The problem started when i downloaded a file online which is a crack file to play the pc game battlefield3. The name of the file is bif3.exe. When i unzipped it eset AV would be activated and tell me that the file was infected by the MSIL/injector.PH trojan virus. Against my better judgement i disabled the real time system file protection as AV wrongly detects these cracked files as viruses on a number of times. Anyway i executed the file and nothing happened. Anyway it took like 1 day before my AV started showing that my c:\windows\win32\sever.exe file was infected and it had quaratined the file, the problem is the warning message keeps on coming up and up and up again and again and again non stop. I am currently running a full system scan on my pc as i write this and a number of theats have been detected. I googled a bit on this virus and found out that it infects a number of files on the pc and it lists which files are infected but i have not taken to manually remove any of them as i am no expert and don't know if it will damage my pc instead hence i started a thread here. Here is my OTL log that i have obtained. Hope that it can be fixed quickly. Thanks to anyone that will help me.
OTL logfile created on: 25/1/2012 7:07:51 PM - Run 4
OTL by OldTimer - Version 3.2.31.0 Folder = D:\idm downloads
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00004809 | Country: Singapore | Language: ENE | Date Format: d/M/yyyy
8.00 Gb Total Physical Memory | 5.20 Gb Available Physical Memory | 65.01% Memory free
8.00 Gb Paging File | 4.80 Gb Available in Paging File | 59.99% Paging File free
Paging file location(s): [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 47.33 Gb Total Space | 18.86 Gb Free Space | 39.85% Space Free | Partition Type: NTFS
Drive D: | 64.45 Gb Total Space | 15.27 Gb Free Space | 23.69% Space Free | Partition Type: NTFS
Drive E: | 298.09 Gb Total Space | 72.56 Gb Free Space | 24.34% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 45.16 Gb Free Space | 19.39% Space Free | Partition Type: NTFS
Computer Name: VIRGILEVEGA-PC | User Name: Virgile Vega | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/01/25 18:54:54 | 000,584,192 | ---- | M] (OldTimer Tools) -- D:\idm downloads\OTL.exe
PRC - [2012/01/03 21:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/12/29 12:15:01 | 003,462,552 | ---- | M] (Tonec Inc.) -- D:\Extra program files x86\Internet Download Manager\IDMan.exe
PRC - [2011/12/27 16:55:10 | 000,055,296 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe
PRC - [2011/12/27 16:55:10 | 000,024,064 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\capiws.exe
PRC - [2011/12/21 15:24:51 | 000,924,632 | ---- | M] (Mozilla Corporation) -- D:\Extra program files x86\Mozilla Firefox\firefox.exe
PRC - [2011/11/09 17:55:26 | 001,014,784 | ---- | M] (IVT Corporation) -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BlueSoleilCS.exe
PRC - [2011/11/07 15:37:50 | 000,327,766 | ---- | M] (IVT Corporation) -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BtTray.exe
PRC - [2011/11/07 15:34:14 | 000,147,563 | ---- | M] (IVT Corporation) -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BsMobileCS.exe
PRC - [2011/02/02 21:40:38 | 000,145,184 | ---- | M] (Sun Microsystems, Inc.) -- D:\Extra program files x86\Java\bin\javaw.exe
PRC - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) -- D:\Extra program files x86\ESET\ESET Smart Security\x86\ekrn.exe
PRC - [2010/05/25 22:28:58 | 000,263,600 | ---- | M] (Tonec Inc.) -- D:\Extra program files x86\Internet Download Manager\IEMonitor.exe
PRC - [2010/05/05 16:56:06 | 000,251,392 | ---- | M] () -- D:\Extra program files x86\Razer\DeathAdder\razerhid.exe
PRC - [2010/04/27 14:41:26 | 000,218,112 | ---- | M] () -- D:\Extra program files x86\Razer\DeathAdder\razertra.exe
PRC - [2007/12/19 11:58:24 | 000,163,840 | ---- | M] (Razer Inc.) -- D:\Extra program files x86\Razer\DeathAdder\razerofa.exe
========== Modules (No Company Name) ==========
MOD - [2011/12/27 16:55:10 | 000,055,296 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\ovpntray.exe
MOD - [2011/12/21 15:24:51 | 002,124,760 | ---- | M] () -- D:\Extra program files x86\Mozilla Firefox\mozjs.dll
MOD - [2011/11/29 00:15:03 | 008,527,008 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
MOD - [2011/11/12 11:48:50 | 000,039,424 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.SSL.pyd
MOD - [2011/11/12 11:48:50 | 000,006,656 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\pyovpnc.pyd
MOD - [2011/11/12 11:48:48 | 000,061,440 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.crypto.pyd
MOD - [2011/11/12 11:48:48 | 000,010,240 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\OpenSSL.rand.pyd
MOD - [2011/11/12 11:48:32 | 000,007,680 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\twisted.protocols._c_urlarg.pyd
MOD - [2011/11/12 11:48:10 | 000,019,968 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\zope.interface._zope_interface_coptimizations.pyd
MOD - [2011/11/07 15:34:16 | 000,028,672 | ---- | M] () -- C:\Windows\SysWOW64\BsMobileCSps.dll
MOD - [2011/08/19 00:44:10 | 000,005,632 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\ovpntray.dll
MOD - [2011/05/01 01:32:08 | 000,054,000 | ---- | M] () -- C:\Windows\SysWOW64\PrxerNsp.dll
MOD - [2011/03/28 11:04:52 | 000,237,568 | ---- | M] () -- D:\Extra program files x86\IVT Corporation\BlueSoleil\Mobile\BaseLib.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2011/02/27 09:12:56 | 000,110,080 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\pywintypes26.dll
MOD - [2011/02/26 10:33:20 | 000,167,424 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\win32gui.pyd
MOD - [2011/02/26 10:33:14 | 000,096,768 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\win32api.pyd
MOD - [2011/02/26 10:32:28 | 000,035,840 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\win32process.pyd
MOD - [2011/02/26 10:31:48 | 000,017,408 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\win32event.pyd
MOD - [2010/08/24 17:48:54 | 000,011,776 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\select.pyd
MOD - [2010/08/24 17:48:52 | 000,286,208 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\_hashlib.pyd
