windows is slowed for 5 minutes after boot, exactly there are small 1 second freeze every 3 seconds, the mouse is stopped during that second, even the windows start sound is slowed, programs take more time to start during that time.
The screens before the desktop (welcome...) seems slower than usual.
During the 5 minutes, no process is using the cpu, only known process taking cpu while starting.
After the 5 minutes, everything is running fine, no slowdown at all.
I have used other tool removal like adwcleaner, malwarebytes, combofix and avast without any success.
Thanks by advance
OTL logfile created on: 20/10/2013 11:39:51 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = H:\d
Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 0000040c | Country: France | Language: FRA | Date Format: dd/MM/yyyy
2,00 Gb Total Physical Memory | 1,45 Gb Available Physical Memory | 72,74% Memory free
4,00 Gb Paging File | 3,07 Gb Available in Paging File | 76,82% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 200,00 Gb Total Space | 115,12 Gb Free Space | 57,56% Space Free | Partition Type: NTFS
Drive E: | 465,76 Gb Total Space | 21,67 Gb Free Space | 4,65% Space Free | Partition Type: NTFS
Drive H: | 1663,02 Gb Total Space | 184,49 Gb Free Space | 11,09% Space Free | Partition Type: NTFS
Computer Name: LUSKY-PC | User Name: Lusky | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/10/20 11:21:41 | 000,602,112 | ---- | M] (OldTimer Tools) -- H:\d\OTL.exe
PRC - [2013/09/11 19:56:12 | 000,829,524 | ---- | M] ( ) -- H:\Program Files\Miranda IM Fr\miranda32.exe
PRC - [2013/05/02 01:33:29 | 004,858,456 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/05/02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2012/11/23 04:48:41 | 000,049,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2011/10/12 22:10:00 | 000,397,312 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2011/10/12 22:09:32 | 000,176,128 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2011/10/12 16:18:28 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2011/05/26 05:31:41 | 002,616,320 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2013/10/11 08:37:40 | 011,914,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\6ebbfafc5521934f7e1c154937a2788b\System.Web.ni.dll
MOD - [2013/10/11 08:37:32 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\d473c19e69818875b9c739cad8f386a5\System.Runtime.Remoting.ni.dll
MOD - [2013/09/15 22:21:47 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\03dc83fbe48384390aed7a455e949789\WindowsFormsIntegration.ni.dll
MOD - [2013/09/15 22:19:38 | 002,297,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\9e38ddbb3a90cc3e782a0640788b1fcb\System.Core.ni.dll
MOD - [2013/09/15 22:15:13 | 014,340,096 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\930e99b2f62cea8c4aa070527d15f748\PresentationFramework.ni.dll
MOD - [2013/09/15 22:12:42 | 012,436,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\28ea347a952d20959ac6ae02d7457d39\System.Windows.Forms.ni.dll
MOD - [2013/09/15 22:12:31 | 001,593,344 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5aa44bce7933e4de09d935848f868a4b\System.Drawing.ni.dll
MOD - [2013/09/15 22:12:27 | 012,238,336 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\585b8f6cc7ba86886462d0dc9753c98f\PresentationCore.ni.dll
MOD - [2013/09/15 22:12:12 | 003,348,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\1f6f220f9efe936d1158c79b9d4b451f\WindowsBase.ni.dll
MOD - [2013/09/15 22:12:04 | 005,464,064 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\09db78d6068543df01862a023aca785a\System.Xml.ni.dll
MOD - [2013/09/15 22:11:59 | 000,978,432 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\8f7d83126a3cf283e5ac97f2d6d99f12\System.Configuration.ni.dll
MOD - [2013/09/15 22:11:52 | 007,989,760 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\5d22a30e587e2cac106b81fb351e7c08\System.ni.dll
MOD - [2013/09/11 19:55:44 | 000,057,432 | ---- | M] () -- H:\Program Files\Miranda IM Fr\zlib.dll
MOD - [2013/09/11 19:55:14 | 000,036,961 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\dbx_mmap.dll
MOD - [2013/08/23 12:14:20 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a2920ed81e097f8551231a9350697bbd\PresentationFramework.Aero.ni.dll
MOD - [2013/08/23 12:12:35 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\8f4a3d09bd38a742ccfe4a20a126fff5\UIAutomationProvider.ni.dll
MOD - [2013/08/23 12:11:32 | 011,499,520 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\9a6c1b7af18b4d5a91dc7f8d6617522f\mscorlib.ni.dll
MOD - [2013/08/07 21:25:24 | 000,093,696 | ---- | M] () -- C:\Program Files\FileZilla FTP Client\fzshellext.dll
MOD - [2012/05/24 21:20:54 | 000,110,592 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\folders.dll
MOD - [2011/10/12 16:23:40 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2011/10/12 16:18:34 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2011/09/08 23:47:50 | 000,094,315 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\StartupStatus.dll
MOD - [2011/05/26 05:27:17 | 000,311,296 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\mscorlib.resources\2.0.0.0_fr_b77a5c561934e089\mscorlib.resources.dll
MOD - [2011/05/26 05:25:26 | 000,212,992 | ---- | M] () -- C:\Windows\assembly\GAC_MSIL\System.resources\2.0.0.0_fr_b77a5c561934e089\System.resources.dll
MOD - [2011/05/15 18:37:04 | 000,555,520 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\spellcheckerW.dll
MOD - [2011/03/19 23:31:02 | 000,099,328 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\updater.dll
MOD - [2011/02/09 22:56:56 | 000,082,021 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\KeepStatus.dll
MOD - [2008/02/13 19:20:20 | 000,056,832 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\keyboardnotify.dll
MOD - [2007/07/20 15:37:56 | 000,129,536 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\MetaContacts.dll
MOD - [2006/07/21 19:09:54 | 000,692,224 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\fingerprint.dll
MOD - [2006/05/29 14:14:04 | 000,024,576 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\PackFr.dll
MOD - [2006/05/21 19:02:34 | 000,037,888 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\mToolTip.dll
MOD - [2005/12/09 15:06:26 | 000,053,248 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\mtextcontrol.dll
MOD - [2005/07/13 21:55:54 | 000,042,496 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\NewStatusNotify.dll
MOD - [2004/12/16 21:03:44 | 000,098,304 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\YAMN.dll
MOD - [2004/10/07 09:40:24 | 000,069,632 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\FullScreenDetectorMirandaPlugin.dll
MOD - [2004/09/21 22:50:00 | 000,004,608 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\YAMN\simple.dll
MOD - [2004/07/16 20:29:00 | 000,037,888 | ---- | M] () -- H:\Program Files\Miranda IM Fr\Plugins\PNGImg.dll
MOD - [2002/06/21 05:01:58 | 000,155,648 | ---- | M] () -- H:\Program Files\Miranda IM Fr\ssleay32.dll
MOD - [2002/06/21 05:01:32 | 000,659,456 | ---- | M] () -- H:\Program Files\Miranda IM Fr\libeay32.dll
========== Services (SafeList) ==========
SRV - [2013/10/09 04:19:14 | 000,565,672 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2013/05/27 06:57:27 | 000,680,960 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend)
SRV - [2013/05/02 01:33:29 | 000,046,808 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2011/10/12 22:09:32 | 000,176,128 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/10/12 16:18:28 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2009/07/14 03:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/14 03:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\XDva401.sys -- (XDva401)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Windows\system32\Drivers\PROCEXP151.SYS -- (PROCEXP151)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\Lusky\AppData\Local\Temp\catchme.sys -- (catchme)
DRV - File not found [Kernel | On_Demand | Unknown] -- -- (au169y0u)
DRV - [2013/07/04 16:38:20 | 000,188,176 | ---- | M] (Oracle Corporation) [Kernel | System | Running] -- C:\Windows\System32\drivers\VBoxDrv.sys -- (VBoxDrv)
DRV - [2013/06/17 22:37:07 | 000,013,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\System32\apf003.sys -- (apf003)
DRV - [2013/06/17 14:12:32 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\sptd.sys -- (sptd)
DRV - [2013/05/02 16:52:41 | 000,174,664 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswVmm.sys -- (aswVmm)
DRV - [2013/05/02 01:34:09 | 000,765,736 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\Windows\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2013/05/02 01:34:09 | 000,368,944 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2013/05/02 01:34:09 | 000,061,680 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswRdr2.sys -- (aswRdr)
DRV - [2013/05/02 01:34:09 | 000,056,080 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2013/05/02 01:34:09 | 000,049,376 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\System32\drivers\aswRvrt.sys -- (aswRvrt)
DRV - [2013/05/02 01:34:08 | 000,066,336 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswMonFlt.sys -- (aswMonFlt)
DRV - [2013/05/02 01:34:07 | 000,029,816 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\Windows\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2013/01/30 13:11:50 | 000,295,936 | ---- | M] (EldoS Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\sscbfs3.sys -- (SSCBFS3)
DRV - [2011/10/12 22:55:06 | 008,598,528 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2011/10/12 21:30:18 | 000,257,024 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2011/06/07 00:06:54 | 000,211,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdW73.sys -- (AtiHDAudioService)
DRV - [2010/11/20 23:29:34 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 23:29:24 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 23:29:03 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 23:29:03 | 000,112,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tsusbhub.sys -- (tsusbhub)
DRV - [2010/11/20 23:29:03 | 000,077,184 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\Synth3dVsc.sys -- (Synth3dVsc)
DRV - [2010/11/20 23:29:03 | 000,062,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\dmvsc.sys -- (dmvsc)
DRV - [2010/11/20 23:29:03 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 23:29:03 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 23:29:03 | 000,027,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2010/11/20 23:29:03 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\terminpt.sys -- (terminpt)
DRV - [2010/11/20 23:29:03 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 23:29:03 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009/07/14 01:45:33 | 000,083,456 | ---- | M] (Brother Industries Ltd.) [Kernel | System | Running] -- C:\Windows\System32\drivers\serial.sys -- (Serial)
DRV - [2009/07/14 00:02:52 | 000,347,264 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\nvm62x32.sys -- (NVENETFD)
DRV - [2006/11/02 08:57:08 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\irsir.sys -- (irsir)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = fr
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 90 54 CB 83 8B 6B CE 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope =
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.addSBtoToolbar: false
FF - prefs.js..browser.search.defaultenginename: "Google CH-FR"
FF - prefs.js..browser.search.selectedEngine: "Google CH-FR"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.fr/ig"
FF - prefs.js..extensions.enabledAddons: fr-classique-reforme1990%40dictionaries.addons.mozilla.org:4.3
FF - prefs.js..extensions.enabledAddons: foxmarks%40kei.com:4.2.1
FF - prefs.js..extensions.enabledAddons: tabscope%40xuldev.org:1.5
FF - prefs.js..extensions.enabledAddons: tiletabs%40DW-dev:10.1
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:24.0
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.2
FF - prefs.js..extensions.enabledItems: [email protected]:0.6
FF - prefs.js..extensions.enabledItems: {ee56ecf0-6e7a-479a-8162-e123a991c7e7}:0.4.4
FF - prefs.js..extensions.enabledItems: [email protected]:1.12.0.36949
FF - prefs.js..extensions.enabledItems: [email protected]:1.5.7
FF - prefs.js..extensions.enabledItems: {655397ca-4766-496b-b7a8-3a5b176ee4c2}:1.4.5
FF - prefs.js..extensions.enabledItems: [email protected]:0.5.12
FF - prefs.js..extensions.enabledItems: {16466865-007f-4ce4-aeb5-a0aa8b34c61a}:3.2
FF - prefs.js..extensions.enabledItems: {E2883E8F-472F-4fb0-9522-AC9BF37916A7}:1.6.2.87
FF - prefs.js..extensions.enabledItems: [email protected]:0.6.1
FF - prefs.js..extensions.enabledItems: {5fb1186a-3398-4c47-b579-0f2eee222ad1}:0.9.0.76
FF - prefs.js..extensions.enabledItems: [email protected]:0.2.0.7
FF - prefs.js..extensions.enabledItems: {15613dee-6815-4f83-90da-2c578102b6c8}:1.0.4
FF - prefs.js..extensions.enabledItems: [email protected]:0.3.6
FF - prefs.js..extensions.enabledItems: [email protected]:0.7
FF - prefs.js..extensions.enabledItems: [email protected]:1.6.8
FF - prefs.js..extensions.enabledItems: [email protected]:2.3.0
FF - prefs.js..network.proxy.autoconfig_url: "file:///h:/d/free-youtube-rule2.pac"
FF - prefs.js..network.proxy.socks: "127.0.0.1"
FF - prefs.js..network.proxy.socks_port: 9050
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF - HKLM\Software\MozillaPlugins\@esn.me/esnsonar,version=0.70.4: C:\Program Files\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@esn/esnlaunch,version=2.1.7: C:\Program Files\Battlelog Web Plugins\2.1.7\npesnlaunch.dll (ESN Social Software AB)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.8: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF [2013/06/17 14:05:46 | 000,000,000 | ---D | M]
[2013/06/17 15:06:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\Extensions
[2013/10/17 19:17:46 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions
[2013/06/17 15:06:37 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/06/17 15:06:39 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2013/06/17 15:06:41 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus®)) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2013/06/17 15:06:36 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions\[email protected]
[2013/06/17 15:06:37 | 000,000,000 | ---D | M] (Dictionnaire français «Classique & Réforme 1990») -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default\extensions\[email protected]
[2013/06/17 15:06:55 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions
[2013/06/17 15:06:50 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/06/17 15:06:53 | 000,000,000 | ---D | M] (EPUBReader) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\{5384767E-00D9-40E9-B72F-9CC39D655D6F}
[2013/06/17 15:06:54 | 000,000,000 | ---D | M] (TabGroups Manager) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\{ca526f8b-9e0a-4756-9077-19d6f3e64ea8}
[2013/06/17 15:06:55 | 000,000,000 | ---D | M] (Adobe DLM (powered by getPlus®)) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
[2013/06/17 15:06:47 | 000,000,000 | ---D | M] (Ctrl-Tab) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/06/17 15:06:47 | 000,000,000 | ---D | M] (Flashbug) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/06/17 15:06:50 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/06/17 15:06:50 | 000,000,000 | ---D | M] (Dictionnaire français «Classique & Réforme 1990») -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/06/17 15:06:50 | 000,000,000 | ---D | M] (Vlc Kontextmenü) -- C:\Users\Lusky\AppData\Roaming\mozilla\Firefox\Profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/04/21 10:40:20 | 000,301,821 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/08/02 09:33:09 | 000,003,958 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/10/04 22:21:37 | 002,209,401 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/10/17 19:17:46 | 000,390,473 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2012/03/31 22:14:45 | 000,081,251 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/09/23 20:04:39 | 000,248,650 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/09/08 20:43:57 | 000,160,818 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2012/09/12 11:33:19 | 000,621,521 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/10/05 22:21:02 | 000,119,969 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/05/02 23:08:02 | 000,009,582 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\[email protected]
[2013/04/11 21:13:52 | 000,232,420 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\{655397ca-4766-496b-b7a8-3a5b176ee4c2}.xpi
[2011/11/10 23:32:21 | 000,093,926 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2013/10/10 09:19:14 | 000,915,554 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/03/29 22:14:45 | 000,129,271 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/11/17 21:48:27 | 000,284,001 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/02/24 12:56:19 | 002,163,784 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/02/10 02:48:16 | 000,141,008 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2011/04/14 15:54:54 | 000,021,763 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/03/31 22:14:45 | 000,081,251 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2011/11/24 23:33:11 | 000,255,318 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2013/02/10 23:15:28 | 000,636,948 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/05/17 18:57:35 | 000,022,247 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2011/06/05 19:40:38 | 000,217,846 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/07/27 11:07:50 | 000,057,698 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/09/12 11:33:19 | 000,621,521 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2012/12/30 01:16:16 | 000,282,113 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\[email protected]
[2011/07/01 18:11:03 | 000,710,352 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{15613dee-6815-4f83-90da-2c578102b6c8}.xpi
[2012/10/18 23:00:47 | 000,220,296 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{655397ca-4766-496b-b7a8-3a5b176ee4c2}.xpi
[2011/11/10 23:32:21 | 000,093,926 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{ba243cb0-b824-4a26-9418-73ee795d9b9d}.xpi
[2013/02/14 23:15:23 | 000,817,280 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/12/29 00:07:15 | 000,747,868 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi
[2011/08/15 22:39:48 | 000,026,585 | ---- | M] () (No name found) -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default - Copy\extensions\{dc5d9a10-2736-11da-8cd6-0800200c9a66}.xpi
[2013/10/19 18:58:54 | 000,002,216 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\google-ch-fr.xml
[2010/08/24 15:40:08 | 000,004,855 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\google-images.xml
[2013/10/19 18:58:54 | 000,002,091 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\google-translate-en-fr.xml
[2013/10/19 18:58:54 | 000,006,130 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\google-translate-fr-en.xml
[2013/10/19 18:58:54 | 000,002,533 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\imdb.xml
[2013/10/19 18:58:54 | 000,002,273 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\mediadico---anglaisfranais.xml
[2013/10/19 18:58:54 | 000,002,311 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\wikipdia-fr---lire.xml
[2011/08/16 19:18:50 | 000,002,468 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\wiktionnaire-fr.xml
[2013/10/19 18:58:54 | 000,002,549 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\wr-english-french.xml
[2013/10/19 18:58:55 | 000,002,549 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\mozilla\firefox\profiles\exodfja2.default\searchplugins\wr-french-english.xml
O1 HOSTS File: ([2009/06/10 23:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Users\Lusky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\miranda32.lnk = H:\Program Files\Miranda IM Fr\miranda32.exe ( )
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.27.40.240 212.27.40.241
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DBF0A545-0CEF-4169-813E-7AB83D396A71}: DhcpNameServer = 212.27.40.240 212.27.40.241
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: EldosMountNotificator - {C28617FD-4FE7-4043-AD51-C8132CE90106} - C:\Windows\System32\SSCbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22 - SharedTaskScheduler: {C28617FD-4FE7-4043-AD51-C8132CE90106} - Virtual Storage Mount Notification - C:\Windows\System32\SSCbFsMntNtf3.dll (EldoS Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2009/11/28 20:18:54 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2013/10/19 23:05:27 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/10/19 23:05:04 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2013/10/14 22:49:11 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Roaming\Pingus
[2013/10/13 16:03:59 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\Altap
[2013/10/13 14:29:48 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013/10/13 14:29:38 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013/10/11 21:22:08 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\My Games
[2013/10/10 21:17:33 | 000,133,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\ataport.sys
[2013/10/10 21:17:11 | 000,271,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
[2013/10/10 21:17:11 | 000,169,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\winsrv.dll
[2013/10/10 21:17:11 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-file-l1-1-0.dll
[2013/10/10 21:17:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-sysinfo-l1-1-0.dll
[2013/10/10 21:17:11 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-synch-l1-1-0.dll
[2013/10/10 21:17:11 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-namedpipe-l1-1-0.dll
[2013/10/10 21:17:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-string-l1-1-0.dll
[2013/10/10 21:17:11 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-rtlsupport-l1-1-0.dll
[2013/10/10 21:17:10 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processthreads-l1-1-0.dll
[2013/10/10 21:17:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-misc-l1-1-0.dll
[2013/10/10 21:17:10 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localregistry-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-processenvironment-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-memory-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-libraryloader-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-interlocked-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-profile-l1-1-0.dll
[2013/10/10 21:17:10 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-io-l1-1-0.dll
[2013/10/10 21:17:09 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-threadpool-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-xstate-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-heap-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-handle-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-fibers-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-errorhandling-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-delayload-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-debug-l1-1-0.dll
[2013/10/10 21:17:09 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-datetime-l1-1-0.dll
[2013/10/10 21:17:08 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-security-base-l1-1-0.dll
[2013/10/10 21:17:08 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-localization-l1-1-0.dll
[2013/10/10 21:17:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-util-l1-1-0.dll
[2013/10/10 21:17:08 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\System32\api-ms-win-core-console-l1-1-0.dll
[2013/10/08 09:07:43 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Roaming\Altap
[2013/10/07 18:42:54 | 000,000,000 | ---D | C] -- C:\Users\Lusky\Documents\My SugarSync
[2013/10/07 18:34:11 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\SugarSync
[2013/10/07 18:34:08 | 000,225,024 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\SSCbFsNetRdr3.dll
[2013/10/07 18:34:08 | 000,159,488 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\SSCbFsMntNtf3.dll
[2013/10/07 18:33:02 | 000,295,936 | ---- | C] (EldoS Corporation) -- C:\Windows\System32\drivers\sscbfs3.sys
[2013/10/07 18:32:49 | 000,000,000 | ---D | C] -- C:\Program Files\SugarSync
[2013/10/06 21:50:14 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\Paint.NET
[2013/10/05 18:49:51 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Roaming\Bioshock2Steam
[2013/10/05 18:49:51 | 000,000,000 | ---D | C] -- C:\Users\Lusky\Documents\Bioshock2
[2013/10/04 00:30:11 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\CrashDumps
[2013/10/02 20:33:06 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\DOSBox
[2013/10/02 17:54:09 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Roaming\ScummVM
[2013/09/28 20:46:02 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\EA Games
[2013/09/27 23:00:04 | 000,000,000 | ---D | C] -- C:\Users\Lusky\Documents\Facepalm Games
[2013/09/27 22:16:13 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\Chromium
[2013/09/27 22:14:44 | 000,000,000 | ---D | C] -- C:\Program Files\Rockstar Games
[2013/09/25 23:09:39 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\IdeoSi
[2013/09/23 23:04:29 | 000,000,000 | ---D | C] -- C:\Users\Lusky\AppData\Local\Electronic Arts
[2013/09/23 23:03:55 | 000,000,000 | ---D | C] -- C:\Users\Lusky\Documents\Electronic Arts
[2013/09/23 23:02:36 | 000,000,000 | ---D | C] -- C:\Users\Lusky\Documents\Electrontic Arts
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/10/20 11:00:57 | 000,022,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/10/20 11:00:57 | 000,022,944 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/10/20 10:51:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/10/20 10:51:26 | 1610,162,176 | -HS- | M] () -- C:\hiberfil.sys
[2013/10/17 08:49:43 | 000,000,835 | ---- | M] () -- C:\Users\Lusky\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2013/10/13 21:35:20 | 000,745,056 | ---- | M] () -- C:\Windows\System32\perfh00C.dat
[2013/10/13 21:35:20 | 000,686,330 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2013/10/13 21:35:20 | 000,651,938 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2013/10/13 21:35:20 | 000,468,808 | ---- | M] () -- C:\Windows\System32\perfh001.dat
[2013/10/13 21:35:20 | 000,148,574 | ---- | M] () -- C:\Windows\System32\perfc00C.dat
[2013/10/13 21:35:20 | 000,147,458 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2013/10/13 21:35:20 | 000,120,870 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2013/10/13 21:35:20 | 000,093,466 | ---- | M] () -- C:\Windows\System32\perfc001.dat
[2013/10/11 08:37:26 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2013/10/11 08:37:26 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2013/10/07 18:34:10 | 000,001,852 | ---- | M] () -- C:\Users\Public\Desktop\SugarSync.lnk
[2013/10/02 23:51:43 | 000,000,600 | ---- | M] () -- C:\Users\Lusky\AppData\Roaming\winscp.rnd
[2013/09/22 23:05:04 | 000,139,032 | ---- | M] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2013/09/22 23:04:56 | 000,290,184 | ---- | M] () -- C:\Windows\System32\PnkBstrB.xtr
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/10/17 08:49:43 | 000,000,835 | ---- | C] () -- C:\Users\Lusky\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2013/10/07 18:34:10 | 000,001,852 | ---- | C] () -- C:\Users\Public\Desktop\SugarSync.lnk
[2013/10/02 22:18:19 | 000,000,834 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Altap Salamander (beta x86).lnk
[2013/08/31 23:13:14 | 000,139,032 | ---- | C] () -- C:\Windows\System32\drivers\PnkBstrK.sys
[2013/08/31 22:54:03 | 000,290,184 | ---- | C] () -- C:\Windows\System32\PnkBstrB.exe
[2013/08/31 22:44:32 | 000,076,888 | ---- | C] () -- C:\Windows\System32\PnkBstrA.exe
[2013/08/31 22:36:39 | 002,601,752 | ---- | C] () -- C:\Windows\System32\pbsvc_moh.exe
[2013/08/30 20:09:49 | 002,580,552 | ---- | C] () -- C:\Windows\System32\pbsvc.exe
[2013/08/29 19:26:28 | 000,138,056 | ---- | C] () -- C:\Users\Lusky\AppData\Roaming\PnkBstrK.sys
[2013/08/01 00:09:28 | 000,000,080 | ---- | C] () -- C:\Users\Lusky\.gitconfig
[2013/07/31 23:20:10 | 000,000,000 | ---- | C] () -- C:\Users\Lusky\.hgrc
[2013/07/31 21:46:58 | 000,000,010 | ---- | C] () -- C:\Users\Lusky\.bash_history
[2013/07/30 19:20:01 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/07/30 19:20:01 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/07/30 19:20:01 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/07/30 19:20:01 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/07/30 19:20:01 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/07/04 01:18:07 | 000,000,496 | ---- | C] () -- C:\Users\Lusky\AppData\Local\glade-3.conf
[2013/07/04 01:18:07 | 000,000,218 | ---- | C] () -- C:\Users\Lusky\AppData\Local\recently-used.xbel
[2013/06/18 00:12:23 | 000,008,192 | ---- | C] () -- C:\Windows\d3dx.dat
[2013/06/17 22:37:07 | 000,016,304 | ---- | C] () -- C:\Windows\System32\apl003.sys
[2013/06/17 22:37:07 | 000,013,232 | ---- | C] () -- C:\Windows\System32\apf003.sys
[2013/06/17 14:26:28 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2013/06/17 14:12:42 | 000,000,600 | ---- | C] () -- C:\Users\Lusky\AppData\Roaming\winscp.rnd
[2013/06/17 14:06:15 | 000,174,664 | ---- | C] () -- C:\Windows\System32\drivers\aswVmm.sys
[2013/06/17 14:06:15 | 000,049,376 | ---- | C] () -- C:\Windows\System32\drivers\aswRvrt.sys
========== ZeroAccess Check ==========
[2009/07/14 06:42:31 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/26 03:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 23:29:20 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/07/14 03:16:17 | 000,342,528 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
< End of report >