Whenever I try to press the "sign in" on youtube I get redirected to accounts.google.com
I sign in to google accounts, but I am still not signed in YouTube as the button remains there, and I can't post or do any action that requires signing in.
Thank you for any of your help.
OTL logfile created on: 9/9/2012 16:40:47 - Run 1
OTL by OldTimer - Version 3.2.61.2 Folder = C:\Documents and Settings\Master\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000408 | Country: Greece | Language: ELL | Date Format: d/M/yyyy
1023,46 Mb Total Physical Memory | 432,48 Mb Available Physical Memory | 42,26% Memory free
2,91 Gb Paging File | 2,41 Gb Available in Paging File | 83,05% Paging File free
Paging file location(s): C:\pagefile.sys 2048 2560 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149,04 Gb Total Space | 9,35 Gb Free Space | 6,27% Space Free | Partition Type: NTFS
Computer Name: LONDON | User Name: Master | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/09/09 16:39:12 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTL.exe
PRC - [2012/09/01 03:47:42 | 000,917,984 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2012/02/27 14:43:07 | 000,801,792 | ---- | M] (Yuna Software) -- C:\Program Files\Windows Live\Messenger Plus! Live\PlusService.exe
PRC - [2010/06/15 10:36:40 | 006,479,712 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\Ralink\Common\RaUI.exe
PRC - [2010/06/01 13:37:58 | 000,193,888 | ---- | M] (Ralink Technology, Corp.) -- C:\Program Files\Ralink\Common\RaRegistry.exe
PRC - [2010/04/29 00:28:18 | 003,727,411 | ---- | M] (FreeDownloadManager.ORG) -- C:\Program Files\Free Download Manager\fdm.exe
PRC - [2009/11/12 03:49:16 | 000,361,632 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2008/04/14 03:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe
PRC - [2008/04/14 03:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/06/21 06:42:44 | 000,577,536 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\soundman.exe
========== Modules (No Company Name) ==========
MOD - [2012/09/01 03:47:41 | 002,242,528 | ---- | M] () -- C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2012/08/29 22:05:50 | 009,813,704 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
MOD - [2010/11/08 18:15:40 | 000,296,448 | ---- | M] () -- C:\Program Files\Notepad++\NppShell_04.dll
MOD - [2010/06/14 14:38:44 | 000,984,416 | ---- | M] () -- C:\Program Files\Ralink\Common\RaWLAPI.dll
MOD - [2009/05/11 11:45:40 | 000,147,456 | ---- | M] () -- C:\WINDOWS\system32\DiagFunc.dll
MOD - [2008/04/14 03:11:59 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
MOD - [2007/12/06 05:50:44 | 000,401,408 | ---- | M] () -- C:\Program Files\Free Download Manager\FUM\fumcore.dll
MOD - [2007/09/20 19:34:58 | 000,129,024 | ---- | M] () -- C:\Program Files\WinRAR\RarExt.dll
MOD - [2007/05/25 13:42:10 | 000,113,664 | ---- | M] () -- C:\WINDOWS\system32\spool\prtprocs\w32x86\lxdfdrpp.dll
MOD - [2007/05/11 01:50:00 | 000,017,024 | ---- | M] () -- C:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll
========== Services (SafeList) ==========
SRV - [2012/07/13 13:28:36 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Disabled | Stopped] -- C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/01/04 14:32:36 | 000,718,888 | ---- | M] (Nokia) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2010/06/01 13:37:58 | 000,193,888 | ---- | M] (Ralink Technology, Corp.) [Auto | Running] -- C:\Program Files\Ralink\Common\RaRegistry.exe -- (RalinkRegistryWriter)
SRV - [2010/05/22 22:47:08 | 002,480,048 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv)
SRV - [2009/11/12 03:49:10 | 000,660,664 | ---- | M] (Acronis) [On_Demand | Stopped] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2009/09/23 14:38:18 | 000,935,208 | ---- | M] (Nero AG) [Disabled | Stopped] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)
SRV - [2008/10/28 17:42:30 | 000,156,968 | ---- | M] (Seagate Technology LLC) [On_Demand | Stopped] -- C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe -- (FreeAgentGoNext Service)
SRV - [2008/04/14 03:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (W3SVC)
SRV - [2008/04/14 03:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (SMTPSVC)
SRV - [2008/04/14 03:12:22 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINDOWS\system32\inetsrv\inetinfo.exe -- (IISADMIN)
