OTL logfile created on: 05.05.2012 13:05:50 - Run 1
OTL by OldTimer - Version 3.2.42.1 Folder = C:\Users\Laptop\Desktop
64bit- Ultimate Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000414 | Country: Norge | Language: NOR | Date Format: dd.MM.yyyy
3,99 Gb Total Physical Memory | 1,81 Gb Available Physical Memory | 45,20% Memory free
7,99 Gb Paging File | 5,78 Gb Available in Paging File | 72,40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 146,39 Gb Total Space | 98,49 Gb Free Space | 67,28% Space Free | Partition Type: NTFS
Drive D: | 319,27 Gb Total Space | 283,62 Gb Free Space | 88,84% Space Free | Partition Type: NTFS
Drive E: | 699,59 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS
Computer Name: LAPTOP-PC | User Name: Laptop | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012.05.05 13:05:10 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Laptop\Desktop\OTL.exe
PRC - [2012.03.31 17:37:33 | 000,949,104 | ---- | M] (Opera Software) -- C:\Program Files (x86)\Opera\opera.exe
PRC - [2012.03.20 12:20:52 | 000,571,320 | ---- | M] (Threat Expert Ltd.) -- C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe
PRC - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011.12.14 13:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2011.03.18 17:50:58 | 002,271,608 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011.01.29 00:17:28 | 001,523,712 | ---- | M] (Don HO don.h@free.fr) -- C:\Program Files (x86)\Notepad++\notepad++.exe
PRC - [2010.10.06 22:28:12 | 003,768,176 | ---- | M] (Stardock) -- C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe
PRC - [2009.02.17 11:27:30 | 001,237,800 | ---- | M] (Swisscom) -- C:\Program Files (x86)\Telenor\mobilt bredband\Sesam\BIN\SecMIPService.exe
========== Modules (No Company Name) ==========
MOD - [2012.04.15 19:17:19 | 008,797,344 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll
MOD - [2012.04.10 22:04:39 | 001,673,728 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll
MOD - [2012.03.31 17:38:09 | 000,276,480 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwebmdec.dll
MOD - [2012.03.31 17:38:09 | 000,078,336 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwavparse.dll
MOD - [2012.03.31 17:38:09 | 000,064,000 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstautodetect.dll
MOD - [2012.03.31 17:38:09 | 000,046,592 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstwaveform.dll
MOD - [2012.03.31 17:38:09 | 000,045,568 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gsttypefindfunctions.dll
MOD - [2012.03.31 17:38:08 | 000,316,928 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstoggdec.dll
MOD - [2012.03.31 17:38:07 | 000,168,448 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstffmpegcolorspace.dll
MOD - [2012.03.31 17:38:07 | 000,076,800 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdirectsound.dll
MOD - [2012.03.31 17:38:06 | 000,783,360 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\gstreamer.dll
MOD - [2012.03.31 17:38:06 | 000,099,840 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstcoreplugins.dll
MOD - [2012.03.31 17:38:06 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioresample.dll
MOD - [2012.03.31 17:38:06 | 000,098,816 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstaudioconvert.dll
MOD - [2012.03.31 17:38:06 | 000,068,608 | ---- | M] () -- C:\Program Files (x86)\Opera\gstreamer\plugins\gstdecodebin2.dll
MOD - [2010.10.04 19:54:31 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDockFree\zlib.dll
MOD - [2010.10.04 19:54:29 | 000,807,936 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDockFree\CrashRpt.dll
MOD - [2010.10.04 19:54:29 | 000,675,840 | ---- | M] () -- C:\Program Files (x86)\Stardock\ObjectDockFree\DockShellHook.dll
MOD - [2010.08.15 20:34:24 | 000,204,800 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\ComparePlugin.dll
MOD - [2008.09.06 14:51:16 | 000,014,336 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
MOD - [2007.08.05 03:10:52 | 000,250,368 | ---- | M] () -- C:\Program Files (x86)\Notepad++\plugins\Config\tidy\libTidy.dll
========== Win32 Services (SafeList) ==========
SRV:
64bit: - [2012.04.12 17:28:06 | 000,087,344 | ---- | M] (MacPaw Inc.) [Auto | Running] -- C:\Program Files\CleanMyPC\CleanMyPCService.exe -- (CleanMyPCService)
SRV:
64bit: - [2011.12.01 12:19:46 | 000,053,760 | ---- | M] () [Auto | Running] -- C:\Program Files\Jotta\jottaVSS.exe -- (jottaVSS)
SRV:
64bit: - [2009.07.14 03:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:
64bit: - [2009.07.14 03:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV - [2012.04.15 19:17:20 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012.04.04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Stopped] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012.03.20 13:49:22 | 001,118,648 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools\PC Tools Security\pctsSvc.exe -- (sdCoreService)
SRV - [2012.03.20 12:20:52 | 000,571,320 | ---- | M] (Threat Expert Ltd.) [Auto | Running] -- C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\BDTUpdateService.exe -- (Browser Defender Update Service)
SRV - [2012.03.20 11:11:50 | 000,402,336 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools\PC Tools Security\pctsAuxs.exe -- (sdAuxService)
SRV - [2012.03.20 11:11:46 | 000,071,008 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files (x86)\PC Tools\PC Tools Security\TFEngine\TFService.exe -- (ThreatFire)
SRV - [2012.01.03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011.12.14 13:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2011.03.18 17:50:58 | 002,271,608 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2010.02.19 14:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2009.06.10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2009.02.17 11:27:30 | 001,237,800 | ---- | M] (Swisscom) [Auto | Running] -- C:\Program Files (x86)\Telenor\mobilt bredband\Sesam\BIN\SecMIPService.exe -- (SesamService)
========== Driver Services (SafeList) ==========
DRV:
64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys -- (esgiguard)
DRV:
64bit: - [2012.05.03 19:00:29 | 000,181,512 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pctplfw64.sys -- (pctplfw)
DRV:
64bit: - [2012.05.03 19:00:28 | 000,077,976 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pctNdisLW64.sys -- (pctNdisLW64)
DRV:
64bit: - [2012.05.03 19:00:26 | 000,122,784 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\pctNdis-PacketFilter64.sys -- (PCTFW-PacketFilter)
DRV:
64bit: - [2012.03.20 13:50:48 | 000,092,896 | ---- | M] (PC Tools) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pctplsg64.sys -- (pctplsg)
DRV:
64bit: - [2012.03.20 13:50:18 | 000,251,528 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\PCTSD64.sys -- (PCTSD)
DRV:
64bit: - [2012.03.20 13:43:36 | 000,339,608 | ---- | M] (PC Tools) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\pctgntdi64.sys -- (pctgntdi)
DRV:
64bit: - [2012.03.20 12:21:14 | 000,085,192 | ---- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\PCTBD64.sys -- (PCTBD)
DRV:
64bit: - [2012.03.20 11:11:48 | 000,706,776 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfSysMon.sys -- (TFSysMon)
DRV:
64bit: - [2012.03.20 11:11:46 | 000,065,664 | --S- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TfFsMon.sys -- (TfFsMon)
DRV:
64bit: - [2012.03.20 11:11:46 | 000,041,968 | --S- | M] (PC Tools) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TfNetMon.sys -- (TfNetMon)
DRV:
64bit: - [2012.03.16 12:15:42 | 000,426,104 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PCTCore64.sys -- (PCTCore)
DRV:
64bit: - [2012.02.28 11:43:18 | 001,096,176 | ---- | M] (PC Tools) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\pctEFA64.sys -- (pctEFA)
DRV:
64bit: - [2012.02.28 11:43:12 | 000,453,896 | ---- | M] (PC Tools) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pctDS64.sys -- (pctDS)
DRV:
64bit: - [2012.02.15 11:01:50 | 000,052,736 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011.03.15 12:46:36 | 000,254,528 | ---- | M] (DT Soft Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:
64bit: - [2011.03.11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011.03.11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2010.11.20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010.11.20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010.11.20 13:03:42 | 000,020,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:
64bit: - [2010.11.12 01:10:49 | 000,155,752 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:
64bit: - [2010.10.02 10:08:56 | 000,043,456 | ---- | M] (
http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\libusb0.sys -- (libusb0)
DRV:
64bit: - [2010.08.27 13:54:02 | 000,138,752 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbnet.sys -- (ewusbnet)
DRV:
64bit: - [2010.08.07 17:49:04 | 000,121,600 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ewusbmdm.sys -- (hwdatacard)
DRV:
64bit: - [2010.03.20 12:06:58 | 000,013,952 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_usbenumfilter.sys -- (ew_usbenumfilter)
DRV:
64bit: - [2010.03.20 10:56:56 | 000,114,560 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV:
64bit: - [2009.09.28 09:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)
DRV:
64bit: - [2009.09.15 19:40:42 | 006,952,960 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Intel®
DRV:
64bit: - [2009.07.14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009.07.14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009.07.14 03:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:
64bit: - [2009.07.14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009.06.10 23:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2009.06.10 22:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:
64bit: - [2009.06.10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009.06.10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009.06.10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009.06.10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009.05.18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2009.01.31 00:30:52 | 000,383,784 | ---- | M] (Swisscom) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wtsmpflt.sys -- (WtSmpFlt)
DRV:
64bit: - [2009.01.31 00:30:52 | 000,056,104 | ---- | M] (Swisscom) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wtsmpadap.sys -- (wtsmpadap)
DRV - [2009.07.14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
DRV - [2009.07.07 19:53:02 | 000,028,160 | ---- | M] (
http://libusb-win32.sourceforge.net) [Kernel | On_Demand | Running] -- C:\Windows\SysWOW64\drivers\libusb0.sys -- (libusb0)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = my.daemon-search.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = no
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 28 7A A4 6C D4 8C CB 01 [binary data]
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/...Box&FORM=IE8SRC
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" =
http://www.daemon-se...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "http://no.woofi.info/"
FF - prefs.js..browser.startup.homepage: "http://no.woofi.info/"
FF - prefs.js..extensions.enabledItems: firebug@software.joehewitt.com:1.6.2
FF - prefs.js..extensions.enabledItems: {75CEEE46-9B64-46f8-94BF-54012DE155F0}:0.4.8
FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.2.0.7165
FF - prefs.js..extensions.enabledItems: secureLogin@blueimp.net:0.9.7
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_233.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Laptop\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Laptop\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\Laptop\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll (Facebook, Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\Firefox\ [2012.05.02 19:13:08 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012.03.23 21:57:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012.04.11 15:14:00 | 000,000,000 | ---D | M]
[2011.03.14 23:33:41 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Laptop\AppData\Roaming\Mozilla\Extensions
[2012.04.29 15:58:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\txv6mpnk.default\extensions
[2012.03.23 21:59:16 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\txv6mpnk.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011.03.15 12:46:10 | 000,002,059 | ---- | M] () -- C:\Users\Laptop\AppData\Roaming\Mozilla\Firefox\Profiles\txv6mpnk.default\searchplugins\daemon-search.xml
[2012.03.23 21:57:31 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
() (No name found) -- C:\USERS\LAPTOP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TXV6MPNK.DEFAULT\EXTENSIONS\{75CEEE46-9B64-46F8-94BF-54012DE155F0}.XPI
() (No name found) -- C:\USERS\LAPTOP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TXV6MPNK.DEFAULT\EXTENSIONS\{FBF6D7FB-F305-4445-BB3D-FEF66579A033}.XPI
() (No name found) -- C:\USERS\LAPTOP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TXV6MPNK.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI
() (No name found) -- C:\USERS\LAPTOP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TXV6MPNK.DEFAULT\EXTENSIONS\SECURELOGIN@BLUEIMP.NET.XPI
() (No name found) -- C:\USERS\LAPTOP\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\TXV6MPNK.DEFAULT\EXTENSIONS\SEODOCTOR@PRELOVAC.COM.XPI
[2012.03.23 21:57:25 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011.05.04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2012.03.23 21:57:22 | 000,001,525 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\amazon-en-GB.xml
[2012.03.23 21:57:22 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012.03.23 21:57:22 | 000,001,218 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bok-NO.xml
[2012.03.23 21:57:22 | 000,000,968 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\qxl-NO.xml
[2012.03.23 21:57:22 | 000,001,203 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\telefonkatalogen-NO.xml
[2012.03.23 21:57:22 | 000,001,176 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\wikipedia-NO.xml
[2012.03.23 21:57:22 | 000,001,192 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-NO.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Laptop\AppData\Local\Google\Chrome\Application\18.0.1025.168\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Laptop\AppData\Local\Google\Chrome\Application\18.0.1025.168\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Laptop\AppData\Local\Google\Chrome\Application\18.0.1025.168\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.260.3 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U26 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Facebook Desktop (Enabled) = C:\Users\Laptop\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Laptop\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
O1 HOSTS File: ([2012.05.05 12:14:50 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitBHO64.dll (TechSmith Corporation)
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (PC Tools Browser Guard BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (ClueIEAddin) - {c14aa221-bae1-45f6-b0b3-90c23f2daa7d} - C:\Clue\adxloader.dll (Add-in Express Ltd)
O3:
64bit: - HKLM\..\Toolbar: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3:
64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (PC Tools Browser Guard) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files (x86)\PC Tools\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - Startup: C:\Users\Laptop\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Startup\Dropbox.lnk = C:\Users\Laptop\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O4 - Startup: C:\Users\Laptop\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Startup\Stardock ObjectDock.lnk = C:\Program Files (x86)\Stardock\ObjectDockFree\ObjectDock.exe (Stardock)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Recovery present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files (x86)\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra Button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files (x86)\PokerStars.NET\PokerStarsUpdate.exe (PokerStars)
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10:
64bit: - Protocol_Catalog9\Catalog_Entries64\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp64.dll (PC Tools Research Pty Ltd.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\Program Files (x86)\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F}
http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_26)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{09082641-F8F3-4877-A085-99AAB573CF9A}: DhcpNameServer = 193.213.112.4 130.67.15.198
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{C218959D-3D1A-45E5-B2DA-4B1A2A5A94C5}: DhcpNameServer = 192.168.0.1
O18:
64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.03.24 12:11:04 | 000,000,053 | R--- | M] () - E:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
========== Files/Folders - Created Within 30 Days ==========
[2012.05.05 13:05:10 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Laptop\Desktop\OTL.exe
[2012.05.05 12:36:47 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012.05.05 11:47:35 | 000,000,000 | ---D | C] -- C:\Users\Laptop\Desktop\tdsskiller
[2012.05.05 11:32:57 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{80450B2C-3422-4C5B-9AA7-1262653B77F0}
[2012.05.05 11:32:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A35F2DDA-0494-4858-9ACB-7B7EAF25F03B}
[2012.05.05 11:09:20 | 000,000,000 | ---D | C] -- C:\Users\Laptop\DoctorWeb
[2012.05.05 10:55:45 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{2DEB05AB-3A09-4908-96BF-9300F79E4AFD}
[2012.05.05 10:25:05 | 000,000,000 | ---D | C] -- C:\Windows\pss
[2012.05.05 10:11:48 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Roaming\CleanMyPC
[2012.05.04 21:06:24 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A2729AEF-B1D5-4BDC-B21E-8F2274739C3B}
[2012.05.04 21:05:41 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{26F97EC1-B30F-4428-B70B-AED52ADD3FBA}
[2012.05.04 20:41:39 | 000,706,776 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfSysMon.sys
[2012.05.04 20:41:39 | 000,065,664 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfFsMon.sys
[2012.05.04 20:41:39 | 000,041,968 | --S- | C] (PC Tools) -- C:\Windows\SysNative\drivers\TfNetMon.sys
[2012.05.04 01:07:22 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012.05.03 19:14:01 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\appmgmt
[2012.05.03 19:07:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Roaming\PC Tools
[2012.05.03 19:07:20 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Roaming\Spam Monitor
[2012.05.03 19:00:29 | 000,181,512 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctplfw64.sys
[2012.05.03 19:00:28 | 000,077,976 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctNdisLW64.sys
[2012.05.03 19:00:26 | 000,122,784 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctNdis-PacketFilter64.sys
[2012.05.03 09:43:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E76F55BF-5304-44E5-B3C8-1463B3570868}
[2012.05.03 09:42:31 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{31FD9E45-606D-4A73-92DE-F7E80A9C9E3D}
[2012.05.03 08:15:51 | 000,000,000 | ---D | C] -- C:\sh4ldr
[2012.05.03 08:15:51 | 000,000,000 | ---D | C] -- C:\Program Files\Enigma Software Group
[2012.05.02 19:16:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Roaming\Malwarebytes
[2012.05.02 19:16:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012.05.02 19:16:19 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012.05.02 19:16:16 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012.05.02 19:15:15 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012.05.02 19:15:15 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012.05.02 19:15:15 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012.05.02 19:13:45 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012.05.02 19:12:54 | 000,085,192 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTBD64.sys
[2012.05.02 19:12:51 | 000,149,432 | ---- | C] (PC Tools) -- C:\Windows\SGDetectionTool.dll
[2012.05.02 19:12:49 | 002,271,160 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDCore.dll
[2012.05.02 19:12:48 | 001,681,336 | ---- | C] (Threat Expert Ltd.) -- C:\Windows\PCTBDRes.dll
[2012.05.02 19:11:22 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012.05.02 19:11:09 | 000,339,608 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctgntdi64.sys
[2012.05.02 19:11:09 | 000,145,432 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctwfpfilter64.sys
[2012.05.02 19:10:56 | 000,014,776 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctBTFix64.sys
[2012.05.02 19:10:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Tools Security
[2012.05.02 19:10:43 | 000,092,896 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctplsg64.sys
[2012.05.02 19:09:55 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PC Tools
[2012.05.02 19:08:15 | 001,096,176 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctEFA64.sys
[2012.05.02 19:08:15 | 000,453,896 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\pctDS64.sys
[2012.05.02 19:08:07 | 000,426,104 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTCore64.sys
[2012.05.02 19:08:02 | 000,251,528 | ---- | C] (PC Tools) -- C:\Windows\SysNative\drivers\PCTSD64.sys
[2012.05.02 19:07:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\PC Tools
[2012.05.02 19:07:32 | 000,000,000 | ---D | C] -- C:\ProgramData\TEMP
[2012.05.02 19:07:23 | 000,000,000 | ---D | C] -- C:\ProgramData\PC Tools
[2012.05.02 19:07:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Roaming\TestApp
[2012.05.02 18:45:19 | 000,000,000 | ---D | C] -- C:\USERS\LAPTOP\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Data Recovery
[2012.05.02 17:05:35 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A03C80F8-7578-49E6-BEB1-096595523F05}
[2012.05.02 17:04:55 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4D2A7420-C2DF-417F-A89D-CD3D2AC8030B}
[2012.05.02 05:04:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CBF387F5-45D7-45D6-959A-E7E99850FDCB}
[2012.05.02 05:03:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{782DC2C1-6AC5-4C7D-B21C-1B83A1FB0AD0}
[2012.05.01 17:02:27 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{163F6D07-167F-4842-B644-3BC644AE9220}
[2012.05.01 17:01:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{D5E5227D-F6EB-4CA2-B309-B7235D2501C1}
[2012.04.30 23:04:00 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A5961688-843E-46EF-9817-F4F7DE3ECA97}
[2012.04.30 23:03:20 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{C47856CF-8A0D-4241-8034-585AF923B485}
[2012.04.30 11:02:24 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{9A64F6FC-CCA3-499D-87E5-45F18B6A6A0A}
[2012.04.30 11:01:44 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{D4DD0248-1167-4389-B777-66921483345B}
[2012.04.29 23:01:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{6A6C4D5C-78BA-426E-93B5-E3B0DA040F56}
[2012.04.29 23:00:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A15F43C1-B271-40A6-B432-10EDA87A5D2E}
[2012.04.29 16:58:50 | 000,000,000 | ---D | C] -- C:\Users\Laptop\Documents\Josefine
[2012.04.29 16:57:25 | 000,090,112 | ---- | C] (MindVision Software) -- C:\Windows\unvise32.exe
[2012.04.29 16:55:03 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Josefine
[2012.04.29 16:55:03 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Josefine
[2012.04.29 10:59:39 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{33B1AD16-7A34-4B72-B7CA-F80DC97495B5}
[2012.04.29 10:58:59 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A1952A4B-9617-4EAF-A921-DF10E0EDD9F8}
[2012.04.28 22:58:17 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{80AB3DC3-F369-4ED6-9218-D549DB3D304D}
[2012.04.28 22:57:37 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{B72E74B0-5CE6-474F-AA13-BD135FFA8D17}
[2012.04.28 10:56:54 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E8CC4CD8-C320-43A1-800B-C147B70245CE}
[2012.04.28 10:56:15 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{158E8810-A634-4640-9BB3-E9C8A6493FAA}
[2012.04.27 16:05:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{963E5C9D-85AB-42FE-AC4A-3B0EA7C6F133}
[2012.04.27 16:04:37 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{1E969B5D-D8F9-48C5-AD16-116601E08B97}
[2012.04.27 16:03:57 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{0A6AB7E6-B23B-4DE2-8075-52CFA700E426}
[2012.04.27 16:03:18 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{39D7125B-0D27-4CCE-BC01-726C299189AC}
[2012.04.26 14:25:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{58DA51F7-8508-4FD8-B6CB-EEBBFF69973D}
[2012.04.26 14:24:36 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{7F67F20A-7A9A-4C79-BF94-C167344880D6}
[2012.04.26 02:23:52 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{B5B01041-8933-4408-BF91-A36BDF6F60AA}
[2012.04.26 02:23:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4F4B804E-7257-433A-AE00-78A757AEB561}
[2012.04.25 14:22:31 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{047C35C6-478C-42DC-A6A1-7D319622F44A}
[2012.04.25 14:21:52 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{000B4989-6C30-48B0-AD80-17394D489C1E}
[2012.04.25 14:21:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A7496789-8AFF-48C9-8153-8828A70856B4}
[2012.04.25 14:20:33 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A3B44EDF-72E2-4D88-B866-404CD4D938F0}
[2012.04.24 14:27:33 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{1BFA9AD5-7726-4571-8E16-625BF9562D45}
[2012.04.24 14:26:54 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BDE94828-FE9B-4152-91FB-1E7A604573E5}
[2012.04.24 14:26:15 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{519AC19F-3A54-42A3-B950-21442FB47801}
[2012.04.24 14:25:36 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{71051F96-B08B-4319-9ACD-1752F6FB7EE3}
[2012.04.24 02:24:55 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{1DCCDFBD-02CD-4A1C-A532-A245A3898B3B}
[2012.04.24 02:24:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{6F7E2E3B-0D92-43BD-B058-BD0B3FB8EC3E}
[2012.04.24 02:23:36 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{D96794CE-C1D9-41F9-ADD0-ED2CD34A1F7F}
[2012.04.24 02:22:57 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CEA10573-9DCE-48D7-8F89-D0A10FCFB5CA}
[2012.04.23 14:22:15 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{83C3864A-6DC2-4F3D-B464-0684867EB0F6}
[2012.04.23 14:21:34 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{803133FE-BF43-41B4-BEB8-5C83581B2502}
[2012.04.22 11:23:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSECache
[2012.04.22 10:25:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{D42ED5A1-7E4A-4246-841D-889FC1C22E85}
[2012.04.21 21:57:41 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{27B4C794-EB3E-4CB9-89C2-E88E3A294CFE}
[2012.04.21 21:57:02 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{53F95BCE-ECCB-42D4-B9D0-0F5CB8BBC536}
[2012.04.21 21:56:23 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CD2B9236-4826-48C9-A311-0D1139C7DE85}
[2012.04.21 21:55:44 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{34D842E0-5090-4531-8796-51F7BD6E446C}
[2012.04.21 09:54:48 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{306FEFCA-EF6B-411F-BBD1-F2DA1E893124}
[2012.04.21 09:54:08 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CE251F2D-99DC-427F-AFC0-D331F6CA72E0}
[2012.04.21 09:53:48 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{3CAFB1DE-5DC0-4351-B2E4-A84865307857}
[2012.04.20 19:12:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{32FA2382-57E7-457B-B82B-BC01D2B2D453}
[2012.04.20 19:11:22 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{59B65628-DB65-43D5-978F-F564C0CF14AA}
[2012.04.20 19:10:41 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{7479100E-32A8-499D-B5AC-9C35B4AD08B8}
[2012.04.20 19:10:02 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E1449031-3C91-4397-86F5-A7A8B6FB208D}
[2012.04.19 19:23:41 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{6315524D-2ED0-4872-ACC9-F2F343976693}
[2012.04.19 19:23:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{9B11B4A6-C865-4C4C-BB06-B7C054E3D387}
[2012.04.19 19:22:22 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BDA74F8E-0E30-47B8-8B09-DA295F2C6531}
[2012.04.19 19:21:43 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A7F0B463-B7B3-4CF6-8746-FE8A3C02007C}
[2012.04.19 07:21:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{47B1D19B-5B31-4269-8100-AEF348BF4C07}
[2012.04.19 07:20:42 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{1C58B21B-6811-439A-864B-D8EA5D737463}
[2012.04.19 07:20:03 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BB5A41A5-3813-4BFB-B002-A66A4F3EC49E}
[2012.04.19 07:17:48 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live
[2012.04.18 22:13:17 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CF4B2DA1-D0A2-4976-9668-68053684006E}
[2012.04.18 22:12:38 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CAE73196-1419-4E14-B7D9-B0844EC037B9}
[2012.04.18 15:56:18 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{519BC042-4D5F-4930-918C-8CEAC4DDFA29}
[2012.04.18 15:55:39 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{5AA87E87-83CA-4B03-B909-DACA5C4C65C1}
[2012.04.18 14:19:07 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{FA166906-056A-473B-9EAD-2958F90CF964}
[2012.04.18 14:18:27 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{92686BA0-1A6E-40FD-86C1-3DA9BF560FF4}
[2012.04.18 13:36:27 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{1ADBA1C4-3B72-413B-B433-E210CC14501C}
[2012.04.18 13:35:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{FAC5099E-3B7E-449B-A215-AE53FC64BD4A}
[2012.04.18 13:33:17 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{75134DC1-B2EA-404C-9411-1F894BDE90D1}
[2012.04.18 13:28:01 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{B20BC6F7-C1F5-423A-9922-2FEA6BEFBFF2}
[2012.04.18 13:27:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{EC1A7845-62DB-4BB5-94FC-9BC13EAE639C}
[2012.04.18 09:59:22 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{ED279A21-5209-435F-B06B-2A32351E538B}
[2012.04.18 09:58:43 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A185E36A-58D1-48E1-9DD2-27DB13B5410C}
[2012.04.17 23:51:21 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{66C74371-5E0B-45C3-BEAB-5A4EBF96F4F2}
[2012.04.17 23:50:40 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{DF7879E1-E186-4C26-9BBA-D579584F2524}
[2012.04.17 22:57:57 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{3A2A520F-C434-40E4-9B52-8B58BA25008D}
[2012.04.17 22:57:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{96915DD3-2478-4B8F-839C-ED88EA06BE45}
[2012.04.17 12:36:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{9C72C47B-14D1-406F-BAA1-2150A000D42D}
[2012.04.17 12:35:37 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{8B7B57E8-47D7-4BE3-B1E7-0D3906A1AF76}
[2012.04.17 12:30:08 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{14F720F7-3264-4C2F-9BA1-41065E41D733}
[2012.04.17 12:24:03 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{273B457A-1EB8-4071-9389-087FD28E0786}
[2012.04.17 11:26:51 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{67B6C5E5-146F-4057-9581-D0DECB94EFFA}
[2012.04.17 11:26:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{DBB3099E-9595-40B8-98A3-2A88CD6DAFE2}
[2012.04.17 10:43:13 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E6C95607-845F-4C2A-A90F-138D90E2FADB}
[2012.04.17 10:42:34 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{106F0B84-F4D1-4F02-A938-BD8B629768F0}
[2012.04.17 10:39:36 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{763A12FF-B3B2-49BF-84C3-F7F14167AE79}
[2012.04.17 07:36:31 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4E487997-4F45-40D9-8255-97DCD2C2BBD8}
[2012.04.17 07:35:52 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{25676CDB-4056-437A-82BF-7ECB57DD6374}
[2012.04.17 00:19:37 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E37CA754-D343-4E84-9C9F-78748E48BF85}
[2012.04.17 00:18:58 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{8B9F6375-910C-45AC-BF09-C620908E155A}
[2012.04.16 23:45:37 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{053283B6-01E7-4C90-A148-8211FD75252F}
[2012.04.16 23:44:58 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{2AA4D95C-CF9F-4AD5-9EEC-A1A0805B2CC0}
[2012.04.16 13:56:46 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{08F737B3-DCF1-49B0-8247-9F5F26AD3597}
[2012.04.16 13:56:07 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{6A395DB8-ABC1-44C1-9880-BB19096CDF70}
[2012.04.16 11:08:03 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{8FC1B109-BE2C-4F27-A145-2F628C497F89}
[2012.04.16 11:07:24 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{0E863BDF-06D8-4378-98AD-42EBAB599761}
[2012.04.16 10:07:22 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{683FE1E4-9970-4401-9150-3F8C380F6546}
[2012.04.16 10:06:43 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{B3E1180A-C07A-4846-8FF1-09056723FEAF}
[2012.04.16 09:45:03 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{D1B1FD10-E050-4560-AEA5-69CA1E9731FD}
[2012.04.16 09:44:22 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{13B2866A-79C8-4BFD-9476-ADA2BC81D46B}
[2012.04.16 07:48:19 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{B647EEAC-FF4A-4B9E-8E10-F2BC22AFA4D9}
[2012.04.15 23:13:20 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BD19DA5A-8018-4F26-9BF7-7336E6C2DA0C}
[2012.04.15 23:12:39 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{F0BB1EA1-933A-4D84-8180-956A746D1499}
[2012.04.15 19:19:10 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4BB1ECB2-F507-4178-BF12-E24B007921CD}
[2012.04.15 19:18:29 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{CE7F20E9-DC50-482F-A1FA-6652C19142F3}
[2012.04.15 19:17:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{3B945E3E-F09D-4D15-8C62-B4920CE26BB3}
[2012.04.15 19:17:02 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{91DF9219-A2A1-4CDA-9336-85BB2DFE34D4}
[2012.04.14 23:13:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{70A0A2FE-81D7-4D20-8398-4319249BA822}
[2012.04.13 22:53:24 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{A94BEE6D-4C00-41F9-90BC-9CCA09B45E9F}
[2012.04.13 22:19:09 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{FDA6E48D-FCB8-4763-9484-B41FB3C711E8}
[2012.04.13 22:18:29 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{E2A78A62-6FFD-44CA-8042-9F7AFA9C7DA6}
[2012.04.13 21:16:12 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{466B0F5D-966F-4C0E-85BE-029B98435BC9}
[2012.04.13 21:15:32 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{3E8B4E59-4D5E-4E2C-A989-566D68487977}
[2012.04.13 20:16:14 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{61A8ED8B-BAB4-43B9-B646-E8385EF86CF3}
[2012.04.12 19:49:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{92963F40-9CD5-4E6C-BA5C-E96629AEA165}
[2012.04.12 19:49:07 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{10ABE373-D5BA-4E81-B9B7-6A83F377D381}
[2012.04.12 07:48:27 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{20552589-101C-408C-B2CC-57EEE0925D8B}
[2012.04.11 22:48:12 | 000,000,000 | ---D | C] -- C:\USERS\LAPTOP\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\Facebook
[2012.04.11 22:47:52 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\Facebook
[2012.04.11 19:07:47 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{9C0E3A41-9BCC-4E9B-B211-F4648688B5F0}
[2012.04.11 07:06:54 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BC8F905C-C4DA-40D1-85CE-B25DF28BAEE9}
[2012.04.10 18:58:20 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{F7B34465-DFF0-49B2-84EB-F2FD36ADC2A3}
[2012.04.10 06:57:39 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4787CB10-F564-4772-9745-E8240238A8C2}
[2012.04.09 13:02:41 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{BFFF6A91-1784-4B2E-80F9-4F7572AB6CA6}
[2012.04.09 10:49:59 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{8F78EA1D-5C9F-4075-AD03-44AF3C4BB156}
[2012.04.08 14:56:05 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{FD89B733-CF2B-47E1-A439-C9272A886F66}
[2012.04.07 09:35:58 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{F0DBFB22-982B-4479-82C7-B0385DF89780}
[2012.04.06 21:35:16 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{4DFA9229-33E5-44C9-9043-A44FC7D8D18E}
[2012.04.06 09:34:10 | 000,000,000 | ---D | C] -- C:\Users\Laptop\AppData\Local\{8AB9D9D5-1699-47E6-BBFD-A0FDA9E3255F}
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012.05.05 13:05:10 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Laptop\Desktop\OTL.exe
[2012.05.05 12:48:00 | 000,001,006 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000UA.job
[2012.05.05 12:26:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.05.05 12:14:50 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012.05.05 11:47:23 | 002,055,783 | ---- | M] () -- C:\Users\Laptop\Desktop\tdsskiller.zip
[2012.05.05 11:38:04 | 000,014,192 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012.05.05 11:38:04 | 000,014,192 | ---- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012.05.05 11:34:41 | 002,798,460 | ---- | M] () -- C:\Windows\SysNative\perfh014.dat
[2012.05.05 11:34:41 | 001,440,526 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012.05.05 11:34:41 | 000,897,894 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012.05.05 11:34:41 | 000,891,280 | ---- | M] () -- C:\Windows\SysNative\perfc014.dat
[2012.05.05 11:34:41 | 000,004,974 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012.05.05 11:31:45 | 001,433,571 | ---- | M] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.05.05 11:30:01 | 000,067,584 | ---- | M] () -- C:\Windows\bootstat.dat
[2012.05.05 11:08:42 | 084,638,576 | ---- | M] () -- C:\Users\Laptop\Desktop\9nm435bk.exe
[2012.05.05 10:52:02 | 000,000,932 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000UA.job
[2012.05.04 22:52:01 | 000,000,910 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000Core.job
[2012.05.04 17:48:01 | 000,000,954 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000Core.job
[2012.05.04 01:08:25 | 000,000,184 | ---- | M] () -- C:\ProgramData\-xsivsBNQ9ebjPfr
[2012.05.04 01:08:25 | 000,000,000 | ---- | M] () -- C:\ProgramData\-xsivsBNQ9ebjPf
[2012.05.03 19:00:29 | 000,181,512 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\pctplfw64.sys
[2012.05.03 19:00:28 | 000,077,976 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\pctNdisLW64.sys
[2012.05.03 19:00:26 | 000,122,784 | ---- | M] (PC Tools) -- C:\Windows\SysNative\drivers\pctNdis-PacketFilter64.sys
[2012.05.02 18:49:42 | 005,143,472 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2012.04.30 18:55:00 | 000,001,456 | ---- | M] () -- C:\Users\Laptop\AppData\Local\Adobe Save for Web 12.0 Prefs
[2012.04.21 22:52:44 | 000,004,096 | ---- | M] () -- C:\Users\Laptop\AppData\Local\keyfile3.drm
[2012.04.08 19:26:09 | 000,147,904 | ---- | M] () -- C:\Windows\SysWow64\mlfcache.dat
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012.05.05 11:47:22 | 002,055,783 | ---- | C] () -- C:\Users\Laptop\Desktop\tdsskiller.zip
[2012.05.05 11:08:02 | 084,638,576 | ---- | C] () -- C:\Users\Laptop\Desktop\9nm435bk.exe
[2012.05.04 20:53:22 | 000,002,503 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Safari.lnk
[2012.05.04 20:53:22 | 000,002,496 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
[2012.05.04 20:53:22 | 000,001,547 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
[2012.05.04 20:53:22 | 000,001,452 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
[2012.05.04 20:53:22 | 000,001,330 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
[2012.05.04 20:53:22 | 000,001,326 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
[2012.05.04 20:53:22 | 000,001,246 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
[2012.05.04 20:53:22 | 000,001,210 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
[2012.05.04 20:53:22 | 000,001,184 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012.05.04 20:53:22 | 000,001,108 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 6.lnk
[2012.05.04 20:53:21 | 000,002,519 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
[2012.05.04 20:53:21 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012.05.04 20:53:21 | 000,002,047 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition 3.0.lnk
[2012.05.04 20:53:21 | 000,001,903 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012.05.04 20:53:21 | 000,001,851 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
[2012.05.04 20:53:21 | 000,001,529 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
[2012.05.04 20:53:21 | 000,001,363 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
[2012.05.04 20:53:21 | 000,001,345 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
[2012.05.04 20:53:21 | 000,001,272 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
[2012.05.04 20:53:21 | 000,001,217 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5.lnk
[2012.05.04 20:53:21 | 000,001,179 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
[2012.05.04 20:53:21 | 000,001,160 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012.05.04 20:53:21 | 000,001,081 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5 (64 Bit).lnk
[2012.05.04 20:53:21 | 000,001,003 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2012.05.02 19:15:15 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012.05.02 19:15:15 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012.05.02 19:15:15 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012.05.02 19:15:15 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012.05.02 19:15:15 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012.05.02 19:12:52 | 000,767,928 | ---- | C] () -- C:\Windows\BDTSupport.dll
[2012.05.02 19:12:51 | 000,003,488 | ---- | C] () -- C:\Windows\UDB.zip
[2012.05.02 19:12:51 | 000,000,882 | ---- | C] () -- C:\Windows\RegSDImport.xml
[2012.05.02 19:12:51 | 000,000,879 | ---- | C] () -- C:\Windows\RegISSImport.xml
[2012.05.02 19:12:51 | 000,000,131 | ---- | C] () -- C:\Windows\IDB.zip
[2012.05.02 19:08:16 | 001,433,571 | ---- | C] () -- C:\Windows\SysNative\drivers\Cat.DB
[2012.05.02 18:45:19 | 000,000,184 | ---- | C] () -- C:\ProgramData\-xsivsBNQ9ebjPfr
[2012.05.02 18:45:19 | 000,000,000 | ---- | C] () -- C:\ProgramData\-xsivsBNQ9ebjPf
[2012.04.21 22:52:44 | 000,004,096 | ---- | C] () -- C:\Users\Laptop\AppData\Local\keyfile3.drm
[2012.04.15 19:17:49 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012.04.11 22:47:57 | 000,000,932 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000UA.job
[2012.04.11 22:47:54 | 000,000,910 | ---- | C] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000Core.job
[2011.06.01 21:35:34 | 000,147,904 | ---- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011.05.12 20:17:27 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011.03.27 16:46:52 | 001,250,322 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011.03.17 00:04:24 | 000,001,456 | ---- | C] () -- C:\Users\Laptop\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011.03.15 13:58:10 | 000,000,056 | ---- | C] () -- C:\Windows\SysWow64\ezsidmv.dat
========== LOP Check ==========
[2011.04.01 22:21:07 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\ACD Systems
[2011.05.05 00:17:53 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012.05.05 10:11:59 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\CleanMyPC
[2011.03.15 10:50:09 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Clue
[2011.03.15 12:53:28 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\DAEMON Tools Lite
[2012.05.03 16:22:25 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Dropbox
[2012.05.02 15:55:51 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\FileZilla
[2011.05.08 10:58:09 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\LPC
[2012.05.05 10:11:19 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Notepad++
[2011.12.19 17:12:56 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Obsidium
[2011.06.27 13:05:01 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Opera
[2011.06.27 13:08:14 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Option
[2011.07.08 23:39:49 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\PacificPoker
[2012.05.03 19:07:20 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Spam Monitor
[2012.04.29 18:37:58 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Spotify
[2011.03.15 13:43:37 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2011.03.13 20:40:30 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Stardock
[2011.03.17 23:16:32 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Steinberg
[2011.03.17 18:56:15 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\SWiSH Max4
[2012.05.04 21:37:50 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\TeamViewer
[2012.05.02 19:07:21 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\TestApp
[2011.03.15 21:15:10 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Thinstall
[2012.05.04 21:37:50 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\uTorrent
[2011.03.14 23:41:56 | 000,000,000 | ---D | M] -- C:\Users\Laptop\AppData\Roaming\Windows Live Writer
[2012.05.04 22:52:01 | 000,000,910 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000Core.job
[2012.05.05 10:52:02 | 000,000,932 | ---- | M] () -- C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1051396789-1699662356-3098169049-1000UA.job
[2009.07.14 07:08:49 | 000,020,952 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 195 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
< End of report >