Log
OTL logfile created on: 20/12/2012 18:44:35 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\paul\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
8.00 Gb Total Physical Memory | 5.70 Gb Available Physical Memory | 71.32% Memory free
16.00 Gb Paging File | 13.46 Gb Available in Paging File | 84.16% Paging File free
Paging file location(s): c:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 465.66 Gb Total Space | 142.34 Gb Free Space | 30.57% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 94.71 Gb Free Space | 20.33% Space Free | Partition Type: NTFS
Drive E: | 195.27 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: PAUL-PC | User Name: paul | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/12/20 18:43:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\paul\Desktop\OTL.exe
PRC - [2012/12/16 20:15:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2012/09/21 15:23:56 | 000,690,096 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_4_402_278_ActiveX.exe
PRC - [2012/07/27 20:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/02/22 19:55:48 | 000,885,760 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe
PRC - [2011/11/17 15:50:34 | 001,685,504 | ---- | M] () -- C:\Program Files (x86)\QPAD\QPAD MK-85 Gaming Keyboard Software\HID.exe
PRC - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) -- C:\Tese\x86\ekrn.exe
PRC - [2010/10/27 18:17:52 | 000,207,424 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
PRC - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
PRC - [2009/12/02 22:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
PRC - [2009/12/02 22:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
PRC - [2009/08/29 06:00:12 | 000,966,656 | ---- | M] () -- C:\Users\paul\Local Settings\Apps\F.lux\flux.exe
PRC - [2008/09/18 09:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) -- C:\Program Files (x86)\ArcSoft\HP Webcam Software Suite\Magic-i Visual Effects 2\uCamMonitor.exe
========== Modules (No Company Name) ==========
MOD - [2012/09/21 02:37:16 | 014,339,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\02f7846cbc5c02a5dbf50fd34325eb61\PresentationFramework.ni.dll
MOD - [2012/09/21 02:37:06 | 012,234,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\f4b2424c1b32fbd11130482bb899b7ae\PresentationCore.ni.dll
MOD - [2012/09/21 02:36:57 | 003,347,968 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\47b9e7f070271ff50f988f75ea68fa3e\WindowsBase.ni.dll
MOD - [2012/09/21 02:36:24 | 012,433,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6c51e152e7404188914c9fa4d8503ff9\System.Windows.Forms.ni.dll
MOD - [2012/09/21 02:36:18 | 001,587,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\ab87129c2b603f218e4aa5300c9b1bdd\System.Drawing.ni.dll
MOD - [2012/09/21 02:36:15 | 005,453,312 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\9866d1f6178e1cde25642f1ac293ff8d\System.Xml.ni.dll
MOD - [2012/09/21 02:36:12 | 007,967,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\faf4e8730ecbd07570111bb7c3b20565\System.ni.dll
MOD - [2012/09/21 02:36:07 | 011,490,304 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\a1a82db68b3badc7c27ea1f6579d22c5\mscorlib.ni.dll
MOD - [2011/11/17 15:50:34 | 001,685,504 | ---- | M] () -- C:\Program Files (x86)\QPAD\QPAD MK-85 Gaming Keyboard Software\HID.exe
MOD - [2009/08/29 06:00:12 | 000,966,656 | ---- | M] () -- C:\Users\paul\Local Settings\Apps\F.lux\flux.exe
========== Services (SafeList) ==========
SRV:64bit: - [2012/09/28 01:38:16 | 000,239,616 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2010/06/29 17:49:27 | 000,128,752 | ---- | M] (SUPERAntiSpyware.com) [On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2009/07/14 01:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2009/07/14 01:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012/12/16 20:15:46 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2012/12/05 17:32:17 | 000,541,168 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2012/11/09 11:21:24 | 000,160,944 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2012/08/03 23:32:19 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)
SRV - [2012/08/03 23:31:29 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)
SRV - [2012/07/27 20:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/06/27 11:29:24 | 002,369,960 | ---- | M] (LogMeIn Inc.) [On_Demand | Stopped] -- C:\Hamachi\hamachi-2.exe -- (Hamachi2Svc)
SRV - [2012/02/29 12:09:28 | 000,105,472 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\CtHdaSvc.exe -- (CtHdaSvc)
SRV - [2012/02/08 06:54:32 | 000,131,912 | ---- | M] (Desura Pty Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Desura\desura_service.exe -- (Desura Install Service)
SRV - [2011/10/19 15:30:50 | 000,423,424 | ---- | M] (Creative Technology Ltd) [On_Demand | Stopped] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)
SRV - [2011/09/22 12:03:30 | 000,974,944 | ---- | M] (ESET) [Auto | Running] -- C:\Tese\x86\ekrn.exe -- (ekrn)
SRV - [2010/05/23 21:28:00 | 003,518,368 | ---- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GameMon.des -- (npggsvc)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 10:19:26 | 000,113,152 | ---- | M] (ArcSoft Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe -- (ACDaemon)
SRV - [2009/12/02 22:23:38 | 000,209,768 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe -- (sftvsa)
SRV - [2009/12/02 22:23:32 | 000,483,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe -- (sftlist)
SRV - [2009/06/10 21:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/09/18 09:59:10 | 000,104,960 | ---- | M] (ArcSoft, Inc.) [Auto | Running] -- C:\Program Files (x86)\ArcSoft\HP Webcam Software Suite\Magic-i Visual Effects 2\uCamMonitor.exe -- (uCamMonitor)
SRV - [2008/04/07 09:17:30 | 000,430,592 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
========== Driver Services (SafeList) ==========
DRV:64bit: - File not found [Kernel | System | Stopped] -- C:\Program Files\SUPERAntiSpyware\SABKUTIL.sys -- (SABKUTIL)
DRV:64bit: - [2012/09/28 02:21:20 | 010,697,216 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)
DRV:64bit: - [2012/09/28 01:12:52 | 000,460,288 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)
DRV:64bit: - [2012/09/16 05:55:46 | 000,038,624 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901.sys -- (tap0901)
DRV:64bit: - [2012/08/21 02:07:58 | 000,037,912 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tap0901_openvpn_accl.sys -- (tap0901_openvpn_accl)
DRV:64bit: - [2012/05/14 06:12:30 | 000,096,896 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)
DRV:64bit: - [2012/04/25 11:11:36 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/02/29 12:15:40 | 000,023,640 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CtHDb.sys -- (cthdb)
DRV:64bit: - [2012/02/29 12:15:18 | 001,271,384 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cthda.sys -- (cthda)
DRV:64bit: - [2011/10/19 11:43:32 | 000,029,440 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\I1KBFLTR.sys -- (I1KBFLTR)
DRV:64bit: - [2011/08/09 14:24:52 | 000,202,576 | ---- | M] (ESET) [File_System | Auto | Running] -- C:\Windows\SysNative\drivers\eamonm.sys -- (eamonm)
DRV:64bit: - [2011/08/04 09:20:38 | 000,146,432 | ---- | M] (ESET) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ehdrv.sys -- (ehdrv)
DRV:64bit: - [2011/08/04 09:20:38 | 000,137,144 | ---- | M] (ESET) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\epfwwfpr.sys -- (epfwwfpr)
DRV:64bit: - [2011/08/01 12:42:10 | 000,057,200 | ---- | M] (Thermaltake) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MS6Filter.sys -- (Thermnaltake MS6 Filter)
DRV:64bit: - [2011/06/14 23:55:24 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2011/03/25 07:38:53 | 001,308,160 | ---- | M] (C-Media Electronics Inc) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CM10864.sys -- (USBPNPA)
DRV:64bit: - [2011/03/11 06:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 06:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2010/11/20 13:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/20 11:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/03/23 01:17:06 | 002,061,856 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RTL85n64.sys -- (RTL85n64)
DRV:64bit: - [2010/02/24 10:20:40 | 000,191,616 | ---- | M] (Protect Software GmbH) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\acedrv11.sys -- (acedrv11)
DRV:64bit: - [2010/02/17 18:23:05 | 000,014,920 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2010/02/17 18:23:05 | 000,012,360 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2009/12/02 22:23:38 | 000,022,376 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftvollh.sys -- (Sftvol)
DRV:64bit: - [2009/12/02 22:23:34 | 000,025,960 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftredirlh.sys -- (Sftredir)
DRV:64bit: - [2009/12/02 22:23:32 | 000,269,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftplaylh.sys -- (Sftplay)
DRV:64bit: - [2009/12/02 22:23:26 | 000,721,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Sftfslh.sys -- (Sftfs)
DRV:64bit: - [2009/07/14 01:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 01:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 01:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2009/07/14 01:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 20:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 20:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 20:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 20:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2009/05/26 13:32:04 | 000,019,968 | ---- | M] (ArcSoft, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ArcSoftKsUFilter.sys -- (ArcSoftKsUFilter)
DRV:64bit: - [2009/05/18 12:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2009/04/22 22:18:48 | 000,035,840 | R--- | M] (Avanquest Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BVRPMPR5a64.SYS -- (BVRPMPR5a64)
DRV:64bit: - [2009/03/18 16:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)
DRV:64bit: - [2009/03/01 22:05:32 | 000,187,392 | ---- | M] (Realtek Corporation ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2007/09/17 15:53:34 | 000,029,184 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pccsmcfdx64.sys -- (pccsmcfd)
DRV:64bit: - [2007/07/23 07:57:04 | 000,052,992 | ---- | M] (Ideazon Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Alpham164.sys -- (Alpham1)
DRV:64bit: - [2007/04/03 12:57:36 | 000,144,648 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116mdm.sys -- (s116mdm)
DRV:64bit: - [2007/04/03 12:57:36 | 000,019,720 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116mdfl.sys -- (s116mdfl)
DRV:64bit: - [2007/04/03 12:57:34 | 000,108,296 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\s116bus.sys -- (s116bus)
DRV:64bit: - [2007/03/20 09:51:04 | 000,021,760 | ---- | M] (Ideazon Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Alpham264.sys -- (Alpham2)
DRV - [2011/11/04 04:10:56 | 000,022,336 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2011/08/01 12:40:20 | 000,031,488 | ---- | M] (Thermaltake) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\MS6Filter.sys -- (Thermnaltake MS6 Filter)
DRV - [2009/07/14 01:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009/03/31 09:39:36 | 000,016,392 | ---- | M] (Teruten Inc) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\TFsExDisk.Sys -- (TFsExDisk)
DRV - [2005/01/03 15:43:08 | 000,004,682 | ---- | M] (INCA Internet Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\npptNT2.sys -- (NPPTNT2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKCU\..\SearchScopes,DefaultScope = {E99A578B-ED37-45CC-BEF7-7991C2C0C7BE}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{E99A578B-ED37-45CC-BEF7-7991C2C0C7BE}: "URL" = http://www.google.co...rchTerms}&meta=
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B000F1EA4-5E08-4564-A29B-29076F63A37A%7D:1.0.3.143
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_268.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\itunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\Sonar\npesnsonar.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch: C:\Program Files (x86)\BF3 Alpha Trial Web Plugins\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.102.0: C:\Program Files (x86)\Battlelog Web Plugins\1.102.0\npesnlaunch.dll File not found
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=1.138.0: C:\Program Files (x86)\Battlelog Web Plugins\1.138.0\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@fileplanet.com/fpdlm: D:\DarkFall\Download Manager\npfpdlm.dll File not found
FF - HKLM\Software\MozillaPlugins\@gamersfirst.com/LiveLauncher: C:\Program Files (x86)\GamersFirst\LIVE!\nplivelauncher.dll File not found
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.10.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.10.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@live.heroesandgenerals.com/npretox: C:\Program Files (x86)\Heroes & Generals\live\npretoxlive.dll (Reto-Moto ApS)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll File not found
FF - HKLM\Software\MozillaPlugins\@nosltd.com/getPlus+®,version=1.6.2.90: C:\Program Files (x86)\NOS\bin\np_gp.dll File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\paul\AppData\Roaming\Mozilla\Firefox\Profiles\emo32wyd.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll ()
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\paul\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll (Ubisoft)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\TESE\MOZILLA THUNDERBIRD [2012/12/20 18:11:13 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\firefox11.0\components [2012/12/10 15:58:47 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\firefox11.0\plugins
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Firefox\components [2012/12/15 12:57:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Firefox\plugins [2012/12/12 15:37:57 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[email protected]: C:\Tese\Mozilla Thunderbird [2012/12/20 18:11:13 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Firefox\components [2012/12/15 12:57:54 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Firefox\plugins [2012/12/12 15:37:57 | 000,000,000 | ---D | M]
[2011/10/07 17:25:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\paul\AppData\Roaming\Mozilla\Extensions
[2011/10/07 17:25:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\paul\AppData\Roaming\Mozilla\Extensions\[email protected]
[2012/12/12 15:38:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\paul\AppData\Roaming\Mozilla\Firefox\Profiles\emo32wyd.default\extensions
[2011/01/02 19:18:48 | 000,000,000 | ---D | M] () -- C:\Users\paul\AppData\Roaming\Mozilla\Firefox\Profiles\emo32wyd.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}
========== Chrome ==========
CHR - homepage: http://www.google.com
CHR - homepage: http://www.google.com
CHR - Extension: Google Search = C:\Users\paul\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\
CHR - Extension: Google Search = C:\Users\paul\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\
CHR - Extension: Gmail = C:\Users\paul\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/12/20 02:09:49 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C44F9E21-D93F-490C-B41C-B3548BDD19FC} - No CLSID value found.
O4:64bit: - HKLM..\Run: [egui] C:\Tese\egui.exe (ESET)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [BM.exe] C:\Program Files (x86)\HP\Button Manager\BM.exe (Hewlett-Packard)
O4 - HKLM..\Run: [ione] C:\Program Files (x86)\QPAD\QPAD MK-85 Gaming Keyboard Software\HID.exe ()
O4 - HKLM..\Run: [Sound Blaster Recon3D PCIe Control Panel] C:\Program Files (x86)\Creative\Sound Blaster Recon3D PCIe\Sound Blaster Recon3D PCIe Control Panel\SBRnPCIe.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [UpdReg] C:\Windows\Updreg.EXE (Creative Technology Ltd.)
O4 - HKCU..\Run: [DcnDwhso] C:\Users\paul\AppData\Local\uvyqmiua\dcndwhso.exe ()
O4 - HKCU..\Run: [F.lux] C:\Users\paul\Local Settings\Apps\F.lux\flux.exe ()
O4 - Startup: C:\Users\paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dcndwhso.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: clonewarsadventures.com ([www] http in Trusted sites)
O15 - HKCU\..Trusted Domains: freerealms.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: soe.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: sony.com ([]* in Trusted sites)
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} http://download.giga...bject/Dldrv.ocx (Dldrv2 Control)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://pcpitstop.com...p/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ri_4.1.72.0.cab (SysInfo Class)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {283B7DE7-A1ED-4D27-AA59-C6E7427544D2} https://sp.itronener...yBoxControl.cab (KeyBox Class)
O16 - DPF: {2A293777-79CA-4DD9-A545-0E1718C0D3CF} https://sp.itronener...yBoxControl.cab (KeyBox Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplane..._2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.co...iaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} https://www.battlefi...er_5.0.31.0.cab (Battlefield Heroes Updater)
O16 - DPF: {C8BC46C7-921C-4102-B67D-F1F7E65FB0BE} https://battlefield....er_1.0.66.2.cab (Battlefield Play4Free Updater)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creat...13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E6F480FC-BD44-4CBA-B74A-89AF7842937D} http://content.syste...ri_4.4.26.0.cab (SysInfo Class)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creat...10926/CTPID.cab (Creative Software AutoUpdate Support Package)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4BA9274C-22E9-4BFB-BBAE-25424E0C64B2}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{892F7C84-392C-440C-BED3-D44859E5D67D}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/07/07 11:09:24 | 000,233,344 | R--- | M] (ESET s.r.o.) - E:\Autorun.exe -- [ UDF ]
O32 - AutoRun File - [2011/06/30 15:38:30 | 000,000,133 | R--- | M] () - E:\AUTORUN.INF -- [ UDF ]
O32 - AutoRun File - [2011/07/19 07:11:59 | 000,000,000 | R--D | M] - E:\AutorunConfig -- [ UDF ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012/12/20 18:43:49 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\paul\Desktop\OTL.exe
[2012/12/20 18:11:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2012/12/20 18:11:01 | 000,000,000 | ---D | C] -- C:\ProgramData\ESET
[2012/12/20 17:48:45 | 000,000,000 | ---D | C] -- C:\Tese
[2012/12/20 02:33:44 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/12/20 02:11:01 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/12/20 01:44:49 | 000,000,000 | ---D | C] -- C:\Users\paul\Desktop\RK_Quarantine
[2012/12/20 00:02:15 | 000,448,512 | ---- | C] (OldTimer Tools) -- C:\Users\paul\Desktop\TFC.exe
[2012/12/19 23:54:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2012/12/19 19:45:10 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVE
[2012/12/19 18:49:17 | 000,000,000 | ---D | C] -- C:\Eve
[2012/12/18 21:49:39 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Local\SUPERAntiSpyware.com
[2012/12/18 07:44:00 | 005,012,372 | R--- | C] (Swearware) -- C:\Users\paul\Desktop\Gotcha.exe
[2012/12/18 05:19:40 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Local\uvyqmiua
[2012/12/18 02:18:09 | 000,000,000 | ---D | C] -- C:\Users\paul\Documents\Might & Magic Heroes VI
[2012/12/18 02:18:09 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Roaming\Might & Magic Heroes VI
[2012/12/17 16:21:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deep Silver
[2012/12/17 16:21:01 | 000,000,000 | ---D | C] -- C:\Users\Public\Documents\STALKER-STCS
[2012/12/14 22:31:10 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Local\WB Games
[2012/12/14 21:46:34 | 000,000,000 | ---D | C] -- C:\lotr
[2012/12/10 15:59:50 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes & Generals
[2012/12/10 15:59:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Heroes & Generals
[2012/12/09 20:46:35 | 000,000,000 | ---D | C] -- C:\Users\paul\Documents\Firefighter
[2012/12/09 19:37:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Real Heroes Firefighter
[2012/12/09 19:36:19 | 000,000,000 | ---D | C] -- C:\firefighter game
[2012/12/08 17:44:16 | 000,000,000 | ---D | C] -- C:\Stalker online
[2012/12/06 23:24:00 | 000,000,000 | ---D | C] -- C:\ProgramData\ATI
[2012/12/06 23:23:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD AVT
[2012/12/06 23:23:45 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AMD APP
[2012/12/06 23:23:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
[2012/11/26 15:14:46 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Local\SteamPopCap
[2012/11/24 14:57:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/11/24 14:57:38 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2012/11/23 23:18:28 | 000,000,000 | ---D | C] -- C:\Users\paul\AppData\Local\Sony Online Entertainment
========== Files - Modified Within 30 Days ==========
[2012/12/20 18:43:56 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\paul\Desktop\OTL.exe
[2012/12/20 18:38:30 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/20 18:38:30 | 000,014,864 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/20 18:30:20 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/12/20 18:30:01 | 2146,295,807 | -HS- | M] () -- C:\hiberfil.sys
[2012/12/20 02:09:49 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/12/20 01:40:01 | 000,756,224 | ---- | M] () -- C:\Users\paul\Desktop\Rogue-killer.exe
[2012/12/20 00:09:29 | 000,000,867 | ---- | M] () -- C:\Users\paul\Desktop\Malwarye.lnk
[2012/12/20 00:02:17 | 000,448,512 | ---- | M] (OldTimer Tools) -- C:\Users\paul\Desktop\TFC.exe
[2012/12/19 22:34:17 | 005,012,372 | R--- | M] (Swearware) -- C:\Users\paul\Desktop\Gotcha.exe
[2012/12/19 22:25:05 | 000,098,152 | --S- | M] () -- C:\Users\paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dcndwhso.exe
[2012/12/19 21:06:23 | 000,000,046 | ---- | M] () -- C:\Windows\264310
[2012/12/19 19:45:10 | 000,001,450 | ---- | M] () -- C:\Users\paul\Desktop\EVE.lnk
[2012/12/19 18:42:37 | 000,000,024 | ---- | M] () -- C:\Users\paul\jagexappletviewer.preferences
[2012/12/19 18:10:41 | 000,000,032 | ---- | M] () -- C:\Users\paul\jagex_cl_runescape_LIVE.dat
[2012/12/18 05:36:10 | 000,000,867 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/17 17:38:54 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.xtr
[2012/12/17 17:38:54 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2012/12/17 16:21:33 | 000,001,006 | ---- | M] () -- C:\Users\Public\Desktop\S.T.A.L.K.E.R. - Clear Sky.lnk
[2012/12/17 01:59:15 | 000,281,688 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2012/12/16 20:15:46 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2012/12/16 20:15:40 | 000,001,201 | ---- | M] () -- C:\Users\paul\Desktop\Uplay.lnk
[2012/12/16 01:04:02 | 562,017,014 | ---- | M] () -- C:\Windows\MEMORY.DMP
[2012/12/10 15:59:48 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Play Heroes & Generals.lnk
[2012/12/10 15:36:38 | 000,796,508 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/10 15:36:38 | 000,675,668 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/12/10 15:36:38 | 000,130,304 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/12/09 19:37:57 | 000,001,786 | ---- | M] () -- C:\Users\Public\Desktop\Real Heroes Firefighter.lnk
[2012/11/27 05:17:50 | 000,000,201 | ---- | M] () -- C:\Users\paul\Desktop\Train Simulator 2013.url
[2012/11/24 14:57:38 | 000,002,515 | ---- | M] () -- C:\Users\Public\Desktop\Skype.lnk
[2012/11/23 23:22:09 | 000,001,487 | ---- | M] () -- C:\Users\paul\Desktop\PlanetSide 2.lnk
========== Files Created - No Company Name ==========
[2012/12/20 01:39:59 | 000,756,224 | ---- | C] () -- C:\Users\paul\Desktop\Rogue-killer.exe
[2012/12/19 23:21:56 | 000,000,867 | ---- | C] () -- C:\Users\paul\Desktop\Malwarye.lnk
[2012/12/19 22:25:08 | 000,098,152 | --S- | C] () -- C:\Users\paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\dcndwhso.exe
[2012/12/19 21:06:23 | 000,000,046 | ---- | C] () -- C:\Windows\264310
[2012/12/19 19:45:10 | 000,001,450 | ---- | C] () -- C:\Users\paul\Desktop\EVE.lnk
[2012/12/17 16:21:33 | 000,001,006 | ---- | C] () -- C:\Users\Public\Desktop\S.T.A.L.K.E.R. - Clear Sky.lnk
[2012/12/16 20:15:40 | 000,001,201 | ---- | C] () -- C:\Users\paul\Desktop\Uplay.lnk
[2012/12/10 15:59:48 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Play Heroes & Generals.lnk
[2012/12/09 19:37:57 | 000,001,786 | ---- | C] () -- C:\Users\Public\Desktop\Real Heroes Firefighter.lnk
[2012/11/27 04:32:34 | 000,000,201 | ---- | C] () -- C:\Users\paul\Desktop\Train Simulator 2013.url
[2012/11/23 23:22:09 | 000,001,517 | ---- | C] () -- C:\Users\paul\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PlanetSide 2.lnk
[2012/11/23 23:22:09 | 000,001,487 | ---- | C] () -- C:\Users\paul\Desktop\PlanetSide 2.lnk
[2012/09/03 02:16:24 | 000,000,024 | ---- | C] () -- C:\Users\paul\jagexappletviewer.preferences
[2012/09/02 00:07:02 | 000,000,044 | ---- | C] () -- C:\Users\paul\jagex_cl_runescape_LIVE3.dat
[2012/09/01 23:34:40 | 000,000,044 | ---- | C] () -- C:\Users\paul\jagex_cl_runescape_LIVE2.dat
[2012/09/01 01:37:22 | 000,000,044 | ---- | C] () -- C:\Users\paul\jagex_cl_runescape_LIVE1.dat
[2012/08/31 20:45:08 | 000,000,032 | ---- | C] () -- C:\Users\paul\jagex_cl_runescape_LIVE.dat
[2012/08/28 19:52:38 | 001,209,805 | ---- | C] () -- C:\Windows\unins000.exe
[2012/08/28 19:52:38 | 000,044,478 | ---- | C] () -- C:\Windows\unins000.dat
[2012/07/10 18:26:43 | 000,000,217 | ---- | C] () -- C:\Windows\RomeTW.ini
[2012/07/10 01:00:16 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/07/10 01:00:16 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/07/10 01:00:16 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/07/10 01:00:16 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/07/10 01:00:16 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/05/15 01:21:50 | 000,423,744 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2012/05/09 12:57:32 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/05/02 14:58:10 | 000,029,184 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll
[2012/04/02 15:58:33 | 000,143,360 | ---- | C] () -- C:\Windows\Vmix108.dll
[2012/04/02 15:58:17 | 000,000,522 | ---- | C] () -- C:\Windows\Cm108.ini.cfl
[2012/04/02 15:58:06 | 000,002,029 | ---- | C] () -- C:\Windows\Cm108.ini.cfg
[2012/04/02 15:58:06 | 000,000,840 | ---- | C] () -- C:\Windows\Cm108.ini.imi
[2012/02/15 20:12:59 | 000,002,528 | ---- | C] () -- C:\Users\paul\AppData\Roaming\$_hpcst$.hpc
[2012/02/15 02:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat
[2012/02/15 02:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat
[2012/02/06 20:46:55 | 000,000,857 | ---- | C] () -- C:\Users\paul\.recently-used.xbel
[2011/12/26 15:06:17 | 003,142,728 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_hos.exe
[2011/10/22 20:05:00 | 000,294,784 | ---- | C] () -- C:\Users\paul\AppData\Roaming\Fallen Earth_2.54.0.3_2011-10-22-20-04.dmp
[2011/10/14 19:34:30 | 000,080,473 | ---- | C] () -- C:\Users\paul\AppData\Roaming\icarus-dxdiag.xml
[2011/09/28 17:44:14 | 000,179,271 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2011/09/12 22:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat
[2011/08/26 22:21:30 | 000,042,392 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2011/08/15 11:28:10 | 000,000,023 | ---- | C] () -- C:\Windows\BlendSettings.ini
[2011/04/07 13:01:39 | 000,007,886 | -HS- | C] () -- C:\Users\paul\AppData\Local\325cq8r6ceko405fg
[2011/04/07 13:01:39 | 000,007,886 | -HS- | C] () -- C:\ProgramData\325cq8r6ceko405fg
[2011/03/25 07:40:22 | 000,001,318 | ---- | C] () -- C:\Windows\cm108.ini
[2011/03/20 15:19:47 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\EALTEST.EXE
[2011/02/14 16:42:44 | 000,000,261 | ---- | C] () -- C:\Users\paul\AppData\Roaming\net.telestream.ustreamproducer.prefs.xml
[2011/01/29 19:36:31 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2010/12/06 22:32:15 | 000,007,616 | ---- | C] () -- C:\Users\paul\AppData\Local\Resmon.ResmonCfg
[2010/11/04 13:26:29 | 000,000,092 | ---- | C] () -- C:\Users\paul\AppData\Local\fusioncache.dat
[2010/10/12 03:28:01 | 000,000,099 | ---- | C] () -- C:\Users\paul\jagex_runescape_preferences2.dat
[2010/10/12 03:26:46 | 000,000,046 | ---- | C] () -- C:\Users\paul\jagex_runescape_preferences.dat
[2010/07/15 03:54:23 | 000,003,584 | ---- | C] () -- C:\Users\paul\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
========== ZeroAccess Check ==========
[2011/02/05 01:23:39 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2012/01/04 10:44:25 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/01/04 08:59:38 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 01:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 12:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 01:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/08/12 16:38:14 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\.minecraft
[2012/10/09 04:55:11 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\.spotflux
[2011/01/15 18:52:48 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\APOX
[2010/10/29 22:54:34 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Atari
[2012/10/21 04:01:11 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\AtomZombieData
[2012/07/17 18:08:48 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Bioshock
[2012/07/14 02:46:19 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Civitas2
[2012/07/14 02:35:56 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Civitas3
[2012/06/17 17:56:13 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\CorsixTH
[2012/07/05 16:59:17 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\DAEMON Tools Lite
[2011/02/06 18:35:01 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Darkfall
[2011/04/01 17:06:54 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\DarksporeData
[2011/08/12 06:39:42 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Dreamlords
[2011/11/01 04:51:02 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\driveridentifier
[2012/10/02 19:52:13 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Fatshark
[2012/07/26 23:17:41 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\FFsplit
[2011/01/22 16:09:12 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Firefly Studios
[2011/03/31 15:32:58 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\GameRanger
[2011/01/12 06:10:16 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\gtk-2.0
[2012/08/28 19:54:24 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\iOne
[2012/01/03 03:39:50 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Kalypso Media
[2010/10/29 21:55:04 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Leadertech
[2011/04/05 15:36:37 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\LolClient
[2012/10/21 20:53:25 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\LucasArts
[2012/12/19 02:13:36 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Might & Magic Heroes VI
[2011/01/06 04:47:01 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Mount&Blade Warband
[2011/09/17 22:30:30 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Mount&Blade With Fire and Sword
[2012/12/07 23:18:29 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Mumble
[2010/07/25 02:29:08 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Mumble(PR Edition)
[2010/07/21 23:27:29 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\My Battle for Middle-earth Files
[2012/09/08 23:17:19 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Natural Selection 2
[2011/06/21 16:38:49 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Octoshape
[2012/08/11 19:01:38 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Origin
[2011/01/20 00:00:28 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\PC Suite
[2010/08/12 02:01:26 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Petroglyph
[2012/09/24 21:43:13 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\PlayFirst
[2011/10/07 17:25:04 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Prism
[2010/12/25 14:40:29 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\ProtectDISC
[2011/02/27 19:16:51 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\RIFT
[2012/02/15 20:13:23 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Samsung
[2012/06/19 03:44:38 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\six-updater
[2012/06/18 22:20:11 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\six-zsync
[2012/12/17 04:32:38 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\SoftGrid Client
[2011/10/03 22:43:59 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\SplitMediaLabs
[2010/07/17 00:12:11 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Splitscreen Studios
[2011/03/08 18:26:38 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Sports Interactive
[2012/10/09 04:10:37 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Spotflux
[2011/06/24 13:29:04 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Stardock
[2010/09/30 14:49:53 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Subversion
[2011/02/22 21:07:20 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\The Creative Assembly
[2012/03/18 20:44:53 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\TP
[2012/07/18 20:21:09 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\TS3Client
[2010/12/17 17:29:51 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Unity
[2012/11/11 16:28:02 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\uTorrent
[2011/02/14 16:42:59 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Vara Software
[2010/09/03 12:09:05 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\W
[2012/10/13 02:29:43 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\wargaming.net
[2011/02/14 16:48:58 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\WebcamMax
[2011/02/14 16:42:44 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\Wirecast
[2012/07/05 19:18:56 | 000,000,000 | ---D | M] -- C:\Users\paul\AppData\Roaming\YourFileDownloader
========== Purity Check ==========
< End of report >