MOD - [2010/08/24 17:48:48 | 000,153,088 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\pyexpat.pyd
MOD - [2010/08/24 17:48:16 | 000,073,728 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\_ctypes.pyd
MOD - [2010/08/24 17:48:02 | 000,720,896 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\_ssl.pyd
MOD - [2010/08/24 17:47:50 | 000,040,448 | ---- | M] () -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\_socket.pyd
MOD - [2010/05/05 16:56:06 | 000,251,392 | ---- | M] () -- D:\Extra program files x86\Razer\DeathAdder\razerhid.exe
MOD - [2010/04/27 14:41:26 | 000,218,112 | ---- | M] () -- D:\Extra program files x86\Razer\DeathAdder\razertra.exe
MOD - [2010/03/31 21:59:20 | 000,122,880 | ---- | M] () -- D:\Extra program files x86\IVT Corporation\BlueSoleil\Mobile\s40pack.dll
MOD - [2003/05/01 17:23:28 | 000,041,472 | ---- | M] () -- D:\Extra program files x86\IVT Corporation\BlueSoleil\Mobile\CsCvt.dll
========== Win32 Services (SafeList) ==========
SRV:64bit: - [2012/01/03 11:21:42 | 000,235,520 | ---- | M] (AMD) [Disabled | Stopped] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2009/07/14 09:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 09:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/01/03 21:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/12/27 16:55:10 | 000,024,064 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\OpenVPN Technologies\OpenVPN Client\core\capiws.exe -- (OpenVPNAccessClient)
SRV - [2011/12/09 14:39:52 | 000,135,584 | ---- | M] (Futuremark Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Futuremark Shared\Futuremark SystemInfo\FMSISvc.exe -- (Futuremark SystemInfo Service)
SRV - [2011/11/09 17:55:26 | 001,014,784 | ---- | M] (IVT Corporation) [Auto | Running] -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BlueSoleilCS.exe -- (BlueSoleilCS)
SRV - [2011/11/07 15:39:42 | 000,199,680 | ---- | M] (IVT Corporation) [On_Demand | Running] -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BsHelpCS.exe -- (BsHelpCS)
SRV - [2011/11/07 15:34:14 | 000,147,563 | ---- | M] (IVT Corporation) [Auto | Running] -- D:\Extra program files x86\IVT Corporation\BlueSoleil\BsMobileCS.exe -- (BsMobileCS)
SRV - [2011/06/12 11:15:00 | 031,125,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- D:\Extra program files x86\Microsoft Office\Office14\GROOVE.EXE -- (Microsoft SharePoint Workspace Audit Service)
SRV - [2010/08/12 14:18:40 | 000,042,360 | ---- | M] (ESET) [On_Demand | Stopped] -- D:\Extra program files x86\ESET\ESET Smart Security\EHttpSrv.exe -- (EhttpSrv)
SRV - [2010/08/12 14:16:26 | 000,810,144 | ---- | M] (ESET) [Auto | Running] -- D:\Extra program files x86\ESET\ESET Smart Security\x86\ekrn.exe -- (ekrn)
SRV - [2010/07/28 23:37:16 | 000,009,936 | ---- | M] () [On_Demand | Stopped] -- D:\Extra program files x86\Prio\prio_svc.exe -- (prio_svc)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/10/19 12:11:50 | 000,828,936 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009/09/28 09:27:56 | 000,057,096 | ---- | M] (Greatis Software, LLC) [Disabled | Stopped] -- C:\Program Files (x86)\BootRacer\BootRacerServ.exe -- (BootRacerServ)
SRV - [2009/07/16 17:04:16 | 000,316,664 | ---- | M] (Valve Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2009/06/11 05:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009/02/11 17:38:40 | 000,354,840 | ---- | M] (Intel Corporation) [Disabled | Stopped] -- C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe -- (IAANTMON) Intel®
SRV - [2008/09/08 07:59:00 | 000,575,488 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/01/03 12:08:44 | 010,720,256 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/01/03 10:26:02 | 000,327,168 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2011/12/16 01:29:42 | 000,031,232 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2011/10/18 01:40:50 | 000,093,712 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2011/08/19 01:46:06 | 000,030,720 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tapoas.sys -- (tapoas)
DRV:64bit: - [2011/07/27 10:30:40 | 000,024,456 | ---- | M] (IVT Corporation.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\BtHidBus.sys -- (BtHidBus)
DRV:64bit: - [2011/07/27 10:29:08 | 000,025,352 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btcombus.sys -- (BTCOMBUS)
DRV:64bit: - [2011/07/27 10:28:58 | 000,029,576 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcomport.sys -- (BTCOM)
DRV:64bit: - [2011/07/27 10:28:28 | 000,042,888 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btcusb.sys -- (Btcsrusb)
DRV:64bit: - [2011/07/06 23:14:42 | 000,145,008 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:64bit: - [2011/06/01 20:17:18 | 000,033,888 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\appliand.sys -- (appliandMP)
DRV:64bit: - [2011/06/01 20:17:18 | 000,033,888 | ---- | M] (Applian Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\appliand.sys -- (appliand)
DRV:64bit: - [2011/05/23 14:33:04 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(5).sys -- (WsAudio_DeviceS(5)) WsAudio_DeviceS(5)
DRV:64bit: - [2011/05/23 14:33:04 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(4).sys -- (WsAudio_DeviceS(4)) WsAudio_DeviceS(4)
DRV:64bit: - [2011/05/23 14:33:04 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(3).sys -- (WsAudio_DeviceS(3)) WsAudio_DeviceS(3)
DRV:64bit: - [2011/05/23 14:33:04 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(2).sys -- (WsAudio_DeviceS(2)) WsAudio_DeviceS(2)
DRV:64bit: - [2011/05/23 14:33:04 | 000,029,288 | ---- | M] (Wondershare) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WsAudio_DeviceS(1).sys -- (WsAudio_DeviceS(1)) WsAudio_DeviceS(1)
DRV:64bit: - [2011/05/10 08:06:14 | 000,022,528 | ---- | M] (Apple Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netaapl64.sys -- (Netaapl)
DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2011/03/11 14:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 14:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/12/24 18:13:39 | 000,254,496 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman)
DRV:64bit: - [2010/12/24 17:47:23 | 001,455,648 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm251.sys -- (tdrpman251) Acronis Try&Decide and Restore Points filter (build 251)
DRV:64bit: - [2010/12/24 17:47:23 | 000,929,312 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter)
DRV:64bit: - [2010/12/18 09:40:30 | 000,191,960 | ---- | M] (EldoS Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\cbfs64.sys -- (CbFs)
DRV:64bit: - [2010/12/15 19:03:09 | 000,083,488 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\tifsfilt.sys -- (tifsfilter)
DRV:64bit: - [2010/12/15 00:10:37 | 000,834,544 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2010/11/20 21:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 19:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/20 19:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2010/08/18 22:19:46 | 000,020,488 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\btnetdrv.sys -- (BT)
DRV:64bit: - [2010/07/29 13:31:26 | 000,171,152 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfw.sys -- (epfw)
DRV:64bit: - [2010/07/29 13:31:26 | 000,168,544 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2010/07/29 13:31:26 | 000,141,264 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2010/07/29 13:31:26 | 000,050,624 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfp.sys -- (epfwwfp)
DRV:64bit: - [2010/07/29 13:31:26 | 000,033,632 | ---- | M] (ESET) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\epfwndis.sys -- (Epfwndis)
DRV:64bit: - [2010/07/15 08:44:20 | 000,016,776 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\epmntdrv.sys -- (epmntdrv)
DRV:64bit: - [2010/07/15 08:44:20 | 000,009,096 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\EuGdiDrv.sys -- (EuGdiDrv)
DRV:64bit: - [2010/04/27 22:01:44 | 000,062,160 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RAMDiskVE.sys -- (RAMDiskVE)
DRV:64bit: - [2010/04/19 17:04:44 | 000,012,032 | ---- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dadder.sys -- (DAdderFltr)
DRV:64bit: - [2010/04/06 18:33:10 | 000,030,088 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btnetBus.sys -- (btnetBUs)
DRV:64bit: - [2010/04/06 18:32:48 | 000,027,016 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IvtBtBus.sys -- (IvtBtBUs)
DRV:64bit: - [2009/12/30 10:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:64bit: - [2009/12/21 21:50:00 | 000,007,552 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vHidDev.sys -- (vhidmini)
DRV:64bit: - [2009/12/16 08:19:56 | 000,044,800 | ---- | M] (Advanced Card Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acr122.sys -- (ACR122U)
DRV:64bit: - [2009/10/21 17:16:54 | 000,243,200 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:64bit: - [2009/10/12 15:23:22 | 000,114,304 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbdev.sys -- (hwusbdev)
DRV:64bit: - [2009/09/10 15:31:56 | 000,117,248 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:64bit: - [2009/07/14 09:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 09:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 09:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/17 14:02:20 | 000,036,872 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BlueletSCOAudio.sys -- (BlueletSCOAudio)
DRV:64bit: - [2009/06/17 14:02:12 | 000,036,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\blueletaudio.sys -- (BlueletAudio)
DRV:64bit: - [2009/06/11 04:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 04:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 04:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 04:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/18 13:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/02/11 17:26:18 | 000,407,576 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2008/08/28 12:44:42 | 000,025,600 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2007/10/28 20:22:32 | 000,340,480 | ---- | M] (Marvell Semiconductor, Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WN111x.sys -- (MRV6X64U) Marvell TOPDOG 802.11n WLAN Driver for Vista x64 (USB8x)
DRV:64bit: - [2007/04/20 21:29:52 | 001,037,312 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\athrxusb.sys -- (athrusb)
DRV - [2010/07/15 08:44:20 | 000,014,216 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\epmntdrv.sys -- (epmntdrv)
DRV - [2010/07/15 08:44:20 | 000,008,456 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\EuGdiDrv.sys -- (EuGdiDrv)
DRV - [2009/07/14 09:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/06/17 14:02:12 | 000,036,360 | ---- | M] (IVT Corporation.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\blueletaudio.sys -- (BlueletAudio)
DRV - [2007/09/11 03:23:46 | 000,018,944 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\mrv64drv.sys -- (Mrvleap)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,DefaultNetProfile = 528064716
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,DefaultNetworkProfile = 528064658
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://xin.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://xin.msn.com/?rd=1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local;*.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://en-GB.start3....en-GB:official"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.9
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.1
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:2.1.2.1rc1
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198
FF - prefs.js..extensions.enabledItems: [email protected]:11.0.1.400
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.7
FF - prefs.js..extensions.enabledItems: [email protected]:0.7.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: [email protected]:7.3.1
FF - prefs.js..network.proxy.backup.ftp: "212.117.166.26"
FF - prefs.js..network.proxy.backup.ftp_port: 18231
FF - prefs.js..network.proxy.backup.gopher: "212.117.166.26"
FF - prefs.js..network.proxy.backup.gopher_port: 18231
FF - prefs.js..network.proxy.backup.socks: "212.117.166.26"
FF - prefs.js..network.proxy.backup.socks_port: 18231
FF - prefs.js..network.proxy.backup.ssl: "212.117.166.26"
FF - prefs.js..network.proxy.backup.ssl_port: 18231
FF - prefs.js..network.proxy.ftp: "201.75.14.179"
FF - prefs.js..network.proxy.ftp_port: 3128
FF - prefs.js..network.proxy.gopher: "201.75.14.179"
FF - prefs.js..network.proxy.gopher_port: 3128
FF - prefs.js..network.proxy.http: "201.75.14.179"
FF - prefs.js..network.proxy.http_port: 3128
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.socks: "201.75.14.179"
FF - prefs.js..network.proxy.socks_port: 3128
FF - prefs.js..network.proxy.ssl: "201.75.14.179"
FF - prefs.js..network.proxy.ssl_port: 3128
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Extra program files x86\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: D:\Extra program files x86\Java\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: D:\EXTRAP~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: D:\EXTRAP~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.18: D:\Extra program files x86\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.18: D:\Extra program files x86\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: D:\EXTRA PROGRAM FILES X86\ESET\ESET SMART SECURITY\MOZILLA THUNDERBIRD [2010/12/23 20:59:11 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: D:\Extra program files x86\Mozilla Firefox\components [2012/01/14 06:51:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: D:\Extra program files x86\Mozilla Firefox\plugins [2012/01/12 18:20:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: D:\Extra program files x86\ESET\ESET Smart Security\Mozilla Thunderbird [2010/12/23 20:59:11 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Virgile Vega\AppData\Roaming\IDM\idmmzcc5 [2012/01/12 13:52:33 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Virgile Vega\AppData\Roaming\IDM\idmmzcc5 [2012/01/12 13:52:33 | 000,000,000 | ---D | M]
[2010/12/14 01:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Extensions
[2012/01/25 06:56:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\y4uqrm15.default\extensions
[2011/06/01 23:53:11 | 000,000,000 | ---D | M] (Save Images) -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\y4uqrm15.default\extensions\[email protected]
[2010/12/14 01:07:08 | 000,000,000 | ---D | M] ("AutocompletePro - Your handy search suggestions tool") -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\y4uqrm15.default\extensions\[email protected]
[2010/12/14 01:07:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\y4uqrm15_original.default\extensions
[2010/12/14 01:07:08 | 000,000,000 | ---D | M] ("AutocompletePro - Your handy search suggestions tool") -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\y4uqrm15_original.default\extensions\[email protected]
[2010/12/14 01:02:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Virgile Vega\AppData\Roaming\Mozilla\Firefox\Profiles\yuks5tp7.default\extensions
[2012/01/12 13:52:33 | 000,000,000 | ---D | M] (IDM CC) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\IDM\IDMMZCC5
() (No name found) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Y4UQRM15.DEFAULT\EXTENSIONS\{46551EC9-40F0-4E47-8E18-8E5CF550CFB8}.XPI
() (No name found) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Y4UQRM15.DEFAULT\EXTENSIONS\{73A6FE31-595D-460B-A920-FCC0F8843232}.XPI
() (No name found) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Y4UQRM15.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
() (No name found) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Y4UQRM15.DEFAULT\EXTENSIONS\{DDC359D1-844A-42A7-9AA1-88A850A938A8}.XPI
() (No name found) -- C:\USERS\VIRGILE VEGA\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\Y4UQRM15.DEFAULT\EXTENSIONS\[email protected]
O1 HOSTS File: ([2012/01/22 22:16:55 | 000,001,001 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.94.0.1 client.openvpn.net
O1 - Hosts: 127.94.0.2 openvpn-client.ch-zur-001.privatetunnel.com
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Extra program files x86\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - D:\Extra program files x86\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Extra program files x86\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - D:\Extra program files x86\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - D:\Extra program files x86\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (IeMonitorBho Class) - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - D:\Extra program files x86\Megaupload\Mega Manager\MegaIEMn.dll (Megaupload Limited)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - D:\Extra program files x86\Java\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (no name) - AutorunsDisabled - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar.dll ()
O4:64bit: - HKLM..\Run: [egui] D:\Extra program files x86\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [DeathAdder] D:\extra program files x86\Razer\DeathAdder\razerhid.exe ()
O4 - HKCU..\Run: [HKCU] C:\Windows\win32\Server.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\AutorunsDisabled: BootRacer = "C:\Program Files (x86)\BootRacer\Bootrace.exe" /2 (Greatis Software)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Download all links with IDM - D:\Extra program files x86\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download FLV video content with IDM - D:\Extra program files x86\Internet Download Manager\IEGetVL.htm ()
O8:64bit: - Extra context menu item: Download Link Using Mega Manager... - D:\Extra program files x86\Megaupload\Mega Manager\mm_file.htm ()
O8:64bit: - Extra context menu item: Download with IDM - D:\Extra program files x86\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: E&xport to Microsoft Excel - D:\Extra program files x86\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O8 - Extra context menu item: Download all links with IDM - D:\Extra program files x86\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download FLV video content with IDM - D:\Extra program files x86\Internet Download Manager\IEGetVL.htm ()
O8 - Extra context menu item: Download Link Using Mega Manager... - D:\Extra program files x86\Megaupload\Mega Manager\mm_file.htm ()
O8 - Extra context menu item: Download with IDM - D:\Extra program files x86\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: E&xport to Microsoft Excel - D:\Extra program files x86\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Extra program files x86\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - D:\Extra program files x86\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Windows\SysNative\PrxerNsp.dll ()
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Windows\SysNative\PrxerDrv.dll (Initex)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Windows\SysNative\PrxerDrv.dll (Initex)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Windows\SysNative\PrxerDrv.dll (Initex)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Windows\SysNative\PrxerDrv.dll (Initex)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000015 - C:\Windows\SysNative\PrxerDrv.dll (Initex)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Windows\SysWOW64\PrxerNsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\Windows\SysWOW64\PrxerDrv.dll (Initex)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_04)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2FAF6DB3-83FF-4096-A658-2ABADE14B791}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4B3905AC-F1CF-4BB5-B563-7191BA703F62}: DhcpNameServer = 202.65.247.32 202.65.244.31
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8716954F-FEF6-4598-B8E7-8C49EA50CEF8}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8A827C40-4BBF-4D2D-8745-9E945FCE953D}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8F3F8F07-AD08-4CA0-8B41-BE52A27C02C5}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{A3359B08-92F2-495B-83A8-065409DEE320}: DhcpNameServer = 192.168.11.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1D97B91-BC7F-4267-89CF-C1F2F4B6C836}: DhcpNameServer = 178.32.51.4 76.73.18.50
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FBA57DD7-11FA-4FBE-AE0E-38D93A4A273A}: DhcpNameServer = 192.168.11.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Windows\SysWOW64\skype4com.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - D:\Extra program files x86\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - AppInit_DLLs: (prio.dll) - D:\Extra program files x86\Prio\prio.dll (O&K Software)
O20 - AppInit_DLLs: (prio32.dll) -D:\Extra program files x86\Prio\prio32.dll (O&K Software)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) -C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - D:\Extra program files x86\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
O30:64bit: - LSA: Authentication Packages - (ows\w) - File not found
O30 - LSA: Authentication Packages - (ows\w) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 05:43:36 | 000,000,024 | ---- | M] () - E:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{07e0241e-3521-11e0-88af-96f27ead2401}\Shell - "" = AutoRun
O33 - MountPoints2\{07e0241e-3521-11e0-88af-96f27ead2401}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{3b6d8227-3b2a-11e0-8d22-9ef99ef2930f}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6d8227-3b2a-11e0-8d22-9ef99ef2930f}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{3b6d8233-3b2a-11e0-8d22-9ef99ef2930f}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6d8233-3b2a-11e0-8d22-9ef99ef2930f}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{3b6d824d-3b2a-11e0-8d22-9ef99ef2930f}\Shell - "" = AutoRun
O33 - MountPoints2\{3b6d824d-3b2a-11e0-8d22-9ef99ef2930f}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{8a32efdc-da2c-11e0-a565-d94d18212a1d}\Shell - "" = AutoRun
O33 - MountPoints2\{8a32efdc-da2c-11e0-a565-d94d18212a1d}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{8a32efea-da2c-11e0-a565-d94d18212a1d}\Shell - "" = AutoRun
O33 - MountPoints2\{8a32efea-da2c-11e0-a565-d94d18212a1d}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{8a32eff6-da2c-11e0-a565-d94d18212a1d}\Shell - "" = AutoRun
O33 - MountPoints2\{8a32eff6-da2c-11e0-a565-d94d18212a1d}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{b6cfc132-3a97-11e0-9ace-cfb145682303}\Shell - "" = AutoRun
O33 - MountPoints2\{b6cfc132-3a97-11e0-9ace-cfb145682303}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{b6cfc15a-3a97-11e0-9ace-cfb145682303}\Shell - "" = AutoRun
O33 - MountPoints2\{b6cfc15a-3a97-11e0-9ace-cfb145682303}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c575a3e4-3d08-11e0-bfed-f7402b499608}\Shell - "" = AutoRun
O33 - MountPoints2\{c575a3e4-3d08-11e0-bfed-f7402b499608}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c93004b1-18b8-11e0-b0f2-c83b10d36808}\Shell - "" = AutoRun
O33 - MountPoints2\{c93004b1-18b8-11e0-b0f2-c83b10d36808}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{c93004c8-18b8-11e0-b0f2-c83b10d36808}\Shell - "" = AutoRun
O33 - MountPoints2\{c93004c8-18b8-11e0-b0f2-c83b10d36808}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\{f029144b-755b-11e0-ae54-daf207748e64}\Shell - "" = AutoRun
O33 - MountPoints2\{f029144b-755b-11e0-ae54-daf207748e64}\Shell\AutoRun\command - "" = I:\AutoRun.exe
O33 - MountPoints2\I\Shell - "" = AutoRun
O33 - MountPoints2\I\Shell\AutoRun\command - "" = I:\AutoRun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/01/25 07:10:28 | 000,000,000 | RHSD | C] -- C:\Windows\win32
[2012/01/25 01:56:47 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Documents\Battlefield 3
[2012/01/25 01:37:48 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2012/01/24 18:34:59 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
[2012/01/24 14:37:28 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Roaming\SuperNZB
[2012/01/24 14:37:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SuperNZB
[2012/01/24 14:06:10 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\Newshosting
[2012/01/24 14:06:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Caphyon
[2012/01/24 14:06:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Newshosting
[2012/01/24 14:05:36 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Roaming\Newshosting
[2012/01/23 19:02:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/01/23 19:02:17 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2012/01/23 19:02:16 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2012/01/20 18:30:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\OpenVPN Technologies
[2012/01/18 20:07:53 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warriors of Elysia
[2012/01/18 18:11:41 | 000,000,000 | R--D | C] -- C:\Users\Virgile Vega\AppData\Roaming\Brother
[2012/01/15 19:05:10 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Documents\meditation
[2012/01/15 10:15:22 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Documents\princton resumes
[2012/01/15 08:53:54 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{518D2EF8-711C-40A0-B786-8FFF36FD7C87}
[2012/01/15 08:53:42 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{C5A249C4-79AD-4EA0-8B7A-60334AB2AA44}
[2012/01/15 07:40:43 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ATI Technologies
[2012/01/15 07:12:49 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/01/15 07:11:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/01/14 19:05:43 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Documents\m6mockpapers
[2012/01/12 16:45:07 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Desktop\radio stations and links
[2012/01/11 01:41:39 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{609BDCA6-9A70-40E4-8D56-42E8CF43441D}
[2012/01/11 01:41:29 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{44F008F7-DCD7-445F-8C45-1E3050C933D4}
[2012/01/09 21:20:21 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{D92FC8A2-3C42-4DD7-B854-831F0F447C6D}
[2012/01/09 21:20:10 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{26F26394-1CA6-482F-B8EA-DD313D147212}
[2012/01/08 14:57:16 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{61E7E2AC-F443-41F3-9494-4E25F0037C17}
[2012/01/08 14:57:06 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{2B498803-28A2-43AF-AD00-971E32DDAF14}
[2012/01/08 00:01:27 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{1E501461-2309-4FBC-A9DA-145384FFE2FB}
[2012/01/08 00:01:16 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{A390FB80-206F-4AF5-BCE8-A8B7A5ACD0D1}
[2012/01/07 16:25:28 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\Documents\Fat loss and strength training
[2012/01/05 14:25:53 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{443A589C-5235-49CA-99EB-49F59DC1A6D5}
[2012/01/05 14:25:43 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{D3A94471-EB95-4C23-B365-7358E9118359}
[2012/01/05 02:25:20 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{387DEF66-24E1-45F9-BF86-11797BFA9763}
[2012/01/05 02:25:11 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Local\{A326674B-368F-49EF-978A-799D78160EE3}
[2012/01/03 11:22:18 | 000,494,080 | ---- | C] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/01/03 11:21:42 | 000,235,520 | ---- | C] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/01/03 11:20:30 | 000,120,320 | ---- | C] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/01/03 11:19:52 | 000,021,504 | ---- | C] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/01/03 10:31:14 | 000,058,880 | ---- | C] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011/12/31 13:42:05 | 000,000,000 | ---D | C] -- C:\Users\Virgile Vega\AppData\Roaming\redsn0w
[2011/12/30 01:13:42 | 000,145,008 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
[2011/08/06 13:55:28 | 000,756,180 | ---- | C] (Tukero[X]Team) -- C:\Users\Virgile Vega\AppData\Roaming\TNod-1.4.0.15-setup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/01/25 16:02:40 | 013,802,875 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\1.gif
[2012/01/25 16:00:17 | 000,860,880 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\Eating_poop.gif
[2012/01/25 15:49:47 | 003,625,747 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\berneydidnotread.gif
[2012/01/25 15:25:39 | 015,340,667 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\478524.gif
[2012/01/25 15:16:55 | 000,000,538 | ---- | M] () -- C:\Users\Virgile Vega\openvpn-connect.json
[2012/01/25 07:41:27 | 000,001,063 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\bf3.exe - Shortcut.lnk
[2012/01/25 07:29:42 | 000,022,592 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/25 07:29:42 | 000,022,592 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/25 07:24:39 | 000,001,218 | ---- | M] () -- C:\Windows\SysWow64\bscs.ini
[2012/01/25 07:24:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/25 01:10:09 | 003,365,905 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\2nulq9g.jpg
[2012/01/25 00:44:16 | 005,893,565 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\michael-jordan-lol.gif
[2012/01/25 00:27:00 | 002,096,402 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\1314976029442.gif
[2012/01/24 23:30:23 | 000,426,478 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\beer_drob_gif.gif
[2012/01/24 22:19:48 | 000,591,052 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\tumblr_ly5t1kto2J1qgmb7wo1_400.gif
[2012/01/24 22:19:08 | 000,906,296 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\76Zr9.gif
[2012/01/24 22:18:50 | 000,507,355 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\Z0ZN2.gif
[2012/01/24 22:18:34 | 000,453,273 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\disgusting.gif
[2012/01/24 22:18:24 | 001,141,361 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\1287347561085.gif
[2012/01/24 14:37:05 | 000,000,660 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\SuperNZB.lnk
[2012/01/24 14:06:07 | 000,000,758 | ---- | M] () -- C:\Users\Public\Desktop\Newshosting.lnk
[2012/01/23 19:02:24 | 000,001,580 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/22 20:54:17 | 000,155,800 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\wedding.jpg
[2012/01/22 20:16:08 | 002,681,953 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\727498213029916073735090.gif
[2012/01/22 19:54:22 | 000,058,414 | ---- | M] () -- C:\Users\Virgile Vega\Desktop\1bU9F.jpg
[2012/01/20 18:30:52 | 000,001,366 | ---- | M] () -- C:\Users\Public\Desktop\OpenVPN Connect.lnk
[2012/01/20 17:27:27 | 000,263,340 | ---- | M] () -- C:\Users\Virgile Vega\Documents\phone number given by darunee's fren_slower.mp3
[2012/01/20 17:21:36 | 000,189,152 | ---- | M] () -- C:\Users\Virgile Vega\Documents\phone number given by darunee's fren.mp3
[2012/01/15 12:39:38 | 000,000,939 | ---- | M] () -- C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2012/01/14 06:51:12 | 000,000,823 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/08 07:36:28 | 001,001,503 | ---- | M] () -- C:\Users\Virgile Vega\Documents\Annc_OIS_20120103.pdf
[2012/01/08 07:36:20 | 000,127,145 | ---- | M] () -- C:\Users\Virgile Vega\Documents\eAnnc_LaunchAndAIP_20120103.pdf
[2012/01/03 11:27:42 | 000,219,912 | ---- | M] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/01/03 11:27:42 | 000,219,912 | ---- | M] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/01/03 11:22:18 | 000,494,080 | ---- | M] (AMD) -- C:\Windows\SysNative\atieclxx.exe
[2012/01/03 11:21:42 | 000,235,520 | ---- | M] (AMD) -- C:\Windows\SysNative\atiesrxx.exe
[2012/01/03 11:20:30 | 000,120,320 | ---- | M] (AMD) -- C:\Windows\SysNative\atitmm64.dll
[2012/01/03 11:19:52 | 000,021,504 | ---- | M] (AMD) -- C:\Windows\SysNative\atimuixx.dll
[2012/01/03 10:42:18 | 002,095,328 | ---- | M] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/01/03 10:42:18 | 000,204,960 | ---- | M] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/01/03 10:42:18 | 000,204,960 | ---- | M] () -- C:\Windows\SysNative\ativvsvl.dat
[2012/01/03 10:42:18 | 000,157,152 | ---- | M] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/03 10:42:18 | 000,157,152 | ---- | M] () -- C:\Windows\SysNative\ativvsva.dat
[2012/01/03 10:35:30 | 002,097,056 | ---- | M] () -- C:\Windows\SysWow64\atiumdva.cap
[2012/01/03 10:31:14 | 000,058,880 | ---- | M] (AMD) -- C:\Windows\SysNative\coinst.dll
[2011/12/31 15:27:31 | 000,040,023 | ---- | M] () -- C:\Users\Virgile Vega\AppData\Roaming\UserTile.png
[2011/12/28 19:14:49 | 000,343,059 | ---- | M] () -- C:\Users\Virgile Vega\Documents\Receipt for graduation fee.pdf
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/01/25 16:01:58 | 013,802,875 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\1.gif
[2012/01/25 16:00:17 | 000,860,880 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\Eating_poop.gif
[2012/01/25 15:49:46 | 003,625,747 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\berneydidnotread.gif
[2012/01/25 15:23:25 | 015,340,667 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\478524.gif
[2012/01/25 07:41:27 | 000,001,063 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\bf3.exe - Shortcut.lnk
[2012/01/25 01:10:09 | 003,365,905 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\2nulq9g.jpg
[2012/01/25 00:42:51 | 005,893,565 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\michael-jordan-lol.gif
[2012/01/25 00:26:59 | 002,096,402 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\1314976029442.gif
[2012/01/24 23:30:22 | 000,426,478 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\beer_drob_gif.gif
[2012/01/24 22:19:47 | 000,591,052 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\tumblr_ly5t1kto2J1qgmb7wo1_400.gif
[2012/01/24 22:19:08 | 000,906,296 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\76Zr9.gif
[2012/01/24 22:18:50 | 000,507,355 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\Z0ZN2.gif
[2012/01/24 22:18:34 | 000,453,273 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\disgusting.gif
[2012/01/24 22:18:20 | 001,141,361 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\1287347561085.gif
[2012/01/24 14:37:05 | 000,000,660 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\SuperNZB.lnk
[2012/01/24 14:06:07 | 000,000,758 | ---- | C] () -- C:\Users\Public\Desktop\Newshosting.lnk
[2012/01/23 19:02:24 | 000,001,580 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2012/01/22 20:54:17 | 000,155,800 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\wedding.jpg
[2012/01/22 20:16:08 | 002,681,953 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\727498213029916073735090.gif
[2012/01/22 19:54:22 | 000,058,414 | ---- | C] () -- C:\Users\Virgile Vega\Desktop\1bU9F.jpg
[2012/01/20 18:30:52 | 000,001,366 | ---- | C] () -- C:\Users\Public\Desktop\OpenVPN Connect.lnk
[2012/01/20 17:27:26 | 000,263,340 | ---- | C] () -- C:\Users\Virgile Vega\Documents\phone number given by darunee's fren_slower.mp3
[2012/01/20 17:21:35 | 000,189,152 | ---- | C] () -- C:\Users\Virgile Vega\Documents\phone number given by darunee's fren.mp3
[2012/01/14 16:39:32 | 000,001,378 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenVPN Connect.lnk
[2012/01/08 07:36:27 | 001,001,503 | ---- | C] () -- C:\Users\Virgile Vega\Documents\Annc_OIS_20120103.pdf
[2012/01/08 07:36:20 | 000,127,145 | ---- | C] () -- C:\Users\Virgile Vega\Documents\eAnnc_LaunchAndAIP_20120103.pdf
[2012/01/03 11:27:42 | 000,219,912 | ---- | C] () -- C:\Windows\SysWow64\atiapfxx.blb
[2012/01/03 11:27:42 | 000,219,912 | ---- | C] () -- C:\Windows\SysNative\atiapfxx.blb
[2012/01/03 10:42:18 | 002,095,328 | ---- | C] () -- C:\Windows\SysNative\atiumd6a.cap
[2012/01/03 10:42:18 | 000,204,960 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/01/03 10:42:18 | 000,204,960 | ---- | C] () -- C:\Windows\SysNative\ativvsvl.dat
[2012/01/03 10:42:18 | 000,157,152 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/03 10:42:18 | 000,157,152 | ---- | C] () -- C:\Windows\SysNative\ativvsva.dat
[2012/01/03 10:35:30 | 002,097,056 | ---- | C] () -- C:\Windows\SysWow64\atiumdva.cap
[2011/12/31 15:27:31 | 000,040,023 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Roaming\UserTile.png
[2011/12/28 19:14:47 | 000,343,059 | ---- | C] () -- C:\Users\Virgile Vega\Documents\Receipt for graduation fee.pdf
[2011/12/08 02:05:11 | 000,156,160 | ---- | C] () -- C:\Windows\SysWow64\WS_ContextMenu.dll
[2011/11/29 02:56:52 | 000,054,000 | ---- | C] () -- C:\Windows\SysWow64\PrxerNsp.dll
[2011/11/17 10:04:24 | 000,002,384 | ---- | C] () -- C:\Windows\SysWow64\SHORTCUT.INI
[2011/11/17 10:03:44 | 000,000,273 | ---- | C] () -- C:\Windows\SysWow64\REMOTEDEVICE.INI
[2011/11/17 10:03:23 | 000,006,497 | ---- | C] () -- C:\Windows\SysWow64\LOCALSERVICE.INI
[2011/11/17 10:02:53 | 000,000,106 | ---- | C] () -- C:\Windows\SysWow64\LOCALDEVICE.INI
[2011/11/17 10:00:19 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\BSPRINT.INI
[2011/11/09 22:39:44 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll
[2011/11/09 22:39:32 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll
[2011/11/09 17:55:30 | 000,001,218 | ---- | C] () -- C:\Windows\SysWow64\bscs.ini
[2011/11/07 15:34:16 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\BsMobileCSps.dll
[2011/09/13 07:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/28 19:51:57 | 000,000,419 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011/08/28 19:51:57 | 000,000,027 | ---- | C] () -- C:\Windows\BRPP2KA.INI
[2011/08/06 13:57:10 | 000,000,000 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Roaming\chrtmp
[2011/06/19 23:41:36 | 000,000,600 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Roaming\winscp.rnd
[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/03/18 12:38:19 | 002,336,384 | ---- | C] () -- C:\Windows\SysWow64\BootMan.exe
[2011/03/18 12:38:19 | 000,086,408 | ---- | C] () -- C:\Windows\SysWow64\setupempdrv03.exe
[2011/03/18 12:38:19 | 000,014,848 | ---- | C] () -- C:\Windows\SysWow64\EuEpmGdi.dll
[2011/03/18 12:38:19 | 000,008,456 | ---- | C] () -- C:\Windows\SysWow64\EuGdiDrv.sys
[2011/03/18 12:38:18 | 000,014,216 | ---- | C] () -- C:\Windows\SysWow64\epmntdrv.sys
[2011/03/09 07:54:05 | 000,000,036 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Local\housecall.guid.cache
[2010/12/27 18:45:41 | 000,169,392 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2010/12/17 15:22:40 | 000,000,201 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Roaming\prio.ini
[2010/12/14 21:21:06 | 000,000,079 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Local\CrystalDiskMark30.ini
[2010/12/14 21:01:53 | 000,000,000 | ---- | C] () -- C:\Windows\Bench32.INI
[2010/12/14 17:56:51 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/12/14 17:56:51 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/12/14 17:56:51 | 000,108,032 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/12/14 17:56:51 | 000,000,038 | ---- | C] () -- C:\Windows\avisplitter.ini
[2010/12/14 17:50:28 | 000,007,609 | ---- | C] () -- C:\Users\Virgile Vega\AppData\Local\resmon.resmoncfg
[2010/12/14 15:13:13 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
[2010/12/14 13:48:16 | 000,000,164 | ---- | C] () -- C:\Windows\install.dat
[2010/12/14 04:12:26 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2010/12/14 01:18:53 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2010/12/14 01:02:42 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2010/01/22 10:04:30 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\BsVistaCommon.dll
[2009/07/14 13:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 10:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/14 10:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/14 08:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/14 07:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/14 05:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/11 05:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2009/01/05 15:44:10 | 000,053,248 | ---- | C] () -- C:\Windows\bdoscandel.exe
[2009/01/05 15:44:10 | 000,000,453 | ---- | C] () -- C:\Windows\bdoscandellang.ini
========== LOP Check ==========
[2010/12/24 17:42:40 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Acronis
[2012/01/04 14:43:52 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Camfrog
[2011/11/10 19:48:22 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\DAEMON Tools Lite
[2010/12/15 00:02:21 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\DAEMON Tools Pro
[2011/06/19 21:24:18 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Day 1 Studios
[2011/06/05 23:11:24 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\DeadMage
[2012/01/25 18:40:15 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\DMCache
[2011/06/12 05:11:20 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Dropbox
[2010/12/23 20:59:25 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\ESET
[2011/05/02 03:05:20 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\FreeArc
[2011/07/06 12:06:35 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\go
[2011/01/03 22:01:39 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\HD Tune Pro
[2012/01/24 00:25:52 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\IDM
[2010/12/16 02:09:07 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\ImgBurn
[2011/05/27 09:52:03 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\IrfanView
[2011/06/19 23:52:14 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Megaupload
[2012/01/24 14:05:36 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Newshosting
[2011/11/29 02:57:34 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Proxifier
[2010/12/13 22:50:25 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Razer
[2011/12/31 13:49:00 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\redsn0w
[2011/07/19 04:16:00 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Replay Media Catcher 4
[2011/07/19 04:12:45 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Replay Media Catcher 4.bak
[2012/01/24 14:39:05 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\SuperNZB
[2010/12/14 21:54:45 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Thinstall
[2012/01/24 12:02:55 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\uTorrent
[2011/02/24 20:33:07 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\WindSolutions
[2011/07/14 22:31:10 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\WinPatrol
[2011/12/08 02:05:45 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\Wondershare Video Converter Ultimate
[2011/11/09 04:47:26 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\ZumoCast
[2012/01/13 11:13:28 | 000,000,000 | ---D | M] -- C:\Users\Virgile Vega\AppData\Roaming\ZumoDrive
[2012/01/04 07:00:49 | 000,032,612 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 99 bytes -> C:\Users\Virgile Vega\Documents\dead space2 +13 v1.0 by DEViATED:ntfslink.junction-tracking
@Alternate Data Stream - 64 bytes -> C:\Users\Virgile Vega\Documents\redsn0w_win_0.9.6b4:ntfslink.junction-tracking
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:4FC01C57
< End of report >