OTL logfile created on: 17/04/2012 1:15:36 - Run 1 OTL by OldTimer - Version 3.2.39.2 Folder = C:\Users\Hugo-2010\Desktop 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000813 | Country: België | Language: NLB | Date Format: d/MM/yyyy 4,00 Gb Total Physical Memory | 1,31 Gb Available Physical Memory | 32,72% Memory free 7,99 Gb Paging File | 4,50 Gb Available in Paging File | 56,29% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 465,66 Gb Total Space | 342,18 Gb Free Space | 73,48% Space Free | Partition Type: NTFS Drive F: | 2794,39 Gb Total Space | 2640,42 Gb Free Space | 94,49% Space Free | Partition Type: NTFS Drive G: | 149,05 Gb Total Space | 129,77 Gb Free Space | 87,07% Space Free | Partition Type: NTFS Drive U: | 149,05 Gb Total Space | 96,48 Gb Free Space | 64,73% Space Free | Partition Type: NTFS Drive V: | 2794,39 Gb Total Space | 1341,51 Gb Free Space | 48,01% Space Free | Partition Type: NTFS Computer Name: HUGO-2010-PC | User Name: Hugo-2010 | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - [2012/04/17 01:14:48 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Hugo-2010\Desktop\OTL.exe PRC - [2012/04/14 01:01:56 | 000,353,440 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_2_202_233_ActiveX.exe PRC - [2012/04/06 19:36:52 | 019,985,920 | ---- | M] () -- C:\ProgramData\BOINC\projects\boinc.bakerlab.org_rosetta\minirosetta_3.26_windows_x86_64.exe PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe PRC - [2012/02/25 18:07:21 | 000,307,824 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe PRC - [2012/01/18 16:11:40 | 000,433,264 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnat.exe PRC - [2012/01/18 16:11:32 | 000,354,416 | ---- | M] (VMware, Inc.) -- C:\Windows\SysWOW64\vmnetdhcp.exe PRC - [2012/01/18 13:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe PRC - [2012/01/05 01:39:38 | 000,843,264 | ---- | M] () -- C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcg_gfam_vina_6.11_windows_intelx86 PRC - [2012/01/05 01:39:37 | 000,502,784 | ---- | M] () -- C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcg_gfam_6.11_windows_intelx86 PRC - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe PRC - [2011/11/07 17:23:59 | 002,741,031 | ---- | M] () -- C:\ProgramData\BOINC\projects\boinc.fzk.de_poem\poempp_0.8_windows_intelx86 PRC - [2011/10/23 22:07:34 | 000,630,784 | ---- | M] (FileZilla Project) -- C:\Program Files (x86)\FileZilla Server\FileZilla server.exe PRC - [2011/09/02 18:14:34 | 008,948,719 | ---- | M] () -- C:\ProgramData\BOINC\projects\einstein.phys.uwm.edu\hsgamma_FGRP1_0.23_windows_intelx86.exe PRC - [2011/08/19 10:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe PRC - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\LQCVFX\COCIManager.exe PRC - [2011/08/12 13:18:42 | 000,205,336 | ---- | M] (Logitech Inc.) -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe PRC - [2011/08/12 13:18:30 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe PRC - [2011/05/24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe PRC - [2011/04/03 22:04:53 | 000,784,384 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_eu_6.09_windows_intelx86.exe PRC - [2011/02/24 16:01:00 | 004,220,416 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_eu_um_6.09_windows_intelx86.exe PRC - [2011/02/24 16:00:59 | 004,398,592 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_eu_um_6.09_windows_intelx86.exe PRC - [2010/09/30 04:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe PRC - [2010/06/18 23:02:20 | 001,423,520 | ---- | M] () -- C:\Program Files (x86)\No-IP\DUC30.exe PRC - [2010/05/06 19:24:09 | 000,406,016 | ---- | M] (Space Sciences Laboratory) -- C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\setiathome_6.03_windows_intelx86.exe PRC - [2010/04/30 22:20:12 | 002,475,952 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe PRC - [2010/04/29 09:22:00 | 007,221,248 | ---- | M] (LaCie SA) -- C:\Program Files (x86)\LaCie\Ethernet Agent\LaCie Network Assistant.exe PRC - [2009/11/13 18:53:26 | 000,357,304 | ---- | M] (Acronis) -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe PRC - [2009/11/13 18:52:10 | 005,075,776 | ---- | M] (Acronis) -- C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe PRC - [2009/10/21 12:12:50 | 000,106,496 | ---- | M] (NEC Electronics Corporation) -- C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe PRC - [2007/08/20 14:05:24 | 001,671,168 | ---- | M] (D-Link) -- C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe PRC - [2007/01/19 11:49:04 | 000,049,152 | ---- | M] (Wireless Service) -- C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe PRC - [2006/11/14 13:22:10 | 000,121,640 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe ========== Modules (No Company Name) ========== MOD - [2012/04/06 19:36:52 | 019,985,920 | ---- | M] () -- C:\ProgramData\BOINC\projects\boinc.bakerlab.org_rosetta\minirosetta_3.26_windows_x86_64.exe MOD - [2012/01/05 01:39:38 | 000,843,264 | ---- | M] () -- C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcg_gfam_vina_6.11_windows_intelx86 MOD - [2012/01/05 01:39:37 | 000,502,784 | ---- | M] () -- C:\ProgramData\BOINC\projects\www.worldcommunitygrid.org\wcg_gfam_6.11_windows_intelx86 MOD - [2011/11/07 17:23:59 | 002,741,031 | ---- | M] () -- C:\ProgramData\BOINC\projects\boinc.fzk.de_poem\poempp_0.8_windows_intelx86 MOD - [2011/09/02 18:14:34 | 008,948,719 | ---- | M] () -- C:\ProgramData\BOINC\projects\einstein.phys.uwm.edu\hsgamma_FGRP1_0.23_windows_intelx86.exe MOD - [2011/08/22 16:47:44 | 000,336,408 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\LWSPlugins\LWS\Applets\CameraHelper\DevManagerCore.dll MOD - [2011/08/12 13:19:40 | 000,680,984 | ---- | M] () -- C:\Program Files (x86)\Common Files\logishrd\LQCVFX\COCIManager.exe MOD - [2011/08/12 13:18:30 | 000,265,240 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe MOD - [2011/06/24 22:56:36 | 000,087,328 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll MOD - [2011/06/24 22:56:14 | 001,241,888 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll MOD - [2011/04/03 22:04:53 | 000,784,384 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_eu_6.09_windows_intelx86.exe MOD - [2011/02/24 16:01:00 | 004,220,416 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadrm3p_eu_um_6.09_windows_intelx86.exe MOD - [2011/02/24 16:00:59 | 004,398,592 | ---- | M] () -- C:\ProgramData\BOINC\projects\climateprediction.net\hadam3p_eu_um_6.09_windows_intelx86.exe MOD - [2010/06/18 23:02:20 | 001,423,520 | ---- | M] () -- C:\Program Files (x86)\No-IP\DUC30.exe MOD - [2010/05/07 19:37:40 | 000,126,808 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll MOD - [2010/05/07 19:37:40 | 000,027,480 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll MOD - [2010/05/07 19:36:54 | 000,340,824 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll MOD - [2010/05/07 19:35:56 | 007,954,776 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll MOD - [2010/05/07 19:35:44 | 002,143,576 | ---- | M] () -- C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll MOD - [2010/05/06 19:24:10 | 000,448,600 | ---- | M] () -- C:\ProgramData\BOINC\projects\setiathome.berkeley.edu\libfftw3f-3-1-1a_upx.dll MOD - [2009/02/17 12:19:22 | 000,194,048 | ---- | M] () -- C:\Program Files (x86)\LaCie\Ethernet Agent\curllib.dll MOD - [2007/08/20 17:41:12 | 000,233,472 | ---- | M] () -- C:\Windows\SysWOW64\WlanApp.dll MOD - [2003/10/24 01:27:46 | 000,110,592 | ---- | M] () -- C:\Program Files (x86)\LaCie\Ethernet Agent\openldap.dll ========== Win32 Services (SafeList) ========== SRV:64bit: - [2012/02/15 05:13:00 | 000,235,520 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility) SRV:64bit: - [2011/04/27 17:21:18 | 000,288,272 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv) SRV:64bit: - [2011/04/27 17:21:18 | 000,012,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc) SRV - [2012/04/14 13:01:30 | 000,253,088 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc) SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService) SRV - [2012/01/18 16:11:40 | 000,433,264 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnat.exe -- (VMware NAT Service) SRV - [2012/01/18 16:11:32 | 000,354,416 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Windows\SysWOW64\vmnetdhcp.exe -- (VMnetDHCP) SRV - [2012/01/18 13:27:20 | 000,079,872 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\VMware\VMware Player\vmware-authd.exe -- (VMAuthdService) SRV - [2012/01/03 15:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice) SRV - [2011/10/23 22:07:34 | 000,630,784 | ---- | M] (FileZilla Project) [Auto | Running] -- C:\Program Files (x86)\FileZilla Server\FileZilla server.exe -- (FileZilla Server) SRV - [2011/08/29 22:11:04 | 000,846,448 | ---- | M] (VMware, Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe -- (VMUSBArbService) SRV - [2011/08/19 10:26:50 | 000,450,848 | ---- | M] (Logitech Inc.) [Auto | Running] -- C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- (UMVPFSrv) SRV - [2011/05/24 10:33:30 | 001,840,128 | ---- | M] (MAGIX AG) [Auto | Running] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe -- (Fabs) SRV - [2011/04/26 13:54:12 | 002,702,848 | ---- | M] (MAGIX®) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe -- (FirebirdServerMAGIXInstance) SRV - [2010/09/30 04:06:46 | 000,169,408 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor9.0) SRV - [2010/05/01 12:30:27 | 000,867,080 | ---- | M] (Acresso Software Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service) SRV - [2010/04/30 22:20:12 | 002,475,952 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe -- (afcdpsrv) SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32) SRV - [2009/11/13 18:55:02 | 000,891,344 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc) SRV - [2009/09/18 04:54:20 | 000,169,312 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe -- (AdobeActiveFileMonitor8.0) SRV - [2009/06/10 23:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32) ========== Driver Services (SafeList) ========== DRV:64bit: - File not found [Kernel | On_Demand | Stopped] -- C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x64\Sandra.sys -- (SANDRA) DRV:64bit: - [2012/04/14 22:41:14 | 000,231,376 | ---- | M] (TrueCrypt Foundation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\truecrypt.sys -- (truecrypt) DRV:64bit: - [2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector) DRV:64bit: - [2012/03/01 08:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec) DRV:64bit: - [2012/02/15 05:48:32 | 010,856,960 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag) DRV:64bit: - [2012/02/15 04:13:12 | 000,327,680 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap) DRV:64bit: - [2012/01/18 16:11:56 | 000,063,088 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmx86.sys -- (vmx86) DRV:64bit: - [2012/01/18 16:11:08 | 000,032,880 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VMkbd.sys -- (vmkbd) DRV:64bit: - [2012/01/18 16:10:38 | 000,030,320 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetuserif.sys -- (VMnetuserif) DRV:64bit: - [2012/01/18 13:06:00 | 000,045,680 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\vmnetbridge.sys -- (VMnetBridge) DRV:64bit: - [2012/01/18 13:06:00 | 000,020,080 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmnetadapter.sys -- (VMnetAdapter) DRV:64bit: - [2012/01/18 07:44:36 | 004,865,568 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvuvc64.sys -- (LVUVC64) Logitech Webcam Pro 9000(UVC) DRV:64bit: - [2012/01/18 07:44:28 | 000,351,136 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\lvrs64.sys -- (LVRS64) DRV:64bit: - [2011/12/05 21:47:30 | 000,095,248 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService) DRV:64bit: - [2011/08/29 22:11:04 | 000,039,024 | ---- | M] (VMware, Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\hcmon.sys -- (hcmon) DRV:64bit: - [2011/08/29 22:01:10 | 000,037,680 | ---- | M] (VMware, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmusb.sys -- (vmusb) DRV:64bit: - [2011/08/08 14:59:12 | 000,116,336 | ---- | M] (VMware, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\vmci.sys -- (vmci) DRV:64bit: - [2011/04/27 15:25:24 | 000,084,864 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv) DRV:64bit: - [2011/03/11 08:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata) DRV:64bit: - [2011/03/11 08:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata) DRV:64bit: - [2010/11/20 15:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD) DRV:64bit: - [2010/11/20 13:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt) DRV:64bit: - [2010/09/23 00:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr) DRV:64bit: - [2010/09/15 08:46:14 | 000,060,288 | ---- | M] (Generic USB smartcard reader) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MHIKEY10x64.sys -- (MHIKEY10) DRV:64bit: - [2010/05/07 19:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2Mon) DRV:64bit: - [2010/05/07 19:43:30 | 000,030,304 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\LVPr2M64.sys -- (LVPr2M64) DRV:64bit: - [2010/05/01 13:52:36 | 000,082,816 | ---- | M] (VSO Software) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pcouffin.sys -- (pcouffin) DRV:64bit: - [2010/04/30 22:20:14 | 000,250,464 | ---- | M] (Acronis) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\afcdp.sys -- (afcdp) DRV:64bit: - [2010/04/30 22:20:09 | 001,477,152 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\tdrpm255.sys -- (tdrpman255) Acronis Try&Decide and Restore Points filter (build 255) DRV:64bit: - [2010/04/30 22:20:08 | 000,929,312 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\timntr.sys -- (timounter) DRV:64bit: - [2010/04/30 22:20:02 | 000,254,496 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\snapman.sys -- (snapman) DRV:64bit: - [2010/03/19 04:00:00 | 000,055,856 | ---- | M] (Sonic Solutions) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PxHlpa64.sys -- (PxHlpa64) DRV:64bit: - [2010/03/09 12:21:42 | 000,123,408 | ---- | M] (ATI Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AtiHdmi.sys -- (AtiHdmiService) DRV:64bit: - [2009/11/11 18:19:54 | 000,027,512 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\dc3d.sys -- (dc3d) MS Hardware Device Detection Driver (USB) DRV:64bit: - [2009/11/11 18:19:54 | 000,015,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nuidfltr.sys -- (NuidFltr) DRV:64bit: - [2009/10/29 10:14:38 | 000,115,824 | ---- | M] (JMicron Technology Corp.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\jraid.sys -- (JRAID) DRV:64bit: - [2009/10/26 23:19:48 | 000,176,640 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3xhc.sys -- (nusb3xhc) DRV:64bit: - [2009/10/26 23:19:46 | 000,075,264 | ---- | M] (NEC Electronics Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nusb3hub.sys -- (nusb3hub) DRV:64bit: - [2009/08/20 18:05:06 | 000,239,616 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167) DRV:64bit: - [2009/07/14 03:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs) DRV:64bit: - [2009/07/14 03:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2) DRV:64bit: - [2009/07/14 03:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor) DRV:64bit: - [2009/07/14 02:06:43 | 000,060,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\61883.sys -- (61883) DRV:64bit: - [2009/07/14 02:06:43 | 000,048,768 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\avc.sys -- (Avc) DRV:64bit: - [2009/07/14 02:06:42 | 000,061,440 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msdv.sys -- (MSDV) DRV:64bit: - [2009/06/10 22:35:36 | 000,867,328 | ---- | M] (Ralink Technology Corp.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netr28ux.sys -- (netr28ux) DRV:64bit: - [2009/06/10 22:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv) DRV:64bit: - [2009/06/10 22:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv) DRV:64bit: - [2009/06/10 22:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a) DRV:64bit: - [2009/06/10 22:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir) DRV:64bit: - [2009/05/18 14:17:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM) DRV:64bit: - [2007/07/24 03:53:04 | 000,125,992 | ---- | M] (Silicon Image, Inc) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\PnP680r.sys -- (Pnp680r) DRV - [2009/07/14 03:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://be.msn.com/default.aspx IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl-BE IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 94 CA 78 7C 31 6A CB 01 [binary data] IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKU\.DEFAULT\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\.DEFAULT\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_nl IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://be.msn.com/default.aspx IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl-BE IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 94 CA 78 7C 31 6A CB 01 [binary data] IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKU\S-1-5-18\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-18\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7&rlz=1I7GGLL_nl IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default Download Directory = C:\Download\Utilities\CD-DVD branden\Burnaware IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.be/ig IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://be.msn.com/default.aspx IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = nl-be IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 42 2F A1 82 DE E7 CA 01 [binary data] IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\SearchScopes,DefaultScope = {E7EFE7B4-CF76-4EDD-AD5A-14D80C36529A} IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" = http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7 IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\SearchScopes\{6DA38389-9A26-45F5-A879-72607AAF7E81}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=FF&o=14594&src=kw&q={searchTerms}&locale=nl_EU&apn_ptnrs=FV&apn_dtid=YYYYYYYYBE&apn_uid=cf096f9b-a3a5-4275-8808-b9d349e4b0f1&apn_sauid=9FF96F89-ACFF-4475-A2DA-BE96F1116E4F IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\SearchScopes\{E7EFE7B4-CF76-4EDD-AD5A-14D80C36529A}: "URL" = http://www.google.be/search?hl=en&q={searchTerms}&meta=&rlz=1I7GGLL_nlBE377 IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_2_202_233.dll File not found FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/06/10 21:15:18 | 000,000,000 | ---D | M] FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll () FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@canon.com/MycameraPlugin: C:\Program Files (x86)\Canon\MyCamera Download Plugin\NPCIG.dll (CANON INC.) FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/Photosynth,version=2.0: C:\Program Files (x86)\Photosynth\npPhotosynthMozilla.dll () FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2010/06/10 21:15:18 | 000,000,000 | ---D | M] FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) [2012/01/01 21:48:52 | 000,002,048 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml O1 HOSTS File: ([2009/06/10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - No CLSID value found. O3:64bit: - HKU\.DEFAULT\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKU\S-1-5-18\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O3:64bit: - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) O4:64bit: - HKLM..\Run: [Acronis Scheduler2Service] C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis) O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated) O4:64bit: - HKLM..\Run: [itype] C:\Program Files\Microsoft IntelliType Pro\itype.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation) O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files (x86)\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [beid] C:\Program Files (x86)\Belgium Identity Card\beid35gui.exe (Belgian Government) O4 - HKLM..\Run: [boincmgr] C:\Program Files\BOINC\boincmgr.exe (Space Sciences Laboratory) O4 - HKLM..\Run: [boinctray] C:\Program Files\BOINC\boinctray.exe (Space Sciences Laboratory) O4 - HKLM..\Run: [D-Link D-Link RangeBooster N DWA-140] C:\Program Files (x86)\D-Link\D-Link RangeBooster N DWA-140\AirNCFG.exe (D-Link) O4 - HKLM..\Run: [FileZilla Server Interface] C:\Program Files (x86)\FileZilla Server\FileZilla Server Interface.exe (FileZilla Project) O4 - HKLM..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe () O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.) O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\Run: [NUSB3MON] C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (NEC Electronics Corporation) O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TrayServer] C:\Program Files (x86)\MAGIX\Video_deluxe_MX_Premium_Download-versie\Trayserver_NL.exe (MAGIX AG) O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis) O4 - HKU\S-1-5-19..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-21-3593445478-578016552-3228295415-1000..\Run: [LaCie Ethernet Agent Startup] C:\Program Files (x86)\LaCie\Ethernet Agent\LaCie Network Assistant.exe (LaCie SA) O4 - HKU\S-1-5-21-3593445478-578016552-3228295415-1000..\Run: [Microsoft Location Finder] C:\Program Files (x86)\Microsoft Location Finder\LocationFinder.exe (Microsoft Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - Startup: C:\Users\Hugo-2010\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\No-IP DUC.lnk = C:\Program Files (x86)\No-IP\DUC30.exe () O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run: 40964 = C:\PROGRA~3\LOCALS~1\Temp\msazujo.com O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutorun = 0 O7 - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000011 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000012 - C:\Windows\SysNative\vsocklib.dll (VMware, Inc.) O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\Windows\SysWOW64\vsocklib.dll (VMware, Inc.) O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O15 - HKU\S-1-5-21-3593445478-578016552-3228295415-1000\..Trusted Ranges: Range1979 ([http] in Trusted sites) O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (Reg Error: Key error.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Reg Error: Key error.) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.1.66.0.cab (Reg Error: Key error.) O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility) O16 - DPF: {3CA45906-EF10-4E4E-9BE4-B444D220FCB0} http://ua.foto.com/ImageUploader6.cab (Uploader Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{42846E5C-B61B-442A-A5C3-CD01953184B2}: DhcpNameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{97CF2B03-C29E-4E3F-AD0B-9E181F18604D}: DhcpNameServer = 192.168.1.1 O18:64bit: - Protocol\Handler\belarc - No CLSID value found O18:64bit: - Protocol\Handler\livecall - No CLSID value found O18:64bit: - Protocol\Handler\msnim - No CLSID value found O18:64bit: - Protocol\Handler\skype-ie-addon-data - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18:64bit: - Protocol\Handler\wlpg - No CLSID value found O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2012/04/17 01:14:48 | 000,593,920 | ---- | C] (OldTimer Tools) -- C:\Users\Hugo-2010\Desktop\OTL.exe [2012/04/17 01:10:50 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{B8C6423E-5EA9-4066-998F-BA1CF924925A} [2012/04/16 22:54:14 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{1FFC7504-008A-47B5-A775-3C28A0C2CE3B} [2012/04/16 22:53:51 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{3EE836B9-9BE0-4131-B479-F883607097DB} [2012/04/16 22:35:44 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{DA32A2B5-AB12-4D54-9875-F35D6E2DE733} [2012/04/16 22:35:22 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{8D007362-8370-4718-B94C-2F5F15F1A005} [2012/04/16 22:32:21 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{1F416AB4-5ACA-4B22-8793-78F2A561096C} [2012/04/16 20:40:29 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{2B62D506-961D-4160-9E60-5F3B67827FFB} [2012/04/16 20:40:18 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{787AF0AB-655C-48B0-83F4-85A2F23D0F4A} [2012/04/16 20:37:08 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{41E838CE-5BFF-428E-A28E-91CBF352665B} [2012/04/16 20:36:52 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{C30C3717-6B83-4FFB-82D6-927F9BB202E9} [2012/04/16 20:33:33 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{06469FD8-192F-4D60-A6CA-6695B95B1AD1} [2012/04/16 20:07:22 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{2C24A87F-7176-491C-8869-E13322DE89E3} [2012/04/16 20:07:05 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{34E015FF-0B74-40A0-8845-D9BFE36FCF89} [2012/04/16 20:01:47 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{98913718-E9B8-45C1-B7BF-1C93B5C8279C} [2012/04/16 20:01:28 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{7C9240E3-214F-42D0-9875-40E94887392B} [2012/04/15 23:20:14 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{F04B55AA-CCAE-4F7C-AE75-27661325DF77} [2012/04/15 23:19:53 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{5C11D4D8-8771-415E-A6D1-DD16A540AB65} [2012/04/15 22:54:16 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{0B94BF89-5682-4192-83F7-60FBD7CD432B} [2012/04/15 22:43:57 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{30C4AD49-B5EB-44C4-8FDC-9F8FB465656F} [2012/04/15 22:12:28 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{843E519B-4953-444B-BA2A-B307885E4649} [2012/04/15 21:57:58 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{0177C792-8AAD-41FA-8560-08DB29982117} [2012/04/15 21:52:57 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{B94E0A54-2BAE-4273-8DD2-06B219ED7F29} [2012/04/15 14:34:06 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{3E334EB8-749E-44E8-8B02-E882FC2E2722} [2012/04/15 14:33:44 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{E7027750-DEB4-45D8-9FA1-B2591AC743B3} [2012/04/15 14:19:09 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{A556EDB0-6CA8-4050-A531-BB256F50A420} [2012/04/15 13:48:01 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{EA9A9F99-5BD5-4B84-B180-A392E9CBE7F4} [2012/04/15 12:09:39 | 000,000,000 | R--D | C] -- C:\32788R22FWJFW [2012/04/14 22:38:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IsoBuster [2012/04/14 22:33:11 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{248F572A-528F-4A57-BD7B-20045C45AACB} [2012/04/14 12:47:01 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{7D1C9996-3D81-456D-BF14-D8904A6A953A} [2012/04/13 22:49:00 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{800FF905-9ED3-46B3-8949-2ED8249FA36C} [2012/04/12 19:54:50 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{23843A14-262A-4376-B924-BA1AAFAEC182} [2012/04/11 19:54:40 | 000,000,000 | ---D | C] -- C:\Program Files\iPod [2012/04/11 19:54:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes [2012/04/11 19:54:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes [2012/04/11 19:50:54 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{FEBF4F75-CFCC-4E1A-971A-3BE94A126274} [2012/04/10 19:24:33 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{6D179046-7A1E-43B1-925D-7CE3A2FB92F0} [2012/04/09 22:17:16 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{4EFE79A7-03ED-433D-BBFC-80EDADEDAB5D} [2012/04/09 00:54:28 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{D5316C05-1EE2-44B2-97C5-4E60B4996582} [2012/04/08 00:52:25 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{56610D69-A2B9-4D65-A760-2E53D56F0E29} [2012/04/08 00:46:12 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{D7F95174-E24B-4937-8BD2-A19C3C3CAD11} [2012/04/07 11:19:54 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{6E4C6B2F-6FB1-44AC-862F-16466F47C1E5} [2012/04/06 19:38:17 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{90E20DD1-DF3E-4C51-A4EB-EC1F2383EFAA} [2012/04/05 19:35:25 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{00930944-BEFE-47C3-8609-F7F9C77A38C3} [2012/04/04 19:46:45 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{986A7BED-ECFB-45CD-A90E-2DB0506A0EFF} [2012/04/03 19:21:50 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{89725327-A0AF-4ECC-85C9-809F31B2FE91} [2012/04/02 20:09:12 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{01F2AC68-6B7F-4818-8581-257985216FBD} [2012/04/02 01:19:43 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{22348CA7-052B-4AE6-9142-24786DE1F9B4} [2012/04/01 12:03:03 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{6E2B1CDF-AD4B-4D01-99CA-114D0255431D} [2012/03/31 10:56:25 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{BBE58B25-1B27-4E5C-A754-14B3923ABF63} [2012/03/31 09:58:03 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{D7CD9887-856F-4F79-9222-71999C3560B8} [2012/03/30 23:15:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MP3 My MP3 3.1 [2012/03/30 19:37:47 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{70233815-6091-4C20-896C-7B6E869873A4} [2012/03/29 19:47:59 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{2B6687A7-2280-4525-9894-5217312462B9} [2012/03/29 01:20:31 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{39657706-DC0C-4965-BF70-24634BDA51AD} [2012/03/29 01:20:09 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{FEC4EB8C-D4F4-41AB-BC98-9C972B8348B2} [2012/03/27 19:56:04 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{EB3E23CA-2CC4-40FC-9416-A6764B90FDB3} [2012/03/27 19:55:44 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{CA463D1E-C063-4EA7-81B6-B0855A54AC99} [2012/03/27 01:17:47 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{068EA4EA-7489-46F9-86F2-2CC31DD7DF73} [2012/03/27 01:17:28 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{7DB97B9C-5067-4321-8FE9-849232FC1E09} [2012/03/26 12:48:10 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{EBFE29C5-CF5B-493C-B1CB-2D407F1741A1} [2012/03/26 12:47:59 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{EA430D28-CA68-49B5-AC4E-088358361119} [2012/03/26 11:17:17 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{AED8925A-AD04-4ED6-B125-4C5DEFF642E5} [2012/03/25 21:14:11 | 000,063,088 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmx86.sys [2012/03/25 21:13:40 | 000,354,416 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnetdhcp.exe [2012/03/25 21:13:38 | 000,433,264 | ---- | C] (VMware, Inc.) -- C:\Windows\SysWow64\vmnat.exe [2012/03/25 21:13:32 | 000,030,320 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\vmnetuserif.sys [2012/03/25 21:13:23 | 000,942,192 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\vnetlib64.dll [2012/03/25 21:13:14 | 000,032,880 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\VMkbd.sys [2012/03/25 21:13:10 | 000,039,024 | ---- | C] (VMware, Inc.) -- C:\Windows\SysNative\drivers\hcmon.sys [2012/03/25 21:12:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware [2012/03/25 21:12:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\VMware [2012/03/25 21:11:33 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\VMware [2012/03/25 21:00:44 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{86305E9D-6759-4F9E-874E-6B8F10082985} [2012/03/25 21:00:30 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{A5801A4C-73C3-496B-AEBC-D4753B7558F3} [2012/03/24 13:12:24 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{1F8DAFD5-96D3-46E9-B735-AF7CC57DEA3F} [2012/03/24 13:12:01 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{ED35EE70-664D-4C1F-A193-736F90BDBFD4} [2012/03/23 23:24:35 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{039CE32D-539F-41EA-9913-F355ED20FEE7} [2012/03/23 23:24:23 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{42F32CE1-E936-469D-B52E-28756AB0B396} [2012/03/22 20:21:23 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{545D05A6-A854-4591-A7D4-C991CC5C6D56} [2012/03/22 20:20:55 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{35E39AC6-6503-4452-80F2-E8E8F8162AD9} [2012/03/21 20:38:37 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{411164FF-99BC-404E-9DB4-48277CEA9FB2} [2012/03/21 20:38:24 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{F124CC7B-F28F-43A0-B1D2-B26B6E1300E5} [2012/03/20 20:27:01 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{B04E9371-C37B-4431-BD8B-724E92CB2A02} [2012/03/20 20:26:44 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{760442AE-2740-48BC-BAEA-B98F2B2DF19C} [2012/03/19 20:47:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Windows OneCare Live [2012/03/19 20:37:46 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{4A6E9BED-67D6-4197-883F-DE4FC265F036} [2012/03/19 20:37:30 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{6F80A696-74B0-483F-918C-35D79C71666C} [2012/03/19 01:52:40 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{4CBB8269-80B4-4D76-A280-31F50AD1E9F0} [2012/03/18 12:41:49 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{6AF8DB76-54CE-48FC-AA00-CD6E3BCAC474} [2012/03/18 12:41:27 | 000,000,000 | ---D | C] -- C:\Users\Hugo-2010\AppData\Local\{8FD4F172-7FB9-4BC7-B2EC-24A0F32A5848} [2012/03/18 01:20:32 | 000,000,000 | ---D | C] -- C:\Windows\Simple Port Forwarding [2012/03/18 01:20:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Simple Port Forwarding [2010/05/01 13:52:36 | 000,082,816 | ---- | C] (VSO Software) -- C:\Users\Hugo-2010\AppData\Roaming\pcouffin.sys ========== Files - Modified Within 30 Days ========== [2012/04/17 01:14:48 | 000,593,920 | ---- | M] (OldTimer Tools) -- C:\Users\Hugo-2010\Desktop\OTL.exe [2012/04/17 01:11:00 | 000,001,062 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012/04/17 01:01:01 | 000,000,940 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012/04/16 20:23:50 | 000,023,264 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012/04/16 20:23:50 | 000,023,264 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012/04/16 20:15:58 | 000,001,058 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012/04/16 20:15:37 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2012/04/16 20:15:36 | 000,000,000 | ---- | M] () -- C:\Windows\SysNative\drivers\lvuvc.hs [2012/04/16 20:15:30 | 3219,763,200 | -HS- | M] () -- C:\hiberfil.sys [2012/04/15 22:22:22 | 000,001,502 | ---- | M] () -- C:\Users\Hugo-2010\.recently-used.xbel [2012/04/15 18:00:01 | 000,000,476 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Registration3.job [2012/04/15 13:04:40 | 000,934,473 | ---- | M] () -- C:\Users\Hugo-2010\AppData\Local\census.cache [2012/04/15 13:03:50 | 000,154,181 | ---- | M] () -- C:\Users\Hugo-2010\AppData\Local\ars.cache [2012/04/14 23:09:19 | 000,000,790 | ---- | M] () -- C:\Users\Hugo-2010\AppData\Roaming\burnaware.ini [2012/04/14 22:44:20 | 000,001,944 | ---- | M] () -- C:\Users\Public\Desktop\CDBurnerXP.lnk [2012/04/14 22:41:14 | 000,231,376 | ---- | M] (TrueCrypt Foundation) -- C:\Windows\SysNative\drivers\truecrypt.sys [2012/04/14 22:36:22 | 000,001,980 | ---- | M] () -- C:\Users\Hugo-2010\Desktop\Update Checker.lnk [2012/04/14 22:34:51 | 001,564,368 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2012/04/14 22:34:51 | 000,706,370 | ---- | M] () -- C:\Windows\SysNative\perfh013.dat [2012/04/14 22:34:51 | 000,620,854 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2012/04/14 22:34:51 | 000,135,828 | ---- | M] () -- C:\Windows\SysNative\perfc013.dat [2012/04/14 22:34:51 | 000,108,660 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2012/04/13 01:22:22 | 000,000,831 | ---- | M] () -- C:\Users\Public\Desktop\FreeFileSync.lnk [2012/04/11 19:55:24 | 000,001,794 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/04/11 00:09:13 | 000,000,450 | ---- | M] () -- C:\Windows\tasks\ParetoLogic Update Version3.job [2012/04/10 19:12:33 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk [2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2012/03/31 13:59:54 | 000,002,112 | ---- | M] () -- C:\Users\Hugo-2010\Documents\SyncSettings.ffs_gui [2012/03/31 10:12:38 | 000,001,028 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk [2012/03/30 23:17:33 | 000,087,552 | ---- | M] () -- C:\Users\Hugo-2010\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2012/03/30 23:15:23 | 000,001,990 | ---- | M] () -- C:\Users\Hugo-2010\Desktop\MP3MyMP3 3.1.lnk [2012/03/26 12:05:30 | 000,007,640 | ---- | M] () -- C:\Users\Hugo-2010\AppData\Local\Resmon.ResmonCfg [2012/03/25 21:14:15 | 000,001,026 | ---- | M] () -- C:\Users\Hugo-2010\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk [2012/03/25 21:12:55 | 001,584,524 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2012/03/25 21:12:53 | 000,002,143 | ---- | M] () -- C:\Users\Public\Desktop\VMware Player.lnk [2012/03/24 02:57:33 | 000,001,077 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk ========== Files Created - No Company Name ========== [2012/04/15 22:22:22 | 000,001,502 | ---- | C] () -- C:\Users\Hugo-2010\.recently-used.xbel [2012/04/15 13:04:40 | 000,934,473 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Local\census.cache [2012/04/15 13:03:50 | 000,154,181 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Local\ars.cache [2012/04/11 19:55:24 | 000,001,794 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk [2012/04/04 19:41:13 | 000,000,940 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012/03/31 13:59:54 | 000,002,112 | ---- | C] () -- C:\Users\Hugo-2010\Documents\SyncSettings.ffs_gui [2012/03/30 23:15:23 | 000,001,990 | ---- | C] () -- C:\Users\Hugo-2010\Desktop\MP3MyMP3 3.1.lnk [2012/03/26 13:06:22 | 000,000,831 | ---- | C] () -- C:\Users\Public\Desktop\FreeFileSync.lnk [2012/03/25 21:14:15 | 000,001,026 | ---- | C] () -- C:\Users\Hugo-2010\Application Data\Microsoft\Internet Explorer\Quick Launch\VMware Player.lnk [2012/03/25 21:12:53 | 000,002,143 | ---- | C] () -- C:\Users\Public\Desktop\VMware Player.lnk [2012/03/24 02:57:33 | 000,001,077 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk [2012/02/20 02:06:26 | 000,001,057 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\vso_ts_preview.xml [2012/02/15 04:36:36 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat [2012/02/15 04:36:36 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat [2012/01/28 03:10:10 | 000,000,636 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\AutoGK.ini [2012/01/18 07:44:00 | 010,920,984 | ---- | C] () -- C:\Windows\SysWow64\LogiDPP.dll [2012/01/18 07:44:00 | 000,336,408 | ---- | C] () -- C:\Windows\SysWow64\DevManagerCore.dll [2012/01/18 07:44:00 | 000,104,472 | ---- | C] () -- C:\Windows\SysWow64\LogiDPPApp.exe [2011/12/05 23:04:00 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OpenVideo.dll [2011/12/05 23:03:52 | 000,054,784 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll [2011/11/06 03:03:50 | 000,035,328 | ---- | C] () -- C:\Windows\INETWH32.DLL [2011/11/06 03:03:50 | 000,009,136 | ---- | C] () -- C:\Windows\INETWH16.DLL [2011/11/06 03:03:50 | 000,004,528 | ---- | C] () -- C:\Windows\SETBROWS.EXE [2011/11/06 02:54:49 | 000,000,089 | ---- | C] () -- C:\Windows\ULead32.ini [2011/09/13 01:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat [2011/08/03 13:21:58 | 004,077,568 | ---- | C] () -- C:\Windows\QLMGXRenderer.dll [2011/03/14 20:11:06 | 000,000,011 | ---- | C] () -- C:\Windows\3DShadow.INI [2011/03/12 16:27:06 | 000,044,544 | ---- | C] () -- C:\Windows\AWuninstall.exe [2011/03/12 16:26:49 | 000,000,550 | ---- | C] () -- C:\Windows\PluginSwitch.ini [2011/03/12 16:26:14 | 000,000,279 | ---- | C] () -- C:\Windows\ImageInc.ini [2011/03/09 01:27:08 | 000,000,016 | ---- | C] () -- C:\Windows\Wininit.ini [2011/01/15 15:40:57 | 001,584,524 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI [2011/01/02 02:24:38 | 000,000,056 | -H-- | C] () -- C:\Windows\SysWow64\ezsidmv.dat [2010/08/02 22:06:05 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI [2010/07/12 21:48:10 | 000,327,168 | ---- | C] () -- C:\Windows\SysWow64\cutil32.dll [2010/07/12 21:38:20 | 000,000,064 | ---- | C] () -- C:\ProgramData\sandra.ldb [2010/05/28 21:07:14 | 000,000,014 | ---- | C] () -- C:\Windows\SysWow64\systeminfo3.dll [2010/05/07 22:10:02 | 000,000,036 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Local\housecall.guid.cache [2010/05/06 22:00:42 | 000,087,552 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010/05/02 20:27:13 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\OctaneARM.dll [2010/05/02 12:00:30 | 000,120,200 | ---- | C] () -- C:\Windows\SysWow64\DLLDEV32i.dll [2010/05/01 13:52:36 | 000,099,384 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\inst.exe [2010/05/01 13:52:36 | 000,007,859 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\pcouffin.cat [2010/05/01 13:52:36 | 000,001,167 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\pcouffin.inf [2010/05/01 13:21:40 | 000,000,019 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\mdbu.bin [2010/05/01 12:30:50 | 000,007,640 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Local\Resmon.ResmonCfg [2010/04/30 22:44:13 | 000,000,790 | ---- | C] () -- C:\Users\Hugo-2010\AppData\Roaming\burnaware.ini [2010/04/30 20:51:37 | 000,073,728 | ---- | C] () -- C:\Windows\SysWow64\afasrv64.exe [2010/04/29 22:52:43 | 000,233,472 | ---- | C] () -- C:\Windows\SysWow64\WlanApp.dll [2010/04/29 22:52:43 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\JJAKEn.dll [2010/04/29 22:31:20 | 000,146,432 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL [2010/04/29 22:31:20 | 000,072,704 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL [2010/04/28 23:20:14 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin ========== LOP Check ========== [2010/07/12 19:52:55 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Acronis [2010/04/30 22:57:25 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\aignes [2011/12/10 00:21:00 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\avidemux [2011/12/04 19:50:44 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Azureus [2010/04/30 22:47:32 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Canneverbe Limited [2011/06/04 12:16:54 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Canon [2011/03/15 23:19:30 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 [2011/11/07 20:45:00 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\CoreFTP [2010/06/10 21:18:53 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\DassaultSystemes [2010/10/25 20:25:24 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\DeviceDoctorSoftware [2011/05/19 21:25:00 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\DriverCure [2012/03/21 00:29:36 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\FreeCommander [2010/10/14 00:30:19 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\FreeFileSync [2012/04/15 22:23:48 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\gtk-2.0 [2010/04/30 22:41:07 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\JAM Software [2011/11/23 22:53:17 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\kompozer.net [2011/01/04 20:49:11 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Leadertech [2011/09/28 18:47:31 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\MAGIX [2012/03/30 22:31:25 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\MediaMonkey [2010/05/01 18:25:25 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\NASA [2010/07/17 20:54:10 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\No Company Name [2010/05/07 00:27:23 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\No Company Name weg [2010/04/30 23:28:27 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\OpenOffice.org [2011/05/19 21:24:59 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\ParetoLogic [2011/09/11 20:55:49 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\proDAD [2011/11/27 13:07:19 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Raptr [2010/05/01 17:31:01 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\ResizeMe_ [2010/05/01 18:29:29 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Stellarium [2012/01/12 01:50:50 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Subtitle Edit [2011/12/04 16:34:00 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Totusoft [2012/04/14 22:41:17 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\TrueCrypt [2010/05/01 15:04:50 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\TuneUp Software [2010/05/01 15:22:47 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\TweakNow PowerPack 2010 [2012/03/08 20:59:32 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Vso [2010/10/26 20:38:54 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\Windows Live Writer [2011/11/03 12:16:53 | 000,000,000 | ---D | M] -- C:\Users\Hugo-2010\AppData\Roaming\xVideoServiceThief [2012/04/15 18:00:01 | 000,000,476 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Registration3.job [2012/04/11 00:09:13 | 000,000,450 | ---- | M] () -- C:\Windows\Tasks\ParetoLogic Update Version3.job [2012/03/04 13:11:50 | 000,032,540 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT ========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 252 bytes -> C:\ProgramData\TEMP:9A870F8B @Alternate Data Stream - 165 bytes -> C:\ProgramData\TEMP:0CE7F3C9 < End of report >