7990-4F97-8198-6428C2F088D8}
[2011/10/25 05:39:00 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{3423A6EF-E8A0-4978-BDF1-A6F60AC59B71}
[2011/10/24 17:38:30 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{C4A081CD-94AF-4B21-B42F-5497DE775F41}
[2011/10/24 09:28:37 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\Microsoft Games
[2011/10/24 05:38:00 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{1B2D8A7F-970E-4E8D-AF8B-A9C01CBE25A5}
[2011/10/23 17:37:31 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{057FD8D5-C992-49A9-8440-32AE88F0147D}
[2011/10/23 05:37:02 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{74AB5993-50A0-4A03-B589-BBAB27058FAA}
[2011/10/22 17:36:34 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{EF1C193A-AA47-4766-858B-451EE4B2264B}
[2011/10/22 05:36:05 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{C2455C65-BAA2-4CDE-AB5C-564F2B642691}
[2011/10/21 17:35:38 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{B4811046-0A7C-4EB3-AE30-71FDF60F6D3A}
[2011/10/21 05:35:10 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{AB1B270B-9B8F-4DFB-AA09-EFD20202A95F}
[2011/10/20 17:34:42 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{96729716-95F0-4756-B7F6-733504C3DB04}
[2011/10/20 05:34:15 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{E18A4DE2-43C9-4E85-A2F7-B9958155721C}
[2011/10/19 17:33:48 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{914C5AF3-7A88-4746-827F-D8796D7416B3}
[2011/10/19 05:33:22 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{5B50832A-E4C7-4B3A-A7C3-6E89EB1C6274}
[2011/10/18 17:32:56 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{A6BB88B6-104F-415F-8CCD-DC9481BBF595}
[2011/10/18 05:32:29 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{EFEB572C-D1D9-4530-8431-CA99C5A2B1BA}
[2011/10/17 17:32:03 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{3F7D4546-3096-44C8-95F8-66A13E36889A}
[2011/10/17 05:31:38 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{F04A283D-3DF0-4E47-97F6-B0F60FF22E74}
[2011/10/16 17:31:13 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{C77AB15E-D2D2-4D01-AAF2-DAE89EDF0681}
[2011/10/16 17:31:01 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D32288D7-0AD4-46B7-951E-68DF21812BC2}
[2011/10/16 05:30:36 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{49224AAA-B72B-48D4-AE4D-0E96E06D77E2}
[2011/10/16 05:30:24 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{9B2182A1-7784-4409-B137-583188119E0A}
[2011/10/15 17:30:11 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{12170724-B536-47A0-9536-1D73EE3EC65F}
[2011/10/15 17:29:58 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{41CE4D19-B15E-4373-A390-12C55057950E}
[2011/10/15 05:29:44 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{9AEFF161-36B8-48F0-B59D-4E1EFC764BA3}
[2011/10/15 05:29:33 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{71C7E389-A36B-4DB6-BF3B-BF4F172E8B45}
[2011/10/14 17:29:19 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{C5857948-6208-4D04-A183-16EA4B94E248}
[2011/10/14 17:29:08 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{15AF7EB9-E426-4F55-AC62-471E12838F1C}
[2011/10/14 05:28:54 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{74E29617-D529-4D3B-BDC4-E70078294605}
[2011/10/14 05:28:43 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{7FB1650C-7722-4E51-9422-0F809C002631}
[2011/10/13 17:28:30 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{79B49105-364E-4824-9B35-8CD2544A0E5D}
[2011/10/13 17:28:18 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{E9EA43A9-B45F-4857-A27B-9461F3ABBA75}
[2011/10/13 05:28:05 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{B4F7B2F1-8E62-45A4-83AF-3C9386A96FA0}
[2011/10/13 05:27:54 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{AC2C66DF-C97F-4810-8CE5-91052FB079DB}
[2011/10/12 17:27:40 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{7F16F78E-F53D-4015-A913-CAE75C349B20}
[2011/10/12 17:27:29 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D9EE5708-1E40-4763-983A-BE05C43E4F0E}
[2011/10/12 05:27:16 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{A9161CE8-0324-47C7-8821-4A20A3F34C92}
[2011/10/12 05:27:05 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{99D0AE6F-359B-4118-919D-FF95612EB0D7}
[2011/10/11 17:26:52 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D6294A31-0536-42BA-8386-2D389D2F4592}
[2011/10/11 17:26:41 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{CC10FF82-BAEF-44B9-AEF7-CCCA3F22F520}
[2011/10/11 05:26:28 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{D252F5D3-437A-4786-9D3E-97C9976296CB}
[2011/10/11 05:26:16 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{35AE3E6C-147D-468B-BC8D-BAE4A07200C5}
[2011/10/10 17:26:02 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{15BA36FC-E267-4315-B6D8-4B67C074CD16}
[2011/10/10 17:25:50 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{B58A9741-8E1C-4B81-AEA2-A31F6006089C}
[2011/10/10 05:25:37 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{F2C5BD47-335D-4F21-9AEC-03EA3E9F328D}
[2011/10/10 05:25:25 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{02D9E395-17AD-4759-973F-1BD34112D35E}
[2011/10/09 17:25:12 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{98F81106-B978-4FC7-9DD6-EAC4020886A1}
[2011/10/09 17:25:01 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{287F8A1C-4988-4995-90B2-FDBFC2E3BB2B}
[2011/10/09 05:24:48 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{A12E1A15-2B35-4E2D-9025-97204EF4D04C}
[2011/10/09 05:24:37 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{A0AC5230-54F9-4250-AB18-9374D4849C29}
[2011/10/08 17:24:24 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{98C66D56-39E5-422A-A0CD-F45B41B07044}
[2011/10/08 17:24:12 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{3EEA039C-8C67-41CD-95CA-1EA7E2D6C516}
[2011/10/08 05:23:59 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{07952418-5AD2-48D0-A445-9B5A570DA4C4}
[2011/10/08 05:23:48 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{1D1C6212-0364-431C-AB4E-CFE5D9A32F5C}
[2011/10/07 17:23:35 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{4189085C-5F8B-453E-A979-3250D8F99B4D}
[2011/10/07 17:23:24 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{EB1F7C68-BF26-49FC-A5DF-49D5C7553349}
[2011/10/07 05:23:11 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{CF6D2F6B-B80D-4040-93C3-602CD109337C}
[2011/10/07 05:23:00 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{857B2201-BB20-44B7-8823-0DEA85701A4A}
[2011/10/06 17:22:47 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{A8F44B56-8077-44AB-B26B-8B5547A3FD3C}
[2011/10/06 17:22:36 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{0EBB3F86-BD15-4173-963C-26BF96FE36A1}
[2011/10/06 05:22:23 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{E2145067-BF04-4B7B-9EF8-E6C8D9720B85}
[2011/10/06 05:22:12 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{FED5C3EF-701E-44DC-BC02-5DB2920A4793}
[2011/10/05 17:21:58 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{5EF3E427-51BD-4907-ADAC-E239CE47C106}
[2011/10/05 17:21:47 | 000,000,000 | -H-D | C] -- C:\Users\Magical\AppData\Local\{90F5F4BF-92C6-4898-A666-F1081F04B2AA}
[2011/06/27 10:56:06 | 000,305,152 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyhcp.dll
[2011/05/30 09:33:55 | 001,417,728 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyserv.dll
[2011/05/30 09:33:55 | 001,099,264 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyusb1.dll
[2011/05/30 09:33:55 | 000,695,808 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcycomc.dll
[2011/05/30 09:33:55 | 000,659,456 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyhbn3.dll
[2011/05/30 09:33:55 | 000,566,192 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcycoms.exe
[2011/05/30 09:33:55 | 000,487,424 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcylmpm.dll
[2011/05/30 09:33:55 | 000,409,600 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcypmui.dll
[2011/05/30 09:33:55 | 000,249,856 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcycomm.dll
[2011/05/30 09:33:55 | 000,238,592 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyinpa.dll
[2011/05/30 09:33:55 | 000,235,952 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcycfg.exe
[2011/05/30 09:33:55 | 000,233,392 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyih.exe
[2011/05/30 09:33:55 | 000,226,816 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyiesc.dll
[2011/05/30 09:33:55 | 000,181,168 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyppls.exe
[2011/05/30 09:33:55 | 000,035,328 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcyprox.dll
[2011/05/30 09:33:55 | 000,010,752 | -H-- | C] ( ) -- C:\Windows\SysWow64\lxcypplc.dll
[2011/05/27 23:06:47 | 000,270,128 | -H-- | C] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/04 09:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At20.job
[2011/11/04 09:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At19.job
[2011/11/04 09:22:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 09:22:55 | 000,009,920 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/04 08:32:57 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/04 08:32:55 | 523,116,543 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/03 23:32:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 23:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At48.job
[2011/11/03 23:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At47.job
[2011/11/03 23:16:51 | 000,727,182 | -H-- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/03 23:16:51 | 000,616,356 | -H-- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/03 23:16:51 | 000,106,478 | -H-- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/03 23:07:21 | 004,285,928 | -H-- | M] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 23:03:23 | 000,066,464 | -H-- | M] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 22:29:02 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At46.job
[2011/11/03 22:29:02 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At45.job
[2011/11/03 21:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At44.job
[2011/11/03 21:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At43.job
[2011/11/03 20:29:14 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At42.job
[2011/11/03 20:29:03 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At41.job
[2011/11/03 19:40:48 | 000,016,432 | -H-- | M] () -- C:\Windows\SysNative\lsdelete.exe
[2011/11/03 19:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At40.job
[2011/11/03 19:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At39.job
[2011/11/03 18:50:47 | 000,274,552 | -H-- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At8.job
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At6.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At9.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At7.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At5.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At4.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At38.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At36.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At34.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At32.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At30.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At28.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At26.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At24.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At22.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At2.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At37.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At35.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At33.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At31.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At3.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At29.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At27.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At25.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At23.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At21.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At18.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At16.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At14.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At12.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At10.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At17.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At15.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At13.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At11.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At1.job
[2011/11/03 18:44:38 | 000,000,118 | -H-- | M] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | -H-- | M] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011/11/03 18:34:02 | 000,000,112 | -H-- | M] () -- C:\ProgramData\ljRkx05F5.dat
[2011/11/03 18:11:55 | 000,000,456 | -H-- | M] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,296 | -H-- | M] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,192 | -H-- | M] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/11/03 18:06:54 | 000,000,685 | -H-- | M] () -- C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/03 18:06:54 | 000,000,661 | -H-- | M] () -- C:\Users\Magical\Desktop\System Restore.lnk
[2011/11/03 12:17:41 | 000,000,064 | -H-- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/11/03 12:17:41 | 000,000,044 | -H-- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/10/28 19:35:28 | 000,069,376 | -H-- | M] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/03 23:32:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 21:04:28 | 000,016,432 | -H-- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2011/11/03 18:47:29 | 004,285,928 | -H-- | C] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 18:47:25 | 000,066,464 | -H-- | C] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 18:44:38 | 000,000,118 | -H-- | C] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | -H-- | C] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011/11/03 18:31:47 | 000,000,112 | -H-- | C] () -- C:\ProgramData\ljRkx05F5.dat
[2011/11/03 18:31:35 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At48.job
[2011/11/03 18:31:35 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At47.job
[2011/11/03 18:31:34 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At46.job
[2011/11/03 18:31:34 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At44.job
[2011/11/03 18:31:34 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At45.job
[2011/11/03 18:31:33 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At42.job
[2011/11/03 18:31:33 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At40.job
[2011/11/03 18:31:33 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At38.job
[2011/11/03 18:31:33 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At36.job
[2011/11/03 18:31:33 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At43.job
[2011/11/03 18:31:33 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At41.job
[2011/11/03 18:31:33 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At39.job
[2011/11/03 18:31:33 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At37.job
[2011/11/03 18:31:33 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At35.job
[2011/11/03 18:31:32 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At34.job
[2011/11/03 18:31:32 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At32.job
[2011/11/03 18:31:32 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At30.job
[2011/11/03 18:31:32 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At33.job
[2011/11/03 18:31:32 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At31.job
[2011/11/03 18:31:31 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At28.job
[2011/11/03 18:31:31 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At26.job
[2011/11/03 18:31:31 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At29.job
[2011/11/03 18:31:31 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At27.job
[2011/11/03 18:31:30 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At25.job
[2011/11/03 18:31:29 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At24.job
[2011/11/03 18:31:29 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At22.job
[2011/11/03 18:31:29 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At23.job
[2011/11/03 18:31:28 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At20.job
[2011/11/03 18:31:28 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At18.job
[2011/11/03 18:31:28 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At21.job
[2011/11/03 18:31:28 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At19.job
[2011/11/03 18:31:27 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At16.job
[2011/11/03 18:31:27 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At14.job
[2011/11/03 18:31:27 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At17.job
[2011/11/03 18:31:27 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At15.job
[2011/11/03 18:31:27 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At13.job
[2011/11/03 18:31:26 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At12.job
[2011/11/03 18:31:26 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At10.job
[2011/11/03 18:31:26 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At9.job
[2011/11/03 18:31:26 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At11.job
[2011/11/03 18:31:25 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At8.job
[2011/11/03 18:31:25 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At6.job
[2011/11/03 18:31:25 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At7.job
[2011/11/03 18:31:25 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At5.job
[2011/11/03 18:31:24 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At4.job
[2011/11/03 18:31:24 | 000,000,352 | -H-- | C] () -- C:\Windows\tasks\At2.job
[2011/11/03 18:31:24 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At3.job
[2011/11/03 18:31:22 | 000,000,350 | -H-- | C] () -- C:\Windows\tasks\At1.job
[2011/11/03 18:06:56 | 000,000,192 | -H-- | C] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/11/03 18:06:55 | 000,000,296 | -H-- | C] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/11/03 18:06:54 | 000,000,685 | -H-- | C] () -- C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/03 18:06:54 | 000,000,661 | -H-- | C] () -- C:\Users\Magical\Desktop\System Restore.lnk
[2011/11/03 18:06:49 | 000,000,456 | -H-- | C] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/07/17 19:38:27 | 000,013,082 | -H-- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/07/17 19:38:20 | 004,022,504 | -H-- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe
[2011/07/17 19:38:20 | 000,018,123 | -H-- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/06/19 20:45:14 | 001,007,358 | -H-- | C] () -- C:\Program Files\Windows-Theme-Manager-Setup.exe
[2011/06/02 14:12:06 | 000,000,069 | -H-- | C] () -- C:\Windows\NeroDigital.ini
[2011/05/30 09:33:55 | 000,385,024 | -H-- | C] () -- C:\Windows\SysWow64\lxcycomx.dll
[2011/05/30 09:33:55 | 000,194,048 | -H-- | C] () -- C:\Windows\SysWow64\lxcyinst.dll
[2011/05/30 08:25:56 | 000,734,810 | -H-- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/02 21:28:30 | 000,007,609 | -H-- | C] () -- C:\Users\Magical\AppData\Local\resmon.resmoncfg
[2011/05/02 11:19:02 | 000,000,064 | -H-- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/05/02 11:19:02 | 000,000,044 | -H-- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/05/01 20:52:30 | 000,000,600 | -H-- | C] () -- C:\Users\Magical\AppData\Roaming\winscp.rnd
[2011/05/01 18:30:50 | 000,000,000 | -H-- | C] () -- C:\Windows\ativpsrm.bin
[2011/05/01 18:09:29 | 000,000,000 | -H-- | C] () -- C:\Windows\nsreg.dat
[2011/02/10 07:57:24 | 000,002,975 | -H-- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/10/27 12:08:21 | 000,131,984 | -H-- | C] () -- C:\ProgramData\FullRemove.exe
[2010/10/27 12:02:31 | 000,008,192 | -H-- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | -H-- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | -H-- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/02 12:33:43 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\acccore
[2011/09/05 21:21:33 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\dBpoweramp
[2011/11/03 18:10:18 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\Dropbox
[2011/11/03 00:05:08 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\foobar2000
[2011/05/02 12:27:31 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\Notepad++
[2011/05/01 15:51:51 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\OEM
[2011/11/03 18:07:29 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\SoftGrid Client
[2011/10/31 15:12:20 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\TeraCopy
[2011/06/19 20:47:46 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\ThemeManager
[2011/05/30 08:26:29 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\TP
[2011/11/04 08:34:40 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\uTorrent
[2011/07/31 04:35:25 | 000,000,000 | -H-D | M] -- C:\Users\Magical\AppData\Roaming\Windows Live Writer
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At1.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At10.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At11.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At12.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At13.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At14.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At15.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At16.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At17.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At18.job
[2011/11/04 09:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At19.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At2.job
[2011/11/04 09:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At20.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At21.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At22.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At23.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At24.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At25.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At26.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At27.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At28.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At29.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At3.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At30.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At31.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At32.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At33.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At34.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At35.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At36.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At37.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At38.job
[2011/11/03 19:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At39.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At4.job
[2011/11/03 19:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At40.job
[2011/11/03 20:29:03 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At41.job
[2011/11/03 20:29:14 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At42.job
[2011/11/03 21:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At43.job
[2011/11/03 21:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At44.job
[2011/11/03 22:29:02 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At45.job
[2011/11/03 22:29:02 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At46.job
[2011/11/03 23:29:00 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At47.job
[2011/11/03 23:29:00 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At48.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At5.job
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At6.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At7.job
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\Tasks\At8.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\Tasks\At9.job
[2009/07/14 06:08:49 | 000,010,722 | -H-- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:0B9176C0

< End of report >


Anyone who go tot he bottom of this massive post is a brave soul and deserves a medal - Thanks for looking, thanks for being here and I hope that there is a solution to this. Please let me know if there is anything I missed or anything additional that you need to know.

Magical -/- Magic

Edit: I decided to look and see what was using up so much of my computers resources and there appears to be a programme called PING.EXE *32 that is eating up 88% of my CPU at the times that my computer is being loud. I killed the process as it really isn't needed to have it on *all the time* but I have a feeling that it may need more other than that. I hope doing this wasn't "a bad thing"

Edit 2: It started itself back up again and is again using 88% of the resources - I'm going to leave it as is now as it was only off for about 2 minutes.

Edited by Magicless, 04 November 2011 - 03:58 AM.

  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
It looks like a combination of several different infections. The worst one is ZeroAccess but before we do anything let's look and see if you have a folder: %temp%\smtmp

This is probably c:\Users\Magical\AppData\Local\temp\smtmp

Copy the next line:

xcopy %Temp%\smtmp \Users\Magical\Desktop\lost /H /I /S /Y

Start, All Programs, Accessories then right click on Command Prompt and select Run as Admin.

right click and Paste or Edit Paste and the copied line should appear. Hit Enter.

(This should create an icon on your desktop called lost. Do not delete this as it contains all of your missing links.)

Now type with an Enter after each line:

cd  \windows\tasks

(prompt should change to show you are now in c:\windows\tasks )

del  /a  at*.job

(I use two spaces in the code box so you can see where 1 space goes)
(This removes all of the malware tasks that I see in your log.
Like these:
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At8.job
[2011/11/03 18:50:39 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At6.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At9.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At7.job
[2011/11/03 18:50:39 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At5.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At4.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At38.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At36.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At34.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At32.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At30.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At28.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At26.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At24.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At22.job
[2011/11/03 18:50:38 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At2.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At37.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At35.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At33.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At31.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At3.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At29.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At27.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At25.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At23.job
[2011/11/03 18:50:38 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At21.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At18.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At16.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At14.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At12.job
[2011/11/03 18:50:36 | 000,000,352 | -H-- | M] () -- C:\Windows\tasks\At10.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At17.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At15.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At13.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At11.job
[2011/11/03 18:50:36 | 000,000,350 | -H-- | M] () -- C:\Windows\tasks\At1.job )

Now let's work on ZeroAccess.


ComboFix

:!: It must be saved to your desktop, do not run it from your browser:!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix.

A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.


Download TDSSKiller:
http://support.kaspe.../tdsskiller.exe
Save it to your desktop then right click and Run as Administrator

If TDSSKiller alerts you that the system needs to reboot, please consent.
When done, a log file should be created on your C: drive named "TDSSKiller.txt" please copy and paste the contents in your next reply.


Download aswMBR.exe ( 511KB ) to your desktop.
Right click aswMBR.exe and Run as Administrator
Click the "Scan" button to start scan
On completion of the scan (Note if the Fix button is enabled (not the FixMBR button) and tell me) click save log, save it to your desktop and post in your next reply


Run OTL (Vista or Win 7 => right click and Run As Administrator)

select the All option in both the Standard and the Extra Registry groups then Run Scan.

You should get two logs. Please copy and paste both of them.

Ron
  • 0

#3
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hiya,

Thanks for your response :yes:

Yes I have the smtmp folder - it has 2 files in it that i can see.

I'd love to do this "Start, All Programs, Accessories then right click on Command Prompt and select Run as Admin." as you asked however I have a *slight* problem with that: there is only the malewarebytes app in the "all programmes" bit ( I believe I mentioned that I didn't have any programmes in that in my first post), however I already run the computer as administrator so I don't need to change that - still looking how to run the command prompt without it being available as an option

brb :)

--
ok windows + r did the trick :)

YAY got the lost folder :)

--
Sorry about the Dutch text in the combofix.txt - even though I actually have the English version installed it insists it reverting to Dutch at times.