SRV - [2008/04/14 03:12:02 | 000,105,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\p2pgasvc.dll -- (p2pgasvc)
SRV - [2007/12/30 01:10:04 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2007/11/06 09:37:56 | 000,734,472 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\PerfectDisk\PDEngine.exe -- (PDEngine)
SRV - [2007/11/06 09:37:48 | 000,414,984 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\PerfectDisk\PDAgent.exe -- (PDAgent)
SRV - [2007/05/29 06:06:44 | 000,598,960 | ---- | M] ( ) [On_Demand | Stopped] -- C:\WINDOWS\system32\lxdfcoms.exe -- (lxdf_device)
SRV - [2007/05/29 06:06:20 | 000,099,248 | ---- | M] () [On_Demand | Stopped] -- C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\\lxdfserv.exe -- (lxdfCATSCustConnectService)
SRV - [2005/08/03 00:18:49 | 000,086,016 | ---- | M] (CACE Technologies) [On_Demand | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (WDICA)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\RTL8187.sys -- (RTLWUSB)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\rt2500usb.sys -- (RT2500USB)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDRELI)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDFRAME)
DRV - File not found [Kernel | On_Demand | Stopped] -- -- (PDCOMP)
DRV - File not found [Kernel | System | Stopped] -- -- (PCIDump)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Games\Lineage II\system\npkcrypt.sys -- (npkcrypt)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\mcdbus.sys -- (mcdbus)
DRV - File not found [Kernel | System | Stopped] -- -- (lbrtfdc)
DRV - File not found [Kernel | System | Stopped] -- -- (i2omgmt)
DRV - File not found [Kernel | Auto | Stopped] -- system32\DRIVERS\EAPPkt.sys -- (EAPPkt)
DRV - File not found [Kernel | System | Stopped] -- -- (Changer)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\Master\LOCALS~1\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btwdndis.sys -- (BTWDNDIS)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\btport.sys -- (BTDriver)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (a1edbvjd)
DRV - [2012/07/03 13:46:44 | 000,022,344 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\mbam.sys -- (MBAMProtector)
DRV - [2011/11/01 11:07:26 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/11/01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/11/01 11:07:26 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/11/01 11:07:24 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/09/22 17:10:34 | 000,238,696 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\WINDOWS\system32\drivers\RsFx0105.sys -- (RsFx0105)
DRV - [2011/08/12 23:44:56 | 000,012,800 | ---- | M] (OEM) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\smccard.sys -- (R5BaseSmc)
DRV - [2010/05/27 14:52:12 | 000,829,792 | ---- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rt2870.sys -- (rt2870)
DRV - [2010/05/22 22:47:09 | 000,160,288 | ---- | M] (Acronis) [File_System | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\afcdp.sys -- (afcdp)
DRV - [2010/05/22 22:47:05 | 000,911,680 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\tdrpm258.sys -- (tdrpman258)
DRV - [2010/05/22 22:47:03 | 000,581,984 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\timntr.sys -- (timounter)
DRV - [2010/05/22 22:46:52 | 000,158,272 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\snapman.sys -- (snapman)
DRV - [2010/02/11 15:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\tcpip6.sys -- (Tcpip6)
DRV - [2009/12/08 21:24:26 | 000,048,128 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Microsoft Visual Studio 10.0\Team Tools\Performance Tools\VSPerfDrv100.sys -- (VSPerfDrv100)
DRV - [2009/04/21 15:31:10 | 000,019,072 | ---- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Scutum50.sys -- (Scutum50)
DRV - [2009/03/30 21:55:06 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2008/10/24 02:27:35 | 000,717,296 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2008/08/26 10:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2008/06/05 17:40:48 | 000,120,976 | ---- | M] (Check Point Software Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vna.sys -- (VNA)
DRV - [2008/05/08 17:02:52 | 000,203,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\rmcast.sys -- (RMCAST)
DRV - [2008/04/13 21:53:09 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 21:45:29 | 000,010,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum)
DRV - [2008/04/13 21:39:44 | 000,092,544 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mqac.sys -- (MQAC)
DRV - [2007/12/06 10:51:00 | 000,285,952 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2007/12/05 08:26:40 | 002,782,208 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2007/11/05 10:55:04 | 000,017,952 | ---- | M] () [Kernel | System | Running] -- C:\Program Files\Radeon Omega Drivers\v4.8.442\ATI Tray Tools\atitray.sys -- (atitray)
DRV - [2007/10/22 06:33:40 | 000,068,624 | ---- | M] (Raxco Software, Inc.) [File_System | Boot | Running] -- C:\WINDOWS\System32\drivers\DefragFs.sys -- (DefragFS)
DRV - [2007/08/29 04:04:04 | 000,116,264 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SI3112r.sys -- (SI3112r)
DRV - [2007/08/29 04:04:04 | 000,019,240 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\SiWinAcc.sys -- (SiFilter)
DRV - [2007/04/16 22:46:00 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2007/04/13 00:46:36 | 000,034,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nx6000.sys -- (MSHUSBVideo)
DRV - [2006/06/27 18:42:14 | 003,972,672 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\alcxwdm.sys -- (ALCXWDM)
DRV - [2005/08/27 00:39:08 | 000,352,768 | ---- | M] (Ralink Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt61.sys -- (RT61)
DRV - [2005/08/18 17:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nvatabus.sys -- (nvatabus)
DRV - [2005/08/03 09:00:00 | 000,232,192 | R--- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\rt73.sys -- (RT73)
DRV - [2005/08/03 00:10:13 | 000,032,512 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2005/04/06 04:22:30 | 000,012,928 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2005/04/06 04:22:28 | 000,033,536 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2004/07/14 13:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2004/05/25 16:58:04 | 000,396,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvapu.sys -- (nvnforce)
DRV - [2004/05/25 16:58:02 | 000,048,640 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvax.sys -- (nvax)
DRV - [2004/04/02 15:40:00 | 000,021,760 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\nv_agp.SYS -- (nv_agp)
DRV - [2003/12/01 11:54:20 | 000,043,136 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ser2pl.sys -- (Ser2pl)
DRV - [2003/05/21 18:58:18 | 000,253,672 | ---- | M] (Jungo) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\windrvr6.sys -- (WinDriver6)
DRV - [2002/07/17 08:53:02 | 000,016,877 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\ASPI32.SYS -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.c...ferrer:source?}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.msn.com/spbasic.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.gr/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://gr.msn.com/?m...el-gr&ocid=iehp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = el
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 74 55 7A 56 C7 43 CC 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {6D91295D-495F-4418-AB51-0FDD953572E8}
IE - HKCU\..\SearchScopes\{6D91295D-495F-4418-AB51-0FDD953572E8}: "URL" = http://www.google.co...rchTerms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "https://www.google.com/"
FF - prefs.js..extensions.enabledAddons: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.4.8.1
FF - prefs.js..extensions.enabledAddons: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:2.0.3
FF - prefs.js..extensions.enabledItems: {19503e42-ca3c-4c27-b1e2-9cdb2170ee34}:1.4.8.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.3.4
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.746
FF - prefs.js..extensions.enabledItems: {37E4D8EA-8BDA-4831-8EA1-89053939A250}:3.0.0.2
FF - prefs.js..extensions.enabledItems: [email protected]:1.7.110.333
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.3: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKCU\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Master\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Master\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Documents and Settings\Master\Local Settings\Application Data\Facebook\Messenger\2.1.4623.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2012/02/12 18:46:33 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_3.6 [2012/02/12 21:14:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/09/01 03:47:43 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/08/29 23:15:22 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_9.0 [2012/02/12 21:14:11 | 000,000,000 | ---D | M]
[2008/08/27 03:49:39 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Master\Application Data\Mozilla\Extensions
[2012/08/31 14:01:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Master\Application Data\Mozilla\Firefox\Profiles\6jfp75ip.default\extensions
[2012/08/11 04:51:17 | 000,000,000 | ---D | M] (FlashGot) -- C:\Documents and Settings\Master\Application Data\Mozilla\Firefox\Profiles\6jfp75ip.default\extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}
[2012/08/31 14:01:13 | 000,741,958 | ---- | M] () (No name found) -- C:\Documents and Settings\Master\Application Data\Mozilla\Firefox\Profiles\6jfp75ip.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/08/29 23:15:27 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2009/11/04 23:59:18 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2009/12/02 03:13:16 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2012/09/01 03:47:42 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2007/12/13 10:55:00 | 000,437,760 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npagent.dll
[2012/09/01 03:47:32 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/09/01 03:47:32 | 000,002,253 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage:
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_4_402_265.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Platform SE 6 U17 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.170.4 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Program Files\Mozilla Firefox\plugins\np32dsw.dll
CHR - plugin: Driver Agent Plug-in (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npagent.dll
CHR - plugin: Windows Genuine Advantage (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npLegitCheckPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.4.1 (Enabled) = C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Facebook\Messenger\2.1.4590.0\npFbDesktopPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Master\Local Settings\Application Data\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files\VideoLAN\VLC\npvlc.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
O1 HOSTS File: ([2012/09/07 22:23:03 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\ShellBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] Removed -- "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" File not found
O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [DumpTeam] Removed -- C:\Downloads\DumpTeam_Pack_v4.5a6.exe /S File not found
O4 - HKLM..\Run: [Eps_Reg.exe] C:\DOCUME~1\Master\LOCALS~1\Temp\Eps_Reg.exe /L /NSmartCard2000 File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [lxdfamon] Removed -- "C:\Program Files\Lexmark 6500 Series\lxdfamon.exe" File not found
O4 - HKLM..\Run: [lxdfmon.exe] Removed -- "C:\Program Files\Lexmark 6500 Series\lxdfmon.exe" File not found
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [MaxMenuMgr] Removed -- "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" File not found
O4 - HKLM..\Run: [Mozilla Firefox] C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [NSU_agent] C:\Program Files\Nokia\Nokia Software Updater\nsu3ui_agent.exe ()
O4 - HKLM..\Run: [PlusService] C:\Program Files\Windows Live\Messenger Plus! Live\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] Removed -- "C:\Program Files\Java\jre6\bin\jusched.exe" File not found
O4 - HKLM..\Run: [TrueImageMonitor.exe] Rem "C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" File not found
O4 - HKCU..\Run: [] File not found
O4 - HKCU..\Run: [Facebook Update] C:\Documents and Settings\Master\Local Settings\Application Data\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [VoipGain] "C:\Program Files\VoipGain.com\VoipGain\VoipGain.exe" -nosplash -minimized File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk = C:\Program Files\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_17.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Games\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Games\Titan Poker\casino.exe (Playtech)
O9 - Extra 'Tools' menuitem : Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Games\Titan Poker\casino.exe (Playtech)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000006 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O15 - HKCU\..Trusted Domains: crucial.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: localhost ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: pokerstars.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: pokerstars.tv ([www] * in Trusted sites)
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.micros...tes/ieawsdc.cab (Microsoft Office Template and Media Control)
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} https://support.micr...veX/MSDcode.cab (Microsoft Data Collection Control)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.micr...922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {402C09CD-68ED-48B0-B008-E7B01DDBD2D5} http://www.vbgold.co...DataPrinter.CAB (RawDataPrinter.Printer)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://gfx2.hotmail....es/MSNPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} http://catalog.updat...b?1226698912562 (MUCatalogWebControl Class)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zon...1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1262787565562 (WUWebControl Class)
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} http://www.systemreq.../sysreqlab2.cab (System Requirements Lab Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1259603704843 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} http://cid-d1b10a193...ad/MsnPUpld.cab (Windows Live Photo Upload Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} http://10.0.0.51:881.../DVM_IPCam2.ocx (DVM_IPCam2 Control)
O16 - DPF: {B4CB50E4-0309-4906-86EA-10B6641C8392} https://in.vivodi.gr...LL/extender.cab (SlimClient Class)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_17)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{8243E4D0-7302-4D4F-BA38-73778E5B6A5B}: NameServer = 10.0.0.140
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - (Ati2evxx.dll) - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Master\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Master\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O29 - HKLM SecurityProviders - (msnsspc.dll credssp.dll) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/12/29 08:51:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{2295548e-7889-11df-876b-54d938e35d1d}\Shell - "" = AutoRun
O33 - MountPoints2\{2295548e-7889-11df-876b-54d938e35d1d}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{2295548e-7889-11df-876b-54d938e35d1d}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a
O33 - MountPoints2\{2295548f-7889-11df-876b-54d938e35d1d}\Shell\AutoRun\command - "" = winlog.exe
O33 - MountPoints2\{37bd2178-d2b9-11e1-8b30-00c0ca3a1a83}\Shell - "" = AutoRun
O33 - MountPoints2\{37bd2178-d2b9-11e1-8b30-00c0ca3a1a83}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{37bd2178-d2b9-11e1-8b30-00c0ca3a1a83}\Shell\AutoRun\command - "" = F:\Startme.exe
O33 - MountPoints2\{578140ba-6255-11e1-8aab-00c0ca3a1a83}\Shell - "" = AutoRun
O33 - MountPoints2\{578140ba-6255-11e1-8aab-00c0ca3a1a83}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{578140ba-6255-11e1-8aab-00c0ca3a1a83}\Shell\AutoRun\command - "" = F:\silkcosmos.exe
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/09 16:39:11 | 000,599,552 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTL.exe
[2012/09/07 22:37:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Desktop\GooredFix Backups
[2012/09/07 21:49:11 | 000,000,000 | ---D | C] -- C:\_OTM
[2012/09/07 20:50:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Start Menu\Programs\Facebook
[2012/09/07 20:50:47 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/09/01 03:49:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Start Menu\Programs\Google Chrome
[2012/09/01 02:00:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Malwarebytes
[2012/08/31 12:55:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Desktop\demie
[2012/08/26 13:50:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Desktop\Summer 2012!!!
[2012/08/19 23:47:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\3CXMyPhone Client Addin
[2012/08/19 23:35:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\Install
[2012/08/19 22:47:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\3CXMyPhone Client Addin
[2012/08/19 22:47:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\My Documents\3CX MyPhone
[2012/08/19 22:44:30 | 011,075,584 | ---- | C] (3CX) -- C:\Documents and Settings\Master\Desktop\3CXMyPhoneDesktopComponents.exe
[2012/08/19 22:34:05 | 000,000,000 | -HSD | C] -- C:\WINDOWS\System32\AI_RecycleBin
[2012/08/19 22:19:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Local Settings\Application Data\3CX VoIP Phone
[2012/08/19 22:19:11 | 000,000,000 | ---D | C] -- C:\Program Files\3CXPhone
[2012/08/19 22:19:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\3CX Phone
[2012/08/15 14:42:42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Local Settings\Application Data\BrainCube
[2012/08/15 14:42:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Application Data\OnlineTichu
[2012/08/15 14:37:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Online Tichu
[2012/08/12 15:06:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Master\Desktop\Panoramic
[2007/12/30 19:59:07 | 000,047,360 | ---- | C] (VSO Software) -- C:\Documents and Settings\Master\Application Data\pcouffin.sys
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/09 16:39:12 | 000,599,552 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Master\Desktop\OTL.exe
[2012/09/09 15:57:00 | 000,083,968 | ---- | M] () -- C:\Documents and Settings\Master\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/09 15:51:00 | 000,000,982 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500UA.job
[2012/09/09 15:33:07 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2012/09/09 15:33:03 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/09/09 15:31:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/09/09 15:31:18 | 1073,250,304 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/07 22:23:03 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2012/09/07 20:51:25 | 000,001,002 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500UA.job
[2012/09/04 03:51:00 | 000,000,930 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500Core.job
[2012/09/02 04:01:10 | 000,028,473 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\gangam_sexy.jpg
[2012/09/02 03:57:45 | 002,356,314 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\gangam_yellow_man.bmp
[2012/09/02 03:54:22 | 001,542,838 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\hey_sexy_gangam.bmp
[2012/09/01 18:00:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Registration.job
[2012/09/01 03:49:53 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\Google Chrome.lnk
[2012/09/01 03:49:53 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\Master\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/28 13:43:17 | 000,001,786 | -H-- | M] () -- C:\Documents and Settings\Master\My Documents\Default.rdp
[2012/08/27 23:48:02 | 000,000,980 | ---- | M] () -- C:\WINDOWS\tasks\FacebookUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500Core.job
[2012/08/25 00:54:10 | 000,089,708 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\otinanai...jpg
[2012/08/25 00:33:08 | 001,478,586 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\bot_chat.jpg
[2012/08/24 04:57:27 | 000,000,418 | ---- | M] () -- C:\WINDOWS\tasks\ParetoLogic Update Version2.job
[2012/08/22 00:07:16 | 000,022,227 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\lolen1.JPG
[2012/08/21 23:49:15 | 000,040,238 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\lolen.jpg
[2012/08/21 06:25:46 | 000,098,059 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\beagle_ad.jpg
[2012/08/19 23:47:03 | 000,001,869 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\3CX MyPhone.lnk
[2012/08/19 23:44:41 | 000,757,828 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2012/08/19 23:44:41 | 000,184,928 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2012/08/19 03:15:49 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\Tichu.lnk
[2012/08/17 06:10:30 | 000,074,990 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\Burn Notice - 06x09 - Official Business.ASAP.English.HI.C.orig.srt
[2012/08/15 14:29:51 | 000,043,923 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\me_wout_u.jpg
[2012/08/11 19:59:36 | 000,166,914 | ---- | M] () -- C:\Documents and Settings\Master\Desktop\kempamp.jpg
[2 C:\Documents and Settings\All Users\*.tmp files -> C:\Documents and Settings\All Users\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/02 04:01:03 | 000,028,473 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\gangam_sexy.jpg
[2012/09/02 03:57:44 | 002,356,314 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\gangam_yellow_man.bmp
[2012/09/02 03:54:21 | 001,542,838 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\hey_sexy_gangam.bmp
[2012/09/01 19:45:17 | 000,739,209 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1801674531-1682526488-839522115-1043-0.dat
[2012/09/01 03:49:53 | 000,002,293 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\Google Chrome.lnk
[2012/09/01 03:49:53 | 000,002,271 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/01 03:46:54 | 000,000,982 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500UA.job
[2012/09/01 03:46:54 | 000,000,930 | ---- | C] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500Core.job
[2012/08/29 23:15:26 | 000,000,730 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk
[2012/08/25 00:54:10 | 000,089,708 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\otinanai...jpg
[2012/08/25 00:33:07 | 001,478,586 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\bot_chat.jpg
[2012/08/22 00:07:16 | 000,022,227 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\lolen1.JPG
[2012/08/21 23:20:42 | 000,040,238 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\lolen.jpg
[2012/08/21 06:25:04 | 000,098,059 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\beagle_ad.jpg
[2012/08/19 23:47:03 | 000,001,875 | ---- | C] () -- C:\Documents and Settings\Master\Start Menu\Programs\3CX MyPhone.lnk
[2012/08/19 23:47:03 | 000,001,869 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\3CX MyPhone.lnk
[2012/08/18 00:10:39 | 000,074,990 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\Burn Notice - 06x09 - Official Business.ASAP.English.HI.C.orig.srt
[2012/08/15 14:43:28 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\Tichu.lnk
[2012/08/15 14:29:49 | 000,043,923 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\me_wout_u.jpg
[2012/08/11 19:59:36 | 000,166,914 | ---- | C] () -- C:\Documents and Settings\Master\Desktop\kempamp.jpg
[2012/04/08 22:30:26 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\iacenc.dll
[2012/03/20 01:07:03 | 000,000,025 | ---- | C] () -- C:\WINDOWS\tlknw18.ini
[2012/03/11 18:39:35 | 000,202,415 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Application Data\debuggee.mdmp
[2012/02/10 06:13:31 | 000,043,602 | ---- | C] () -- C:\WINDOWS\System32\xvid-uninstall.exe
[2011/11/06 23:58:50 | 000,135,168 | ---- | C] () -- C:\WINDOWS\u39v22.exe
[2011/08/12 23:44:56 | 000,021,888 | ---- | C] () -- C:\WINDOWS\System32\drivers\eps2kt1.sys
[2011/08/12 23:44:56 | 000,004,608 | ---- | C] () -- C:\WINDOWS\System32\R5CoInst.dll
[2011/07/11 21:16:09 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.dll
[2011/07/11 21:16:09 | 000,001,191 | ---- | C] () -- C:\WINDOWS\System32\W32N55.INI
[2011/07/11 21:16:09 | 000,000,449 | ---- | C] () -- C:\WINDOWS\System32\DiagFunc.ini
[2011/07/11 21:15:45 | 000,014,051 | ---- | C] () -- C:\WINDOWS\System32\RaCoInst.dat
[2011/07/11 20:59:03 | 000,451,072 | ---- | C] () -- C:\WINDOWS\System32\ISSRemoveSP.exe
[2011/07/08 11:16:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\DiffMerge.INI
[2010/11/16 21:42:59 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Application Data\fusioncache.dat
[2010/08/19 00:10:16 | 002,448,840 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-1801674531-1682526488-839522115-500-0.dat
[2010/08/19 00:10:15 | 000,449,740 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
[2009/09/15 12:30:56 | 000,001,326 | ---- | C] () -- C:\Documents and Settings\All Users\lxdf
[2008/11/15 11:01:41 | 001,458,897 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\vso_ts_preview.xml
[2008/08/29 23:22:48 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\inst.exe
[2008/08/25 17:20:36 | 000,000,040 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\.zreglib
[2008/04/24 06:43:12 | 000,013,817 | ---- | C] () -- C:\Documents and Settings\Master\dec-user.ini
[2008/04/22 22:35:59 | 000,000,430 | RHS- | C] () -- C:\Documents and Settings\All Users\ntuser.pol
[2008/04/14 13:33:00 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Master\baseis1.sql
[2008/03/17 00:55:50 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Master\.gtk-bookmarks
[2008/01/08 03:06:36 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/12/30 19:59:07 | 000,087,608 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\ezpinst.exe
[2007/12/30 19:59:07 | 000,007,887 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\pcouffin.cat
[2007/12/30 19:59:07 | 000,001,144 | ---- | C] () -- C:\Documents and Settings\Master\Application Data\pcouffin.inf
[2007/12/29 21:05:10 | 000,083,968 | ---- | C] () -- C:\Documents and Settings\Master\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== LOP Check ==========
[2012/08/20 03:11:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\3CXMyPhone Client Addin
[2010/05/22 23:10:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
[2010/10/23 12:46:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software
[2011/02/05 18:42:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Cached Installations
[2008/09/06 14:58:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
[2012/02/12 19:21:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations
[2009/02/14 13:47:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe
[2012/06/20 00:45:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LxThumbs
[2012/02/26 18:18:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2012/02/12 21:12:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Nokia
[2012/02/12 21:00:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NokiaInstallerCache
[2011/02/05 18:43:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ParetoLogic
[2009/07/09 03:09:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite
[2010/08/05 23:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PreEmptive Solutions
[2011/07/11 21:15:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ralink Driver
[2009/03/18 20:50:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2008/10/22 00:56:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2012/06/20 00:48:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ThumbnailCache4R
[2009/04/14 02:45:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ViceVersa PRO 2
[2007/12/30 21:41:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vsosdk
[2012/07/21 01:36:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\YTD Video Downloader
[2012/08/19 23:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\3CXMyPhone Client Addin
[2009/02/12 23:03:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Acreon
[2010/05/22 23:11:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Acronis
[2010/09/23 21:31:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2009/11/05 00:00:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\CrypTool
[2007/12/29 21:49:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\DAEMON Tools
[2012/01/21 23:13:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\DeviceDoctorSoftware
[2012/03/18 07:24:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\e-academy Inc
[2012/09/09 16:45:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Free Download Manager
[2012/01/03 00:28:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\HandBrake
[2008/06/25 21:23:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Iminent
[2012/08/19 23:35:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Install
[2011/12/07 08:45:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\iSpy
[2009/09/15 12:26:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Lexmark Productivity Studio
[2008/04/18 00:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\MySQL
[2008/07/16 14:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\NetMedia Providers
[2012/02/12 21:15:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Nokia
[2012/02/02 23:49:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Notepad++
[2009/07/09 03:29:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Nseries
[2012/08/15 14:42:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\OnlineTichu
[2012/06/23 02:13:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\PacificPoker
[2009/08/23 23:32:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\PC Suite
[2008/07/16 14:07:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Publish Providers
[2012/03/13 00:27:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\QuickSFV
[2008/01/06 19:20:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\SmartDraw
[2008/07/16 14:06:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Sony
[2012/04/13 02:00:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\TeamViewer
[2009/03/28 21:25:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Thinstall
[2012/09/02 04:32:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\uTorrent
[2009/11/08 15:00:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Vso
[2012/04/08 22:37:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Windows Desktop Search
[2012/04/09 11:56:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\Windows Search
[2012/07/23 14:33:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\wtxpcom
[2011/09/29 21:07:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\www.shadowexplorer.com
[2010/06/13 17:06:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\YoudaGames
[2012/07/23 14:33:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Master\Application Data\YouTube Downloader
[2008/01/14 12:19:12 | 000,000,322 | ---- | M] () -- C:\WINDOWS\Tasks\Alicia Keys - No One.job
[2012/08/27 23:48:02 | 000,000,980 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500Core.job
[2012/09/07 20:51:25 | 000,001,002 | ---- | M] () -- C:\WINDOWS\Tasks\FacebookUpdateTaskUserS-1-5-21-1801674531-1682526488-839522115-500UA.job
[2009/07/31 18:34:09 | 000,000,430 | -H-- | M] () -- C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
[2012/09/09 15:33:07 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
[2012/09/01 18:00:00 | 000,000,444 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Registration.job
[2012/08/24 04:57:27 | 000,000,418 | ---- | M] () -- C:\WINDOWS\Tasks\ParetoLogic Update Version2.job
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 24 bytes -> C:\WINDOWS:2EFE7126C654D42F
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >