OTL Results
OTL logfile created on: 17/09/2012 8:39:25 - Run 1
OTL by OldTimer - Version 3.2.61.5 Folder = D:\Downloads\Mirror\Programs
64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000421 | Country: Indonesia | Language: IND | Date Format: dd/MM/yyyy
1,93 Gb Total Physical Memory | 0,77 Gb Available Physical Memory | 39,76% Memory free
3,85 Gb Paging File | 1,24 Gb Available in Paging File | 32,16% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 70,10 Gb Total Space | 23,88 Gb Free Space | 34,06% Space Free | Partition Type: NTFS
Drive D: | 218,12 Gb Total Space | 73,57 Gb Free Space | 33,73% Space Free | Partition Type: NTFS
Drive E: | 3,25 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Drive F: | 33,16 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: NAVIGATOR | User Name: Markun | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - D:\Downloads\Mirror\Programs\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 5\Suo10_SmartRAM.exe (IObit)
PRC - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Smartfren Connex EC1261-2 UI.exe ()
PRC - C:\ProgramData\Smartfren Connex EC1261-2 UI\OnlineUpdate\ouc.exe ()
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe (Crystal Rich Ltd)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
PRC - C:\Program Files (x86)\Smadav\SMΔRTP.exe (Smadsoft)
PRC - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
PRC - C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
PRC - C:\ProgramData\DataCardService\DCSHelper.exe (Huawei Technologies Co., Ltd.)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Tonec Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\ProcessTamer\ProcessTamerTray.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\libglesv2.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\libegl.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\avutil-51.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\avformat-54.dll ()
MOD - C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\avcodec-54.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\0c00b1a8336dd4c1bd1ebce7780f20b4\System.Runtime.Remoting.ni.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Smartfren Connex EC1261-2 UI.exe ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\SMSUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\StatusBarMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\SmsSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\ToolBarMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\XFramePlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\XCodec.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\STKSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\USSDSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Trace.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Win7Support.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\SmsAppPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\QtGui4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\QtXml4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\plugins\imageformats\qtiff4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\sdk.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\QtCore4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\plugins\imageformats\qmng4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NDISAPI.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\AddrBookPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\AddrBookUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\CallUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\CallAppPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\CallLogSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\PluginContainer.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DeviceMgrUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NetInfoUIExPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DialupUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\core.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\CallLogUIPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Proxy.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DeviceAppPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NetConnectPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DeviceSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\MenuMgrPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NetInfoSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\LiveUpdateInterface.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\AddrBookSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\AtCodec.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NetSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\Common.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DialUpPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NDISPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\CallSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NetConnectSrvPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\DataServicePlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\OSDialup.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\OSNDIS.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\ATR2SMgr.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\LayoutPlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\OSAdapt.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\NotifyServicePlugin.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\OSPowerMgr.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\OSCall.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\libgcc_s_dw2-1.dll ()
MOD - C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\mingwm10.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\009c50fb69919b90fb233cb4c35d0ad7\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\b68fdf2c95b93fc5006a092c11eed07c\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cb079eab134fd1a752ad91db13274110\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorUtil\53617f47bfecf408ce5234479afbd2e5\IAStorUtil.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\c4d40afe53c11104c3374aa07c59498f\IAStorCommon.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ebefde27b0ef7f39bb49c493b34a602c\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\5c85c9c42e1b8a8760de82ecb4c7d582\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\System\2ebb3c259eab50af565e3a8dba6ad20e\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\5858678a79aae31262b0214424245d06\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\Smadav\SM?RTP.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 5\madexcept_.bpl ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 5\madbasic_.bpl ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 5\maddisAsm_.bpl ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\ProcessTamer\ProcessTamerTray.exe ()
========== Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (avast! Firewall) -- C:\Program Files\AVAST Software\Avast\afwServ.exe (AVAST Software)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Flexera Software, Inc.)
SRV:64bit: - (MsMpSvc) -- C:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (PSI_SVC_2_x64) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe (arvato digital services llc)
SRV:64bit: - (btwdins) -- C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Broadcom Corporation.)
SRV:64bit: - (wlcrasvc) -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (wltrysvc) -- C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Dell Inc.)
SRV:64bit: - (TurboBoost) -- C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) -- C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AppMgmt) -- C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)
SRV:64bit: - (AERTFilters) -- C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (Smartfren Connex EC1261-2 UI. RunOuc) -- C:\Program Files (x86)\Smartfren Connex EC1261-2 UI\UpdateDog\ouc.exe ()
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (USBSafelyRemoveService) -- C:\Program Files (x86)\USB Safely Remove\USBSRService.exe (Crystal Rich Ltd)
SRV - (AdvancedSystemCareService5) -- C:\Program Files (x86)\IObit\Advanced SystemCare 5\ASCService.exe (IObit)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (IMFservice) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (PanService) -- C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe (Pandora.TV)
SRV - (SeagateDashboardService) -- C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe (Memeo)
SRV - (MemeoBackgroundService) -- C:\Program Files (x86)\Memeo\AutoBackup\MemeoBackgroundService.exe (Memeo)
SRV - (HWDeviceService64.exe) -- C:\ProgramData\DataCardService\HWDeviceService64.exe ()
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (SwitchBoard) -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (UNS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (IDMWFP) -- C:\Windows\SysNative\drivers\idmwfp.sys (Tonec Inc.)
DRV:64bit: - (aswSnx) -- C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) -- C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswTdi) -- C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswNdis2) -- C:\Windows\SysNative\drivers\aswNdis2.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) -- C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswRdr) -- C:\Windows\SysNative\drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswFW) -- C:\Windows\SysNative\drivers\aswFW.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) -- C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (aswKbd) -- C:\Windows\SysNative\drivers\aswKbd.sys (AVAST Software)
DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020200}_0) -- c:\Program Files\Dell Support Center\pcdsrvc_x64.pkms (PC-Doctor, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (dtsoftbus01) -- C:\Windows\SysNative\drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (ewusbmbb) -- C:\Windows\SysNative\drivers\ewusbwwan.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (ew_hwusbdev) -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (huawei_enumerator) -- C:\Windows\SysNative\drivers\ew_jubusenum.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (hwdatacard) -- C:\Windows\SysNative\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
DRV:64bit: - (aswNdis) -- C:\Windows\SysNative\drivers\aswNdis.sys (ALWIL Software)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (AmgHips) -- C:\Windows\SysNative\drivers\AmgHips.sys ()
DRV:64bit: - (fssfltr) -- C:\Windows\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Trufos) -- C:\Windows\SysNative\drivers\trufos.sys (BitDefender S.R.L.)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Rovi Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RDPDISPM) -- C:\Windows\SysNative\drivers\rdpdispm.sys (Microsoft Corporation)
DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
DRV:64bit: - (BCM42RLY) -- C:\Windows\SysNative\drivers\bcm42rly.sys (Broadcom Corporation)
DRV:64bit: - (BcmVWL) -- C:\Windows\SysNative\drivers\bcmvwl64.sys (Broadcom Corporation)
DRV:64bit: - (BCM43XX) -- C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TurboB) -- C:\Windows\SysNative\drivers\TurboB.sys ()
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) -- C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (CtClsFlt) -- C:\Windows\SysNative\drivers\CtClsFlt.sys (Creative Technology Ltd.)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RimUsb) -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (BTWAMPFL) -- C:\Windows\SysNative\drivers\btwampfl.sys (Broadcom Corporation.)
DRV:64bit: - (btwavdt) -- C:\Windows\SysNative\drivers\btwavdt.sys (Broadcom Corporation.)
DRV:64bit: - (btwaudio) -- C:\Windows\SysNative\drivers\btwaudio.sys (Broadcom Corporation.)
DRV:64bit: - (btwl2cap) -- C:\Windows\SysNative\drivers\btwl2cap.sys (Broadcom Corporation.)
DRV:64bit: - (btwrchid) -- C:\Windows\SysNative\drivers\btwrchid.sys (Broadcom Corporation.)
DRV - (hwinterface) -- C:\Windows\SysWOW64\drivers\hwinterface.sys (Logix4u)
DRV - (UrlFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)
DRV - (RegFilter) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)
DRV - (FileMonitor) -- C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (WinRing0_1_2_0) -- D:\Setelan\RealTemp\WinRing0x64.sys (OpenLibSys.org)
DRV - (hwdatacard) -- C:\Windows\SysWOW64\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - No CLSID value found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = id-ID
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = D5 A3 D3 61 FB 45 CD 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {7F4EFF06-7032-458e-AE16-1C1D8255C28A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = http://blekko.com/ws...q={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{7F4EFF06-7032-458e-AE16-1C1D8255C28A}: "URL" = http://home.speedbit...q={searchTerms}
IE - HKCU\..\SearchScopes\{A94BE7DF-9350-4F27-A9CF-B5A1B11828A2}: "URL" = http://www.google.co...ie=utf8&oe=utf8
IE - HKCU\..\SearchScopes\{E8E2A51B-1A15-4ED4-9B47-E0AE4928F453}: "URL" = http://websearch.ask...2E-E93A0F6E8BD2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 10.17.27.250:8080
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Google"
FF - prefs.js..browser.search.defaultenginename: "SpeedBit Search"
FF - prefs.js..browser.search.defaulturl: "http://home.speedbit...spx?aff=115&q="
FF - prefs.js..browser.search.order.1: "SpeedBit Search"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "about:home"
FF - prefs.js..extensions.enabledAddons: [email protected]:2.0.0.100
FF - prefs.js..extensions.enabledAddons: {c2921baa-9930-4d73-a203-f69db688f139}:1.0
FF - prefs.js..extensions.enabledAddons: [email protected]:7.0.1466
FF - prefs.js..extensions.enabledAddons: {bb6bc1bb-f824-4702-90cd-35e2fb24f25d}:1.5.1.1
FF - prefs.js..extensions.enabledAddons: [email protected]:7.3.28
FF - prefs.js..extensions.enabledAddons: [email protected]:5.0.2
FF - prefs.js..extensions.enabledAddons: {e4a8a97b-f2ed-450b-b12d-ee082ba24781}:1.1
FF - prefs.js..extensions.enabledAddons: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:2.0.15
FF - prefs.js..keyword.URL: "http://home.speedbit...spx?aff=115&q="
FF - prefs.js..network.proxy.gopher: ""
FF - prefs.js..network.proxy.gopher_port: 0
FF - prefs.js..network.proxy.share_proxy_settings: true
FF - prefs.js..network.proxy.type: 0
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_265.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@photodex.com/PhotodexPresenter: C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll ( )
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Markun\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Markun\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@us-w1.rockmelt.com/RockMelt Update;version=8: C:\Users\Markun\AppData\Local\RockMelt\Update\1.2.189.1\npRockMeltOneClick8.dll (RockMelt Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Markun\AppData\Local\Facebook\Messenger\2.1.4570.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2012/08/25 23:53:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/15 01:55:51 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/09/15 01:55:27 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Pale Moon 15.0\extensions\\Components: C:\Program Files (x86)\Pale Moon\components [2012/08/28 07:36:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\Markun\AppData\Roaming\IDM\idmmzcc5 [2012/09/08 20:27:59 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\Markun\AppData\Roaming\IDM\idmmzcc5 [2012/09/08 20:27:59 | 000,000,000 | ---D | M]
[2012/04/07 11:53:23 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Extensions
[2012/09/15 01:56:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions
[2012/09/01 17:46:51 | 000,000,000 | ---D | M] (Cookies Manager+) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\{bb6bc1bb-f824-4702-90cd-35e2fb24f25d}
[2012/09/06 17:10:18 | 000,000,000 | ---D | M] (IDM CC) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\[email protected]
[2012/09/15 01:56:31 | 000,371,729 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\[email protected]
[2012/07/28 14:17:36 | 000,456,182 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\[email protected]
[2012/05/04 17:27:09 | 000,003,047 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\[email protected]
[2012/05/04 17:27:28 | 000,003,714 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\{c2921baa-9930-4d73-a203-f69db688f139}.xpi
[2012/07/25 17:03:56 | 000,741,958 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/09/15 01:56:31 | 000,698,867 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi
[2012/09/15 01:56:31 | 000,270,876 | ---- | M] () (No name found) -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi
[2012/06/06 21:31:06 | 000,002,333 | ---- | M] () -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\searchplugins\askcom.xml
[2012/08/26 09:37:01 | 000,002,534 | ---- | M] () -- C:\Users\Markun\AppData\Roaming\Mozilla\Firefox\Profiles\wu62w605.default\searchplugins\speedbit.xml
[2012/09/15 01:55:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/08/25 23:53:38 | 000,000,000 | ---D | M] (avast! WebRep) -- C:\PROGRAM FILES\AVAST SOFTWARE\AVAST\WEBREP\FF
[2012/09/15 01:55:51 | 000,266,720 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/08/29 19:24:38 | 000,002,465 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/07/29 22:49:46 | 000,002,167 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\search.xml
[2012/08/29 19:24:38 | 000,002,253 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://home.speedbit.com/?aff=115
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://home.speedbit.com/?aff=115
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Markun\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\PepperFlash\11.2.31.144\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_235.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.0.61118.0\npctrl.dll
CHR - plugin: Photodex Presenter Plugin (Enabled) = C:\Program Files (x86)\Photodex Presenter\npPxPlay.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\Markun\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Markun\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - Extension: Turn Off the Lights = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfbmjmiodbnnpllbbbfblcplfjjepjdn\2.1.0.6_0\
CHR - Extension: YouTube = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Google Search = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Google+ = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlppkpafhbajpcmmoheippocdidnckmm\1.0.1.424_0\
CHR - Extension: TweetDeck = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\hbdpomandigafcibbmofojjchbcdagbl\1.6.0_0\
CHR - Extension: goo.gl URL Shortener = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\iblijlcdoidgdpfknkckljiocdbnlagk\0.7.2_0\
CHR - Extension: avast! WebRep = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\7.0.1466_0\
CHR - Extension: Dragonfly7 = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifcaofnekaooediccpfakjlbikfdghn\1.1_0\
CHR - Extension: IDM Integration = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmolcgpienlcieaajfkkdamlngancncm\6.12.17_0\
CHR - Extension: Download Assistant = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfjkgbjaikamkkojmakjclmkianficch\5.0.2_0\
CHR - Extension: Awesome New Tab Page = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg\2012.135.7.2_0\
CHR - Extension: FastestChrome - Browse Faster = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\6.7.5_0\
CHR - Extension: Gmail = C:\Users\Markun\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/09/04 14:43:19 | 000,001,451 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 tonec.com
O1 - Hosts: 127.0.0.1 www.tonec.com
O1 - Hosts: 127.0.0.1 registeridm.com
O1 - Hosts: 127.0.0.1 secure.registeridm.com
O1 - Hosts: 127.0.0.1 internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 www.internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 secure.internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 mirror.internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 mirror2.internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 mirror3.internetdownloadmanager.com
O1 - Hosts: 127.0.0.1 star.tonec.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 lmlicenses.wip4.adobe.com
O1 - Hosts: 127.0.0.1 lm.licenses.adobe.com
O2:64bit: - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (Internet Download Manager, Tonec Inc.)
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2 - BHO: (IDM integration (IDMIEHlprObj Class)) - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (Internet Download Manager, Tonec Inc.)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [Broadcom Wireless Manager UI] c:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Dell Inc.)
O4:64bit: - HKLM..\Run: [QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [USB Safely Remove] C:\Program Files (x86)\USB Safely Remove\USBSafelyRemove.exe (Crystal Rich Ltd)
O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [Dell Webcam Central] c:\program files (x86)\dell webcam\dell webcam central\webcamdell2.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [IAStorIcon] c:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [ProcessTamer] C:\Program Files (x86)\ProcessTamer\ProcessTamerTray.exe ()
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [RockMelt Update] C:\Users\Markun\AppData\Local\RockMelt\Update\RockMeltUpdate.exe (RockMelt Inc.)
O4 - HKCU..\Run: [SmartRAM] C:\Program Files (x86)\IObit\Advanced SystemCare 5\suo10_smartram.exe (IObit)
O4 - HKCU..\Run: [SMΔRT-Protection] C:\Program Files (x86)\Smadav\SMΔRTP.exe (Smadsoft)
O4 - HKLM..\RunOnceEx: [Flags] Reg Error: Invalid data type. File not found
O4 - HKLM..\RunOnceEx: [Title] UnHackMe Rootkit Check File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:64bit: - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8:64bit: - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000008 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.5.0)
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_05)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_05)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{16513986-1023-4450-8846-D5137AF4A524}: NameServer = 10.17.3.252 10.17.3.246
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{536E1A20-F881-414A-B4E2-D230CDF7884F}: NameServer = 208.67.222.123,208.67.220.123
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E9CC98BC-3C3C-49AB-8818-8AD0BCED646E}: NameServer = 8.8.8.8,8.8.4.4
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/07/14 16:29:38 | 000,000,122 | R--- | M] () - E:\autorun.inf -- [ UDF ]
O32 - AutoRun File - [2011/03/17 10:57:22 | 000,148,320 | R--- | M] () - F:\AutoRun.exe -- [ CDFS ]
O32 - AutoRun File - [2011/03/18 16:48:14 | 000,000,045 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{808ef6ec-8952-11e1-99c7-b8ac6f61c9ee}\Shell - "" = AutoRun
O33 - MountPoints2\{a0aecf9a-9f4b-11e1-b483-b8ac6f61c9ee}\Shell - "" = AutoRun
O33 - MountPoints2\{a0aecf9a-9f4b-11e1-b483-b8ac6f61c9ee}\Shell\AutoRun\command - "" = F:\Setup.exe /Auto
O33 - MountPoints2\{b922ada0-d17d-11e1-b195-001e101fe70e}\Shell - "" = AutoRun
O33 - MountPoints2\{b922ada0-d17d-11e1-b195-001e101fe70e}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2011/03/17 10:57:22 | 000,148,320 | R--- | M] ()
O33 - MountPoints2\{bcc27501-fe60-11e1-9d9f-b8ac6f61c9ee}\Shell - "" = AutoRun
O33 - MountPoints2\{bcc27501-fe60-11e1-9d9f-b8ac6f61c9ee}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{f9f7b5cd-d005-11e1-a6ff-b8ac6f61c9ee}\Shell - "" = AutoRun
O33 - MountPoints2\{f9f7b5cd-d005-11e1-a6ff-b8ac6f61c9ee}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2011/03/17 10:57:22 | 000,148,320 | R--- | M] ()
O33 - MountPoints2\{f9f7b5d3-d005-11e1-a6ff-b8ac6f61c9ee}\Shell - "" = AutoRun
O33 - MountPoints2\{f9f7b5d3-d005-11e1-a6ff-b8ac6f61c9ee}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2011/03/17 10:57:22 | 000,148,320 | R--- | M] ()
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/09/16 21:01:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QPST
[2012/09/15 23:30:17 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bluetooth Devices
[2012/09/15 19:57:21 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Indowebster Desktop Uploader
[2012/09/15 01:55:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/09/14 23:42:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\NirSoft
[2012/09/14 22:08:31 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\dll-files.com
[2012/09/14 22:08:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files.com Fixer
[2012/09/14 22:08:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dll-Files.com Fixer
[2012/09/13 23:11:22 | 000,159,456 | ---- | C] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
[2012/09/11 22:57:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeyFinder
[2012/09/11 22:57:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Magical Jelly Bean
[2012/09/11 17:10:39 | 000,142,128 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFW.sys
[2012/09/11 17:09:49 | 000,266,776 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/09/11 17:09:48 | 000,019,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
[2012/09/11 17:09:41 | 000,012,368 | ---- | C] (ALWIL Software) -- C:\Windows\SysNative\drivers\aswNdis.sys
[2012/09/11 15:38:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\avast! Internet Security
[2012/09/10 11:45:41 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\DonationCoder
[2012/09/10 11:45:38 | 000,000,000 | ---D | C] -- C:\Users\Markun\Documents\DonationCoder
[2012/09/10 11:45:23 | 000,000,000 | ---D | C] -- C:\ProgramData\DonationCoder
[2012/09/10 11:45:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProcessTamer
[2012/09/10 11:45:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ProcessTamer
[2012/09/09 12:21:31 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Local\Norman Malware Cleaner
[2012/09/09 11:11:08 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
[2012/09/09 11:10:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSI Afterburner
[2012/09/07 22:51:33 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Local\LooksBuilder
[2012/09/07 22:51:13 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Red Giant Link
[2012/09/07 22:50:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant
[2012/09/07 22:50:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Magic Bullet Looks
[2012/09/07 22:50:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LooksBuilder
[2012/09/07 22:49:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Red Giant Link
[2012/09/07 22:44:58 | 000,000,000 | ---D | C] -- C:\ProgramData\RedGiant
[2012/09/04 00:16:42 | 000,000,000 | ---D | C] -- C:\ProgramData\VideoCopilot
[2012/09/03 16:57:22 | 000,000,000 | ---D | C] -- C:\ProgramData\ALM
[2012/09/03 16:49:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
[2012/09/03 15:11:30 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2012/09/02 19:22:32 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Unity
[2012/09/02 19:14:18 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Local\Unity
[2012/09/02 18:21:10 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RockMelt
[2012/09/02 18:11:49 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Local\RockMelt
[2012/09/01 11:07:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
[2012/09/01 11:06:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2012/08/31 11:17:12 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Support Center
[2012/08/31 09:17:23 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\IDM
[2012/08/31 09:17:17 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2012/08/31 09:17:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
[2012/08/31 09:17:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Internet Download Manager
[2012/08/31 00:34:14 | 000,000,000 | ---D | C] -- C:\ProgramData\PC-Doctor for Windows
[2012/08/28 18:59:18 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Hear
[2012/08/28 18:59:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hear
[2012/08/28 18:59:10 | 000,000,000 | ---D | C] -- C:\Program Files\Hear
[2012/08/28 12:30:03 | 000,000,000 | --SD | C] -- C:\Users\Markun\Documents\My Shapes
[2012/08/28 00:21:00 | 000,029,424 | ---- | C] (DeskSoft) -- C:\Windows\SysNative\drivers\dsnpfd.sys
[2012/08/27 14:48:07 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIMP3
[2012/08/26 16:56:03 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Topaz Software Manager
[2012/08/26 16:56:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Topaz Software Manager
[2012/08/25 23:32:43 | 000,359,464 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012/08/25 23:32:43 | 000,025,232 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/08/25 23:32:42 | 000,059,728 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012/08/25 23:32:42 | 000,054,072 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/08/25 23:32:40 | 000,969,200 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012/08/25 23:32:38 | 000,071,600 | ---- | C] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/08/25 23:31:53 | 000,227,648 | ---- | C] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012/08/25 23:31:53 | 000,041,224 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/08/25 18:47:53 | 000,000,000 | ---D | C] -- C:\Windows\AutoKMS
[2012/08/25 18:34:45 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012/08/25 18:34:35 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedBit
[2012/08/25 18:34:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SpeedBit
[2012/08/25 17:54:46 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
[2012/08/25 17:54:42 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/08/25 17:52:19 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Synchronization Services
[2012/08/25 17:52:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/08/25 17:51:37 | 000,000,000 | ---D | C] -- C:\Windows\PCHEALTH
[2012/08/25 17:51:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Sync Framework
[2012/08/25 17:48:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/08/25 17:47:58 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/08/25 17:46:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Analysis Services
[2012/08/25 17:46:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Office
[2012/08/25 17:44:51 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/08/24 09:03:56 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\USBSafelyRemove
[2012/08/24 09:03:16 | 000,000,000 | ---D | C] -- C:\ProgramData\USBSRService
[2012/08/24 09:03:15 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Safely Remove
[2012/08/24 09:03:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\USB Safely Remove
[2012/08/23 15:10:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IDWS Desktop Uploader Beta
[2012/08/23 15:10:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IDWS Desktop Uploader Beta
[2012/08/22 10:35:00 | 000,000,000 | ---D | C] -- C:\Windows\SysWow64\Wat
[2012/08/22 10:35:00 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Wat
[2012/08/21 22:03:54 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Local\AlbumArtDownloader
[2012/08/21 22:03:15 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Album Art Downloader
[2012/08/21 22:03:14 | 000,000,000 | ---D | C] -- C:\Program Files\AlbumArtDownloader
[2012/08/21 14:52:09 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/08/21 14:51:29 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/08/21 14:50:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/08/21 12:29:01 | 000,000,000 | ---D | C] -- C:\Users\Markun\AppData\Roaming\Qualcomm
[2012/08/21 12:28:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QXDM Professional
[2012/08/21 12:27:58 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\Qualcomm
[2012/08/21 12:23:01 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Qualcomm
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/09/17 08:35:03 | 000,029,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/17 08:35:03 | 000,029,280 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/17 08:24:38 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/09/17 08:24:20 | 1551,253,504 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/16 20:17:02 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000UA.job
[2012/09/16 20:08:01 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/16 18:38:25 | 000,830,644 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/09/16 18:38:25 | 000,690,340 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/09/16 18:38:25 | 000,133,702 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/09/16 18:17:01 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000Core.job
[2012/09/15 23:14:49 | 000,021,741 | ---- | M] () -- C:\Users\Markun\AppData\Local\Temp16.html
[2012/09/15 23:13:29 | 000,001,955 | ---- | M] () -- C:\Users\Markun\AppData\Local\Temp1.html
[2012/09/15 22:16:27 | 000,000,294 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/09/15 01:15:10 | 000,000,278 | ---- | M] () -- C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/09/14 22:08:21 | 000,001,996 | ---- | M] () -- C:\Users\Markun\Desktop\DLL-Files.com FIXER.lnk
[2012/09/14 22:08:21 | 000,001,980 | ---- | M] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\DLL-Files.com FIXER.lnk
[2012/09/14 08:25:40 | 000,159,456 | ---- | M] (Tonec Inc.) -- C:\Windows\SysNative\drivers\idmwfp.sys
[2012/09/12 09:47:49 | 000,001,926 | ---- | M] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/09/12 09:47:47 | 000,000,000 | ---- | M] () -- C:\Windows\SysWow64\config.nt
[2012/09/11 23:14:27 | 000,000,352 | ---- | M] () -- C:\Users\Markun\AppData\Roaming\Network Meter_Settings.ini
[2012/09/11 22:57:23 | 000,000,990 | ---- | M] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\KeyFinder.lnk
[2012/09/10 11:45:41 | 000,000,046 | ---- | M] () -- C:\Windows\SysWow64\DonationCoder_processtamer_InstallInfo.dat
[2012/09/10 11:45:41 | 000,000,046 | ---- | M] () -- C:\Users\Markun\AppData\Local\DonationCoder_processtamer_InstallInfo.dat
[2012/09/09 21:03:30 | 000,000,266 | ---- | M] () -- C:\Windows\tasks\AutoKMS.job
[2012/09/09 11:11:09 | 000,001,054 | ---- | M] () -- C:\Users\Markun\Desktop\MSI Afterburner.lnk
[2012/09/08 10:09:41 | 000,003,026 | ---- | M] (Logix4u) -- C:\Windows\SysWow64\drivers\hwinterface.sys
[2012/09/04 18:59:02 | 005,328,792 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012/09/04 14:43:46 | 000,000,021 | ---- | M] () -- C:\Windows\SurCode.INI
[2012/09/02 18:41:05 | 000,002,198 | ---- | M] () -- C:\Users\Markun\Desktop\RockMelt.lnk
[2012/09/01 11:07:09 | 000,002,453 | ---- | M] () -- C:\Users\Public\Desktop\SeaTools for Windows.lnk
[2012/08/31 00:34:22 | 000,000,128 | ---- | M] () -- C:\Windows\wininit.ini
[2012/08/30 19:16:25 | 000,001,105 | ---- | M] () -- C:\Users\Public\Desktop\Angry Birds Space.lnk
[2012/08/30 19:04:33 | 000,002,081 | ---- | M] () -- C:\Users\Public\Desktop\Angry Birds Seasons.lnk
[2012/08/29 15:40:27 | 000,000,028 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/08/28 18:59:13 | 000,000,784 | ---- | M] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\Hear.lnk
[2012/08/28 00:21:00 | 000,029,424 | ---- | M] (DeskSoft) -- C:\Windows\SysNative\drivers\dsnpfd.sys
[2012/08/26 19:19:05 | 000,001,252 | ---- | M] () -- C:\Users\Markun\Desktop\photoFXlab(64Bit).lnk
[2012/08/26 16:56:05 | 000,001,150 | ---- | M] () -- C:\TopazLabs.lnk
[2012/08/26 16:56:03 | 000,001,314 | ---- | M] () -- C:\Users\Markun\Desktop\TopazSoftwareManager.lnk
[2012/08/25 18:34:00 | 000,109,256 | ---- | M] () -- C:\Windows\SysWow64\EasyHook64.dll
[2012/08/25 18:34:00 | 000,090,824 | ---- | M] () -- C:\Windows\SysWow64\EasyHook32.dll
[2012/08/24 09:03:15 | 000,001,097 | ---- | M] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\USB Safely Remove.lnk
[2012/08/22 08:23:45 | 000,000,505 | ---- | M] () -- C:\Users\Markun\Desktop\Devices and Printers - Shortcut.lnk
[2012/08/21 16:13:13 | 000,969,200 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSnx.sys
[2012/08/21 16:13:13 | 000,359,464 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswSP.sys
[2012/08/21 16:13:13 | 000,059,728 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswTdi.sys
[2012/08/21 16:13:12 | 000,266,776 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswNdis2.sys
[2012/08/21 16:13:12 | 000,071,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswMonFlt.sys
[2012/08/21 16:13:12 | 000,054,072 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswRdr2.sys
[2012/08/21 16:13:11 | 000,142,128 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFW.sys
[2012/08/21 16:13:11 | 000,025,232 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswFsBlk.sys
[2012/08/21 16:13:11 | 000,019,600 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\drivers\aswKbd.sys
[2012/08/21 16:12:33 | 000,041,224 | ---- | M] (AVAST Software) -- C:\Windows\avastSS.scr
[2012/08/21 16:12:23 | 000,227,648 | ---- | M] (AVAST Software) -- C:\Windows\SysWow64\aswBoot.exe
[2012/08/21 16:12:02 | 000,285,328 | ---- | M] (AVAST Software) -- C:\Windows\SysNative\aswBoot.exe
[4 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/09/14 22:08:38 | 000,000,294 | ---- | C] () -- C:\Windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/09/14 22:08:37 | 000,000,278 | ---- | C] () -- C:\Windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/09/14 22:08:21 | 000,001,996 | ---- | C] () -- C:\Users\Markun\Desktop\DLL-Files.com FIXER.lnk
[2012/09/14 22:08:21 | 000,001,980 | ---- | C] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\DLL-Files.com FIXER.lnk
[2012/09/14 21:28:17 | 000,021,741 | ---- | C] () -- C:\Users\Markun\AppData\Local\Temp16.html
[2012/09/12 22:12:23 | 000,000,165 | ---- | C] () -- C:\800.scr
[2012/09/12 22:12:23 | 000,000,165 | ---- | C] () -- C:\1900.scr
[2012/09/12 22:12:23 | 000,000,156 | ---- | C] () -- C:\normal.scr
[2012/09/12 22:12:23 | 000,000,127 | ---- | C] () -- C:\otapa.scr
[2012/09/12 22:12:23 | 000,000,123 | ---- | C] () -- C:\hybon.scr
[2012/09/11 23:14:14 | 000,000,352 | ---- | C] () -- C:\Users\Markun\AppData\Roaming\Network Meter_Settings.ini
[2012/09/11 22:57:23 | 000,000,990 | ---- | C] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\KeyFinder.lnk
[2012/09/11 15:38:48 | 000,001,926 | ---- | C] () -- C:\Users\Public\Desktop\avast! Internet Security.lnk
[2012/09/10 11:45:41 | 000,000,046 | ---- | C] () -- C:\Windows\SysWow64\DonationCoder_processtamer_InstallInfo.dat
[2012/09/10 11:45:41 | 000,000,046 | ---- | C] () -- C:\Users\Markun\AppData\Local\DonationCoder_processtamer_InstallInfo.dat
[2012/09/09 21:03:30 | 000,000,266 | ---- | C] () -- C:\Windows\tasks\AutoKMS.job
[2012/09/09 11:11:09 | 000,001,054 | ---- | C] () -- C:\Users\Markun\Desktop\MSI Afterburner.lnk
[2012/09/02 18:41:05 | 000,002,198 | ---- | C] () -- C:\Users\Markun\Desktop\RockMelt.lnk
[2012/09/02 18:12:05 | 000,000,932 | ---- | C] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000UA.job
[2012/09/02 18:12:05 | 000,000,880 | ---- | C] () -- C:\Windows\tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000Core.job
[2012/09/01 11:07:09 | 000,002,453 | ---- | C] () -- C:\Users\Public\Desktop\SeaTools for Windows.lnk
[2012/08/31 00:34:22 | 000,000,128 | ---- | C] () -- C:\Windows\wininit.ini
[2012/08/30 19:16:25 | 000,001,105 | ---- | C] () -- C:\Users\Public\Desktop\Angry Birds Space.lnk
[2012/08/30 19:04:33 | 000,002,081 | ---- | C] () -- C:\Users\Public\Desktop\Angry Birds Seasons.lnk
[2012/08/28 18:59:13 | 000,000,784 | ---- | C] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\Hear.lnk
[2012/08/28 12:26:09 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2012/08/26 19:19:05 | 000,001,252 | ---- | C] () -- C:\Users\Markun\Desktop\photoFXlab(64Bit).lnk
[2012/08/26 16:56:04 | 000,001,150 | ---- | C] () -- C:\TopazLabs.lnk
[2012/08/26 16:56:03 | 000,001,314 | ---- | C] () -- C:\Users\Markun\Desktop\TopazSoftwareManager.lnk
[2012/08/25 18:34:31 | 000,109,256 | ---- | C] () -- C:\Windows\SysWow64\EasyHook64.dll
[2012/08/25 18:34:31 | 000,090,824 | ---- | C] () -- C:\Windows\SysWow64\EasyHook32.dll
[2012/08/24 09:03:15 | 000,001,097 | ---- | C] () -- C:\Users\Markun\Application Data\Microsoft\Internet Explorer\Quick Launch\USB Safely Remove.lnk
[2012/08/22 08:23:45 | 000,000,505 | ---- | C] () -- C:\Users\Markun\Desktop\Devices and Printers - Shortcut.lnk
[2012/08/17 00:34:32 | 000,001,013 | ---- | C] () -- C:\Users\Markun\Internet Download Manager.lnk
[2012/08/03 11:54:33 | 000,043,520 | ---- | C] () -- C:\Windows\SysWow64\CmdLineExt03.dll
[2012/07/29 20:53:13 | 000,381,440 | ---- | C] () -- C:\Windows\SysWow64\foo_input_dts.dll
[2012/06/19 09:42:42 | 004,178,432 | ---- | C] () -- C:\Windows\SysWow64\PhotoLooksRenderer.dll
[2012/06/10 19:57:32 | 000,002,072 | RHS- | C] () -- C:\Users\Markun\ntuser.pol
[2012/06/03 22:04:48 | 000,001,955 | ---- | C] () -- C:\Users\Markun\AppData\Local\Temp1.html
[2012/06/02 21:18:21 | 000,175,616 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2012/05/15 13:38:10 | 000,269,740 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2012/05/13 16:32:00 | 000,000,021 | ---- | C] () -- C:\Windows\SurCode.INI
[2012/05/07 01:37:48 | 000,021,520 | ---- | C] () -- C:\Windows\DCEBoot64.exe
[2012/05/06 12:19:48 | 000,000,370 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2012/04/29 22:31:37 | 000,000,153 | ---- | C] () -- C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
[2012/04/29 17:59:03 | 000,007,597 | ---- | C] () -- C:\Users\Markun\AppData\Local\Resmon.ResmonCfg
[2012/04/26 23:31:17 | 000,000,000 | ---- | C] () -- C:\Windows\canopus.ini
[2012/04/26 22:59:45 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\pavedius5db.dll
[2012/04/26 22:59:45 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\pavedius.dll
[2012/04/26 18:14:26 | 000,005,632 | ---- | C] () -- C:\Users\Markun\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/04/23 09:18:58 | 000,002,298 | ---- | C] () -- C:\Users\Markun\AppData\Roaming\ASSDraw3.cfg
[2012/04/09 00:52:22 | 000,157,696 | ---- | C] () -- C:\Windows\SysWow64\d3d9_smaa.dll
[2012/04/09 00:52:22 | 000,002,496 | ---- | C] () -- C:\Windows\SysWow64\enbseries.ini
[2012/04/08 11:11:24 | 000,000,132 | ---- | C] () -- C:\Windows\MYOBPOpt.INI
[2012/04/08 11:04:11 | 000,000,388 | ---- | C] () -- C:\Windows\MYOBP.INI
[2012/04/08 11:04:11 | 000,000,127 | ---- | C] () -- C:\Windows\SwDrvs.ini
[2012/04/08 11:04:11 | 000,000,042 | ---- | C] () -- C:\Windows\MYOB.INI
[2012/04/08 10:56:58 | 000,000,000 | ---- | C] () -- C:\Windows\drvxl32.INI
[2012/04/08 10:56:56 | 000,000,000 | ---- | C] () -- C:\Windows\drvwd32.INI
[2012/04/08 10:56:55 | 000,000,000 | ---- | C] () -- C:\Windows\drvwp32.INI
[2012/04/07 10:37:31 | 000,815,158 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/04/06 23:19:25 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/04/06 22:21:02 | 000,000,074 | RHS- | C] () -- C:\Windows\CT4CET.bin
[2012/03/09 11:31:26 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/03/09 11:31:26 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/01/31 07:00:24 | 000,016,896 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2011/10/25 21:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll
[2011/09/19 20:03:40 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\rtvcvfw32.dll
[2011/09/13 05:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
========== LOP Check ==========
[2012/04/22 22:21:29 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Aegisub
[2012/09/16 11:41:29 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\AIMP3
[2012/04/30 00:06:09 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Autodesk
[2012/07/14 09:41:27 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\BatteryCare
[2012/04/26 23:25:31 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Canopus
[2012/07/21 23:47:31 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\com.adobe.dmp.contentviewer
[2012/05/13 16:39:39 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\com.adobe.WidgetBrowser
[2012/04/17 13:06:56 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\com.prezi.PreziDesktop
[2012/08/29 16:07:45 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\DAEMON Tools Lite
[2012/05/05 17:58:09 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Digiarty
[2012/09/14 22:08:31 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\dll-files.com
[2012/09/17 00:14:56 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\DMCache
[2012/09/10 11:45:41 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\DonationCoder
[2012/08/09 15:37:27 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\DVDVideoSoft
[2012/04/07 21:08:52 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\ExtremeCopy
[2012/07/07 00:57:31 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\FFSJ
[2012/09/16 17:45:19 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\foobar2000
[2012/07/25 16:42:48 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Hard Disk Sentinel
[2012/08/28 19:20:51 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Hear
[2012/09/17 23:18:15 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\IDM
[2012/05/16 00:41:15 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\ImTOO
[2012/09/15 19:58:32 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Indowebster Desktop Uploader
[2012/05/06 12:56:18 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\IObit
[2012/04/07 21:06:01 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Leadertech
[2012/04/07 21:49:37 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Memeo
[2012/04/29 01:01:42 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\MiniLyrics
[2012/09/08 17:48:52 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Mirillis
[2012/04/07 11:52:39 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Moonchild Productions
[2012/05/09 00:36:11 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Netscape
[2012/07/01 13:48:07 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Opera
[2012/06/21 11:50:20 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Origin
[2012/05/13 16:32:00 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\PACE Anti-Piracy
[2012/07/26 10:12:53 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\PCDr
[2012/08/17 08:22:09 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\PDF Reader
[2012/05/09 00:35:00 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Photodex
[2012/04/07 11:50:01 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Pixlromatic
[2012/07/21 14:50:56 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\PlatinumHideIP
[2012/04/26 23:15:18 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\proDAD
[2012/08/21 12:29:01 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Qualcomm
[2012/09/11 02:07:37 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Rainmeter
[2012/09/07 22:51:13 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Red Giant Link
[2012/04/08 18:46:02 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Rovio
[2012/04/07 21:20:49 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Seagate
[2012/04/07 01:15:15 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Smadav
[2012/05/15 22:43:38 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Softland
[2012/04/26 23:40:14 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Sony
[2012/09/16 18:40:39 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\SPlayer
[2012/05/29 23:02:12 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/09/17 23:22:38 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\TeraCopy
[2012/09/02 19:22:32 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Unity
[2012/09/17 08:26:22 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\USBSafelyRemove
[2012/09/10 18:47:23 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\uTorrent
[2012/04/10 20:20:41 | 000,000,000 | ---D | M] -- C:\Users\Markun\AppData\Roaming\Windows Live Writer
[2012/09/09 21:03:30 | 000,000,266 | ---- | M] () -- C:\Windows\Tasks\AutoKMS.job
[2012/09/15 01:15:10 | 000,000,278 | ---- | M] () -- C:\Windows\Tasks\DLL-files.com Fixer_MONTHLY.job
[2012/09/15 22:16:27 | 000,000,294 | ---- | M] () -- C:\Windows\Tasks\DLL-files.com Fixer_UPDATES.job
[2012/09/16 18:17:01 | 000,000,880 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000Core.job
[2012/09/16 20:17:02 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\RockMeltUpdateTaskUserS-1-5-21-3855026746-3988461744-3588451260-1000UA.job
[2012/09/11 12:28:15 | 000,032,644 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Files - Unicode (All) ==========
[2012/05/08 12:56:33 | 000,000,000 | ---D | M](C:\Program Files (x86)\ACE??) -- C:\Program Files (x86)\ACE침대
[2012/05/08 12:56:33 | 000,000,000 | ---D | M](C:\Program Files (x86)\ACE??) -- C:\Program Files (x86)\ACE침대
[2012/04/28 01:53:31 | 000,001,968 | ---- | M] ()(C:\Windows\SysWow64\JB, ??? - New Dreaming.lrc) -- C:\Windows\SysWow64\JB, 박서준 - New Dreaming.lrc
[2012/04/28 01:53:31 | 000,001,968 | ---- | C] ()(C:\Windows\SysWow64\JB, ??? - New Dreaming.lrc) -- C:\Windows\SysWow64\JB, 박서준 - New Dreaming.lrc
[2012/04/28 01:53:18 | 000,002,055 | ---- | M] ()(C:\Windows\SysWow64\??(2AM) & Jr. & ??? & ??? - B???.lrc) -- C:\Windows\SysWow64\진운(2AM) & Jr. & 김지수 & 강소라 - B급인생.lrc
[2012/04/28 01:53:18 | 000,002,055 | ---- | C] ()(C:\Windows\SysWow64\??(2AM) & Jr. & ??? & ??? - B???.lrc) -- C:\Windows\SysWow64\진운(2AM) & Jr. & 김지수 & 강소라 - B급인생.lrc
[2012/04/28 01:53:03 | 000,001,387 | ---- | M] ()(C:\Windows\SysWow64\?? [???] - ????.lrc) -- C:\Windows\SysWow64\지연 [티아라] - 하루하루.lrc
[2012/04/28 01:53:03 | 000,001,387 | ---- | C] ()(C:\Windows\SysWow64\?? [???] - ????.lrc) -- C:\Windows\SysWow64\지연 [티아라] - 하루하루.lrc
[2012/04/28 01:52:35 | 000,002,508 | ---- | M] ()(C:\Windows\SysWow64\??, JB - Together.lrc) -- C:\Windows\SysWow64\지연, JB - Together.lrc
[2012/04/28 01:52:35 | 000,002,508 | ---- | C] ()(C:\Windows\SysWow64\??, JB - Together.lrc) -- C:\Windows\SysWow64\지연, JB - Together.lrc
[2012/04/28 01:52:28 | 000,001,629 | ---- | M] ()(C:\Windows\SysWow64\??? (Lee Ki Chan) - ?? ?? (Sick of Hope).lrc) -- C:\Windows\SysWow64\이기찬 (Lee Ki Chan) - 아픈 희망 (Sick of Hope).lrc
[2012/04/28 01:52:28 | 000,001,629 | ---- | C] ()(C:\Windows\SysWow64\??? (Lee Ki Chan) - ?? ?? (Sick of Hope).lrc) -- C:\Windows\SysWow64\이기찬 (Lee Ki Chan) - 아픈 희망 (Sick of Hope).lrc
[2012/04/28 01:52:23 | 000,002,229 | ---- | M] ()(C:\Windows\SysWow64\??, ??, ??? - Super Star.lrc) -- C:\Windows\SysWow64\효린, 지연, 에일리 - Super Star.lrc
[2012/04/28 01:52:23 | 000,002,229 | ---- | C] ()(C:\Windows\SysWow64\??, ??, ??? - Super Star.lrc) -- C:\Windows\SysWow64\효린, 지연, 에일리 - Super Star.lrc
[2012/04/28 01:52:14 | 000,001,469 | ---- | M] ()(C:\Windows\SysWow64\?? (Wonder Girls) - Hello To Myself.lrc) -- C:\Windows\SysWow64\예은 (Wonder Girls) - Hello To Myself.lrc
[2012/04/28 01:52:14 | 000,001,469 | ---- | C] ()(C:\Windows\SysWow64\?? (Wonder Girls) - Hello To Myself.lrc) -- C:\Windows\SysWow64\예은 (Wonder Girls) - Hello To Myself.lrc
[2012/04/28 01:52:09 | 000,001,415 | ---- | M] ()(C:\Windows\SysWow64\??(Miss A) - You're My Star.lrc) -- C:\Windows\SysWow64\수지(Miss A) - You're My Star.lrc
[2012/04/28 01:52:09 | 000,001,415 | ---- | C] ()(C:\Windows\SysWow64\??(Miss A) - You're My Star.lrc) -- C:\Windows\SysWow64\수지(Miss A) - You're My Star.lrc
[2012/04/28 01:52:02 | 000,001,639 | ---- | M] ()(C:\Windows\SysWow64\??? - Falling.lrc) -- C:\Windows\SysWow64\박진영 - Falling.lrc
[2012/04/28 01:52:02 | 000,001,639 | ---- | C] ()(C:\Windows\SysWow64\??? - Falling.lrc) -- C:\Windows\SysWow64\박진영 - Falling.lrc
[2012/04/28 01:51:04 | 000,001,890 | ---- | M] ()(C:\Windows\SysWow64\SE7EN - ?? ??? ???.lrc) -- C:\Windows\SysWow64\SE7EN - 내가 노래를 못해도.lrc
[2012/04/28 01:51:04 | 000,001,890 | ---- | C] ()(C:\Windows\SysWow64\SE7EN - ?? ??? ???.lrc) -- C:\Windows\SysWow64\SE7EN - 내가 노래를 못해도.lrc
(C:\Program Files (x86)\ACE??) -- C:\Program Files (x86)\ACE침대
========== Alternate Data Streams ==========
@Alternate Data Stream - 949 bytes -> C:\ProgramData\Microsoft:BNs4ZUk00zsVzaZVkVagBxhS3U
@Alternate Data Stream - 192 bytes -> C:\Windows:nlsPreferences
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:56E2E879
@Alternate Data Stream - 1175 bytes -> C:\ProgramData\Microsoft:oDA9XSHtbwjPiqe8Tiog3XsJJ
@Alternate Data Stream - 1012 bytes -> C:\ProgramData\Microsoft:NdpbV42eXl1pU1vrh
< End of report >
Edited by blackcampaign, 16 September 2012 - 08:13 PM.