02:31:59.0205 1404 TDSS rootkit removing tool 2.6.15.0 Nov 3 2011 17:15:49
02:31:59.0306 1404 ============================================================
02:31:59.0307 1404 Current date / time: 2011/11/05 02:31:59.0306
02:31:59.0307 1404 SystemInfo:
02:31:59.0307 1404
02:31:59.0307 1404 OS Version: 6.1.7601 ServicePack: 1.0
02:31:59.0307 1404 Product type: Workstation
02:31:59.0307 1404 ComputerName: BROOMSTICK
02:31:59.0307 1404 UserName: Magical
02:31:59.0307 1404 Windows directory: C:\Windows
02:31:59.0307 1404 System windows directory: C:\Windows
02:31:59.0307 1404 Running under WOW64
02:31:59.0307 1404 Processor architecture: Intel x64
02:31:59.0307 1404 Number of processors: 8
02:31:59.0307 1404 Page size: 0x1000
02:31:59.0307 1404 Boot type: Normal boot
02:31:59.0307 1404 ============================================================
02:32:00.0457 1404 Initialize success
02:32:05.0467 4344 ============================================================
02:32:05.0467 4344 Scan started
02:32:05.0467 4344 Mode: Manual;
02:32:05.0467 4344 ============================================================
02:32:06.0230 4344 1394ohci - ok
02:32:06.0233 4344 ACPI - ok
02:32:06.0238 4344 AcpiPmi - ok
02:32:06.0268 4344 adp94xx - ok
02:32:06.0274 4344 adpahci - ok
02:32:06.0280 4344 adpu320 - ok
02:32:06.0292 4344 AFD - ok
02:32:06.0298 4344 agp440 - ok
02:32:06.0307 4344 aliide - ok
02:32:06.0323 4344 amdide - ok
02:32:06.0329 4344 AmdK8 - ok
02:32:06.0335 4344 amdkmdag - ok
02:32:06.0341 4344 amdkmdap - ok
02:32:06.0347 4344 AmdPPM - ok
02:32:06.0351 4344 amdsata - ok
02:32:06.0354 4344 amdsbs - ok
02:32:06.0357 4344 amdxata - ok
02:32:06.0420 4344 AppID - ok
02:32:06.0433 4344 arc - ok
02:32:06.0440 4344 arcsas - ok
02:32:06.0445 4344 AsyncMac - ok
02:32:06.0451 4344 atapi - ok
02:32:06.0460 4344 AtiHDAudioService - ok
02:32:06.0475 4344 b06bdrv - ok
02:32:06.0480 4344 b57nd60a - ok
02:32:06.0492 4344 Beep - ok
02:32:06.0501 4344 blbdrive - ok
02:32:06.0504 4344 bowser - ok
02:32:06.0506 4344 BrFiltLo - ok
02:32:06.0509 4344 BrFiltUp - ok
02:32:06.0535 4344 Brserid - ok
02:32:06.0538 4344 BrSerWdm - ok
02:32:06.0541 4344 BrUsbMdm - ok
02:32:06.0544 4344 BrUsbSer - ok
02:32:06.0546 4344 BTHMODEM - ok
02:32:06.0588 4344 catchme - ok
02:32:06.0593 4344 cdfs - ok
02:32:06.0598 4344 cdrom - ok
02:32:06.0608 4344 circlass - ok
02:32:06.0613 4344 CLFS - ok
02:32:06.0650 4344 CmBatt - ok
02:32:06.0655 4344 cmdide - ok
02:32:06.0661 4344 CNG - ok
02:32:06.0666 4344 Compbatt - ok
02:32:06.0673 4344 CompositeBus - ok
02:32:06.0681 4344 crcdisk - ok
02:32:06.0716 4344 DfsC - ok
02:32:06.0724 4344 discache - ok
02:32:06.0728 4344 Disk - ok
02:32:06.0738 4344 drmkaud - ok
02:32:06.0742 4344 DXGKrnl - ok
02:32:06.0747 4344 e1cexpress - ok
02:32:06.0753 4344 ebdrv - ok
02:32:06.0878 4344 ElbyCDIO - ok
02:32:06.0884 4344 elxstor - ok
02:32:06.0888 4344 ErrDev - ok
02:32:06.0902 4344 exfat - ok
02:32:06.0907 4344 fastfat - ok
02:32:06.0915 4344 fdc - ok
02:32:06.0923 4344 FileInfo - ok
02:32:06.0926 4344 Filetrace - ok
02:32:06.0929 4344 flpydisk - ok
02:32:06.0931 4344 FltMgr - ok
02:32:06.0937 4344 FsDepends - ok
02:32:06.0939 4344 Fs_Rec - ok
02:32:06.0941 4344 fvevol - ok
02:32:06.0945 4344 gagp30kx - ok
02:32:06.0957 4344 hcw85cir - ok
02:32:06.0961 4344 HdAudAddService - ok
02:32:06.0963 4344 HDAudBus - ok
02:32:06.0965 4344 HidBatt - ok
02:32:06.0967 4344 HidBth - ok
02:32:06.0970 4344 HidIr - ok
02:32:06.0974 4344 HidUsb - ok
02:32:06.0990 4344 HpSAMD - ok
02:32:06.0992 4344 HTTP - ok
02:32:06.0994 4344 hwpolicy - ok
02:32:06.0996 4344 i8042prt - ok
02:32:06.0998 4344 iaStor - ok
02:32:07.0039 4344 iaStorV - ok
02:32:07.0048 4344 iirsp - ok
02:32:07.0059 4344 IntcAzAudAddService - ok
02:32:07.0065 4344 intelide - ok
02:32:07.0071 4344 intelppm - ok
02:32:07.0078 4344 IpFilterDriver - ok
02:32:07.0084 4344 IPMIDRV - ok
02:32:07.0090 4344 IPNAT - ok
02:32:07.0094 4344 IRENUM - ok
02:32:07.0099 4344 isapnp - ok
02:32:07.0104 4344 iScsiPrt - ok
02:32:07.0108 4344 kbdclass - ok
02:32:07.0114 4344 kbdhid - ok
02:32:07.0148 4344 KSecDD - ok
02:32:07.0152 4344 KSecPkg - ok
02:32:07.0156 4344 ksthunk - ok
02:32:07.0174 4344 Lavasoft Kernexplorer - ok
02:32:07.0180 4344 Lbd - ok
02:32:07.0189 4344 lltdio - ok
02:32:07.0200 4344 LSI_FC - ok
02:32:07.0203 4344 LSI_SAS - ok
02:32:07.0207 4344 LSI_SAS2 - ok
02:32:07.0211 4344 LSI_SCSI - ok
02:32:07.0214 4344 luafv - ok
02:32:07.0220 4344 MBAMProtector - ok
02:32:07.0227 4344 megasas - ok
02:32:07.0231 4344 MegaSR - ok
02:32:07.0234 4344 MEIx64 - ok
02:32:07.0239 4344 Modem - ok
02:32:07.0242 4344 monitor - ok
02:32:07.0246 4344 mouclass - ok
02:32:07.0249 4344 mouhid - ok
02:32:07.0252 4344 mountmgr - ok
02:32:07.0255 4344 mpio - ok
02:32:07.0257 4344 mpsdrv - ok
02:32:07.0261 4344 MRxDAV - ok
02:32:07.0263 4344 mrxsmb - ok
02:32:07.0266 4344 mrxsmb10 - ok
02:32:07.0269 4344 mrxsmb20 - ok
02:32:07.0271 4344 msahci - ok
02:32:07.0274 4344 msdsm - ok
02:32:07.0281 4344 Msfs - ok
02:32:07.0284 4344 mshidkmdf - ok
02:32:07.0287 4344 msisadrv - ok
02:32:07.0292 4344 MSKSSRV - ok
02:32:07.0295 4344 MSPCLOCK - ok
02:32:07.0297 4344 MSPQM - ok
02:32:07.0300 4344 MsRPC - ok
02:32:07.0304 4344 mssmbios - ok
02:32:07.0307 4344 MSTEE - ok
02:32:07.0310 4344 MTConfig - ok
02:32:07.0312 4344 Mup - ok
02:32:07.0315 4344 mwlPSDFilter - ok
02:32:07.0318 4344 mwlPSDNServ - ok
02:32:07.0321 4344 mwlPSDVDisk - ok
02:32:07.0348 4344 NativeWifiP - ok
02:32:07.0352 4344 NDIS - ok
02:32:07.0354 4344 NdisCap - ok
02:32:07.0357 4344 NdisTapi - ok
02:32:07.0367 4344 Ndisuio - ok
02:32:07.0370 4344 NdisWan - ok
02:32:07.0373 4344 NDProxy - ok
02:32:07.0376 4344 NetBIOS - ok
02:32:07.0379 4344 NetBT - ok
02:32:07.0386 4344 netr28x - ok
02:32:07.0390 4344 nfrd960 - ok
02:32:07.0394 4344 Npfs - ok
02:32:07.0398 4344 nsiproxy - ok
02:32:07.0402 4344 Ntfs - ok
02:32:07.0404 4344 Null - ok
02:32:07.0407 4344 nvraid - ok
02:32:07.0410 4344 nvstor - ok
02:32:07.0413 4344 nv_agp - ok
02:32:07.0416 4344 ohci1394 - ok
02:32:07.0424 4344 Parport - ok
02:32:07.0426 4344 partmgr - ok
02:32:07.0431 4344 pci - ok
02:32:07.0434 4344 pciide - ok
02:32:07.0437 4344 pcmcia - ok
02:32:07.0440 4344 pcw - ok
02:32:07.0443 4344 PEAUTH - ok
02:32:07.0481 4344 PptpMiniport - ok
02:32:07.0484 4344 Processor - ok
02:32:07.0489 4344 Psched - ok
02:32:07.0491 4344 ql2300 - ok
02:32:07.0494 4344 ql40xx - ok
02:32:07.0498 4344 QWAVEdrv - ok
02:32:07.0500 4344 RasAcd - ok
02:32:07.0503 4344 RasAgileVpn - ok
02:32:07.0506 4344 Rasl2tp - ok
02:32:07.0510 4344 RasPppoe - ok
02:32:07.0513 4344 RasSstp - ok
02:32:07.0515 4344 rdbss - ok
02:32:07.0518 4344 rdpbus - ok
02:32:07.0521 4344 RDPCDD - ok
02:32:07.0525 4344 RDPENCDD - ok
02:32:07.0529 4344 RDPREFMP - ok
02:32:07.0532 4344 RDPWD - ok
02:32:07.0535 4344 rdyboost - ok
02:32:07.0545 4344 rspndr - ok
02:32:07.0548 4344 sbp2port - ok
02:32:07.0554 4344 scfilter - ok
02:32:07.0560 4344 secdrv - ok
02:32:07.0566 4344 Serenum - ok
02:32:07.0569 4344 Serial - ok
02:32:07.0571 4344 sermouse - ok
02:32:07.0580 4344 sffdisk - ok
02:32:07.0583 4344 sffp_mmc - ok
02:32:07.0585 4344 sffp_sd - ok
02:32:07.0588 4344 sfloppy - ok
02:32:07.0590 4344 Sftfs - ok
02:32:07.0594 4344 Sftplay - ok
02:32:07.0597 4344 Sftredir - ok
02:32:07.0599 4344 Sftvol - ok
02:32:07.0606 4344 SiSRaid2 - ok
02:32:07.0608 4344 SiSRaid4 - ok
02:32:07.0611 4344 Smb - ok
02:32:07.0617 4344 spldr - ok
02:32:07.0623 4344 srv - ok
02:32:07.0626 4344 srv2 - ok
02:32:07.0628 4344 srvnet - ok
02:32:07.0634 4344 stexstor - ok
02:32:07.0637 4344 swenum - ok
02:32:07.0646 4344 Tcpip - ok
02:32:07.0649 4344 TCPIP6 - ok
02:32:07.0652 4344 tcpipreg - ok
02:32:07.0656 4344 TDPIPE - ok
02:32:07.0659 4344 TDTCP - ok
02:32:07.0662 4344 tdx - ok
02:32:07.0665 4344 TermDD - ok
02:32:07.0676 4344 tssecsrv - ok
02:32:07.0678 4344 TsUsbFlt - ok
02:32:07.0681 4344 tunnel - ok
02:32:07.0684 4344 uagp35 - ok
02:32:07.0686 4344 udfs - ok
02:32:07.0692 4344 uliagpkx - ok
02:32:07.0695 4344 umbus - ok
02:32:07.0698 4344 UmPass - ok
02:32:07.0705 4344 usbaudio - ok
02:32:07.0707 4344 usbccgp - ok
02:32:07.0710 4344 usbcir - ok
02:32:07.0713 4344 usbehci - ok
02:32:07.0716 4344 usbhub - ok
02:32:07.0718 4344 usbohci - ok
02:32:07.0721 4344 usbprint - ok
02:32:07.0724 4344 usbscan - ok
02:32:07.0726 4344 USBSTOR - ok
02:32:07.0729 4344 usbuhci - ok
02:32:07.0734 4344 VClone - ok
02:32:07.0736 4344 vdrvroot - ok
02:32:07.0740 4344 vga - ok
02:32:07.0743 4344 VgaSave - ok
02:32:07.0746 4344 vhdmp - ok
02:32:07.0748 4344 viaide - ok
02:32:07.0751 4344 volmgr - ok
02:32:07.0753 4344 volmgrx - ok
02:32:07.0755 4344 volsnap - ok
02:32:07.0758 4344 vsmraid - ok
02:32:07.0762 4344 vwifibus - ok
02:32:07.0764 4344 vwififlt - ok
02:32:07.0769 4344 WacomPen - ok
02:32:07.0772 4344 WANARP - ok
02:32:07.0775 4344 Wanarpv6 - ok
02:32:07.0784 4344 Wd - ok
02:32:07.0787 4344 Wdf01000 - ok
02:32:07.0798 4344 WfpLwf - ok
02:32:07.0800 4344 WIMMount - ok
02:32:07.0815 4344 WmiAcpi - ok
02:32:07.0825 4344 ws2ifsl - ok
02:32:07.0832 4344 WudfPf - ok
02:32:07.0835 4344 WUDFRd - ok
02:32:07.0852 4344 MBR (0x1B8) (3051207086651214e435112e51817dc5) \Device\Harddisk0\DR0
02:32:07.0982 4344 \Device\Harddisk0\DR0 - ok
02:32:07.0995 4344 MBR (0x1B8) (a36c5e4f47e84449ff07ed3517b43a31) \Device\Harddisk1\DR1
02:32:08.0021 4344 \Device\Harddisk1\DR1 - ok
02:32:08.0026 4344 Boot (0x1200) (58328132cfd65b63c2f87dec0f4708ed) \Device\Harddisk0\DR0\Partition0
02:32:08.0027 4344 \Device\Harddisk0\DR0\Partition0 - ok
02:32:08.0043 4344 Boot (0x1200) (dffaefe058448a39e60bb62427798534) \Device\Harddisk0\DR0\Partition1
02:32:08.0044 4344 \Device\Harddisk0\DR0\Partition1 - ok
02:32:08.0045 4344 ============================================================
02:32:08.0045 4344 Scan finished
02:32:08.0045 4344 ============================================================
02:32:08.0055 3324 Detected object count: 0
02:32:08.0055 3324 Actual detected object count: 0
02:32:35.0640 1220 Deinitialize success


--

aswMBR did NOT show a "fix" button - it was greyed out.

--
ComboFix 11-11-04.04 - Magical 05-11-2011 2:20:01.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.31.1033.18.6127.3367 [GMT 1:00]
Gestart vanuit: C:\Users\Magical\Desktop\ComboFix.exe
AV: Lavasoft Ad-Watch Live! Anti-Virus *Disabled/Updated* {9FF26384-70D4-CE6B-3ECB-E759A6A40116}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {24938260-56EE-C1E5-047B-DC2BDD234BAB}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}


(((((((((((((((((((((((((((((((((( Andere Verwijderingen )))))))))))))))))))))))))))))))))))))))))))))))))


C:\ProgramData\FullRemove.exe
C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\System Restore.lnk
C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\Uninstall System Restore.lnk
C:\Windows\security\Database\tmp.edb
C:\Windows\System64


(((((((((((((((((((( Bestanden Gemaakt van 2011-10-05 to 2011-11-05 ))))))))))))))))))))))))))))))


2011-11-05 01:22:21 . 2011-11-05 01:22:21 -------- d-----w- C:\Users\Default\AppData\Local\temp
2011-11-03 22:48:56 . 2011-11-04 19:42:56 735702 ----a-w- C:\Windows\system32\PerfStringBackup.TMP
2011-11-03 22:33:46 . 2011-11-03 22:33:46 -------- d-----w- C:\Users\Magical\AppData\Roaming\Malwarebytes
2011-11-03 22:32:44 . 2011-11-03 22:32:44 -------- d-----w- C:\ProgramData\Malwarebytes
2011-11-03 22:32:42 . 2011-11-03 22:32:45 -------- d-----w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2011-11-03 22:32:42 . 2011-08-31 16:00:50 25416 ----a-w- C:\Windows\system32\drivers\mbam.sys
2011-11-03 20:04:28 . 2011-11-03 18:40:48 16432 ---ha-w- C:\Windows\system32\lsdelete.exe
2011-11-03 18:32:52 . 2011-10-28 18:35:28 69376 ---ha-w- C:\Windows\system32\drivers\Lbd.sys
2011-11-03 17:43:56 . 2011-06-21 04:09:00 200976 ---ha-w- C:\Windows\SysWow64\drivers\tmcomm.sys
2011-11-03 17:40:21 . 2011-10-07 04:16:03 8570192 ---ha-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{7D0402AF-9938-4541-BF9C-6F922A895326}\mpengine.dll
2011-11-03 17:37:43 . 2011-09-06 03:03:17 3138048 ----a-w- C:\Windows\system32\win32k.sys
2011-11-03 17:37:31 . 2011-08-17 05:26:46 613888 ----a-w- C:\Windows\system32\psisdecd.dll
2011-11-03 17:37:31 . 2011-08-17 05:25:08 108032 ----a-w- C:\Windows\system32\psisrndr.ax
2011-11-03 17:37:31 . 2011-08-17 04:24:12 465408 ----a-w- C:\Windows\SysWow64\psisdecd.dll
2011-11-03 17:37:31 . 2011-08-17 04:19:27 75776 ----a-w- C:\Windows\SysWow64\psisrndr.ax
2011-11-03 17:37:26 . 2011-08-27 05:37:49 861696 ----a-w- C:\Windows\system32\oleaut32.dll
2011-11-03 17:37:26 . 2011-08-27 05:37:48 331776 ----a-w- C:\Windows\system32\oleacc.dll
2011-11-03 17:37:26 . 2011-08-27 04:26:27 571904 ----a-w- C:\Windows\SysWow64\oleaut32.dll
2011-11-03 17:37:26 . 2011-08-27 04:26:27 233472 ----a-w- C:\Windows\SysWow64\oleacc.dll
2011-10-24 08:28:37 . 2011-10-26 20:02:22 -------- d--h--w- C:\Users\Magical\AppData\Local\Microsoft Games
.


((((((((((((((((((((((((((((((((((((((( Find3M Rapport ))))))))))))))))))))))))))))))))))))))))))))))))))))

2011-08-28 03:48:57 . 2011-05-01 19:48:58 404640 ---h--w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-08-27 20:28:39 . 2010-06-24 09:33:56 18328 ---ha-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-05-30 20:43:52 . 2011-06-19 19:45:14 1007358 ---ha-w- C:\Program Files\Windows-Theme-Manager-Setup.exe
2011-05-27 22:06:47 . 2011-05-27 22:06:47 270128 ---ha-w- C:\Program Files\uTorrent.exe


((((((((((((((((((((((((((((((((((((( Reg Opstartpunten )))))))))))))))))))))))))))))))))))))))))))))))))))


*Nota* lege verwijzingen & legitieme standaard verwijzingen worden niet getoond
REGEDIT4

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 94208 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 94208 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 94208 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 94208 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:40:28 120176 ---ha-w- C:\Program Files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Aim"="C:\Program Files (x86)\AIM\aim.exe" [2011-05-03 15:43:14 4321112]
"Messenger (Yahoo!)"="C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 08:17:48 5252408]
"MultiScreen"="C:\Program Files (x86)\MultiScreen\MultiScreen.exe" [2009-08-11 11:57:26 303104]
"uTorrent"="C:\Program Files\uTorrent.exe" [2011-05-27 22:06:47 270128]
"msnmsgr"="C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" [2011-05-13 14:03:34 4283256]
"Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe" [2011-10-13 07:27:14 17351304]

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" [2010-09-14 01:32:30 283160]
"SuiteTray"="C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-05-27 02:59:08 337264]
"EgisUpdate"="C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" [2010-03-11 05:11:42 201584]
"EgisTecPMMUpdate"="C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe" [2010-03-11 05:11:56 407920]
"StartCCC"="C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-01-10 10:53:00 336384]
"Hotkey Utility"="C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe" [2010-12-03 06:00:42 618600]
"googletalk"="C:\Program Files (x86)\Google\Google Talk\googletalk.exe" [2007-01-01 21:22:02 3739648]
"Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 10:55:28 937920]
"VirtualCloneDrive"="C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2011-03-07 13:33:08 89456]
"SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2011-04-08 10:59:52 254696]
"Malwarebytes' Anti-Malware"="C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-08-31 16:00:48 449608]

C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe [2011-5-25 24176560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

R2 AMService;AMService;C:\Windows\TEMP\nydecp\setup.exe run [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 11:16:28 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 12:27:14 138576]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [2010-10-20 13:23:26 821664]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-10-05 13:08:46 2655768]
R3 MWLService;MyWinLocker Service;C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 02:41:06 305520]
R3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 19:34:24 4925184]
R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\system32\Wat\WatAdminSvc.exe [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 16:10:10 57184]
S0 Lbd;Lbd;C:\Windows\system32\DRIVERS\Lbd.sys [x]
S1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys [x]
S1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys [x]
S1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys [x]
S1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys [x]
S2 AdobeARMservice;Adobe Acrobat Update Service;C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2011-06-06 10:55:28 64952]
S2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe [x]
S2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 13:21:22 23584]
S2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-09-14 01:32:32 13336]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe [2011-10-28 18:35:26 2152152]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-08-31 16:00:48 366152]
S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 13:31:10 1153368]
S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2010-09-14 03:45:44 508264]
S2 Updater Service;Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 23:27:36 243232]
S3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [x]
S3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys [x]
S3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys [x]
S3 e1cexpress;Intel® PRO/1000 PCI Express Network Connection Driver C;C:\Windows\system32\DRIVERS\e1c62x64.sys [x]
S3 Lavasoft Kernexplorer;Lavasoft helper driver;C:\Program Files (x86)\Lavasoft\Ad-Aware\KernExplorer64.sys [2011-11-03 18:40:49 17152]
S3 MBAMProtector;MBAMProtector;C:\Windows\system32\drivers\mbam.sys [x]
S3 MEIx64;Intel® Management Engine Interface;C:\Windows\system32\DRIVERS\HECIx64.sys [x]
S3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\system32\DRIVERS\netr28x.sys [x]
S3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2010-09-14 03:45:56 219496]


--- Andere Services/Drivers In Geheugen ---

*NewlyCreated* - LAVASOFT_KERNEXPLORER

Inhoud van de 'Gedeelde Taken' map

2011-11-05 C:\Windows\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files (x86)\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2011-10-28 18:35:26 . 2011-10-28 18:35:26]


--------- x86-64 -----------


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 97792 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 97792 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 97792 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2011-02-18 05:12:20 97792 ---ha-w- C:\Users\Magical\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP]
@="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}"
[HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}]
2010-05-27 02:42:12 137584 ---ha-w- C:\Program Files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"mwlDaemon"="C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-05-27 02:41:24 349552]
"RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-09-03 08:17:38 11464296]
"lxcymon.exe"="C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe" [2009-05-01 11:54:44 291496]
"EzPrint"="C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe" [2009-05-01 11:54:46 82600]
"LXCYCATS"="C:\Windows\system32\spool\DRIVERS\x64\3\LXCYtime.dll" [2006-11-21 11:29:24 31744]
"combofix"="C:\ComboFix\CF14156.3XE" [2010-11-20 13:24:33 345088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0

------- Bijkomende Scan -------

uStart Page = about:blank
uLocal Page = C:\Windows\system32\blank.htm
mStart Page = hxxp://acer.msn.com
mLocal Page = C:\Windows\SysWOW64\blank.htm
TCP: Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: NameServer = 8.8.8.8,8.8.4.4
FF - ProfilePath - C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
FF - Ext: Xmarks: [email protected] - %profile%\extensions\[email protected]
FF - Ext: ChatZilla: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2} - %profile%\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
FF - Ext: Greasemonkey: {e4a8a97b-f2ed-450b-b12d-ee082ba24781} - %profile%\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
FF - Ext: Smartest Bookmarks Bar: {b442f4c0-c292-4998-aabe-48608a73ba75} - %profile%\extensions\{b442f4c0-c292-4998-aabe-48608a73ba75}
FF - Ext: RSS Ticker: {1f91cde0-c040-11da-a94d-0800200c9a66} - %profile%\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
FF - Ext: Multirow Bookmarks Toolbar: {FBF6D7FB-F305-4445-BB3D-FEF66579A033} - %profile%\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
FF - Ext: BlackFox V1-Blue: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Add-on Compatibility Reporter: [email protected] - %profile%\extensions\[email protected]
FF - Ext: DNS Cache: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Element Hiding Helper for Adblock Plus: [email protected] - %profile%\extensions\[email protected]
FF - Ext: British English Dictionary: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Webmail Ad Blocker: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Cooliris: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Smart Bookmarks Bar: [email protected] - %profile%\extensions\[email protected]
FF - Ext: Tab Counter: tabcounter@morac - %profile%\extensions\tabcounter@morac
FF - Ext: Screengrab: {02450954-cdd9-410f-b1da-db804e18c671} - %profile%\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
FF - Ext: Image Zoom: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68} - %profile%\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
FF - Ext: DNS Flusher: {7d575baa-b543-11dc-8314-0800200c9a66} - %profile%\extensions\{7d575baa-b543-11dc-8314-0800200c9a66}
FF - Ext: Showcase: {89506680-e3f4-484c-a2c0-ed711d481eda} - %profile%\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Favicon Picker 2: {446c03e0-2c35-11db-a98b-0800200c9a66} - %profile%\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
FF - user.js: network.protocol-handler.warn-external.dnupdate - false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false);user_pref(network.protocol-handler.warn-external.dnupdate, false

- - - - ORPHANS VERWIJDERD - - - -

Toolbar-Locked - (no file)
Toolbar-Locked - (no file)
AddRemove-Adobe Shockwave Player - C:\Windows\system32\Adobe\Shockwave 11\uninstaller.exe
AddRemove-dBpoweramp DSP Effects - C:\Windows\system32\SpoonUninstall.exe
AddRemove-dBpoweramp Music Converter - C:\Windows\system32\SpoonUninstall.exe

Attached Files


Edited by RKinner, 04 November 2011 - 08:14 PM.

  • 0

#4
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Putting the OTL logs into a separate reply to try and keep things readable for you :)

OTL.txt:

OTL logfile created on: 11/5/2011 2:47:34 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 3.90 Gb Available Physical Memory | 65.17% Memory free
11.96 Gb Paging File | 9.87 Gb Available in Paging File | 82.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 888.13 Gb Free Space | 96.23% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 287.00 Gb Free Space | 58.76% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 153.22 Gb Free Space | 78.45% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 217.78 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive M: | 434.57 Gb Total Space | 98.56 Gb Free Space | 22.68% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/04 09:18:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Magical\Downloads\OTL.com
PRC - [2011/10/28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/09/28 09:32:23 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/03 16:43:14 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/10/05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/10/05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/09/14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/14 02:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/06/01 09:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/05/27 03:41:24 | 000,349,552 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010/03/11 06:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010/03/11 06:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
PRC - [2009/05/01 12:54:46 | 000,082,600 | ---- | M] (Lexmark International Inc.) -- C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe
PRC - [2009/05/01 12:54:44 | 000,291,496 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/01/01 22:22:02 | 003,739,648 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Talk\googletalk.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/03 20:00:31 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll
MOD - [2011/11/03 20:00:31 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll
MOD - [2011/11/03 18:53:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/11/03 18:52:54 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/11/03 18:52:46 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/11/03 18:52:30 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/11/03 18:52:25 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/11/03 18:52:21 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/11/03 18:52:20 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/11/03 18:51:31 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/09/28 09:32:23 | 001,015,256 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2011/08/28 04:48:57 | 006,277,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/05/03 16:38:52 | 000,176,128 | ---- | M] () -- C:\Program Files (x86)\AIM\nssckbi.dll
MOD - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/12/03 04:44:54 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
MOD - [2010/06/01 09:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
MOD - [2009/08/11 12:56:52 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MGResEng.dll
MOD - [2009/08/11 12:54:36 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\SmartMouseDll.dll
MOD - [2009/08/11 12:54:28 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\TitleBar.dll
MOD - [2009/05/01 12:54:44 | 000,291,496 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe
MOD - [2006/08/08 14:54:18 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcyscw.dll
MOD - [2006/05/25 15:20:44 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\iptk.dll
MOD - [2006/02/13 08:04:20 | 000,143,360 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcydrec.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/01/10 10:03:43 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/10/28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/11/20 13:21:36 | 000,351,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- winhttp.dll -- (WinHttpAutoProxySvc)
SRV - [2010/10/05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/10/05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/09/14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010/09/14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010/09/14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/05/27 03:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/10/28 19:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/01/15 17:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2011/01/10 10:31:20 | 008,283,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/01/10 09:28:18 | 000,295,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/21 09:31:00 | 000,316,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010/12/16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/09/14 04:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010/09/14 04:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010/09/14 04:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010/09/14 04:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010/09/14 02:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/08/11 04:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/03 03:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/03 03:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/03 03:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2011/11/03 19:40:49 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (All) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer.msn.com
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...=ie&ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\..\URLSearchHook: {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\SysWOW64\ieframe.dll (Microsoft Corporation)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:4.0.2
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.12
FF - prefs.js..extensions.enabledItems: {b442f4c0-c292-4998-aabe-48608a73ba75}:1.0.1.3
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:9
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.4.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.3.50136
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: tabcounter@morac:1.8.8
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {7d575baa-b543-11dc-8314-0800200c9a66}:2.0.5
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.23
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.6


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/10/16 21:03:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/09/28 09:32:23 | 000,000,000 | ---D | M]

[2011/05/01 18:09:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Extensions
[2011/05/01 20:13:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2011/11/04 23:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/05/02 12:15:59 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2011/09/13 12:21:34 | 000,000,000 | ---D | M] (RSS Ticker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
[2011/08/26 08:18:32 | 000,000,000 | ---D | M] (Integrated Gmail) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2011/06/16 01:41:34 | 000,000,000 | ---D | M] (Favicon Picker 2) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
[2011/06/06 01:55:11 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (BitmeTV Menu) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{633b7287-e788-4131-a31c-db09d8ebbe51}(2)
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (DNS Flusher) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{7d575baa-b543-11dc-8314-0800200c9a66}
[2011/08/31 21:54:04 | 000,000,000 | ---D | M] (Showcase) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2011/08/26 13:00:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2011/05/01 21:32:21 | 000,000,000 | ---D | M] (Smartest Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{b442f4c0-c292-4998-aabe-48608a73ba75}
[2011/10/01 01:21:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/10/16 21:04:20 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011/10/01 01:21:41 | 000,000,000 | ---D | M] (Add-on Compatibility Reporter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:15:57 | 000,000,000 | ---D | M] (DNS Cache) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/10/01 01:21:40 | 000,000,000 | ---D | M] (Element Hiding Helper for Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:15 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/25 20:57:40 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/13 12:21:34 | 000,000,000 | ---D | M] (Webmail Ad Blocker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/19 01:13:54 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/09/19 01:13:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:16 | 000,000,000 | ---D | M] (Smart Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:17 | 000,000,000 | ---D | M] (Tab Counter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\tabcounter@morac
[2011/10/01 01:21:41 | 000,000,000 | ---D | M] (BlackFox V1-Blue) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/26 13:00:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/11/01 10:08:47 | 000,001,032 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\exigo.xml
[2010/04/30 18:04:17 | 000,001,504 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\imdb.xml
[2010/04/24 17:18:48 | 000,002,352 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\search-firefox-addons.xml
[2010/05/25 00:38:29 | 000,004,140 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\youtube.xml
[2011/11/04 23:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/09/28 09:32:23 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2011/05/01 20:50:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/09/28 09:35:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/09/28 09:32:23 | 000,025,048 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browserdirprovider.dll
[2011/09/28 09:32:23 | 000,140,248 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\brwsrcmp.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/28 09:32:23 | 000,066,520 | ---- | M] (mozilla.org) -- C:\Program Files (x86)\mozilla firefox\plugins\npnul32.dll
[2011/06/06 11:55:30 | 000,183,696 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll
[2011/04/21 00:07:17 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/21 00:07:17 | 000,002,193 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\answers.xml
[2011/04/21 00:07:17 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/21 00:07:17 | 000,001,534 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\creativecommons.xml
[2011/04/21 00:07:17 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/04/21 00:07:17 | 000,002,371 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\google.xml
[2011/04/21 00:07:17 | 000,001,178 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia.xml
[2011/04/21 00:07:17 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/11/05 02:23:58 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [combofix] C:\ComboFix\CF14156.3XE (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [LXCYCATS] C:\Windows\SysNative\spool\DRIVERS\x64\3\LXCYtime.DLL (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [lxcymon.exe] C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe ()
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Adobe ARM] C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [VirtualCloneDrive] C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Elaborate Bytes AG)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [MultiScreen] C:\Program Files (x86)\MultiScreen\MultiScreen.exe ()
O4 - HKCU..\Run: [Skype] C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000001 [] - mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000002 [] - C:\Windows\SysNative\NapiNSP.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000003 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000004 [] - C:\Windows\SysNative\pnrpnsp.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - mswsock.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000006 [] - C:\Windows\SysNative\winrnr.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - C:\Windows\SysNative\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Windows\SysWOW64\winrnr.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000027 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000028 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000029 - C:\Windows\SysWOW64\mswsock.dll (Microsoft Corporation)
O1364bit: - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysNative\inetcomm.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysNative\urlmon.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysNative\itss.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysNative\MSVidCtl.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysNative\mshtml.dll (Microsoft Corporation)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\about {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\cdl {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\dvd {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\file {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ftp {79eac9e3-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\http {79eac9e2-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\https {79eac9e5-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\javascript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\local {79eac9e7-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\mailto {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\mhtml {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\SysWOW64\inetcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\mk {79eac9e6-baf9-11ce-8c82-00aa004ba90b} - C:\Windows\SysWOW64\urlmon.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-its {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\SysWOW64\itss.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll (Microsoft Corporation)
O18 - Protocol\Handler\res {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\tv {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\SysWOW64\MSVidCtl.dll (Microsoft Corporation)
O18 - Protocol\Handler\vbscript {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\SysWOW64\mshtml.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlpg {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18:64bit: - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWOW64\webcheck.dll (Microsoft Corporation)
O29:64bit: - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (credssp.dll) -credssp.dll (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Authentication Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (kerberos) - C:\Windows\SysNative\kerberos.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (msv1_0) - C:\Windows\SysNative\msv1_0.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (schannel) - C:\Windows\SysNative\schannel.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (wdigest) - C:\Windows\SysNative\wdigest.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (tspkg) - C:\Windows\SysNative\TSpkg.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (pku2u) - C:\Windows\SysNative\pku2u.dll (Microsoft Corporation)
O30:64bit: - LSA: Security Packages - (livessp) - C:\Windows\SysNative\LIVESSP.DLL (Microsoft Corp.)
O30 - LSA: Security Packages - (kerberos) -C:\Windows\SysWow64\kerberos.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (msv1_0) -C:\Windows\SysWow64\msv1_0.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (schannel) -C:\Windows\SysWow64\schannel.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (wdigest) -C:\Windows\SysWow64\wdigest.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (tspkg) -C:\Windows\SysWow64\TSpkg.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) -C:\Windows\SysWow64\pku2u.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (livessp) -C:\Windows\SysWow64\LIVESSP.DLL (Microsoft Corp.)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/22 11:24:38 | 000,000,000 | -H-- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/05 02:41:19 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011/11/05 02:31:20 | 001,563,952 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011/11/05 02:22:20 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/11/05 02:19:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/11/05 02:19:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/11/05 02:19:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/11/05 02:19:25 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/05 02:19:24 | 000,000,000 | ---D | C] -- C:\ComboFix
[2011/11/05 02:19:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/05 02:13:40 | 004,284,246 | R--- | C] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011/11/05 02:04:45 | 000,000,000 | ---D | C] -- C:\Users\Magical\Desktop\lost
[2011/11/04 20:34:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A74238AF-F985-4C54-B753-3C3E0B5FF6F7}
[2011/11/04 20:34:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1E75554F-0FA9-4128-8F2D-A41333AD2C7A}
[2011/11/04 08:34:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A48E29C5-8D30-46E1-B3DD-A4ACBB35EE02}
[2011/11/04 08:33:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CBBD8B9-07D0-4110-B258-D84D562E514F}
[2011/11/03 23:33:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Roaming\Malwarebytes
[2011/11/03 23:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 23:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/03 23:32:42 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/03 23:32:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/03 19:32:52 | 000,069,376 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2011/11/03 19:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/11/03 19:32:15 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011/11/03 18:43:56 | 000,200,976 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/11/03 18:39:26 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011/11/03 18:39:26 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011/11/03 18:39:25 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011/11/03 18:39:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011/11/03 18:39:24 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011/11/03 18:39:23 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011/11/03 18:39:23 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011/11/03 18:39:23 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011/11/03 18:39:23 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011/11/03 18:37:31 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2011/11/03 18:37:31 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2011/11/03 18:37:31 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2011/11/03 18:37:31 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2011/11/03 18:37:26 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2011/11/03 18:37:26 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2011/11/03 17:50:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D4C94249-A4BD-4B7D-887D-884E143AAD16}
[2011/11/03 05:49:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D63D7844-9801-42DD-ADE6-4831ED93C8D2}
[2011/11/02 17:49:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{87E3EBB1-7FF7-4901-99D7-4DAF46AAF9D3}
[2011/11/02 05:48:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{43EDBA0A-6DD0-4C23-B7E8-B1B0A86B9334}
[2011/11/01 17:47:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EE36652D-BAFE-4F17-9AD5-3E4DF5765A31}
[2011/11/01 05:47:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{637D5548-7DE6-49B0-8549-1D983001FA07}
[2011/10/31 17:46:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F784FAAE-CC16-49BD-947A-884C8279F464}
[2011/10/31 11:18:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\Documents\Stuff that used to be in dropbox
[2011/10/31 05:46:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{92CBC907-2386-47DA-9958-63C7EFF57ED9}
[2011/10/30 17:45:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{35E733DD-0BA5-440F-BEC9-749E4867548A}
[2011/10/30 05:44:49 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CC4A491-409E-49DE-8278-786C38FA7BDC}
[2011/10/29 17:44:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E6782204-61AC-493C-8AEE-B5AE825874DB}
[2011/10/29 05:43:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3DC0B751-9BC6-48F2-BF39-B648D11D53A9}
[2011/10/28 17:43:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{0EB83299-8115-4D51-BAEE-DDCE4741254F}
[2011/10/28 05:42:27 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F6424066-E600-4DB4-9273-8C01C900025C}
[2011/10/27 17:41:51 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{72A3BAC0-E766-4697-B006-B74608057CE6}
[2011/10/27 05:41:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{FEC61A44-90AF-4347-AB20-B68D9194669F}
[2011/10/26 17:40:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B0B050C5-5F13-4BAD-A334-9AE589773182}
[2011/10/26 05:40:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{356B0CFB-26EC-426E-BAA3-CE05C2C1E2D8}
[2011/10/25 17:39:32 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{359FCEBE-7990-4F97-8198-6428C2F088D8}
[2011/10/25 05:39:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3423A6EF-E8A0-4978-BDF1-A6F60AC59B71}
[2011/10/24 17:38:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C4A081CD-94AF-4B21-B42F-5497DE775F41}
[2011/10/24 09:28:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\Microsoft Games
[2011/10/24 05:38:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1B2D8A7F-970E-4E8D-AF8B-A9C01CBE25A5}
[2011/10/23 17:37:31 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{057FD8D5-C992-49A9-8440-32AE88F0147D}
[2011/10/23 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74AB5993-50A0-4A03-B589-BBAB27058FAA}
[2011/10/22 17:36:34 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EF1C193A-AA47-4766-858B-451EE4B2264B}
[2011/10/22 05:36:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C2455C65-BAA2-4CDE-AB5C-564F2B642691}
[2011/10/21 17:35:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4811046-0A7C-4EB3-AE30-71FDF60F6D3A}
[2011/10/21 05:35:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AB1B270B-9B8F-4DFB-AA09-EFD20202A95F}
[2011/10/20 17:34:42 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{96729716-95F0-4756-B7F6-733504C3DB04}
[2011/10/20 05:34:15 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E18A4DE2-43C9-4E85-A2F7-B9958155721C}
[2011/10/19 17:33:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{914C5AF3-7A88-4746-827F-D8796D7416B3}
[2011/10/19 05:33:22 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5B50832A-E4C7-4B3A-A7C3-6E89EB1C6274}
[2011/10/18 17:32:56 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A6BB88B6-104F-415F-8CCD-DC9481BBF595}
[2011/10/18 05:32:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EFEB572C-D1D9-4530-8431-CA99C5A2B1BA}
[2011/10/17 17:32:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3F7D4546-3096-44C8-95F8-66A13E36889A}
[2011/10/17 05:31:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F04A283D-3DF0-4E47-97F6-B0F60FF22E74}
[2011/10/16 17:31:13 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C77AB15E-D2D2-4D01-AAF2-DAE89EDF0681}
[2011/10/16 17:31:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D32288D7-0AD4-46B7-951E-68DF21812BC2}
[2011/10/16 05:30:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{49224AAA-B72B-48D4-AE4D-0E96E06D77E2}
[2011/10/16 05:30:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9B2182A1-7784-4409-B137-583188119E0A}
[2011/10/15 17:30:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{12170724-B536-47A0-9536-1D73EE3EC65F}
[2011/10/15 17:29:58 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{41CE4D19-B15E-4373-A390-12C55057950E}
[2011/10/15 05:29:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9AEFF161-36B8-48F0-B59D-4E1EFC764BA3}
[2011/10/15 05:29:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{71C7E389-A36B-4DB6-BF3B-BF4F172E8B45}
[2011/10/14 17:29:19 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C5857948-6208-4D04-A183-16EA4B94E248}
[2011/10/14 17:29:08 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{15AF7EB9-E426-4F55-AC62-471E12838F1C}
[2011/10/14 05:28:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74E29617-D529-4D3B-BDC4-E70078294605}
[2011/10/14 05:28:43 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7FB1650C-7722-4E51-9422-0F809C002631}
[2011/10/13 17:28:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{79B49105-364E-4824-9B35-8CD2544A0E5D}
[2011/10/13 17:28:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E9EA43A9-B45F-4857-A27B-9461F3ABBA75}
[2011/10/13 05:28:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4F7B2F1-8E62-45A4-83AF-3C9386A96FA0}
[2011/10/13 05:27:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AC2C66DF-C97F-4810-8CE5-91052FB079DB}
[2011/10/12 17:27:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7F16F78E-F53D-4015-A913-CAE75C349B20}
[2011/10/12 17:27:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D9EE5708-1E40-4763-983A-BE05C43E4F0E}
[2011/10/12 05:27:16 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A9161CE8-0324-47C7-8821-4A20A3F34C92}
[2011/10/12 05:27:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{99D0AE6F-359B-4118-919D-FF95612EB0D7}
[2011/10/11 17:26:52 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D6294A31-0536-42BA-8386-2D389D2F4592}
[2011/10/11 17:26:41 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{CC10FF82-BAEF-44B9-AEF7-CCCA3F22F520}
[2011/10/11 05:26:28 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D252F5D3-437A-4786-9D3E-97C9976296CB}
[2011/10/11 05:26:16 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{35AE3E6C-147D-468B-BC8D-BAE4A07200C5}
[2011/10/10 17:26:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{15BA36FC-E267-4315-B6D8-4B67C074CD16}
[2011/10/10 17:25:50 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B58A9741-8E1C-4B81-AEA2-A31F6006089C}
[2011/10/10 05:25:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F2C5BD47-335D-4F21-9AEC-03EA3E9F328D}
[2011/10/10 05:25:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{02D9E395-17AD-4759-973F-1BD34112D35E}
[2011/10/09 17:25:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{98F81106-B978-4FC7-9DD6-EAC4020886A1}
[2011/10/09 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{287F8A1C-4988-4995-90B2-FDBFC2E3BB2B}
[2011/10/09 05:24:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A12E1A15-2B35-4E2D-9025-97204EF4D04C}
[2011/10/09 05:24:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A0AC5230-54F9-4250-AB18-9374D4849C29}
[2011/10/08 17:24:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{98C66D56-39E5-422A-A0CD-F45B41B07044}
[2011/10/08 17:24:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3EEA039C-8C67-41CD-95CA-1EA7E2D6C516}
[2011/10/08 05:23:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{07952418-5AD2-48D0-A445-9B5A570DA4C4}
[2011/10/08 05:23:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1D1C6212-0364-431C-AB4E-CFE5D9A32F5C}
[2011/10/07 17:23:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{4189085C-5F8B-453E-A979-3250D8F99B4D}
[2011/10/07 17:23:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EB1F7C68-BF26-49FC-A5DF-49D5C7553349}
[2011/10/07 05:23:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{CF6D2F6B-B80D-4040-93C3-602CD109337C}
[2011/10/07 05:23:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{857B2201-BB20-44B7-8823-0DEA85701A4A}
[2011/10/06 17:22:47 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A8F44B56-8077-44AB-B26B-8B5547A3FD3C}
[2011/10/06 17:22:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{0EBB3F86-BD15-4173-963C-26BF96FE36A1}
[2011/10/06 05:22:23 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E2145067-BF04-4B7B-9EF8-E6C8D9720B85}
[2011/10/06 05:22:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{FED5C3EF-701E-44DC-BC02-5DB2920A4793}
[2011/06/27 10:56:06 | 000,305,152 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhcp.dll
[2011/05/30 09:33:55 | 001,417,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyserv.dll
[2011/05/30 09:33:55 | 001,099,264 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyusb1.dll
[2011/05/30 09:33:55 | 000,695,808 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomc.dll
[2011/05/30 09:33:55 | 000,659,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhbn3.dll
[2011/05/30 09:33:55 | 000,566,192 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycoms.exe
[2011/05/30 09:33:55 | 000,487,424 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcylmpm.dll
[2011/05/30 09:33:55 | 000,409,600 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypmui.dll
[2011/05/30 09:33:55 | 000,249,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomm.dll
[2011/05/30 09:33:55 | 000,238,592 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyinpa.dll
[2011/05/30 09:33:55 | 000,235,952 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycfg.exe
[2011/05/30 09:33:55 | 000,233,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyih.exe
[2011/05/30 09:33:55 | 000,226,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyiesc.dll
[2011/05/30 09:33:55 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyppls.exe
[2011/05/30 09:33:55 | 000,035,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyprox.dll
[2011/05/30 09:33:55 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypplc.dll
[2011/05/27 23:06:47 | 000,270,128 | ---- | C] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/05 02:43:30 | 000,000,512 | ---- | M] () -- C:\Users\Magical\Desktop\MBR.dat
[2011/11/05 02:41:17 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011/11/05 02:32:22 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/05 02:32:22 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/05 02:31:16 | 001,563,952 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011/11/05 02:23:58 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/11/05 02:23:55 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/05 02:23:43 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/05 02:23:40 | 523,116,543 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/05 02:15:57 | 004,284,246 | R--- | M] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011/11/03 23:32:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 23:16:51 | 000,727,182 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/03 23:16:51 | 000,616,356 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/03 23:16:51 | 000,106,478 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/03 23:07:21 | 004,285,928 | ---- | M] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 23:03:23 | 000,066,464 | ---- | M] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 19:40:48 | 000,016,432 | ---- | M] () -- C:\Windows\SysNative\lsdelete.exe
[2011/11/03 18:50:47 | 000,274,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/03 18:44:38 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | ---- | M] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011/11/03 18:34:02 | 000,000,112 | ---- | M] () -- C:\ProgramData\ljRkx05F5.dat
[2011/11/03 18:11:55 | 000,000,456 | ---- | M] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,296 | ---- | M] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,192 | ---- | M] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/11/03 18:06:54 | 000,000,685 | ---- | M] () -- C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/03 18:06:54 | 000,000,661 | ---- | M] () -- C:\Users\Magical\Desktop\System Restore.lnk
[2011/11/03 12:17:41 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/11/03 12:17:41 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/10/28 19:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/05 02:43:30 | 000,000,512 | ---- | C] () -- C:\Users\Magical\Desktop\MBR.dat
[2011/11/05 02:23:55 | 000,000,408 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/05 02:21:02 | 000,002,490 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/11/05 02:21:02 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/11/05 02:21:02 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2011/11/05 02:21:02 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/11/05 02:21:02 | 000,001,462 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/11/05 02:21:02 | 000,001,378 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/11/05 02:21:02 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/11/05 02:21:02 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/11/05 02:21:02 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011/11/05 02:21:02 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/11/05 02:21:02 | 000,001,309 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/11/05 02:21:02 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011/11/05 02:21:02 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011/11/05 02:21:02 | 000,001,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2011/11/05 02:21:02 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2011/11/05 02:21:02 | 000,000,959 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2011/11/05 02:19:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/11/05 02:19:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/11/05 02:19:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/11/05 02:19:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/11/05 02:19:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/11/03 23:32:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/11/03 21:04:28 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2011/11/03 18:47:29 | 004,285,928 | ---- | C] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 18:47:25 | 000,066,464 | ---- | C] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 18:44:38 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | ---- | C] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011/11/03 18:31:47 | 000,000,112 | ---- | C] () -- C:\ProgramData\ljRkx05F5.dat
[2011/11/03 18:06:56 | 000,000,192 | ---- | C] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/11/03 18:06:55 | 000,000,296 | ---- | C] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/11/03 18:06:54 | 000,000,685 | ---- | C] () -- C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/03 18:06:54 | 000,000,661 | ---- | C] () -- C:\Users\Magical\Desktop\System Restore.lnk
[2011/11/03 18:06:49 | 000,000,456 | ---- | C] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/07/17 19:38:27 | 000,013,082 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/07/17 19:38:20 | 004,022,504 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe
[2011/07/17 19:38:20 | 000,018,123 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/06/19 20:45:14 | 001,007,358 | ---- | C] () -- C:\Program Files\Windows-Theme-Manager-Setup.exe
[2011/06/02 14:12:06 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/05/30 09:33:55 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxcycomx.dll
[2011/05/30 09:33:55 | 000,194,048 | ---- | C] () -- C:\Windows\SysWow64\lxcyinst.dll
[2011/05/30 08:25:56 | 000,734,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/02 21:28:30 | 000,007,609 | ---- | C] () -- C:\Users\Magical\AppData\Local\resmon.resmoncfg
[2011/05/02 11:19:02 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/05/02 11:19:02 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/05/01 20:52:30 | 000,000,600 | ---- | C] () -- C:\Users\Magical\AppData\Roaming\winscp.rnd
[2011/05/01 18:30:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/05/01 18:09:29 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/10 07:57:24 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/10/27 12:02:31 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:0B9176C0

< End of report >


Extra's:

OTL Extras logfile created on: 11/5/2011 2:47:34 AM - Run 2
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 3.90 Gb Available Physical Memory | 65.17% Memory free
11.96 Gb Paging File | 9.87 Gb Available in Paging File | 82.48% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 888.13 Gb Free Space | 96.23% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 287.00 Gb Free Space | 58.76% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 153.22 Gb Free Space | 78.45% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 217.78 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive M: | 434.57 Gb Total Space | 98.56 Gb Free Space | 22.68% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = ComFile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\SysWow64\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\SysWow64\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\SysWow64\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\SysWow64\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\SysWow64\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\SysWow64\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A125C1EA-3D24-D4CC-318A-CCBC62663E1B}" = AMD Drag and Drop Transcoding
"{B7F9AFA9-C855-0AF4-3238-E338D16DE1E6}" = ccc-utility64
"{CB703E0A-443F-4612-64FE-8D1FAF68C0C9}" = ATI AVIVO64 Codecs
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F4DBEFD1-1E91-64A9-520E-C68D19E51A3A}" = ATI Catalyst Install Manager
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Lexmark 3400 Series" = Lexmark 3400 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"TeraCopy_is1" = TeraCopy 2.12
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0764244D-B5B4-FE84-72EB-D30D020AA0BF}" = CCC Help Italian
"{0AB0FD1B-0C6C-A192-1ED5-F4800F00B773}" = CCC Help Hungarian
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AA583C0-4BAD-D55D-3AB6-8A5A141B7A26}" = CCC Help Chinese Standard
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2274ED79-8F51-3EBA-A505-BCE355090EA6}" = CCC Help Thai
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3368F8D0-CC3A-4872-B585-04748C0D1D8E}" = CCC Help German
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3668C840-CA7C-F7AC-816B-3B8F7B7CA413}" = CCC Help Korean
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51EB1680-EDB7-6874-7129-4C983D9E9D74}" = CCC Help Norwegian
"{55E2E85A-48F9-B94D-5407-DF7869C88C37}" = CCC Help Portuguese
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5D3435E8-AAC5-CD53-585A-EE0ECC0C7D65}" = CCC Help Spanish
"{63E65FF4-5CCB-EDB0-5327-2F859E309BA4}" = CCC Help English
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C2B0E3E-3625-4FAB-B7D5-A516218741A5}" = CCC Help Finnish
"{6D841B2A-6629-AD72-33A2-92F81D1C8F92}" = CCC Help Swedish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{8229EB52-BF74-E006-8D4E-A6735737DCC7}" = Catalyst Control Center Localization All
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91FD9139-EFE6-81AD-3CDB-0EC531953BDB}" = CCC Help Czech
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A8CF74A-7CDD-096C-81FC-CAA4A25C6B96}" = CCC Help Chinese Traditional
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AD3D31C4-DF57-D055-5BE3-EF602E2C51C1}" = CCC Help Dutch
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6F14A1D-A1A2-2812-9DF2-6BDE53821884}" = Catalyst Control Center InstallProxy
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D019764D-4690-1790-05C1-8BCB6E0DAA62}" = CCC Help Greek
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2223157-A5F5-061C-88E1-681DCD8558AF}" = CCC Help Japanese
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE35B2C9-35AF-E4B6-3F0E-DDC3417C0365}" = CCC Help Polish
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E36E864B-BFB6-440A-9A23-2B0BEDE59A92}" = MultiScreen
"{E43196CF-182A-4D9E-9CE7-69616DBEE3B0}" = Ad-Aware
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E75B5672-3D53-1D60-6B4B-9F74342BD12B}" = ccc-core-static
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C9EB74-EF5B-9154-6619-663FDE7768FE}" = CCC Help Russian
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7D5760B-4C4C-C6DE-42F1-94515A5C9167}" = CCC Help French
"{FAC20146-EBEA-867B-24CF-5E678EB5E216}" = CCC Help Danish
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer Registration" = Acer Registration
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_7" = AIM 7
"Audacity_is1" = Audacity 1.2.6
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"FileZilla Client" = FileZilla Client 3.5.0
"foobar2000" = foobar2000 v1.1.6
"Hotkey Utility" = Hotkey Utility
"IceChat_is1" = IceChat 7.70 (Build 20101031)
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"LastFM_is1" = Last.fm 1.5.4.27091
"Lexmark 3400 Series" = Lexmark 3400 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"Notepad++" = Notepad++
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PuTTY_is1" = PuTTY version 0.60
"RealVNC_is1" = VNC Free Edition 4.1.3
"ThemeManager" = Theme Manager v 1.0
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
"winscp3_is1" = WinSCP 4.3.3
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 9/13/2011 7:46:27 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/13/2011 7:46:44 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/18/2011 9:19:19 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/18/2011 9:19:41 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/19/2011 6:33:20 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/19/2011 6:33:33 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/23/2011 6:30:17 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/23/2011 6:30:34 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 9/28/2011 8:24:09 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 9/28/2011 8:24:26 PM | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 9/19/2011 12:00:15 PM | Computer Name = Broomstick | Source = DCOM | ID = 10005
Description =

Error - 9/19/2011 12:00:15 PM | Computer Name = Broomstick | Source = Service Control Manager | ID = 7000
Description = The Windows Search service failed to start due to the following error:
%%1053

Error - 9/25/2011 1:01:47 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 10/2/2011 1:01:57 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 10/9/2011 1:01:52 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 10/16/2011 1:02:04 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 10/23/2011 1:02:17 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 10/30/2011 2:02:25 PM | Computer Name = Broomstick | Source = VDS Basic Provider | ID = 33554433
Description =

Error - 11/3/2011 1:09:11 PM | Computer Name = Broomstick | Source = Service Control Manager | ID = 7000
Description = The Windows Firewall Authorization Driver service failed to start
due to the following error: %%183

Error - 11/3/2011 1:09:11 PM | Computer Name = Broomstick | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Windows Firewall Authorization
Driver service which failed to start because of the following error: %%183


< End of report >

I hope I did all that correctly! In any case it was good to see all my files and photo's back :yes:

Thanks so much for your help so far :)
  • 0

#5
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
Run Combofix one more time. I want to be sure the the C:\Windows\System64 folder does not come back.


Copy the text in the code box by highlighting and Ctrl + c


:processes
killallprocesses

:Services


:OTL
[2011/11/03 18:34:02 | 000,000,112 | ---- | M] () -- C:\ProgramData\ljRkx05F5.dat
[2011/11/03 18:11:55 | 000,000,456 | ---- | M] () -- C:\ProgramData\6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,296 | ---- | M] () -- C:\ProgramData\~6DSS92c31Apgjk
[2011/11/03 18:11:03 | 000,000,192 | ---- | M] () -- C:\ProgramData\~6DSS92c31Apgjkr
[2011/11/03 18:06:54 | 000,000,685 | ---- | M] () -- C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk
[2011/11/03 18:06:54 | 000,000,661 | ---- | M] () -- C:\Users\Magical\Desktop\System Restore.lnk

:files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C
rmdir /s \windows\assemby\tmp /c
mkdir \windows\assemby\tmp /c
     
:Commands
[EMPTYJAVA]
[purity]
[CREATERESTOREPOINT] 
[Reboot]


then Rightclick on OTL and select Run As Administrator to start. Under the Custom Scans/Fixes box at the bottom, paste (ctrl +v) the text. Verify that you got it all and Then click the RUN FIX button (NOT THE QUICK SCAN button!) at the top
Let the program run unhindered, OTL will reboot the PC when it is done. Please Save the log then Copy and paste it into a reply.

Download, Save and Right click on unhide.exe and Run As Administrator from

http://download.blee...nler/unhide.exe


Open OTL again and do a Quickscan and post the log.
  • 0

#6
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hiya,

Sorry it took so long for me to get back to you - I'd started OTL and put the text in at almost 4 am and set it going (I'd clicked the Run Fix button)- when it hadn't completed at 4:30 I decided to call it a night and see if it was finished in the morning so turned the screen off but left the computer running, it's not though. It's stuck on "processing [2011/11/03 18:06:54 | 000,000,661 |----| M] 0c:\Users\Magical\Desktop\System Restore.lnk..

The cmd window says: c:\Program Files (x86)\Mozilla Firefox>rmdir /s \windows\assemby\tmp 1>"C:\Users\Magical\Downloads\cmd.txt"

I wasn't sure if I should close it or not so left it open for now (helped getting the text I just gave you anyway :) ) and the only thing I have started is FF so I could let you know what was going on.

I did run Combofix first and have included the log for that - it didn't restart the computer this time, which it had the first time.

Attached Files

  • Attached File  log.txt   24.57KB   95 downloads

Edited by Magicless, 05 November 2011 - 04:07 AM.

  • 0

#7
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
Go ahead and kill OTL. It should not take so long. Usually just 30 minutes at most.


Copy the text in the code box:


netsvcs
drivers32
%SYSTEMDRIVE%\*.*
%systemroot%\Fonts\*.com
%systemroot%\Fonts\*.dll
%systemroot%\Fonts\*.ini
%systemroot%\Fonts\*.ini2
%systemroot%\Fonts\*.exe
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\REPAIR\*.bak1
%systemroot%\REPAIR\*.ini
%systemroot%\system32\*.jpg 
%systemroot%\*.jpg 
%systemroot%\*.png 
%systemroot%\*.scr
%systemroot%\*._sy
%APPDATA%\Adobe\Update\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%APPDATA%\Microsoft\*.*
%PROGRAMFILES%\*.*
%APPDATA%\Update\*.*
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\System32\config\*.sav 
%PROGRAMFILES%\bak. /s
%systemroot%\system32\bak. /s
%ALLUSERSPROFILE%\Start Menu\*.lnk /x 
%systemroot%\system32\config\systemprofile\*.dat /x
%systemroot%\*.config
%systemroot%\system32\*.db
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
/md5start
DMIcall.sys
beep.sys
Netshell.dll
netcfgx.dll
Netman.dll
connect.dll
mswsock.dll
mmswsock.dll 
/md5stop
mdnsNSP.dll
c:\windows\assembly\tmp\*.* 

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes

Select the All option in the Extra Registry group then Run Scan. Copy and paste the log into a reply.



Combofix is looking much better.

Ron
  • 0

#8
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
hiya,

Thanks for your reply :)

ok I killed OTL, it insisted on restarting and then gave me this log:

========== PROCESSES ==========
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
C:\ProgramData\ljRkx05F5.dat moved successfully.
C:\ProgramData\6DSS92c31Apgjk moved successfully.
C:\ProgramData\~6DSS92c31Apgjk moved successfully.
C:\ProgramData\~6DSS92c31Apgjkr moved successfully.
C:\Users\Magical\Application Data\Microsoft\Internet Explorer\Quick Launch\System Restore.lnk moved successfully.
C:\Users\Magical\Desktop\System Restore.lnk moved successfully.
========== FILES ==========
< xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C >
0 File(s) copied
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
< xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C >
0 File(s) copied
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
< xcopy %Temp%\smtmp\3 "%AppData%\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar" /H /I /S /Y /C >
0 File(s) copied
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
< xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C >
0 File(s) copied
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
< rmdir /s \windows\assemby\tmp /c >
\windows\assemby\tmp, Are you sure (Y/N)?
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
< mkdir \windows\assemby\tmp /c >
C:\Users\Magical\Downloads\cmd.bat deleted successfully.
C:\Users\Magical\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Magical
->Java cache emptied: 268924 bytes

User: Public

Total Java Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.31.0 log created on 11052011_034914

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...



I started OTL running but it stalled and i had some fun and games with my internet connection which I was able to fix. Once the internet connection was back OTL started up again.

Logs after the second scan:

OTL logfile created on: 11/5/2011 4:57:40 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 4.18 Gb Available Physical Memory | 69.89% Memory free
11.96 Gb Paging File | 9.99 Gb Available in Paging File | 83.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 888.50 Gb Free Space | 96.27% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 287.00 Gb Free Space | 58.76% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 153.22 Gb Free Space | 78.45% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 217.78 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive M: | 434.57 Gb Total Space | 98.56 Gb Free Space | 22.68% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2011/11/04 09:18:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Magical\Downloads\OTL.com
PRC - [2011/10/28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe
PRC - [2011/10/28 19:35:26 | 001,187,072 | ---- | M] (Lavasoft Limited) -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe
PRC - [2011/09/28 09:32:23 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/27 23:06:47 | 000,270,128 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe
PRC - [2011/05/25 21:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/05/03 16:43:14 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/10/05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/10/05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/09/14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/14 02:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/06/01 09:17:48 | 005,252,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2010/05/27 03:41:24 | 000,349,552 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010/03/11 06:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010/03/11 06:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
PRC - [2009/05/01 12:54:46 | 000,082,600 | ---- | M] (Lexmark International Inc.) -- C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe
PRC - [2009/05/01 12:54:44 | 000,291,496 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/01/01 22:22:02 | 003,739,648 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Talk\googletalk.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/03 20:00:31 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll
MOD - [2011/11/03 20:00:31 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll
MOD - [2011/11/03 18:53:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/11/03 18:52:54 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/11/03 18:52:46 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/11/03 18:52:30 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/11/03 18:52:25 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/11/03 18:52:21 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/11/03 18:52:20 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/11/03 18:51:31 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/09/28 09:32:23 | 001,015,256 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2011/08/28 04:48:57 | 006,277,280 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/12/03 04:44:54 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
MOD - [2010/06/01 09:17:46 | 000,929,792 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
MOD - [2009/08/11 12:56:52 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MGResEng.dll
MOD - [2009/08/11 12:54:36 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\SmartMouseDll.dll
MOD - [2009/08/11 12:54:28 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\TitleBar.dll
MOD - [2009/05/01 12:54:44 | 000,291,496 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe
MOD - [2006/08/08 14:54:18 | 000,278,528 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcyscw.dll
MOD - [2006/05/25 15:20:44 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\iptk.dll
MOD - [2006/02/13 08:04:20 | 000,143,360 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\lxcydrec.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/01/10 10:03:43 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010-09-22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009-07-14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011-10-28 19:35:26 | 002,152,152 | ---- | M] (Lavasoft Limited) [Auto | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2011-08-31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011-06-06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010-10-05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010-10-05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010-09-14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010-09-14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010-09-14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010-05-27 03:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010-03-18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010-01-08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009-06-10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009-01-26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011-10-28 19:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\Lbd.sys -- (Lbd)
DRV:64bit: - [2011-08-31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011-03-11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011-03-11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011-01-15 17:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2011-01-10 10:31:20 | 008,283,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011-01-10 09:28:18 | 000,295,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010-12-21 09:31:00 | 000,316,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010-12-16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010-11-20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010-11-20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010-11-17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010-10-19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010-09-14 04:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010-09-14 04:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010-09-14 04:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010-09-14 04:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010-09-14 02:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010-08-11 04:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2009-07-14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009-07-14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009-07-14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009-06-10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009-06-10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009-06-10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009-06-10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009-06-03 03:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009-06-03 03:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009-06-03 03:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV - [2011-11-03 19:40:49 | 000,017,152 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys -- (Lavasoft Kernexplorer)
DRV - [2009-07-14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:4.0.2
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.12
FF - prefs.js..extensions.enabledItems: {b442f4c0-c292-4998-aabe-48608a73ba75}:1.0.1.3
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:9
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.4.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.3.50136
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: tabcounter@morac:1.8.8
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {7d575baa-b543-11dc-8314-0800200c9a66}:2.0.5
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.6


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011-10-16 21:03:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.23\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011-09-28 09:32:23 | 000,000,000 | ---D | M]

[2011-05-01 18:09:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Extensions
[2011-11-04 23:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions
[2011-05-02 12:16:00 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011-05-02 12:15:59 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2011-09-13 12:21:34 | 000,000,000 | ---D | M] (RSS Ticker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
[2011-08-26 08:18:32 | 000,000,000 | ---D | M] (Integrated Gmail) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2011-06-16 01:41:34 | 000,000,000 | ---D | M] (Favicon Picker 2) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
[2011-06-06 01:55:11 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2011-05-02 12:16:00 | 000,000,000 | ---D | M] (BitmeTV Menu) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{633b7287-e788-4131-a31c-db09d8ebbe51}(2)
[2011-05-02 12:16:00 | 000,000,000 | ---D | M] (DNS Flusher) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{7d575baa-b543-11dc-8314-0800200c9a66}
[2011-08-31 21:54:04 | 000,000,000 | ---D | M] (Showcase) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2011-08-26 13:00:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2011-05-01 21:32:21 | 000,000,000 | ---D | M] (Smartest Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{b442f4c0-c292-4998-aabe-48608a73ba75}
[2011-10-01 01:21:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011-10-16 21:04:20 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011-05-02 12:16:00 | 000,000,000 | ---D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011-10-01 01:21:41 | 000,000,000 | ---D | M] (Add-on Compatibility Reporter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-05-02 12:15:57 | 000,000,000 | ---D | M] (DNS Cache) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-10-01 01:21:40 | 000,000,000 | ---D | M] (Element Hiding Helper for Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-05-02 12:10:15 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-08-25 20:57:40 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-09-13 12:21:34 | 000,000,000 | ---D | M] (Webmail Ad Blocker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-09-19 01:13:54 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-09-19 01:13:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-05-02 12:10:16 | 000,000,000 | ---D | M] (Smart Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-05-02 12:10:17 | 000,000,000 | ---D | M] (Tab Counter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\tabcounter@morac
[2011-10-01 01:21:41 | 000,000,000 | ---D | M] (BlackFox V1-Blue) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-08-26 13:00:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011-11-01 10:08:47 | 000,001,032 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\exigo.xml
[2010-04-30 18:04:17 | 000,001,504 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\imdb.xml
[2010-04-24 17:18:48 | 000,002,352 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\search-firefox-addons.xml
[2010-05-25 00:38:29 | 000,004,140 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\youtube.xml
[2011-11-04 23:35:50 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011-05-01 20:50:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011-09-28 09:35:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011-05-04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011-04-21 00:07:17 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011-04-21 00:07:17 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011-04-21 00:07:17 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011-04-21 00:07:17 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011-11-05 02:23:58 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [LXCYCATS] C:\Windows\SysNative\spool\DRIVERS\x64\3\LXCYtime.DLL (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [lxcymon.exe] C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe ()
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MultiScreen] C:\Program Files (x86)\MultiScreen\MultiScreen.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-02-22 11:24:38 | 000,000,000 | -H-- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (lsdelete)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2011-11-05 16:53:43 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C3FC1CF1-624F-4DC2-B9C3-ED0D2286541B}
[2011-11-05 16:52:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011-11-05 16:50:08 | 000,000,000 | ---D | C] -- C:\Windows\assemby
[2011-11-05 03:49:14 | 000,000,000 | ---D | C] -- C:\_OTL
[2011-11-05 03:44:27 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011-11-05 02:41:19 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011-11-05 02:31:20 | 001,563,952 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011-11-05 02:19:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011-11-05 02:19:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011-11-05 02:19:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011-11-05 02:19:25 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011-11-05 02:19:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-11-05 02:13:40 | 004,284,246 | R--- | C] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011-11-05 02:04:45 | 000,000,000 | ---D | C] -- C:\Users\Magical\Desktop\lost
[2011-11-04 20:34:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A74238AF-F985-4C54-B753-3C3E0B5FF6F7}
[2011-11-04 20:34:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1E75554F-0FA9-4128-8F2D-A41333AD2C7A}
[2011-11-04 08:34:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A48E29C5-8D30-46E1-B3DD-A4ACBB35EE02}
[2011-11-04 08:33:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CBBD8B9-07D0-4110-B258-D84D562E514F}
[2011-11-03 23:33:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Roaming\Malwarebytes
[2011-11-03 23:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011-11-03 23:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011-11-03 23:32:42 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011-11-03 23:32:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011-11-03 19:32:52 | 000,069,376 | ---- | C] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys
[2011-11-03 19:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011-11-03 19:32:15 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011-11-03 18:43:56 | 000,200,976 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys
[2011-11-03 18:39:26 | 000,096,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2011-11-03 18:39:26 | 000,072,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2011-11-03 18:39:25 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll
[2011-11-03 18:39:25 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll
[2011-11-03 18:39:24 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2011-11-03 18:39:23 | 002,309,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2011-11-03 18:39:23 | 000,818,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll
[2011-11-03 18:39:23 | 000,716,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll
[2011-11-03 18:39:23 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2011-11-03 18:37:31 | 000,613,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisdecd.dll
[2011-11-03 18:37:31 | 000,465,408 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisdecd.dll
[2011-11-03 18:37:31 | 000,108,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\psisrndr.ax
[2011-11-03 18:37:31 | 000,075,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\psisrndr.ax
[2011-11-03 18:37:26 | 000,861,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleaut32.dll
[2011-11-03 18:37:26 | 000,331,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\oleacc.dll
[2011-11-03 17:50:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D4C94249-A4BD-4B7D-887D-884E143AAD16}
[2011-11-03 05:49:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D63D7844-9801-42DD-ADE6-4831ED93C8D2}
[2011-11-02 17:49:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{87E3EBB1-7FF7-4901-99D7-4DAF46AAF9D3}
[2011-11-02 05:48:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{43EDBA0A-6DD0-4C23-B7E8-B1B0A86B9334}
[2011-11-01 17:47:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EE36652D-BAFE-4F17-9AD5-3E4DF5765A31}
[2011-11-01 05:47:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{637D5548-7DE6-49B0-8549-1D983001FA07}
[2011-10-31 17:46:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F784FAAE-CC16-49BD-947A-884C8279F464}
[2011-10-31 11:18:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\Documents\Stuff that used to be in dropbox
[2011-10-31 05:46:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{92CBC907-2386-47DA-9958-63C7EFF57ED9}
[2011-10-30 17:45:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{35E733DD-0BA5-440F-BEC9-749E4867548A}
[2011-10-30 05:44:49 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CC4A491-409E-49DE-8278-786C38FA7BDC}
[2011-10-29 17:44:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E6782204-61AC-493C-8AEE-B5AE825874DB}
[2011-10-29 05:43:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3DC0B751-9BC6-48F2-BF39-B648D11D53A9}
[2011-10-28 17:43:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{0EB83299-8115-4D51-BAEE-DDCE4741254F}
[2011-10-28 05:42:27 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F6424066-E600-4DB4-9273-8C01C900025C}
[2011-10-27 17:41:51 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{72A3BAC0-E766-4697-B006-B74608057CE6}
[2011-10-27 05:41:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{FEC61A44-90AF-4347-AB20-B68D9194669F}
[2011-10-26 17:40:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B0B050C5-5F13-4BAD-A334-9AE589773182}
[2011-10-26 05:40:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{356B0CFB-26EC-426E-BAA3-CE05C2C1E2D8}
[2011-10-25 17:39:32 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{359FCEBE-7990-4F97-8198-6428C2F088D8}
[2011-10-25 05:39:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3423A6EF-E8A0-4978-BDF1-A6F60AC59B71}
[2011-10-24 17:38:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C4A081CD-94AF-4B21-B42F-5497DE775F41}
[2011-10-24 09:28:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\Microsoft Games
[2011-10-24 05:38:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1B2D8A7F-970E-4E8D-AF8B-A9C01CBE25A5}
[2011-10-23 17:37:31 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{057FD8D5-C992-49A9-8440-32AE88F0147D}
[2011-10-23 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74AB5993-50A0-4A03-B589-BBAB27058FAA}
[2011-10-22 17:36:34 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EF1C193A-AA47-4766-858B-451EE4B2264B}
[2011-10-22 05:36:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C2455C65-BAA2-4CDE-AB5C-564F2B642691}
[2011-10-21 17:35:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4811046-0A7C-4EB3-AE30-71FDF60F6D3A}
[2011-10-21 05:35:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AB1B270B-9B8F-4DFB-AA09-EFD20202A95F}
[2011-10-20 17:34:42 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{96729716-95F0-4756-B7F6-733504C3DB04}
[2011-10-20 05:34:15 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E18A4DE2-43C9-4E85-A2F7-B9958155721C}
[2011-10-19 17:33:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{914C5AF3-7A88-4746-827F-D8796D7416B3}
[2011-10-19 05:33:22 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5B50832A-E4C7-4B3A-A7C3-6E89EB1C6274}
[2011-10-18 17:32:56 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A6BB88B6-104F-415F-8CCD-DC9481BBF595}
[2011-10-18 05:32:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EFEB572C-D1D9-4530-8431-CA99C5A2B1BA}
[2011-10-17 17:32:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3F7D4546-3096-44C8-95F8-66A13E36889A}
[2011-10-17 05:31:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F04A283D-3DF0-4E47-97F6-B0F60FF22E74}
[2011-10-16 17:31:13 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C77AB15E-D2D2-4D01-AAF2-DAE89EDF0681}
[2011-10-16 17:31:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D32288D7-0AD4-46B7-951E-68DF21812BC2}
[2011-10-16 05:30:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{49224AAA-B72B-48D4-AE4D-0E96E06D77E2}
[2011-10-16 05:30:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9B2182A1-7784-4409-B137-583188119E0A}
[2011-10-15 17:30:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{12170724-B536-47A0-9536-1D73EE3EC65F}
[2011-10-15 17:29:58 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{41CE4D19-B15E-4373-A390-12C55057950E}
[2011-10-15 05:29:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9AEFF161-36B8-48F0-B59D-4E1EFC764BA3}
[2011-10-15 05:29:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{71C7E389-A36B-4DB6-BF3B-BF4F172E8B45}
[2011-10-14 17:29:19 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C5857948-6208-4D04-A183-16EA4B94E248}
[2011-10-14 17:29:08 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{15AF7EB9-E426-4F55-AC62-471E12838F1C}
[2011-10-14 05:28:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74E29617-D529-4D3B-BDC4-E70078294605}
[2011-10-14 05:28:43 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7FB1650C-7722-4E51-9422-0F809C002631}
[2011-10-13 17:28:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{79B49105-364E-4824-9B35-8CD2544A0E5D}
[2011-10-13 17:28:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E9EA43A9-B45F-4857-A27B-9461F3ABBA75}
[2011-10-13 05:28:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4F7B2F1-8E62-45A4-83AF-3C9386A96FA0}
[2011-10-13 05:27:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AC2C66DF-C97F-4810-8CE5-91052FB079DB}
[2011-10-12 17:27:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7F16F78E-F53D-4015-A913-CAE75C349B20}
[2011-10-12 17:27:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D9EE5708-1E40-4763-983A-BE05C43E4F0E}
[2011-10-12 05:27:16 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A9161CE8-0324-47C7-8821-4A20A3F34C92}
[2011-10-12 05:27:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{99D0AE6F-359B-4118-919D-FF95612EB0D7}
[2011-10-11 17:26:52 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D6294A31-0536-42BA-8386-2D389D2F4592}
[2011-10-11 17:26:41 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{CC10FF82-BAEF-44B9-AEF7-CCCA3F22F520}
[2011-10-11 05:26:28 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D252F5D3-437A-4786-9D3E-97C9976296CB}
[2011-10-11 05:26:16 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{35AE3E6C-147D-468B-BC8D-BAE4A07200C5}
[2011-10-10 17:26:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{15BA36FC-E267-4315-B6D8-4B67C074CD16}
[2011-10-10 17:25:50 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B58A9741-8E1C-4B81-AEA2-A31F6006089C}
[2011-10-10 05:25:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F2C5BD47-335D-4F21-9AEC-03EA3E9F328D}
[2011-10-10 05:25:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{02D9E395-17AD-4759-973F-1BD34112D35E}
[2011-10-09 17:25:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{98F81106-B978-4FC7-9DD6-EAC4020886A1}
[2011-10-09 17:25:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{287F8A1C-4988-4995-90B2-FDBFC2E3BB2B}
[2011-10-09 05:24:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A12E1A15-2B35-4E2D-9025-97204EF4D04C}
[2011-10-09 05:24:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A0AC5230-54F9-4250-AB18-9374D4849C29}
[2011-10-08 17:24:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{98C66D56-39E5-422A-A0CD-F45B41B07044}
[2011-10-08 17:24:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3EEA039C-8C67-41CD-95CA-1EA7E2D6C516}
[2011-10-08 05:23:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{07952418-5AD2-48D0-A445-9B5A570DA4C4}
[2011-10-08 05:23:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1D1C6212-0364-431C-AB4E-CFE5D9A32F5C}
[2011-10-07 17:23:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{4189085C-5F8B-453E-A979-3250D8F99B4D}
[2011-10-07 17:23:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EB1F7C68-BF26-49FC-A5DF-49D5C7553349}
[2011-10-07 05:23:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{CF6D2F6B-B80D-4040-93C3-602CD109337C}
[2011-10-07 05:23:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{857B2201-BB20-44B7-8823-0DEA85701A4A}
[2011-10-06 17:22:47 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A8F44B56-8077-44AB-B26B-8B5547A3FD3C}
[2011-10-06 17:22:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{0EBB3F86-BD15-4173-963C-26BF96FE36A1}
[2011-06-27 10:56:06 | 000,305,152 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhcp.dll
[2011-05-30 09:33:55 | 001,417,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyserv.dll
[2011-05-30 09:33:55 | 001,099,264 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyusb1.dll
[2011-05-30 09:33:55 | 000,695,808 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomc.dll
[2011-05-30 09:33:55 | 000,659,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhbn3.dll
[2011-05-30 09:33:55 | 000,566,192 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycoms.exe
[2011-05-30 09:33:55 | 000,487,424 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcylmpm.dll
[2011-05-30 09:33:55 | 000,409,600 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypmui.dll
[2011-05-30 09:33:55 | 000,249,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomm.dll
[2011-05-30 09:33:55 | 000,238,592 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyinpa.dll
[2011-05-30 09:33:55 | 000,235,952 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycfg.exe
[2011-05-30 09:33:55 | 000,233,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyih.exe
[2011-05-30 09:33:55 | 000,226,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyiesc.dll
[2011-05-30 09:33:55 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyppls.exe
[2011-05-30 09:33:55 | 000,035,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyprox.dll
[2011-05-30 09:33:55 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypplc.dll
[2011-05-27 23:06:47 | 000,270,128 | ---- | C] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe

========== Files - Modified Within 30 Days ==========

[2011-11-05 16:59:49 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011-11-05 16:59:49 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011-11-05 16:56:18 | 000,735,702 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011-11-05 16:56:18 | 000,620,608 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011-11-05 16:56:18 | 000,110,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011-11-05 16:51:50 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011-11-05 16:51:47 | 523,116,543 | -HS- | M] () -- C:\hiberfil.sys
[2011-11-05 02:43:30 | 000,000,512 | ---- | M] () -- C:\Users\Magical\Desktop\MBR.dat
[2011-11-05 02:41:17 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011-11-05 02:31:16 | 001,563,952 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011-11-05 02:23:58 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011-11-05 02:15:57 | 004,284,246 | R--- | M] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011-11-03 23:32:45 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-11-03 23:07:21 | 004,285,928 | ---- | M] () -- C:\Users\Magical\AppData\Local\census.cache
[2011-11-03 23:03:23 | 000,066,464 | ---- | M] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011-11-03 19:40:48 | 000,016,432 | ---- | M] () -- C:\Windows\SysNative\lsdelete.exe
[2011-11-03 18:50:47 | 000,274,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011-11-03 18:44:38 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011-11-03 18:43:17 | 000,000,036 | ---- | M] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011-11-03 12:17:41 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011-11-03 12:17:41 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011-10-28 19:35:28 | 000,069,376 | ---- | M] (Lavasoft AB) -- C:\Windows\SysNative\drivers\Lbd.sys

========== Files Created - No Company Name ==========

[2011-11-05 02:43:30 | 000,000,512 | ---- | C] () -- C:\Users\Magical\Desktop\MBR.dat
[2011-11-05 02:21:02 | 000,002,490 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011-11-05 02:21:02 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011-11-05 02:21:02 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2011-11-05 02:21:02 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011-11-05 02:21:02 | 000,001,462 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011-11-05 02:21:02 | 000,001,378 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011-11-05 02:21:02 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011-11-05 02:21:02 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011-11-05 02:21:02 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011-11-05 02:21:02 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011-11-05 02:21:02 | 000,001,309 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011-11-05 02:21:02 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011-11-05 02:21:02 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011-11-05 02:21:02 | 000,001,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2011-11-05 02:21:02 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2011-11-05 02:21:02 | 000,000,959 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2011-11-05 02:19:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011-11-05 02:19:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011-11-05 02:19:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011-11-05 02:19:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011-11-05 02:19:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011-11-03 23:32:45 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-11-03 21:04:28 | 000,016,432 | ---- | C] () -- C:\Windows\SysNative\lsdelete.exe
[2011-11-03 18:47:29 | 004,285,928 | ---- | C] () -- C:\Users\Magical\AppData\Local\census.cache
[2011-11-03 18:47:25 | 000,066,464 | ---- | C] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011-11-03 18:44:38 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011-11-03 18:43:17 | 000,000,036 | ---- | C] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011-07-17 19:38:27 | 000,013,082 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011-07-17 19:38:20 | 004,022,504 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe
[2011-07-17 19:38:20 | 000,018,123 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011-06-19 20:45:14 | 001,007,358 | ---- | C] () -- C:\Program Files\Windows-Theme-Manager-Setup.exe
[2011-06-02 14:12:06 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011-05-30 09:33:55 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxcycomx.dll
[2011-05-30 09:33:55 | 000,194,048 | ---- | C] () -- C:\Windows\SysWow64\lxcyinst.dll
[2011-05-30 08:25:56 | 000,734,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011-05-02 21:28:30 | 000,007,609 | ---- | C] () -- C:\Users\Magical\AppData\Local\resmon.resmoncfg
[2011-05-02 11:19:02 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011-05-02 11:19:02 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011-05-01 20:52:30 | 000,000,600 | ---- | C] () -- C:\Users\Magical\AppData\Roaming\winscp.rnd
[2011-05-01 18:30:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011-05-01 18:09:29 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011-02-10 07:57:24 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010-10-27 12:02:31 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009-07-14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009-07-14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009-07-14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009-07-14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009-07-14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009-07-13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009-06-10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2011-11-05 16:51:47 | 000,003,233 | ---- | M] () -- C:\aaw7boot.log
[2010-10-27 12:38:49 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2011-11-05 03:44:25 | 000,025,162 | ---- | M] () -- C:\ComboFix.txt
[2011-11-05 16:51:47 | 523,116,543 | -HS- | M] () -- C:\hiberfil.sys
[2011-05-01 20:53:36 | 000,000,354 | ---- | M] () -- C:\IPH.PH
[2011-11-05 17:04:45 | 000,372,038 | ---- | M] () -- C:\lxcy.log
[2011-11-05 16:51:47 | 2129,145,855 | -HS- | M] () -- C:\pagefile.sys
[2010-10-27 12:03:21 | 000,002,188 | ---- | M] () -- C:\RHDSetup.log
[2011-11-05 02:32:35 | 000,020,570 | ---- | M] () -- C:\TDSSKiller.2.6.15.0_05.11.2011_02.31.59_log.txt

< %systemroot%\Fonts\*.com >
[2009-07-14 06:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009-07-14 06:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009-07-14 06:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009-07-14 06:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009-06-10 21:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011-05-13 14:42:24 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009-07-14 05:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >


< MD5 for: BEEP.SYS >
[2009-07-14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\SysNative\drivers\beep.sys
[2009-07-14 01:00:13 | 000,006,656 | ---- | M] (Microsoft Corporation) MD5=16A47CE2DECC9B099349A5F840654746 -- C:\Windows\winsxs\amd64_microsoft-windows-beepsys_31bf3856ad364e35_6.1.7600.16385_none_201592fa214e4f02\beep.sys

< MD5 for: CONNECT.DLL >
[2009-07-14 02:15:07 | 001,344,512 | ---- | M] (Microsoft Corporation) MD5=5FC2D30C05487B480C2A154D5D281BA0 -- C:\Windows\SysWOW64\connect.dll
[2009-07-14 02:15:07 | 001,344,512 | ---- | M] (Microsoft Corporation) MD5=5FC2D30C05487B480C2A154D5D281BA0 -- C:\Windows\winsxs\x86_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.1.7600.16385_none_64e4e40af80e0f24\connect.dll
[2009-07-14 02:40:23 | 001,393,152 | ---- | M] (Microsoft Corporation) MD5=ECE81C30343DC8A1FADA4BF1437F7ED1 -- C:\Windows\SysNative\connect.dll
[2009-07-14 02:40:23 | 001,393,152 | ---- | M] (Microsoft Corporation) MD5=ECE81C30343DC8A1FADA4BF1437F7ED1 -- C:\Windows\winsxs\amd64_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.1.7600.16385_none_c1037f8eb06b805a\connect.dll

< MD5 for: MSWSOCK.DLL >
[2010-11-20 14:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\ERDNT\cache64\mswsock.dll
[2010-11-20 14:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\SysNative\mswsock.dll
[2010-11-20 14:27:10 | 000,326,144 | ---- | M] (Microsoft Corporation) MD5=1D5185A4C7E6695431AE4B55C3D7D333 -- C:\Windows\winsxs\amd64_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_16795c7543eb48cf\mswsock.dll
[2010-11-20 13:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\ERDNT\cache86\mswsock.dll
[2010-11-20 13:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\SysWOW64\mswsock.dll
[2010-11-20 13:19:56 | 000,232,448 | ---- | M] (Microsoft Corporation) MD5=8999B8631C7FD9F7F9EC3CAFD953BA24 -- C:\Windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll

< MD5 for: NETCFGX.DLL >
[2010-11-20 14:27:22 | 000,519,680 | ---- | M] (Microsoft Corporation) MD5=03706015DB44368375AEBE6339490E66 -- C:\Windows\SysNative\netcfgx.dll
[2010-11-20 14:27:22 | 000,519,680 | ---- | M] (Microsoft Corporation) MD5=03706015DB44368375AEBE6339490E66 -- C:\Windows\winsxs\amd64_microsoft-windows-ndis-tdi-bindingengine_31bf3856ad364e35_6.1.7601.17514_none_9c3aecd33c2750cf\netcfgx.dll
[2010-11-20 13:20:28 | 000,406,528 | ---- | M] (Microsoft Corporation) MD5=1FF7E4F548C7C372C804938F0D5B36AE -- C:\Windows\SysWOW64\netcfgx.dll
[2010-11-20 13:20:28 | 000,406,528 | ---- | M] (Microsoft Corporation) MD5=1FF7E4F548C7C372C804938F0D5B36AE -- C:\Windows\winsxs\x86_microsoft-windows-ndis-tdi-bindingengine_31bf3856ad364e35_6.1.7601.17514_none_401c514f83c9df99\netcfgx.dll

< MD5 for: NETMAN.DLL >
[2009-07-14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=847D3AE376C0817161A14A82C8922A9E -- C:\Windows\ERDNT\cache64\netman.dll
[2009-07-14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=847D3AE376C0817161A14A82C8922A9E -- C:\Windows\SysNative\netman.dll
[2009-07-14 02:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) MD5=847D3AE376C0817161A14A82C8922A9E -- C:\Windows\winsxs\amd64_microsoft-windows-netman_31bf3856ad364e35_6.1.7600.16385_none_6bb20d3d6b80d9da\netman.dll

< MD5 for: NETSHELL.DLL >
[2010-11-20 14:27:22 | 002,652,160 | ---- | M] (Microsoft Corporation) MD5=A42F2C1EB3B66C54FB3C7B79D30C1A6D -- C:\Windows\SysNative\netshell.dll
[2010-11-20 14:27:22 | 002,652,160 | ---- | M] (Microsoft Corporation) MD5=A42F2C1EB3B66C54FB3C7B79D30C1A6D -- C:\Windows\winsxs\amd64_microsoft-windows-netshell_31bf3856ad364e35_6.1.7601.17514_none_33a9704224aa536e\netshell.dll
[2010-11-20 13:20:29 | 002,494,464 | ---- | M] (Microsoft Corporation) MD5=EAB975DB4C2805927FE5BD047D05C9AA -- C:\Windows\SysWOW64\netshell.dll
[2010-11-20 13:20:29 | 002,494,464 | ---- | M] (Microsoft Corporation) MD5=EAB975DB4C2805927FE5BD047D05C9AA -- C:\Windows\winsxs\x86_microsoft-windows-netshell_31bf3856ad364e35_6.1.7601.17514_none_d78ad4be6c4ce238\netshell.dll

< mdnsNSP.dll >

< c:\windows\assembly\tmp\*.* >

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:0B9176C0

< End of report >

Extras:

OTL Extras logfile created on: 11/5/2011 4:57:40 PM - Run 3
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 4.18 Gb Available Physical Memory | 69.89% Memory free
11.96 Gb Paging File | 9.99 Gb Available in Paging File | 83.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 888.50 Gb Free Space | 96.27% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 287.00 Gb Free Space | 58.76% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 153.22 Gb Free Space | 78.45% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 217.78 Gb Free Space | 80.53% Space Free | Partition Type: NTFS
Drive M: | 434.57 Gb Total Space | 98.56 Gb Free Space | 22.68% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (All) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.chm[@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cpl[@ = cplfile] -- C:\Windows\SysNative\control.exe (Microsoft Corporation)
.hlp[@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta[@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html[@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf[@ = inffile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.ini[@ = inifile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = JSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.jse[@ = JSEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.reg[@ = regfile] -- C:\Windows\regedit.exe (Microsoft Corporation)
.txt[@ = txtfile] -- C:\Windows\SysNative\NOTEPAD.EXE (Microsoft Corporation)
.vbe[@ = VBEFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.vbs[@ = VBSFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsf[@ = WSFFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)
.wsh[@ = WSHFile] -- C:\Windows\SysNative\WScript.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.bat [@ = batfile] -- "%1" %*
.chm [@ = chm.file] -- C:\Windows\hh.exe (Microsoft Corporation)
.cmd [@ = cmdfile] -- "%1" %*
.com [@ = ComFile] -- "%1" %*
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.exe [@ = exefile] -- "%1" %*
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)
.hta [@ = htafile] -- C:\Windows\SysWOW64\mshta.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
.inf [@ = inffile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.ini [@ = inifile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.url [@ = InternetShortcut] -- C:\Windows\SysWow64\rundll32.exe (Microsoft Corporation)
.js [@ = JSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.jse [@ = JSEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.pif [@ = piffile] -- "%1" %*
.reg [@ = regfile] -- C:\Windows\SysWow64\regedit.exe (Microsoft Corporation)
.scr [@ = scrfile] -- "%1" /S
.txt [@ = txtfile] -- C:\Windows\SysWow64\NOTEPAD.EXE (Microsoft Corporation)
.vbe [@ = VBEFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.vbs [@ = VBSFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsf [@ = WSFFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)
.wsh [@ = WSHFile] -- C:\Windows\SysWow64\WScript.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
batfile [open] -- "%1" %*
batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
chm.file [open] -- "%SystemRoot%\hh.exe" %1 (Microsoft Corporation)
cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
cmdfile [open] -- "%1" %*
cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htafile [open] -- C:\Windows\SysWOW64\mshta.exe "%1" %* (Microsoft Corporation)
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 (Microsoft Corporation)
inffile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
inifile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
inifile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
jsfile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsfile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
jsefile [edit] -- C:\Windows\System32\Notepad.exe %1 (Microsoft Corporation)
jsefile [open] -- C:\Windows\System32\WScript.exe "%1" %* (Microsoft Corporation)
jsefile [print] -- C:\Windows\System32\Notepad.exe /p %1 (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [edit] -- %SystemRoot%\system32\notepad.exe "%1" (Microsoft Corporation)
regfile [open] -- regedit.exe "%1" (Microsoft Corporation)
regfile [merge] -- Reg Error: Key error.
regfile [print] -- %SystemRoot%\system32\notepad.exe /p "%1" (Microsoft Corporation)
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 (Microsoft Corporation)
txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 (Microsoft Corporation)
txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" (Microsoft Corporation)
vbefile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbefile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbefile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
vbsfile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
vbsfile [open] -- %SystemRoot%\System32\WScript.exe "%1" %* (Microsoft Corporation)
vbsfile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wsffile [edit] -- "%SystemRoot%\System32\Notepad.exe" %1 (Microsoft Corporation)
wsffile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
wsffile [print] -- "%SystemRoot%\System32\Notepad.exe" /p %1 (Microsoft Corporation)
wshfile [open] -- "%SystemRoot%\System32\WScript.exe" "%1" %* (Microsoft Corporation)
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files (x86)\Internet Explorer\iexplore.exe" (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A125C1EA-3D24-D4CC-318A-CCBC62663E1B}" = AMD Drag and Drop Transcoding
"{B7F9AFA9-C855-0AF4-3238-E338D16DE1E6}" = ccc-utility64
"{CB703E0A-443F-4612-64FE-8D1FAF68C0C9}" = ATI AVIVO64 Codecs
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F4DBEFD1-1E91-64A9-520E-C68D19E51A3A}" = ATI Catalyst Install Manager
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CutePDF Writer Installation" = CutePDF Writer 2.8
"Lexmark 3400 Series" = Lexmark 3400 Series
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"TeraCopy_is1" = TeraCopy 2.12
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0764244D-B5B4-FE84-72EB-D30D020AA0BF}" = CCC Help Italian
"{0AB0FD1B-0C6C-A192-1ED5-F4800F00B773}" = CCC Help Hungarian
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D7CD0D9-4A88-4A63-8F91-3F4E8F371768}" = MyWinLocker
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1AA583C0-4BAD-D55D-3AB6-8A5A141B7A26}" = CCC Help Chinese Standard
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2274ED79-8F51-3EBA-A505-BCE355090EA6}" = CCC Help Thai
"{26A24AE4-039D-4CA4-87B4-2F83216025FF}" = Java™ 6 Update 26
"{287ECFA4-719A-2143-A09B-D6A12DE54E40}" = Acrobat.com
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{3368F8D0-CC3A-4872-B585-04748C0D1D8E}" = CCC Help German
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3668C840-CA7C-F7AC-816B-3B8F7B7CA413}" = CCC Help Korean
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51EB1680-EDB7-6874-7129-4C983D9E9D74}" = CCC Help Norwegian
"{55E2E85A-48F9-B94D-5407-DF7869C88C37}" = CCC Help Portuguese
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5D3435E8-AAC5-CD53-585A-EE0ECC0C7D65}" = CCC Help Spanish
"{63E65FF4-5CCB-EDB0-5327-2F859E309BA4}" = CCC Help English
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6C2B0E3E-3625-4FAB-B7D5-A516218741A5}" = CCC Help Finnish
"{6D841B2A-6629-AD72-33A2-92F81D1C8F92}" = CCC Help Swedish
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"{7F811A54-5A09-4579-90E1-C93498E230D9}" = Acer eRecovery Management
"{8229EB52-BF74-E006-8D4E-A6735737DCC7}" = Catalyst Control Center Localization All
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91FD9139-EFE6-81AD-3CDB-0EC531953BDB}" = CCC Help Czech
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A8CF74A-7CDD-096C-81FC-CAA4A25C6B96}" = CCC Help Chinese Traditional
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.0)
"{AD3D31C4-DF57-D055-5BE3-EF602E2C51C1}" = CCC Help Dutch
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6F14A1D-A1A2-2812-9DF2-6BDE53821884}" = Catalyst Control Center InstallProxy
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D019764D-4690-1790-05C1-8BCB6E0DAA62}" = CCC Help Greek
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D2223157-A5F5-061C-88E1-681DCD8558AF}" = CCC Help Japanese
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE35B2C9-35AF-E4B6-3F0E-DDC3417C0365}" = CCC Help Polish
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E36E864B-BFB6-440A-9A23-2B0BEDE59A92}" = MultiScreen
"{E43196CF-182A-4D9E-9CE7-69616DBEE3B0}" = Ad-Aware
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E75B5672-3D53-1D60-6B4B-9F74342BD12B}" = ccc-core-static
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C9EB74-EF5B-9154-6619-663FDE7768FE}" = CCC Help Russian
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F7D5760B-4C4C-C6DE-42F1-94515A5C9167}" = CCC Help French
"{FAC20146-EBEA-867B-24CF-5E678EB5E216}" = CCC Help Danish
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"Acer Registration" = Acer Registration
"Acer Welcome Center" = Welcome Center
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.5
"AIM_7" = AIM 7
"Audacity_is1" = Audacity 1.2.6
"dBpoweramp DSP Effects" = dBpoweramp DSP Effects
"dBpoweramp Music Converter" = dBpoweramp Music Converter
"FileZilla Client" = FileZilla Client 3.5.0
"foobar2000" = foobar2000 v1.1.6
"Hotkey Utility" = Hotkey Utility
"IceChat_is1" = IceChat 7.70 (Build 20101031)
"Identity Card" = Identity Card
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{738BF5C3-AF7B-4BB0-B7EF-E505EFC756BE}" = MyWinLocker Suite
"LastFM_is1" = Last.fm 1.5.4.27091
"Lexmark 3400 Series" = Lexmark 3400 Series
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware version 1.51.2.1300
"Mozilla Firefox (3.6.23)" = Mozilla Firefox (3.6.23)
"Notepad++" = Notepad++
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PuTTY_is1" = PuTTY version 0.60
"RealVNC_is1" = VNC Free Edition 4.1.3
"ThemeManager" = Theme Manager v 1.0
"VirtualCloneDrive" = VirtualCloneDrive
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
"winscp3_is1" = WinSCP 4.3.3
"Yahoo! Messenger" = Yahoo! Messenger

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"uTorrent" = µTorrent

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 18-9-2011 21:19:41 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 19-9-2011 18:33:20 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 19-9-2011 18:33:33 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 23-9-2011 18:30:17 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 23-9-2011 18:30:34 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 28-9-2011 20:24:09 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 28-9-2011 20:24:26 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

Error - 2-10-2011 17:39:10 | Computer Name = Broomstick | Source = VSS | ID = 8194
Description =

Error - 2-10-2011 20:03:42 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\Program Files (x86)\Common
Files\Adobe AIR\Versions\1.0\Adobe AIR.dll".Error in manifest or policy file "c:\Program
Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll" on line 3. The value
"MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" of attribute
"version" in element "assemblyIdentity" is invalid.

Error - 2-10-2011 20:04:00 | Computer Name = Broomstick | Source = SideBySide | ID = 16842815
Description = Activation context generation failed for "c:\program files (x86)\spybot
- search & destroy\DelZip179.dll".Error in manifest or policy file "c:\program
files (x86)\spybot - search & destroy\DelZip179.dll" on line 8. The value "*" of
attribute "language" in element "assemblyIdentity" is invalid.

[ System Events ]
Error - 3-11-2011 13:09:11 | Computer Name = Broomstick | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Windows Firewall Authorization
Driver service which failed to start because of the following error: %%183

Error - 3-11-2011 13:14:11 | Computer Name = Broomstick | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 3-11-2011 13:16:12 | Computer Name = Broomstick | Source = Service Control Manager | ID = 7022
Description = The Windows Update service hung on starting.

Error - 3-11-2011 13:30:08 | Computer Name = Broomstick | Source = Service Control Manager | ID = 7000
Description = The Windows Firewall Authorization Driver service failed to start
due to the following error: %%183

Error - 3-11-2011 13:30:08 | Computer Name = Broomstick | Source = Service Control Manager | ID = 7001
Description = The Windows Firewall service depends on the Windows Firewall Authorization
Driver service which failed to start because of the following error: %%183

Error - 3-11-2011 13:30:11 | Computer Name = Broomstick | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 3-11-2011 13:31:07 | Computer Name = Broomstick | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 3-11-2011 13:31:07 | Computer Name = Broomstick | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 3-11-2011 13:31:12 | Computer Name = Broomstick | Source = Service Control Manager | ID = 7030
Description = The AMService service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 3-11-2011 13:31:49 | Computer Name = Broomstick | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.


< End of report >

I see some stuff about DNS here - it might be useful to know that I normally have google DNS set up. If not well.. better too much than too little information for you to work with :yes:

Didn't do the rest of your post before your last one as I wasn't sure if you wanted me to yet and I'd rather not do something and be safe than do something you don't want me to and mess things up.
  • 0

#9
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
I don't see an anti-virus. This infection usually corrupts your anti-virus anyway so that it needs to be reinstalled.

If you have one please uninstall it and then reboot.
Download and Save the free Avast installer.
http://www.avast.com...ivirus-download
Install Avast. (Register when it asks you - they will try to talk you in to buying the full product but the free version is what we want.)

Once you have it installed and it has updated:

Click on the Avast ball. Then click on Scan Computer, then on
Boot-Time Scan then on Settings. Change the Ask at the bottom to Move to Chest. OK then Schedule Now. Reboot and let it run a scan. It may take hours.
Once it finishes it should load windows. Click on the Avast ball and then on Scan Logs, select the Boot-time scan report then View Results. How many did it find?
See if you can find where it hides aswboot.txt file. I think it is C:\ProgramData\Alwil Software\Avast5\report\aswboot.txt but it might be in C:\ProgramData\AVAST Software\Avast\report\aswBoot.txt. IF you find it copy and paste it.

Ron

PS. I can see the google dns but I would think it would be a bit slow for you. You would do better with one closer to home.
https://www.grc.com/dns/benchmark.htm
  • 0

#10
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Thanks :)

Adware has one and I was (possibly stupidly) using that along with a once a month check with housecall. I am a bit puzzled as I cannot find it anywhere on my computer and it was there when I started doing stuff. *shrug* If that's the only thing I've lost I got off lightly :)

I'll get back to you once it's done :)

Thanks - I'll have a look at the DNS thing :)

EDIT:

Well that went faster than expected :) I had a good chuckle that avast thought that the tarball of UnrealIRCD was a torjan but I let it have it's way with it - especially as Unreal have recently released a new version of their IRCD so I was going to delete this one anyway. :yes:

Logs:
11/05/2011 18:01
Scan of all local drives

File C:\ProgramData\Lavasoft\Ad-Aware\Update\CSC39-EN-0-10953-F.sbr.sgn|>cblk.vtd Error 42126 {RAR archive is corrupted.}
File C:\Windows\assembly\temp\kwrd.dll is infected by Win32:Malware-gen, Moved to chest
File C:\Windows\assembly\temp\U\00000002.@|>[Embedded_R#00290] is infected by Win32:Malware-gen, Moved to chest
File C:\Windows\assembly\temp\U\80000032.@ is infected by Win32:DNSChanger-VJ [Trj], Moved to chest
File C:\Windows\System32\consrv.dll is infected by Win32:Malware-gen, Moved to chest
File D:\afterx\afterx-web\public_html\afterx.net\committees\dev-com\resources\unreal\Unreal3.2.tar.gz|>Unreal3.2.tar|>Unreal3.2\src\win32\tre.dll is infected by Win32:Trojan-gen, Moved to chest
File D:\afterx\afterx-web\public_html\afterx.net.drupal.5.2.tar|>afterx.net\committees\dev-com\resources\unreal\Unreal3.2.tar.gz|>Unreal3.2.tar|>Unreal3.2\src\win32\tre.dll is infected by Win32:Trojan-gen

Edited by Magicless, 05 November 2011 - 11:44 AM.

  • 0

Advertisements


#11
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
hmm for some reason I don't think this is completely fixed as I am still missing access on my M and G drives as I can see folders but they are "empty" but I can access *some* of the content via apps I've looked at the content with in the past.

I have in the mean time set up avast and zone alarm (tried onlinearmour but it was eating resources and CPU and slowed my computer down far too much) and kept MalwareBytes active as well.
  • 0

#12
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
Download, Save and Right click on unhide.exe and Run As Administrator from

http://download.blee...nler/unhide.exe


If that doesn't work then Open (My) Computer and double click on one of the drives that is having problems. Right click on each folder and uncheck the Hidden box and Apply.

If all else fails then run OTL again (quickscan) and let's make sure you are still clean.

Ron
  • 0

#13
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Awesome ! that worked a treat :)

Thanks so much for your help! :yes:
  • 0

#14
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,622 posts
  • MVP
Could you run OTL quickscan again? I saw something in the Avast log that makes me think we are not quite done.

Ron
  • 0

#15
Magicless

Magicless

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Hiya,

Sorry for the delay.

Here is the log you asked for:

OTL logfile created on: 11/10/2011 10:42:39 AM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Magical\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

5.98 Gb Total Physical Memory | 3.10 Gb Available Physical Memory | 51.75% Memory free
11.96 Gb Paging File | 8.53 Gb Available in Paging File | 71.29% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 922.95 Gb Total Space | 882.14 Gb Free Space | 95.58% Space Free | Partition Type: NTFS
Drive D: | 488.39 Gb Total Space | 278.99 Gb Free Space | 57.12% Space Free | Partition Type: NTFS
Drive F: | 195.31 Gb Total Space | 152.98 Gb Free Space | 78.33% Space Free | Partition Type: NTFS
Drive G: | 270.44 Gb Total Space | 211.28 Gb Free Space | 78.12% Space Free | Partition Type: NTFS
Drive M: | 434.57 Gb Total Space | 97.21 Gb Free Space | 22.37% Space Free | Partition Type: NTFS

Computer Name: BROOMSTICK | User Name: Magical | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - File not found --
PRC - [2011/11/09 16:27:49 | 000,912,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe
PRC - [2011/11/04 09:18:50 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Magical\Downloads\OTL.com
PRC - [2011/09/06 22:45:30 | 003,722,416 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/09/06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2011/08/31 17:00:48 | 000,449,608 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/08/22 01:18:08 | 006,276,408 | ---- | M] (Yahoo! Inc.) -- C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
PRC - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/05/27 23:06:47 | 000,270,128 | ---- | M] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe
PRC - [2011/05/25 21:07:14 | 024,176,560 | ---- | M] (Dropbox, Inc.) -- C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2011/05/03 16:43:14 | 004,321,112 | ---- | M] (AOL Inc.) -- C:\Program Files (x86)\AIM\aim.exe
PRC - [2011/04/22 19:08:54 | 002,008,576 | ---- | M] () -- C:\Program Files (x86)\foobar2000\foobar2000.exe
PRC - [2011/03/18 01:26:14 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
PRC - [2011/03/18 01:24:50 | 001,043,968 | ---- | M] (Check Point Software Technologies LTD) -- C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
PRC - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
PRC - [2010/10/31 00:36:22 | 003,862,528 | ---- | M] (IceChat Networks) -- C:\Program Files\IceChat\IceChat7.exe
PRC - [2010/10/27 20:21:54 | 001,155,072 | ---- | M] (Last.fm) -- C:\Program Files (x86)\Last.fm\LastFM.exe
PRC - [2010/10/05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/10/05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/09/14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2010/09/14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2010/09/14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2010/09/14 02:32:30 | 000,283,160 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
PRC - [2010/05/27 03:41:24 | 000,349,552 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
PRC - [2010/03/11 06:11:56 | 000,407,920 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
PRC - [2010/03/11 06:11:42 | 000,201,584 | ---- | M] (Egis Technology Inc.) -- C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
PRC - [2010/02/28 01:33:14 | 000,077,664 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
PRC - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe
PRC - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
PRC - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
PRC - [2009/05/01 12:54:46 | 000,082,600 | ---- | M] (Lexmark International Inc.) -- C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe
PRC - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
PRC - [2007/01/01 22:22:02 | 003,739,648 | ---- | M] (Google) -- C:\Program Files (x86)\Google\Google Talk\googletalk.exe


========== Modules (No Company Name) ==========

MOD - [2011/11/09 20:24:21 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/09 16:27:49 | 000,849,368 | ---- | M] () -- C:\Program Files (x86)\Mozilla Firefox\js3250.dll
MOD - [2011/11/03 20:00:31 | 000,475,136 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\60c320dbe033e8ff4830cdc059933f2c\IAStorUtil.ni.dll
MOD - [2011/11/03 20:00:31 | 000,014,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\ebfad289d9759034cd3a887802fadb5b\IAStorCommon.ni.dll
MOD - [2011/11/03 18:53:33 | 011,819,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\8e7909ef6b5f953d49244c6b9f5f5100\System.Web.ni.dll
MOD - [2011/11/03 18:53:23 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\b2622080e047040fa044dd21a04ff10d\System.Runtime.Remoting.ni.dll
MOD - [2011/11/03 18:52:54 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6e592e424a204aafeadbe22b6b31b9db\System.Windows.Forms.ni.dll
MOD - [2011/11/03 18:52:46 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\3b2cfd85528a27eb71dc41d8067359a1\System.Drawing.ni.dll
MOD - [2011/11/03 18:52:30 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\d7a64c28cf0c90e6c48af4f7d6f9ed41\WindowsBase.ni.dll
MOD - [2011/11/03 18:52:25 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\130ad4d9719e566ca933ac7158a04203\System.Xml.ni.dll
MOD - [2011/11/03 18:52:21 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\2d5bcbeb9475ef62189f605bcca1cec6\System.Configuration.ni.dll
MOD - [2011/11/03 18:52:20 | 007,963,648 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\abab08afa60a6f06bdde0fcc9649c379\System.ni.dll
MOD - [2011/11/03 18:51:31 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/08/22 01:18:06 | 000,925,696 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\yui.dll
MOD - [2011/08/22 01:18:06 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Yahoo!\Messenger\pcre.dll
MOD - [2011/05/03 16:38:52 | 000,176,128 | ---- | M] () -- C:\Program Files (x86)\AIM\nssckbi.dll
MOD - [2011/04/22 19:08:54 | 002,008,576 | ---- | M] () -- C:\Program Files (x86)\foobar2000\foobar2000.exe
MOD - [2011/04/22 19:07:30 | 001,128,960 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_ui_std.dll
MOD - [2011/04/22 19:07:24 | 000,299,008 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_cdda.dll
MOD - [2011/04/22 19:07:20 | 001,368,576 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_input_std.dll
MOD - [2011/04/22 19:07:12 | 000,282,112 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_rgscan.dll
MOD - [2011/04/22 19:07:08 | 000,479,744 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_converter.dll
MOD - [2011/04/22 19:06:14 | 000,148,480 | ---- | M] () -- C:\Program Files (x86)\foobar2000\shared.dll
MOD - [2011/03/11 15:16:10 | 000,364,544 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_albumlist.dll
MOD - [2011/03/11 15:16:10 | 000,275,456 | ---- | M] () -- C:\Program Files (x86)\foobar2000\components\foo_dsp_std.dll
MOD - [2010/12/03 07:00:42 | 000,618,600 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MOD - [2010/12/03 04:44:54 | 000,151,656 | ---- | M] () -- C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
MOD - [2010/10/27 20:23:04 | 000,106,496 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_rtaudioplayback.dll
MOD - [2010/10/27 20:22:52 | 000,057,344 | ---- | M] () -- C:\Program Files (x86)\Last.fm\ext_messengernotify.dll
MOD - [2010/10/27 20:22:42 | 000,058,880 | ---- | M] () -- C:\Program Files (x86)\Last.fm\ext_skypenotify.dll
MOD - [2010/10/27 20:22:08 | 000,147,456 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_madtranscode.dll
MOD - [2010/10/27 20:22:00 | 000,028,160 | ---- | M] () -- C:\Program Files (x86)\Last.fm\srv_httpinput.dll
MOD - [2010/10/27 20:19:28 | 000,372,736 | ---- | M] () -- C:\Program Files (x86)\Last.fm\LastFmFingerprint1.dll
MOD - [2010/10/27 20:19:06 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Last.fm\breakpad.dll
MOD - [2010/10/27 20:18:50 | 000,180,224 | ---- | M] () -- C:\Program Files (x86)\Last.fm\Moose1.dll
MOD - [2010/10/27 20:18:34 | 000,540,672 | ---- | M] () -- C:\Program Files (x86)\Last.fm\LastFmTools1.dll
MOD - [2010/10/27 20:13:52 | 001,382,507 | ---- | M] () -- C:\Program Files (x86)\Last.fm\libfftw3f-3.dll
MOD - [2010/10/27 20:13:52 | 000,074,240 | ---- | M] () -- C:\Program Files (x86)\Last.fm\zlibwapi.dll
MOD - [2010/04/21 13:48:00 | 000,066,560 | ---- | M] () -- C:\Program Files (x86)\foobar2000\zlib1.dll
MOD - [2010/02/28 01:33:14 | 000,077,664 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
MOD - [2009/08/11 12:57:26 | 000,303,104 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MultiScreen.exe
MOD - [2009/08/11 12:56:52 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\MGResEng.dll
MOD - [2009/08/11 12:54:36 | 000,053,248 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\SmartMouseDll.dll
MOD - [2009/08/11 12:54:28 | 000,094,208 | ---- | M] () -- C:\Program Files (x86)\MultiScreen\TitleBar.dll
MOD - [2008/04/16 16:42:30 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtNetwork4.dll
MOD - [2008/04/16 16:42:16 | 000,524,288 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtSql4.dll
MOD - [2008/04/16 16:42:02 | 006,701,056 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtGui4.dll
MOD - [2008/04/16 16:36:38 | 000,376,832 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtXml4.dll
MOD - [2008/04/16 16:36:34 | 001,654,784 | ---- | M] () -- C:\Program Files (x86)\Last.fm\QtCore4.dll
MOD - [2008/04/02 13:26:50 | 000,233,472 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qmng4.dll
MOD - [2008/04/02 13:26:34 | 000,021,504 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qgif4.dll
MOD - [2008/04/02 13:26:28 | 000,135,168 | ---- | M] () -- C:\Program Files (x86)\Last.fm\imageformats\qjpeg4.dll
MOD - [2006/05/25 15:20:44 | 000,241,664 | ---- | M] () -- C:\Program Files (x86)\Lexmark 3400 Series\iptk.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2011/09/06 22:45:28 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV:64bit: - [2011/01/10 10:03:43 | 000,203,776 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2010/09/22 17:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/01/29 00:27:36 | 000,243,232 | ---- | M] (Acer Group) [Auto | Running] -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe -- (Updater Service)
SRV:64bit: - [2009/07/14 02:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2011/08/31 17:00:48 | 000,366,152 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/06/06 11:55:28 | 000,064,952 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/03/18 01:26:14 | 002,435,592 | ---- | M] (Check Point Software Technologies LTD) [Auto | Running] -- C:\Windows\SysWOW64\ZoneLabs\vsmon.exe -- (vsmon)
SRV - [2010/10/05 14:08:46 | 002,655,768 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS) Intel®
SRV - [2010/10/05 14:08:42 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS) Intel®
SRV - [2010/09/14 04:45:56 | 000,219,496 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2010/09/14 04:45:44 | 000,508,264 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2010/09/14 02:32:32 | 000,013,336 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc) Intel®
SRV - [2010/05/27 03:41:06 | 000,305,520 | ---- | M] (Egis Technology Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe -- (MWLService)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/01/08 14:21:22 | 000,023,584 | ---- | M] (Acer Incorporated) [Auto | Running] -- C:\Program Files (x86)\Acer\Registration\GREGsvc.exe -- (GREGService)
SRV - [2009/06/10 22:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/01/26 14:31:10 | 001,153,368 | ---- | M] (Safer Networking Ltd.) [Auto | Running] -- C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe -- (SBSDWSCService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2011/09/06 22:38:18 | 000,601,944 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\SysNative\drivers\aswSnx.sys -- (aswSnx)
DRV:64bit: - [2011/09/06 22:38:16 | 000,301,912 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswSP.sys -- (aswSP)
DRV:64bit: - [2011/09/06 22:36:41 | 000,058,200 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswTdi.sys -- (aswTdi)
DRV:64bit: - [2011/09/06 22:36:41 | 000,042,328 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\aswRdr.sys -- (aswRdr)
DRV:64bit: - [2011/09/06 22:36:30 | 000,065,368 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV:64bit: - [2011/09/06 22:36:14 | 000,024,408 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV:64bit: - [2011/08/31 17:00:50 | 000,025,416 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2011/03/11 07:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 07:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/01/15 17:21:04 | 000,036,352 | ---- | M] (Elaborate Bytes AG) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VClone.sys -- (VClone)
DRV:64bit: - [2011/01/10 10:31:20 | 008,283,136 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2011/01/10 09:28:18 | 000,295,424 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2010/12/21 09:31:00 | 000,316,080 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\e1c62x64.sys -- (e1cexpress) Intel®
DRV:64bit: - [2010/12/16 23:58:14 | 000,040,816 | ---- | M] (Elaborate Bytes AG) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ElbyCDIO.sys -- (ElbyCDIO)
DRV:64bit: - [2010/11/20 14:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 12:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/17 13:04:32 | 000,115,216 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2010/10/19 22:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64) Intel®
DRV:64bit: - [2010/09/14 04:45:52 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2010/09/14 04:45:50 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2010/09/14 04:45:48 | 000,268,648 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2010/09/14 04:45:44 | 000,760,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2010/09/14 02:24:26 | 000,437,272 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2010/08/11 04:40:06 | 001,014,624 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\netr28x.sys -- (netr28x)
DRV:64bit: - [2010/05/15 16:30:52 | 000,458,840 | ---- | M] (Check Point Software Technologies LTD) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vsdatant.sys -- (Vsdatant)
DRV:64bit: - [2009/07/14 02:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 02:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 02:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 21:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 21:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 21:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 21:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/06/03 03:15:30 | 000,060,464 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys -- (mwlPSDVDisk)
DRV:64bit: - [2009/06/03 03:15:30 | 000,022,576 | ---- | M] (Egis Technology Inc.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys -- (mwlPSDFilter)
DRV:64bit: - [2009/06/03 03:15:30 | 000,020,016 | ---- | M] (Egis Technology Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys -- (mwlPSDNServ)
DRV:64bit: - [2008/07/26 15:26:34 | 000,050,072 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LVUSBS64.sys -- (LVUSBS64)
DRV:64bit: - [2008/07/26 15:22:34 | 002,624,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LV302V64.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2009/07/14 02:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://acer.msn.com

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [email protected]:4.0.2
FF - prefs.js..extensions.enabledItems: {59c81df5-4b7a-477b-912d-4e0fdf64e5f2}:0.9.87
FF - prefs.js..extensions.enabledItems: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:0.9.12
FF - prefs.js..extensions.enabledItems: {b442f4c0-c292-4998-aabe-48608a73ba75}:1.0.1.3
FF - prefs.js..extensions.enabledItems: {1f91cde0-c040-11da-a94d-0800200c9a66}:9
FF - prefs.js..extensions.enabledItems: {FBF6D7FB-F305-4445-BB3D-FEF66579A033}:5.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}:6.0.25
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.7
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.19.1
FF - prefs.js..extensions.enabledItems: [email protected]:3.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.3.53363
FF - prefs.js..extensions.enabledItems: [email protected]:1.4.3
FF - prefs.js..extensions.enabledItems: tabcounter@morac:1.8.8
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.6
FF - prefs.js..extensions.enabledItems: {7d575baa-b543-11dc-8314-0800200c9a66}:2.0.5
FF - prefs.js..extensions.enabledItems: {89506680-e3f4-484c-a2c0-ed711d481eda}:0.9.5.7
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.10
FF - prefs.js..extensions.enabledItems: {446c03e0-2c35-11db-a98b-0800200c9a66}:0.6.2.15
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: [email protected]:6.0.1289
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.6


FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2011/11/05 17:47:39 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/11/09 16:27:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.24\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/09 16:27:50 | 000,000,000 | ---D | M]

[2011/05/01 18:09:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Extensions
[2011/11/10 00:10:54 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (Screengrab) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2011/05/02 12:15:59 | 000,000,000 | ---D | M] (Image Zoom) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2011/09/13 12:21:34 | 000,000,000 | ---D | M] (RSS Ticker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{1f91cde0-c040-11da-a94d-0800200c9a66}
[2011/08/26 08:18:32 | 000,000,000 | ---D | M] (Integrated Gmail) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{28197867-b1ef-4140-8e3b-55c45b9c8460}
[2011/06/16 01:41:34 | 000,000,000 | ---D | M] (Favicon Picker 2) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{446c03e0-2c35-11db-a98b-0800200c9a66}
[2011/06/06 01:55:11 | 000,000,000 | ---D | M] (ChatZilla) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{59c81df5-4b7a-477b-912d-4e0fdf64e5f2}
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (BitmeTV Menu) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{633b7287-e788-4131-a31c-db09d8ebbe51}(2)
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (DNS Flusher) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{7d575baa-b543-11dc-8314-0800200c9a66}
[2011/08/31 21:54:04 | 000,000,000 | ---D | M] (Showcase) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{89506680-e3f4-484c-a2c0-ed711d481eda}
[2011/08/26 13:00:38 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{961408A3-C970-4577-970A-D97C29839A67}
[2011/05/01 21:32:21 | 000,000,000 | ---D | M] (Smartest Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{b442f4c0-c292-4998-aabe-48608a73ba75}
[2011/10/01 01:21:40 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2011/10/16 21:04:20 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/05/02 12:16:00 | 000,000,000 | ---D | M] (Multirow Bookmarks Toolbar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}
[2011/10/01 01:21:41 | 000,000,000 | ---D | M] (Add-on Compatibility Reporter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:15:57 | 000,000,000 | ---D | M] (DNS Cache) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/10/01 01:21:40 | 000,000,000 | ---D | M] (Element Hiding Helper for Adblock Plus) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:15 | 000,000,000 | ---D | M] (British English Dictionary) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/25 20:57:40 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/11/09 00:09:11 | 000,000,000 | ---D | M] (Webmail Ad Blocker) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/11/09 00:09:13 | 000,000,000 | ---D | M] (Cooliris) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:16 | 000,000,000 | ---D | M] (Smart Bookmarks Bar) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/05/02 12:10:17 | 000,000,000 | ---D | M] (Tab Counter) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\tabcounter@morac
[2011/10/01 01:21:41 | 000,000,000 | ---D | M] (BlackFox V1-Blue) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/08/26 13:00:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\extensions\[email protected]
[2011/11/08 12:57:38 | 000,001,032 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\exigo.xml
[2010/04/30 18:04:17 | 000,001,504 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\imdb.xml
[2010/04/24 17:18:48 | 000,002,352 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\search-firefox-addons.xml
[2010/05/25 00:38:29 | 000,004,140 | ---- | M] () -- C:\Users\Magical\AppData\Roaming\Mozilla\Firefox\Profiles\8ts1yyzy.default\searchplugins\youtube.xml
[2011/11/10 00:10:54 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/05/01 20:50:24 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}
[2011/09/28 09:35:16 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
[2011/11/06 15:16:27 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}
[2011/11/05 17:47:39 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2011/10/03 05:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/04/21 00:07:17 | 000,001,538 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/21 00:07:17 | 000,000,947 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/21 00:07:17 | 000,000,769 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/04/21 00:07:17 | 000,001,135 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2011/11/05 02:23:58 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [EzPrint] C:\Program Files (x86)\Lexmark 3400 Series\ezprint.exe (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [LXCYCATS] C:\Windows\SysNative\spool\DRIVERS\x64\3\LXCYtime.DLL (Lexmark International Inc.)
O4:64bit: - HKLM..\Run: [lxcymon.exe] C:\Program Files (x86)\Lexmark 3400 Series\lxcymon.exe ()
O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Egis Technology Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [EgisTecPMMUpdate] C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [EgisUpdate] C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [googletalk] C:\Program Files (x86)\Google\Google Talk\googletalk.exe (Google)
O4 - HKLM..\Run: [Hotkey Utility] C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe ()
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SuiteTray] C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe (Egis Technology Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [MultiScreen] C:\Program Files (x86)\MultiScreen\MultiScreen.exe ()
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Users\Magical\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Magical\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - %SystemRoot%\System32\nwprovau.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000025 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000026 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4DC80F5F-8843-40AD-930A-E6ECA0C8B00F}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/02/22 11:24:38 | 000,000,000 | ---- | M] () - F:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/11/10 06:42:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{48BE62A2-36F1-4D79-95E4-A358EC64327B}
[2011/11/10 06:42:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7289CC38-29CC-44F1-8458-CBDE3782EEC7}
[2011/11/09 18:41:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{400671E6-B2A7-48B5-8878-F79A86E24D7B}
[2011/11/09 06:41:08 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{75F07E25-59CB-4D87-8C7E-3C534864F231}
[2011/11/08 18:40:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3D4925C8-06F9-48E9-8DA2-EC0FC9A0F25E}
[2011/11/08 06:39:49 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{962A94B5-8635-4C14-B3F5-11B216ACA47C}
[2011/11/07 18:39:13 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{92CF4F49-7D16-4F2D-ABC9-12855CEF9E59}
[2011/11/07 18:38:51 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B94E1794-073E-4D47-9FA3-E8D3A9A52DDD}
[2011/11/07 09:17:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yahoo! Messenger
[2011/11/07 08:38:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ZoneAlarm
[2011/11/07 08:37:42 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\ZoneLabs
[2011/11/07 08:36:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Zone Labs
[2011/11/07 08:35:45 | 000,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2011/11/07 08:35:45 | 000,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2011/11/07 06:38:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EFA80663-C2C5-4551-A6B3-2ED0A881C96D}
[2011/11/07 06:37:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F8526256-6F02-437A-8657-2838377AA499}
[2011/11/07 03:04:45 | 000,032,920 | ---- | C] (Emsisoft) -- C:\Windows\SysNative\drivers\oanet.sys
[2011/11/06 19:07:24 | 000,167,296 | ---- | C] (Gibson Research Corp.) -- C:\Users\Magical\Desktop\DNSBench.exe
[2011/11/06 18:37:20 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1F2EA325-926A-4C7D-89DC-A0147BDFACF0}
[2011/11/06 15:16:40 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2011/11/06 06:36:41 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E961B8DC-96D3-4AE1-930D-54B0FA533DE5}
[2011/11/06 00:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\logishrd
[2011/11/05 18:35:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{69E7E7DA-E3CE-4706-996E-3D1722EF7070}
[2011/11/05 18:35:28 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3F7BDE34-F4B3-442E-9F76-75569951F066}
[2011/11/05 17:48:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Free Antivirus
[2011/11/05 17:48:04 | 000,024,408 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2011/11/05 17:48:02 | 000,301,912 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2011/11/05 17:48:00 | 000,042,328 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr.sys
[2011/11/05 17:47:58 | 000,058,200 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2011/11/05 17:47:57 | 000,601,944 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2011/11/05 17:47:53 | 000,254,400 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[2011/11/05 17:47:53 | 000,065,368 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2011/11/05 17:47:35 | 000,199,304 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2011/11/05 17:47:35 | 000,041,184 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2011/11/05 17:47:31 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
[2011/11/05 17:47:31 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2011/11/05 16:53:43 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C3FC1CF1-624F-4DC2-B9C3-ED0D2286541B}
[2011/11/05 16:52:03 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2011/11/05 16:50:08 | 000,000,000 | ---D | C] -- C:\Windows\assemby
[2011/11/05 03:49:14 | 000,000,000 | ---D | C] -- C:\_OTL
[2011/11/05 03:44:27 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2011/11/05 02:41:19 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011/11/05 02:31:20 | 001,563,952 | ---- | C] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011/11/05 02:19:29 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2011/11/05 02:19:29 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2011/11/05 02:19:29 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2011/11/05 02:19:25 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2011/11/05 02:19:23 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011/11/05 02:13:40 | 004,284,246 | R--- | C] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011/11/05 02:04:45 | 000,000,000 | ---D | C] -- C:\Users\Magical\Desktop\lost
[2011/11/04 20:34:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A74238AF-F985-4C54-B753-3C3E0B5FF6F7}
[2011/11/04 20:34:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1E75554F-0FA9-4128-8F2D-A41333AD2C7A}
[2011/11/04 08:34:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A48E29C5-8D30-46E1-B3DD-A4ACBB35EE02}
[2011/11/04 08:33:59 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CBBD8B9-07D0-4110-B258-D84D562E514F}
[2011/11/03 23:33:46 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Roaming\Malwarebytes
[2011/11/03 23:32:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/11/03 23:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/11/03 23:32:42 | 000,025,416 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2011/11/03 23:32:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/11/03 19:32:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
[2011/11/03 18:43:56 | 000,200,976 | ---- | C] (Trend Micro Inc.) -- C:\Windows\SysWow64\drivers\tmcomm.sys
[2011/11/03 17:50:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D4C94249-A4BD-4B7D-887D-884E143AAD16}
[2011/11/03 05:49:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D63D7844-9801-42DD-ADE6-4831ED93C8D2}
[2011/11/02 17:49:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{87E3EBB1-7FF7-4901-99D7-4DAF46AAF9D3}
[2011/11/02 05:48:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{43EDBA0A-6DD0-4C23-B7E8-B1B0A86B9334}
[2011/11/01 17:47:55 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EE36652D-BAFE-4F17-9AD5-3E4DF5765A31}
[2011/11/01 05:47:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{637D5548-7DE6-49B0-8549-1D983001FA07}
[2011/10/31 17:46:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F784FAAE-CC16-49BD-947A-884C8279F464}
[2011/10/31 11:18:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\Documents\Stuff that used to be in dropbox
[2011/10/31 05:46:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{92CBC907-2386-47DA-9958-63C7EFF57ED9}
[2011/10/30 17:45:25 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{35E733DD-0BA5-440F-BEC9-749E4867548A}
[2011/10/30 05:44:49 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5CC4A491-409E-49DE-8278-786C38FA7BDC}
[2011/10/29 17:44:12 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E6782204-61AC-493C-8AEE-B5AE825874DB}
[2011/10/29 05:43:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3DC0B751-9BC6-48F2-BF39-B648D11D53A9}
[2011/10/28 17:43:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{0EB83299-8115-4D51-BAEE-DDCE4741254F}
[2011/10/28 05:42:27 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F6424066-E600-4DB4-9273-8C01C900025C}
[2011/10/27 17:41:51 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{72A3BAC0-E766-4697-B006-B74608057CE6}
[2011/10/27 05:41:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{FEC61A44-90AF-4347-AB20-B68D9194669F}
[2011/10/26 17:40:35 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B0B050C5-5F13-4BAD-A334-9AE589773182}
[2011/10/26 05:40:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{356B0CFB-26EC-426E-BAA3-CE05C2C1E2D8}
[2011/10/25 17:39:32 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{359FCEBE-7990-4F97-8198-6428C2F088D8}
[2011/10/25 05:39:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3423A6EF-E8A0-4978-BDF1-A6F60AC59B71}
[2011/10/24 17:38:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C4A081CD-94AF-4B21-B42F-5497DE775F41}
[2011/10/24 09:28:37 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\Microsoft Games
[2011/10/24 05:38:00 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{1B2D8A7F-970E-4E8D-AF8B-A9C01CBE25A5}
[2011/10/23 17:37:31 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{057FD8D5-C992-49A9-8440-32AE88F0147D}
[2011/10/23 05:37:02 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74AB5993-50A0-4A03-B589-BBAB27058FAA}
[2011/10/22 17:36:34 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EF1C193A-AA47-4766-858B-451EE4B2264B}
[2011/10/22 05:36:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C2455C65-BAA2-4CDE-AB5C-564F2B642691}
[2011/10/21 17:35:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4811046-0A7C-4EB3-AE30-71FDF60F6D3A}
[2011/10/21 05:35:10 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AB1B270B-9B8F-4DFB-AA09-EFD20202A95F}
[2011/10/20 17:34:42 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{96729716-95F0-4756-B7F6-733504C3DB04}
[2011/10/20 05:34:15 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E18A4DE2-43C9-4E85-A2F7-B9958155721C}
[2011/10/19 17:33:48 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{914C5AF3-7A88-4746-827F-D8796D7416B3}
[2011/10/19 05:33:22 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{5B50832A-E4C7-4B3A-A7C3-6E89EB1C6274}
[2011/10/18 17:32:56 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A6BB88B6-104F-415F-8CCD-DC9481BBF595}
[2011/10/18 05:32:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{EFEB572C-D1D9-4530-8431-CA99C5A2B1BA}
[2011/10/17 17:32:03 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{3F7D4546-3096-44C8-95F8-66A13E36889A}
[2011/10/17 05:31:38 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{F04A283D-3DF0-4E47-97F6-B0F60FF22E74}
[2011/10/16 17:31:13 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C77AB15E-D2D2-4D01-AAF2-DAE89EDF0681}
[2011/10/16 17:31:01 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D32288D7-0AD4-46B7-951E-68DF21812BC2}
[2011/10/16 05:30:36 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{49224AAA-B72B-48D4-AE4D-0E96E06D77E2}
[2011/10/16 05:30:24 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9B2182A1-7784-4409-B137-583188119E0A}
[2011/10/15 17:30:11 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{12170724-B536-47A0-9536-1D73EE3EC65F}
[2011/10/15 17:29:58 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{41CE4D19-B15E-4373-A390-12C55057950E}
[2011/10/15 05:29:44 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{9AEFF161-36B8-48F0-B59D-4E1EFC764BA3}
[2011/10/15 05:29:33 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{71C7E389-A36B-4DB6-BF3B-BF4F172E8B45}
[2011/10/14 17:29:19 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{C5857948-6208-4D04-A183-16EA4B94E248}
[2011/10/14 17:29:08 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{15AF7EB9-E426-4F55-AC62-471E12838F1C}
[2011/10/14 05:28:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{74E29617-D529-4D3B-BDC4-E70078294605}
[2011/10/14 05:28:43 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7FB1650C-7722-4E51-9422-0F809C002631}
[2011/10/13 17:28:30 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{79B49105-364E-4824-9B35-8CD2544A0E5D}
[2011/10/13 17:28:18 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{E9EA43A9-B45F-4857-A27B-9461F3ABBA75}
[2011/10/13 05:28:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{B4F7B2F1-8E62-45A4-83AF-3C9386A96FA0}
[2011/10/13 05:27:54 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{AC2C66DF-C97F-4810-8CE5-91052FB079DB}
[2011/10/12 17:27:40 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{7F16F78E-F53D-4015-A913-CAE75C349B20}
[2011/10/12 17:27:29 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D9EE5708-1E40-4763-983A-BE05C43E4F0E}
[2011/10/12 05:27:16 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{A9161CE8-0324-47C7-8821-4A20A3F34C92}
[2011/10/12 05:27:05 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{99D0AE6F-359B-4118-919D-FF95612EB0D7}
[2011/10/11 17:26:52 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{D6294A31-0536-42BA-8386-2D389D2F4592}
[2011/10/11 17:26:41 | 000,000,000 | ---D | C] -- C:\Users\Magical\AppData\Local\{CC10FF82-BAEF-44B9-AEF7-CCCA3F22F520}
[2011/06/27 10:56:06 | 000,305,152 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhcp.dll
[2011/05/30 09:33:55 | 001,417,728 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyserv.dll
[2011/05/30 09:33:55 | 001,099,264 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyusb1.dll
[2011/05/30 09:33:55 | 000,695,808 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomc.dll
[2011/05/30 09:33:55 | 000,659,456 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyhbn3.dll
[2011/05/30 09:33:55 | 000,566,192 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycoms.exe
[2011/05/30 09:33:55 | 000,487,424 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcylmpm.dll
[2011/05/30 09:33:55 | 000,409,600 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypmui.dll
[2011/05/30 09:33:55 | 000,249,856 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycomm.dll
[2011/05/30 09:33:55 | 000,238,592 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyinpa.dll
[2011/05/30 09:33:55 | 000,235,952 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcycfg.exe
[2011/05/30 09:33:55 | 000,233,392 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyih.exe
[2011/05/30 09:33:55 | 000,226,816 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyiesc.dll
[2011/05/30 09:33:55 | 000,181,168 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyppls.exe
[2011/05/30 09:33:55 | 000,035,328 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcyprox.dll
[2011/05/30 09:33:55 | 000,010,752 | ---- | C] ( ) -- C:\Windows\SysWow64\lxcypplc.dll
[2011/05/27 23:06:47 | 000,270,128 | ---- | C] (BitTorrent, Inc.) -- C:\Program Files\uTorrent.exe
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/11/09 20:30:43 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/11/09 20:30:43 | 000,009,920 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/11/09 20:28:26 | 000,735,702 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2011/11/09 20:28:26 | 000,620,608 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2011/11/09 20:28:26 | 000,110,538 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2011/11/09 20:22:24 | 000,274,552 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2011/11/09 20:22:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/11/09 20:21:56 | 523,116,543 | -HS- | M] () -- C:\hiberfil.sys
[2011/11/07 08:39:31 | 000,420,800 | ---- | M] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2011/11/07 03:04:45 | 000,032,920 | ---- | M] (Emsisoft) -- C:\Windows\SysNative\drivers\oanet.sys
[2011/11/07 02:48:54 | 000,007,626 | ---- | M] () -- C:\Users\Magical\AppData\Local\resmon.resmoncfg
[2011/11/06 23:30:16 | 000,000,408 | ---- | M] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/06 19:39:56 | 000,000,064 | ---- | M] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/11/06 19:39:56 | 000,000,044 | ---- | M] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/11/06 19:06:40 | 000,167,296 | ---- | M] (Gibson Research Corp.) -- C:\Users\Magical\Desktop\DNSBench.exe
[2011/11/05 17:47:53 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2011/11/05 02:41:17 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Users\Magical\Desktop\aswMBR.exe
[2011/11/05 02:31:16 | 001,563,952 | ---- | M] (Kaspersky Lab ZAO) -- C:\Users\Magical\Desktop\tdsskiller.exe
[2011/11/05 02:23:58 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2011/11/05 02:15:57 | 004,284,246 | R--- | M] (Swearware) -- C:\Users\Magical\Desktop\ComboFix.exe
[2011/11/03 23:07:21 | 004,285,928 | ---- | M] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 23:03:23 | 000,066,464 | ---- | M] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 18:44:38 | 000,000,118 | ---- | M] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | ---- | M] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[1 C:\Windows\SysNative\drivers\*.tmp files -> C:\Windows\SysNative\drivers\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/11/07 08:37:40 | 000,420,800 | ---- | C] () -- C:\Windows\SysNative\drivers\vsconfig.xml
[2011/11/06 23:14:26 | 000,000,408 | ---- | C] () -- C:\Windows\tasks\Ad-Aware Update (Weekly).job
[2011/11/05 17:47:53 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\config.nt
[2011/11/05 02:21:02 | 000,002,490 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2011/11/05 02:21:02 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2011/11/05 02:21:02 | 000,002,435 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2010.lnk
[2011/11/05 02:21:02 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2011/11/05 02:21:02 | 000,001,462 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2011/11/05 02:21:02 | 000,001,378 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Photo Gallery.lnk
[2011/11/05 02:21:02 | 000,001,352 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk
[2011/11/05 02:21:02 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2011/11/05 02:21:02 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2011/11/05 02:21:02 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2011/11/05 02:21:02 | 000,001,309 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Movie Maker.lnk
[2011/11/05 02:21:02 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2011/11/05 02:21:02 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2011/11/05 02:21:02 | 000,001,192 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paint.NET.lnk
[2011/11/05 02:21:02 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2011/11/05 02:21:02 | 000,000,959 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2011/11/05 02:19:29 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2011/11/05 02:19:29 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2011/11/05 02:19:29 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2011/11/05 02:19:29 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2011/11/05 02:19:29 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2011/11/03 18:47:29 | 004,285,928 | ---- | C] () -- C:\Users\Magical\AppData\Local\census.cache
[2011/11/03 18:47:25 | 000,066,464 | ---- | C] () -- C:\Users\Magical\AppData\Local\ars.cache
[2011/11/03 18:44:38 | 000,000,118 | ---- | C] () -- C:\Windows\SysNative\MRT.INI
[2011/11/03 18:43:17 | 000,000,036 | ---- | C] () -- C:\Users\Magical\AppData\Local\housecall.guid.cache
[2011/07/17 19:38:27 | 000,013,082 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp DSP Effects.dat
[2011/07/17 19:38:20 | 004,022,504 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe
[2011/07/17 19:38:20 | 000,018,123 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat
[2011/06/19 20:45:14 | 001,007,358 | ---- | C] () -- C:\Program Files\Windows-Theme-Manager-Setup.exe
[2011/06/02 14:12:06 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2011/05/30 09:33:55 | 000,385,024 | ---- | C] () -- C:\Windows\SysWow64\lxcycomx.dll
[2011/05/30 09:33:55 | 000,194,048 | ---- | C] () -- C:\Windows\SysWow64\lxcyinst.dll
[2011/05/30 08:25:56 | 000,734,810 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/02 21:28:30 | 000,007,626 | ---- | C] () -- C:\Users\Magical\AppData\Local\resmon.resmoncfg
[2011/05/02 11:19:02 | 000,000,064 | ---- | C] () -- C:\Windows\SysWow64\rp_stats.dat
[2011/05/02 11:19:02 | 000,000,044 | ---- | C] () -- C:\Windows\SysWow64\rp_rules.dat
[2011/05/01 20:52:30 | 000,000,600 | ---- | C] () -- C:\Users\Magical\AppData\Roaming\winscp.rnd
[2011/05/01 18:30:50 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/05/01 18:09:29 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/02/10 07:57:24 | 000,002,975 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2010/10/27 12:02:31 | 000,008,192 | ---- | C] () -- C:\Windows\SysWow64\drivers\IntelMEFWVer.dll
[2009/07/14 06:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 03:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 03:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 01:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 22:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat

========== LOP Check ==========

[2011/05/02 12:33:43 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\acccore
[2011/09/05 21:21:33 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\dBpoweramp
[2011/11/09 20:23:40 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\Dropbox
[2011/11/09 21:56:08 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\foobar2000
[2011/05/02 12:27:31 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\Notepad++
[2011/05/01 15:51:51 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\OEM
[2011/11/09 20:20:37 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\SoftGrid Client
[2011/11/06 21:55:55 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\TeraCopy
[2011/06/19 20:47:46 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\ThemeManager
[2011/05/30 08:26:29 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\TP
[2011/11/10 10:56:03 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\uTorrent
[2011/07/31 04:35:25 | 000,000,000 | ---D | M] -- C:\Users\Magical\AppData\Roaming\Windows Live Writer
[2011/11/06 23:30:16 | 000,000,408 | ---- | M] () -- C:\Windows\Tasks\Ad-Aware Update (Weekly).job
[2009/07/14 06:08:49 | 000,012,684 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:0B9176C0

< End of report >
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP