Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Ebay pop up mallware [Closed]


  • This topic is locked This topic is locked

#1
Felixbrs

Felixbrs

    New Member

  • Member
  • Pip
  • 1 posts
Hi,

Since a couple of days I got this nasty pop up when I search for something on ebay.
it says that I have to fill in some credit card info blabla and I can't get rid of it.
This is my OTL log:

OTL logfile created on: 12/29/2011 6:34:00 AM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Felixb\Desktop
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: Netherlands | Language: NLD | Date Format: d-M-yyyy

3.25 Gb Total Physical Memory | 1.61 Gb Available Physical Memory | 49.44% Memory free
6.93 Gb Paging File | 4.05 Gb Available in Paging File | 58.50% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 8.86 Gb Free Space | 1.90% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 609.37 Gb Free Space | 65.42% Space Free | Partition Type: NTFS

Computer Name: FELIXB-PC | User Name: Felixb | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Felixb\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Felixb\Desktop\EEK\start.exe (Emsi Software GmbH)
PRC - C:\Users\Felixb\Desktop\EEK\Run\a2emergencykit.exe (Emsi Software GmbH)
PRC - C:\Program Files\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe (ACD Systems)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Steam\Steam.exe (Valve Corporation)
PRC - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe (Apple Inc.)
PRC - C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
PRC - C:\Program Files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe ()
PRC - C:\Program Files\Bamboo Dock\BambooCore.exe ()
PRC - C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Logitech, Inc.)
PRC - C:\Program Files\Logitech\ScrollApp\KhalScroll.exe (Logitech, Inc.)
PRC - c:\Program Files\Microsoft Silverlight\4.0.60831.0\agcp.exe (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\SketchBook Pro 2011\SketchBookSnapshot.exe (Autodesk Inc)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)
PRC - C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (http://tortoisesvn.net)
PRC - C:\Users\Felixb\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
PRC - C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
PRC - C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TabletUser.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
PRC - C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
PRC - C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - C:\Program Files\ASUS\EPU-4 Engine\FourEngine.exe (ASUSTeK Computer Inc.)
PRC - C:\Program Files\WIBUKEY\Server\WkSvMgr.exe (WIBU-SYSTEMS AG)
PRC - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
PRC - C:\Windows\System32\rserver30\FamItrfc.Exe (Famatech Corp.)
PRC - C:\Windows\System32\rserver30\rserver3.exe (Famatech Corp.)
PRC - C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
PRC - C:\Windows\twain_32\Samsung\CLX3170\Scan2Pc.exe ()
PRC - C:\Program Files\FTD Watchdog\FtdMonitor.exe ()
PRC - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe ()
PRC - C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Windows\vphc600.exe (Sonix)
PRC - C:\Windows\CTHELPER.EXE (Creative Technology Ltd)
PRC - C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
PRC - C:\Program Files\Philips\SPC 600NC PC Camera\TrayMin600.exe ()


========== Modules (No Company Name) ==========

MOD - C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\Steam\bin\libcef.dll ()
MOD - C:\Program Files\Steam\bin\avcodec-52.dll ()
MOD - C:\Program Files\Steam\bin\chromehtml.dll ()
MOD - C:\Program Files\Steam\bin\avformat-52.dll ()
MOD - C:\Program Files\Steam\bin\avutil-50.dll ()
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\Program Files\Logitech\SetPointP\Macros\MacroCore.dll ()
MOD - C:\Program Files\Bamboo Dock\Bamboo Dock\Bamboo Dock.exe ()
MOD - C:\Program Files\Bamboo Dock\BambooCore.exe ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files\ManyCam\Bin\cximagecrt.dll ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files\Tablet\Pen\libxml2.dll ()
MOD - C:\Program Files\WinRAR\RarExt.dll ()
MOD - C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
MOD - C:\Windows\System32\AsIO.dll ()
MOD - C:\Windows\twain_32\Samsung\CLX3170\Scan2Pc.exe ()
MOD - C:\Windows\System32\APOMngr.DLL ()
MOD - C:\Program Files\ASUS\EPU-4 Engine\AsSpindownTimeout.dll ()
MOD - C:\Program Files\ASUS\EPU-4 Engine\AiNap.dll ()
MOD - C:\Program Files\ASUS\EPU-4 Engine\vvc.dll ()
MOD - C:\Program Files\FTD Watchdog\FtdMonitor.exe ()
MOD - C:\Windows\System32\CmdRtr.DLL ()
MOD - C:\Program Files\ASUS\EPU-4 Engine\pngio.dll ()
MOD - C:\Windows\twain_32\Samsung\CLX3170\SSOle.dll ()
MOD - C:\Windows\twain_32\Samsung\CLX3170\NetModule.dll ()
MOD - C:\Windows\twain_32\Samsung\CLX3170\IMFilter.dll ()
MOD - C:\Program Files\Philips\SPC 600NC PC Camera\TrayMin600.exe ()
MOD - C:\Windows\System32\CTMMACTL.DLL ()


========== Win32 Services (SafeList) ==========

SRV - (Steam Client Service) -- C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (LBTServ) -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe (Logitech, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (Futuremark SystemInfo Service) -- C:\Program Files\Futuremark\Futuremark SystemInfo\FMSISvc.exe (Futuremark Corporation)
SRV - (Microsoft SharePoint Workspace Audit Service) -- C:\Program Files\Microsoft Office\Office14\GROOVE.EXE (Microsoft Corporation)
SRV - (3d-io License Server v2.0) -- C:\Program Files\3d-io plugins\licensing_v2\ActiveLockServerV2.exe (3d-io GmbH)
SRV - (nvUpdatusService) -- C:\Program Files\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (NVIDIA Corporation)
SRV - (mi-raysat_3dsmax2012_32) -- C:\Program Files\Autodesk\3ds Max 2012\mentalimages\satellite\raysat_3dsmax2012_32server.exe ()
SRV - (Creative Dolby Digital Live Pack Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\DDLLicensing.exe (Creative Labs)
SRV - (Creative ALchemy AL6 Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Autodesk Licensing Service) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (TabletServicePen) -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe (Wacom Technology, Corp.)
SRV - (TouchServicePen) -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe (Wacom Technology, Corp.)
SRV - (avg9emc) -- C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9wd) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (Creative Audio Engine Licensing Service) -- C:\Program Files\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (WatAdminSvc) -- C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (mi-raysat_3dsmax2011_32) -- C:\Program Files\Autodesk\3ds Max 2011\mentalimages\satellite\raysat_3dsmax2011_32server.exe ()
SRV - (SwitchBoard) -- C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (NAUpdate) -- C:\Program Files\Nero\Update\NASvc.exe (Nero AG)
SRV - (CTAudSvcService) -- C:\Program Files\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (RServer3) -- C:\Windows\System32\rserver30\RServer3.exe (Famatech Corp.)
SRV - (SensrSvc) -- C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (mi-raysat_3dsMax2008_32) -- C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe ()


========== Driver Services (SafeList) ==========

DRV - (LMouFilt) -- C:\Windows\System32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (LUsbFilt) -- C:\Windows\System32\drivers\LUsbFilt.sys (Logitech, Inc.)
DRV - (LHidFilt) -- C:\Windows\System32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (asmtxhci) -- C:\Windows\System32\drivers\asmtxhci.sys (ASMedia Technology Inc)
DRV - (asmthub3) -- C:\Windows\System32\drivers\asmthub3.sys (ASMedia Technology Inc)
DRV - (nvlddmkm) -- C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (NVHDA) -- C:\Windows\System32\drivers\nvhda32v.sys (NVIDIA Corporation)
DRV - (TsUsbFlt) -- C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (WinUsb) -- C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (wacmoumonitor) -- C:\Windows\System32\drivers\wacmoumonitor.sys (Wacom Technology)
DRV - (wacommousefilter) -- C:\Windows\System32\drivers\wacommousefilter.sys (Wacom Technology)
DRV - (wacomvhid) -- C:\Windows\System32\drivers\wacomvhid.sys (Wacom Technology)
DRV - (AvgRkx86) -- C:\Windows\System32\Drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX) -- C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) -- C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) -- C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (sptd) -- C:\Windows\System32\Drivers\sptd.sys ()
DRV - (L8042Kbd) -- C:\Windows\System32\drivers\L8042Kbd.sys (Logitech, Inc.)
DRV - (ha20x2k) -- C:\Windows\System32\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV - (emupia) -- C:\Windows\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k) -- C:\Windows\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (ctprxy2k) -- C:\Windows\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ossrv) -- C:\Windows\System32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (ctdvda2k) -- C:\Windows\System32\drivers\ctdvda2k.sys (Creative Technology Ltd)
DRV - (ctaud2k) Creative Audio Driver (WDM) -- C:\Windows\System32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctac32k) -- C:\Windows\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (CTEXFIFX.SYS) -- C:\Windows\System32\drivers\CTEXFIFX.SYS (Creative Technology Ltd.)
DRV - (CTEXFIFX) -- C:\Windows\System32\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV - (CTHWIUT.SYS) -- C:\Windows\System32\drivers\CTHWIUT.SYS (Creative Technology Ltd.)
DRV - (CTHWIUT) -- C:\Windows\System32\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV - (CT20XUT.SYS) -- C:\Windows\System32\drivers\CT20XUT.SYS (Creative Technology Ltd.)
DRV - (CT20XUT) -- C:\Windows\System32\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV - (WIBUKEY) -- C:\Windows\System32\drivers\WibuKey.sys (WIBU-SYSTEMS AG)
DRV - (raddrvv3) -- C:\Windows\System32\rserver30\raddrvv3.sys (Famatech Corp.)
DRV - (mirrorv3) -- C:\Windows\System32\drivers\rminiv3.sys (Famatech International Corp.)
DRV - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\system32\DRIVERS\AtiPcie.sys (Advanced Micro Devices Inc.)
DRV - (AsIO) -- C:\Windows\System32\drivers\AsIO.sys ()
DRV - (MTsensor) -- C:\Windows\System32\drivers\ASACPI.sys ()
DRV - (AtcL001) -- C:\Windows\System32\drivers\l160x86.sys (Atheros Communications, Inc.)
DRV - (DgiVecp) -- C:\Windows\System32\drivers\DgivEcp.sys (Samsung Electronics Co., Ltd.)
DRV - (ManyCam) -- C:\Windows\System32\drivers\ManyCam.sys (ManyCam LLC.)
DRV - (SSPORT) -- C:\Windows\System32\drivers\SSPORT.SYS (Samsung Electronics)
DRV - (phc600) USB PC Camera (SPC600NC) -- C:\Windows\System32\drivers\phc600.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://nl.msn.com/?ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 6D 77 E5 5B 37 A1 CC 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Felixb\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/09/20 13:19:41 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{5D3F3872-91E9-4d59-AD9F-AA174A3145DD}: C:\Program Files\Logitech\ScrollApp\LogiSmoothFirefoxExt [2011/11/03 16:30:15 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/23 17:02:20 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/05/18 00:13:27 | 000,000,000 | ---D | M]

[2011/05/31 07:40:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Felixb\AppData\Roaming\Mozilla\Extensions
[2011/05/31 07:40:15 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Felixb\AppData\Roaming\Mozilla\Extensions\[email protected]
[2011/12/01 14:08:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Felixb\AppData\Roaming\Mozilla\Firefox\Profiles\6kwq821m.default\extensions
[2011/12/01 14:08:12 | 000,000,000 | ---D | M] ("Free YouTube Download (Free Studio) Menu") -- C:\Users\Felixb\AppData\Roaming\Mozilla\Firefox\Profiles\6kwq821m.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
[2011/03/04 12:52:11 | 000,000,000 | ---D | M] (Download Manager Tweak) -- C:\Users\Felixb\AppData\Roaming\Mozilla\Firefox\Profiles\6kwq821m.default\extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}
[2011/11/23 17:02:21 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/11/18 22:13:02 | 000,000,000 | ---D | M] (Skype Click to Call) -- C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2011/11/23 17:02:19 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/05/04 03:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/09/11 15:23:49 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/09/11 15:23:49 | 000,001,892 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bolcom-nl.xml
[2011/09/11 15:23:49 | 000,004,558 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\marktplaats-nl.xml
[2011/09/11 15:23:49 | 000,001,049 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-nl.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Felixb\AppData\Local\Google\Chrome\Application\15.0.874.120\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U26 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~4\Office14\NPSPWRAP.DLL
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Felixb\AppData\Local\Google\Chrome\Application\15.0.874.120\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Felixb\AppData\Local\Google\Chrome\Application\15.0.874.120\pdf.dll
CHR - plugin: NPCIG.dll (Enabled) = C:\Program Files\Canon\MyCamera Download Plugin\NPCIG.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files\TabletPlugins\npwacom.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Felixb\AppData\Local\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Skype Click to Call = C:\Users\Felixb\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8442_0\
CHR - Extension: Dark Horizon = C:\Users\Felixb\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncjjeokpcnllmmbbipeaagmdpdpiadin\1.0_0\

O1 HOSTS File: ([2011/05/30 13:44:17 | 000,002,183 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 3dns.adobe.com 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com activate.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobeereg.com practivate.adobe practivate.adobe.com practivate.adobe.newoa practivate.adobe.ntp practivate.adobe.ipp ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com wwis-dubc1-vip60.adobe.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com wwis-dubc1-vip60.adobe.com crl.verisign.net CRL.VERISIGN.NET ood.opsource.net
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 www.adobeereg.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 3 more lines...
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Logitech Scroll App) - {E11DB59D-5008-42ff-9069-535843BC0BE1} - C:\Program Files\Logitech\ScrollApp\LogiSmooth.dll (Logitech, Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKLM..\Run: [3170 Scan2PC] C:\Windows\twain_32\Samsung\CLX3170\Scan2Pc.exe ()
O4 - HKLM..\Run: [ACPW05EN] C:\Program Files\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe (ACD Systems)
O4 - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AudioDrvEmulator] C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe (Creative Technology Ltd.)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BambooCore] C:\Program Files\Bamboo Dock\BambooCore.exe ()
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [CTHelper] C:\Windows\CTHELPER.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\System32\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [EvtMgr6] C:\Program Files\Logitech\SetPointP\SetPoint.exe (Logitech, Inc.)
O4 - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [LogiScrollApp] C:\Program Files\Logitech\ScrollApp\KhalScroll.exe (Logitech, Inc.)
O4 - HKLM..\Run: [NBAgent] C:\Program Files\Nero\Nero 10\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [phc600] C:\Windows\vphc600.exe (Sonix)
O4 - HKLM..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe ()
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [VolPanel] C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe" File not found
O4 - HKCU..\Run: [{6CA4E1D8-4483-40CC-4102-0B95A9E1D80E}] C:\Users\Felixb\AppData\Roaming\Qyfyyg\wianz.exe (Packard Bell BV)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [FTD Watchdog Monitor] C:\Program Files\FTD Watchdog\FtdMonitor.exe ()
O4 - HKCU..\Run: [SetDefaultMIDI] C:\Windows\MIDIDEF.EXE (Creative Technology Ltd)
O4 - HKCU..\Run: [Steam] C:\Program Files\Steam\steam.exe (Valve Corporation)
O4 - Startup: C:\Users\Felixb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Felixb\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - C:\Program Files\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Free YouTube Download - C:\Users\Felixb\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm ()
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\Felixb\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm ()
O8 - Extra context menu item: SmarThru4 Capture Selection - C:\Program Files\SmarThru 4\WEBCapture.dll2.htm ()
O8 - Extra context menu item: SmarThru4 Save as HTML - C:\Program Files\SmarThru 4\WEBCapture.dll1.htm ()
O8 - Extra context menu item: SmarThru4 Save Selected Text - C:\Program Files\SmarThru 4\WEBCapture.dll.htm ()
O8 - Extra context menu item: SmarThru4 Web Capture - C:\Program Files\SmarThru 4\WebCapture.dll ()
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} http://messenger.zon...er.cab56986.cab (Minesweeper Flags Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...15112/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.54.40.25 212.54.35.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A66A9498-4E84-472F-95DB-FB6AF293B555}: DhcpNameServer = 212.54.40.25 212.54.35.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{F4C6EC3E-ABEB-4532-9551-80FF607F3D88}: DhcpNameServer = 212.54.40.25 212.54.35.25
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20 - AppInit_DLLs: (avgrsstx.dll) -C:\Windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) -C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/09/02 16:56:26 | 000,000,000 | ---D | M] - C:\Autodesk -- [ NTFS ]
O32 - AutoRun File - [2009/06/10 22:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{8c18d5b5-be5a-11df-bb06-001e8c1fb61f}\Shell - "" = AutoRun
O33 - MountPoints2\{8c18d5b5-be5a-11df-bb06-001e8c1fb61f}\Shell\AutoRun\command - "" = E:\Autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/12/29 01:41:19 | 000,000,000 | ---D | C] -- C:\Users\Felixb\Desktop\EEK
[2011/12/29 01:41:09 | 000,584,192 | ---- | C] (OldTimer Tools) -- C:\Users\Felixb\Desktop\OTL.exe
[2011/12/29 00:02:10 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Juce VST Host
[2011/12/29 00:02:07 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Hardcore
[2011/12/28 22:19:37 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
[2011/12/28 22:19:37 | 000,000,000 | ---D | C] -- C:\Program Files\ASIO4ALL v2
[2011/12/28 22:19:18 | 000,225,280 | ---- | C] (Propellerhead Software AB) -- C:\Windows\System32\rewire.dll
[2011/12/28 22:19:16 | 000,000,000 | ---D | C] -- C:\Users\Felixb\Documents\Image-Line
[2011/12/28 22:19:03 | 001,554,944 | ---- | C] (HMS http://hp.vector.co....thors/VA012897/) -- C:\Windows\System32\vorbis.acm
[2011/12/28 22:18:48 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
[2011/12/28 22:18:43 | 000,000,000 | ---D | C] -- C:\Program Files\Outsim
[2011/12/28 22:16:38 | 000,000,000 | ---D | C] -- C:\Program Files\Image-Line
[2011/12/28 20:34:28 | 000,000,000 | ---D | C] -- C:\Users\Felixb\Desktop\New folder
[2011/12/28 12:20:04 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{20B067D8-16ED-4CFB-AF96-589E9F8860D8}
[2011/12/27 12:23:38 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{FD25BC95-6EC8-408F-8E25-95B9E1516A88}
[2011/12/23 15:19:46 | 000,000,000 | ---D | C] -- C:\Users\Felixb\Desktop\VA - Dubstep Academy 101_San Francisco (Bass Star Records [DUBSTEPSF101]) - 2011
[2011/12/23 11:56:08 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{2AB8E5B6-0AF1-4AF0-B692-0F2BF10A7F06}
[2011/12/22 12:22:44 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{0A837728-474E-4AF8-9202-03AB3D3ABCC9}
[2011/12/21 19:01:06 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{7DDDB12B-ECFE-44DE-A0AB-4796D0D98A25}
[2011/12/21 17:05:35 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{D1D09E51-CB0A-455C-AD3B-62E38D0E695A}
[2011/12/20 00:41:36 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\licensecb
[2011/12/20 00:41:36 | 000,000,000 | ---D | C] -- C:\ProgramData\licensecb
[2011/12/20 00:41:10 | 000,000,000 | ---D | C] -- C:\ProgramData\CrazyBump
[2011/12/20 00:40:55 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Crazybump
[2011/12/20 00:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Crazybump
[2011/12/20 00:40:35 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\CrazyBump
[2011/12/20 00:40:35 | 000,000,000 | ---D | C] -- C:\Program Files\Crazybump
[2011/12/19 21:06:11 | 000,000,000 | ---D | C] -- C:\ProgramData\Windows
[2011/12/19 18:33:08 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{9A1878CF-A02C-4C5C-B38E-890130FD7A65}
[2011/12/19 09:59:16 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{239C420D-1446-48F2-AFD0-1A56FA26D597}
[2011/12/18 13:59:16 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{46F9A3EE-C8C3-438A-ACEF-AD0AC299D744}
[2011/12/17 12:55:15 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Media Player Classic
[2011/12/17 12:51:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ffdshow
[2011/12/17 11:23:31 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{DF05B6E8-DE0F-4BF3-AFB2-E96A0D8D6DD4}
[2011/12/16 10:55:19 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{E18E292F-BAED-4D0E-A743-B23E141E2ED2}
[2011/12/15 03:33:59 | 001,638,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\mshtml.tlb
[2011/12/15 03:33:59 | 000,599,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2011/12/15 03:33:59 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieui.dll
[2011/12/15 03:33:59 | 000,132,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\url.dll
[2011/12/15 03:33:59 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jsproxy.dll
[2011/12/15 03:33:53 | 002,342,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2011/12/15 03:33:51 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tzres.dll
[2011/12/15 03:33:49 | 000,534,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\EncDec.dll
[2011/12/15 03:33:48 | 000,038,912 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\csrsrv.dll
[2011/12/15 03:33:47 | 003,967,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntkrnlpa.exe
[2011/12/15 03:33:47 | 003,912,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2011/12/14 23:41:47 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{8056E3D6-CA78-4285-90C9-791801E4243C}
[2011/12/14 19:36:27 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{2CE914BD-930B-4CCC-A2EC-D194F78DDD18}
[2011/12/13 16:01:54 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{58C2D921-570C-4429-946F-8E956E97EFE5}
[2011/12/12 11:05:54 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{2070412B-93EE-41B6-8A3C-5F35B8B1162A}
[2011/12/11 15:14:45 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{3CCAFF8F-B3B6-49EB-A991-30C202D8303C}
[2011/12/11 12:15:17 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{8A7D52A6-1260-4F56-A8E4-C4A841BD0773}
[2011/12/10 14:24:38 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{94FB0AA4-F0DB-498B-BFAE-CE8F9313F2CF}
[2011/12/09 19:32:09 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{F1B1220E-FCEA-4D20-A5FE-B95539D8A304}
[2011/12/09 14:05:13 | 000,000,000 | ---D | C] -- C:\Users\Felixb\Desktop\New Girl
[2011/12/09 13:22:28 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{8786B3FD-0630-4A40-8B35-FECA0D55701B}
[2011/12/08 23:13:41 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{730C1E0C-D469-488D-8CDE-32BDA9D52274}
[2011/12/08 13:18:59 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{5FA0A592-DF1A-45FD-A8DB-71A0BD057617}
[2011/12/05 23:11:30 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Malwarebytes
[2011/12/05 23:11:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2011/12/05 21:13:40 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Need for Speed World
[2011/12/05 20:42:24 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\Electronic_Arts_Inc
[2011/12/05 20:41:14 | 000,000,000 | ---D | C] -- C:\Program Files\Electronic Arts
[2011/12/05 19:42:23 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{E0678F83-03BE-47AD-8FFF-9F5479DDA700}
[2011/12/05 15:29:58 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{25DC96BF-AACD-4A65-A038-D22C64D6E22F}
[2011/12/04 21:57:20 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{2A7B3CF0-5477-4E5D-9E82-82DC4310E660}
[2011/12/04 15:46:40 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{B8CB19D7-17A5-43A8-92F8-77B8277FE15E}
[2011/12/02 15:04:46 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{AB8B0A54-9F60-4F93-844B-D23CFEA4E200}
[2011/12/02 12:31:41 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{6CC88F85-F989-4EA0-AD09-82C37B98215C}
[2011/12/01 22:19:00 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{AC9166C4-3CDB-49F6-82B4-6C913B629213}
[2011/12/01 15:43:53 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Qyfyyg
[2011/12/01 15:43:53 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Roaming\Gyukeg
[2011/12/01 14:07:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2011/12/01 14:06:15 | 000,000,000 | ---D | C] -- C:\Program Files\DVDVideoSoft
[2011/12/01 14:06:15 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DVDVideoSoft
[2011/12/01 13:37:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/01 13:34:08 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/11/30 16:37:31 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{3957B240-28BC-49E2-967D-EF57B285B041}
[2011/11/29 13:12:50 | 000,000,000 | ---D | C] -- C:\Users\Felixb\AppData\Local\{8C9068A1-1720-4B19-B55E-68B8062DD27D}
[2010/11/26 15:30:02 | 007,387,648 | ---- | C] (Chaos Software Ltd) -- C:\Program Files\vray2010.dll
[2010/11/26 15:30:02 | 003,291,320 | ---- | C] (Intel Corporation) -- C:\Program Files\libmmd.dll
[2010/11/26 15:30:02 | 000,914,944 | ---- | C] (Joe Alter Inc) -- C:\Program Files\HairVrPrims2010.dll
[2010/09/10 15:33:27 | 000,061,440 | ---- | C] ( ) -- C:\Windows\System32\cphc600.dll
[2010/05/05 18:59:10 | 000,060,928 | ---- | C] ( ) -- C:\Windows\System32\a3d.dll
[2010/05/05 18:38:18 | 000,012,800 | ---- | C] ( ) -- C:\Windows\System32\killapps.exe
[26 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Felixb\Desktop\*.tmp files -> C:\Users\Felixb\Desktop\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/12/29 01:41:10 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Felixb\Desktop\OTL.exe
[2011/12/29 01:40:47 | 112,523,033 | ---- | M] () -- C:\Users\Felixb\Desktop\EmsisoftEmergencyKit.zip
[2011/12/29 00:03:02 | 000,291,638 | ---- | M] () -- C:\Users\Felixb\Documents\iphone4-wallpaper-cf22.png
[2011/12/29 00:00:57 | 000,335,531 | ---- | M] () -- C:\Users\Felixb\Documents\iphoneback.jpg
[2011/12/29 00:00:17 | 000,335,531 | ---- | M] () -- C:\Users\Felixb\Desktop\background.jpg
[2011/12/28 23:59:39 | 000,335,531 | ---- | M] () -- C:\Users\Felixb\Desktop\AirMax1Backgroun.jpg
[2011/12/28 23:56:47 | 000,291,638 | ---- | M] () -- C:\Users\Felixb\Desktop\bg.png
[2011/12/28 22:19:37 | 000,001,066 | ---- | M] () -- C:\Users\Felixb\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/12/28 22:19:17 | 000,001,067 | ---- | M] () -- C:\Users\Felixb\Desktop\FL Studio 9.lnk
[2011/12/28 20:24:00 | 000,651,892 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2011/12/28 20:24:00 | 000,120,824 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2011/12/28 17:11:18 | 000,609,931 | ---- | M] () -- C:\Users\Felixb\Documents\am1solebg.jpg
[2011/12/28 14:49:19 | 000,000,132 | ---- | M] () -- C:\Users\Felixb\AppData\Roaming\Adobe AIFF Format CS5 Prefs
[2011/12/28 12:35:20 | 000,014,992 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/12/28 12:35:20 | 000,014,992 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/12/28 12:18:00 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2011/12/28 12:17:56 | 2615,762,944 | -HS- | M] () -- C:\hiberfil.sys
[2011/12/23 11:55:24 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2011/12/22 16:47:54 | 000,137,464 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2011/12/22 16:47:45 | 000,214,520 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[2011/12/22 16:47:45 | 000,214,520 | ---- | M] () -- C:\Windows\System32\PnkBstrB.ex0
[2011/12/20 00:40:56 | 000,000,971 | ---- | M] () -- C:\Users\Felixb\Application Data\Microsoft\Internet Explorer\Quick Launch\Crazybump.lnk
[2011/12/20 00:40:56 | 000,000,947 | ---- | M] () -- C:\Users\Felixb\Desktop\Crazybump.lnk
[2011/12/19 10:58:08 | 008,542,437 | ---- | M] () -- C:\Users\Felixb\Desktop\DUBSTEP ACADEMY (OFFICIAL VIDEO BY JON ZOMBIE).mp3
[2011/12/19 10:15:35 | 734,396,416 | ---- | M] () -- C:\Users\Felixb\Desktop\Rise of the Footsoldier[2007]DvDrip[Eng]-FXG.avi
[2011/12/16 10:51:27 | 003,861,872 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2011/12/15 22:16:54 | 000,079,360 | ---- | M] () -- C:\Windows\System32\ff_vfw.dll
[2011/12/15 21:37:19 | 000,000,118 | ---- | M] () -- C:\Windows\System32\MRT.INI
[2011/12/13 11:01:00 | 001,698,408 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Windows\RtlExUpd.dll
[2011/12/11 20:36:43 | 000,000,132 | ---- | M] () -- C:\Users\Felixb\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2011/12/08 18:39:26 | 000,001,167 | ---- | M] () -- C:\Users\Felixb\Desktop\DVDVideoSoft Free Studio.lnk
[2011/12/05 20:41:51 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011/12/04 19:19:28 | 000,356,053 | ---- | M] () -- C:\Users\Felixb\Desktop\sigurdjung.jpg
[2011/12/02 18:07:43 | 000,001,456 | ---- | M] () -- C:\Users\Felixb\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/12/01 13:41:55 | 000,001,151 | ---- | M] () -- C:\Windows\System32\mapisvc.inf
[2011/11/29 16:24:38 | 1137,708,528 | ---- | M] () -- C:\Users\Felixb\Desktop\Nightmare Outdoor - Lost In The Forest (2010).mp4
[26 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Felixb\Desktop\*.tmp files -> C:\Users\Felixb\Desktop\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/12/29 01:40:09 | 112,523,033 | ---- | C] () -- C:\Users\Felixb\Desktop\EmsisoftEmergencyKit.zip
[2011/12/29 00:03:00 | 000,291,638 | ---- | C] () -- C:\Users\Felixb\Documents\iphone4-wallpaper-cf22.png
[2011/12/29 00:00:56 | 000,335,531 | ---- | C] () -- C:\Users\Felixb\Documents\iphoneback.jpg
[2011/12/29 00:00:17 | 000,335,531 | ---- | C] () -- C:\Users\Felixb\Desktop\background.jpg
[2011/12/28 23:59:38 | 000,335,531 | ---- | C] () -- C:\Users\Felixb\Desktop\AirMax1Backgroun.jpg
[2011/12/28 23:56:46 | 000,291,638 | ---- | C] () -- C:\Users\Felixb\Desktop\bg.png
[2011/12/28 22:19:37 | 000,001,066 | ---- | C] () -- C:\Users\Felixb\Desktop\ASIO4ALL v2 Instruction Manual.lnk
[2011/12/28 22:19:17 | 000,001,067 | ---- | C] () -- C:\Users\Felixb\Desktop\FL Studio 9.lnk
[2011/12/28 17:11:13 | 000,609,931 | ---- | C] () -- C:\Users\Felixb\Documents\am1solebg.jpg
[2011/12/28 14:49:19 | 000,000,132 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\Adobe AIFF Format CS5 Prefs
[2011/12/20 00:40:56 | 000,000,971 | ---- | C] () -- C:\Users\Felixb\Application Data\Microsoft\Internet Explorer\Quick Launch\Crazybump.lnk
[2011/12/20 00:40:56 | 000,000,947 | ---- | C] () -- C:\Users\Felixb\Desktop\Crazybump.lnk
[2011/12/19 10:05:46 | 734,396,416 | ---- | C] () -- C:\Users\Felixb\Desktop\Rise of the Footsoldier[2007]DvDrip[Eng]-FXG.avi
[2011/12/17 12:51:50 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2011/12/17 11:33:23 | 008,542,437 | ---- | C] () -- C:\Users\Felixb\Desktop\DUBSTEP ACADEMY (OFFICIAL VIDEO BY JON ZOMBIE).mp3
[2011/12/15 21:37:19 | 000,000,118 | ---- | C] () -- C:\Windows\System32\MRT.INI
[2011/12/08 18:39:26 | 000,001,167 | ---- | C] () -- C:\Users\Felixb\Desktop\DVDVideoSoft Free Studio.lnk
[2011/12/05 20:41:51 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\Need For Speed World.lnk
[2011/12/04 19:17:27 | 000,356,053 | ---- | C] () -- C:\Users\Felixb\Desktop\sigurdjung.jpg
[2011/11/29 15:20:34 | 1137,708,528 | ---- | C] () -- C:\Users\Felixb\Desktop\Nightmare Outdoor - Lost In The Forest (2010).mp4
[2011/10/28 02:03:39 | 000,024,576 | R--- | C] () -- C:\Windows\System32\AsIO.dll
[2011/10/28 02:03:39 | 000,011,296 | R--- | C] () -- C:\Windows\System32\drivers\AsIO.sys
[2011/10/28 02:03:36 | 000,011,832 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp64.sys
[2011/10/28 02:03:36 | 000,010,216 | ---- | C] () -- C:\Windows\System32\drivers\AsInsHelp32.sys
[2011/10/28 02:01:57 | 000,080,416 | ---- | C] () -- C:\Windows\System32\RtNicProp32.dll
[2011/10/28 01:32:07 | 000,001,769 | ---- | C] () -- C:\Windows\Language_trs.ini
[2011/10/28 01:32:04 | 000,032,431 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2011/10/13 21:29:40 | 000,042,392 | ---- | C] () -- C:\Windows\System32\xfcodec.dll
[2011/10/04 19:17:26 | 000,004,608 | ---- | C] () -- C:\Users\Felixb\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/09/29 21:09:37 | 000,000,132 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\Adobe Targa Format CS5 Prefs
[2011/04/09 17:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2011/03/15 23:12:54 | 000,057,344 | R--- | C] () -- C:\Windows\System32\XSIChooser.exe
[2011/03/05 22:27:07 | 000,057,552 | ---- | C] () -- C:\Windows\System32\WkDos.exe
[2010/11/26 18:44:20 | 000,000,231 | ---- | C] () -- C:\Windows\System32\3dsmax.ini
[2010/11/26 18:44:20 | 000,000,043 | ---- | C] () -- C:\Windows\System32\InstallSettings.ini
[2010/11/26 15:30:04 | 000,172,032 | ---- | C] () -- C:\Program Files\vraydummy2010.max
[2010/11/26 15:30:04 | 000,113,152 | ---- | C] () -- C:\Program Files\vrayspawner2010.exe
[2010/11/26 15:30:04 | 000,006,544 | ---- | C] () -- C:\Program Files\vraydummy2010.xml
[2010/11/26 15:30:04 | 000,000,125 | ---- | C] () -- C:\Program Files\plugin.ini
[2010/10/24 16:55:10 | 000,000,056 | -H-- | C] () -- C:\Windows\System32\ezsidmv.dat
[2010/10/11 17:52:02 | 000,000,132 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2010/10/08 17:35:08 | 000,142,336 | -H-- | C] () -- C:\Windows\System32\mlfcache.dat
[2010/09/21 18:11:50 | 000,001,456 | ---- | C] () -- C:\Users\Felixb\AppData\Local\Adobe Save for Web 12.0 Prefs
[2010/09/15 21:49:33 | 000,165,376 | ---- | C] () -- C:\Windows\System32\unrar.dll
[2010/09/15 16:10:04 | 000,482,408 | ---- | C] () -- C:\Windows\ssndii.exe
[2010/09/15 16:09:52 | 000,011,227 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\SmarThruOptions.xml
[2010/09/15 16:09:41 | 000,036,864 | ---- | C] () -- C:\Windows\System32\SvcMan.exe
[2010/09/15 16:09:35 | 000,172,032 | ---- | C] () -- C:\Windows\System32\SecSNMP.dll
[2010/09/15 16:09:34 | 000,094,208 | ---- | C] () -- C:\Windows\System32\SamFaxPort.dll
[2010/09/15 16:09:28 | 000,000,124 | ---- | C] () -- C:\Windows\Readiris.ini
[2010/09/15 16:09:26 | 000,023,040 | ---- | C] () -- C:\Windows\System32\irisco32.dll
[2010/09/15 16:07:23 | 000,113,768 | R--- | C] () -- C:\Windows\Wiainst.exe
[2010/09/15 16:06:19 | 000,147,456 | ---- | C] () -- C:\Windows\System32\SaMinDrv.dll
[2010/09/15 16:06:19 | 000,027,136 | ---- | C] () -- C:\Windows\System32\SaImgFlt.dll
[2010/09/15 16:06:19 | 000,011,264 | ---- | C] () -- C:\Windows\System32\SaSegFlt.dll
[2010/09/15 16:06:19 | 000,010,752 | ---- | C] () -- C:\Windows\System32\SaErHdlr.dll
[2010/09/15 16:06:04 | 000,022,723 | ---- | C] () -- C:\Windows\System32\sst1cl3.dll
[2010/09/14 14:39:40 | 000,000,029 | ---- | C] () -- C:\Windows\sfbm.INI
[2010/09/14 12:07:30 | 000,000,319 | ---- | C] () -- C:\Windows\game.ini
[2010/09/12 16:59:18 | 000,000,262 | ---- | C] () -- C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/09/12 16:57:49 | 000,137,464 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2010/09/12 16:57:49 | 000,022,328 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\PnkBstrK.sys
[2010/09/12 16:57:27 | 000,214,520 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2010/09/12 16:57:26 | 000,075,136 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2010/09/10 16:14:24 | 000,148,480 | ---- | C] () -- C:\Windows\System32\APOMngr.DLL
[2010/09/10 16:14:24 | 000,073,728 | ---- | C] () -- C:\Windows\System32\CmdRtr.DLL
[2010/09/10 15:33:27 | 000,422,144 | ---- | C] () -- C:\Windows\System32\drivers\phc600.sys
[2010/09/10 15:33:27 | 000,015,488 | ---- | C] () -- C:\Windows\phc600.ini
[2010/09/10 15:04:59 | 000,003,072 | ---- | C] () -- C:\Windows\CTXFIDUT.DLL
[2010/09/10 15:00:14 | 000,000,760 | ---- | C] () -- C:\Users\Felixb\AppData\Roaming\setup_ldm.iss
[2010/05/05 19:37:52 | 000,021,204 | ---- | C] () -- C:\Windows\System32\instwdm.ini
[2010/05/05 19:37:50 | 000,000,054 | ---- | C] () -- C:\Windows\System32\ctzapxx.ini
[2010/05/05 18:56:46 | 000,002,560 | ---- | C] () -- C:\Windows\System32\CtxfiRes.dll
[2010/05/05 18:46:30 | 000,321,512 | ---- | C] () -- C:\Windows\System32\ctdlang.dat
[2010/05/05 18:41:30 | 000,016,384 | ---- | C] () -- C:\Windows\System32\regplib.exe
[2010/05/05 18:38:22 | 000,007,680 | ---- | C] () -- C:\Windows\System32\enlocstr.exe
[2009/07/16 04:36:30 | 000,013,216 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2009/07/14 05:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 05:33:53 | 003,861,872 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/14 03:05:48 | 000,651,892 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/14 03:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/14 03:05:48 | 000,120,824 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/14 03:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/14 03:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/14 03:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/14 00:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 00:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/14 00:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 22:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2009/06/03 23:40:44 | 000,056,509 | ---- | C] () -- C:\Windows\System32\ctdnlstr.dat
[2009/04/02 13:30:14 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2006/05/24 06:00:48 | 000,037,888 | ---- | C] () -- C:\Windows\System32\CTBURST.DLL
[2006/05/24 05:20:42 | 000,034,304 | ---- | C] () -- C:\Windows\PSCONV.EXE
[2006/05/24 04:37:12 | 000,140,643 | ---- | C] () -- C:\Windows\System32\CTBAS2W.DAT
[2006/05/24 04:34:34 | 000,264,526 | ---- | C] () -- C:\Windows\System32\CTSBAS2W.DAT
[2006/05/24 04:34:14 | 000,113,221 | ---- | C] () -- C:\Windows\System32\CTBASICW.DAT
[2006/05/24 04:34:13 | 000,231,281 | ---- | C] () -- C:\Windows\System32\CTSBASW.DAT
[2006/05/24 04:33:34 | 000,053,932 | ---- | C] () -- C:\Windows\System32\CTDAUGHT.DAT
[2006/05/24 04:33:33 | 000,313,207 | ---- | C] () -- C:\Windows\System32\CTSTATIC.DAT
[2005/07/27 06:13:12 | 000,000,285 | ---- | C] () -- C:\Windows\System32\kill.ini
[2005/06/07 14:10:50 | 000,070,656 | ---- | C] () -- C:\Windows\System32\CTMMACTL.DLL

========== LOP Check ==========

[2011/10/23 14:10:01 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\2012IGFPIRATEKART
[2011/11/24 20:31:34 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\ACD Systems
[2011/02/12 20:24:58 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\AIMP3
[2011/09/07 22:01:51 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Autodesk
[2010/09/16 19:44:07 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\AVG9
[2011/05/30 12:45:15 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Canon
[2010/09/12 11:48:20 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\DAEMON Tools Lite
[2011/12/28 12:19:44 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Dropbox
[2011/12/17 11:30:36 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\DVDVideoSoft
[2011/01/18 23:28:44 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\DVDVideoSoftIEHelpers
[2011/10/28 02:10:06 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Easeware
[2011/05/31 07:40:15 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Flickr
[2010/09/10 15:28:15 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\GetRightToGo
[2010/09/15 15:53:57 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\GHISLER
[2011/12/27 12:24:16 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Gyukeg
[2011/12/29 00:02:07 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Hardcore
[2011/02/11 16:09:52 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\HDRLightStudio
[2011/12/29 00:02:40 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Juce VST Host
[2010/09/10 15:00:21 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Leadertech
[2011/09/06 23:31:53 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\ManyCam
[2011/06/05 19:57:47 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Mumble
[2011/12/05 21:13:40 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Need for Speed World
[2010/09/28 15:16:40 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Publish Providers
[2011/12/08 17:52:47 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Qyfyyg
[2010/09/15 16:09:55 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\SmarThru4
[2010/10/04 17:47:56 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Sony
[2010/09/14 14:30:51 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011/10/06 15:00:53 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Subversion
[2011/06/06 15:02:21 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\TS3Client
[2011/12/29 06:34:23 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\uTorrent
[2011/08/28 14:27:17 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\Wacom
[2011/08/28 14:27:18 | 000,000,000 | ---D | M] -- C:\Users\Felixb\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2011/10/28 02:22:58 | 000,000,438 | ---- | M] () -- C:\Windows\Tasks\DriverNavigator Scheduled Scan.job
[2011/07/31 11:23:48 | 000,032,618 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >


Could someone please help me with this.

Cheers
  • 0

Advertisements


#2
myrti

myrti

    Expert

  • Expert
  • 2,580 posts
Hi,

the log shows some signs of infection. To get a better picture please also run a scan with gmer:
Please download GMER from one of the following locations and save it to your desktop:
  • Main Mirror
    This version will download a randomly named file (Recommended)
  • Zipped Mirror
    This version will download a zip file you will need to extract first. If you use this mirror, please extract the zip file to your desktop.
  • Disconnect from the Internet and close all running programs.
  • Temporarily disable any real-time active protection so your security programs will not conflict with gmer's driver.
  • Double-click on the randomly named GMER file (i.e. n7gmo46c.exe) and allow the gmer.sys driver to load if asked.
  • Note: If you downloaded the zipped version, extract the file to its own folder such as C:\gmer and then double-click on gmer.exe.

    Posted Image
  • GMER will open to the Rootkit/Malware tab and perform an automatic quick scan when first run. (do not use the computer while the scan is in progress)
  • If you receive a WARNING!!! about rootkit activity and are asked to fully scan your system...click NO.
  • Now click the Scan button. If you see a rootkit warning window, click OK.
  • When the scan is finished, click the Save... button to save the scan results to your Desktop. Save the file as gmer.log.
  • Click the Copy button and paste the results into your next reply.
  • Exit GMER and re-enable all active protection when done.
-- If you encounter any problems, try running GMER in Safe Mode.
  • 0

#3
myrti

myrti

    Expert

  • Expert
  • 2,580 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP